Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CERTFR-2026-AVI-1164
Vulnerability from certfr_avis
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Impacted products
| Vendor | Product | Description | ||
|---|---|---|---|---|
| SUSE | SUSE Linux Enterprise Real Time | SUSE Linux Enterprise Real Time 15 SP7 | ||
| SUSE | SUSE Linux Enterprise Live Patching | SUSE Linux Enterprise Live Patching 15-SP7 | ||
| SUSE | SUSE Linux Enterprise Server | SUSE Linux Enterprise Server for SAP Applications 15 SP7 | ||
| SUSE | SUSE Linux Micro | SUSE Linux Micro 6.1 | ||
| SUSE | SUSE Linux Micro | SUSE Linux Micro 6.0 | ||
| SUSE | SUSE Linux Enterprise Server | SUSE Linux Enterprise Server 15 SP7 | ||
| SUSE | SUSE Real Time Module | SUSE Real Time Module 15-SP7 | ||
| SUSE | SUSE Linux Micro Extras | SUSE Linux Micro Extras 6.0 |
References
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "SUSE Linux Enterprise Real Time 15 SP7",
"product": {
"name": "SUSE Linux Enterprise Real Time",
"vendor": {
"name": "SUSE",
"scada": false
}
}
},
{
"description": "SUSE Linux Enterprise Live Patching 15-SP7",
"product": {
"name": "SUSE Linux Enterprise Live Patching",
"vendor": {
"name": "SUSE",
"scada": false
}
}
},
{
"description": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
"product": {
"name": "SUSE Linux Enterprise Server",
"vendor": {
"name": "SUSE",
"scada": false
}
}
},
{
"description": "SUSE Linux Micro 6.1",
"product": {
"name": "SUSE Linux Micro",
"vendor": {
"name": "SUSE",
"scada": false
}
}
},
{
"description": "SUSE Linux Micro 6.0",
"product": {
"name": "SUSE Linux Micro",
"vendor": {
"name": "SUSE",
"scada": false
}
}
},
{
"description": "SUSE Linux Enterprise Server 15 SP7",
"product": {
"name": "SUSE Linux Enterprise Server",
"vendor": {
"name": "SUSE",
"scada": false
}
}
},
{
"description": "SUSE Real Time Module 15-SP7",
"product": {
"name": "SUSE Real Time Module",
"vendor": {
"name": "SUSE",
"scada": false
}
}
},
{
"description": "SUSE Linux Micro Extras 6.0",
"product": {
"name": "SUSE Linux Micro Extras",
"vendor": {
"name": "SUSE",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2026-68116",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68116"
},
{
"name": "CVE-2025-71075",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-71075"
},
{
"name": "CVE-2026-64214",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64214"
},
{
"name": "CVE-2026-53091",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53091"
},
{
"name": "CVE-2026-64376",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64376"
},
{
"name": "CVE-2026-74395",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74395"
},
{
"name": "CVE-2026-68343",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68343"
},
{
"name": "CVE-2026-64552",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64552"
},
{
"name": "CVE-2026-64287",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64287"
},
{
"name": "CVE-2026-53381",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53381"
},
{
"name": "CVE-2026-64275",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64275"
},
{
"name": "CVE-2026-64274",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64274"
},
{
"name": "CVE-2026-64538",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64538"
},
{
"name": "CVE-2026-74394",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74394"
},
{
"name": "CVE-2026-68450",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68450"
},
{
"name": "CVE-2026-68480",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68480"
},
{
"name": "CVE-2026-68271",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68271"
},
{
"name": "CVE-2026-74297",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74297"
},
{
"name": "CVE-2026-64133",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64133"
},
{
"name": "CVE-2026-31658",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-31658"
},
{
"name": "CVE-2026-64047",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64047"
},
{
"name": "CVE-2026-74481",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74481"
},
{
"name": "CVE-2026-68138",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68138"
},
{
"name": "CVE-2026-64192",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64192"
},
{
"name": "CVE-2026-68193",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68193"
},
{
"name": "CVE-2026-68204",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68204"
},
{
"name": "CVE-2026-52925",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52925"
},
{
"name": "CVE-2026-74669",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74669"
},
{
"name": "CVE-2026-68302",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68302"
},
{
"name": "CVE-2026-64452",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64452"
},
{
"name": "CVE-2026-52929",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52929"
},
{
"name": "CVE-2026-68081",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68081"
},
{
"name": "CVE-2026-64483",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64483"
},
{
"name": "CVE-2026-63980",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63980"
},
{
"name": "CVE-2026-74482",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74482"
},
{
"name": "CVE-2026-64322",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64322"
},
{
"name": "CVE-2026-43448",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43448"
},
{
"name": "CVE-2026-64470",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64470"
},
{
"name": "CVE-2026-63923",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63923"
},
{
"name": "CVE-2026-68339",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68339"
},
{
"name": "CVE-2026-64513",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64513"
},
{
"name": "CVE-2026-68218",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68218"
},
{
"name": "CVE-2026-68088",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68088"
},
{
"name": "CVE-2026-64388",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64388"
},
{
"name": "CVE-2026-64512",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64512"
},
{
"name": "CVE-2026-64409",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64409"
},
{
"name": "CVE-2026-68129",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68129"
},
{
"name": "CVE-2026-74571",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74571"
},
{
"name": "CVE-2026-68245",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68245"
},
{
"name": "CVE-2026-64268",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64268"
},
{
"name": "CVE-2026-68428",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68428"
},
{
"name": "CVE-2026-64099",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64099"
},
{
"name": "CVE-2026-64489",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64489"
},
{
"name": "CVE-2026-74581",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74581"
},
{
"name": "CVE-2026-64480",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64480"
},
{
"name": "CVE-2026-72494",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72494"
},
{
"name": "CVE-2026-64257",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64257"
},
{
"name": "CVE-2026-64006",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64006"
},
{
"name": "CVE-2026-68313",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68313"
},
{
"name": "CVE-2026-64385",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64385"
},
{
"name": "CVE-2026-74537",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74537"
},
{
"name": "CVE-2026-63995",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63995"
},
{
"name": "CVE-2026-64217",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64217"
},
{
"name": "CVE-2026-46319",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46319"
},
{
"name": "CVE-2026-68326",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68326"
},
{
"name": "CVE-2026-68184",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68184"
},
{
"name": "CVE-2026-64454",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64454"
},
{
"name": "CVE-2026-64407",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64407"
},
{
"name": "CVE-2026-68417",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68417"
},
{
"name": "CVE-2026-64527",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64527"
},
{
"name": "CVE-2026-23227",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-23227"
},
{
"name": "CVE-2026-74563",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74563"
},
{
"name": "CVE-2026-23454",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-23454"
},
{
"name": "CVE-2026-68248",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68248"
},
{
"name": "CVE-2026-63886",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63886"
},
{
"name": "CVE-2026-64365",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64365"
},
{
"name": "CVE-2026-53260",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53260"
},
{
"name": "CVE-2026-64128",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64128"
},
{
"name": "CVE-2026-68277",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68277"
},
{
"name": "CVE-2026-68288",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68288"
},
{
"name": "CVE-2026-68410",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68410"
},
{
"name": "CVE-2026-68437",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68437"
},
{
"name": "CVE-2026-68261",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68261"
},
{
"name": "CVE-2026-74345",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74345"
},
{
"name": "CVE-2025-40204",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40204"
},
{
"name": "CVE-2026-72083",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72083"
},
{
"name": "CVE-2026-64333",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64333"
},
{
"name": "CVE-2026-68304",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68304"
},
{
"name": "CVE-2026-68155",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68155"
},
{
"name": "CVE-2026-63928",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63928"
},
{
"name": "CVE-2026-68132",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68132"
},
{
"name": "CVE-2026-64574",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64574"
},
{
"name": "CVE-2026-63879",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63879"
},
{
"name": "CVE-2026-68102",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68102"
},
{
"name": "CVE-2026-74488",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74488"
},
{
"name": "CVE-2026-68086",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68086"
},
{
"name": "CVE-2025-39939",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-39939"
},
{
"name": "CVE-2026-53220",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53220"
},
{
"name": "CVE-2026-64246",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64246"
},
{
"name": "CVE-2026-68085",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68085"
},
{
"name": "CVE-2026-68446",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68446"
},
{
"name": "CVE-2026-68408",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68408"
},
{
"name": "CVE-2026-64386",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64386"
},
{
"name": "CVE-2026-43163",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43163"
},
{
"name": "CVE-2026-68226",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68226"
},
{
"name": "CVE-2026-53365",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53365"
},
{
"name": "CVE-2026-68350",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68350"
},
{
"name": "CVE-2026-23210",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-23210"
},
{
"name": "CVE-2026-68419",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68419"
},
{
"name": "CVE-2026-68091",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68091"
},
{
"name": "CVE-2026-68297",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68297"
},
{
"name": "CVE-2026-53224",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53224"
},
{
"name": "CVE-2026-68199",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68199"
},
{
"name": "CVE-2026-64383",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64383"
},
{
"name": "CVE-2026-68425",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68425"
},
{
"name": "CVE-2026-64337",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64337"
},
{
"name": "CVE-2026-63888",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63888"
},
{
"name": "CVE-2026-52956",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52956"
},
{
"name": "CVE-2026-80534",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80534"
},
{
"name": "CVE-2026-72466",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72466"
},
{
"name": "CVE-2026-64178",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64178"
},
{
"name": "CVE-2026-64497",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64497"
},
{
"name": "CVE-2026-53163",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53163"
},
{
"name": "CVE-2026-46195",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46195"
},
{
"name": "CVE-2026-64599",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64599"
},
{
"name": "CVE-2026-68293",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68293"
},
{
"name": "CVE-2026-68365",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68365"
},
{
"name": "CVE-2026-72254",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72254"
},
{
"name": "CVE-2026-64598",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64598"
},
{
"name": "CVE-2026-68320",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68320"
},
{
"name": "CVE-2026-63810",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63810"
},
{
"name": "CVE-2026-31531",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-31531"
},
{
"name": "CVE-2026-64098",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64098"
},
{
"name": "CVE-2026-63801",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63801"
},
{
"name": "CVE-2026-63827",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63827"
},
{
"name": "CVE-2026-64304",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64304"
},
{
"name": "CVE-2026-43014",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43014"
},
{
"name": "CVE-2026-68280",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68280"
},
{
"name": "CVE-2026-68362",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68362"
},
{
"name": "CVE-2025-68179",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-68179"
},
{
"name": "CVE-2026-63842",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63842"
},
{
"name": "CVE-2026-68430",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68430"
},
{
"name": "CVE-2026-68427",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68427"
},
{
"name": "CVE-2026-43319",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43319"
},
{
"name": "CVE-2026-64146",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64146"
},
{
"name": "CVE-2026-72500",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72500"
},
{
"name": "CVE-2026-53309",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53309"
},
{
"name": "CVE-2026-68324",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68324"
},
{
"name": "CVE-2026-68308",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68308"
},
{
"name": "CVE-2026-64276",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64276"
},
{
"name": "CVE-2026-64190",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64190"
},
{
"name": "CVE-2026-68210",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68210"
},
{
"name": "CVE-2026-64237",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64237"
},
{
"name": "CVE-2026-64323",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64323"
},
{
"name": "CVE-2026-68267",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68267"
},
{
"name": "CVE-2026-68309",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68309"
},
{
"name": "CVE-2026-68403",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68403"
},
{
"name": "CVE-2026-68139",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68139"
},
{
"name": "CVE-2026-64271",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64271"
},
{
"name": "CVE-2026-74566",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74566"
},
{
"name": "CVE-2026-52939",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52939"
},
{
"name": "CVE-2026-63925",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63925"
},
{
"name": "CVE-2026-68093",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68093"
},
{
"name": "CVE-2026-72262",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72262"
},
{
"name": "CVE-2026-68166",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68166"
},
{
"name": "CVE-2026-63990",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63990"
},
{
"name": "CVE-2026-64455",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64455"
},
{
"name": "CVE-2026-72467",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72467"
},
{
"name": "CVE-2026-64421",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64421"
},
{
"name": "CVE-2026-64584",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64584"
},
{
"name": "CVE-2026-64445",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64445"
},
{
"name": "CVE-2026-52935",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52935"
},
{
"name": "CVE-2026-68310",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68310"
},
{
"name": "CVE-2026-64433",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64433"
},
{
"name": "CVE-2026-68115",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68115"
},
{
"name": "CVE-2026-68133",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68133"
},
{
"name": "CVE-2026-68246",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68246"
},
{
"name": "CVE-2026-64563",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64563"
},
{
"name": "CVE-2026-68405",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68405"
},
{
"name": "CVE-2026-68219",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68219"
},
{
"name": "CVE-2026-68216",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68216"
},
{
"name": "CVE-2026-64500",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64500"
},
{
"name": "CVE-2026-53094",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53094"
},
{
"name": "CVE-2026-64097",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64097"
},
{
"name": "CVE-2026-68328",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68328"
},
{
"name": "CVE-2026-68394",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68394"
},
{
"name": "CVE-2026-53330",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53330"
},
{
"name": "CVE-2025-23137",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-23137"
},
{
"name": "CVE-2026-64348",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64348"
},
{
"name": "CVE-2026-68196",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68196"
},
{
"name": "CVE-2026-64362",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64362"
},
{
"name": "CVE-2026-72464",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72464"
},
{
"name": "CVE-2026-68269",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68269"
},
{
"name": "CVE-2026-68255",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68255"
},
{
"name": "CVE-2026-64102",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64102"
},
{
"name": "CVE-2026-68363",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68363"
},
{
"name": "CVE-2026-46091",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46091"
},
{
"name": "CVE-2026-68213",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68213"
},
{
"name": "CVE-2026-68278",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68278"
},
{
"name": "CVE-2026-64486",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64486"
},
{
"name": "CVE-2026-68145",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68145"
},
{
"name": "CVE-2026-64517",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64517"
},
{
"name": "CVE-2026-74454",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74454"
},
{
"name": "CVE-2026-64341",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64341"
},
{
"name": "CVE-2026-72342",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72342"
},
{
"name": "CVE-2026-64338",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64338"
},
{
"name": "CVE-2026-68361",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68361"
},
{
"name": "CVE-2026-64083",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64083"
},
{
"name": "CVE-2026-68181",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68181"
},
{
"name": "CVE-2026-46037",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46037"
},
{
"name": "CVE-2026-64249",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64249"
},
{
"name": "CVE-2026-72222",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72222"
},
{
"name": "CVE-2026-64536",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64536"
},
{
"name": "CVE-2026-43213",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43213"
},
{
"name": "CVE-2026-64570",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64570"
},
{
"name": "CVE-2026-63850",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63850"
},
{
"name": "CVE-2026-31663",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-31663"
},
{
"name": "CVE-2026-68113",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68113"
},
{
"name": "CVE-2026-68286",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68286"
},
{
"name": "CVE-2026-64010",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64010"
},
{
"name": "CVE-2026-64243",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64243"
},
{
"name": "CVE-2026-52975",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52975"
},
{
"name": "CVE-2026-68160",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68160"
},
{
"name": "CVE-2026-46127",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46127"
},
{
"name": "CVE-2026-64553",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64553"
},
{
"name": "CVE-2026-68157",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68157"
},
{
"name": "CVE-2026-64351",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64351"
},
{
"name": "CVE-2026-64051",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64051"
},
{
"name": "CVE-2026-23230",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-23230"
},
{
"name": "CVE-2026-64039",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64039"
},
{
"name": "CVE-2026-68368",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68368"
},
{
"name": "CVE-2026-68281",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68281"
},
{
"name": "CVE-2026-74474",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74474"
},
{
"name": "CVE-2026-68335",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68335"
},
{
"name": "CVE-2026-53353",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53353"
},
{
"name": "CVE-2026-68426",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68426"
},
{
"name": "CVE-2026-68329",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68329"
},
{
"name": "CVE-2026-68189",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68189"
},
{
"name": "CVE-2026-64375",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64375"
},
{
"name": "CVE-2026-64296",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64296"
},
{
"name": "CVE-2026-72307",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72307"
},
{
"name": "CVE-2026-64546",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64546"
},
{
"name": "CVE-2026-63926",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63926"
},
{
"name": "CVE-2026-68212",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68212"
},
{
"name": "CVE-2026-53110",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53110"
},
{
"name": "CVE-2026-64593",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64593"
},
{
"name": "CVE-2026-23240",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-23240"
},
{
"name": "CVE-2026-64568",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64568"
},
{
"name": "CVE-2026-63865",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63865"
},
{
"name": "CVE-2026-64052",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64052"
},
{
"name": "CVE-2026-68389",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68389"
},
{
"name": "CVE-2026-64603",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64603"
},
{
"name": "CVE-2026-53219",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53219"
},
{
"name": "CVE-2026-68215",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68215"
},
{
"name": "CVE-2026-64109",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64109"
},
{
"name": "CVE-2026-64085",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64085"
},
{
"name": "CVE-2026-64166",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64166"
},
{
"name": "CVE-2026-31418",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-31418"
},
{
"name": "CVE-2026-64504",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64504"
},
{
"name": "CVE-2026-68369",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68369"
},
{
"name": "CVE-2026-63898",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63898"
},
{
"name": "CVE-2026-64148",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64148"
},
{
"name": "CVE-2026-72495",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72495"
},
{
"name": "CVE-2026-64004",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64004"
},
{
"name": "CVE-2026-31392",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-31392"
},
{
"name": "CVE-2026-63992",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63992"
},
{
"name": "CVE-2026-64155",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64155"
},
{
"name": "CVE-2026-72084",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72084"
},
{
"name": "CVE-2026-68340",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68340"
},
{
"name": "CVE-2026-72317",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72317"
},
{
"name": "CVE-2026-68352",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68352"
},
{
"name": "CVE-2026-68106",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68106"
},
{
"name": "CVE-2026-46242",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46242"
},
{
"name": "CVE-2026-63996",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63996"
},
{
"name": "CVE-2026-68197",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68197"
},
{
"name": "CVE-2026-64343",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64343"
},
{
"name": "CVE-2026-64021",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64021"
},
{
"name": "CVE-2026-68315",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68315"
},
{
"name": "CVE-2026-68346",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68346"
},
{
"name": "CVE-2026-68377",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68377"
},
{
"name": "CVE-2026-68413",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68413"
},
{
"name": "CVE-2026-68372",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68372"
},
{
"name": "CVE-2026-64471",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64471"
},
{
"name": "CVE-2026-64180",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64180"
},
{
"name": "CVE-2026-68357",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68357"
},
{
"name": "CVE-2026-53034",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53034"
},
{
"name": "CVE-2024-57841",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-57841"
},
{
"name": "CVE-2026-74318",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74318"
},
{
"name": "CVE-2026-68399",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68399"
},
{
"name": "CVE-2026-64539",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64539"
},
{
"name": "CVE-2026-64602",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64602"
},
{
"name": "CVE-2026-64583",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64583"
},
{
"name": "CVE-2026-64125",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64125"
},
{
"name": "CVE-2026-68418",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68418"
},
{
"name": "CVE-2026-64551",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64551"
},
{
"name": "CVE-2026-53111",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53111"
},
{
"name": "CVE-2026-68312",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68312"
},
{
"name": "CVE-2026-80529",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80529"
},
{
"name": "CVE-2026-68262",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68262"
},
{
"name": "CVE-2026-68194",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68194"
},
{
"name": "CVE-2026-64131",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64131"
},
{
"name": "CVE-2026-64048",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64048"
},
{
"name": "CVE-2026-31759",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-31759"
},
{
"name": "CVE-2026-68127",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68127"
},
{
"name": "CVE-2026-72341",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72341"
},
{
"name": "CVE-2026-68112",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68112"
},
{
"name": "CVE-2026-64306",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64306"
},
{
"name": "CVE-2026-64313",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64313"
},
{
"name": "CVE-2026-52994",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52994"
},
{
"name": "CVE-2026-64112",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64112"
},
{
"name": "CVE-2026-64442",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64442"
},
{
"name": "CVE-2026-64554",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64554"
},
{
"name": "CVE-2026-64477",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64477"
},
{
"name": "CVE-2026-64463",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64463"
},
{
"name": "CVE-2026-64401",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64401"
},
{
"name": "CVE-2026-68159",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68159"
},
{
"name": "CVE-2026-74694",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74694"
},
{
"name": "CVE-2026-64018",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64018"
},
{
"name": "CVE-2026-64541",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64541"
},
{
"name": "CVE-2026-64332",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64332"
},
{
"name": "CVE-2026-63920",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63920"
},
{
"name": "CVE-2026-68202",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68202"
},
{
"name": "CVE-2026-72389",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72389"
},
{
"name": "CVE-2026-72498",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72498"
},
{
"name": "CVE-2026-53096",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53096"
},
{
"name": "CVE-2026-72499",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72499"
},
{
"name": "CVE-2026-43077",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43077"
},
{
"name": "CVE-2026-64127",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64127"
},
{
"name": "CVE-2026-68104",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68104"
},
{
"name": "CVE-2026-64378",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64378"
},
{
"name": "CVE-2026-53076",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53076"
},
{
"name": "CVE-2026-64549",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64549"
},
{
"name": "CVE-2026-68137",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68137"
},
{
"name": "CVE-2026-68143",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68143"
},
{
"name": "CVE-2026-53182",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53182"
},
{
"name": "CVE-2026-64055",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64055"
},
{
"name": "CVE-2026-46070",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46070"
},
{
"name": "CVE-2026-53207",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53207"
},
{
"name": "CVE-2026-68349",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68349"
},
{
"name": "CVE-2026-64244",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64244"
},
{
"name": "CVE-2025-40199",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40199"
},
{
"name": "CVE-2026-74496",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74496"
},
{
"name": "CVE-2026-68257",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68257"
},
{
"name": "CVE-2026-53126",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53126"
},
{
"name": "CVE-2026-68252",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68252"
},
{
"name": "CVE-2026-63970",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63970"
},
{
"name": "CVE-2026-72502",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72502"
},
{
"name": "CVE-2026-68351",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68351"
},
{
"name": "CVE-2026-68289",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68289"
},
{
"name": "CVE-2026-43271",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43271"
},
{
"name": "CVE-2026-68402",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68402"
},
{
"name": "CVE-2026-72463",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72463"
},
{
"name": "CVE-2026-64224",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64224"
},
{
"name": "CVE-2026-68117",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68117"
},
{
"name": "CVE-2026-64559",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64559"
},
{
"name": "CVE-2026-68333",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68333"
},
{
"name": "CVE-2026-64544",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64544"
},
{
"name": "CVE-2026-68386",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68386"
},
{
"name": "CVE-2025-71104",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-71104"
},
{
"name": "CVE-2026-68111",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68111"
},
{
"name": "CVE-2026-64577",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64577"
},
{
"name": "CVE-2026-64115",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64115"
},
{
"name": "CVE-2026-52946",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52946"
},
{
"name": "CVE-2026-53059",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53059"
},
{
"name": "CVE-2026-72308",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72308"
},
{
"name": "CVE-2026-53133",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53133"
},
{
"name": "CVE-2026-74334",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74334"
},
{
"name": "CVE-2026-68142",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68142"
},
{
"name": "CVE-2026-64427",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64427"
},
{
"name": "CVE-2026-68243",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68243"
},
{
"name": "CVE-2026-64164",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64164"
},
{
"name": "CVE-2026-64346",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64346"
},
{
"name": "CVE-2026-68209",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68209"
},
{
"name": "CVE-2026-68306",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68306"
},
{
"name": "CVE-2026-53263",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53263"
},
{
"name": "CVE-2026-63891",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63891"
},
{
"name": "CVE-2026-68207",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68207"
},
{
"name": "CVE-2026-64342",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64342"
},
{
"name": "CVE-2026-68373",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68373"
},
{
"name": "CVE-2026-63985",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63985"
},
{
"name": "CVE-2026-64478",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64478"
},
{
"name": "CVE-2026-68206",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68206"
},
{
"name": "CVE-2026-68110",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68110"
},
{
"name": "CVE-2026-74577",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74577"
},
{
"name": "CVE-2026-64472",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64472"
},
{
"name": "CVE-2026-74516",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74516"
},
{
"name": "CVE-2026-64581",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64581"
},
{
"name": "CVE-2026-64585",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64585"
},
{
"name": "CVE-2026-72132",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72132"
},
{
"name": "CVE-2026-64335",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64335"
},
{
"name": "CVE-2026-68391",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68391"
},
{
"name": "CVE-2026-53228",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53228"
},
{
"name": "CVE-2026-64315",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64315"
},
{
"name": "CVE-2026-68227",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68227"
},
{
"name": "CVE-2026-68348",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68348"
},
{
"name": "CVE-2026-64273",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64273"
},
{
"name": "CVE-2026-63828",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63828"
},
{
"name": "CVE-2026-68331",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68331"
},
{
"name": "CVE-2026-74567",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74567"
},
{
"name": "CVE-2026-68238",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68238"
},
{
"name": "CVE-2026-53336",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53336"
},
{
"name": "CVE-2026-74582",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74582"
},
{
"name": "CVE-2026-68432",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68432"
},
{
"name": "CVE-2026-64084",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64084"
},
{
"name": "CVE-2026-64014",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64014"
},
{
"name": "CVE-2026-74548",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74548"
},
{
"name": "CVE-2026-64001",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64001"
},
{
"name": "CVE-2026-64545",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64545"
},
{
"name": "CVE-2026-74518",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74518"
},
{
"name": "CVE-2026-53388",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53388"
},
{
"name": "CVE-2026-63937",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63937"
},
{
"name": "CVE-2026-45897",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-45897"
},
{
"name": "CVE-2026-64305",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64305"
},
{
"name": "CVE-2026-80590",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80590"
},
{
"name": "CVE-2026-43015",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43015"
},
{
"name": "CVE-2026-68398",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68398"
},
{
"name": "CVE-2026-68322",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68322"
},
{
"name": "CVE-2026-64381",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64381"
},
{
"name": "CVE-2026-64604",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64604"
},
{
"name": "CVE-2026-53337",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53337"
},
{
"name": "CVE-2026-68429",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68429"
},
{
"name": "CVE-2026-64597",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64597"
},
{
"name": "CVE-2026-63887",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63887"
},
{
"name": "CVE-2026-68136",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68136"
},
{
"name": "CVE-2026-64496",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64496"
},
{
"name": "CVE-2025-39964",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-39964"
},
{
"name": "CVE-2026-64113",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64113"
},
{
"name": "CVE-2026-64387",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64387"
},
{
"name": "CVE-2026-68263",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68263"
},
{
"name": "CVE-2026-68299",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68299"
},
{
"name": "CVE-2026-63972",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63972"
},
{
"name": "CVE-2026-68082",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68082"
},
{
"name": "CVE-2026-68366",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68366"
},
{
"name": "CVE-2026-46274",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46274"
},
{
"name": "CVE-2026-64408",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64408"
},
{
"name": "CVE-2026-68156",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68156"
},
{
"name": "CVE-2026-74695",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74695"
},
{
"name": "CVE-2026-64136",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64136"
},
{
"name": "CVE-2026-68121",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68121"
},
{
"name": "CVE-2026-68231",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68231"
},
{
"name": "CVE-2026-68182",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68182"
},
{
"name": "CVE-2026-74717",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74717"
},
{
"name": "CVE-2026-64481",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64481"
},
{
"name": "CVE-2026-64316",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64316"
},
{
"name": "CVE-2026-72036",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72036"
},
{
"name": "CVE-2026-68422",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68422"
},
{
"name": "CVE-2026-64000",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64000"
},
{
"name": "CVE-2026-68327",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68327"
},
{
"name": "CVE-2026-64582",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64582"
},
{
"name": "CVE-2026-53223",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53223"
},
{
"name": "CVE-2026-64423",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64423"
},
{
"name": "CVE-2026-64034",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64034"
},
{
"name": "CVE-2026-74610",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74610"
},
{
"name": "CVE-2026-64443",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64443"
},
{
"name": "CVE-2026-68433",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68433"
},
{
"name": "CVE-2026-68195",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68195"
},
{
"name": "CVE-2026-31557",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-31557"
},
{
"name": "CVE-2026-63868",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63868"
},
{
"name": "CVE-2026-72123",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72123"
},
{
"name": "CVE-2026-64269",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64269"
},
{
"name": "CVE-2026-45968",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-45968"
},
{
"name": "CVE-2026-64540",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64540"
},
{
"name": "CVE-2026-72296",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72296"
},
{
"name": "CVE-2024-44981",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-44981"
},
{
"name": "CVE-2026-64482",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64482"
},
{
"name": "CVE-2026-64218",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64218"
},
{
"name": "CVE-2026-64495",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64495"
},
{
"name": "CVE-2026-72072",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72072"
},
{
"name": "CVE-2026-68279",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68279"
},
{
"name": "CVE-2026-68205",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68205"
},
{
"name": "CVE-2026-68234",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68234"
},
{
"name": "CVE-2026-52920",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52920"
},
{
"name": "CVE-2026-53001",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53001"
},
{
"name": "CVE-2026-43206",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43206"
},
{
"name": "CVE-2026-43273",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43273"
},
{
"name": "CVE-2026-74510",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74510"
},
{
"name": "CVE-2026-68256",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68256"
},
{
"name": "CVE-2026-68303",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68303"
},
{
"name": "CVE-2026-53269",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53269"
},
{
"name": "CVE-2026-68445",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68445"
},
{
"name": "CVE-2026-64479",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64479"
},
{
"name": "CVE-2026-74512",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74512"
},
{
"name": "CVE-2026-64329",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64329"
},
{
"name": "CVE-2026-64434",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64434"
},
{
"name": "CVE-2026-46115",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46115"
},
{
"name": "CVE-2026-63997",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63997"
},
{
"name": "CVE-2026-64219",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64219"
},
{
"name": "CVE-2026-64277",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64277"
},
{
"name": "CVE-2026-64126",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64126"
},
{
"name": "CVE-2026-64503",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64503"
},
{
"name": "CVE-2026-64562",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64562"
},
{
"name": "CVE-2026-68434",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68434"
},
{
"name": "CVE-2026-64168",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64168"
},
{
"name": "CVE-2026-68105",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68105"
},
{
"name": "CVE-2026-68444",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68444"
},
{
"name": "CVE-2026-72035",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72035"
},
{
"name": "CVE-2025-68214",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-68214"
},
{
"name": "CVE-2026-68153",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68153"
},
{
"name": "CVE-2026-64558",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64558"
},
{
"name": "CVE-2026-63881",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63881"
},
{
"name": "CVE-2026-64571",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64571"
},
{
"name": "CVE-2026-72496",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72496"
},
{
"name": "CVE-2026-63969",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63969"
},
{
"name": "CVE-2026-53089",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53089"
},
{
"name": "CVE-2026-68188",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68188"
},
{
"name": "CVE-2026-68161",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68161"
},
{
"name": "CVE-2026-64436",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64436"
},
{
"name": "CVE-2026-64403",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64403"
},
{
"name": "CVE-2026-64222",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64222"
},
{
"name": "CVE-2026-64121",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64121"
},
{
"name": "CVE-2026-68259",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68259"
},
{
"name": "CVE-2026-68235",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68235"
},
{
"name": "CVE-2026-68223",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68223"
},
{
"name": "CVE-2026-64412",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64412"
},
{
"name": "CVE-2026-74556",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74556"
},
{
"name": "CVE-2026-64188",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64188"
},
{
"name": "CVE-2026-64144",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64144"
},
{
"name": "CVE-2026-64487",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64487"
},
{
"name": "CVE-2026-64303",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64303"
},
{
"name": "CVE-2026-74296",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74296"
},
{
"name": "CVE-2026-64086",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64086"
},
{
"name": "CVE-2026-68414",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68414"
},
{
"name": "CVE-2026-64429",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64429"
},
{
"name": "CVE-2026-64344",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64344"
},
{
"name": "CVE-2026-64286",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64286"
},
{
"name": "CVE-2026-68214",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68214"
},
{
"name": "CVE-2026-64029",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64029"
},
{
"name": "CVE-2026-68217",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68217"
},
{
"name": "CVE-2026-68222",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68222"
},
{
"name": "CVE-2026-74692",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74692"
},
{
"name": "CVE-2026-68124",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68124"
},
{
"name": "CVE-2026-53077",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53077"
},
{
"name": "CVE-2026-64350",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64350"
},
{
"name": "CVE-2026-68250",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68250"
},
{
"name": "CVE-2026-72473",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72473"
},
{
"name": "CVE-2026-43110",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43110"
},
{
"name": "CVE-2026-68397",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68397"
},
{
"name": "CVE-2026-64572",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64572"
},
{
"name": "CVE-2026-64411",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64411"
},
{
"name": "CVE-2026-68126",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68126"
},
{
"name": "CVE-2026-74321",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74321"
},
{
"name": "CVE-2026-63998",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63998"
},
{
"name": "CVE-2026-64137",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64137"
},
{
"name": "CVE-2026-23449",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-23449"
},
{
"name": "CVE-2026-43386",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43386"
},
{
"name": "CVE-2026-64537",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64537"
},
{
"name": "CVE-2026-64334",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64334"
},
{
"name": "CVE-2026-74495",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74495"
},
{
"name": "CVE-2026-64448",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64448"
},
{
"name": "CVE-2026-72497",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72497"
},
{
"name": "CVE-2026-68125",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68125"
},
{
"name": "CVE-2026-68135",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68135"
},
{
"name": "CVE-2026-53033",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53033"
},
{
"name": "CVE-2026-72032",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72032"
},
{
"name": "CVE-2026-72221",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72221"
},
{
"name": "CVE-2026-72289",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72289"
},
{
"name": "CVE-2026-72251",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72251"
},
{
"name": "CVE-2026-64134",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64134"
},
{
"name": "CVE-2026-68254",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68254"
},
{
"name": "CVE-2026-64005",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64005"
},
{
"name": "CVE-2026-68360",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68360"
},
{
"name": "CVE-2026-46107",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46107"
},
{
"name": "CVE-2026-64524",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64524"
},
{
"name": "CVE-2026-80654",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80654"
},
{
"name": "CVE-2025-38469",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-38469"
},
{
"name": "CVE-2026-68244",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68244"
},
{
"name": "CVE-2026-64382",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64382"
},
{
"name": "CVE-2026-68249",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68249"
},
{
"name": "CVE-2026-68107",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68107"
},
{
"name": "CVE-2026-68392",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68392"
},
{
"name": "CVE-2026-68300",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68300"
},
{
"name": "CVE-2026-64444",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64444"
},
{
"name": "CVE-2026-68260",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68260"
},
{
"name": "CVE-2026-68229",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68229"
},
{
"name": "CVE-2026-64225",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64225"
},
{
"name": "CVE-2026-64331",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64331"
},
{
"name": "CVE-2026-64511",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64511"
},
{
"name": "CVE-2026-68284",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68284"
},
{
"name": "CVE-2026-53264",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53264"
},
{
"name": "CVE-2026-63999",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63999"
},
{
"name": "CVE-2026-43109",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43109"
},
{
"name": "CVE-2026-53142",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53142"
},
{
"name": "CVE-2026-68152",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68152"
},
{
"name": "CVE-2026-68353",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68353"
},
{
"name": "CVE-2026-63944",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63944"
},
{
"name": "CVE-2026-53273",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53273"
},
{
"name": "CVE-2026-64547",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64547"
},
{
"name": "CVE-2026-64056",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64056"
},
{
"name": "CVE-2026-63860",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63860"
},
{
"name": "CVE-2026-64494",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64494"
},
{
"name": "CVE-2026-68108",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68108"
},
{
"name": "CVE-2026-64033",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64033"
},
{
"name": "CVE-2026-64565",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64565"
},
{
"name": "CVE-2026-68158",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68158"
},
{
"name": "CVE-2026-64543",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64543"
},
{
"name": "CVE-2026-64573",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64573"
},
{
"name": "CVE-2026-53246",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53246"
},
{
"name": "CVE-2026-64245",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64245"
},
{
"name": "CVE-2026-43278",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43278"
},
{
"name": "CVE-2026-63823",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63823"
},
{
"name": "CVE-2026-68325",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68325"
},
{
"name": "CVE-2026-68253",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68253"
},
{
"name": "CVE-2026-72501",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72501"
},
{
"name": "CVE-2026-68355",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68355"
},
{
"name": "CVE-2026-64530",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64530"
},
{
"name": "CVE-2026-64015",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64015"
},
{
"name": "CVE-2026-64294",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64294"
},
{
"name": "CVE-2026-43125",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43125"
},
{
"name": "CVE-2026-68470",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68470"
},
{
"name": "CVE-2026-63808",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63808"
},
{
"name": "CVE-2026-72343",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72343"
},
{
"name": "CVE-2026-63973",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63973"
},
{
"name": "CVE-2026-68180",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68180"
},
{
"name": "CVE-2026-68247",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68247"
},
{
"name": "CVE-2026-74722",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74722"
},
{
"name": "CVE-2026-68407",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68407"
},
{
"name": "CVE-2026-64247",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64247"
},
{
"name": "CVE-2026-68123",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68123"
},
{
"name": "CVE-2026-64420",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64420"
},
{
"name": "CVE-2026-53180",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53180"
},
{
"name": "CVE-2026-53238",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53238"
},
{
"name": "CVE-2026-43416",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43416"
},
{
"name": "CVE-2026-64548",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64548"
},
{
"name": "CVE-2026-64118",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64118"
},
{
"name": "CVE-2026-68162",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68162"
},
{
"name": "CVE-2026-68220",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68220"
},
{
"name": "CVE-2026-64384",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64384"
},
{
"name": "CVE-2026-64406",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64406"
},
{
"name": "CVE-2026-68354",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68354"
},
{
"name": "CVE-2026-64600",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64600"
},
{
"name": "CVE-2026-68149",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68149"
},
{
"name": "CVE-2026-64312",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64312"
},
{
"name": "CVE-2026-72469",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72469"
},
{
"name": "CVE-2026-63889",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63889"
},
{
"name": "CVE-2026-68375",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68375"
},
{
"name": "CVE-2026-64505",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64505"
},
{
"name": "CVE-2026-53366",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53366"
},
{
"name": "CVE-2026-52923",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52923"
},
{
"name": "CVE-2026-64087",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64087"
},
{
"name": "CVE-2026-68251",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68251"
},
{
"name": "CVE-2026-74584",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74584"
},
{
"name": "CVE-2026-53154",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53154"
},
{
"name": "CVE-2026-64358",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64358"
},
{
"name": "CVE-2026-64355",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64355"
},
{
"name": "CVE-2026-64515",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64515"
},
{
"name": "CVE-2026-72069",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72069"
},
{
"name": "CVE-2026-68359",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68359"
},
{
"name": "CVE-2026-64185",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64185"
},
{
"name": "CVE-2026-72020",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72020"
},
{
"name": "CVE-2026-68370",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68370"
},
{
"name": "CVE-2026-43116",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43116"
},
{
"name": "CVE-2026-64340",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64340"
},
{
"name": "CVE-2026-64007",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64007"
},
{
"name": "CVE-2026-64567",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64567"
},
{
"name": "CVE-2026-64450",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64450"
},
{
"name": "CVE-2026-64484",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64484"
},
{
"name": "CVE-2026-52990",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52990"
},
{
"name": "CVE-2026-64114",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64114"
},
{
"name": "CVE-2026-64266",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64266"
},
{
"name": "CVE-2025-40022",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40022"
},
{
"name": "CVE-2026-43363",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43363"
},
{
"name": "CVE-2026-68236",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68236"
},
{
"name": "CVE-2026-64088",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64088"
},
{
"name": "CVE-2026-64073",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64073"
},
{
"name": "CVE-2026-64576",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64576"
},
{
"name": "CVE-2026-68192",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68192"
},
{
"name": "CVE-2026-74712",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74712"
},
{
"name": "CVE-2026-74550",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74550"
},
{
"name": "CVE-2026-74269",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74269"
},
{
"name": "CVE-2026-74509",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74509"
},
{
"name": "CVE-2026-64002",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64002"
},
{
"name": "CVE-2026-72288",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72288"
},
{
"name": "CVE-2026-68272",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68272"
},
{
"name": "CVE-2026-64135",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64135"
},
{
"name": "CVE-2026-64440",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64440"
},
{
"name": "CVE-2026-52977",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52977"
},
{
"name": "CVE-2026-52972",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-52972"
},
{
"name": "CVE-2026-74527",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74527"
},
{
"name": "CVE-2026-72046",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72046"
},
{
"name": "CVE-2026-68406",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68406"
},
{
"name": "CVE-2026-31629",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-31629"
},
{
"name": "CVE-2026-64011",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64011"
},
{
"name": "CVE-2026-64317",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64317"
},
{
"name": "CVE-2026-68336",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68336"
},
{
"name": "CVE-2026-64569",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64569"
},
{
"name": "CVE-2026-46078",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46078"
},
{
"name": "CVE-2026-68154",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68154"
}
],
"initial_release_date": "2026-09-11T00:00:00",
"last_revision_date": "2026-09-11T00:00:00",
"links": [],
"reference": "CERTFR-2026-AVI-1164",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2026-09-11T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
},
{
"description": "Ex\u00e9cution de code arbitraire"
},
{
"description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
},
{
"description": "Contournement de la politique de s\u00e9curit\u00e9"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans le noyau Linux de SUSE. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans le noyau Linux de SUSE",
"vendor_advisories": [
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23490-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623490-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23485-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623485-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23479-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623479-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23486-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623486-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23477-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623477-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23484-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623484-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23487-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623487-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23488-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623488-1"
},
{
"published_at": "2026-09-10",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:4120-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264120-1"
},
{
"published_at": "2026-08-31",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23439-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623439-1"
},
{
"published_at": "2026-08-31",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23440-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623440-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23482-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623482-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23481-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623481-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23483-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623483-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23489-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623489-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23491-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623491-1"
},
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2026:23480-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-202623480-1"
}
]
}
CVE-2026-64051 (GCVE-0-2026-64051)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
accel/qaic: Add overflow check to remap_pfn_range during mmap
The call to remap_pfn_range in qaic_gem_object_mmap is susceptible to
(re)mapping beyond the VMA if the BO is too large. This can cause use
after free issues when munmap() unmaps only the VMA region and not the
additional mappings. To prevent this, check the remaining size of the
VMA before remapping and truncate the remapped length if sg->length is
too large.
[jhugo: fix braces from checkpatch --strict]
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/accel/qaic/qaic_data.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9baafc2fea096279e75480f93fd5942e8336b510",
"status": "affected",
"version": "ff13be8303336ead5621712f2c55012d738878b5",
"versionType": "git"
},
{
"lessThan": "8dd6edbe26770df147136c3f2ac976c873b82650",
"status": "affected",
"version": "ff13be8303336ead5621712f2c55012d738878b5",
"versionType": "git"
},
{
"lessThan": "97a8e89cdef36207a8776edc03d6931763a06ad0",
"status": "affected",
"version": "ff13be8303336ead5621712f2c55012d738878b5",
"versionType": "git"
},
{
"lessThan": "8c795012d0e06b7740e40319b86ff8d2a435098d",
"status": "affected",
"version": "ff13be8303336ead5621712f2c55012d738878b5",
"versionType": "git"
},
{
"lessThan": "aa16b2bc0f02709919e2435f531406531e5bcc69",
"status": "affected",
"version": "ff13be8303336ead5621712f2c55012d738878b5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/accel/qaic/qaic_data.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\naccel/qaic: Add overflow check to remap_pfn_range during mmap\n\nThe call to remap_pfn_range in qaic_gem_object_mmap is susceptible to\n(re)mapping beyond the VMA if the BO is too large. This can cause use\nafter free issues when munmap() unmaps only the VMA region and not the\nadditional mappings. To prevent this, check the remaining size of the\nVMA before remapping and truncate the remapped length if sg-\u003elength is\ntoo large.\n\n[jhugo: fix braces from checkpatch --strict]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access via the QAIC accel device node (/dev/accel/accel*) through DRM ioctls and mmap syscalls; there is no network-facing attack surface.\nAC:L - An attacker fully controls BO allocation size, partial mmap length, and munmap timing, deterministically mapping PFNs beyond the VMA without races or external conditions.\nPR:L - No DRM master or root is required; any unprivileged local user with access to the accel device node (common on shared cloud AI inference hosts) can create a BO, partial-mmap it, and trigger the bug.\nUI:N - Exploitation requires only attacker-initiated ioctl and mmap operations on an open accel file descriptor, with no victim interaction.\nS:U - The UAF corrupts kernel page-table mappings within the same kernel security domain; it does not cross VM, container, or IOMMU boundaries.\nC:H - The commit explicitly identifies a use-after-free of page structures left mapped past the VMA; UAF of kernel mappings enables arbitrary kernel memory read primitives.\nI:H - UAF on kernel page structures can be leveraged for arbitrary kernel memory writes and local privilege escalation through heap grooming and control of freed pages.\nA:H - Accessing stale PFN mappings after BO teardown causes kernel oops/panic; UAF reliably threatens system availability even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:42.519Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9baafc2fea096279e75480f93fd5942e8336b510"
},
{
"url": "https://git.kernel.org/stable/c/8dd6edbe26770df147136c3f2ac976c873b82650"
},
{
"url": "https://git.kernel.org/stable/c/97a8e89cdef36207a8776edc03d6931763a06ad0"
},
{
"url": "https://git.kernel.org/stable/c/8c795012d0e06b7740e40319b86ff8d2a435098d"
},
{
"url": "https://git.kernel.org/stable/c/aa16b2bc0f02709919e2435f531406531e5bcc69"
}
],
"title": "accel/qaic: Add overflow check to remap_pfn_range during mmap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64051",
"datePublished": "2026-07-19T15:39:34.608Z",
"dateReserved": "2026-07-19T07:54:57.029Z",
"dateUpdated": "2026-08-05T12:38:42.519Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68254 (GCVE-0-2026-68254)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/vrr: require valid min/max vfreq for VRR
Ensure the EDID provided min/max vfreq are valid. Most scenarios are
already covered (by coincidence) through the checks in
intel_vrr_is_capable() and intel_vrr_is_in_range(), but be more explicit
about it. At worst, a zero min_vfreq could lead to a division by zero in
intel_vrr_compute_vmax().
Discovered using AI-assisted static analysis confirmed by Intel Product
Security.
(cherry picked from commit 1765cf59f517b02f3b0591fe5120930d08bddeb6)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_vrr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2f9aa8d42b7fc17621894456433ac07689fb4a21",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "5225122b9cad6b0c61e767fb2adea8c07da925be",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "6598ac1721c3a5543efdbcab579a8561268d7ce1",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "f16218689b41efcbc491207cd7716477b1223879",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "df1582c0a101e2e2f133dd331d2a3258bb6a7518",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "c726c8bbee5115dad37fa7867136ebaa50690331",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "f8a9262c7a6fc2de9802e14b0228114f0333869e",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_vrr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/vrr: require valid min/max vfreq for VRR\n\nEnsure the EDID provided min/max vfreq are valid. Most scenarios are\nalready covered (by coincidence) through the checks in\nintel_vrr_is_capable() and intel_vrr_is_in_range(), but be more explicit\nabout it. At worst, a zero min_vfreq could lead to a division by zero in\nintel_vrr_compute_vmax().\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\n(cherry picked from commit 1765cf59f517b02f3b0591fe5120930d08bddeb6)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:12.167Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2f9aa8d42b7fc17621894456433ac07689fb4a21"
},
{
"url": "https://git.kernel.org/stable/c/5225122b9cad6b0c61e767fb2adea8c07da925be"
},
{
"url": "https://git.kernel.org/stable/c/6598ac1721c3a5543efdbcab579a8561268d7ce1"
},
{
"url": "https://git.kernel.org/stable/c/f16218689b41efcbc491207cd7716477b1223879"
},
{
"url": "https://git.kernel.org/stable/c/df1582c0a101e2e2f133dd331d2a3258bb6a7518"
},
{
"url": "https://git.kernel.org/stable/c/c726c8bbee5115dad37fa7867136ebaa50690331"
},
{
"url": "https://git.kernel.org/stable/c/f8a9262c7a6fc2de9802e14b0228114f0333869e"
}
],
"title": "drm/i915/vrr: require valid min/max vfreq for VRR",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68254",
"datePublished": "2026-08-10T12:01:20.400Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-23T12:46:12.167Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63860 (GCVE-0-2026-63860)
Vulnerability from cvelistv5
Published
2026-07-19 14:04
Modified
2026-08-05 12:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: Prefer NLA_NUL_STRING
These attributes are evaluated as c-string (passed to strcmp), but
NLA_STRING doesn't check for the presence of a \0 terminator.
Either this needs to switch to nla_strcmp() and needs to adjust printf fmt
specifier to not use plain %s, or this needs to use NLA_NUL_STRING.
As the code has been this way for long time, it seems to me that userspace
does include the terminating nul, even tough its not enforced so far, and
thus NLA_NUL_STRING use is the simpler solution.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 30dc5e63d6a5ad24894b5512d10b228d73645a44 Version: 30dc5e63d6a5ad24894b5512d10b228d73645a44 Version: 30dc5e63d6a5ad24894b5512d10b228d73645a44 Version: 30dc5e63d6a5ad24894b5512d10b228d73645a44 Version: 30dc5e63d6a5ad24894b5512d10b228d73645a44 Version: 30dc5e63d6a5ad24894b5512d10b228d73645a44 Version: 30dc5e63d6a5ad24894b5512d10b228d73645a44 Version: 30dc5e63d6a5ad24894b5512d10b228d73645a44 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/iwpm_msg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fcd07d3b8ee7a39b344d73aed69c1a68cd9eacdf",
"status": "affected",
"version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
"versionType": "git"
},
{
"lessThan": "87111356d58d86edb221ba144d261ed83a5b8bbe",
"status": "affected",
"version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
"versionType": "git"
},
{
"lessThan": "abda65bdd13084c771842adaac1f652d0660dd82",
"status": "affected",
"version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
"versionType": "git"
},
{
"lessThan": "137b5918931d4d05aa8ea8d3adf67f7224eef63c",
"status": "affected",
"version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
"versionType": "git"
},
{
"lessThan": "5877c043398d5fa0e93919a3d837e5cd7a98a961",
"status": "affected",
"version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
"versionType": "git"
},
{
"lessThan": "f2c7b39dde2e61df8157066969cc2a408cd3dcd9",
"status": "affected",
"version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
"versionType": "git"
},
{
"lessThan": "c26a0052cceed4c4d380ee5808b699f937fb58d8",
"status": "affected",
"version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
"versionType": "git"
},
{
"lessThan": "6ed3d14fc45d3da6025e7fe4a6a09066856698e2",
"status": "affected",
"version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/iwpm_msg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Prefer NLA_NUL_STRING\n\nThese attributes are evaluated as c-string (passed to strcmp), but\nNLA_STRING doesn\u0027t check for the presence of a \\0 terminator.\n\nEither this needs to switch to nla_strcmp() and needs to adjust printf fmt\nspecifier to not use plain %s, or this needs to use NLA_NUL_STRING.\n\nAs the code has been this way for long time, it seems to me that userspace\ndoes include the terminating nul, even tough its not enforced so far, and\nthus NLA_NUL_STRING use is the simpler solution."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached when userspace sends crafted NETLINK_RDMA (protocol 20) messages to the iWARP Port Mapper netlink handlers in `iwpm_register_pid_cb()` and `iwpm_mapping_info_cb()`, not from remote network packets.\nAC:L - An attacker fully controls the netlink attribute payload and can send a maximal-length string without a NUL terminator to reliably trigger unbounded `strcmp()` reads; no race or victim-dependent state is required beyond reaching the handler.\nPR:N - IWPM netlink ops lack `RDMA_NL_ADMIN_PERM`, and `netlink_sendmsg()` only enforces `CAP_NET_ADMIN` when `dst_pid` or `dst_group` is non-zero, so an unprivileged local process can send messages to the kernel RDMA netlink socket without capabilities or user-namespace tricks.\nUI:N - Exploitation requires only a local process sending a crafted netlink message; no victim interaction such as mounting a filesystem or opening a device is needed.\nS:U - Impact is confined to kernel RDMA/iWARP port-mapper state (e.g., `iwpm_user_pid`, mapping tables) within the same kernel security authority and does not cross VM, container, or IOMMU boundaries.\nC:H - `NLA_STRING` does not enforce a NUL terminator, yet `strcmp()` reads until `\\0`, causing an out-of-bounds kernel read past the attribute boundary; error paths also pass the pointer to `%s` in `pr_info()`, enabling further kernel memory disclosure.\nI:H - By sending exactly 19 bytes of `iWarpPortMapperUser` without a terminator, an attacker can make `strcmp()` read a NUL from NLA padding and pass validation, hijacking `iwpm_user_pid` and redirecting subsequent iWARP port-mapping operations to attacker-controlled userspace.\nA:H - Unbounded `strcmp()` on a non-NUL-terminated netlink attribute can read beyond the skb buffer and trigger a kernel page fault/oops, and successful port-mapper impersonation can disrupt iWARP connectivity on affected systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:36:38.134Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fcd07d3b8ee7a39b344d73aed69c1a68cd9eacdf"
},
{
"url": "https://git.kernel.org/stable/c/87111356d58d86edb221ba144d261ed83a5b8bbe"
},
{
"url": "https://git.kernel.org/stable/c/abda65bdd13084c771842adaac1f652d0660dd82"
},
{
"url": "https://git.kernel.org/stable/c/137b5918931d4d05aa8ea8d3adf67f7224eef63c"
},
{
"url": "https://git.kernel.org/stable/c/5877c043398d5fa0e93919a3d837e5cd7a98a961"
},
{
"url": "https://git.kernel.org/stable/c/f2c7b39dde2e61df8157066969cc2a408cd3dcd9"
},
{
"url": "https://git.kernel.org/stable/c/c26a0052cceed4c4d380ee5808b699f937fb58d8"
},
{
"url": "https://git.kernel.org/stable/c/6ed3d14fc45d3da6025e7fe4a6a09066856698e2"
}
],
"title": "RDMA/core: Prefer NLA_NUL_STRING",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63860",
"datePublished": "2026-07-19T14:04:48.153Z",
"dateReserved": "2026-07-19T07:54:57.017Z",
"dateUpdated": "2026-08-05T12:36:38.134Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63827 (GCVE-0-2026-63827)
Vulnerability from cvelistv5
Published
2026-07-19 12:02
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix use-after-free in rawdata dedup loop
aa_replace_profiles() walks ns->rawdata_list to dedup the incoming
policy blob against entries already attached to existing profiles.
Per the kernel-doc on struct aa_loaddata, list membership does not
hold a reference: profiles hold pcount, and when the last pcount
drops, do_ploaddata_rmfs() is queued on a workqueue that takes
ns->lock and removes the entry. Between dropping the last pcount
and the workqueue running, an entry remains on the list with
pcount == 0.
aa_get_profile_loaddata() is an unconditional kref_get() on
pcount, so when the dedup loop hits such an entry, refcount
hardening reports
refcount_t: addition on 0; use-after-free.
inside aa_replace_profiles(), and the poisoned counter then
trips "saturated" and "underflow" warnings on the subsequent
uses of the same loaddata.
Before commit a0b7091c4de4 ("apparmor: fix race on rawdata
dereference") the dedup path used a get_unless_zero-style helper
on a single counter, so the existing "if (tmp)" guard was
meaningful. The split-refcount refactor introduced
aa_get_profile_loaddata(), which has plain kref_get() semantics,
and the guard quietly became a no-op.
Introduce aa_get_profile_loaddata_not0(), matching the existing
_not0 convention used by aa_get_profile_not0(), and use it for
the rawdata_list dedup lookup so dying entries are skipped.
Reproduced on x86_64 with v7.1-rc5 in QEMU+KVM running Ubuntu
24.04 + stress-ng 0.17.06:
stress-ng --apparmor 1 --klog-check --timeout 60s
Without this patch the three refcount_t warnings fire within a
few seconds. With it the same 60 s run is clean. Coverage is a
smoke-test only; a longer soak with CONFIG_KASAN, CONFIG_KCSAN
and CONFIG_PROVE_LOCKING would be welcome from anyone with the
cycles.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3b8e77c7abab40e6de9ad9de730d77984a498840 Version: d9d8560b9b7932f8cffc4c068c14289220900f79 Version: 6b6ba87579c7e7c669e0bec91823e7fb693bc5df Version: 6ef1f2926c41ab96952d9696d55a052f1b3a9418 Version: f9761add6d100962a23996cb68f3d6abdd4d1815 Version: af782cc8871e3683ddd5a3cd2f7df526599863a9 Version: a0b7091c4de45a7325c8780e6934a894f92ac86b Version: a0b7091c4de45a7325c8780e6934a894f92ac86b Version: 763e838adc3c7ec5a7df2990ce84cad951e42721 Version: 5.10.253 ≤ Version: 5.15.203 ≤ Version: 6.1.169 ≤ Version: 6.6.130 ≤ Version: 6.12.77 ≤ Version: 6.18.18 ≤ Version: 6.19.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/apparmor/include/policy_unpack.h",
"security/apparmor/policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "643221da57dbb1a8fd800610331cf1ec27969f71",
"status": "affected",
"version": "3b8e77c7abab40e6de9ad9de730d77984a498840",
"versionType": "git"
},
{
"lessThan": "b17f0c59cc1525765625cf07d0391b7f9c1ed7e5",
"status": "affected",
"version": "d9d8560b9b7932f8cffc4c068c14289220900f79",
"versionType": "git"
},
{
"lessThan": "a7a2890028f16e5b0af0bb005d80fcb32559cca3",
"status": "affected",
"version": "6b6ba87579c7e7c669e0bec91823e7fb693bc5df",
"versionType": "git"
},
{
"lessThan": "15fd83a1e42ede15070968806bb6c8b1a5170688",
"status": "affected",
"version": "6ef1f2926c41ab96952d9696d55a052f1b3a9418",
"versionType": "git"
},
{
"lessThan": "ce261a20b41db522e320a41bbf1292bf85af66df",
"status": "affected",
"version": "f9761add6d100962a23996cb68f3d6abdd4d1815",
"versionType": "git"
},
{
"lessThan": "c3ca2631073b2cef06824fd2bfc452ff7a1023de",
"status": "affected",
"version": "af782cc8871e3683ddd5a3cd2f7df526599863a9",
"versionType": "git"
},
{
"lessThan": "5e34fa9f6f7cd688ae153fff13139a5cf2d42339",
"status": "affected",
"version": "a0b7091c4de45a7325c8780e6934a894f92ac86b",
"versionType": "git"
},
{
"lessThan": "6f060496d03e4dc560a40f73770bd08335cb7a27",
"status": "affected",
"version": "a0b7091c4de45a7325c8780e6934a894f92ac86b",
"versionType": "git"
},
{
"status": "affected",
"version": "763e838adc3c7ec5a7df2990ce84cad951e42721",
"versionType": "git"
},
{
"lessThan": "5.10.261",
"status": "affected",
"version": "5.10.253",
"versionType": "semver"
},
{
"lessThan": "5.15.212",
"status": "affected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThan": "6.1.177",
"status": "affected",
"version": "6.1.169",
"versionType": "semver"
},
{
"lessThan": "6.6.144",
"status": "affected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThan": "6.12.95",
"status": "affected",
"version": "6.12.77",
"versionType": "semver"
},
{
"lessThan": "6.18.38",
"status": "affected",
"version": "6.18.18",
"versionType": "semver"
},
{
"lessThan": "6.20",
"status": "affected",
"version": "6.19.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/apparmor/include/policy_unpack.h",
"security/apparmor/policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.0"
},
{
"lessThan": "7.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.10.253",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.15.203",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "6.1.169",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.6.130",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.12.77",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "6.18.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.19.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix use-after-free in rawdata dedup loop\n\naa_replace_profiles() walks ns-\u003erawdata_list to dedup the incoming\npolicy blob against entries already attached to existing profiles.\nPer the kernel-doc on struct aa_loaddata, list membership does not\nhold a reference: profiles hold pcount, and when the last pcount\ndrops, do_ploaddata_rmfs() is queued on a workqueue that takes\nns-\u003elock and removes the entry. Between dropping the last pcount\nand the workqueue running, an entry remains on the list with\npcount == 0.\n\naa_get_profile_loaddata() is an unconditional kref_get() on\npcount, so when the dedup loop hits such an entry, refcount\nhardening reports\n\n refcount_t: addition on 0; use-after-free.\n\ninside aa_replace_profiles(), and the poisoned counter then\ntrips \"saturated\" and \"underflow\" warnings on the subsequent\nuses of the same loaddata.\n\nBefore commit a0b7091c4de4 (\"apparmor: fix race on rawdata\ndereference\") the dedup path used a get_unless_zero-style helper\non a single counter, so the existing \"if (tmp)\" guard was\nmeaningful. The split-refcount refactor introduced\naa_get_profile_loaddata(), which has plain kref_get() semantics,\nand the guard quietly became a no-op.\n\nIntroduce aa_get_profile_loaddata_not0(), matching the existing\n_not0 convention used by aa_get_profile_not0(), and use it for\nthe rawdata_list dedup lookup so dying entries are skipped.\n\nReproduced on x86_64 with v7.1-rc5 in QEMU+KVM running Ubuntu\n24.04 + stress-ng 0.17.06:\n\n stress-ng --apparmor 1 --klog-check --timeout 60s\n\nWithout this patch the three refcount_t warnings fire within a\nfew seconds. With it the same 60 s run is clean. Coverage is a\nsmoke-test only; a longer soak with CONFIG_KASAN, CONFIG_KCSAN\nand CONFIG_PROVE_LOCKING would be welcome from anyone with the\ncycles."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local write() to AppArmor policy management interfaces (.load/.replace) under securityfs/apparmorfs, not through any network-facing protocol.\nAC:L - An attacker with policy-admin capability can reliably win the race by concurrently loading/replacing and removing profiles with identical rawdata blobs, as demonstrated by stress-ng reproducing refcount UAF warnings within seconds.\nPR:L - Triggering aa_replace_profiles() requires CAP_MAC_ADMIN plus policy-view rights; on typical AppArmor deployments (e.g. Ubuntu) namespace-root in an unprivileged user namespace can obtain CAP_MAC_ADMIN via unprivileged_userns_apparmor_policy without init-namespace root.\nUI:N - Exploitation is driven entirely by the attacker\u0027s own policy load/replace/remove operations and does not require any action from another user or administrator.\nS:U - Impact is kernel memory corruption and potential local privilege escalation within the same kernel security boundary, not a cross-VM or cross-security-authority escape.\nC:H - The vulnerability is a use-after-free on aa_loaddata profile refcounts; refcount hardening reports \"addition on 0; use-after-free\" and poisons the counter, creating a path to arbitrary kernel memory disclosure.\nI:H - UAF and refcount saturation/underflow on aa_loaddata enable heap corruption primitives that can be leveraged for arbitrary kernel writes and local privilege escalation.\nA:H - The bug reliably triggers refcount_t UAF warnings and corrupts subsequent refcount operations on the same loaddata, causing kernel instability and potential crash/panic under concurrent policy management."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:35.761Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/643221da57dbb1a8fd800610331cf1ec27969f71"
},
{
"url": "https://git.kernel.org/stable/c/b17f0c59cc1525765625cf07d0391b7f9c1ed7e5"
},
{
"url": "https://git.kernel.org/stable/c/a7a2890028f16e5b0af0bb005d80fcb32559cca3"
},
{
"url": "https://git.kernel.org/stable/c/15fd83a1e42ede15070968806bb6c8b1a5170688"
},
{
"url": "https://git.kernel.org/stable/c/ce261a20b41db522e320a41bbf1292bf85af66df"
},
{
"url": "https://git.kernel.org/stable/c/c3ca2631073b2cef06824fd2bfc452ff7a1023de"
},
{
"url": "https://git.kernel.org/stable/c/5e34fa9f6f7cd688ae153fff13139a5cf2d42339"
},
{
"url": "https://git.kernel.org/stable/c/6f060496d03e4dc560a40f73770bd08335cb7a27"
}
],
"title": "apparmor: fix use-after-free in rawdata dedup loop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63827",
"datePublished": "2026-07-19T12:02:22.083Z",
"dateReserved": "2026-07-19T07:54:57.014Z",
"dateUpdated": "2026-08-17T04:51:35.761Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68309 (GCVE-0-2026-68309)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
mt76_connac_get_he_phy_cap routine can theoretically return NULL so
check cap pointer before dereferencing it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt76_connac_mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d1f8705d6545d20950991785306d08884b0056fc",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "91eb15c026debd8b7bfbd83f062e6245a4e69964",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "b09508dd7bc4a8948ea00603041a918c09788502",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "2afc2d5098866518a5c446a2e647b1b3f43daaf4",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "c058786b09cfab080125bc3ee7928a181dcbd37a",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "8709c66e665a2a09192853d4f3d0fb4bd0f76403",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "2c1fb2335f5e3afb34f91bc07ecb63517c328090",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt76_connac_mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()\n\nmt76_connac_get_he_phy_cap routine can theoretically return NULL so\ncheck cap pointer before dereferencing it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:00.744Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d1f8705d6545d20950991785306d08884b0056fc"
},
{
"url": "https://git.kernel.org/stable/c/91eb15c026debd8b7bfbd83f062e6245a4e69964"
},
{
"url": "https://git.kernel.org/stable/c/b09508dd7bc4a8948ea00603041a918c09788502"
},
{
"url": "https://git.kernel.org/stable/c/2afc2d5098866518a5c446a2e647b1b3f43daaf4"
},
{
"url": "https://git.kernel.org/stable/c/c058786b09cfab080125bc3ee7928a181dcbd37a"
},
{
"url": "https://git.kernel.org/stable/c/8709c66e665a2a09192853d4f3d0fb4bd0f76403"
},
{
"url": "https://git.kernel.org/stable/c/2c1fb2335f5e3afb34f91bc07ecb63517c328090"
}
],
"title": "wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68309",
"datePublished": "2026-08-10T12:02:43.950Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:33:00.744Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74527 (GCVE-0-2026-74527)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-17 05:48
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: Block VFs from clobbering special CGX PKIND state
PF and VF NIX LFs that share a CGX LMAC reuse the same hardware PKIND
programming. When HiGig2 or EDSA parsing is enabled, a VF NIX LF alloc must
not reset the LMAC RX PKIND or default TX parse config over the PF setup.
Add cgx_get_pkind() and rvu_cgx_is_pkind_config_permitted() so VFs skip
cgx_set_pkind(), rvu_npc_set_pkind(), and NIX_AF_LFX_TX_PARSE_CFG updates
when the LMAC is using NPC_RX_HIGIG_PKIND or NPC_RX_EDSA_PKIND.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/af/cgx.c",
"drivers/net/ethernet/marvell/octeontx2/af/cgx.h",
"drivers/net/ethernet/marvell/octeontx2/af/rvu.h",
"drivers/net/ethernet/marvell/octeontx2/af/rvu_cgx.c",
"drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c",
"drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d3c6b0f48f126a36955b3fb4154a59d0b3621d97",
"status": "affected",
"version": "94d942c5fb970ac2166216838b278613decfa9a0",
"versionType": "git"
},
{
"lessThan": "3bd438a58e910db5dc369aa25dfed1fc95f1b596",
"status": "affected",
"version": "94d942c5fb970ac2166216838b278613decfa9a0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/af/cgx.c",
"drivers/net/ethernet/marvell/octeontx2/af/cgx.h",
"drivers/net/ethernet/marvell/octeontx2/af/rvu.h",
"drivers/net/ethernet/marvell/octeontx2/af/rvu_cgx.c",
"drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c",
"drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: Block VFs from clobbering special CGX PKIND state\n\nPF and VF NIX LFs that share a CGX LMAC reuse the same hardware PKIND\nprogramming. When HiGig2 or EDSA parsing is enabled, a VF NIX LF alloc must\nnot reset the LMAC RX PKIND or default TX parse config over the PF setup.\n\nAdd cgx_get_pkind() and rvu_cgx_is_pkind_config_permitted() so VFs skip\ncgx_set_pkind(), rvu_npc_set_pkind(), and NIX_AF_LFX_TX_PARSE_CFG updates\nwhen the LMAC is using NPC_RX_HIGIG_PKIND or NPC_RX_EDSA_PKIND."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a malicious SR-IOV VF tenant to send NIX_LF_ALLOC mailbox messages over PCI BAR registers during netdev bring-up; the vulnerable AF code is not reachable from remote network packets.\nAC:L - In the target OcteonTX2 DSA/HiGig multi-tenant deployment, a VF reliably triggers the bug by opening its netdev; no races or attacker-uncontrollable memory layout are needed once HiGig/EDSA parsing is enabled on the shared LMAC.\nPR:L - The attacker is a cloud/NFV tenant with an assigned OcteonTX2 VF; triggering NIX LF allocation during interface up requires only guest-level netdev privileges (e.g., CAP_NET_ADMIN in the VM), not host root or init-namespace admin rights.\nUI:N - No victim interaction is required; the clobber occurs automatically when the attacker brings up or reinitializes their VF network interface through the standard driver probe/open path.\nS:C - A VF guest corrupts host-managed shared CGX LMAC hardware PKIND and NPC parse configuration, impacting the PF and other functions on that port beyond the VF\u0027s own security authority\u2014crossing the VM/tenant isolation boundary.\nC:H - Resetting HiGig/EDSA RX PKIND misconfigures NPC packet parsing for the entire shared LMAC, potentially misdelivering or exposing fabric/switch-tagged traffic intended for the PF or other tenants to the attacker\u0027s VF.\nI:H - The VF forcibly overwrites shared LMAC RX PKIND via cgx_set_pkind() and programs default TX parse config, corrupting host-controlled switching-header parsing that governs how transmitted and received fabric traffic is processed on the port.\nA:H - Clobbering special HiGig/EDSA PKIND state breaks correct packet parsing for all PF/VF traffic on the shared LMAC, causing sustained loss of connectivity and denial of network service to the host and co-located tenants."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:48:16.718Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d3c6b0f48f126a36955b3fb4154a59d0b3621d97"
},
{
"url": "https://git.kernel.org/stable/c/3bd438a58e910db5dc369aa25dfed1fc95f1b596"
}
],
"title": "octeontx2-af: Block VFs from clobbering special CGX PKIND state",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74527",
"datePublished": "2026-08-15T12:27:43.568Z",
"dateReserved": "2026-08-15T05:44:03.912Z",
"dateUpdated": "2026-08-17T05:48:16.718Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64504 (GCVE-0-2026-64504)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iio: accel: bmc150: clamp the device-reported FIFO frame count
__bmc150_accel_fifo_flush() copies the number of samples the device
reports in its hardware FIFO into an on-stack buffer
u16 buffer[BMC150_ACCEL_FIFO_LENGTH * 3];
which is sized for at most BMC150_ACCEL_FIFO_LENGTH (32) samples. The
frame count is read from the FIFO_STATUS register and only masked to its
7 valid bits:
count = val & 0x7F;
so it can be 0..127. The only other limit applied to it is the optional
caller-supplied sample budget:
if (samples && count > samples)
count = samples;
which does not constrain count on the flush-all path (samples == 0), and
leaves it well above 32 whenever samples is larger. count samples are
then transferred into buffer[]:
bmc150_accel_fifo_transfer(data, (u8 *)buffer, count);
bmc150_accel_fifo_transfer() reads count * 6 bytes through regmap, so a
malfunctioning, malicious or counterfeit accelerometer (or an attacker
tampering with the I2C/SPI bus) that reports up to 127 frames writes up
to 762 bytes into the 192-byte buffer: a stack out-of-bounds write of up
to 570 bytes that clobbers the stack canary, saved registers and the
return address.
Clamp count to BMC150_ACCEL_FIFO_LENGTH, the number of samples buffer[]
is sized for, before the transfer, mirroring the watermark clamp already
done in bmc150_accel_set_watermark(). A well-formed flush reports at most
BMC150_ACCEL_FIFO_LENGTH frames, so legitimate devices are unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3bbec9773389112330954a6a64422eaa78d546c1 Version: 3bbec9773389112330954a6a64422eaa78d546c1 Version: 3bbec9773389112330954a6a64422eaa78d546c1 Version: 3bbec9773389112330954a6a64422eaa78d546c1 Version: 3bbec9773389112330954a6a64422eaa78d546c1 Version: 3bbec9773389112330954a6a64422eaa78d546c1 Version: 3bbec9773389112330954a6a64422eaa78d546c1 Version: 3bbec9773389112330954a6a64422eaa78d546c1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iio/accel/bmc150-accel-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b5a9f521e0a49a0266200fd535b32a9668ecb33b",
"status": "affected",
"version": "3bbec9773389112330954a6a64422eaa78d546c1",
"versionType": "git"
},
{
"lessThan": "2fe0531dd73eff1de0f2584cb77716d645e548d5",
"status": "affected",
"version": "3bbec9773389112330954a6a64422eaa78d546c1",
"versionType": "git"
},
{
"lessThan": "d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff",
"status": "affected",
"version": "3bbec9773389112330954a6a64422eaa78d546c1",
"versionType": "git"
},
{
"lessThan": "bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc",
"status": "affected",
"version": "3bbec9773389112330954a6a64422eaa78d546c1",
"versionType": "git"
},
{
"lessThan": "89f4a4ca0ac3a933c750569a771c079a290b0721",
"status": "affected",
"version": "3bbec9773389112330954a6a64422eaa78d546c1",
"versionType": "git"
},
{
"lessThan": "3e766526827acd542bcd36c20c4d5f397e0f6521",
"status": "affected",
"version": "3bbec9773389112330954a6a64422eaa78d546c1",
"versionType": "git"
},
{
"lessThan": "35a3cd8fd65e15029eb90f1e510045b1bb071175",
"status": "affected",
"version": "3bbec9773389112330954a6a64422eaa78d546c1",
"versionType": "git"
},
{
"lessThan": "ce0e1cae26096fe959a0da5563a6d6d5a801d5fb",
"status": "affected",
"version": "3bbec9773389112330954a6a64422eaa78d546c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iio/accel/bmc150-accel-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: accel: bmc150: clamp the device-reported FIFO frame count\n\n__bmc150_accel_fifo_flush() copies the number of samples the device\nreports in its hardware FIFO into an on-stack buffer\n\n\tu16 buffer[BMC150_ACCEL_FIFO_LENGTH * 3];\n\nwhich is sized for at most BMC150_ACCEL_FIFO_LENGTH (32) samples. The\nframe count is read from the FIFO_STATUS register and only masked to its\n7 valid bits:\n\n\tcount = val \u0026 0x7F;\n\nso it can be 0..127. The only other limit applied to it is the optional\ncaller-supplied sample budget:\n\n\tif (samples \u0026\u0026 count \u003e samples)\n\t\tcount = samples;\n\nwhich does not constrain count on the flush-all path (samples == 0), and\nleaves it well above 32 whenever samples is larger. count samples are\nthen transferred into buffer[]:\n\n\tbmc150_accel_fifo_transfer(data, (u8 *)buffer, count);\n\nbmc150_accel_fifo_transfer() reads count * 6 bytes through regmap, so a\nmalfunctioning, malicious or counterfeit accelerometer (or an attacker\ntampering with the I2C/SPI bus) that reports up to 127 frames writes up\nto 762 bytes into the 192-byte buffer: a stack out-of-bounds write of up\nto 570 bytes that clobbers the stack canary, saved registers and the\nreturn address.\n\nClamp count to BMC150_ACCEL_FIFO_LENGTH, the number of samples buffer[]\nis sized for, before the transfer, mirroring the watermark clamp already\ndone in bmc150_accel_set_watermark(). A well-formed flush reports at most\nBMC150_ACCEL_FIFO_LENGTH frames, so legitimate devices are unaffected."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:54.396Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b5a9f521e0a49a0266200fd535b32a9668ecb33b"
},
{
"url": "https://git.kernel.org/stable/c/2fe0531dd73eff1de0f2584cb77716d645e548d5"
},
{
"url": "https://git.kernel.org/stable/c/d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff"
},
{
"url": "https://git.kernel.org/stable/c/bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc"
},
{
"url": "https://git.kernel.org/stable/c/89f4a4ca0ac3a933c750569a771c079a290b0721"
},
{
"url": "https://git.kernel.org/stable/c/3e766526827acd542bcd36c20c4d5f397e0f6521"
},
{
"url": "https://git.kernel.org/stable/c/35a3cd8fd65e15029eb90f1e510045b1bb071175"
},
{
"url": "https://git.kernel.org/stable/c/ce0e1cae26096fe959a0da5563a6d6d5a801d5fb"
}
],
"title": "iio: accel: bmc150: clamp the device-reported FIFO frame count",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64504",
"datePublished": "2026-07-25T08:51:58.887Z",
"dateReserved": "2026-07-19T15:36:31.793Z",
"dateUpdated": "2026-08-17T04:56:54.396Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68102 (GCVE-0-2026-68102)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix aperture mapping leak
amdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver
fini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to
always return false, so iounmap(aper_base_kaddr) never runs on normal
driver unload, leaving an orphaned entry in the x86 PAT interval tree.
On connected_to_cpu hardware, the aperture is mapped write-back (WB) via
ioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC)
over the same range. The WC vs WB conflict causes:
ioremap error for 0x..., requested 0x1, got 0x0
amdgpu: discovery failed: -2
Fix by switching to devres-managed mappings so cleanup is guaranteed
regardless of drm_dev_enter() state:
- connected_to_cpu path: devm_memremap(MEMREMAP_WB). For
IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut,
returning __va(offset) from the existing kernel direct map. No new
ioremap VA or PAT entry is created, so there is nothing to orphan.
- dGPU path: devm_ioremap_wc() registers iounmap() as a devres action,
guaranteeing cleanup at device_del() time.
Also remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio()
since the mapping is now devres-owned.
v2: Remove redundant x86_64 guard (Lijo)
(cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_device.c",
"drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "67bc3647e418e23dc0d17604bdba634a73de809f",
"status": "affected",
"version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
"versionType": "git"
},
{
"lessThan": "a343d028ad6c174da8dc6af560c51e6d140a6727",
"status": "affected",
"version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
"versionType": "git"
},
{
"lessThan": "6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa",
"status": "affected",
"version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
"versionType": "git"
},
{
"lessThan": "f5988b5c300a32ff751724ffd33d5a8d5873e4a7",
"status": "affected",
"version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
"versionType": "git"
},
{
"lessThan": "ea772a440d56b285f4d491affac50ecd41f6b402",
"status": "affected",
"version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_device.c",
"drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix aperture mapping leak\n\namdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver\nfini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to\nalways return false, so iounmap(aper_base_kaddr) never runs on normal\ndriver unload, leaving an orphaned entry in the x86 PAT interval tree.\n\nOn connected_to_cpu hardware, the aperture is mapped write-back (WB) via\nioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC)\nover the same range. The WC vs WB conflict causes:\n\n ioremap error for 0x..., requested 0x1, got 0x0\n amdgpu: discovery failed: -2\n\nFix by switching to devres-managed mappings so cleanup is guaranteed\nregardless of drm_dev_enter() state:\n\n- connected_to_cpu path: devm_memremap(MEMREMAP_WB). For\n IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut,\n returning __va(offset) from the existing kernel direct map. No new\n ioremap VA or PAT entry is created, so there is nothing to orphan.\n\n- dGPU path: devm_ioremap_wc() registers iounmap() as a devres action,\n guaranteeing cleanup at device_del() time.\n\nAlso remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio()\nsince the mapping is now devres-owned.\n\nv2: Remove redundant x86_64 guard (Lijo)\n\n(cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:50.338Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/67bc3647e418e23dc0d17604bdba634a73de809f"
},
{
"url": "https://git.kernel.org/stable/c/a343d028ad6c174da8dc6af560c51e6d140a6727"
},
{
"url": "https://git.kernel.org/stable/c/6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa"
},
{
"url": "https://git.kernel.org/stable/c/f5988b5c300a32ff751724ffd33d5a8d5873e4a7"
},
{
"url": "https://git.kernel.org/stable/c/ea772a440d56b285f4d491affac50ecd41f6b402"
}
],
"title": "drm/amdgpu: fix aperture mapping leak",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68102",
"datePublished": "2026-08-10T11:58:18.093Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-17T04:58:50.338Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68153 (GCVE-0-2026-68153)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: remove debugfs files before client teardown
ceph_destroy_client() tears down the monitor client before removing
the per-client debugfs files. A concurrent read of the monmap debugfs
file can enter monmap_show() after ceph_monc_stop() has freed
monc->monmap, triggering a use-after-free.
Remove the debugfs files before stopping the OSD and monitor clients.
debugfs_remove() drains active handlers and prevents new accesses, so
the debugfs callbacks can no longer race the rest of client teardown.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/ceph_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ac78549d186090ee7125d28c3a8c376573b36194",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "463a264e9094384112a5c8b46f0a9ddaf8566904",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "fe46b7e06f14f6f94766832df309b249cb689d27",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "fc1010e7e0204ece6cc0f9af4f473e9553535eab",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "d3dc8889d39a676bf840132bd5c5c48cb0daba23",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "8f5a3abc54ba24dbceb14cc3a719908c4f688091",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "b9fedda2f628e030384228de0dafc574b7fb0c2f",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "e4c804726c4afce3ba648b982d564f6af2cfa328",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/ceph_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: remove debugfs files before client teardown\n\nceph_destroy_client() tears down the monitor client before removing\nthe per-client debugfs files. A concurrent read of the monmap debugfs\nfile can enter monmap_show() after ceph_monc_stop() has freed\nmonc-\u003emonmap, triggering a use-after-free.\n\nRemove the debugfs files before stopping the OSD and monitor clients.\ndebugfs_remove() drains active handlers and prevents new accesses, so\nthe debugfs callbacks can no longer race the rest of client teardown."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to debugfs via read() on /sys/kernel/debug/ceph/client*/monmap concurrent with local ceph client teardown via umount or rbd unmap; the bug is not reachable through Ceph network protocol handlers.\nAC:L - The attacker controls both sides of the race by concurrently reading the monmap debugfs file while triggering ceph_destroy_client() via umount/rbd teardown, and can retry until the window between ceph_monc_stop() and debugfs removal is hit.\nPR:L - An unprivileged local user can use user-namespace capabilities (CAP_DAC_READ_SEARCH) to read root-owned debugfs files and race reads against libceph client teardown during automated volume detach or service restarts on Ceph storage nodes.\nUI:N - No victim user interaction is required; a local attacker can independently issue debugfs reads and trigger or time against client teardown without requiring another user to click, open files, or mount filesystems.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security domain and does not cross VM, container, or IOMMU boundaries; impact is standard kernel privilege escalation or crash.\nC:H - The use-after-free on monc-\u003emonmap permits reading freed heap memory containing monitor addresses and entity metadata, and UAF primitives are routinely leveraged for arbitrary kernel memory disclosure.\nI:H - Heap use-after-free on the variable-length ceph_monmap structure enables memory corruption that can be groomed into arbitrary kernel write primitives and local privilege escalation via control-flow hijacking.\nA:H - Concurrent access to freed monmap memory during debugfs iteration can cause kernel oops, BUG, or panic, and UAF corruption reliably threatens system availability even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:18.048Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ac78549d186090ee7125d28c3a8c376573b36194"
},
{
"url": "https://git.kernel.org/stable/c/463a264e9094384112a5c8b46f0a9ddaf8566904"
},
{
"url": "https://git.kernel.org/stable/c/fe46b7e06f14f6f94766832df309b249cb689d27"
},
{
"url": "https://git.kernel.org/stable/c/fc1010e7e0204ece6cc0f9af4f473e9553535eab"
},
{
"url": "https://git.kernel.org/stable/c/d3dc8889d39a676bf840132bd5c5c48cb0daba23"
},
{
"url": "https://git.kernel.org/stable/c/8f5a3abc54ba24dbceb14cc3a719908c4f688091"
},
{
"url": "https://git.kernel.org/stable/c/b9fedda2f628e030384228de0dafc574b7fb0c2f"
},
{
"url": "https://git.kernel.org/stable/c/e4c804726c4afce3ba648b982d564f6af2cfa328"
}
],
"title": "libceph: remove debugfs files before client teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68153",
"datePublished": "2026-08-10T11:59:19.302Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:18.048Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68306 (GCVE-0-2026-68306)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
mt76_connac_get_eht_phy_cap routine can theoretically return NULL so
check cap pointer before dereferencing it.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7996/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2b1882cf313ae44181146629b3578a7826c672c9",
"status": "affected",
"version": "ba01944adee9f4a71cf2879b9529057fd8de1972",
"versionType": "git"
},
{
"lessThan": "3e4f848f4a620e1d77c38459e73cf3b362f7bc6b",
"status": "affected",
"version": "ba01944adee9f4a71cf2879b9529057fd8de1972",
"versionType": "git"
},
{
"lessThan": "d5628f39fccc107dca00b98a491d9848898599f7",
"status": "affected",
"version": "ba01944adee9f4a71cf2879b9529057fd8de1972",
"versionType": "git"
},
{
"lessThan": "45c496756c6f6df6c3aeb5b2cb996993d2f14687",
"status": "affected",
"version": "ba01944adee9f4a71cf2879b9529057fd8de1972",
"versionType": "git"
},
{
"lessThan": "2fffc472bec490c8357defcee9c075ca74467352",
"status": "affected",
"version": "ba01944adee9f4a71cf2879b9529057fd8de1972",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7996/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()\n\nmt76_connac_get_eht_phy_cap routine can theoretically return NULL so\ncheck cap pointer before dereferencing it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:58.582Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2b1882cf313ae44181146629b3578a7826c672c9"
},
{
"url": "https://git.kernel.org/stable/c/3e4f848f4a620e1d77c38459e73cf3b362f7bc6b"
},
{
"url": "https://git.kernel.org/stable/c/d5628f39fccc107dca00b98a491d9848898599f7"
},
{
"url": "https://git.kernel.org/stable/c/45c496756c6f6df6c3aeb5b2cb996993d2f14687"
},
{
"url": "https://git.kernel.org/stable/c/2fffc472bec490c8357defcee9c075ca74467352"
}
],
"title": "wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68306",
"datePublished": "2026-08-10T12:02:40.907Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-17T05:02:58.582Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64136 (GCVE-0-2026-64136)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields")
refactored cifs code to change cifs_tcp_ses_lock for tc_lock around
tc_count changes.
There was missing lock around tc_count increment inside
smb2_find_smb_sess_tcon_unlocked().
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 953953abb66e52c224057ab91e404284fefeab62 Version: 601dd3b79769b38d30b693c40afdb2a4b7edf9d0 Version: 3969db6b22e3d90d8c5f22ac1a7fe0350a94c136 Version: 96c4af418586ee9a6aab61738644366426e05316 Version: 96c4af418586ee9a6aab61738644366426e05316 Version: 8c59eeeeffa1524ef57e173a89a1a3ff539888d5 Version: 6.6.128 ≤ Version: 6.12.75 ≤ Version: 6.18.16 ≤ Version: 6.19.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2transport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7df1df6f40c0720d30206aa35c0343b962350e0d",
"status": "affected",
"version": "953953abb66e52c224057ab91e404284fefeab62",
"versionType": "git"
},
{
"lessThan": "13fb413ae22a37c69341918a6d651d19a9b0b9b7",
"status": "affected",
"version": "601dd3b79769b38d30b693c40afdb2a4b7edf9d0",
"versionType": "git"
},
{
"lessThan": "bf4ebdb19ff9b3cdf992b50715fe61633327416a",
"status": "affected",
"version": "3969db6b22e3d90d8c5f22ac1a7fe0350a94c136",
"versionType": "git"
},
{
"lessThan": "e374f4e496fef8168784f93a4477d67be34485fd",
"status": "affected",
"version": "96c4af418586ee9a6aab61738644366426e05316",
"versionType": "git"
},
{
"lessThan": "4d8690dace005a38e6dbde9ecce2da3ad85c7c41",
"status": "affected",
"version": "96c4af418586ee9a6aab61738644366426e05316",
"versionType": "git"
},
{
"status": "affected",
"version": "8c59eeeeffa1524ef57e173a89a1a3ff539888d5",
"versionType": "git"
},
{
"lessThan": "6.6.142",
"status": "affected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThan": "6.12.92",
"status": "affected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThan": "6.18.34",
"status": "affected",
"version": "6.18.16",
"versionType": "semver"
},
{
"lessThan": "6.20",
"status": "affected",
"version": "6.19.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2transport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.0"
},
{
"lessThan": "7.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.6.128",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.12.75",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.18.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.19.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()\n\nCommit 96c4af418586 (\"cifs: Fix locking usage for tcon fields\")\nrefactored cifs code to change cifs_tcp_ses_lock for tc_lock around\ntc_count changes.\n\nThere was missing lock around tc_count increment inside\nsmb2_find_smb_sess_tcon_unlocked()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in the in-kernel SMB/CIFS client (fs/smb/client/), reached when processing SMB2 responses received over TCP from a remote server in cifs_demultiplex_thread(). A network-positioned attacker controlling or impersonating the SMB server can drive the vulnerable cancelled-mid handling path.\nAC:L - The attacker controls SMB response timing and can trigger concurrent cifs_put_tcon() via server-initiated disconnect/reconnect, racing the unprotected tc_count increment. Cancelled-mid conditions arise from normal concurrent I/O, signals, and unmount/reconnect activity that the attacker can reliably provoke.\nPR:N - Exploitation requires no local privileges on the victim; a remote malicious or compromised SMB server can attack any client that has an active CIFS mount/session, without the attacker holding an account or capabilities on the victim host.\nUI:N - No victim interaction is needed at exploit time in common deployments where CIFS shares are automounted at boot or persistently connected (cloud file shares, enterprise NAS); the attacker abuses an already-established SMB session rather than requiring a new mount action.\nS:U - Impact is kernel memory corruption and potential local privilege escalation within the same kernel security domain, not a cross-boundary escape such as guest-to-host VM breakout.\nC:H - The race can cause a use-after-free of struct cifs_tcon; UAF of kernel heap objects enables arbitrary memory disclosure through controlled reuse of the freed structure.\nI:H - The UAF leads to subsequent kernel operations (SMB2_close, workqueue handlers) on freed memory, providing a path to arbitrary kernel write and potential code execution via heap grooming.\nA:H - Winning the refcount race causes use-after-free of cifs_tcon with continued kernel use of the freed object, which can trigger kernel oops/panic and denial of service even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:37.286Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7df1df6f40c0720d30206aa35c0343b962350e0d"
},
{
"url": "https://git.kernel.org/stable/c/13fb413ae22a37c69341918a6d651d19a9b0b9b7"
},
{
"url": "https://git.kernel.org/stable/c/bf4ebdb19ff9b3cdf992b50715fe61633327416a"
},
{
"url": "https://git.kernel.org/stable/c/e374f4e496fef8168784f93a4477d67be34485fd"
},
{
"url": "https://git.kernel.org/stable/c/4d8690dace005a38e6dbde9ecce2da3ad85c7c41"
}
],
"title": "smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64136",
"datePublished": "2026-07-19T15:40:30.351Z",
"dateReserved": "2026-07-19T07:54:57.036Z",
"dateUpdated": "2026-08-05T12:39:37.286Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68202 (GCVE-0-2026-68202)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: seq: close a re-opened queue timer in the destructor
queue_delete() closes the queue timer, then frees it. snd_seq_timer_close()
clears q->timer->timeri. snd_use_lock_sync() then drains borrowers, and
snd_seq_timer_delete() frees q->timer.
A borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT
that took a queueptr() use_lock reference before the queue was unlinked
runs snd_seq_timer_open() after the close. Open refuses re-open only while
timeri is set, and the close just cleared it, so it re-opens timeri.
snd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop()
is a no-op, because running was cleared first. So it frees q->timer with the
instance still live. The queue is freed next.
The instance stays on the global timer with callback_data pointing at the
freed queue. A non-owner START on the unlocked queue arms it. The next tick
derefs the freed queue in snd_seq_timer_interrupt().
Reachable by an unprivileged user with access to /dev/snd/seq. No CAP and
no queue ownership required.
Close any lingering instance in the destructor. There, ->timeri can no
longer change: the queue is unlinked and all use_lock borrowers have
drained, so no snd_seq_queue_use() can re-open it. Close it before clearing
q->timer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt()
to finish, and that callback still reads q->timer (via snd_seq_check_queue()),
so q->timer must stay valid until it drains.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/core/seq/seq_timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b7feeaca1f53b10df9b4de9eaf611767ca70dc92",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7478ef94b49bc9789cf1a003deec58b42283dde4",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9d9be6fc30f384f92c4e1b8ed40bd9d4796b7833",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "fb40d03ed792a8a8bf77aa0ee15df57b0ff78b07",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "24f0cabf173539f048946c8fc221131dc221f277",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6a10025c7fd09a7d2af37a3ae1da188569fce470",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "31a6163e301d832060f8236f1ed17cbc1ca198df",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2c4dc0ed50b05cd847a4b34b8cebf0775f19aeb9",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/core/seq/seq_timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: close a re-opened queue timer in the destructor\n\nqueue_delete() closes the queue timer, then frees it. snd_seq_timer_close()\nclears q-\u003etimer-\u003etimeri. snd_use_lock_sync() then drains borrowers, and\nsnd_seq_timer_delete() frees q-\u003etimer.\n\nA borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT\nthat took a queueptr() use_lock reference before the queue was unlinked\nruns snd_seq_timer_open() after the close. Open refuses re-open only while\ntimeri is set, and the close just cleared it, so it re-opens timeri.\n\nsnd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop()\nis a no-op, because running was cleared first. So it frees q-\u003etimer with the\ninstance still live. The queue is freed next.\n\nThe instance stays on the global timer with callback_data pointing at the\nfreed queue. A non-owner START on the unlocked queue arms it. The next tick\nderefs the freed queue in snd_seq_timer_interrupt().\n\nReachable by an unprivileged user with access to /dev/snd/seq. No CAP and\nno queue ownership required.\n\nClose any lingering instance in the destructor. There, -\u003etimeri can no\nlonger change: the queue is unlinked and all use_lock borrowers have\ndrained, so no snd_seq_queue_use() can re-open it. Close it before clearing\nq-\u003etimer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt()\nto finish, and that callback still reads q-\u003etimer (via snd_seq_check_queue()),\nso q-\u003etimer must stay valid until it drains."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through ioctls on the local character device /dev/snd/seq (SNDRV_SEQ_IOCTL_CREATE_QUEUE/DELETE_QUEUE/SET_QUEUE_CLIENT); no network or adjacent-network path exists to the ALSA sequencer.\nAC:L - The attacker controls both sides of the race \u2014 one thread deletes the queue while another spins on SET_QUEUE_CLIENT holding a queueptr() reference \u2014 and can retry the loop indefinitely on a default kernel with CONFIG_SND_SEQUENCER, so the window is reliably hit.\nPR:L - Only an unprivileged local user able to open /dev/snd/seq is needed; snd_seq_queue_use() performs no owner or access check and no capability is required, as the fix commit states explicitly.\nUI:N - The attacker\u0027s own threads create, delete and re-use the queue and the global system timer fires on its own; no victim action is involved.\nS:U - The use-after-free corrupts kernel heap objects within the same kernel security authority, giving at most kernel privilege escalation rather than crossing a VM, IOMMU or sandbox boundary.\nC:H - The stale timer instance dereferences the freed snd_seq_queue and snd_seq_timer, reading tick/time fields and freed prioq pointers that can be reclaimed by attacker-sprayed objects, giving a route to disclose arbitrary kernel memory.\nI:H - snd_seq_timer_interrupt() writes cur_time, tick and last_update into the freed snd_seq_timer slab and snd_seq_check_queue() dispatches events through freed queue pointers, yielding a controllable write primitive on reclaimed heap memory suitable for privilege escalation.\nA:H - Even unexploited, the timer callback derefs freed memory and takes a spinlock in a freed object from interrupt context, causing oops, lock corruption or panic \u2014 a repeatable denial of service for any local user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:08.116Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b7feeaca1f53b10df9b4de9eaf611767ca70dc92"
},
{
"url": "https://git.kernel.org/stable/c/7478ef94b49bc9789cf1a003deec58b42283dde4"
},
{
"url": "https://git.kernel.org/stable/c/9d9be6fc30f384f92c4e1b8ed40bd9d4796b7833"
},
{
"url": "https://git.kernel.org/stable/c/fb40d03ed792a8a8bf77aa0ee15df57b0ff78b07"
},
{
"url": "https://git.kernel.org/stable/c/24f0cabf173539f048946c8fc221131dc221f277"
},
{
"url": "https://git.kernel.org/stable/c/6a10025c7fd09a7d2af37a3ae1da188569fce470"
},
{
"url": "https://git.kernel.org/stable/c/31a6163e301d832060f8236f1ed17cbc1ca198df"
},
{
"url": "https://git.kernel.org/stable/c/2c4dc0ed50b05cd847a4b34b8cebf0775f19aeb9"
}
],
"title": "ALSA: seq: close a re-opened queue timer in the destructor",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68202",
"datePublished": "2026-08-10T12:00:21.279Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-23T12:46:08.116Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53366 (GCVE-0-2026-53366)
Vulnerability from cvelistv5
Published
2026-07-16 05:13
Modified
2026-08-17 04:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: account for fraggap on the paged allocation path
In __ip_append_data(), when the paged-allocation branch is taken,
alloclen and pagedlen are computed as
alloclen = fragheaderlen + transhdrlen;
pagedlen = datalen - transhdrlen;
datalen already includes fraggap, but the fraggap bytes carried over
from the previous skb are copied into the new skb's linear area at
offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The
linear area is therefore undersized by fraggap bytes while pagedlen is
overstated by the same amount.
The non-paged branch sets alloclen to fraglen, which already accounts
for fraggap because datalen does. Bring the paged branch in line by
adding fraggap to alloclen and subtracting it from pagedlen.
After this adjustment, copy no longer collapses to -fraggap on the
paged path, so remove the stale comment describing that old arithmetic.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8eb77cc73977d88787b37c92831b1c242e035396 Version: 8eb77cc73977d88787b37c92831b1c242e035396 Version: 8eb77cc73977d88787b37c92831b1c242e035396 Version: 8eb77cc73977d88787b37c92831b1c242e035396 Version: 8eb77cc73977d88787b37c92831b1c242e035396 Version: 8eb77cc73977d88787b37c92831b1c242e035396 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/ip_output.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5c6375bced6147ec2e460ee3b653f4860d5ecdc2",
"status": "affected",
"version": "8eb77cc73977d88787b37c92831b1c242e035396",
"versionType": "git"
},
{
"lessThan": "ce494707a9c07f27c219ca67f3e138061f53d9b3",
"status": "affected",
"version": "8eb77cc73977d88787b37c92831b1c242e035396",
"versionType": "git"
},
{
"lessThan": "a9c24eda24bd15f432e37824e6fc440977cb241c",
"status": "affected",
"version": "8eb77cc73977d88787b37c92831b1c242e035396",
"versionType": "git"
},
{
"lessThan": "77798d7be6ef71e72fb6fc8a2901bf74ebc9706f",
"status": "affected",
"version": "8eb77cc73977d88787b37c92831b1c242e035396",
"versionType": "git"
},
{
"lessThan": "c04d9ece23deb9e26c19f9ca215e98b3295aa1bb",
"status": "affected",
"version": "8eb77cc73977d88787b37c92831b1c242e035396",
"versionType": "git"
},
{
"lessThan": "eca856950f7cb1a221e02b99d758409f2c5cec42",
"status": "affected",
"version": "8eb77cc73977d88787b37c92831b1c242e035396",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/ip_output.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: account for fraggap on the paged allocation path\n\nIn __ip_append_data(), when the paged-allocation branch is taken,\nalloclen and pagedlen are computed as\n\n\talloclen = fragheaderlen + transhdrlen;\n\tpagedlen = datalen - transhdrlen;\n\ndatalen already includes fraggap, but the fraggap bytes carried over\nfrom the previous skb are copied into the new skb\u0027s linear area at\noffset transhdrlen by the subsequent skb_copy_and_csum_bits(). The\nlinear area is therefore undersized by fraggap bytes while pagedlen is\noverstated by the same amount.\n\nThe non-paged branch sets alloclen to fraglen, which already accounts\nfor fraggap because datalen does. Bring the paged branch in line by\nadding fraggap to alloclen and subtracting it from pagedlen.\n\nAfter this adjustment, copy no longer collapses to -fraggap on the\npaged path, so remove the stale comment describing that old arithmetic."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached while a local process constructs outgoing IPv4 UDP/raw/ping datagrams through sendmsg/splice/sendfile-style socket paths. I did not find a defensible received-packet or unauthenticated remote path that supplies the required cork/MSG_MORE-style fraggap conditions.\nAC:L - The attacker can choose UDP socket options/flags, payload sizes, corking/MSG_MORE behavior, and splice/zerocopy-style paged sends to reach the fraggap paged-allocation path. There is no race or external timing condition required.\nPR:L - A normal unprivileged local user can create IPv4 UDP sockets and use UDP_CORK/MSG_MORE/splice or related paged send paths; raw sockets are CAP_NET_RAW-gated but are not needed for the strongest local trigger. This is therefore basic local user privilege, not real administrator privilege.\nUI:N - No victim interaction is required once the attacker can run the local send/splice sequence. The vulnerable skb construction happens synchronously in the attacker-driven socket send path.\nS:U - The impact is within the same kernel security authority as the vulnerable IPv4 networking code. This is not a VM escape, IOMMU bypass, or cross-authority boundary violation.\nC:H - The bug under-allocates/accounting for the linear skb area and can copy attacker-controlled fraggap bytes past skb-\u003eend into trailing skb_shared_info metadata. Kernel memory corruption of this kind is reasonably capable of being developed into information disclosure, so the higher severity confidentiality value is appropriate.\nI:H - The copied fraggap bytes corrupt kernel skb metadata past the intended buffer boundary. This is an out-of-bounds write in kernel heap/networking structures and is scored as high integrity impact.\nA:H - The corrupted skb metadata can crash or destabilize the kernel networking stack, and related negative-copy accounting can also produce severe send-path failure behavior. Kernel crash or oops potential is high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:50:30.453Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5c6375bced6147ec2e460ee3b653f4860d5ecdc2"
},
{
"url": "https://git.kernel.org/stable/c/ce494707a9c07f27c219ca67f3e138061f53d9b3"
},
{
"url": "https://git.kernel.org/stable/c/a9c24eda24bd15f432e37824e6fc440977cb241c"
},
{
"url": "https://git.kernel.org/stable/c/77798d7be6ef71e72fb6fc8a2901bf74ebc9706f"
},
{
"url": "https://git.kernel.org/stable/c/c04d9ece23deb9e26c19f9ca215e98b3295aa1bb"
},
{
"url": "https://git.kernel.org/stable/c/eca856950f7cb1a221e02b99d758409f2c5cec42"
}
],
"title": "ipv4: account for fraggap on the paged allocation path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53366",
"datePublished": "2026-07-16T05:13:40.893Z",
"dateReserved": "2026-06-09T07:44:35.400Z",
"dateUpdated": "2026-08-17T04:50:30.453Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68392 (GCVE-0-2026-68392)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
Dereferencing RCU-protected pointers outside critical sections is
invalid and may lead to UAF.
Take hdev->lock for hci_conn lookup and hci_abort_conn(). Don't use RCU
to ensure the conn is fully initialized at this point.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7fe4d391e937c2f048a43ff4b421e677f10d83c0 Version: 249c88e7fb45b6b705040c5af4bd0d0f2bc9735c Version: 227a0cdf4a028a73dc256d0f5144b4808d718893 Version: 227a0cdf4a028a73dc256d0f5144b4808d718893 Version: 227a0cdf4a028a73dc256d0f5144b4808d718893 Version: 227a0cdf4a028a73dc256d0f5144b4808d718893 Version: 58afdc9b18871eb1d461c725be9e9f3f44a39aeb Version: 6.6.51 ≤ Version: 6.10.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "74f3e6e21ebc6c418d348f8ce68aef6fe6d82c82",
"status": "affected",
"version": "7fe4d391e937c2f048a43ff4b421e677f10d83c0",
"versionType": "git"
},
{
"lessThan": "8bc83f9ef6789571f399ff631a2a14a12b6d8585",
"status": "affected",
"version": "249c88e7fb45b6b705040c5af4bd0d0f2bc9735c",
"versionType": "git"
},
{
"lessThan": "579faba5ede6df6b7f36777c431dc8dcf9d272e7",
"status": "affected",
"version": "227a0cdf4a028a73dc256d0f5144b4808d718893",
"versionType": "git"
},
{
"lessThan": "ca58ad287bfc5b9d31a72ecb8650289df2b57250",
"status": "affected",
"version": "227a0cdf4a028a73dc256d0f5144b4808d718893",
"versionType": "git"
},
{
"lessThan": "b11511006f9e17000de3f4cadee451364f658ca3",
"status": "affected",
"version": "227a0cdf4a028a73dc256d0f5144b4808d718893",
"versionType": "git"
},
{
"lessThan": "16cd66443957e4ad42155c6fec401012f600c6f8",
"status": "affected",
"version": "227a0cdf4a028a73dc256d0f5144b4808d718893",
"versionType": "git"
},
{
"status": "affected",
"version": "58afdc9b18871eb1d461c725be9e9f3f44a39aeb",
"versionType": "git"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.51",
"versionType": "semver"
},
{
"lessThan": "6.11",
"status": "affected",
"version": "6.10.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.51",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.10.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: mgmt: fix locking in unpair_device/disconnect_sync\n\nDereferencing RCU-protected pointers outside critical sections is\ninvalid and may lead to UAF.\n\nTake hdev-\u003elock for hci_conn lookup and hci_abort_conn(). Don\u0027t use RCU\nto ensure the conn is fully initialized at this point."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is entered by a local process sending MGMT_OP_DISCONNECT/MGMT_OP_UNPAIR_DEVICE on an AF_BLUETOOTH/BTPROTO_HCI socket bound to HCI_CHANNEL_CONTROL, and the freeing side is drivable locally via /dev/vhci events or ioctl(HCIDEVDOWN)/hci_conn_hash_flush; no over-the-air access is required.\nAC:L - The attacker controls both sides of the race \u2014 repeatedly queuing the mgmt command while tearing the connection down (vhci-injected disconnect-complete, HCIDEVDOWN, or connection timeout) \u2014 and can retry indefinitely, so the window is reached reliably.\nPR:L - The mgmt command needs a trusted control socket, but that capability is routinely held by the Bluetooth daemon and exposed to unprivileged session users through BlueZ Disconnect/RemoveDevice D-Bus methods, so an ordinary local user can drive the path with attacker-chosen addresses.\nUI:N - Both the mgmt command and the concurrent connection teardown are initiated programmatically by the attacker; no victim action such as pairing confirmation or opening a file is needed.\nS:U - The corruption is confined to kernel heap objects managed by the Bluetooth subsystem within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - hci_abort_conn() dereferences the freed hci_conn (conn-\u003ehdev, conn-\u003eabort_reason, conn-\u003ehandle) after it has been unlinked and released, so an attacker who reclaims the slab with controlled data obtains a read primitive over kernel memory and can leak pointers.\nI:H - The use-after-free is not read-only: hci_abort_conn() stores the attacker-reachable reason byte into conn-\u003eabort_reason and hci_conn_get() increments a refcount inside the freed object, giving a write primitive into reclaimed heap memory that is leverageable for control-flow hijack.\nA:H - Dereferencing a freed or partially initialized hci_conn and then queuing abort_conn_sync on it produces slab-use-after-free oopses, refcount underflow, and kernel panics, crashing the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:21.017Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/74f3e6e21ebc6c418d348f8ce68aef6fe6d82c82"
},
{
"url": "https://git.kernel.org/stable/c/8bc83f9ef6789571f399ff631a2a14a12b6d8585"
},
{
"url": "https://git.kernel.org/stable/c/579faba5ede6df6b7f36777c431dc8dcf9d272e7"
},
{
"url": "https://git.kernel.org/stable/c/ca58ad287bfc5b9d31a72ecb8650289df2b57250"
},
{
"url": "https://git.kernel.org/stable/c/b11511006f9e17000de3f4cadee451364f658ca3"
},
{
"url": "https://git.kernel.org/stable/c/16cd66443957e4ad42155c6fec401012f600c6f8"
}
],
"title": "Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68392",
"datePublished": "2026-08-10T12:04:11.543Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-23T12:46:21.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68259 (GCVE-0-2026-68259)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Check bounds in allocate_event_notification_slot
The valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT
allocate_event_notification_slot has an option to specify
an event id to allocate at, used by CRIU. We weren't checking
the bounds on that value.
Check them.
v2: Lower bounds check is unecessary because of idr_alloc
already rejecting negative numbers. Upper bounds check should
be KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might
not yet exist
(cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6884fc142b17f456caac50c14505f509bfbcd012",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "85eedff5f0c4aba5a66bc37a1bd6bcecd0d77b53",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "4622214f0542f64b02c250db0f9c677eeb032d9b",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "50319efb865f72db45f191c8709511746d58ee0a",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "abeeb1947d81610c65349db4d89c6151f270e136",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "bb52249fbbe948875155ccd45cd8d74bf4ae747b",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Check bounds in allocate_event_notification_slot\n\nThe valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT\n\nallocate_event_notification_slot has an option to specify\nan event id to allocate at, used by CRIU. We weren\u0027t checking\nthe bounds on that value.\n\nCheck them.\n\nv2: Lower bounds check is unecessary because of idr_alloc\nalready rejecting negative numbers. Upper bounds check should\nbe KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might\nnot yet exist\n\n(cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:28.586Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6884fc142b17f456caac50c14505f509bfbcd012"
},
{
"url": "https://git.kernel.org/stable/c/85eedff5f0c4aba5a66bc37a1bd6bcecd0d77b53"
},
{
"url": "https://git.kernel.org/stable/c/4622214f0542f64b02c250db0f9c677eeb032d9b"
},
{
"url": "https://git.kernel.org/stable/c/50319efb865f72db45f191c8709511746d58ee0a"
},
{
"url": "https://git.kernel.org/stable/c/abeeb1947d81610c65349db4d89c6151f270e136"
},
{
"url": "https://git.kernel.org/stable/c/bb52249fbbe948875155ccd45cd8d74bf4ae747b"
}
],
"title": "drm/amdkfd: Check bounds in allocate_event_notification_slot",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68259",
"datePublished": "2026-08-10T12:01:33.110Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-19T16:32:28.586Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64222 (GCVE-0-2026-64222)
Vulnerability from cvelistv5
Published
2026-07-24 15:23
Modified
2026-08-05 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: avoid double free of pool->stack on AQ init failure
otx2_pool_aq_init() frees pool->stack when mailbox sync or retry
allocation fails, but leaves the pointer unchanged. Later,
otx2_sq_aura_pool_init() unwinds the partial setup through
otx2_aura_pool_free(), which frees pool->stack again. The CN20K-specific
cn20k_pool_aq_init() implementation has the same bug in
its corresponding error path.
Set pool->stack to NULL immediately after the local free so the shared
cleanup path does not free the same stack again while cleaning up
partially initialized pool state.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still present in
v7.1-rc3.
Runtime validation was not performed because reproducing this path
requires OcteonTX2/CN20K hardware.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/nic/cn20k.c",
"drivers/net/ethernet/marvell/octeontx2/nic/otx2_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e6e9bc0bf963662b7042048ab0281014625d4cb4",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "b92e7ea408b6f1144648909c9c49a55d245d7300",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "94192b0579333c3deee2441379aab8ca98fc2e6b",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "4c29603498b05c049dbbbc47e882f2fbf0193cd7",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "0488a0bb344fb1992853b60082acff6be8164d74",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "0d9b9d7dbef976ae7f855b6358f1d703014e96ea",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "c4b8c5d51632538b19ee01cf6d70cbceeefbd3ec",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "9b244c242bec48b37e82b89787afd6a4c43457e1",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/nic/cn20k.c",
"drivers/net/ethernet/marvell/octeontx2/nic/otx2_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: avoid double free of pool-\u003estack on AQ init failure\n\notx2_pool_aq_init() frees pool-\u003estack when mailbox sync or retry\nallocation fails, but leaves the pointer unchanged. Later,\notx2_sq_aura_pool_init() unwinds the partial setup through\notx2_aura_pool_free(), which frees pool-\u003estack again. The CN20K-specific\ncn20k_pool_aq_init() implementation has the same bug in\nits corresponding error path.\n\nSet pool-\u003estack to NULL immediately after the local free so the shared\ncleanup path does not free the same stack again while cleaning up\npartially initialized pool state.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still present in\nv7.1-rc3.\n\nRuntime validation was not performed because reproducing this path\nrequires OcteonTX2/CN20K hardware."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable initialization is reached through local netdevice operations such as RTM_SETLINK or ethtool reconfiguration, ultimately invoking ndo_open; received network packets do not directly reach it.\nAC:H - The attacker can fill the fixed mailbox by configuring many queues, but exploitation additionally requires an AF/NPA synchronization error or timeout. Legitimate mailbox users are serialized, so this failure is not reliably attacker-controlled.\nPR:L - CAP_NET_ADMIN is required in the device\u0027s owning network namespace. OcteonTX2 VFs can reasonably be delegated to a user-owned network namespace, where namespace-level administration suffices without initial-namespace root.\nUI:N - The attacker can initiate the interface-open or reconfiguration operation directly, without action by another user.\nS:U - The double free corrupts the kernel managing the affected PF or VF but does not inherently cross a VM, IOMMU, or separate security-authority boundary.\nC:H - The repeated release of coherent DMA pages can create overlapping allocations, while the stale qmem object can also be reclaimed and its DMA metadata influenced. This memory corruption can plausibly expose arbitrary kernel memory.\nI:H - Double-freeing DMA-backed pages can corrupt the page allocator and produce overlapping ownership, enabling arbitrary kernel-memory modification or control-flow hijacking.\nA:H - The double DMA/page release can immediately cause allocator warnings, an oops, or a kernel panic, and corrupted allocator state can crash the system later."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:40:09.522Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e6e9bc0bf963662b7042048ab0281014625d4cb4"
},
{
"url": "https://git.kernel.org/stable/c/b92e7ea408b6f1144648909c9c49a55d245d7300"
},
{
"url": "https://git.kernel.org/stable/c/94192b0579333c3deee2441379aab8ca98fc2e6b"
},
{
"url": "https://git.kernel.org/stable/c/4c29603498b05c049dbbbc47e882f2fbf0193cd7"
},
{
"url": "https://git.kernel.org/stable/c/0488a0bb344fb1992853b60082acff6be8164d74"
},
{
"url": "https://git.kernel.org/stable/c/0d9b9d7dbef976ae7f855b6358f1d703014e96ea"
},
{
"url": "https://git.kernel.org/stable/c/c4b8c5d51632538b19ee01cf6d70cbceeefbd3ec"
},
{
"url": "https://git.kernel.org/stable/c/9b244c242bec48b37e82b89787afd6a4c43457e1"
}
],
"title": "octeontx2-pf: avoid double free of pool-\u003estack on AQ init failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64222",
"datePublished": "2026-07-24T15:23:08.072Z",
"dateReserved": "2026-07-19T15:36:31.770Z",
"dateUpdated": "2026-08-05T12:40:09.522Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64500 (GCVE-0-2026-64500)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: lpc32xx: Initialize completion before requesting IRQ
In the report from Jaeyoung Chung:
"lpc32xx_adc_probe() in drivers/iio/adc/lpc32xx_adc.c registers its
interrupt handler with devm_request_irq() before it initializes
st->completion with init_completion(). If an interrupt arrives after
devm_request_irq() and before init_completion(), the handler calls
complete() on an uninitialized completion, causing a kernel panic.
The probe path, in lpc32xx_adc_probe():
iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */
...
retval = devm_request_irq(&pdev->dev, irq, lpc32xx_adc_isr, 0,
LPC32XXAD_NAME, st); /* register handler */
...
init_completion(&st->completion); /* initialize completion */
lpc32xx_adc_isr() calls complete():
complete(&st->completion);
If the device raises an interrupt before init_completion() runs,
complete() acquires the uninitialized wait.lock and walks the zeroed
task_list in swake_up_locked(). The zeroed task_list makes list_empty()
return false, so swake_up_locked() dereferences a NULL list entry,
triggering a KASAN wild-memory-access."
Fix the chance of a spurious IRQ causing an uninitialized pointer
dereference by moving init_completion() above devm_request_irq().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7901b2a1453e48c9defff2c97c67d3089bf4df7a Version: 7901b2a1453e48c9defff2c97c67d3089bf4df7a Version: 7901b2a1453e48c9defff2c97c67d3089bf4df7a Version: 7901b2a1453e48c9defff2c97c67d3089bf4df7a Version: 7901b2a1453e48c9defff2c97c67d3089bf4df7a Version: 7901b2a1453e48c9defff2c97c67d3089bf4df7a Version: 7901b2a1453e48c9defff2c97c67d3089bf4df7a Version: 7901b2a1453e48c9defff2c97c67d3089bf4df7a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iio/adc/lpc32xx_adc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7090c0d29708ee305022d0ea7b37612b33242fa2",
"status": "affected",
"version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
"versionType": "git"
},
{
"lessThan": "0e33587967b356519aa6f220b5b43c6976320397",
"status": "affected",
"version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
"versionType": "git"
},
{
"lessThan": "1ddf7b6ffb8ebb22b92a184a9eaa76277ef0c7cd",
"status": "affected",
"version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
"versionType": "git"
},
{
"lessThan": "820c4f15353efe9a9429ae86ccceeaf4e0e4e585",
"status": "affected",
"version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
"versionType": "git"
},
{
"lessThan": "48eccc6caed4e62c0f199ab3a3772fa969cd3b2d",
"status": "affected",
"version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
"versionType": "git"
},
{
"lessThan": "9e2e8b8cdfd37ae7c7a8a5c96c59e98a768731c4",
"status": "affected",
"version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
"versionType": "git"
},
{
"lessThan": "2f18c5551aa97ca7f39dbb151c67c9053ccadc17",
"status": "affected",
"version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
"versionType": "git"
},
{
"lessThan": "e561b35633f450ee607e87a6401d97f156a0cd54",
"status": "affected",
"version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iio/adc/lpc32xx_adc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: lpc32xx: Initialize completion before requesting IRQ\n\nIn the report from Jaeyoung Chung:\n\n\"lpc32xx_adc_probe() in drivers/iio/adc/lpc32xx_adc.c registers its\ninterrupt handler with devm_request_irq() before it initializes\nst-\u003ecompletion with init_completion(). If an interrupt arrives after\ndevm_request_irq() and before init_completion(), the handler calls\ncomplete() on an uninitialized completion, causing a kernel panic.\n\nThe probe path, in lpc32xx_adc_probe():\n\n iodev = devm_iio_device_alloc(\u0026pdev-\u003edev, sizeof(*st)); /* st kzalloc-zeroed */\n ...\n retval = devm_request_irq(\u0026pdev-\u003edev, irq, lpc32xx_adc_isr, 0,\n LPC32XXAD_NAME, st); /* register handler */\n ...\n init_completion(\u0026st-\u003ecompletion); /* initialize completion */\n\nlpc32xx_adc_isr() calls complete():\n\n complete(\u0026st-\u003ecompletion);\n\nIf the device raises an interrupt before init_completion() runs,\ncomplete() acquires the uninitialized wait.lock and walks the zeroed\ntask_list in swake_up_locked(). The zeroed task_list makes list_empty()\nreturn false, so swake_up_locked() dereferences a NULL list entry,\ntriggering a KASAN wild-memory-access.\"\n\nFix the chance of a spurious IRQ causing an uninitialized pointer\ndereference by moving init_completion() above devm_request_irq()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:49.966Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7090c0d29708ee305022d0ea7b37612b33242fa2"
},
{
"url": "https://git.kernel.org/stable/c/0e33587967b356519aa6f220b5b43c6976320397"
},
{
"url": "https://git.kernel.org/stable/c/1ddf7b6ffb8ebb22b92a184a9eaa76277ef0c7cd"
},
{
"url": "https://git.kernel.org/stable/c/820c4f15353efe9a9429ae86ccceeaf4e0e4e585"
},
{
"url": "https://git.kernel.org/stable/c/48eccc6caed4e62c0f199ab3a3772fa969cd3b2d"
},
{
"url": "https://git.kernel.org/stable/c/9e2e8b8cdfd37ae7c7a8a5c96c59e98a768731c4"
},
{
"url": "https://git.kernel.org/stable/c/2f18c5551aa97ca7f39dbb151c67c9053ccadc17"
},
{
"url": "https://git.kernel.org/stable/c/e561b35633f450ee607e87a6401d97f156a0cd54"
}
],
"title": "iio: adc: lpc32xx: Initialize completion before requesting IRQ",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64500",
"datePublished": "2026-07-25T08:51:56.053Z",
"dateReserved": "2026-07-19T15:36:31.793Z",
"dateUpdated": "2026-08-17T04:56:49.966Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68210 (GCVE-0-2026-68210)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: stm32: dcmi: unregister notifier on probe failure
dcmi_graph_init() registers the async notifier before dcmi_probe() toggles
the reset line. If reset_control_assert() or reset_control_deassert()
fails afterwards, probe returns through err_cleanup and the driver core
will not call dcmi_remove().
Unregister the notifier before cleaning it up on that error path,
matching the successful remove path and the V4L2 async notifier lifetime
rules.
[hverkuil: added Fixes tag]
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/st/stm32/stm32-dcmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "222a9301b086852b90d3b092fef436c3f4e927c4",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "37ff63c5d7119cbc5c6bacdcc658add6008a8e1f",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "6c6f22b7e6cbc4e8c1e359fc9b190419391c3db7",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "931abe1deb65b919d23fa203d7f6d6fbd4fccd8e",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "4b7ee504969e074725e439c949f2483e5fa5572a",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "084973ebd67b28f0945c5d45408f86c58b540110",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/st/stm32/stm32-dcmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: stm32: dcmi: unregister notifier on probe failure\n\ndcmi_graph_init() registers the async notifier before dcmi_probe() toggles\nthe reset line. If reset_control_assert() or reset_control_deassert()\nfails afterwards, probe returns through err_cleanup and the driver core\nwill not call dcmi_remove().\n\nUnregister the notifier before cleaning it up on that error path,\nmatching the successful remove path and the V4L2 async notifier lifetime\nrules.\n\n[hverkuil: added Fixes tag]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The affected code is a platform camera-interface driver probe path on STM32 SoCs; it is reached only through local device/driver binding on the machine itself, with the resulting dangling notifier consumed by in-kernel V4L2 subdev registration. No network or remote data path reaches this code.\nAC:L - Once the driver has probe-failed on the reset line, the stale notifier remains on the global v4l2 notifier_list indefinitely, and any subsequent subdev registration deterministically walks the freed object; no race or unpredictable memory layout must be won to reach the freed dereference.\nPR:L - A local user account on the device is sufficient to interact with the media/V4L2 stack and trigger subdev registration paths that walk the corrupted global notifier list; no root or administrative capability is needed to consume the dangling pointer.\nUI:N - The stale notifier is left behind automatically by the failing probe path and is dereferenced by kernel-internal V4L2 async registration; no victim action such as opening a file or mounting a filesystem is required.\nS:U - The freed memory, the corrupted list, and the resulting impact are all within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The devm-allocated stm32_dcmi object containing the notifier is freed while still linked into the global notifier_list, so reallocated heap contents are read back as notifier state and traversed as list pointers, which can be leveraged to disclose kernel memory.\nI:H - Traversal and eventual list_del of the freed notifier_entry performs writes through attacker-influenceable heap contents, giving a use-after-free list-corruption primitive that can be shaped into an arbitrary write and control-flow hijack.\nA:H - Dereferencing and unlinking a freed notifier from the global list reliably produces list corruption and an oops or panic in the V4L2 async core, taking down the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:34.517Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/222a9301b086852b90d3b092fef436c3f4e927c4"
},
{
"url": "https://git.kernel.org/stable/c/37ff63c5d7119cbc5c6bacdcc658add6008a8e1f"
},
{
"url": "https://git.kernel.org/stable/c/6c6f22b7e6cbc4e8c1e359fc9b190419391c3db7"
},
{
"url": "https://git.kernel.org/stable/c/931abe1deb65b919d23fa203d7f6d6fbd4fccd8e"
},
{
"url": "https://git.kernel.org/stable/c/4b7ee504969e074725e439c949f2483e5fa5572a"
},
{
"url": "https://git.kernel.org/stable/c/084973ebd67b28f0945c5d45408f86c58b540110"
}
],
"title": "media: stm32: dcmi: unregister notifier on probe failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68210",
"datePublished": "2026-08-10T12:00:29.515Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:34.517Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68470 (GCVE-0-2026-68470)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-17 05:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: validate extension-frame layout before RX
Extension frames only have the extension header at the regular 802.11
header offset. The generic RX path can still reach helpers and interface
dispatch code that read regular header address fields before unsupported
extension subtypes are dropped.
mac80211 currently only handles S1G beacon extension frames. Drop other
extension subtypes before they can reach regular-header RX processing.
For S1G beacons, linearize the SKB with the management-frame path and
require the fixed S1G beacon header, including optional fixed fields
indicated by frame control, before generic RX dispatch.
Route S1G beacons through the station/default-link RX path without
regular-header station lookup. Avoid regular-header address reads in the
mac80211 RX paths that process S1G extension beacons, including
accept-frame, duplicate-detection, address-copy, and MLO
address-translation paths.
Also make ieee80211_get_bssid() length-safe before returning the S1G
source-address pointer.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/rx.c",
"net/mac80211/util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "625fc704b19cb48d7d269ad54ffffb4d3bf9c7ed",
"status": "affected",
"version": "09a740ce352e1a1d16b9984115514ba9a4f4704b",
"versionType": "git"
},
{
"lessThan": "57d503ce32eccfa7650065ca4c560f7e29a2e676",
"status": "affected",
"version": "09a740ce352e1a1d16b9984115514ba9a4f4704b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/rx.c",
"net/mac80211/util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: validate extension-frame layout before RX\n\nExtension frames only have the extension header at the regular 802.11\nheader offset. The generic RX path can still reach helpers and interface\ndispatch code that read regular header address fields before unsupported\nextension subtypes are dropped.\n\nmac80211 currently only handles S1G beacon extension frames. Drop other\nextension subtypes before they can reach regular-header RX processing.\nFor S1G beacons, linearize the SKB with the management-frame path and\nrequire the fixed S1G beacon header, including optional fixed fields\nindicated by frame control, before generic RX dispatch.\n\nRoute S1G beacons through the station/default-link RX path without\nregular-header station lookup. Avoid regular-header address reads in the\nmac80211 RX paths that process S1G extension beacons, including\naccept-frame, duplicate-detection, address-copy, and MLO\naddress-translation paths.\n\nAlso make ieee80211_get_bssid() length-safe before returning the S1G\nsource-address pointer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Malformed 802.11 extension/S1G frames reach mac80211 via the normal WiFi RX path (driver -\u003e ieee80211_rx_list -\u003e __ieee80211_rx_handle_packet); an attacker within radio range can inject frames over the air without routing through the Internet.\nAC:L - The attacker fully controls crafted extension-frame length, subtype, and frame-control flags; only 4 bytes are validated before code reads up to 24 bytes of presumed 802.11 addresses, so triggering the bug is reliable and does not depend on victim-specific timing or memory layout.\nPR:N - Exploitation requires only transmitting WiFi frames to a victim with an active mac80211 interface; no local account, capability, or association/authentication is needed because vulnerable header parsing runs before extension subtype filtering and RX handler dispatch.\nUI:N - The victim does not need to click links, join networks, or perform any deliberate action beyond having WiFi enabled; passive reception of attacker-injected extension frames on AP, STA, or mesh interfaces is sufficient to reach the vulnerable code.\nS:U - Impact is confined to kernel mac80211 RX processing on the receiving host (OOB skb reads/writes and possible crash/privilege escalation); it does not cross a VM, container, or IOMMU security boundary into another authority.\nC:H - Pre-fix code reads regular-header addr1/addr2/addr3/seq_ctrl and copies 18 bytes of addrs on extension frames whose layout differs and may be shorter than 24 bytes, causing out-of-bounds reads and disclosure of adjacent skb/heap memory via ieee80211_get_bssid(), accept-frame, duplicate detection, and MLO prep paths.\nI:H - ieee80211_prepare_and_rx_handle can perform ether_addr_copy() MLO address translation on S1G/extension frames because ieee80211_is_beacon() is false for FTYPE_EXT, writing attacker-influenced MAC bytes into wrong skb offsets and enabling memory corruption that could be developed into arbitrary kernel write/code execution.\nA:H - Out-of-bounds access while parsing short or malformed extension frames can provoke kernel oops/panic or destabilize RX processing; even failed exploitation still enables repeatable remote DoS against any reachable WiFi interface by retransmitting malicious extension frames."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:39:12.948Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/625fc704b19cb48d7d269ad54ffffb4d3bf9c7ed"
},
{
"url": "https://git.kernel.org/stable/c/57d503ce32eccfa7650065ca4c560f7e29a2e676"
}
],
"title": "wifi: mac80211: validate extension-frame layout before RX",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68470",
"datePublished": "2026-08-15T05:51:28.211Z",
"dateReserved": "2026-07-30T09:28:09.396Z",
"dateUpdated": "2026-08-17T05:39:12.948Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64548 (GCVE-0-2026-64548)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
When the scatterlist ring is full or nearly full, bpf_msg_push_data()
enters a copy fallback path and computes copy + len for the page
allocation size. Since len comes from BPF with arg3_type = ARG_ANYTHING
and both are u32, a crafted len can wrap the sum to a small value,
causing an undersized allocation followed by an out-of-bounds memcpy.
BUG: unable to handle page fault for address: ffffed104089a402
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
Call Trace:
__asan_memcpy (mm/kasan/shadow.c:105)
bpf_msg_push_data (net/core/filter.c:2852 net/core/filter.c:2788)
bpf_prog_9ed8b5711920a7d7+0x2e/0x36
sk_psock_msg_verdict (net/core/skmsg.c:934)
tcp_bpf_sendmsg (net/ipv4/tcp_bpf.c:421 net/ipv4/tcp_bpf.c:584)
__sys_sendto (net/socket.c:2206)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
Add an overflow check before the allocation.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f1644c9508d24f50dd9e8ebe8d3ba86e0996d2f5",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "a12b1575f9feabd91695a9e9d004862f7195fa25",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "ff39d0e3b4feeb65ca43c453d7c75fdf872ded0d",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "888706a76286c547bd035432602571e8024b5305",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "db77b6bb6e6edb79b10b4efcce346eec5582d588",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "4e40056bb5c829f0423f0a6694a0477726d2147e",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "bd004716ba75fed6d185795c85cdc92540ebeaab",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "0c0a8ed85349dae298712d79cb276acfeb794d82",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()\n\nWhen the scatterlist ring is full or nearly full, bpf_msg_push_data()\nenters a copy fallback path and computes copy + len for the page\nallocation size. Since len comes from BPF with arg3_type = ARG_ANYTHING\nand both are u32, a crafted len can wrap the sum to a small value,\ncausing an undersized allocation followed by an out-of-bounds memcpy.\n\n BUG: unable to handle page fault for address: ffffed104089a402\n Oops: Oops: 0000 [#1] SMP KASAN NOPTI\n Call Trace:\n __asan_memcpy (mm/kasan/shadow.c:105)\n bpf_msg_push_data (net/core/filter.c:2852 net/core/filter.c:2788)\n bpf_prog_9ed8b5711920a7d7+0x2e/0x36\n sk_psock_msg_verdict (net/core/skmsg.c:934)\n tcp_bpf_sendmsg (net/ipv4/tcp_bpf.c:421 net/ipv4/tcp_bpf.c:584)\n __sys_sendto (net/socket.c:2206)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nAdd an overflow check before the allocation."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable helper only runs from the sk_msg egress verdict path, reached via a local `sendmsg()`/`sendto()` syscall on a sockmap- or kTLS-attached socket (`tcp_bpf_sendmsg` \u2192 `sk_psock_msg_verdict`, `tls_sw_sendmsg`), as shown in the reported call trace. There is no remote-peer input path into `bpf_msg_push_data()`.\nAC:L - Both trigger conditions are fully attacker-controlled and deterministic: the copy-fallback path is forced by sending \u2265 MAX_SKB_FRAGS*PAGE_SIZE bytes in one sendmsg to fill the SG ring, and the wrapping `len` is a constant chosen by the sk_msg program. No race, timing window, or uncontrolled memory state is involved.\nPR:N - The act that triggers the corruption \u2014 `sendmsg()` on a socket already in the sockmap \u2014 requires no privileges whatsoever, and the same helper\u0027s prior flaw (CVE-2026-63926) was scored PR:N on this basis. `ARG_ANYTHING` means the verifier enforces no bound, so a deployed L7-proxy sk_msg program that derives `len` from message content (e.g. a signed `want - have` underflowing to a huge u32) hands the wrapping value to the kernel without any attacker privilege; where program authorship is needed, CAP_BPF+CAP_NET_ADMIN is delegable to unprivileged container users via a bpffs BPF token.\nUI:N - Exploitation is entirely driven by the attacker\u0027s own socket writes and BPF program; no victim action, mount, or file access is required.\nS:U - The undersized allocation and out-of-bounds write corrupt kernel memory within the same security authority as the vulnerable code. No VM, IOMMU, or hypervisor boundary is crossed.\nC:H - The wild-offset write plus the corrupted `sg.size`/element-length/`data_end` state (huge `len` added to `sg.size` while `sg_set_page()` records the wrapped length) lets adjacent kernel memory be exposed to the BPF program and pushed out on the socket, and the write primitive is readily convertible into an arbitrary kernel read.\nI:H - `memcpy(raw + front + len, from, back)` writes up to a full SG element of attacker-supplied payload roughly 4 GiB past a single-page allocation, with the offset tunable over a ~4 MiB window and the source page groomable \u2014 an attacker-controlled write into the direct map, sufficient for control-flow hijack and privilege escalation.\nA:H - The reported reproducer is an unrecoverable oops (\"unable to handle page fault for address: ffffed104089a402\") when the wild pointer hits unmapped direct-map space, and the ~4 GiB `sk_mem_charge()`/`sg.size` accounting corruption further destabilises the socket and allocator."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:25.465Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f1644c9508d24f50dd9e8ebe8d3ba86e0996d2f5"
},
{
"url": "https://git.kernel.org/stable/c/a12b1575f9feabd91695a9e9d004862f7195fa25"
},
{
"url": "https://git.kernel.org/stable/c/ff39d0e3b4feeb65ca43c453d7c75fdf872ded0d"
},
{
"url": "https://git.kernel.org/stable/c/888706a76286c547bd035432602571e8024b5305"
},
{
"url": "https://git.kernel.org/stable/c/db77b6bb6e6edb79b10b4efcce346eec5582d588"
},
{
"url": "https://git.kernel.org/stable/c/4e40056bb5c829f0423f0a6694a0477726d2147e"
},
{
"url": "https://git.kernel.org/stable/c/bd004716ba75fed6d185795c85cdc92540ebeaab"
},
{
"url": "https://git.kernel.org/stable/c/0c0a8ed85349dae298712d79cb276acfeb794d82"
}
],
"title": "bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64548",
"datePublished": "2026-07-27T20:10:38.355Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:25.465Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-38469 (GCVE-0-2025-38469)
Vulnerability from cvelistv5
Published
2025-07-28 11:21
Modified
2026-05-11 21:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls
kvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host
for more than one event channel potr (nr_ports > 1).
After the kmalloc_array(), the error paths need to go through the
"out" label, but the call to kvm_read_guest_virt() does not.
[Adjusted commit message. - Paolo]
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/xen.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3ee59c38ae7369ad1f7b846e05633ccf0d159fab",
"status": "affected",
"version": "92c58965e9656dc6e682a8ffe520fac0fb256d13",
"versionType": "git"
},
{
"lessThan": "fd627ac8a5cff4d45269f164b13ddddc0726f2cc",
"status": "affected",
"version": "92c58965e9656dc6e682a8ffe520fac0fb256d13",
"versionType": "git"
},
{
"lessThan": "061c553c66bc1638c280739999224c8000fd4602",
"status": "affected",
"version": "92c58965e9656dc6e682a8ffe520fac0fb256d13",
"versionType": "git"
},
{
"lessThan": "5a53249d149f48b558368c5338b9921b76a12f8c",
"status": "affected",
"version": "92c58965e9656dc6e682a8ffe520fac0fb256d13",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/xen.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.100",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.15.*",
"status": "unaffected",
"version": "6.15.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.16",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.100",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.40",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15.8",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls\n\nkvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host\nfor more than one event channel potr (nr_ports \u003e 1).\n\nAfter the kmalloc_array(), the error paths need to go through the\n\"out\" label, but the call to kvm_read_guest_virt() does not.\n\n[Adjusted commit message. - Paolo]"
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T21:28:36.841Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3ee59c38ae7369ad1f7b846e05633ccf0d159fab"
},
{
"url": "https://git.kernel.org/stable/c/fd627ac8a5cff4d45269f164b13ddddc0726f2cc"
},
{
"url": "https://git.kernel.org/stable/c/061c553c66bc1638c280739999224c8000fd4602"
},
{
"url": "https://git.kernel.org/stable/c/5a53249d149f48b558368c5338b9921b76a12f8c"
}
],
"title": "KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-38469",
"datePublished": "2025-07-28T11:21:30.992Z",
"dateReserved": "2025-04-16T04:51:24.020Z",
"dateUpdated": "2026-05-11T21:28:36.841Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64148 (GCVE-0-2026-64148)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
pds_core: fix error handling in pdsc_devcmd_wait
Fix two cases where pdsc_devcmd_wait() returns stale success from
the completion register instead of an error:
1. FW crash: If firmware stops running, the wait loop breaks early with
running=false. The condition "if ((!done || timeout) && running)" is
false, so error handling is bypassed and stale status is returned.
Check !running first and return -ENXIO.
2. Timeout: If a command times out, err is set to -ETIMEDOUT but then
overwritten by pdsc_err_to_errno(status) which reads stale status.
Return -ETIMEDOUT immediately after cleaning up.
Both errors now propagate to pdsc_devcmd_locked() which queues
health_work for recovery.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/amd/pds_core/dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3231aff8ab26111c54e630b1a200fc43a729dd14",
"status": "affected",
"version": "45d76f492938cdc27ddadc16e1e75103f4cfbf56",
"versionType": "git"
},
{
"lessThan": "10ae3180095bbe2d378c5b1d6f2f2fd74dda3cc2",
"status": "affected",
"version": "45d76f492938cdc27ddadc16e1e75103f4cfbf56",
"versionType": "git"
},
{
"lessThan": "784dd2bdc622ed3cc6ef8e113aa1852e252de36f",
"status": "affected",
"version": "45d76f492938cdc27ddadc16e1e75103f4cfbf56",
"versionType": "git"
},
{
"lessThan": "560d559324169fe0583d54c475b5329550a86f71",
"status": "affected",
"version": "45d76f492938cdc27ddadc16e1e75103f4cfbf56",
"versionType": "git"
},
{
"lessThan": "0e46b6635b03d29807f810c3b415c4755a3f958d",
"status": "affected",
"version": "45d76f492938cdc27ddadc16e1e75103f4cfbf56",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/amd/pds_core/dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: fix error handling in pdsc_devcmd_wait\n\nFix two cases where pdsc_devcmd_wait() returns stale success from\nthe completion register instead of an error:\n\n1. FW crash: If firmware stops running, the wait loop breaks early with\n running=false. The condition \"if ((!done || timeout) \u0026\u0026 running)\" is\n false, so error handling is bypassed and stale status is returned.\n Check !running first and return -ENXIO.\n\n2. Timeout: If a command times out, err is set to -ETIMEDOUT but then\n overwritten by pdsc_err_to_errno(status) which reads stale status.\n Return -ETIMEDOUT immediately after cleaning up.\n\nBoth errors now propagate to pdsc_devcmd_locked() which queues\nhealth_work for recovery."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code is in the AMD/Pensando pds_core host driver for a network DPU/NIC whose firmware processes remote traffic; a remote attacker can crash or hang firmware via crafted packets, which drives kernel recovery through pdsc_devcmd_locked() during pdsc_fw_up/pdsc_setup.\nAC:L - Once the device is reachable, an attacker can reliably induce the triggering conditions (firmware crash or devcmd timeout) by sending concurrent or malformed network traffic to stress the DPU firmware, without depending on uncontrollable timing or memory layout.\nPR:N - Exploitation does not require host credentials; an unauthenticated remote attacker who can send traffic to the Pensando DSC interface can cause firmware failure that reaches pdsc_devcmd_wait() during automatic driver recovery, independent of devlink or root-only management paths.\nUI:N - No victim interaction is required beyond normal network connectivity to the affected DPU-backed host; recovery is triggered automatically by firmware failure and the driver\u0027s health/recovery workqueue path.\nS:U - The flaw affects host kernel driver state and device recovery within the same security authority; it does not cross a VM, container, or IOMMU boundary to impact a separate security domain.\nC:N - The bug is a logic error returning stale MMIO completion status rather than a memory-safety flaw; it does not expose arbitrary kernel memory, only misinterprets bounded device register contents from prior commands.\nI:N - There is no kernel memory corruption or arbitrary write primitive; the worst case is proceeding with stale device-command completion data, which affects driver/device recovery state rather than modifying protected host data.\nA:H - Masking firmware crash or timeout as success prevents immediate health_work recovery, can leave the driver believing a failed INIT/reset succeeded, and can cause prolonged or repeated loss of DPU/network availability on internet-facing cloud servers until manual intervention or repeated recovery cycles."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:43.750Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3231aff8ab26111c54e630b1a200fc43a729dd14"
},
{
"url": "https://git.kernel.org/stable/c/10ae3180095bbe2d378c5b1d6f2f2fd74dda3cc2"
},
{
"url": "https://git.kernel.org/stable/c/784dd2bdc622ed3cc6ef8e113aa1852e252de36f"
},
{
"url": "https://git.kernel.org/stable/c/560d559324169fe0583d54c475b5329550a86f71"
},
{
"url": "https://git.kernel.org/stable/c/0e46b6635b03d29807f810c3b415c4755a3f958d"
}
],
"title": "pds_core: fix error handling in pdsc_devcmd_wait",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64148",
"datePublished": "2026-07-19T15:40:38.816Z",
"dateReserved": "2026-07-19T07:54:57.037Z",
"dateUpdated": "2026-08-05T12:39:43.750Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64083 (GCVE-0-2026-64083)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-07-19 15:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors
adm1266_gpio_get() and adm1266_gpio_get_multiple() both compose the
pin-status word as
pins_status = read_buf[0] + (read_buf[1] << 8);
right after i2c_smbus_read_block_data(), guarding only against an
error return. A well-behaved device returns 2 bytes for
GPIO_STATUS/PDIO_STATUS, but the helper happily reports a 0- or
1-byte response too. If the device returns 0 bytes, both read_buf
slots are uninitialized stack memory; if it returns 1 byte, read_buf[1]
is.
The composed value then flows through set_bit() into the caller's
*bits in adm1266_gpio_get_multiple(), or into the return value of
adm1266_gpio_get(), and ends up in userspace via gpiolib (sysfs and
the char-dev ioctls). That leaks a few bits of kernel stack per
request on any device whose firmware glitch, bus error, or hostile
slave produces a short block-read response.
Add the missing length check to both call sites and surface a short
response as -EIO.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fd9196aad9e5a3845cea17de3405ebc700382142",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "ee4799becf7d2af3778007e22c2e55c4009a49c7",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "c603b6c6840ac0c6285f5eefea0de6242710af21",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "eb3cd9bb590460c6127145cb245be925d23f5232",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "64fa9328948ddcc0f7f3c23ea1756c126d9dffac",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "a7232f68c43ca62f545049b7f5fbfc75137b843b",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors\n\nadm1266_gpio_get() and adm1266_gpio_get_multiple() both compose the\npin-status word as\n\n\tpins_status = read_buf[0] + (read_buf[1] \u003c\u003c 8);\n\nright after i2c_smbus_read_block_data(), guarding only against an\nerror return. A well-behaved device returns 2 bytes for\nGPIO_STATUS/PDIO_STATUS, but the helper happily reports a 0- or\n1-byte response too. If the device returns 0 bytes, both read_buf\nslots are uninitialized stack memory; if it returns 1 byte, read_buf[1]\nis.\n\nThe composed value then flows through set_bit() into the caller\u0027s\n*bits in adm1266_gpio_get_multiple(), or into the return value of\nadm1266_gpio_get(), and ends up in userspace via gpiolib (sysfs and\nthe char-dev ioctls). That leaks a few bits of kernel stack per\nrequest on any device whose firmware glitch, bus error, or hostile\nslave produces a short block-read response.\n\nAdd the missing length check to both call sites and surface a short\nresponse as -EIO."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:39:54.756Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fd9196aad9e5a3845cea17de3405ebc700382142"
},
{
"url": "https://git.kernel.org/stable/c/ee4799becf7d2af3778007e22c2e55c4009a49c7"
},
{
"url": "https://git.kernel.org/stable/c/c603b6c6840ac0c6285f5eefea0de6242710af21"
},
{
"url": "https://git.kernel.org/stable/c/a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f"
},
{
"url": "https://git.kernel.org/stable/c/ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946"
},
{
"url": "https://git.kernel.org/stable/c/eb3cd9bb590460c6127145cb245be925d23f5232"
},
{
"url": "https://git.kernel.org/stable/c/64fa9328948ddcc0f7f3c23ea1756c126d9dffac"
},
{
"url": "https://git.kernel.org/stable/c/a7232f68c43ca62f545049b7f5fbfc75137b843b"
}
],
"title": "hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64083",
"datePublished": "2026-07-19T15:39:54.756Z",
"dateReserved": "2026-07-19T07:54:57.031Z",
"dateUpdated": "2026-07-19T15:39:54.756Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64384 (GCVE-0-2026-64384)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix change notify replay double-free
A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_notify_init() fails before the next send, cleanup
retains the previous buffer type and frees that response again.
Reset response bookkeeping before each attempt to prevent the stale free.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 433042a91f9373241307725b52de573933ffedbf Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 6.6.32 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5821f9dbb8b5b24391850a13418e633edd0fb003",
"status": "affected",
"version": "433042a91f9373241307725b52de573933ffedbf",
"versionType": "git"
},
{
"lessThan": "d684f4134998085702009b94c35c2003fc9e72d3",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "52af1975f0dfae990c5a0e85872cc41be0e88a68",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "901891513951bc8322ece754863909ea45af95c6",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "145f820dcbb2cced374f2532f8a61a44dce4a615",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.32",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix change notify replay double-free\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_notify_init() fails before the next send, cleanup\nretains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious SMB server can return a replayable response and then force reconnect failure over the network, causing the client to free stale response state twice.\nAC:L - The peer controls both prerequisites by returning a status such as STATUS_RETRY and then disconnecting or refusing reconnection; repeated attempts make the scheduling window attacker-controllable.\nPR:N - The malicious SMB peer requires no account, capability, or other privilege on the vulnerable client; the established client session does not grant the attacker privileges on that host.\nUI:N - An ordinary automated CIFS workload can maintain an outstanding change-notify request, after which the remote peer completes the trigger without human involvement.\nS:U - Exploitation compromises the kernel and resources governed by the same host security authority, without crossing a separate virtualization or sandbox boundary.\nC:H - The double-free corrupts the CIFS response-buffer slab or mempool, permitting overlapping live objects and freelist manipulation that can support disclosure of arbitrary kernel memory.\nI:H - The heap corruption can provide attacker-influenced writes through aliased request and response buffers or freelist poisoning, potentially enabling kernel control-flow hijacking.\nA:H - Hardened allocators can immediately panic on the consecutive double-free, while unhardened allocators can crash later through freelist corruption."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:36.154Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5821f9dbb8b5b24391850a13418e633edd0fb003"
},
{
"url": "https://git.kernel.org/stable/c/d684f4134998085702009b94c35c2003fc9e72d3"
},
{
"url": "https://git.kernel.org/stable/c/52af1975f0dfae990c5a0e85872cc41be0e88a68"
},
{
"url": "https://git.kernel.org/stable/c/901891513951bc8322ece754863909ea45af95c6"
},
{
"url": "https://git.kernel.org/stable/c/145f820dcbb2cced374f2532f8a61a44dce4a615"
}
],
"title": "smb: client: fix change notify replay double-free",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64384",
"datePublished": "2026-07-25T08:50:33.306Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-08-17T04:54:36.154Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68428 (GCVE-0-2026-68428)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86/mmu: Fix use-after-free on vendor module reload
mmu_destroy_caches() destroys pte_list_desc_cache and
mmu_page_header_cache, but leaves both pointers unchanged. The pointers
live in kvm.ko, and therefore survive when a vendor module is unloaded
while kvm.ko remains loaded.
If creation of pte_list_desc_cache fails during a subsequent vendor
module load, its assignment sets pte_list_desc_cache to NULL and the
error path calls mmu_destroy_caches(). mmu_page_header_cache still
points to the cache destroyed during the preceding vendor module
unload. Passing that stale pointer to kmem_cache_destroy() causes a
slab use-after-free.
Reproduce the issue on a v7.1.3 kernel with CONFIG_KASAN=y,
CONFIG_KASAN_GENERIC=y, CONFIG_KVM=m, and CONFIG_KVM_INTEL=m. A
one-shot test hook forces pte_list_desc_cache to NULL on the second
invocation of kvm_mmu_vendor_module_init():
1. Load kvm.ko and kvm-intel.ko, creating both caches.
2. Unload only kvm_intel, leaving kvm.ko loaded.
3. Reload kvm_intel and force initialization through the -ENOMEM path.
KASAN reports:
BUG: KASAN: slab-use-after-free in
kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]
...
kmem_cache_destroy+0x21/0x1d0
kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]
...
Allocated by task 16817:
__kmem_cache_create_args+0x12c/0x3b0
__kmem_cache_create.constprop.0+0xb6/0xf0 [kvm]
kvm_mmu_vendor_module_init+0x13b/0x170 [kvm]
...
Freed by task 16820:
kmem_cache_destroy+0x117/0x1d0
kvm_mmu_vendor_module_exit+0x21/0x30 [kvm]
Clear both pointers immediately after destroying their caches so that
the stored state reflects the caches' lifetime and repeated cleanup is
safe.
With the fix applied, the same injected vendor module reload fails with
-ENOMEM as expected and produces no KASAN report.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "034b7fa1f5846d69eb51f12ce6d1c71871e83c2d",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "42272b0f239f3a89f9c26a01cc37aee06138b1b7",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "940950d5cd86f250dca578279ad5ca63b4e0986b",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "6f4be73880302d5642c83a0813fdfe1f5fd4b6e3",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "32b9f89ed9e6d7a45075d64089c254a7f6e13695",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "ec9daa8fd1b6f45545c9839dca55bd867fad9e13",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "43cfb20d62ffe49626d62beecfc32eb6f262191c",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "52f2f7c30126037975389aa04d24c506a5177c35",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/mmu: Fix use-after-free on vendor module reload\n\nmmu_destroy_caches() destroys pte_list_desc_cache and\nmmu_page_header_cache, but leaves both pointers unchanged. The pointers\nlive in kvm.ko, and therefore survive when a vendor module is unloaded\nwhile kvm.ko remains loaded.\n\nIf creation of pte_list_desc_cache fails during a subsequent vendor\nmodule load, its assignment sets pte_list_desc_cache to NULL and the\nerror path calls mmu_destroy_caches(). mmu_page_header_cache still\npoints to the cache destroyed during the preceding vendor module\nunload. Passing that stale pointer to kmem_cache_destroy() causes a\nslab use-after-free.\n\nReproduce the issue on a v7.1.3 kernel with CONFIG_KASAN=y,\nCONFIG_KASAN_GENERIC=y, CONFIG_KVM=m, and CONFIG_KVM_INTEL=m. A\none-shot test hook forces pte_list_desc_cache to NULL on the second\ninvocation of kvm_mmu_vendor_module_init():\n\n 1. Load kvm.ko and kvm-intel.ko, creating both caches.\n 2. Unload only kvm_intel, leaving kvm.ko loaded.\n 3. Reload kvm_intel and force initialization through the -ENOMEM path.\n\nKASAN reports:\n\n BUG: KASAN: slab-use-after-free in\n kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]\n ...\n kmem_cache_destroy+0x21/0x1d0\n kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]\n ...\n Allocated by task 16817:\n __kmem_cache_create_args+0x12c/0x3b0\n __kmem_cache_create.constprop.0+0xb6/0xf0 [kvm]\n kvm_mmu_vendor_module_init+0x13b/0x170 [kvm]\n ...\n Freed by task 16820:\n kmem_cache_destroy+0x117/0x1d0\n kvm_mmu_vendor_module_exit+0x21/0x30 [kvm]\n\nClear both pointers immediately after destroying their caches so that\nthe stored state reflects the caches\u0027 lifetime and repeated cleanup is\nsafe.\n\nWith the fix applied, the same injected vendor module reload fails with\n-ENOMEM as expected and produces no KASAN report."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:25.214Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/034b7fa1f5846d69eb51f12ce6d1c71871e83c2d"
},
{
"url": "https://git.kernel.org/stable/c/42272b0f239f3a89f9c26a01cc37aee06138b1b7"
},
{
"url": "https://git.kernel.org/stable/c/940950d5cd86f250dca578279ad5ca63b4e0986b"
},
{
"url": "https://git.kernel.org/stable/c/6f4be73880302d5642c83a0813fdfe1f5fd4b6e3"
},
{
"url": "https://git.kernel.org/stable/c/32b9f89ed9e6d7a45075d64089c254a7f6e13695"
},
{
"url": "https://git.kernel.org/stable/c/ec9daa8fd1b6f45545c9839dca55bd867fad9e13"
},
{
"url": "https://git.kernel.org/stable/c/43cfb20d62ffe49626d62beecfc32eb6f262191c"
},
{
"url": "https://git.kernel.org/stable/c/52f2f7c30126037975389aa04d24c506a5177c35"
}
],
"title": "KVM: x86/mmu: Fix use-after-free on vendor module reload",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68428",
"datePublished": "2026-08-10T12:04:48.905Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:25.214Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53094 (GCVE-0-2026-53094)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-08-05 12:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix stale offload->prog pointer after constant blinding
When a dev-bound-only BPF program (BPF_F_XDP_DEV_BOUND_ONLY) undergoes
JIT compilation with constant blinding enabled (bpf_jit_harden >= 2),
bpf_jit_blind_constants() clones the program. The original prog is then
freed in bpf_jit_prog_release_other(), which updates aux->prog to point
to the surviving clone, but fails to update offload->prog.
This leaves offload->prog pointing to the freed original program. When
the network namespace is subsequently destroyed, cleanup_net() triggers
bpf_dev_bound_netdev_unregister(), which iterates ondev->progs and calls
__bpf_prog_offload_destroy(offload->prog). Accessing the freed prog
causes a page fault:
BUG: unable to handle page fault for address: ffffc900085f1038
Workqueue: netns cleanup_net
RIP: 0010:__bpf_prog_offload_destroy+0xc/0x80
Call Trace:
__bpf_offload_dev_netdev_unregister+0x257/0x350
bpf_dev_bound_netdev_unregister+0x4a/0x90
unregister_netdevice_many_notify+0x2a2/0x660
...
cleanup_net+0x21a/0x320
The test sequence that triggers this reliably is:
1. Set net.core.bpf_jit_harden=2 (echo 2 > /proc/sys/net/core/bpf_jit_harden)
2. Run xdp_metadata selftest, which creates a dev-bound-only XDP
program on a veth inside a netns (./test_progs -t xdp_metadata)
3. cleanup_net -> page fault in __bpf_prog_offload_destroy
Dev-bound-only programs are unique in that they have an offload structure
but go through the normal JIT path instead of bpf_prog_offload_compile().
This means they are subject to constant blinding's prog clone-and-replace,
while also having offload->prog that must stay in sync.
Fix this by updating offload->prog in bpf_jit_prog_release_other(),
alongside the existing aux->prog update. Both are back-pointers to
the prog that must be kept in sync when the prog is replaced.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/bpf/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a713b72ff88cdab4d5d692908ab1259ada511f4d",
"status": "affected",
"version": "2b3486bc2d237ec345b3942b7be5deabf8c8fed1",
"versionType": "git"
},
{
"lessThan": "25484c39d1ec82a0368798d956da3de5039b3fe8",
"status": "affected",
"version": "2b3486bc2d237ec345b3942b7be5deabf8c8fed1",
"versionType": "git"
},
{
"lessThan": "059525cf18e69a9313baf947d8898c6ee7ca6b65",
"status": "affected",
"version": "2b3486bc2d237ec345b3942b7be5deabf8c8fed1",
"versionType": "git"
},
{
"lessThan": "c79f8503d83d4665be461fb9e45e215d0380c67b",
"status": "affected",
"version": "2b3486bc2d237ec345b3942b7be5deabf8c8fed1",
"versionType": "git"
},
{
"lessThan": "a1aa9ef47c299c5bbc30594d3c2f0589edf908e6",
"status": "affected",
"version": "2b3486bc2d237ec345b3942b7be5deabf8c8fed1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/bpf/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix stale offload-\u003eprog pointer after constant blinding\n\nWhen a dev-bound-only BPF program (BPF_F_XDP_DEV_BOUND_ONLY) undergoes\nJIT compilation with constant blinding enabled (bpf_jit_harden \u003e= 2),\nbpf_jit_blind_constants() clones the program. The original prog is then\nfreed in bpf_jit_prog_release_other(), which updates aux-\u003eprog to point\nto the surviving clone, but fails to update offload-\u003eprog.\n\nThis leaves offload-\u003eprog pointing to the freed original program. When\nthe network namespace is subsequently destroyed, cleanup_net() triggers\nbpf_dev_bound_netdev_unregister(), which iterates ondev-\u003eprogs and calls\n__bpf_prog_offload_destroy(offload-\u003eprog). Accessing the freed prog\ncauses a page fault:\n\nBUG: unable to handle page fault for address: ffffc900085f1038\nWorkqueue: netns cleanup_net\nRIP: 0010:__bpf_prog_offload_destroy+0xc/0x80\nCall Trace:\n__bpf_offload_dev_netdev_unregister+0x257/0x350\nbpf_dev_bound_netdev_unregister+0x4a/0x90\nunregister_netdevice_many_notify+0x2a2/0x660\n...\ncleanup_net+0x21a/0x320\n\nThe test sequence that triggers this reliably is:\n\n1. Set net.core.bpf_jit_harden=2 (echo 2 \u003e /proc/sys/net/core/bpf_jit_harden)\n2. Run xdp_metadata selftest, which creates a dev-bound-only XDP\n program on a veth inside a netns (./test_progs -t xdp_metadata)\n3. cleanup_net -\u003e page fault in __bpf_prog_offload_destroy\n\nDev-bound-only programs are unique in that they have an offload structure\nbut go through the normal JIT path instead of bpf_prog_offload_compile().\nThis means they are subject to constant blinding\u0027s prog clone-and-replace,\nwhile also having offload-\u003eprog that must stay in sync.\n\nFix this by updating offload-\u003eprog in bpf_jit_prog_release_other(),\nalongside the existing aux-\u003eprog update. Both are back-pointers to\nthe prog that must be kept in sync when the prog is replaced."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached through local `bpf(BPF_PROG_LOAD)` and netlink/netns operations used to create and tear down a device-bound XDP program, not by remote packets.\nAC:L - Once the target has BPF JIT hardening set to blind constants for all users, the trigger is deterministic: load a dev-bound-only XDP program with constants, then unregister the device or destroy the netns. There is no attacker-uncontrolled race to win.\nPR:L - XDP program loading requires BPF and NET_ADMIN privileges, but these can be available in user-namespace/container deployments through BPF token delegation and namespaced capabilities. Under the required rule, this is scored as Low rather than High.\nUI:N - No victim action is required after the attacker has local execution; the attacker can perform the BPF load and netdevice/netns teardown directly.\nS:U - The bug corrupts/dereferences kernel memory within the same kernel security authority. This is standard local kernel compromise/DoS rather than a VM or hardware isolation boundary escape.\nC:H - The stale `offload-\u003eprog` is a use-after-free of a `struct bpf_prog`; if reclaimed, the cleanup path trusts attacker-shaped pointers and can be developed into kernel memory disclosure primitives. Kernel UAFs are scored High for confidentiality.\nI:H - The same UAF can drive trusted list/free/write operations through forged `prog-\u003eaux` and `offload` pointers, making arbitrary kernel memory corruption or code execution plausible. Kernel UAFs are scored High for integrity.\nA:H - The upstream report shows a reliable kernel page fault during `cleanup_net()`/netdevice unregister when the stale pointer is dereferenced. This is a kernel crash availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:33:20.910Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a713b72ff88cdab4d5d692908ab1259ada511f4d"
},
{
"url": "https://git.kernel.org/stable/c/25484c39d1ec82a0368798d956da3de5039b3fe8"
},
{
"url": "https://git.kernel.org/stable/c/059525cf18e69a9313baf947d8898c6ee7ca6b65"
},
{
"url": "https://git.kernel.org/stable/c/c79f8503d83d4665be461fb9e45e215d0380c67b"
},
{
"url": "https://git.kernel.org/stable/c/a1aa9ef47c299c5bbc30594d3c2f0589edf908e6"
}
],
"title": "bpf: Fix stale offload-\u003eprog pointer after constant blinding",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53094",
"datePublished": "2026-06-24T16:30:32.815Z",
"dateReserved": "2026-06-09T07:44:35.384Z",
"dateUpdated": "2026-08-05T12:33:20.910Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64266 (GCVE-0-2026-64266)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fuse: re-lock request before returning from fuse_ref_folio()
fuse_ref_folio() unlocks the request but does not re-lock it before
returning. fuse_chan_abort() can end the request and the async end
callback (eg fuse_writepage_free()) can free the args while the
subsequent copy chain logic after fuse_ref_folio() accesses them,
leading to use-after-free issues.
Fix this by locking the request in fuse_ref_folio() before returning.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c3021629a0d820247ee12b6c5192a1d5380e21c6 Version: c3021629a0d820247ee12b6c5192a1d5380e21c6 Version: c3021629a0d820247ee12b6c5192a1d5380e21c6 Version: c3021629a0d820247ee12b6c5192a1d5380e21c6 Version: c3021629a0d820247ee12b6c5192a1d5380e21c6 Version: c3021629a0d820247ee12b6c5192a1d5380e21c6 Version: c3021629a0d820247ee12b6c5192a1d5380e21c6 Version: c3021629a0d820247ee12b6c5192a1d5380e21c6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/fuse/dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1f9156714592356b4fda57beac7eab9c2a462dd3",
"status": "affected",
"version": "c3021629a0d820247ee12b6c5192a1d5380e21c6",
"versionType": "git"
},
{
"lessThan": "5630da218a45ba80f0aba0846cbe8aa655da122b",
"status": "affected",
"version": "c3021629a0d820247ee12b6c5192a1d5380e21c6",
"versionType": "git"
},
{
"lessThan": "1ca605cfa59377f0143fb35b5b01360f37d1b7c4",
"status": "affected",
"version": "c3021629a0d820247ee12b6c5192a1d5380e21c6",
"versionType": "git"
},
{
"lessThan": "0e4a5a000123d81234e27a2f8187688cf608f755",
"status": "affected",
"version": "c3021629a0d820247ee12b6c5192a1d5380e21c6",
"versionType": "git"
},
{
"lessThan": "e6aa539720c3d8def69683ed0c07cf9faea4e8be",
"status": "affected",
"version": "c3021629a0d820247ee12b6c5192a1d5380e21c6",
"versionType": "git"
},
{
"lessThan": "be353caffa8640f5e25fb3714ce8b0cef5e410e5",
"status": "affected",
"version": "c3021629a0d820247ee12b6c5192a1d5380e21c6",
"versionType": "git"
},
{
"lessThan": "65a1c2551f7e16085acbb54aedde1feaa559ba7a",
"status": "affected",
"version": "c3021629a0d820247ee12b6c5192a1d5380e21c6",
"versionType": "git"
},
{
"lessThan": "b5befa80fdbe287a98480effed9564712924add5",
"status": "affected",
"version": "c3021629a0d820247ee12b6c5192a1d5380e21c6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/fuse/dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.35"
},
{
"lessThan": "2.6.35",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.35",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: re-lock request before returning from fuse_ref_folio()\n\nfuse_ref_folio() unlocks the request but does not re-lock it before\nreturning. fuse_chan_abort() can end the request and the async end\ncallback (eg fuse_writepage_free()) can free the args while the\nsubsequent copy chain logic after fuse_ref_folio() accesses them,\nleading to use-after-free issues.\n\nFix this by locking the request in fuse_ref_folio() before returning."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - A local attacker reaches the flaw by serving a self-created FUSE mount and invoking splice() on its associated /dev/fuse descriptor.\nAC:L - The attacker controls writeback generation, splice processing, and concurrent connection abort, allowing repeated attempts at the race without an uncontrollable prerequisite.\nPR:L - FUSE supports user-namespace mounts, and an unprivileged mount owner can operate /dev/fuse and abort their own connection without init-namespace root.\nUI:N - The attacker can create and exercise their own FUSE connection without any victim action.\nS:U - Exploitation compromises the kernel within the same operating-system security authority and does not inherently cross a virtualization boundary.\nC:H - The freed argument and folio arrays are subsequently dereferenced, permitting attacker-influenced stale folio pointers and potential arbitrary kernel-memory disclosure through pipe buffers.\nI:H - Heap reclamation can replace the freed folio pointers and loop metadata, enabling attacker-directed memory or refcount operations that may support arbitrary writes and kernel code execution.\nA:H - The repeatable use-after-free and invalid folio operations can cause an oops, panic, or other complete system failure."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:20.108Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1f9156714592356b4fda57beac7eab9c2a462dd3"
},
{
"url": "https://git.kernel.org/stable/c/5630da218a45ba80f0aba0846cbe8aa655da122b"
},
{
"url": "https://git.kernel.org/stable/c/1ca605cfa59377f0143fb35b5b01360f37d1b7c4"
},
{
"url": "https://git.kernel.org/stable/c/0e4a5a000123d81234e27a2f8187688cf608f755"
},
{
"url": "https://git.kernel.org/stable/c/e6aa539720c3d8def69683ed0c07cf9faea4e8be"
},
{
"url": "https://git.kernel.org/stable/c/be353caffa8640f5e25fb3714ce8b0cef5e410e5"
},
{
"url": "https://git.kernel.org/stable/c/65a1c2551f7e16085acbb54aedde1feaa559ba7a"
},
{
"url": "https://git.kernel.org/stable/c/b5befa80fdbe287a98480effed9564712924add5"
}
],
"title": "fuse: re-lock request before returning from fuse_ref_folio()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64266",
"datePublished": "2026-07-25T08:49:15.142Z",
"dateReserved": "2026-07-19T15:36:31.775Z",
"dateUpdated": "2026-08-17T04:52:20.108Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64268 (GCVE-0-2026-64268)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: bound Read Response placement to the RREAD length
In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each
inbound Read Response DDP segment at sge->laddr + wqe->processed and then
accumulates wqe->processed, but it never checks the running total against
the sink buffer length on continuation segments. siw_check_sge() resolves
and validates the sink memory only on the first fragment (the if (!*mem)
branch), and siw_rresp_check_ntoh() compares the cumulative length against
wqe->bytes only on the final segment (the !frx->more_ddp_segs guard).
A connected siw peer that answers an outstanding RREAD with Read Response
segments that keep the DDP Last flag clear, carrying more total payload
than the RREAD requested, drives wqe->processed past the validated sink
buffer; the next siw_rx_data() call writes out of bounds at
sge->laddr + wqe->processed. siw runs iWARP over ordinary routable TCP,
so the peer is the remote end of an established RDMA connection and needs
no local privilege.
Bound every segment before placement, exactly as siw_proc_send() and
siw_proc_write() already do for their tagged and untagged paths, and
terminate the connection with a base-or-bounds DDP error when the
Read Response would overrun the sink buffer.
This is the second receive-path length fix for this file. A separate
change rejects an MPA FPDU length that underflows the per-fragment
remainder in the header decode; that guard does not cover this case,
because here each individual segment length is self-consistent and only
the accumulated placement offset overruns the buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_qp_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a31b6d18ded3cc32d9ee85a6ff0726d4274887b2",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "595e6537ad1a210da32cbb9a7f91aa73090915ba",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "3ef7e052cbd05a8b13a51a07b185a39ec93ee1cf",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "b2e26c955f8dd7e8d3f16c858db05245ea4fa817",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "6bc89f34a4597f9f6d41f7a60c67a3153bfe8851",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "423a78ff7928c2601013f73ec6d896f5597d0df5",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "75c93cd3c421890f49ea93f0b978b9b7bb10e5e3",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "7d29f7e9dbd844cae4d3e559cf78324b9642fd6b",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_qp_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: bound Read Response placement to the RREAD length\n\nIn drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each\ninbound Read Response DDP segment at sge-\u003eladdr + wqe-\u003eprocessed and then\naccumulates wqe-\u003eprocessed, but it never checks the running total against\nthe sink buffer length on continuation segments. siw_check_sge() resolves\nand validates the sink memory only on the first fragment (the if (!*mem)\nbranch), and siw_rresp_check_ntoh() compares the cumulative length against\nwqe-\u003ebytes only on the final segment (the !frx-\u003emore_ddp_segs guard).\n\nA connected siw peer that answers an outstanding RREAD with Read Response\nsegments that keep the DDP Last flag clear, carrying more total payload\nthan the RREAD requested, drives wqe-\u003eprocessed past the validated sink\nbuffer; the next siw_rx_data() call writes out of bounds at\nsge-\u003eladdr + wqe-\u003eprocessed. siw runs iWARP over ordinary routable TCP,\nso the peer is the remote end of an established RDMA connection and needs\nno local privilege.\n\nBound every segment before placement, exactly as siw_proc_send() and\nsiw_proc_write() already do for their tagged and untagged paths, and\nterminate the connection with a base-or-bounds DDP error when the\nRead Response would overrun the sink buffer.\n\nThis is the second receive-path length fix for this file. A separate\nchange rejects an MPA FPDU length that underflows the per-fragment\nremainder in the header decode; that guard does not cover this case,\nbecause here each individual segment length is self-consistent and only\nthe accumulated placement offset overruns the buffer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - siw carries iWARP over ordinary routable TCP, and the vulnerable receive callback processes crafted Read Response FPDUs from the remote endpoint of an established RDMA connection.\nAC:L - The peer learns the sink tag, address, and length from the RREAD and can deterministically send oversized continuation segments; no race or uncontrollable condition is required.\nPR:N - The MPA/siw data path performs no credential or capability check on the connected peer, and an unauthenticated RDMA service can accept the connection and issue attacker-induced RREADs.\nUI:N - The overflow is triggered through an automated RDMA protocol exchange and requires no human action.\nS:U - The corruption compromises resources within the affected host\u0027s kernel security authority and does not inherently cross a VM, IOMMU, or other security boundary.\nC:H - The global DMA/KVA sink case exposes the sink address and permits attacker-controlled kernel memory corruption, which can enable control-flow hijacking and arbitrary kernel-memory disclosure.\nI:H - Attacker-chosen response bytes are written beyond the validated sink into adjacent kernel memory, providing an exploitable out-of-bounds write capable of modifying objects or achieving kernel code execution.\nA:H - The overwrite can corrupt critical kernel objects or reach invalid memory, causing an oops or panic; bounded FRWR sinks still permit connection-terminating denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:22.293Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a31b6d18ded3cc32d9ee85a6ff0726d4274887b2"
},
{
"url": "https://git.kernel.org/stable/c/595e6537ad1a210da32cbb9a7f91aa73090915ba"
},
{
"url": "https://git.kernel.org/stable/c/3ef7e052cbd05a8b13a51a07b185a39ec93ee1cf"
},
{
"url": "https://git.kernel.org/stable/c/b2e26c955f8dd7e8d3f16c858db05245ea4fa817"
},
{
"url": "https://git.kernel.org/stable/c/6bc89f34a4597f9f6d41f7a60c67a3153bfe8851"
},
{
"url": "https://git.kernel.org/stable/c/423a78ff7928c2601013f73ec6d896f5597d0df5"
},
{
"url": "https://git.kernel.org/stable/c/75c93cd3c421890f49ea93f0b978b9b7bb10e5e3"
},
{
"url": "https://git.kernel.org/stable/c/7d29f7e9dbd844cae4d3e559cf78324b9642fd6b"
}
],
"title": "RDMA/siw: bound Read Response placement to the RREAD length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64268",
"datePublished": "2026-07-25T08:49:16.336Z",
"dateReserved": "2026-07-19T15:36:31.775Z",
"dateUpdated": "2026-08-17T04:52:22.293Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68280 (GCVE-0-2026-68280)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
The deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks
for both runtime PM and system sleep. This causes the DSI clocks to be
disabled twice: once during runtime suspend and again during system
suspend, resulting in a WARN message from the clock framework when
attempting to disable already-disabled clocks.
[ 84.384540] clk:231:5 already disabled
[ 84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clk_core_disable+0xa4/0xac
...
[ 84.579183] Call trace:
[ 84.581624] clk_core_disable+0xa4/0xac
[ 84.585457] clk_disable+0x30/0x4c
[ 84.588857] cdns_dsi_suspend+0x20/0x58 [cdns_dsi]
[ 84.593651] pm_generic_suspend+0x2c/0x44
[ 84.597661] ti_sci_pd_suspend+0xbc/0x15c
[ 84.601670] dpm_run_callback+0x8c/0x14c
[ 84.605588] __device_suspend+0x1a0/0x56c
[ 84.609594] dpm_suspend+0x17c/0x21c
[ 84.613165] dpm_suspend_start+0xa0/0xa8
[ 84.617083] suspend_devices_and_enter+0x12c/0x634
[ 84.621872] pm_suspend+0x1fc/0x368
To address this issue, replace UNIVERSAL_DEV_PM_OPS() with
RUNTIME_PM_OPS(). Bridge and panel drivers should only deal with runtime
PM, as the DRM framework manages system-wide power transitions through
the bridge enable() and disable() hooks.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1014b279264c0fc9f56324608754e36d33b7b5ae",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "c18d46d9830c29677be5213a067daafe1ac80e43",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "347bc3a6a4d968c403d2292e5ad986294d919dfc",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "c0384d6872f4dc2701960048a0be1a12a8d2dc6e",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "1f9c6b74e79639179e90ad0c0fbeae26e31e044b",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "2d8b08844c0ecc6f2002fa68711e779aa18c8585",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()\n\nThe deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks\nfor both runtime PM and system sleep. This causes the DSI clocks to be\ndisabled twice: once during runtime suspend and again during system\nsuspend, resulting in a WARN message from the clock framework when\nattempting to disable already-disabled clocks.\n\n[ 84.384540] clk:231:5 already disabled\n[ 84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clk_core_disable+0xa4/0xac\n...\n[ 84.579183] Call trace:\n[ 84.581624] clk_core_disable+0xa4/0xac\n[ 84.585457] clk_disable+0x30/0x4c\n[ 84.588857] cdns_dsi_suspend+0x20/0x58 [cdns_dsi]\n[ 84.593651] pm_generic_suspend+0x2c/0x44\n[ 84.597661] ti_sci_pd_suspend+0xbc/0x15c\n[ 84.601670] dpm_run_callback+0x8c/0x14c\n[ 84.605588] __device_suspend+0x1a0/0x56c\n[ 84.609594] dpm_suspend+0x17c/0x21c\n[ 84.613165] dpm_suspend_start+0xa0/0xa8\n[ 84.617083] suspend_devices_and_enter+0x12c/0x634\n[ 84.621872] pm_suspend+0x1fc/0x368\n\nTo address this issue, replace UNIVERSAL_DEV_PM_OPS() with\nRUNTIME_PM_OPS(). Bridge and panel drivers should only deal with runtime\nPM, as the DRM framework manages system-wide power transitions through\nthe bridge enable() and disable() hooks."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:17.699Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1014b279264c0fc9f56324608754e36d33b7b5ae"
},
{
"url": "https://git.kernel.org/stable/c/c18d46d9830c29677be5213a067daafe1ac80e43"
},
{
"url": "https://git.kernel.org/stable/c/347bc3a6a4d968c403d2292e5ad986294d919dfc"
},
{
"url": "https://git.kernel.org/stable/c/c0384d6872f4dc2701960048a0be1a12a8d2dc6e"
},
{
"url": "https://git.kernel.org/stable/c/1f9c6b74e79639179e90ad0c0fbeae26e31e044b"
},
{
"url": "https://git.kernel.org/stable/c/2d8b08844c0ecc6f2002fa68711e779aa18c8585"
}
],
"title": "drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68280",
"datePublished": "2026-08-10T12:02:11.434Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:17.699Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68279 (GCVE-0-2026-68279)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw
message and then unconditionally does:
memcpy(bytes, &raw->msg[idx], num_bytes);
without checking that idx + num_bytes <= raw->curlen. raw->msg[] is
256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger
than the remaining payload, the memcpy reads past the received data
into whatever follows in raw->msg[].
drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted
with a /* TODO check */ comment since the code was introduced).
Fix both functions by using a single combined check
(idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8,
it is always >= 0, so this strictly subsumes the simpler idx > curlen
form and no separate step is needed.
[added missing fixes tag]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "185de1d74e658e2edb723ba76fa61903f77d8a68",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "d7b9b1e33b4ed8c48d4db6e6e21c257ebbbb2586",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "c2fbda0fe0163c55ba3820ee6cea0c6b43622eda",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "04d953f50d61e542e94a5977822cc53735f8c0ce",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "533d9e2bede4aeefdc2a0561d7071cfede95958f",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "e6ef5455b06cb4e5d181aabcd723791587c79f12",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "1a8f537f5a1eeac941f262fe73078d6b08ba83c0",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers\n\ndrm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw\nmessage and then unconditionally does:\n\n memcpy(bytes, \u0026raw-\u003emsg[idx], num_bytes);\n\nwithout checking that idx + num_bytes \u003c= raw-\u003ecurlen. raw-\u003emsg[] is\n256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger\nthan the remaining payload, the memcpy reads past the received data\ninto whatever follows in raw-\u003emsg[].\n\ndrm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted\nwith a /* TODO check */ comment since the code was introduced).\n\nFix both functions by using a single combined check\n(idx + num_bytes \u003e curlen) before each memcpy. Since num_bytes is u8,\nit is always \u003e= 0, so this strictly subsumes the simpler idx \u003e curlen\nform and no separate step is needed.\n\n[added missing fixes tag]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:16.563Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/185de1d74e658e2edb723ba76fa61903f77d8a68"
},
{
"url": "https://git.kernel.org/stable/c/d7b9b1e33b4ed8c48d4db6e6e21c257ebbbb2586"
},
{
"url": "https://git.kernel.org/stable/c/c2fbda0fe0163c55ba3820ee6cea0c6b43622eda"
},
{
"url": "https://git.kernel.org/stable/c/22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2"
},
{
"url": "https://git.kernel.org/stable/c/04d953f50d61e542e94a5977822cc53735f8c0ce"
},
{
"url": "https://git.kernel.org/stable/c/533d9e2bede4aeefdc2a0561d7071cfede95958f"
},
{
"url": "https://git.kernel.org/stable/c/e6ef5455b06cb4e5d181aabcd723791587c79f12"
},
{
"url": "https://git.kernel.org/stable/c/1a8f537f5a1eeac941f262fe73078d6b08ba83c0"
}
],
"title": "drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68279",
"datePublished": "2026-08-10T12:02:09.423Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:16.563Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64047 (GCVE-0-2026-64047)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
When an sk_msg scatterlist ring wraps (sg.end < sg.start),
tls_push_record() chains the tail portion of the ring to the head
using sg_chain(). An extra entry in the sg array is reserved for
this:
struct sk_msg_sg {
[...]
/* The extra two elements:
* 1) used for chaining the front and sections when the list becomes
* partitioned (e.g. end < start). The crypto APIs require the
* chaining;
* 2) to chain tailer SG entries after the message.
*/
struct scatterlist data[MAX_MSG_FRAGS + 2];
The current code uses MAX_SKB_FRAGS + 1 as the ring size:
sg_chain(&msg_pl->sg.data[msg_pl->sg.start],
MAX_SKB_FRAGS - msg_pl->sg.start + 1,
msg_pl->sg.data);
This places the chain pointer at
sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =
&data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =
data[start + (MAX_SKB_FRAGS - start + 1) - 1] =
data[MAX_SKB_FRAGS]
instead of the true last entry. This is likely due to a "race" of
the commit under Fixes landing close to
commit 031097d9e079 ("bpf: sk_msg, zap ingress queue on psock down")
Convert to ARRAY_SIZE and drop the data[start] / - start (as suggested
by Sabrina).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9aaaa56845a06aeabdd597cbe19492dc01f281ec Version: 9aaaa56845a06aeabdd597cbe19492dc01f281ec Version: 9aaaa56845a06aeabdd597cbe19492dc01f281ec Version: 9aaaa56845a06aeabdd597cbe19492dc01f281ec Version: 9aaaa56845a06aeabdd597cbe19492dc01f281ec Version: 9aaaa56845a06aeabdd597cbe19492dc01f281ec Version: 9aaaa56845a06aeabdd597cbe19492dc01f281ec Version: 9aaaa56845a06aeabdd597cbe19492dc01f281ec Version: d529d6c9f7e3aaeac13c4948f79799ccb825f29d Version: 5.4.14 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "73963a375885d5ccb7def39fd0b4f542e0f343dd",
"status": "affected",
"version": "9aaaa56845a06aeabdd597cbe19492dc01f281ec",
"versionType": "git"
},
{
"lessThan": "47110c3a9ac247b688657337f5981efcfcb240dc",
"status": "affected",
"version": "9aaaa56845a06aeabdd597cbe19492dc01f281ec",
"versionType": "git"
},
{
"lessThan": "84158c2997159df4a0d70cd9c46774512d32a522",
"status": "affected",
"version": "9aaaa56845a06aeabdd597cbe19492dc01f281ec",
"versionType": "git"
},
{
"lessThan": "131ef12057d92b77b636321b7849c69222405a97",
"status": "affected",
"version": "9aaaa56845a06aeabdd597cbe19492dc01f281ec",
"versionType": "git"
},
{
"lessThan": "66339b71f105e6f83e0da3b9583d95077534fe1d",
"status": "affected",
"version": "9aaaa56845a06aeabdd597cbe19492dc01f281ec",
"versionType": "git"
},
{
"lessThan": "eca989eab4b2599dcb02f72140a7c08f08838520",
"status": "affected",
"version": "9aaaa56845a06aeabdd597cbe19492dc01f281ec",
"versionType": "git"
},
{
"lessThan": "2fb0dc7e0099686c4e9d2732745d8a31b18c3628",
"status": "affected",
"version": "9aaaa56845a06aeabdd597cbe19492dc01f281ec",
"versionType": "git"
},
{
"lessThan": "285943c6e7ca309bbea84b253745154241d9788a",
"status": "affected",
"version": "9aaaa56845a06aeabdd597cbe19492dc01f281ec",
"versionType": "git"
},
{
"status": "affected",
"version": "d529d6c9f7e3aaeac13c4948f79799ccb825f29d",
"versionType": "git"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.14",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring\n\nWhen an sk_msg scatterlist ring wraps (sg.end \u003c sg.start),\ntls_push_record() chains the tail portion of the ring to the head\nusing sg_chain(). An extra entry in the sg array is reserved for\nthis:\n\n struct sk_msg_sg {\n [...]\n /* The extra two elements:\n * 1) used for chaining the front and sections when the list becomes\n * partitioned (e.g. end \u003c start). The crypto APIs require the\n * chaining;\n * 2) to chain tailer SG entries after the message.\n */\n struct scatterlist data[MAX_MSG_FRAGS + 2];\n\nThe current code uses MAX_SKB_FRAGS + 1 as the ring size:\n\n sg_chain(\u0026msg_pl-\u003esg.data[msg_pl-\u003esg.start],\n MAX_SKB_FRAGS - msg_pl-\u003esg.start + 1,\n msg_pl-\u003esg.data);\n\nThis places the chain pointer at\n\n sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =\n \u0026data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =\n data[start + (MAX_SKB_FRAGS - start + 1) - 1] =\n data[MAX_SKB_FRAGS]\n\ninstead of the true last entry. This is likely due to a \"race\" of\nthe commit under Fixes landing close to\ncommit 031097d9e079 (\"bpf: sk_msg, zap ingress queue on psock down\")\n\nConvert to ARRAY_SIZE and drop the data[start] / - start (as suggested\nby Sabrina)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in kernel TLS (kTLS) software transmit encryption triggered when a TLS socket sends records; remote peers on established TLS connections drive this TX path through normal network I/O.\nAC:L - An attacker who controls connection traffic can reliably create the wrapped sk_msg ring state via BPF sockmap SK_MSG verdict helpers (push/pop/redirect) and then trigger record push on demand.\nPR:N - Exploitation requires no privileges on the target host beyond being a network peer on a kTLS socket with sockmap BPF already configured by the service; attacker capabilities are not needed on the victim system.\nUI:N - Triggering requires only automated server-side TLS transmit activity in response to network input, with no victim user action.\nS:U - Impact is kernel memory corruption and potential privilege escalation within the same kernel/host security boundary, not a cross-VM or sandbox escape by itself.\nC:H - Corrupting an active scatterlist entry causes the AEAD crypto path to follow an incorrect chain, enabling out-of-bounds kernel memory reads beyond intended plaintext buffers.\nI:H - The malformed scatterlist passed to crypto_aead_encrypt() can direct encryption I/O to wrong memory regions, providing an out-of-bounds write primitive exploitable for control-flow hijacking.\nA:H - Scatterlist corruption in the kernel crypto TX path can cause kernel oopses, panics, or fatal BUG conditions when invalid chain entries or page pointers are dereferenced."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:39.300Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/73963a375885d5ccb7def39fd0b4f542e0f343dd"
},
{
"url": "https://git.kernel.org/stable/c/47110c3a9ac247b688657337f5981efcfcb240dc"
},
{
"url": "https://git.kernel.org/stable/c/84158c2997159df4a0d70cd9c46774512d32a522"
},
{
"url": "https://git.kernel.org/stable/c/131ef12057d92b77b636321b7849c69222405a97"
},
{
"url": "https://git.kernel.org/stable/c/66339b71f105e6f83e0da3b9583d95077534fe1d"
},
{
"url": "https://git.kernel.org/stable/c/eca989eab4b2599dcb02f72140a7c08f08838520"
},
{
"url": "https://git.kernel.org/stable/c/2fb0dc7e0099686c4e9d2732745d8a31b18c3628"
},
{
"url": "https://git.kernel.org/stable/c/285943c6e7ca309bbea84b253745154241d9788a"
}
],
"title": "net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64047",
"datePublished": "2026-07-19T15:39:31.960Z",
"dateReserved": "2026-07-19T07:54:57.029Z",
"dateUpdated": "2026-08-05T12:38:39.300Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64549 (GCVE-0-2026-64549)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
bpa10x_setup() sends the vendor command 0xfc0e and passes the response
to bt_dev_info() and hci_set_fw_info() as a "%s" string starting at
skb->data + 1, without checking the length:
bt_dev_info(hdev, "%s", (char *)(skb->data + 1));
hci_set_fw_info(hdev, "%s", skb->data + 1);
A device that returns a one-byte response (status only) leaves
skb->data + 1 past the end of the data, and the %s walk reads adjacent
slab memory until it meets a NUL. The same happens when the payload is
not NUL-terminated within skb->len. The out-of-bounds bytes end up in
the kernel log and the firmware-info debugfs file.
Print the revision string with a bounded "%.*s" limited to skb->len - 1
instead. This keeps the string readable for well-behaved devices while
never reading past the received data, and does not fail setup, so a
device returning a short or unterminated response keeps working.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ddd68ec8f4847b460c9f580076eafe13b031a6fd Version: ddd68ec8f4847b460c9f580076eafe13b031a6fd Version: ddd68ec8f4847b460c9f580076eafe13b031a6fd Version: ddd68ec8f4847b460c9f580076eafe13b031a6fd Version: ddd68ec8f4847b460c9f580076eafe13b031a6fd Version: ddd68ec8f4847b460c9f580076eafe13b031a6fd Version: ddd68ec8f4847b460c9f580076eafe13b031a6fd Version: ddd68ec8f4847b460c9f580076eafe13b031a6fd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/bpa10x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1813add71e386f77b3040e6c8dc9b7b3ff965a6c",
"status": "affected",
"version": "ddd68ec8f4847b460c9f580076eafe13b031a6fd",
"versionType": "git"
},
{
"lessThan": "bd56c23f1f8681a2857ee924a8bd3abf87c8913b",
"status": "affected",
"version": "ddd68ec8f4847b460c9f580076eafe13b031a6fd",
"versionType": "git"
},
{
"lessThan": "7a64f39ebe1bacd9004a62eceadac0b122ec3cc2",
"status": "affected",
"version": "ddd68ec8f4847b460c9f580076eafe13b031a6fd",
"versionType": "git"
},
{
"lessThan": "f80b4afe893dffa9fabdbf80fb4d6782b24a6793",
"status": "affected",
"version": "ddd68ec8f4847b460c9f580076eafe13b031a6fd",
"versionType": "git"
},
{
"lessThan": "4b4008dda1d0c6e598d7865631ad4eda63a560f0",
"status": "affected",
"version": "ddd68ec8f4847b460c9f580076eafe13b031a6fd",
"versionType": "git"
},
{
"lessThan": "bfc9e7be289df11e8e38c98cd78019d67fdd0bd5",
"status": "affected",
"version": "ddd68ec8f4847b460c9f580076eafe13b031a6fd",
"versionType": "git"
},
{
"lessThan": "a8e169d308775039200bb9c905c7ce420db6e8c5",
"status": "affected",
"version": "ddd68ec8f4847b460c9f580076eafe13b031a6fd",
"versionType": "git"
},
{
"lessThan": "dd068ef044128db655f48323a4acfd5907e04903",
"status": "affected",
"version": "ddd68ec8f4847b460c9f580076eafe13b031a6fd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/bpa10x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.4"
},
{
"lessThan": "4.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()\n\nbpa10x_setup() sends the vendor command 0xfc0e and passes the response\nto bt_dev_info() and hci_set_fw_info() as a \"%s\" string starting at\nskb-\u003edata + 1, without checking the length:\n\n\tbt_dev_info(hdev, \"%s\", (char *)(skb-\u003edata + 1));\n\thci_set_fw_info(hdev, \"%s\", skb-\u003edata + 1);\n\nA device that returns a one-byte response (status only) leaves\nskb-\u003edata + 1 past the end of the data, and the %s walk reads adjacent\nslab memory until it meets a NUL. The same happens when the payload is\nnot NUL-terminated within skb-\u003elen. The out-of-bounds bytes end up in\nthe kernel log and the firmware-info debugfs file.\n\nPrint the revision string with a bounded \"%.*s\" limited to skb-\u003elen - 1\ninstead. This keeps the string readable for well-behaved devices while\nnever reading past the received data, and does not fail setup, so a\ndevice returning a short or unterminated response keeps working."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:26.570Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1813add71e386f77b3040e6c8dc9b7b3ff965a6c"
},
{
"url": "https://git.kernel.org/stable/c/bd56c23f1f8681a2857ee924a8bd3abf87c8913b"
},
{
"url": "https://git.kernel.org/stable/c/7a64f39ebe1bacd9004a62eceadac0b122ec3cc2"
},
{
"url": "https://git.kernel.org/stable/c/f80b4afe893dffa9fabdbf80fb4d6782b24a6793"
},
{
"url": "https://git.kernel.org/stable/c/4b4008dda1d0c6e598d7865631ad4eda63a560f0"
},
{
"url": "https://git.kernel.org/stable/c/bfc9e7be289df11e8e38c98cd78019d67fdd0bd5"
},
{
"url": "https://git.kernel.org/stable/c/a8e169d308775039200bb9c905c7ce420db6e8c5"
},
{
"url": "https://git.kernel.org/stable/c/dd068ef044128db655f48323a4acfd5907e04903"
}
],
"title": "Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64549",
"datePublished": "2026-07-27T20:10:38.894Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:26.570Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-23240 (GCVE-0-2026-23240)
Vulnerability from cvelistv5
Published
2026-03-10 17:28
Modified
2026-08-05 12:20
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tls: Fix race condition in tls_sw_cancel_work_tx()
This issue was discovered during a code audit.
After cancel_delayed_work_sync() is called from tls_sk_proto_close(),
tx_work_handler() can still be scheduled from paths such as the
Delayed ACK handler or ksoftirqd.
As a result, the tx_work_handler() worker may dereference a freed
TLS object.
The following is a simple race scenario:
cpu0 cpu1
tls_sk_proto_close()
tls_sw_cancel_work_tx()
tls_write_space()
tls_sw_write_space()
if (!test_and_set_bit(BIT_TX_SCHEDULED, &tx_ctx->tx_bitmask))
set_bit(BIT_TX_SCHEDULED, &ctx->tx_bitmask);
cancel_delayed_work_sync(&ctx->tx_work.work);
schedule_delayed_work(&tx_ctx->tx_work.work, 0);
To prevent this race condition, cancel_delayed_work_sync() is
replaced with disable_delayed_work_sync().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a5de36d6cee74a92c1a21b260bc507e64bc451de",
"status": "affected",
"version": "f87e62d45e51b12d48d2cb46b5cde8f83b866bc4",
"versionType": "git"
},
{
"lessThan": "854cd32bc74fe573353095e90958490e4e4d641b",
"status": "affected",
"version": "f87e62d45e51b12d48d2cb46b5cde8f83b866bc4",
"versionType": "git"
},
{
"lessThan": "17153f154f80be2b47ebf52840f2d8f724eb2f3b",
"status": "affected",
"version": "f87e62d45e51b12d48d2cb46b5cde8f83b866bc4",
"versionType": "git"
},
{
"lessThan": "7bb09315f93dce6acc54bf59e5a95ba7365c2be4",
"status": "affected",
"version": "f87e62d45e51b12d48d2cb46b5cde8f83b866bc4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: Fix race condition in tls_sw_cancel_work_tx()\n\nThis issue was discovered during a code audit.\n\nAfter cancel_delayed_work_sync() is called from tls_sk_proto_close(),\ntx_work_handler() can still be scheduled from paths such as the\nDelayed ACK handler or ksoftirqd.\nAs a result, the tx_work_handler() worker may dereference a freed\nTLS object.\n\nThe following is a simple race scenario:\n\n cpu0 cpu1\n\ntls_sk_proto_close()\n tls_sw_cancel_work_tx()\n tls_write_space()\n tls_sw_write_space()\n if (!test_and_set_bit(BIT_TX_SCHEDULED, \u0026tx_ctx-\u003etx_bitmask))\n set_bit(BIT_TX_SCHEDULED, \u0026ctx-\u003etx_bitmask);\n cancel_delayed_work_sync(\u0026ctx-\u003etx_work.work);\n schedule_delayed_work(\u0026tx_ctx-\u003etx_work.work, 0);\n\nTo prevent this race condition, cancel_delayed_work_sync() is\nreplaced with disable_delayed_work_sync()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The tls_write_space callback is triggered by a remote TCP peer sending ACKs, which causes tcp_data_snd_check \u2192 tcp_check_space \u2192 tcp_new_space \u2192 sk-\u003esk_write_space (tls_write_space). Any server using kTLS (nginx, HAProxy, NFS with TLS) is reachable over the network.\nAC:L - The attacker controls both sides of the race: they send TCP ACKs to trigger tls_write_space and initiate disconnect to trigger the close path. With repeated connection attempts and ACK flooding, the race window is reliably winnable.\nPR:N - No authentication or privileges are needed to establish a TCP connection and send ACKs to a kTLS-enabled server. The race is triggered during normal TCP processing before any application-level authentication occurs.\nUI:N - No user interaction is needed. The attacker connects to the server, sends ACKs, and disconnects to trigger the race. The server processes this automatically.\nS:U - The vulnerability results in kernel-level use-after-free within the same security authority (kernel space). There is no crossing of a virtualization or sandbox boundary.\nC:H - This is a use-after-free where the freed tls_sw_context_tx (freed via immediate kfree, not kfree_rcu) can be reallocated with attacker-influenced data. The UAF gives read access to reallocated memory contents, enabling arbitrary kernel memory disclosure.\nI:H - The UAF on the tls_sw_context_tx structure enables heap spraying to control the freed object\u0027s contents. The tx_work_handler then calls tls_tx_records through corrupted context pointers, enabling control flow hijacking and arbitrary code execution.\nA:H - The use-after-free on the embedded delayed_work struct causes kernel crashes when the workqueue attempts to execute the freed work item, resulting in kernel panic or oops."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:20:50.947Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a5de36d6cee74a92c1a21b260bc507e64bc451de"
},
{
"url": "https://git.kernel.org/stable/c/854cd32bc74fe573353095e90958490e4e4d641b"
},
{
"url": "https://git.kernel.org/stable/c/17153f154f80be2b47ebf52840f2d8f724eb2f3b"
},
{
"url": "https://git.kernel.org/stable/c/7bb09315f93dce6acc54bf59e5a95ba7365c2be4"
}
],
"title": "tls: Fix race condition in tls_sw_cancel_work_tx()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-23240",
"datePublished": "2026-03-10T17:28:27.371Z",
"dateReserved": "2026-01-13T15:37:45.989Z",
"dateUpdated": "2026-08-05T12:20:50.947Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64000 (GCVE-0-2026-64000)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: hsr: fix potential OOB access in supervision frame handling
Ensure the entire TLV header is linearized before access by adding
sizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this,
a truncated frame could cause an out-of-bounds access.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eafaa88b3eb7f28aecb222281655473431d3ef2e Version: eafaa88b3eb7f28aecb222281655473431d3ef2e Version: eafaa88b3eb7f28aecb222281655473431d3ef2e Version: eafaa88b3eb7f28aecb222281655473431d3ef2e Version: eafaa88b3eb7f28aecb222281655473431d3ef2e Version: eafaa88b3eb7f28aecb222281655473431d3ef2e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/hsr/hsr_forward.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "09a37dca090c55ffb1a33f52d8667f1c2367ef48",
"status": "affected",
"version": "eafaa88b3eb7f28aecb222281655473431d3ef2e",
"versionType": "git"
},
{
"lessThan": "a4b64f3e9c7b8259f7dd251a0313420ba7c01852",
"status": "affected",
"version": "eafaa88b3eb7f28aecb222281655473431d3ef2e",
"versionType": "git"
},
{
"lessThan": "71c986c0ba45b7dc574fae27c83e7b6671556f37",
"status": "affected",
"version": "eafaa88b3eb7f28aecb222281655473431d3ef2e",
"versionType": "git"
},
{
"lessThan": "fbd0662f9c9a66e8cc3df3099cca8ed6d3837cc7",
"status": "affected",
"version": "eafaa88b3eb7f28aecb222281655473431d3ef2e",
"versionType": "git"
},
{
"lessThan": "78607a6854a22a2502f68092202e75a39af4865d",
"status": "affected",
"version": "eafaa88b3eb7f28aecb222281655473431d3ef2e",
"versionType": "git"
},
{
"lessThan": "f229426072fc865654a60978bb7fda790a051ff3",
"status": "affected",
"version": "eafaa88b3eb7f28aecb222281655473431d3ef2e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/hsr/hsr_forward.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: fix potential OOB access in supervision frame handling\n\nEnsure the entire TLV header is linearized before access by adding\nsizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this,\na truncated frame could cause an out-of-bounds access."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code is reached when the kernel processes received Ethernet frames via the netdev RX handler in net/hsr, and a remote attacker on the HSR/PRP ring can deliver a crafted supervision frame without any local access to the victim host.\nAC:L - The attacker fully controls the malformed frame content and length; a precisely truncated supervision frame reliably passes existing TLV validation and triggers the out-of-bounds read with no races or attacker-uncontrollable conditions.\nPR:N - Exploitation requires only the ability to inject L2 HSR/PRP supervision frames onto the ring segment; no local account, capabilities, or authentication on the target kernel is needed.\nUI:N - No victim user action is required beyond normal operation of an HSR/PRP-configured node; the attacker triggers the bug solely by sending a malicious frame.\nS:U - Impact is confined to kernel memory safety within the same security authority; there is no VM escape, IOMMU bypass, or cross-security-boundary scope change.\nC:H - The bug is an out-of-bounds read of supervision TLV header fields past the skb tail, which can disclose adjacent kernel heap/skb memory and is not strictly bounded to a few attacker-uncontrolled bytes.\nI:H - Out-of-bounds access in kernel packet parsing can supply attacker-influenced TLV type/length values that drive further skb_pull arithmetic and extended parsing, creating a plausible path to memory corruption and control-flow hijacking.\nA:H - Reading beyond the skb buffer boundary during softirq packet processing can cause a kernel oops/panic, and the attacker can repeatedly trigger the condition with crafted frames."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:01.596Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/09a37dca090c55ffb1a33f52d8667f1c2367ef48"
},
{
"url": "https://git.kernel.org/stable/c/a4b64f3e9c7b8259f7dd251a0313420ba7c01852"
},
{
"url": "https://git.kernel.org/stable/c/71c986c0ba45b7dc574fae27c83e7b6671556f37"
},
{
"url": "https://git.kernel.org/stable/c/fbd0662f9c9a66e8cc3df3099cca8ed6d3837cc7"
},
{
"url": "https://git.kernel.org/stable/c/78607a6854a22a2502f68092202e75a39af4865d"
},
{
"url": "https://git.kernel.org/stable/c/f229426072fc865654a60978bb7fda790a051ff3"
}
],
"title": "net: hsr: fix potential OOB access in supervision frame handling",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64000",
"datePublished": "2026-07-19T14:56:18.116Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-08-05T12:38:01.596Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64303 (GCVE-0-2026-64303)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
When dmaengine_prep_slave_sg() fails for the TX channel, the error path
terminates the TX DMA channel but leaves the RX channel running. Since
the RX channel was already submitted and issued prior to preparing
the TX descriptor, returning -EINVAL causes the SPI core to unmap the
DMA buffers while the RX DMA engine continues writing to them, leading
to potential memory corruption or use-after-free.
Terminate the RX channel before returning on the TX prepare failure path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 09c04466ce7ea494993c0635ba5edb6d2222a806 Version: 09c04466ce7ea494993c0635ba5edb6d2222a806 Version: 09c04466ce7ea494993c0635ba5edb6d2222a806 Version: 09c04466ce7ea494993c0635ba5edb6d2222a806 Version: 09c04466ce7ea494993c0635ba5edb6d2222a806 Version: 09c04466ce7ea494993c0635ba5edb6d2222a806 Version: 09c04466ce7ea494993c0635ba5edb6d2222a806 Version: 09c04466ce7ea494993c0635ba5edb6d2222a806 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/spi/spi-fsl-lpspi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ad370d1c7a9a832f77b2341513cd31188c9443af",
"status": "affected",
"version": "09c04466ce7ea494993c0635ba5edb6d2222a806",
"versionType": "git"
},
{
"lessThan": "cce2063404b2341e7b2bbf85eddfcd70a31a0033",
"status": "affected",
"version": "09c04466ce7ea494993c0635ba5edb6d2222a806",
"versionType": "git"
},
{
"lessThan": "af39a2698f69b584d14a00cffe0f51a2caa15337",
"status": "affected",
"version": "09c04466ce7ea494993c0635ba5edb6d2222a806",
"versionType": "git"
},
{
"lessThan": "e65505d91fa036a238968e4c10744244d1b968c4",
"status": "affected",
"version": "09c04466ce7ea494993c0635ba5edb6d2222a806",
"versionType": "git"
},
{
"lessThan": "d5c1060218a3749c8a18b36f8169d910fce20639",
"status": "affected",
"version": "09c04466ce7ea494993c0635ba5edb6d2222a806",
"versionType": "git"
},
{
"lessThan": "808033d80d5c9f8adf7e8de9317389270ce13430",
"status": "affected",
"version": "09c04466ce7ea494993c0635ba5edb6d2222a806",
"versionType": "git"
},
{
"lessThan": "9d000bdd250d649a11cd7f733175686877344582",
"status": "affected",
"version": "09c04466ce7ea494993c0635ba5edb6d2222a806",
"versionType": "git"
},
{
"lessThan": "01980b5da56e573d62798d0ff6c86bcaa2b22cbe",
"status": "affected",
"version": "09c04466ce7ea494993c0635ba5edb6d2222a806",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/spi/spi-fsl-lpspi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: fsl-lpspi: terminate the RX channel on TX prepare failure path\n\nWhen dmaengine_prep_slave_sg() fails for the TX channel, the error path\nterminates the TX DMA channel but leaves the RX channel running. Since\nthe RX channel was already submitted and issued prior to preparing\nthe TX descriptor, returning -EINVAL causes the SPI core to unmap the\nDMA buffers while the RX DMA engine continues writing to them, leading\nto potential memory corruption or use-after-free.\n\nTerminate the RX channel before returning on the TX prepare failure path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - In a reasonable network-facing deployment, an SPI Ethernet controller such as ENC28J60 receives an unauthenticated remote frame, raises its IRQ, and calls spi_sync(), which traverses the SPI core into the vulnerable fsl-lpspi DMA path.\nAC:L - An attacker can repeatedly drive DMA preparation and influence GFP_NOWAIT allocation pressure with packet flooding; once TX preparation fails after RX issuance, subsequent traffic deterministically exercises the stale RX descriptor without a race to win.\nPR:N - The SPI Ethernet receive IRQ path runs before protocol authentication and has no capability, device-node, or namespace privilege check, so a remote sender needs no privileges.\nUI:N - No victim action is needed after the network interface and SPI NIC are configured; attacker traffic alone invokes the affected transfer path.\nS:U - The stale DMA corrupts memory within the same host kernel security authority and does not inherently cross a VM, IOMMU, or other security scope boundary.\nC:H - The active RX DMA descriptor can write device- and packet-influenced data into unmapped, freed, and reallocated kernel memory, yielding memory corruption that can be leveraged for kernel-memory disclosure.\nI:H - The stale DEV_TO_MEM DMA operation provides attacker-influenced writes into freed or reallocated kernel memory, permitting object corruption and potentially control-flow hijacking or arbitrary kernel code execution.\nA:H - Continued DMA into invalid or repurposed memory can cause an IOMMU fault, kernel oops, panic, or hang, and unauthenticated traffic can trigger the condition repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:02.185Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ad370d1c7a9a832f77b2341513cd31188c9443af"
},
{
"url": "https://git.kernel.org/stable/c/cce2063404b2341e7b2bbf85eddfcd70a31a0033"
},
{
"url": "https://git.kernel.org/stable/c/af39a2698f69b584d14a00cffe0f51a2caa15337"
},
{
"url": "https://git.kernel.org/stable/c/e65505d91fa036a238968e4c10744244d1b968c4"
},
{
"url": "https://git.kernel.org/stable/c/d5c1060218a3749c8a18b36f8169d910fce20639"
},
{
"url": "https://git.kernel.org/stable/c/808033d80d5c9f8adf7e8de9317389270ce13430"
},
{
"url": "https://git.kernel.org/stable/c/9d000bdd250d649a11cd7f733175686877344582"
},
{
"url": "https://git.kernel.org/stable/c/01980b5da56e573d62798d0ff6c86bcaa2b22cbe"
}
],
"title": "spi: fsl-lpspi: terminate the RX channel on TX prepare failure path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64303",
"datePublished": "2026-07-25T08:49:38.223Z",
"dateReserved": "2026-07-19T15:36:31.779Z",
"dateUpdated": "2026-08-17T04:53:02.185Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64573 (GCVE-0-2026-64573)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: qca: fix NVM tag length underflow in TLV parser
In the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is
"while (idx < length - sizeof(struct tlv_type_nvm))". "length" is a signed
int from the firmware TLV header and sizeof(struct tlv_type_nvm) is a
size_t (12), so "length" is converted to size_t and any firmware-supplied
"length" < 12 makes the subtraction wrap to a huge value. The loop body
then reads a 12-byte struct tlv_type_nvm past the end of the short
vmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).
Rewrite the bound as "idx + sizeof(struct tlv_type_nvm) <= length"; both
operands are non-negative, so it no longer underflows and a "length" too
small for one record correctly skips the loop.
BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)
Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52
Workqueue: hci0 hci_power_on
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)
qca_uart_setup (drivers/bluetooth/btqca.c:948)
qca_setup (drivers/bluetooth/hci_qca.c:2029)
hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)
hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)
hci_power_on (net/bluetooth/hci_core.c:920)
process_one_work (kernel/workqueue.c:3322)
worker_thread (kernel/workqueue.c:3486)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ed53949cc92e28aaa3463d246942bda1fbb7f307 Version: 1caceadfb50432dbf6d808796cb6c34ebb6d662c Version: 427281f9498ed614f9aabc80e46ec077c487da6d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 02f05ed44b71152d5e11d29be28aed91c0489b4e Version: 5.15.159 ≤ Version: 6.1.91 ≤ Version: 6.6.31 ≤ Version: 6.8.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btqca.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a7ee11441d71ab036a705d110a415421f5a4a898",
"status": "affected",
"version": "ed53949cc92e28aaa3463d246942bda1fbb7f307",
"versionType": "git"
},
{
"lessThan": "5d34e537755d2f9eba2d4e54d70126f987ef20b4",
"status": "affected",
"version": "1caceadfb50432dbf6d808796cb6c34ebb6d662c",
"versionType": "git"
},
{
"lessThan": "70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24",
"status": "affected",
"version": "427281f9498ed614f9aabc80e46ec077c487da6d",
"versionType": "git"
},
{
"lessThan": "59fd2f075bca94f030c7c78e94878ea0803d7690",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"lessThan": "a087ed960fce54e9302796229e9d545bbc9bcd4a",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"lessThan": "4fcfb5b2c736785464ff9745f94c6726c5ee2d85",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"lessThan": "c90164ca0f7036942ba088eb7ea8d3f6c2352020",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"status": "affected",
"version": "02f05ed44b71152d5e11d29be28aed91c0489b4e",
"versionType": "git"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.159",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.91",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.31",
"versionType": "semver"
},
{
"lessThan": "6.9",
"status": "affected",
"version": "6.8.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btqca.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.159",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.91",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.8.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx \u003c length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" \u003c 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc\u0027d firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) \u003c= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n Workqueue: hci0 hci_power_on\n Call Trace:\n ...\n kasan_report (mm/kasan/report.c:595)\n qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n qca_uart_setup (drivers/bluetooth/btqca.c:948)\n qca_setup (drivers/bluetooth/hci_qca.c:2029)\n hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n hci_power_on (net/bluetooth/hci_core.c:920)\n process_one_work (kernel/workqueue.c:3322)\n worker_thread (kernel/workqueue.c:3486)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:52.002Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a7ee11441d71ab036a705d110a415421f5a4a898"
},
{
"url": "https://git.kernel.org/stable/c/5d34e537755d2f9eba2d4e54d70126f987ef20b4"
},
{
"url": "https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24"
},
{
"url": "https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690"
},
{
"url": "https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a"
},
{
"url": "https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85"
},
{
"url": "https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020"
}
],
"title": "Bluetooth: qca: fix NVM tag length underflow in TLV parser",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64573",
"datePublished": "2026-08-05T08:08:09.669Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:52.002Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72342 (GCVE-0-2026-72342)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-17 05:43
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix HV VHCA stats agent registration race
mlx5e_hv_vhca_stats_create() registers the stats agent through
mlx5_hv_vhca_agent_create(). The helper publishes the agent in
hv_vhca->agents[type] under agents_lock and immediately schedules an
asynchronous control invalidation on the HV VHCA workqueue before
returning to mlx5e.
The asynchronous invalidation invokes the control agent's invalidate
callback, which reads the hypervisor control block and forwards the
command to mlx5e_hv_vhca_stats_control(). That callback may either:
- call cancel_delayed_work_sync(&priv->stats_agent.work), or
- call queue_delayed_work(priv->wq, &sagent->work, sagent->delay).
However, the delayed_work and priv->stats_agent.agent are only
initialized after mlx5_hv_vhca_agent_create() returns to mlx5e:
agent = mlx5_hv_vhca_agent_create(...); /* publish + invalidate */
...
priv->stats_agent.agent = agent; /* too late */
INIT_DELAYED_WORK(&priv->stats_agent.work, ...); /* too late */
If the asynchronous control path runs before the two assignments
above, it can:
- Operate on an uninitialized delayed_work whose timer.function is
NULL. queue_delayed_work() calls add_timer() unconditionally, so
when the timer expires the timer softirq invokes a NULL function
pointer.
- Re-initialize the timer later through INIT_DELAYED_WORK() while
the timer is already enqueued in the timer wheel, corrupting the
hlist (entry.pprev cleared while the previous bucket node still
points at this entry).
- When the worker eventually runs, mlx5e_hv_vhca_stats_work() reads
sagent->agent (NULL) and dereferences it inside
mlx5_hv_vhca_agent_write().
Fix this by:
- Initializing priv->stats_agent.work before invoking
mlx5_hv_vhca_agent_create(), so the work is always in a valid
state when the control callback observes it.
- Adding a struct mlx5_hv_vhca_agent **ctx_update out-parameter
to mlx5_hv_vhca_agent_create(). The helper writes the agent
pointer to *ctx_update before publishing into hv_vhca->agents[]
and triggering the agents_update flow, so any callback
subsequently invoked from that flow already sees a valid
priv->stats_agent.agent. This avoids having the control
callback participate in agent initialization.
While at it, access priv->stats_agent.agent with
READ_ONCE()/WRITE_ONCE() for the cross-CPU access with the worker, and
clear priv->stats_agent.buf on the agent_create() failure path.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cef35af34d6dc3792333075115c7deb7062b6e18 Version: cef35af34d6dc3792333075115c7deb7062b6e18 Version: cef35af34d6dc3792333075115c7deb7062b6e18 Version: cef35af34d6dc3792333075115c7deb7062b6e18 Version: cef35af34d6dc3792333075115c7deb7062b6e18 Version: cef35af34d6dc3792333075115c7deb7062b6e18 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.c",
"drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b0fd6d3bb06182f19f3b59a53f57b5098b99048a",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
},
{
"lessThan": "24c77044cdfcf5b8b2e9f3b620d8b9aa392d9add",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
},
{
"lessThan": "e8fc3304cb67fb1d7d11ff9ef9abd5fb64e7e1d5",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
},
{
"lessThan": "60fddda7207d81fea71463abd403f0b10f74f2e1",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
},
{
"lessThan": "f5677797b094c3ec5fb350eb8ea7710b88a3d018",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
},
{
"lessThan": "89b25b5f46f488ea3b29b3444864c76944c9075b",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.c",
"drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix HV VHCA stats agent registration race\n\nmlx5e_hv_vhca_stats_create() registers the stats agent through\nmlx5_hv_vhca_agent_create(). The helper publishes the agent in\nhv_vhca-\u003eagents[type] under agents_lock and immediately schedules an\nasynchronous control invalidation on the HV VHCA workqueue before\nreturning to mlx5e.\n\nThe asynchronous invalidation invokes the control agent\u0027s invalidate\ncallback, which reads the hypervisor control block and forwards the\ncommand to mlx5e_hv_vhca_stats_control(). That callback may either:\n\n - call cancel_delayed_work_sync(\u0026priv-\u003estats_agent.work), or\n - call queue_delayed_work(priv-\u003ewq, \u0026sagent-\u003ework, sagent-\u003edelay).\n\nHowever, the delayed_work and priv-\u003estats_agent.agent are only\ninitialized after mlx5_hv_vhca_agent_create() returns to mlx5e:\n\n agent = mlx5_hv_vhca_agent_create(...); /* publish + invalidate */\n ...\n priv-\u003estats_agent.agent = agent; /* too late */\n INIT_DELAYED_WORK(\u0026priv-\u003estats_agent.work, ...); /* too late */\n\nIf the asynchronous control path runs before the two assignments\nabove, it can:\n\n - Operate on an uninitialized delayed_work whose timer.function is\n NULL. queue_delayed_work() calls add_timer() unconditionally, so\n when the timer expires the timer softirq invokes a NULL function\n pointer.\n - Re-initialize the timer later through INIT_DELAYED_WORK() while\n the timer is already enqueued in the timer wheel, corrupting the\n hlist (entry.pprev cleared while the previous bucket node still\n points at this entry).\n - When the worker eventually runs, mlx5e_hv_vhca_stats_work() reads\n sagent-\u003eagent (NULL) and dereferences it inside\n mlx5_hv_vhca_agent_write().\n\nFix this by:\n\n - Initializing priv-\u003estats_agent.work before invoking\n mlx5_hv_vhca_agent_create(), so the work is always in a valid\n state when the control callback observes it.\n - Adding a struct mlx5_hv_vhca_agent **ctx_update out-parameter\n to mlx5_hv_vhca_agent_create(). The helper writes the agent\n pointer to *ctx_update before publishing into hv_vhca-\u003eagents[]\n and triggering the agents_update flow, so any callback\n subsequently invoked from that flow already sees a valid\n priv-\u003estats_agent.agent. This avoids having the control\n callback participate in agent initialization.\n\nWhile at it, access priv-\u003estats_agent.agent with\nREAD_ONCE()/WRITE_ONCE() for the cross-CPU access with the worker, and\nclear priv-\u003estats_agent.buf on the agent_create() failure path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in mlx5e HV VHCA stats agent registration during mlx5e driver attach on Hyper-V/Azure mlx5 NICs; it is reached via the VMBus PCI config back-channel and driver init, not via remote network packet handling.\nAC:L - mlx5_hv_vhca_agent_create() always queues asynchronous control invalidation before returning; on SMP hosts the workqueue races unfinished delayed_work/agent setup, and the path can be re-triggered via devlink reload or driver reattach.\nPR:N - No guest privileges are required: the race opens during normal mlx5e attach at boot/resume on CONFIG_PCI_HYPERV_INTERFACE systems, and the hypervisor can drive the control callback via the VHCA control block without guest credentials.\nUI:N - No user or administrator action is needed beyond normal VM boot and mlx5 driver initialization; exploitation does not depend on a victim opening files, mounting filesystems, or other interactive steps.\nS:U - Memory corruption and kernel crashes are confined to the guest kernel running mlx5e; the bug does not cross VM/host, IOMMU, or other security boundaries into a separate authority.\nC:H - The race can corrupt the kernel timer wheel hlist, invoke a NULL timer callback, or dereference a NULL agent during mlx5_hv_vhca_agent_write(), providing serious kernel memory corruption or disclosure primitives.\nI:H - Timer wheel hlist corruption and operating on uninitialized delayed_work structures are exploitable memory corruption that can be leveraged for arbitrary kernel writes or control-flow hijacking, not merely a bounded fault.\nA:H - Exploitation causes kernel oops/panic from NULL function-pointer timer callbacks, corrupted timer lists, or NULL agent dereferences, reliably denying availability of the affected system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:43:00.745Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b0fd6d3bb06182f19f3b59a53f57b5098b99048a"
},
{
"url": "https://git.kernel.org/stable/c/24c77044cdfcf5b8b2e9f3b620d8b9aa392d9add"
},
{
"url": "https://git.kernel.org/stable/c/e8fc3304cb67fb1d7d11ff9ef9abd5fb64e7e1d5"
},
{
"url": "https://git.kernel.org/stable/c/60fddda7207d81fea71463abd403f0b10f74f2e1"
},
{
"url": "https://git.kernel.org/stable/c/f5677797b094c3ec5fb350eb8ea7710b88a3d018"
},
{
"url": "https://git.kernel.org/stable/c/89b25b5f46f488ea3b29b3444864c76944c9075b"
}
],
"title": "net/mlx5e: Fix HV VHCA stats agent registration race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72342",
"datePublished": "2026-08-15T05:55:48.412Z",
"dateReserved": "2026-08-09T03:40:39.920Z",
"dateUpdated": "2026-08-17T05:43:00.745Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74694 (GCVE-0-2026-74694)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
ncsi_send_cmd_nl() takes the number of bytes to copy from the
attacker-controlled ncsi_pkt_hdr.length field of the in-band packet
header, while the source buffer is the NCSI_ATTR_DATA netlink
attribute whose readable size is nla_len() - sizeof(ncsi_pkt_hdr).
The two length sources are never cross-checked: only
nla_len() >= sizeof(struct ncsi_pkt_hdr) is enforced.
With hdr->length set larger than the attribute payload (up to 65535
against at most 2032 readable bytes), ncsi_cmd_handler_oem() copies
past the end of the netlink attribute buffer with unsafe_memcpy(),
leaking up to ~64KB of kernel heap memory into the transmitted NCSI
command packet. The destination skb is sized by the declared payload,
so the write side does not overflow - this is a pure OOB read /
information leak, reachable with CAP_NET_ADMIN on systems with a
registered NCSI device (e.g. OpenBMC on Aspeed BMC SoCs, where
NET_NCSI=y is standard).
Reject commands whose declared payload extends past the end of the
data attribute.
The issue was found by the autokbug dynamic kernel fuzzer at Tencent
Yunding Lab.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ncsi/ncsi-netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e60afa01d35f8b2671b27ca93309921427144cce",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "67c72b8ef63d9d9a610546fda30b116638f39745",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "4489b4a17892750131e4bef4bc1d3d703c8fb5ba",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "43c7d0a6917751ea898ae584d00f24f5deac46d4",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "b5231ad0b376b801ab8cf2962b182cc29deaedb3",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "02226af69362758046822840fc6a497f5de33f00",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "3a60b5af75abe8e3494ccd074fb4ae6e601a3e55",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "afa58b7384913c8773d837acdb07b035690ec5d2",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ncsi/ncsi-netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length\n\nncsi_send_cmd_nl() takes the number of bytes to copy from the\nattacker-controlled ncsi_pkt_hdr.length field of the in-band packet\nheader, while the source buffer is the NCSI_ATTR_DATA netlink\nattribute whose readable size is nla_len() - sizeof(ncsi_pkt_hdr).\nThe two length sources are never cross-checked: only\nnla_len() \u003e= sizeof(struct ncsi_pkt_hdr) is enforced.\n\nWith hdr-\u003elength set larger than the attribute payload (up to 65535\nagainst at most 2032 readable bytes), ncsi_cmd_handler_oem() copies\npast the end of the netlink attribute buffer with unsafe_memcpy(),\nleaking up to ~64KB of kernel heap memory into the transmitted NCSI\ncommand packet. The destination skb is sized by the declared payload,\nso the write side does not overflow - this is a pure OOB read /\ninformation leak, reachable with CAP_NET_ADMIN on systems with a\nregistered NCSI device (e.g. OpenBMC on Aspeed BMC SoCs, where\nNET_NCSI=y is standard).\n\nReject commands whose declared payload extends past the end of the\ndata attribute.\n\nThe issue was found by the autokbug dynamic kernel fuzzer at Tencent\nYunding Lab."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:57.113Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e60afa01d35f8b2671b27ca93309921427144cce"
},
{
"url": "https://git.kernel.org/stable/c/67c72b8ef63d9d9a610546fda30b116638f39745"
},
{
"url": "https://git.kernel.org/stable/c/4489b4a17892750131e4bef4bc1d3d703c8fb5ba"
},
{
"url": "https://git.kernel.org/stable/c/43c7d0a6917751ea898ae584d00f24f5deac46d4"
},
{
"url": "https://git.kernel.org/stable/c/b5231ad0b376b801ab8cf2962b182cc29deaedb3"
},
{
"url": "https://git.kernel.org/stable/c/02226af69362758046822840fc6a497f5de33f00"
},
{
"url": "https://git.kernel.org/stable/c/3a60b5af75abe8e3494ccd074fb4ae6e601a3e55"
},
{
"url": "https://git.kernel.org/stable/c/afa58b7384913c8773d837acdb07b035690ec5d2"
}
],
"title": "net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74694",
"datePublished": "2026-08-22T15:32:57.113Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-22T15:32:57.113Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64480 (GCVE-0-2026-64480)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ice1712: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails. The
ice1712 driver calls snd_ctl_new1() without checking the return value
before dereferencing the pointer in multiple places (ice1712.c,
ice1724.c, aureon.c), which can lead to NULL pointer dereferences.
Add NULL checks after snd_ctl_new1() calls and return -ENOMEM if any
fails.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0df0097ea2d52401c31e550389ac758c90e6a1eb Version: b9a4efd61b6b9f62f83752959e75a5dae20624fa Version: b9a4efd61b6b9f62f83752959e75a5dae20624fa Version: b9a4efd61b6b9f62f83752959e75a5dae20624fa Version: b9a4efd61b6b9f62f83752959e75a5dae20624fa Version: b9a4efd61b6b9f62f83752959e75a5dae20624fa Version: 286e17a1c3baeb1b1cd36b63ee16e8a6e63d558e Version: 6.1.34 ≤ Version: 6.3.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/pci/ice1712/aureon.c",
"sound/pci/ice1712/ice1712.c",
"sound/pci/ice1712/ice1724.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "57d59be545b309d4bb54ac472b15d1e67f254d95",
"status": "affected",
"version": "0df0097ea2d52401c31e550389ac758c90e6a1eb",
"versionType": "git"
},
{
"lessThan": "69bf1dfa3215524c4ae255bb9dce0770875abbeb",
"status": "affected",
"version": "b9a4efd61b6b9f62f83752959e75a5dae20624fa",
"versionType": "git"
},
{
"lessThan": "d34ad480b8896d2b486e2cf29ce1790326cad205",
"status": "affected",
"version": "b9a4efd61b6b9f62f83752959e75a5dae20624fa",
"versionType": "git"
},
{
"lessThan": "71b87108ad93d433cdb20704a8dc8852304cf2c2",
"status": "affected",
"version": "b9a4efd61b6b9f62f83752959e75a5dae20624fa",
"versionType": "git"
},
{
"lessThan": "38a7cc46370a57122fb29c4bfe48a851c0c64459",
"status": "affected",
"version": "b9a4efd61b6b9f62f83752959e75a5dae20624fa",
"versionType": "git"
},
{
"lessThan": "2b929b91b0f3bc6de8a844370049cd99ee8e31ff",
"status": "affected",
"version": "b9a4efd61b6b9f62f83752959e75a5dae20624fa",
"versionType": "git"
},
{
"status": "affected",
"version": "286e17a1c3baeb1b1cd36b63ee16e8a6e63d558e",
"versionType": "git"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.34",
"versionType": "semver"
},
{
"lessThan": "6.4",
"status": "affected",
"version": "6.3.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/pci/ice1712/aureon.c",
"sound/pci/ice1712/ice1712.c",
"sound/pci/ice1712/ice1724.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ice1712: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails. The\nice1712 driver calls snd_ctl_new1() without checking the return value\nbefore dereferencing the pointer in multiple places (ice1712.c,\nice1724.c, aureon.c), which can lead to NULL pointer dereferences.\n\nAdd NULL checks after snd_ctl_new1() calls and return -ENOMEM if any\nfails."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:26.964Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/57d59be545b309d4bb54ac472b15d1e67f254d95"
},
{
"url": "https://git.kernel.org/stable/c/69bf1dfa3215524c4ae255bb9dce0770875abbeb"
},
{
"url": "https://git.kernel.org/stable/c/d34ad480b8896d2b486e2cf29ce1790326cad205"
},
{
"url": "https://git.kernel.org/stable/c/71b87108ad93d433cdb20704a8dc8852304cf2c2"
},
{
"url": "https://git.kernel.org/stable/c/38a7cc46370a57122fb29c4bfe48a851c0c64459"
},
{
"url": "https://git.kernel.org/stable/c/2b929b91b0f3bc6de8a844370049cd99ee8e31ff"
}
],
"title": "ALSA: ice1712: check snd_ctl_new1() return value",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64480",
"datePublished": "2026-07-25T08:51:41.691Z",
"dateReserved": "2026-07-19T15:36:31.791Z",
"dateUpdated": "2026-08-17T04:56:26.964Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63879 (GCVE-0-2026-63879)
Vulnerability from cvelistv5
Published
2026-07-19 14:54
Modified
2026-08-05 12:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix amdgpu_hmm_range_get_pages
The notifier sequence must only be read once or otherwise we could work
with invalid pages.
While at it also fix the coding style, e.g. drop the pre-initialized
return value and use the common define for 2G range.
(cherry picked from commit c08972f555945cda57b0adb72272a37910153390)
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_hmm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2fd24407457a6b181ba827705678da70e528dcd0",
"status": "affected",
"version": "c1420a5dd4dd2a1ffc86965ad1c6f439afb130bc",
"versionType": "git"
},
{
"lessThan": "962d684b5dc0741dcd93485d41b450de402d5592",
"status": "affected",
"version": "c1420a5dd4dd2a1ffc86965ad1c6f439afb130bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_hmm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix amdgpu_hmm_range_get_pages\n\nThe notifier sequence must only be read once or otherwise we could work\nwith invalid pages.\n\nWhile at it also fix the coding style, e.g. drop the pre-initialized\nreturn value and use the common define for 2G range.\n\n(cherry picked from commit c08972f555945cda57b0adb72272a37910153390)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local AMDGPU DRM ioctls (e.g., AMDGPU_GEM_USERPTR, AMDGPU_CS) and KFD ioctls on /dev/kfd that call amdgpu_hmm_range_get_pages(); there is no network-facing entry point.\nAC:L - Exploitation requires a \u003e2GB userptr/SVM mapping and a concurrent munmap/remap during the multi-chunk HMM walk, but the attacker controls both the ioctl thread and the address-space manipulation, so the race is attacker-driven rather than dependent on uncontrollable conditions.\nPR:L - Any unprivileged local user with access to the AMDGPU render node or /dev/kfd (typically render/video group membership) can create large userptr buffers and submit GPU work that triggers the vulnerable HMM path; root or init-namespace capabilities are not required.\nUI:N - Exploitation is fully attacker-driven through GPU memory registration and command submission ioctls and does not require any action from another user or administrator.\nS:U - The flaw corrupts or misuses kernel-tracked page metadata and enables standard local kernel memory safety impact and privilege escalation within the same kernel security domain, not a VM escape or IOMMU boundary bypass.\nC:H - Re-reading the MMU notifier sequence per 2GB chunk lets later validation pass while earlier PFNs may reference unmapped or freed pages, giving the GPU (and kernel DMA helpers) a stale-page/use-after-free primitive that can disclose arbitrary physical memory contents.\nI:H - Stale PFNs from invalidated mappings can be DMA-mapped and written by GPU operations, enabling arbitrary memory corruption and potential control-flow hijacking via repurposed physical pages rather than a bounded or crash-only effect.\nA:H - Operating on invalid struct page pointers during pinning/DMA mapping can trigger kernel oopses or panics, and the underlying use-after-free class of bug inherently threatens system availability even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:36:49.976Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2fd24407457a6b181ba827705678da70e528dcd0"
},
{
"url": "https://git.kernel.org/stable/c/962d684b5dc0741dcd93485d41b450de402d5592"
}
],
"title": "drm/amdgpu: fix amdgpu_hmm_range_get_pages",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63879",
"datePublished": "2026-07-19T14:54:51.698Z",
"dateReserved": "2026-07-19T07:54:57.018Z",
"dateUpdated": "2026-08-05T12:36:49.976Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64056 (GCVE-0-2026-64056)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: cortina: Make RX SKB per-port
The SKB used to assemble packets from fragments in gmac_rx()
is static local, but the Gemini has two ethernet ports, meaning
there can be races between the ports on a bad day if a device
is using both.
Make the RX SKB a per-port variable and carry it over between
invocations in the port struct instead.
Zero the pointer once we call napi_gro_frags(), on error (after
calling napi_free_frags()) or if the port is stopped.
Zero it in some place where not strictly necessary just to
emphasize what is going on.
This was found by Sashiko during normal patch review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cortina/gemini.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "27856d533eca3804008695f61c1e4d5ff984196b",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "b6b22824b30e48ce1df3a2e80990f4b8505deb50",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "6bba24e9ebe6f1c0b356cd471e36bdc7fa434897",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "3b249988d774dacf13b203817e971934a42243c4",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "72158ea185b27afae163949b0e86164cb6b64e55",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "cfd62907f3cdbc3b6da8f49ba907c0390018fe5e",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "67a35e7da7ef9d2f000aa758552a128324c604a0",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "06937db21ee311ed07eba47954447245041a982d",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cortina/gemini.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.16"
},
{
"lessThan": "4.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: cortina: Make RX SKB per-port\n\nThe SKB used to assemble packets from fragments in gmac_rx()\nis static local, but the Gemini has two ethernet ports, meaning\nthere can be races between the ports on a bad day if a device\nis using both.\n\nMake the RX SKB a per-port variable and carry it over between\ninvocations in the port struct instead.\n\nZero the pointer once we call napi_gro_frags(), on error (after\ncalling napi_free_frags()) or if the port is stopped.\n\nZero it in some place where not strictly necessary just to\nemphasize what is going on.\n\nThis was found by Sashiko during normal patch review."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code runs in the netdev RX path (gmac_irq \u2192 napi_schedule \u2192 gmac_napi_poll \u2192 gmac_rx) when Ethernet frames are DMA\u0027d from the wire, so any remote host that can send packets to a reachable Gemini GMAC interface can trigger it.\nAC:L - An attacker controls both sides of the race by flooding one or both GMAC ports with multi-descriptor/jumbo frames to keep skb assembly in progress while concurrent NAPI polls run on the independent per-port IRQ handlers without serialization on the shared static skb pointer.\nPR:N - Exploitation requires only the ability to deliver Ethernet frames to an active interface; there are no authentication gates, capability checks, or local syscalls on the RX path from hardware interrupt through gmac_rx().\nUI:N - Triggering the race requires only crafted or high-volume network traffic; no victim interaction such as mounting a filesystem or opening a file is needed.\nS:U - The corruption is confined to kernel networking state (shared skb assembly between the two GMAC ports on the same host); impact does not cross a VM, IOMMU, or sandbox security boundary.\nC:H - Concurrent corruption of a shared skb and mismatched napi_get_frags/napi_gro_frags/napi_free_frags usage across ports can cause use-after-free and skb metadata corruption that enables arbitrary kernel memory disclosure.\nI:H - Cross-port skb corruption via concurrent skb_fill_page_desc and len updates, plus orphaned or double-freed skb/page state, provides memory corruption primitives that can be leveraged for arbitrary kernel writes or code execution.\nA:H - The race can cause kernel oopses or panics from slab/list corruption, invalid page refcount handling, or crashes inside napi_gro_frags when skb state is corrupted across the two ports."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:45.763Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/27856d533eca3804008695f61c1e4d5ff984196b"
},
{
"url": "https://git.kernel.org/stable/c/b6b22824b30e48ce1df3a2e80990f4b8505deb50"
},
{
"url": "https://git.kernel.org/stable/c/6bba24e9ebe6f1c0b356cd471e36bdc7fa434897"
},
{
"url": "https://git.kernel.org/stable/c/3b249988d774dacf13b203817e971934a42243c4"
},
{
"url": "https://git.kernel.org/stable/c/72158ea185b27afae163949b0e86164cb6b64e55"
},
{
"url": "https://git.kernel.org/stable/c/cfd62907f3cdbc3b6da8f49ba907c0390018fe5e"
},
{
"url": "https://git.kernel.org/stable/c/67a35e7da7ef9d2f000aa758552a128324c604a0"
},
{
"url": "https://git.kernel.org/stable/c/06937db21ee311ed07eba47954447245041a982d"
}
],
"title": "net: ethernet: cortina: Make RX SKB per-port",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64056",
"datePublished": "2026-07-19T15:39:37.673Z",
"dateReserved": "2026-07-19T07:54:57.030Z",
"dateUpdated": "2026-08-05T12:38:45.763Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64411 (GCVE-0-2026-64411)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ebtables: terminate table name before find_table_lock()
update_counters() and compat_update_counters() forward a user-supplied
32-byte table name to find_table_lock() without NUL-terminating it. On a
lookup miss, find_inlist_lock() calls try_then_request_module(..., "%s%s",
"ebtable_", name), and vsnprintf() reads past the name field and the
stack object until it hits a zero byte.
BUG: KASAN: stack-out-of-bounds in string (lib/vsprintf.c:648 lib/vsprintf.c:730)
Read of size 1 at addr ffff8880119dfb20 by task exploit/147
Call Trace:
...
string (lib/vsprintf.c:648 lib/vsprintf.c:730)
vsnprintf (lib/vsprintf.c:2945)
__request_module (kernel/module/kmod.c:150)
do_update_counters.isra.0 (net/bridge/netfilter/ebtables.c:371 net/bridge/netfilter/ebtables.c:380)
update_counters (net/bridge/netfilter/ebtables.c:1440)
do_ebt_set_ctl (net/bridge/netfilter/ebtables.c:2573)
nf_setsockopt (net/netfilter/nf_sockopt.c:101)
ip_setsockopt (net/ipv4/ip_sockglue.c:1424)
raw_setsockopt (net/ipv4/raw.c:847)
__sys_setsockopt (net/socket.c:2393)
...
compat_do_replace() shares the same unterminated name via
compat_copy_ebt_replace_from_user(); terminate it there too so all
find_table_lock() callers behave alike. The other callers already
terminate the name after the copy.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:28.908Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bridge/netfilter/ebtables.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4c046ca4e35a83ea32f6e748f54139f5fe2a1d01",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ab63ccefb9c71627f957a0724c2b9ebc869c6f20",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c6f539311e58e76aa96feef0f1572b13a564f8a2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2664f537ca5bcb2ef3fac2683dcca602e51fad24",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7436da6c1bc44654b7f11a17e746f6999fd37250",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6fe8d3cecd20bfaaaf440db3a06ba674d2f2e322",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b6183b1b88a722b6d8ea0cecc99eba168a15e0be",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a622d2e9608c9dff47fc2e5759ac7aa3a836b45d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bridge/netfilter/ebtables.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: terminate table name before find_table_lock()\n\nupdate_counters() and compat_update_counters() forward a user-supplied\n32-byte table name to find_table_lock() without NUL-terminating it. On a\nlookup miss, find_inlist_lock() calls try_then_request_module(..., \"%s%s\",\n\"ebtable_\", name), and vsnprintf() reads past the name field and the\nstack object until it hits a zero byte.\n\n BUG: KASAN: stack-out-of-bounds in string (lib/vsprintf.c:648 lib/vsprintf.c:730)\n Read of size 1 at addr ffff8880119dfb20 by task exploit/147\n Call Trace:\n ...\n string (lib/vsprintf.c:648 lib/vsprintf.c:730)\n vsnprintf (lib/vsprintf.c:2945)\n __request_module (kernel/module/kmod.c:150)\n do_update_counters.isra.0 (net/bridge/netfilter/ebtables.c:371 net/bridge/netfilter/ebtables.c:380)\n update_counters (net/bridge/netfilter/ebtables.c:1440)\n do_ebt_set_ctl (net/bridge/netfilter/ebtables.c:2573)\n nf_setsockopt (net/netfilter/nf_sockopt.c:101)\n ip_setsockopt (net/ipv4/ip_sockglue.c:1424)\n raw_setsockopt (net/ipv4/raw.c:847)\n __sys_setsockopt (net/socket.c:2393)\n ...\n\ncompat_do_replace() shares the same unterminated name via\ncompat_copy_ebt_replace_from_user(); terminate it there too so all\nfind_table_lock() callers behave alike. The other callers already\nterminate the name after the copy."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is reached through a local setsockopt() call into the legacy ebtables interface, not through received network traffic.\nAC:L - The attacker directly supplies a nonterminated table name and guarantees a lookup miss without racing or relying on conditions outside their control.\nPR:L - The path requires CAP_NET_ADMIN in the socket\u0027s network namespace, which an unprivileged user can obtain using a new user and network namespace.\nUI:N - No action by another user is required after the attacker invokes the crafted setsockopt() operation.\nS:U - The over-read affects the same host kernel security authority and does not cross a virtualization or comparable security boundary.\nC:H - The unbounded source read can copy kernel-stack contents into the generated module name, potentially exposing sensitive kernel data.\nI:N - The flaw performs an out-of-bounds read only; the destination formatting is bounded and no attacker-controlled write or memory corruption occurs.\nA:H - The unbounded scan can reach an unmapped stack boundary and cause an oops or panic, as supported by the demonstrated KASAN stack-out-of-bounds failure."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:10.076Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4c046ca4e35a83ea32f6e748f54139f5fe2a1d01"
},
{
"url": "https://git.kernel.org/stable/c/ab63ccefb9c71627f957a0724c2b9ebc869c6f20"
},
{
"url": "https://git.kernel.org/stable/c/c6f539311e58e76aa96feef0f1572b13a564f8a2"
},
{
"url": "https://git.kernel.org/stable/c/2664f537ca5bcb2ef3fac2683dcca602e51fad24"
},
{
"url": "https://git.kernel.org/stable/c/7436da6c1bc44654b7f11a17e746f6999fd37250"
},
{
"url": "https://git.kernel.org/stable/c/6fe8d3cecd20bfaaaf440db3a06ba674d2f2e322"
},
{
"url": "https://git.kernel.org/stable/c/b6183b1b88a722b6d8ea0cecc99eba168a15e0be"
},
{
"url": "https://git.kernel.org/stable/c/a622d2e9608c9dff47fc2e5759ac7aa3a836b45d"
}
],
"title": "netfilter: ebtables: terminate table name before find_table_lock()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64411",
"datePublished": "2026-07-25T08:50:52.143Z",
"dateReserved": "2026-07-19T15:36:31.786Z",
"dateUpdated": "2026-09-08T08:50:28.908Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68386 (GCVE-0-2026-68386)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Reject unhashed UDP sockets on sockmap update
UDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means
sk_is_refcounted(unbound) = true, while sk_is_refcounted(bound) = false.
Because sockmap accepts unbound UDP sockets, a BPF program can increment a
socket's refcount via lookup. If the socket is subsequently bound, the
transition from unbound to bound causes bpf_sk_release() to skip the
decrement of the refcount, causing a memory leak.
unreferenced object 0xffff88810bc2eb40 (size 1984):
comm "test_progs", pid 2451, jiffies 4295320596
hex dump (first 32 bytes):
7f 00 00 01 7f 00 00 01 d2 04 1b b7 04 d2 00 00 ................
02 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00 ...@............
backtrace (crc bdee079d):
kmem_cache_alloc_noprof+0x557/0x660
sk_prot_alloc+0x69/0x240
sk_alloc+0x30/0x460
inet_create+0x2ce/0xf80
__sock_create+0x25b/0x5c0
__sys_socket+0x119/0x1d0
__x64_sys_socket+0x72/0xd0
do_syscall_64+0xa1/0x5f0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
Instead of special-casing for refcounted sockets, reject unhashed UDP
sockets during sockmap updates, as there is no benefit to supporting those.
This effectively reverts the commit under Fixes, with two exceptions:
1. sock_map_sk_state_allowed() maintains a fall-through `return true`.
2. In the spirit of commit b8b8315e39ff ("bpf, sockmap: Remove unhash
handler for BPF sockmap usage"), the proto::unhash BPF handler is not
reintroduced.
Historical note: this issue is related to commit 67312adc96b5 ("bpf: reject
unhashed sockets in bpf_sk_assign").
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/sock_map.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2271276ac5279d2d204be7739a1a28d4ef6cf608",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "7ffe529e7127411806c8692fb1490f552c629dc2",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "17b7ef6b86112a4e61cee1e9009a4b318e3225c5",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "250474c69bc3fc48a5fc21d7c349f279caad947a",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "8692655da369961128658cf8539334b6a960ecb0",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "66efd3368ae10d05e08fbe6425b50fdec7186ac7",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/sock_map.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Reject unhashed UDP sockets on sockmap update\n\nUDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means\nsk_is_refcounted(unbound) = true, while sk_is_refcounted(bound) = false.\n\nBecause sockmap accepts unbound UDP sockets, a BPF program can increment a\nsocket\u0027s refcount via lookup. If the socket is subsequently bound, the\ntransition from unbound to bound causes bpf_sk_release() to skip the\ndecrement of the refcount, causing a memory leak.\n\nunreferenced object 0xffff88810bc2eb40 (size 1984):\n comm \"test_progs\", pid 2451, jiffies 4295320596\n hex dump (first 32 bytes):\n 7f 00 00 01 7f 00 00 01 d2 04 1b b7 04 d2 00 00 ................\n 02 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00 ...@............\n backtrace (crc bdee079d):\n kmem_cache_alloc_noprof+0x557/0x660\n sk_prot_alloc+0x69/0x240\n sk_alloc+0x30/0x460\n inet_create+0x2ce/0xf80\n __sock_create+0x25b/0x5c0\n __sys_socket+0x119/0x1d0\n __x64_sys_socket+0x72/0xd0\n do_syscall_64+0xa1/0x5f0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nInstead of special-casing for refcounted sockets, reject unhashed UDP\nsockets during sockmap updates, as there is no benefit to supporting those.\nThis effectively reverts the commit under Fixes, with two exceptions:\n\n1. sock_map_sk_state_allowed() maintains a fall-through `return true`.\n2. In the spirit of commit b8b8315e39ff (\"bpf, sockmap: Remove unhash\n handler for BPF sockmap usage\"), the proto::unhash BPF handler is not\n reintroduced.\n\nHistorical note: this issue is related to commit 67312adc96b5 (\"bpf: reject\nunhashed sockets in bpf_sk_assign\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:40.363Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2271276ac5279d2d204be7739a1a28d4ef6cf608"
},
{
"url": "https://git.kernel.org/stable/c/7ffe529e7127411806c8692fb1490f552c629dc2"
},
{
"url": "https://git.kernel.org/stable/c/17b7ef6b86112a4e61cee1e9009a4b318e3225c5"
},
{
"url": "https://git.kernel.org/stable/c/250474c69bc3fc48a5fc21d7c349f279caad947a"
},
{
"url": "https://git.kernel.org/stable/c/8692655da369961128658cf8539334b6a960ecb0"
},
{
"url": "https://git.kernel.org/stable/c/66efd3368ae10d05e08fbe6425b50fdec7186ac7"
}
],
"title": "bpf, sockmap: Reject unhashed UDP sockets on sockmap update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68386",
"datePublished": "2026-08-10T12:04:05.306Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-19T16:34:40.363Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74717 (GCVE-0-2026-74717)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: fw_tracer, return NULL on create error
Tracer creation can fail by returning either NULL or ERR_PTR.
The return value is stored without a check on the device, and users
treat ERR_PTR and NULL the same way.
This also causes a crash in the core dump logic, which is missing the
ERR_PTR check and ends up dereferencing it, as shown in the trace below.
Switch tracer creation to return NULL on failure only, so callers only
need a single NULL check.
Internal error: Oops: 0000000096000006 [#1] SMP
Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core
CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none)
Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core]
pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core]
lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core]
sp : ffff800081cf3c40
x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000
x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05
x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000
x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0
x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac
x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650
x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8
x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030
x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e
Call trace:
mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P)
mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core]
devlink_health_do_dump+0x9c/0x160
devlink_health_report+0x1c0/0x288
mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core]
process_one_work+0x15c/0x3d8
worker_thread+0x18c/0x320
kthread+0x148/0x228
ret_from_fork+0x10/0x20
Code: b9400000 5ac00800 7a401800 540003ca (3940a260)
---[ end trace 0000000000000000 ]---
Kernel panic - not syncing: Oops: Fatal exception
SMP: stopping secondary CPUs
Kernel Offset: disabled
CPU features: 0x000000,00078031,75fce5a1,35fffe67
Memory Limit: none
---[ end Kernel panic - not syncing: Oops: Fatal exception ]---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "47fe0d2571e5b446a0f0b0c1d6b99f55e51f5cc0",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "ee41ea49c4ab0e4015919f52ad23ec251d3b39d3",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "04599570c3a18f9ae7aad36825eb46f3dcd2c4e3",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "9a416f000285a94c1b723877547981dec8132434",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "b1d6375b9a63c9dc7e5e780d3ea9b126fe30d6cb",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "80094352bd40ba54a33731f9c22872493983ed6d",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "4aafa600d93e9551c1f24e785d57cbd4adf021d5",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "af39eb111ce6b5eba9c08513b62c4868eb7e7fd5",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: fw_tracer, return NULL on create error\n\nTracer creation can fail by returning either NULL or ERR_PTR.\nThe return value is stored without a check on the device, and users\ntreat ERR_PTR and NULL the same way.\nThis also causes a crash in the core dump logic, which is missing the\nERR_PTR check and ends up dereferencing it, as shown in the trace below.\n\nSwitch tracer creation to return NULL on failure only, so callers only\nneed a single NULL check.\n\n Internal error: Oops: 0000000096000006 [#1] SMP\n Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core\n CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none)\n Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core]\n pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core]\n lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core]\n sp : ffff800081cf3c40\n x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000\n x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05\n x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000\n x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0\n x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac\n x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650\n x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8\n x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000\n x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030\n x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e\n Call trace:\n mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P)\n mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core]\n devlink_health_do_dump+0x9c/0x160\n devlink_health_report+0x1c0/0x288\n mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core]\n process_one_work+0x15c/0x3d8\n worker_thread+0x18c/0x320\n kthread+0x148/0x228\n ret_from_fork+0x10/0x20\n Code: b9400000 5ac00800 7a401800 540003ca (3940a260)\n ---[ end trace 0000000000000000 ]---\n Kernel panic - not syncing: Oops: Fatal exception\n SMP: stopping secondary CPUs\n Kernel Offset: disabled\n CPU features: 0x000000,00078031,75fce5a1,35fffe67\n Memory Limit: none\n ---[ end Kernel panic - not syncing: Oops: Fatal exception ]---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On internet-facing cloud/HPC hosts with mlx5 PF NICs, a remote attacker can induce ConnectX firmware syndrome via crafted network/RDMA traffic; the kernel health poller then auto-invokes mlx5_fw_reporter_dump without any local syscall.\nAC:L - On affected hardware, mlx5_fw_tracer_create leaves ERR_PTR in dev-\u003etracer at probe (e.g. -EOPNOTSUPP when trace_to_memory is unset); once present, any FW syndrome or health miss counter event reliably queues the dump workqueue that dereferences the bad pointer.\nPR:N - The crash path shown in the fix oops is triggered automatically by mlx5_fw_reporter_err_work from the health poller with no userspace action; inducing FW syndrome over the network requires no host credentials, unlike the optional devlink dump path that needs CAP_NET_ADMIN.\nUI:N - Exploitation requires no victim interaction; the devlink health auto_dump fires from kernel workqueues when firmware reports a syndrome or miss-count threshold, independent of user actions such as mounts or file opens.\nS:U - Impact is confined to kernel crash/panic on the host running mlx5_core; there is no VM escape, IOMMU bypass, or crossing from guest VF context into a separate security authority beyond standard host kernel failure.\nC:N - The bug is an ERR_PTR mishandled as a valid mlx5_fw_tracer pointer; mlx5_fw_tracer_trigger_core_dump_general dereferences tracer-\u003eowner and faults immediately, producing an oops with no out-of-bounds read, UAF, or information disclosure primitive.\nI:N - Faulting on an ERR_PTR-encoded address does not corrupt adjacent memory or provide a controllable write primitive; the only outcome is an unrecoverable kernel oops/panic, not arbitrary modification or code execution.\nA:H - The fix commit documents a fatal kernel Oops in mlx5_fw_tracer_trigger_core_dump_general followed by \u0027Kernel panic - not syncing\u0027, causing complete loss of host availability on affected mlx5 PF systems when the FW reporter dump path runs."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:59.788Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/47fe0d2571e5b446a0f0b0c1d6b99f55e51f5cc0"
},
{
"url": "https://git.kernel.org/stable/c/ee41ea49c4ab0e4015919f52ad23ec251d3b39d3"
},
{
"url": "https://git.kernel.org/stable/c/04599570c3a18f9ae7aad36825eb46f3dcd2c4e3"
},
{
"url": "https://git.kernel.org/stable/c/9a416f000285a94c1b723877547981dec8132434"
},
{
"url": "https://git.kernel.org/stable/c/b1d6375b9a63c9dc7e5e780d3ea9b126fe30d6cb"
},
{
"url": "https://git.kernel.org/stable/c/80094352bd40ba54a33731f9c22872493983ed6d"
},
{
"url": "https://git.kernel.org/stable/c/4aafa600d93e9551c1f24e785d57cbd4adf021d5"
},
{
"url": "https://git.kernel.org/stable/c/af39eb111ce6b5eba9c08513b62c4868eb7e7fd5"
}
],
"title": "net/mlx5: fw_tracer, return NULL on create error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74717",
"datePublished": "2026-08-22T15:33:11.488Z",
"dateReserved": "2026-08-15T05:44:03.928Z",
"dateUpdated": "2026-08-25T05:41:59.788Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64562 (GCVE-0-2026-64562)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: nVMX: Hide shadow VMCS right after VMCLEAR
free_nested() frees the shadow VMCS while vmcs01 still points to it. But
because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU
might migrate before the pointer is cleared and __loaded_vmcs_clear()
may then execute VMCLEAR.
The VMCS needs to stay attached until its explicit VMCLEAR completes, but
then it can be hidden and the page safely freed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/vmx/nested.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b82c3144d8264265448292ca406f60bafeba3b6f",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "4f50e6aec16f69627dbad5704d1e90a255d766a7",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "dc3eecfa219ebc9d01eaf7d1abd1441efe884dab",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "af56298e9d86e6098cd1d2e155cb2949b7c45412",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "589419470030a89f16cf19300658b6dc644ca946",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "8001d2ce9d9bd09118ce523aef595aa094573ae3",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "1dabef6e206568bf9d9ade74f6e56a48ea35695d",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "622ebfac01ba4f9c0060cebd41257fe46fc4a0b3",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/vmx/nested.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Hide shadow VMCS right after VMCLEAR\n\nfree_nested() frees the shadow VMCS while vmcs01 still points to it. But\nbecause it is asynchronous with respect to loaded_vmcs_clear(), the vCPU\nmight migrate before the pointer is cleared and __loaded_vmcs_clear()\nmay then execute VMCLEAR.\n\nThe VMCS needs to stay attached until its explicit VMCLEAR completes, but\nthen it can be hidden and the page safely freed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through local KVM nested VMX: open /dev/kvm, run a nested guest, then tear down nested state (VMXOFF/handle_vmxoff or vmx_leave_nested). It is not reachable via network or adjacent-radio packets.\nAC:L - A KVM VMM attacker controls both sides of the race by driving nested teardown (VMXOFF/vcpu destroy) while forcing vCPU migration via thread affinity/scheduling so __loaded_vmcs_clear() VMCLEARs the dangling shadow VMCS pointer.\nPR:L - Exploitation needs permission to use /dev/kvm and nested VMX (commonly kvm-group or equivalent), not real init-namespace root; KVM create/run ioctls have no CAP_SYS_ADMIN gate on this path.\nUI:N - After the attacker has KVM/nested access, they trigger free_nested and migration themselves; no separate victim action is required.\nS:C - free_nested runs in host KVM while handling L1 nested VMX teardown, and the UAF corrupts host kernel memory, crossing the guest/hypervisor isolation boundary (guest-to-host escape class).\nC:H - The dangling shadow VMCS pointer lets VMCLEAR operate on a freed page that may be reused, yielding a host kernel use-after-free that can be leveraged for arbitrary information disclosure.\nI:H - VMCLEAR writes VMCS state into the freed page; with page reuse this is host heap corruption enabling write primitives and potential host code execution, consistent with UAF guidance.\nA:H - Use-after-free of the shadow VMCS page can oops/panic the host kernel when VMCLEAR or later accessors touch reallocated memory, fully denying host availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:32.954Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b82c3144d8264265448292ca406f60bafeba3b6f"
},
{
"url": "https://git.kernel.org/stable/c/4f50e6aec16f69627dbad5704d1e90a255d766a7"
},
{
"url": "https://git.kernel.org/stable/c/dc3eecfa219ebc9d01eaf7d1abd1441efe884dab"
},
{
"url": "https://git.kernel.org/stable/c/af56298e9d86e6098cd1d2e155cb2949b7c45412"
},
{
"url": "https://git.kernel.org/stable/c/589419470030a89f16cf19300658b6dc644ca946"
},
{
"url": "https://git.kernel.org/stable/c/8001d2ce9d9bd09118ce523aef595aa094573ae3"
},
{
"url": "https://git.kernel.org/stable/c/1dabef6e206568bf9d9ade74f6e56a48ea35695d"
},
{
"url": "https://git.kernel.org/stable/c/622ebfac01ba4f9c0060cebd41257fe46fc4a0b3"
}
],
"title": "KVM: nVMX: Hide shadow VMCS right after VMCLEAR",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64562",
"datePublished": "2026-08-04T06:23:21.855Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-08-19T16:28:32.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68445 (GCVE-0-2026-68445)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vc4: Prevent shader BO mappings from becoming writable
vc4_gem_object_mmap() rejects a writable mapping of a validated shader
BO, but leaves VM_MAYWRITE set. Userspace can map the BO read-only and
then turn it writable with mprotect().
Validated shader BOs must stay read-only: the validator checks the
instructions once and the GPU trusts them afterwards. A writable
mapping lets userspace rewrite the code after validation, bypassing the
validator.
Clear VM_MAYWRITE on the read-only path so the mapping cannot be
upgraded, as i915 already does for its read-only objects.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_bo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9f0ee411fc2d76333d6087c5862ffa907cf7a175",
"status": "affected",
"version": "463873d5701427f2964a0b4b72c45f1f14b6df87",
"versionType": "git"
},
{
"lessThan": "019e6ad247f7fd038d2e009789f6d9bfcccb1ae7",
"status": "affected",
"version": "463873d5701427f2964a0b4b72c45f1f14b6df87",
"versionType": "git"
},
{
"lessThan": "6deaa317201851c644c431b57682e54d06b35838",
"status": "affected",
"version": "463873d5701427f2964a0b4b72c45f1f14b6df87",
"versionType": "git"
},
{
"lessThan": "fe168ef1d232d734d9998fd74822e2e20930dfff",
"status": "affected",
"version": "463873d5701427f2964a0b4b72c45f1f14b6df87",
"versionType": "git"
},
{
"lessThan": "0c9e6367639548307d3f578f6943ce72c9d39087",
"status": "affected",
"version": "463873d5701427f2964a0b4b72c45f1f14b6df87",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_bo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Prevent shader BO mappings from becoming writable\n\nvc4_gem_object_mmap() rejects a writable mapping of a validated shader\nBO, but leaves VM_MAYWRITE set. Userspace can map the BO read-only and\nthen turn it writable with mprotect().\n\nValidated shader BOs must stay read-only: the validator checks the\ninstructions once and the GPU trusts them afterwards. A writable\nmapping lets userspace rewrite the code after validation, bypassing the\nvalidator.\n\nClear VM_MAYWRITE on the read-only path so the mapping cannot be\nupgraded, as i915 already does for its read-only objects."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to the vc4 DRM render node (/dev/dri/renderD*) to issue VC4_CREATE_SHADER_BO, VC4_MMAP_BO, mmap/mprotect and VC4_SUBMIT_CL; there is no remote or network-facing path to this code.\nAC:L - The attacker fully controls every step: create a shader that passes validation, map it PROT_READ, upgrade it with mprotect(PROT_WRITE), rewrite the instructions and submit. There is no race, no memory-layout dependency, and it works on the default configuration of any VC4 (Raspberry Pi) system.\nPR:L - VC4_CREATE_SHADER_BO, VC4_MMAP_BO and VC4_SUBMIT_CL are all DRM_RENDER_ALLOW ioctls, so an ordinary unprivileged user with render-node access (the default for logged-in/graphical users on Raspberry Pi and embedded VC4 devices) can perform the whole sequence. No capability check is involved.\nUI:N - The attacking process performs the entire sequence itself; no action by another user or administrator is needed.\nS:U - The vulnerable driver and the compromised resource (kernel/system memory) are both under the kernel\u0027s security authority; this is a standard local kernel privilege escalation rather than a VM or hypervisor boundary escape.\nC:H - Post-validation rewriting of shader code lets the GPU, which has no IOMMU on VC4, read arbitrary system memory via texture, uniform and direct-addressed TMU lookups \u2014 exactly the disclosure the validator exists to prevent, giving arbitrary kernel memory read.\nI:H - Unvalidated QPU code can use the VPM write address register in general-purpose DMA mode to write to arbitrary physical addresses, an arbitrary kernel-memory write primitive that yields full privilege escalation and code execution.\nA:H - The same arbitrary DMA writes and unbounded shader execution readily corrupt kernel structures or hang the GPU, causing kernel panics or a full system hang triggerable at will by an unprivileged user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:42.989Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9f0ee411fc2d76333d6087c5862ffa907cf7a175"
},
{
"url": "https://git.kernel.org/stable/c/019e6ad247f7fd038d2e009789f6d9bfcccb1ae7"
},
{
"url": "https://git.kernel.org/stable/c/6deaa317201851c644c431b57682e54d06b35838"
},
{
"url": "https://git.kernel.org/stable/c/fe168ef1d232d734d9998fd74822e2e20930dfff"
},
{
"url": "https://git.kernel.org/stable/c/0c9e6367639548307d3f578f6943ce72c9d39087"
}
],
"title": "drm/vc4: Prevent shader BO mappings from becoming writable",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68445",
"datePublished": "2026-08-12T00:07:36.230Z",
"dateReserved": "2026-07-30T09:28:09.394Z",
"dateUpdated": "2026-08-17T05:05:42.989Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64276 (GCVE-0-2026-64276)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
rmi_f30_map_gpios() allocates gpioled_key_map with
min(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but
rmi_f30_attention() iterates the full f30->gpioled_count (device query
register, range 0..31) and dereferences gpioled_key_map[i], and
input->keycodemax is set to the full gpioled_count while input->keycode
points at the 6-entry allocation.
A device that reports gpioled_count > 6 with GPIO support enabled
therefore causes an out-of-bounds read on the attention interrupt and
out-of-bounds read/write through the EVIOCGKEYCODE/EVIOCSKEYCODE ioctls,
which bound the index only against keycodemax. This is the same defect
as the F3A handler, which was copied from F30.
Size the keymap for the full gpioled_count; the mapping loop still
assigns only the first min(gpioled_count, TRACKSTICK_RANGE_END) entries.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3e64fcbdbd10e46dede502d507dbcc104837cd59 Version: 3e64fcbdbd10e46dede502d507dbcc104837cd59 Version: 3e64fcbdbd10e46dede502d507dbcc104837cd59 Version: 3e64fcbdbd10e46dede502d507dbcc104837cd59 Version: 3e64fcbdbd10e46dede502d507dbcc104837cd59 Version: 3e64fcbdbd10e46dede502d507dbcc104837cd59 Version: 3e64fcbdbd10e46dede502d507dbcc104837cd59 Version: 3e64fcbdbd10e46dede502d507dbcc104837cd59 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f30.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8c6d18d61bb6fe0e6edf848413391c590552e8a9",
"status": "affected",
"version": "3e64fcbdbd10e46dede502d507dbcc104837cd59",
"versionType": "git"
},
{
"lessThan": "d162a1ead7de404d8b41a093c83ed0db6487cded",
"status": "affected",
"version": "3e64fcbdbd10e46dede502d507dbcc104837cd59",
"versionType": "git"
},
{
"lessThan": "f0be9eba946e9200b43265e0a748d38bd0a56954",
"status": "affected",
"version": "3e64fcbdbd10e46dede502d507dbcc104837cd59",
"versionType": "git"
},
{
"lessThan": "26c895928d7118436a24f564587cb4aefc40cdd8",
"status": "affected",
"version": "3e64fcbdbd10e46dede502d507dbcc104837cd59",
"versionType": "git"
},
{
"lessThan": "4e3689c26854356f41fbaa1eafa382e58ac79e00",
"status": "affected",
"version": "3e64fcbdbd10e46dede502d507dbcc104837cd59",
"versionType": "git"
},
{
"lessThan": "e849c6f51e6877104c765da084e001ec37c8e119",
"status": "affected",
"version": "3e64fcbdbd10e46dede502d507dbcc104837cd59",
"versionType": "git"
},
{
"lessThan": "bfe622efecd4ff0a792d0ecd1a8dce535a902f50",
"status": "affected",
"version": "3e64fcbdbd10e46dede502d507dbcc104837cd59",
"versionType": "git"
},
{
"lessThan": "d577e46785d45484b2ab7e7309c49b18764bf56c",
"status": "affected",
"version": "3e64fcbdbd10e46dede502d507dbcc104837cd59",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f30.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count\n\nrmi_f30_map_gpios() allocates gpioled_key_map with\nmin(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but\nrmi_f30_attention() iterates the full f30-\u003egpioled_count (device query\nregister, range 0..31) and dereferences gpioled_key_map[i], and\ninput-\u003ekeycodemax is set to the full gpioled_count while input-\u003ekeycode\npoints at the 6-entry allocation.\n\nA device that reports gpioled_count \u003e 6 with GPIO support enabled\ntherefore causes an out-of-bounds read on the attention interrupt and\nout-of-bounds read/write through the EVIOCGKEYCODE/EVIOCSKEYCODE ioctls,\nwhich bound the index only against keycodemax. This is the same defect\nas the F3A handler, which was copied from F30.\n\nSize the keymap for the full gpioled_count; the mapping loop still\nassigns only the first min(gpioled_count, TRACKSTICK_RANGE_END) entries."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - An unprivileged local process that can open the affected /dev/input/event node can reach the flawed table through EVIOCGKEYCODE or EVIOCSKEYCODE; no physical reattachment or network path is required on systems with an affected F30 device.\nAC:L - Once an F30 device reports more than six GPIO/LEDs, attacker-selected indices deterministically trigger two-byte heap out-of-bounds reads or writes. No race or condition outside the attacker\u0027s control is required.\nPR:L - The evdev ioctl path contains no capability or namespace privilege check, so any ordinary user permitted to open the event node can trigger it.\nUI:N - The attacker directly issues the ioctls, and the separate attention path is device-driven; neither requires action by another user.\nS:U - The vulnerable driver and the affected kernel memory share the same security authority. Kernel privilege escalation or code execution does not itself cross a VM, IOMMU, or other scope boundary.\nC:H - EVIOCGKEYCODE returns attacker-selected out-of-bounds u16 values and can disclose multiple adjacent slab words across the available indices. This heap disclosure can expose security-sensitive kernel data and facilitate further exploitation.\nI:H - EVIOCSKEYCODE performs attacker-controlled u16 writes beyond the allocation at selectable offsets. These writes can corrupt adjacent heap objects or metadata and plausibly enable control-flow hijacking.\nA:H - The controlled heap corruption can damage adjacent kernel objects and cause an oops or panic, while the device can also repeatedly trigger the out-of-bounds attention path."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:31.046Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8c6d18d61bb6fe0e6edf848413391c590552e8a9"
},
{
"url": "https://git.kernel.org/stable/c/d162a1ead7de404d8b41a093c83ed0db6487cded"
},
{
"url": "https://git.kernel.org/stable/c/f0be9eba946e9200b43265e0a748d38bd0a56954"
},
{
"url": "https://git.kernel.org/stable/c/26c895928d7118436a24f564587cb4aefc40cdd8"
},
{
"url": "https://git.kernel.org/stable/c/4e3689c26854356f41fbaa1eafa382e58ac79e00"
},
{
"url": "https://git.kernel.org/stable/c/e849c6f51e6877104c765da084e001ec37c8e119"
},
{
"url": "https://git.kernel.org/stable/c/bfe622efecd4ff0a792d0ecd1a8dce535a902f50"
},
{
"url": "https://git.kernel.org/stable/c/d577e46785d45484b2ab7e7309c49b18764bf56c"
}
],
"title": "Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64276",
"datePublished": "2026-07-25T08:49:21.300Z",
"dateReserved": "2026-07-19T15:36:31.776Z",
"dateUpdated": "2026-08-17T04:52:31.046Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46070 (GCVE-0-2026-46070)
Vulnerability from cvelistv5
Published
2026-05-27 12:57
Modified
2026-08-05 12:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
md/raid5: validate payload size before accessing journal metadata
r5c_recovery_analyze_meta_block() and
r5l_recovery_verify_data_checksum_for_mb() iterate over payloads in a
journal metadata block using on-disk payload size fields without
validating them against the remaining space in the metadata block.
A corrupted journal contains payload sizes extending beyond the PAGE_SIZE
boundary can cause out-of-bounds reads when accessing payload fields or
computing offsets.
Add bounds validation for each payload type to ensure the full payload
fits within meta_size before processing.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b4c625c67362b3940f619c1a836b4e8329106658 Version: b4c625c67362b3940f619c1a836b4e8329106658 Version: b4c625c67362b3940f619c1a836b4e8329106658 Version: b4c625c67362b3940f619c1a836b4e8329106658 Version: b4c625c67362b3940f619c1a836b4e8329106658 Version: b4c625c67362b3940f619c1a836b4e8329106658 Version: b4c625c67362b3940f619c1a836b4e8329106658 Version: b4c625c67362b3940f619c1a836b4e8329106658 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/raid5-cache.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c96c6f01d84b5c67db1bf1cc8591c0b7146826fc",
"status": "affected",
"version": "b4c625c67362b3940f619c1a836b4e8329106658",
"versionType": "git"
},
{
"lessThan": "ef4851d8324fd978ca1ff9ec76a275438f887743",
"status": "affected",
"version": "b4c625c67362b3940f619c1a836b4e8329106658",
"versionType": "git"
},
{
"lessThan": "28d3ff7109c66e99dc1b7cddacb5c760849620ef",
"status": "affected",
"version": "b4c625c67362b3940f619c1a836b4e8329106658",
"versionType": "git"
},
{
"lessThan": "33698bd1b2db9764a29df7751533d33967ff5c98",
"status": "affected",
"version": "b4c625c67362b3940f619c1a836b4e8329106658",
"versionType": "git"
},
{
"lessThan": "c3a1cf78bd1bbb51b2cc5189b4743056553c1e0e",
"status": "affected",
"version": "b4c625c67362b3940f619c1a836b4e8329106658",
"versionType": "git"
},
{
"lessThan": "73ce72edd113374801045924d4417199963f73a3",
"status": "affected",
"version": "b4c625c67362b3940f619c1a836b4e8329106658",
"versionType": "git"
},
{
"lessThan": "406aa86394ead347c47428fb51b6359bdaa2257d",
"status": "affected",
"version": "b4c625c67362b3940f619c1a836b4e8329106658",
"versionType": "git"
},
{
"lessThan": "b0cc3ae97e893bf54bbce447f4e9fd2e0b88bff9",
"status": "affected",
"version": "b4c625c67362b3940f619c1a836b4e8329106658",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/raid5-cache.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.86",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.27",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.86",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.27",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.4",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid5: validate payload size before accessing journal metadata\n\nr5c_recovery_analyze_meta_block() and\nr5l_recovery_verify_data_checksum_for_mb() iterate over payloads in a\njournal metadata block using on-disk payload size fields without\nvalidating them against the remaining space in the metadata block.\n\nA corrupted journal contains payload sizes extending beyond the PAGE_SIZE\nboundary can cause out-of-bounds reads when accessing payload fields or\ncomputing offsets.\n\nAdd bounds validation for each payload type to ensure the full payload\nfits within meta_size before processing."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The malicious input is the on-disk journal metadata processed during local MD array assembly/start; it is not a network-facing service. Even when the journal sits on remote storage, the vulnerable recovery code runs locally against a block device, so the vector is Local.\nAC:L - A crafted journal block deterministically triggers the OOB read on every assembly; the required CRC is fully attacker-computable from the publicly-stored array UUID, and there is no race or uncontrolled condition.\nPR:L - Exploitation only requires planting crafted bytes on the journal block device (e.g. disk-group/device write access), after which routine or boot-time auto-assembly processes it; this is a low-privilege primitive rather than full init-namespace root.\nUI:N - Array assembly/journal recovery runs automatically at boot or device hot-plug, so no human interaction is needed once the corrupted journal is in place.\nS:U - The OOB read stays within the kernel\u0027s own memory and security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The flaw is a large, unbounded out-of-bounds read of adjacent kernel memory (FLUSH count up to ~500M entries), which per scoring guidance for unbounded OOB reads is treated as a high confidentiality impact.\nI:N - The fix adds only read-bounds validation; the vulnerability provides no out-of-bounds write or corruption primitive against system data, so there is no integrity impact.\nA:H - OOB access to unmapped memory (or the int overflow / BUG_ON in the read path) causes a kernel oops/panic, crashing the host during array assembly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:29:28.864Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c96c6f01d84b5c67db1bf1cc8591c0b7146826fc"
},
{
"url": "https://git.kernel.org/stable/c/ef4851d8324fd978ca1ff9ec76a275438f887743"
},
{
"url": "https://git.kernel.org/stable/c/28d3ff7109c66e99dc1b7cddacb5c760849620ef"
},
{
"url": "https://git.kernel.org/stable/c/33698bd1b2db9764a29df7751533d33967ff5c98"
},
{
"url": "https://git.kernel.org/stable/c/c3a1cf78bd1bbb51b2cc5189b4743056553c1e0e"
},
{
"url": "https://git.kernel.org/stable/c/73ce72edd113374801045924d4417199963f73a3"
},
{
"url": "https://git.kernel.org/stable/c/406aa86394ead347c47428fb51b6359bdaa2257d"
},
{
"url": "https://git.kernel.org/stable/c/b0cc3ae97e893bf54bbce447f4e9fd2e0b88bff9"
}
],
"title": "md/raid5: validate payload size before accessing journal metadata",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46070",
"datePublished": "2026-05-27T12:57:54.345Z",
"dateReserved": "2026-05-13T15:03:33.095Z",
"dateUpdated": "2026-08-05T12:29:28.864Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64444 (GCVE-0-2026-64444)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each
iteration but only guards on i < pkt_len. When a malicious AP sends an
AssocResponse whose last IE has only one byte remaining in the frame
(the element_id byte lands at pkt_len-1), the loop reads pIE->length
from pframe[pkt_len], which is one byte past the allocated receive buffer.
Additionally, even when the header bytes are in bounds, pIE->length
itself can extend the data window beyond pkt_len, silently passing a
truncated IE to the handler functions.
Add two guards at the top of the loop body:
1. Break if fewer than sizeof(*pIE) bytes remain (can't read header).
2. Break if the IE's declared data extends past pkt_len.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "889ca6000ac7fa73457b041848fcb08e0d51b809",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "1a52a05471494546f955a58e8c170c0c796c52d5",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "0406d746574e875d8778552eb674fcfbf5330bfb",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "0970dd47726a57e52013594e9fbf667586eb3673",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "04f612dc03427e0b1ac80a2611b5ac0ba93ac446",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "7e7741c8315e4160aead00a60cdd6f81ab880717",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "f9654207e92283e0acac5d64fe5f8835383b5a23",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop\n\nThe IE parsing loop in OnAssocRsp() advances by (pIE-\u003elength + 2) each\niteration but only guards on i \u003c pkt_len. When a malicious AP sends an\nAssocResponse whose last IE has only one byte remaining in the frame\n(the element_id byte lands at pkt_len-1), the loop reads pIE-\u003elength\nfrom pframe[pkt_len], which is one byte past the allocated receive buffer.\n\nAdditionally, even when the header bytes are in bounds, pIE-\u003elength\nitself can extend the data window beyond pkt_len, silently passing a\ntruncated IE to the handler functions.\n\nAdd two guards at the top of the loop body:\n 1. Break if fewer than sizeof(*pIE) bytes remain (can\u0027t read header).\n 2. Break if the IE\u0027s declared data extends past pkt_len."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - An attacker within WiFi radio range can inject a spoofed 802.11 association response to an RTL8723BS station. WiFi management-frame injection is an adjacent attack vector.\nAC:L - The malformed final IE or oversized declared IE deterministically triggers the faulty parsing, and the attacker can observe and answer an association request. No race or condition outside attacker control is required.\nPR:N - Association responses are processed before WPA or 802.1X key establishment, without credentials or capabilities. The path checks the destination and association state but does not validate the response source or BSSID.\nUI:N - Auto-connecting phones, embedded devices, and IoT systems associate or reassociate without human action. An attacker can wait for or induce an automatic reconnect.\nS:U - The vulnerable driver and affected kernel resources belong to the same security authority. No VM, sandbox, or IOMMU boundary is crossed.\nC:H - Truncated HT or WMM elements can make handlers consume up to approximately 26 bytes beyond the logical receive frame from adjacent kernel skb memory. Under the required conservative treatment of a nontrivial out-of-bounds read, confidentiality impact is High.\nI:N - This flaw performs out-of-bounds reads but provides no out-of-bounds write or control-flow primitive. The separate HT capability overwrite was already fixed in the upstream parent and is not attributed to this CVE.\nA:H - Out-of-bounds accesses in the kernel receive tasklet can produce an oops or panic on hardened or unfavorable memory layouts. An unauthenticated adjacent attacker can repeat the trigger during association or reassociation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:46.699Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/889ca6000ac7fa73457b041848fcb08e0d51b809"
},
{
"url": "https://git.kernel.org/stable/c/1a52a05471494546f955a58e8c170c0c796c52d5"
},
{
"url": "https://git.kernel.org/stable/c/0406d746574e875d8778552eb674fcfbf5330bfb"
},
{
"url": "https://git.kernel.org/stable/c/0970dd47726a57e52013594e9fbf667586eb3673"
},
{
"url": "https://git.kernel.org/stable/c/04f612dc03427e0b1ac80a2611b5ac0ba93ac446"
},
{
"url": "https://git.kernel.org/stable/c/7e7741c8315e4160aead00a60cdd6f81ab880717"
},
{
"url": "https://git.kernel.org/stable/c/f9654207e92283e0acac5d64fe5f8835383b5a23"
}
],
"title": "staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64444",
"datePublished": "2026-07-25T08:51:15.968Z",
"dateReserved": "2026-07-19T15:36:31.788Z",
"dateUpdated": "2026-08-17T04:55:46.699Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72032 (GCVE-0-2026-72032)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-17 05:06
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: HWS, fix matcher leak on resize target setup failure
hws_bwc_matcher_move() allocates a replacement matcher before setting it
as the resize target. If mlx5hws_matcher_resize_set_target() fails, the
replacement matcher is not attached anywhere and is leaked.
Fix the leak by destroying the replacement matcher before returning from
the resize-target failure path.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.
An x86_64 allyesconfig build showed no new warnings. As we do not have a
mlx5 HWS-capable device to test with, no runtime testing was able to be
performed.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/steering/hws/bwc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a751ccdc6ea9bde154f25a5ba66926f462f96c19",
"status": "affected",
"version": "2111bb970c787b16b002dc726c1d296ce87a00fb",
"versionType": "git"
},
{
"lessThan": "1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a",
"status": "affected",
"version": "2111bb970c787b16b002dc726c1d296ce87a00fb",
"versionType": "git"
},
{
"lessThan": "ae0265f0a95aaacef59d560a3e1ea36db8be9a52",
"status": "affected",
"version": "2111bb970c787b16b002dc726c1d296ce87a00fb",
"versionType": "git"
},
{
"lessThan": "bb09d0e64ecaa0aa0f7d1133a1696ed74dead295",
"status": "affected",
"version": "2111bb970c787b16b002dc726c1d296ce87a00fb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/steering/hws/bwc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: HWS, fix matcher leak on resize target setup failure\n\nhws_bwc_matcher_move() allocates a replacement matcher before setting it\nas the resize target. If mlx5hws_matcher_resize_set_target() fails, the\nreplacement matcher is not attached anywhere and is leaked.\n\nFix the leak by destroying the replacement matcher before returning from\nthe resize-target failure path.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have a\nmlx5 HWS-capable device to test with, no runtime testing was able to be\nperformed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:06:57.395Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a751ccdc6ea9bde154f25a5ba66926f462f96c19"
},
{
"url": "https://git.kernel.org/stable/c/1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a"
},
{
"url": "https://git.kernel.org/stable/c/ae0265f0a95aaacef59d560a3e1ea36db8be9a52"
},
{
"url": "https://git.kernel.org/stable/c/bb09d0e64ecaa0aa0f7d1133a1696ed74dead295"
}
],
"title": "net/mlx5: HWS, fix matcher leak on resize target setup failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72032",
"datePublished": "2026-08-15T05:51:54.461Z",
"dateReserved": "2026-08-09T03:40:39.901Z",
"dateUpdated": "2026-08-17T05:06:57.395Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-31663 (GCVE-0-2026-31663)
Vulnerability from cvelistv5
Published
2026-04-24 14:45
Modified
2026-08-21 12:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: hold dev ref until after transport_finish NF_HOOK
After async crypto completes, xfrm_input_resume() calls dev_put()
immediately on re-entry before the skb reaches transport_finish.
The skb->dev pointer is then used inside NF_HOOK and its okfn,
which can race with device teardown.
Remove the dev_put from the async resumption entry and instead
drop the reference after the NF_HOOK call in transport_finish,
using a saved device pointer since NF_HOOK may consume the skb.
This covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip
the okfn.
For non-transport exits (decaps, gro, drop) and secondary
async return points, release the reference inline when
async is set.
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: acf568ee859f098279eadf551612f103afdacb4e Version: acf568ee859f098279eadf551612f103afdacb4e Version: acf568ee859f098279eadf551612f103afdacb4e Version: acf568ee859f098279eadf551612f103afdacb4e Version: 69895c5ea0ca2e8d7de1e6d36965d0ab9730787f Version: 833760100588acfb267dac4d6a02ab9931237739 Version: e095ecaec6d94aa2156cceb98a85d409b51190f3 Version: 3.2.100 ≤ Version: 3.16.55 ≤ Version: 4.14.24 ≤ |
||
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-04-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel\u0027s `xfrm` (IP eXtensible FRamework) subsystem. This vulnerability involves a race condition where a network device\u0027s reference is released too early during packet processing after asynchronous cryptography. This premature release can lead to the system attempting to access a deallocated device, potentially causing a system crash (Denial of Service)."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Moderate"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-826",
"description": "Premature Release of Resource During Expected Lifetime",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T12:12:59.640Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-31663"
},
{
"name": "RHBZ#2461462",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461462"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31663.json"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-04-24T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-04-24T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: xfrm: hold dev ref until after transport_finish NF_HOOK",
"workarounds": [
{
"lang": "en",
"value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."
}
],
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/xfrm4_input.c",
"net/ipv6/xfrm6_input.c",
"net/xfrm/xfrm_input.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4236c30b437b80f673b9e08c8fae38b8d471ac9e",
"status": "affected",
"version": "acf568ee859f098279eadf551612f103afdacb4e",
"versionType": "git"
},
{
"lessThan": "0f451b43c88bf2b9c038b414be580efee42e031b",
"status": "affected",
"version": "acf568ee859f098279eadf551612f103afdacb4e",
"versionType": "git"
},
{
"lessThan": "5002beda5cac69d522dc54da0d5d463ed9c963d2",
"status": "affected",
"version": "acf568ee859f098279eadf551612f103afdacb4e",
"versionType": "git"
},
{
"lessThan": "1c428b03840094410c5fb6a5db30640486bbbfcb",
"status": "affected",
"version": "acf568ee859f098279eadf551612f103afdacb4e",
"versionType": "git"
},
{
"status": "affected",
"version": "69895c5ea0ca2e8d7de1e6d36965d0ab9730787f",
"versionType": "git"
},
{
"status": "affected",
"version": "833760100588acfb267dac4d6a02ab9931237739",
"versionType": "git"
},
{
"status": "affected",
"version": "e095ecaec6d94aa2156cceb98a85d409b51190f3",
"versionType": "git"
},
{
"lessThan": "3.3",
"status": "affected",
"version": "3.2.100",
"versionType": "semver"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.55",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.24",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/xfrm4_input.c",
"net/ipv6/xfrm6_input.c",
"net/xfrm/xfrm_input.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.23",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.23",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.13",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.2.100",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.55",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: hold dev ref until after transport_finish NF_HOOK\n\nAfter async crypto completes, xfrm_input_resume() calls dev_put()\nimmediately on re-entry before the skb reaches transport_finish.\nThe skb-\u003edev pointer is then used inside NF_HOOK and its okfn,\nwhich can race with device teardown.\n\nRemove the dev_put from the async resumption entry and instead\ndrop the reference after the NF_HOOK call in transport_finish,\nusing a saved device pointer since NF_HOOK may consume the skb.\nThis covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip\nthe okfn.\n\nFor non-transport exits (decaps, gro, drop) and secondary\nasync return points, release the reference inline when\nasync is set."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The complete attacker-controlled path requires a local unprivileged user to create a user/net namespace, configure transport-mode XFRM state, send traffic, and tear down the namespace/device in parallel.\nAC:L - The race is attacker-controlled in the user-namespace scenario: the attacker controls packet injection and device/netns teardown and can repeat the sequence reliably.\nPR:L - XFRM and rtnetlink setup require CAP_NET_ADMIN, but these checks are against the network namespace user_ns and are reachable after unshare -Urn by an unprivileged local user.\nUI:N - No victim action is required once the attacker can run local code and create the namespace setup.\nS:U - The vulnerable component and impacted resource are the kernel itself; this is a standard kernel memory-safety issue rather than a VM or hardware boundary escape.\nC:H - This is a net_device use-after-free, and freed kernel heap objects can potentially be reclaimed and abused for kernel memory disclosure.\nI:H - Use-after-free in kernel networking code can potentially be shaped into control-flow or data-structure corruption, so high integrity impact is appropriate.\nA:H - The issue was reproduced as a KASAN slab-use-after-free in the async XFRM reinject path and can crash the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:24:13.957Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4236c30b437b80f673b9e08c8fae38b8d471ac9e"
},
{
"url": "https://git.kernel.org/stable/c/0f451b43c88bf2b9c038b414be580efee42e031b"
},
{
"url": "https://git.kernel.org/stable/c/5002beda5cac69d522dc54da0d5d463ed9c963d2"
},
{
"url": "https://git.kernel.org/stable/c/1c428b03840094410c5fb6a5db30640486bbbfcb"
}
],
"title": "xfrm: hold dev ref until after transport_finish NF_HOOK",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-31663",
"datePublished": "2026-04-24T14:45:13.239Z",
"dateReserved": "2026-03-09T15:48:24.129Z",
"dateUpdated": "2026-08-21T12:12:59.640Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68426 (GCVE-0-2026-68426)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix stale skb->prev after async crypto steals a GSO segment
skb_gso_segment() leaves the segment list head with ->prev pointing at
the last segment, an invariant validate_xmit_skb_list() relies on when
it sets its tail pointer (tail = skb->prev).
When validate_xmit_xfrm() walks a GSO list and some segments are stolen
by async crypto (->xmit() returns -EINPROGRESS), those segments are
unlinked from the list but the head ->prev is never updated. If the
last segment is the one stolen, the returned head still has ->prev
pointing at it, even though it is now owned by the crypto engine and may
be freed. validate_xmit_skb_list() later does tail->next = skb, writing
through that stale pointer -- a use-after-free.
Repoint skb->prev at the last retained segment before returning.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_device.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "33e1b0d25ca0d2818c635ff80e6aa0d295e08a98",
"status": "affected",
"version": "f53c723902d1ac5f0b0a11d7c9dcbff748dde74e",
"versionType": "git"
},
{
"lessThan": "bbca7cc3b2b4b10afbfee99b81d9ee78f5423046",
"status": "affected",
"version": "f53c723902d1ac5f0b0a11d7c9dcbff748dde74e",
"versionType": "git"
},
{
"lessThan": "3f4c3919baf0944ad96580467c302bc6c7758b00",
"status": "affected",
"version": "f53c723902d1ac5f0b0a11d7c9dcbff748dde74e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_device.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.16"
},
{
"lessThan": "4.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix stale skb-\u003eprev after async crypto steals a GSO segment\n\nskb_gso_segment() leaves the segment list head with -\u003eprev pointing at\nthe last segment, an invariant validate_xmit_skb_list() relies on when\nit sets its tail pointer (tail = skb-\u003eprev).\n\nWhen validate_xmit_xfrm() walks a GSO list and some segments are stolen\nby async crypto (-\u003exmit() returns -EINPROGRESS), those segments are\nunlinked from the list but the head -\u003eprev is never updated. If the\nlast segment is the one stolen, the returned head still has -\u003eprev\npointing at it, even though it is now owned by the crypto engine and may\nbe freed. validate_xmit_skb_list() later does tail-\u003enext = skb, writing\nthrough that stale pointer -- a use-after-free.\n\nRepoint skb-\u003eprev at the last retained segment before returning."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in the IPsec transmit path (validate_xmit_xfrm) which processes any skb routed into an offloaded SA, including GRO-aggregated traffic forwarded from remote hosts on an IPsec gateway; xfrm_dev_offload_ok() has no socket/local-origin requirement, so a remote peer\u0027s packet stream drives the vulnerable GSO segmentation and async-crypto steal directly.\nAC:L - The attacker drives both preconditions with traffic alone: sustained large GSO flows keep the crypto engine backlogged so -\u003exmit() returns -EINPROGRESS routinely, and packet volume advances xo-\u003eseq.low toward the wrap that forces segmentation; each stolen trailing segment reproduces the stale skb-\u003eprev, and the subsequent tail-\u003enext write is deterministic once it occurs.\nPR:N - On an IPsec gateway the traffic that triggers the path is forwarded from remote, unauthenticated senders \u2014 no account, credentials, or capability on the target host is needed, since the SA and offload are pre-existing administrative configuration rather than something the attacker must set up.\nUI:N - No victim action is required; the vulnerable code runs automatically in softirq context on every qualifying transmit, driven purely by the attacker\u0027s packet stream.\nS:U - The corruption is of kernel sk_buff list state within the same host kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Writing through the stale -\u003eprev is a use-after-free on an skb whose memory the attacker can influence via heap grooming with concurrent traffic; per kernel UAF guidance this yields a high-confidentiality primitive, and the corrupted list can splice engine-owned skbs into the transmit path, exposing freed/reused memory contents on the wire.\nI:H - tail-\u003enext = skb is an attacker-influenced pointer write into freed heap memory, and the resulting skb list corruption lets live and engine-owned skbs be chained together; this is classic heap corruption that can be shaped via spraying into an arbitrary write or control-flow hijack.\nA:H - Even without full exploitation the use-after-free write and the double-ownership of a stolen segment cause list corruption, double-free/oops and kernel panic in the softirq transmit path, taking down the gateway."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:22.080Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/33e1b0d25ca0d2818c635ff80e6aa0d295e08a98"
},
{
"url": "https://git.kernel.org/stable/c/bbca7cc3b2b4b10afbfee99b81d9ee78f5423046"
},
{
"url": "https://git.kernel.org/stable/c/3f4c3919baf0944ad96580467c302bc6c7758b00"
}
],
"title": "xfrm: fix stale skb-\u003eprev after async crypto steals a GSO segment",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68426",
"datePublished": "2026-08-10T12:04:46.945Z",
"dateReserved": "2026-07-30T09:28:09.392Z",
"dateUpdated": "2026-08-17T05:05:22.080Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72072 (GCVE-0-2026-72072)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-17 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
When an offloaded MACsec RX SC is deleted, macsec_del_rxsc_ctx() freed
the per-SC metadata_dst with metadata_dst_free(), which kfree()s the
object unconditionally and ignores the dst reference count. The RX
datapath in mlx5e_macsec_offload_handle_rx_skb() looks up the SC under
rcu_read_lock() via xa_load(), takes a reference with dst_hold() and
attaches the dst to the skb with skb_dst_set(). A reader that already
obtained the rx_sc pointer can race with the delete path and operate on
freed memory.
Fix the owner side by dropping the reference with dst_release() instead
of freeing unconditionally, and convert the RX datapath to
dst_hold_safe() so a reader racing the SC delete cannot attach a dst
whose last reference was just dropped; only attach it when a reference
was actually taken.
mlx5e_macsec_add_rxsc() also published sc_xarray_element via xa_alloc()
before rx_sc->md_dst was allocated and initialised, so a datapath reader
that looked the SC up by fs_id could observe rx_sc with md_dst still
NULL or, on weakly-ordered architectures, a non-NULL md_dst pointer
whose contents were not yet visible. NULL-check the xa_load() result and
md_dst on the datapath, and reorder add_rxsc() so the xa_alloc() publish
happens only after md_dst is fully initialised; the xarray RCU publish
then pairs with the rcu_read_lock()/xa_load() in the datapath.
Note: macsec_del_rxsc_ctx() also kfree()s rx_sc->sc_xarray_element
without an RCU grace period while the same datapath reads it under
rcu_read_lock(); that is a separate pre-existing issue left to a
follow-up patch.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b7c9400cbc48c3713190b3bce4e0c87e924e4104 Version: b7c9400cbc48c3713190b3bce4e0c87e924e4104 Version: b7c9400cbc48c3713190b3bce4e0c87e924e4104 Version: b7c9400cbc48c3713190b3bce4e0c87e924e4104 Version: b7c9400cbc48c3713190b3bce4e0c87e924e4104 Version: b7c9400cbc48c3713190b3bce4e0c87e924e4104 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b1a4d0c568bbb52c7c04f4fce3c097dae89ed6cb",
"status": "affected",
"version": "b7c9400cbc48c3713190b3bce4e0c87e924e4104",
"versionType": "git"
},
{
"lessThan": "218cc15a4c907659ad4b0e68c535c61594311205",
"status": "affected",
"version": "b7c9400cbc48c3713190b3bce4e0c87e924e4104",
"versionType": "git"
},
{
"lessThan": "4a5073b7b30243658f58b2d2d35a823da7fd34d9",
"status": "affected",
"version": "b7c9400cbc48c3713190b3bce4e0c87e924e4104",
"versionType": "git"
},
{
"lessThan": "ed3cc4218070d6b98bf5fb456dccae424fd38c4f",
"status": "affected",
"version": "b7c9400cbc48c3713190b3bce4e0c87e924e4104",
"versionType": "git"
},
{
"lessThan": "088873af13590ebde10de2ade847f57a05ec61c6",
"status": "affected",
"version": "b7c9400cbc48c3713190b3bce4e0c87e924e4104",
"versionType": "git"
},
{
"lessThan": "de74d8fd10291763d97b218f09adcc7513c975e4",
"status": "affected",
"version": "b7c9400cbc48c3713190b3bce4e0c87e924e4104",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete\n\nWhen an offloaded MACsec RX SC is deleted, macsec_del_rxsc_ctx() freed\nthe per-SC metadata_dst with metadata_dst_free(), which kfree()s the\nobject unconditionally and ignores the dst reference count. The RX\ndatapath in mlx5e_macsec_offload_handle_rx_skb() looks up the SC under\nrcu_read_lock() via xa_load(), takes a reference with dst_hold() and\nattaches the dst to the skb with skb_dst_set(). A reader that already\nobtained the rx_sc pointer can race with the delete path and operate on\nfreed memory.\n\nFix the owner side by dropping the reference with dst_release() instead\nof freeing unconditionally, and convert the RX datapath to\ndst_hold_safe() so a reader racing the SC delete cannot attach a dst\nwhose last reference was just dropped; only attach it when a reference\nwas actually taken.\n\nmlx5e_macsec_add_rxsc() also published sc_xarray_element via xa_alloc()\nbefore rx_sc-\u003emd_dst was allocated and initialised, so a datapath reader\nthat looked the SC up by fs_id could observe rx_sc with md_dst still\nNULL or, on weakly-ordered architectures, a non-NULL md_dst pointer\nwhose contents were not yet visible. NULL-check the xa_load() result and\nmd_dst on the datapath, and reorder add_rxsc() so the xa_alloc() publish\nhappens only after md_dst is fully initialised; the xarray RCU publish\nthen pairs with the rcu_read_lock()/xa_load() in the datapath.\n\nNote: macsec_del_rxsc_ctx() also kfree()s rx_sc-\u003esc_xarray_element\nwithout an RCU grace period while the same datapath reads it under\nrcu_read_lock(); that is a separate pre-existing issue left to a\nfollow-up patch.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is reached by racing MACSEC_CMD_DEL_RXSC/ADD_RXSC netlink configuration (GENL_ADMIN_PERM) against mlx5e MACsec RX processing; the privileged genlink/rtnl control path is required to trigger the bug, not remote packets alone.\nAC:L - An attacker with CAP_NET_ADMIN can drive both sides by looping RX SC add/delete while flooding MACsec-offloaded RX traffic on the mlx5e netdev, reliably winning the RCU race between xa_load/dst_hold and metadata_dst_free.\nPR:L - MACsec offload mutations require GENL_ADMIN_PERM (CAP_NET_ADMIN); on Mellanox ConnectX/BlueField systems this is reachable by cloud tenants with SR-IOV VFs, containers, or user/network namespaces without init-namespace root.\nUI:N - No victim user action is needed; automated concurrent netlink MACsec operations and incoming MACsec-offloaded frames on an active mlx5e interface suffice once MACsec offload is configured.\nS:U - Impact is kernel heap use-after-free and memory corruption within the host kernel on the mlx5 NIC; it enables local privilege escalation but does not by itself cross VM, IOMMU, or hypervisor security boundaries.\nC:H - The race calls dst_hold() and skb_dst_set() on a freed metadata_dst, a classic slab UAF that can disclose kernel memory through subsequent dst_entry and MACsec skb metadata handling.\nI:H - Freed metadata_dst objects can be reallocated via heap spraying while the RX datapath still references them, enabling refcount corruption and arbitrary kernel memory writes or control-flow hijack beyond a mere crash.\nA:H - Concurrent use of freed md_dst during mlx5e MACsec RX processing can cause immediate kernel oops, BUG, or panic on datacenter/cloud hosts using mlx5 hardware MACsec offload, fully denying system availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:40:03.099Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b1a4d0c568bbb52c7c04f4fce3c097dae89ed6cb"
},
{
"url": "https://git.kernel.org/stable/c/218cc15a4c907659ad4b0e68c535c61594311205"
},
{
"url": "https://git.kernel.org/stable/c/4a5073b7b30243658f58b2d2d35a823da7fd34d9"
},
{
"url": "https://git.kernel.org/stable/c/ed3cc4218070d6b98bf5fb456dccae424fd38c4f"
},
{
"url": "https://git.kernel.org/stable/c/088873af13590ebde10de2ade847f57a05ec61c6"
},
{
"url": "https://git.kernel.org/stable/c/de74d8fd10291763d97b218f09adcc7513c975e4"
}
],
"title": "net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72072",
"datePublished": "2026-08-15T05:52:23.946Z",
"dateReserved": "2026-08-09T03:40:39.904Z",
"dateUpdated": "2026-08-17T05:40:03.099Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53033 (GCVE-0-2026-53033)
Vulnerability from cvelistv5
Published
2026-06-24 16:29
Modified
2026-08-05 12:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Take state lock for af_unix iter
When a BPF iterator program updates a sockmap, there is a race condition in
unix_stream_bpf_update_proto() where the `peer` pointer can become stale[1]
during a state transition TCP_ESTABLISHED -> TCP_CLOSE.
CPU0 bpf CPU1 close
-------- ----------
// unix_stream_bpf_update_proto()
sk_pair = unix_peer(sk)
if (unlikely(!sk_pair))
return -EINVAL;
// unix_release_sock()
skpair = unix_peer(sk);
unix_peer(sk) = NULL;
sock_put(skpair)
sock_hold(sk_pair) // UaF
More practically, this fix guarantees that the iterator program is
consistently provided with a unix socket that remains stable during
iterator execution.
[1]:
BUG: KASAN: slab-use-after-free in unix_stream_bpf_update_proto+0x155/0x490
Write of size 4 at addr ffff8881178c9a00 by task test_progs/2231
Call Trace:
dump_stack_lvl+0x5d/0x80
print_report+0x170/0x4f3
kasan_report+0xe4/0x1c0
kasan_check_range+0x125/0x200
unix_stream_bpf_update_proto+0x155/0x490
sock_map_link+0x71c/0xec0
sock_map_update_common+0xbc/0x600
sock_map_update_elem+0x19a/0x1f0
bpf_prog_bbbf56096cdd4f01_selective_dump_unix+0x20c/0x217
bpf_iter_run_prog+0x21e/0xae0
bpf_iter_unix_seq_show+0x1e0/0x2a0
bpf_seq_read+0x42c/0x10d0
vfs_read+0x171/0xb20
ksys_read+0xff/0x200
do_syscall_64+0xf7/0x5e0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
Allocated by task 2236:
kasan_save_stack+0x30/0x50
kasan_save_track+0x14/0x30
__kasan_slab_alloc+0x63/0x80
kmem_cache_alloc_noprof+0x1d5/0x680
sk_prot_alloc+0x59/0x210
sk_alloc+0x34/0x470
unix_create1+0x86/0x8a0
unix_stream_connect+0x318/0x15b0
__sys_connect+0xfd/0x130
__x64_sys_connect+0x72/0xd0
do_syscall_64+0xf7/0x5e0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
Freed by task 2236:
kasan_save_stack+0x30/0x50
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x70
__kasan_slab_free+0x47/0x70
kmem_cache_free+0x11c/0x590
__sk_destruct+0x432/0x6e0
unix_release_sock+0x9b3/0xf60
unix_release+0x8a/0xf0
__sock_release+0xb0/0x270
sock_close+0x18/0x20
__fput+0x36e/0xac0
fput_close_sync+0xe5/0x1a0
__x64_sys_close+0x7d/0xd0
do_syscall_64+0xf7/0x5e0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2c860a43dd77f969bb959336a2f743d7103a8f63 Version: 2c860a43dd77f969bb959336a2f743d7103a8f63 Version: 2c860a43dd77f969bb959336a2f743d7103a8f63 Version: 2c860a43dd77f969bb959336a2f743d7103a8f63 Version: 2c860a43dd77f969bb959336a2f743d7103a8f63 Version: 2c860a43dd77f969bb959336a2f743d7103a8f63 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "unaffected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-06-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel\u0027s sockmap functionality. A race condition exists in the unix_stream_bpf_update_proto() function when a BPF (Berkeley Packet Filter) iterator program updates a sockmap. This can lead to a use-after-free (UaF) vulnerability, where memory is accessed after it has been freed. An attacker could potentially exploit this to cause a denial of service or achieve arbitrary code execution."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Moderate"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-825",
"description": "Expired Pointer Dereference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-15T00:45:13.077Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-53033"
},
{
"name": "RHBZ#2492281",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492281"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53033.json"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: bpf, sockmap: Take state lock for af_unix iter",
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/unix/af_unix.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c6f4015eac2e3cbc3cb7a17539e10bbb5c2049c3",
"status": "affected",
"version": "2c860a43dd77f969bb959336a2f743d7103a8f63",
"versionType": "git"
},
{
"lessThan": "d0d124dbcef9318e326956137b31671407094bd4",
"status": "affected",
"version": "2c860a43dd77f969bb959336a2f743d7103a8f63",
"versionType": "git"
},
{
"lessThan": "1a59cc6b65fd3ad9915aae5970d859109d4ce9fb",
"status": "affected",
"version": "2c860a43dd77f969bb959336a2f743d7103a8f63",
"versionType": "git"
},
{
"lessThan": "921920c34cb591947dd30c692500795a69f1e3fa",
"status": "affected",
"version": "2c860a43dd77f969bb959336a2f743d7103a8f63",
"versionType": "git"
},
{
"lessThan": "98f744d204e5d6fca589cd2c44c3190a0c71697f",
"status": "affected",
"version": "2c860a43dd77f969bb959336a2f743d7103a8f63",
"versionType": "git"
},
{
"lessThan": "64c2f93fc3254d3bf5de4445fb732ee5c451edb6",
"status": "affected",
"version": "2c860a43dd77f969bb959336a2f743d7103a8f63",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/unix/af_unix.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Take state lock for af_unix iter\n\nWhen a BPF iterator program updates a sockmap, there is a race condition in\nunix_stream_bpf_update_proto() where the `peer` pointer can become stale[1]\nduring a state transition TCP_ESTABLISHED -\u003e TCP_CLOSE.\n\n CPU0 bpf CPU1 close\n -------- ----------\n// unix_stream_bpf_update_proto()\nsk_pair = unix_peer(sk)\nif (unlikely(!sk_pair))\n return -EINVAL;\n // unix_release_sock()\n skpair = unix_peer(sk);\n unix_peer(sk) = NULL;\n sock_put(skpair)\nsock_hold(sk_pair) // UaF\n\nMore practically, this fix guarantees that the iterator program is\nconsistently provided with a unix socket that remains stable during\niterator execution.\n\n[1]:\nBUG: KASAN: slab-use-after-free in unix_stream_bpf_update_proto+0x155/0x490\nWrite of size 4 at addr ffff8881178c9a00 by task test_progs/2231\nCall Trace:\n dump_stack_lvl+0x5d/0x80\n print_report+0x170/0x4f3\n kasan_report+0xe4/0x1c0\n kasan_check_range+0x125/0x200\n unix_stream_bpf_update_proto+0x155/0x490\n sock_map_link+0x71c/0xec0\n sock_map_update_common+0xbc/0x600\n sock_map_update_elem+0x19a/0x1f0\n bpf_prog_bbbf56096cdd4f01_selective_dump_unix+0x20c/0x217\n bpf_iter_run_prog+0x21e/0xae0\n bpf_iter_unix_seq_show+0x1e0/0x2a0\n bpf_seq_read+0x42c/0x10d0\n vfs_read+0x171/0xb20\n ksys_read+0xff/0x200\n do_syscall_64+0xf7/0x5e0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nAllocated by task 2236:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n __kasan_slab_alloc+0x63/0x80\n kmem_cache_alloc_noprof+0x1d5/0x680\n sk_prot_alloc+0x59/0x210\n sk_alloc+0x34/0x470\n unix_create1+0x86/0x8a0\n unix_stream_connect+0x318/0x15b0\n __sys_connect+0xfd/0x130\n __x64_sys_connect+0x72/0xd0\n do_syscall_64+0xf7/0x5e0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nFreed by task 2236:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x70\n __kasan_slab_free+0x47/0x70\n kmem_cache_free+0x11c/0x590\n __sk_destruct+0x432/0x6e0\n unix_release_sock+0x9b3/0xf60\n unix_release+0x8a/0xf0\n __sock_release+0xb0/0x270\n sock_close+0x18/0x20\n __fput+0x36e/0xac0\n fput_close_sync+0xe5/0x1a0\n __x64_sys_close+0x7d/0xd0\n do_syscall_64+0xf7/0x5e0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation is through local syscalls: loading/attaching a BPF Unix-socket iterator, creating/updating a sockmap, reading the iterator fd, and racing an AF_UNIX socket close. No remote network packet path reaches this iterator execution.\nAC:L - The attacker can create the AF_UNIX sockets, run the iterator read, and close the peer concurrently, controlling both sides of the race. No external victim timing or uncommon state is required beyond winning an attacker-orchestrated race.\nPR:L - The non-delegated path requires BPF-related capabilities, but BPF tokens can delegate the needed CAP_BPF/CAP_PERFMON/CAP_NET_ADMIN checks into a non-init user namespace. Under the higher-severity rule, this is best treated as reachable with low delegated local privileges rather than requiring init-namespace root.\nUI:N - No victim action is needed after the attacker has local execution and the required BPF access. The attacker triggers the iterator read and socket close directly.\nS:U - The bug corrupts kernel memory within the same OS security authority. It is not a VM escape, IOMMU bypass, or cross-scope boundary violation.\nC:H - The bug is a slab use-after-free on an AF_UNIX peer socket object during `sock_hold()`. Per kernel UAF guidance, this memory corruption can be leveraged for kernel memory disclosure in a plausible exploit.\nI:H - The stale peer pointer leads to a write to freed memory via the socket refcount increment. As a kernel UAF/write primitive, it is reasonably treated as enabling arbitrary corruption or control-flow compromise.\nA:H - The reported failure is a KASAN slab-use-after-free in kernel context and can crash or oops the kernel. Repeated local triggering can cause high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:32:46.155Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c6f4015eac2e3cbc3cb7a17539e10bbb5c2049c3"
},
{
"url": "https://git.kernel.org/stable/c/d0d124dbcef9318e326956137b31671407094bd4"
},
{
"url": "https://git.kernel.org/stable/c/1a59cc6b65fd3ad9915aae5970d859109d4ce9fb"
},
{
"url": "https://git.kernel.org/stable/c/921920c34cb591947dd30c692500795a69f1e3fa"
},
{
"url": "https://git.kernel.org/stable/c/98f744d204e5d6fca589cd2c44c3190a0c71697f"
},
{
"url": "https://git.kernel.org/stable/c/64c2f93fc3254d3bf5de4445fb732ee5c451edb6"
}
],
"title": "bpf, sockmap: Take state lock for af_unix iter",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53033",
"datePublished": "2026-06-24T16:29:40.794Z",
"dateReserved": "2026-06-09T07:44:35.380Z",
"dateUpdated": "2026-08-05T12:32:46.155Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68340 (GCVE-0-2026-68340)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: occ: validate poll response sensor blocks
The OCC poll response parser walks a counted list of sensor data blocks.
It used the static backing-array capacity as the parse boundary, but a
transport response makes only data_length bytes current and valid. A
truncated response can therefore make the parser consume a block header or
block extent outside the current response.
Use data_length as the parent boundary, prove the fixed poll header and
each current block header before reading them, and prove the complete block
before advancing. Keep parsed sensor metadata local until the complete
response has passed validation, then publish it. Propagate
malformed-response errors before publishing the OCC as active.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/occ/common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6e6c72c37433640514db325408bd6913ad28fe69",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "1902e9572901d37901e3db1f3f6b0885f4e49a66",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "112525534ab5cff482d35897ca4ca11fd3a76f46",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "54cb78eceb4e286ccd5a5c01a4632157860d47f0",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "538d862cc0dbd5c732fe26d5aad98eae039e6676",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "b042e538e98b939fccfffc464e2c34c29f0e96ef",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "70e76e700fc6c46afb4e17aec099a1ea089b4a22",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/occ/common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: occ: validate poll response sensor blocks\n\nThe OCC poll response parser walks a counted list of sensor data blocks.\nIt used the static backing-array capacity as the parse boundary, but a\ntransport response makes only data_length bytes current and valid. A\ntruncated response can therefore make the parser consume a block header or\nblock extent outside the current response.\n\nUse data_length as the parent boundary, prove the fixed poll header and\neach current block header before reading them, and prove the complete block\nbefore advancing. Keep parsed sensor metadata local until the complete\nresponse has passed validation, then publish it. Propagate\nmalformed-response errors before publishing the OCC as active."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The malformed poll response reaches the BMC kernel over the local FSI/SBE or I2C link to the attached POWER OCC (drivers/hwmon/occ/p9_sbe.c, p8_i2c.c); there is no network protocol involved, but no physical access is needed either since a bare-metal host-side attacker can drive OCC firmware in software.\nAC:L - The attacker fully controls the response contents and its data_length, so simply returning a truncated poll response with a large num_sensor_data_blocks deterministically drives the parser past the valid data. No race, memory-layout guess, or uncontrolled precondition is involved.\nPR:N - occ_setup() calls occ_active(occ, true) during driver probe unless ibm,no-poll-on-init is set, so the malformed response is parsed automatically at bind with no credentials on the affected BMC system; the OCC-side attacker holds no privileges in the victim kernel\u0027s authority.\nUI:N - Parsing happens automatically during driver probe, or from the management daemon\u0027s periodic occ_active write; no victim action such as mounting or opening a file is required.\nS:U - The out-of-bounds reads and corrupted sensor metadata are confined to the kernel that parses the response; no IOMMU, hypervisor, or sandbox boundary is crossed by the impact itself.\nC:H - Sensor metadata (data pointer, num_sensors, version) is taken from bytes outside the valid response, and consumers index it with fixed per-version struct sizes in occ_setup_sensor_attrs() and every occ_show_* handler, reading far past the devm-allocated occ object and exposing kernel heap contents through world-readable hwmon sysfs attributes.\nI:N - The parse path only reads; the unvalidated lengths yield out-of-bounds loads and bogus metadata, but no attacker-controlled data is written outside any object and no control-flow-hijack primitive is created.\nA:H - Out-of-bounds reads of up to a couple of kilobytes past the allocation can hit unmapped memory or trip KASAN/BUG and oops the kernel, and pre-fix the OCC was marked active with invalid sensor state, leaving the hwmon device in an inconsistent, unusable condition."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:40.900Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6e6c72c37433640514db325408bd6913ad28fe69"
},
{
"url": "https://git.kernel.org/stable/c/1902e9572901d37901e3db1f3f6b0885f4e49a66"
},
{
"url": "https://git.kernel.org/stable/c/112525534ab5cff482d35897ca4ca11fd3a76f46"
},
{
"url": "https://git.kernel.org/stable/c/54cb78eceb4e286ccd5a5c01a4632157860d47f0"
},
{
"url": "https://git.kernel.org/stable/c/538d862cc0dbd5c732fe26d5aad98eae039e6676"
},
{
"url": "https://git.kernel.org/stable/c/b042e538e98b939fccfffc464e2c34c29f0e96ef"
},
{
"url": "https://git.kernel.org/stable/c/70e76e700fc6c46afb4e17aec099a1ea089b4a22"
}
],
"title": "hwmon: occ: validate poll response sensor blocks",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68340",
"datePublished": "2026-08-10T12:03:16.552Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:40.900Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68313 (GCVE-0-2026-68313)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix infinite loop in __tipc_nl_compat_dumpit
cmd->dumpit callback can return a negative errno, causing an infinite
loop due to the while(len) condition. As the loop never terminates,
genl_mutex is never released, and other tasks waiting on it starve in D
state.
Check dumpit's return value, propagate it and jump to err_out on error.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink_compat.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2a1c1397275f27e33b6a2a565d81cfef0deb6656",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "98d09766cee3182aae292886e2fef0cbe8dba537",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "9cd8c88e1336ec0fbe02af1ddf2b52838d30fae4",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "f9c669d9f4cac832fe31193cdbc24c6a9d99398b",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "1ab78af2140189b735b8d3b889b0284128cb2013",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "e740e90ca8e7f70d9eac1aa31a8b3e0e4d32b2ef",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "b8f3b8efa5f99081b14de1a7ffa68a81bf01bd48",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "22f8aa35964e8f2ab026578f45befc9605fd1b28",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink_compat.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.0"
},
{
"lessThan": "4.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix infinite loop in __tipc_nl_compat_dumpit\n\ncmd-\u003edumpit callback can return a negative errno, causing an infinite\nloop due to the while(len) condition. As the loop never terminates,\ngenl_mutex is never released, and other tasks waiting on it starve in D\nstate.\n\nCheck dumpit\u0027s return value, propagate it and jump to err_out on error."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:05.750Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2a1c1397275f27e33b6a2a565d81cfef0deb6656"
},
{
"url": "https://git.kernel.org/stable/c/98d09766cee3182aae292886e2fef0cbe8dba537"
},
{
"url": "https://git.kernel.org/stable/c/9cd8c88e1336ec0fbe02af1ddf2b52838d30fae4"
},
{
"url": "https://git.kernel.org/stable/c/f9c669d9f4cac832fe31193cdbc24c6a9d99398b"
},
{
"url": "https://git.kernel.org/stable/c/1ab78af2140189b735b8d3b889b0284128cb2013"
},
{
"url": "https://git.kernel.org/stable/c/e740e90ca8e7f70d9eac1aa31a8b3e0e4d32b2ef"
},
{
"url": "https://git.kernel.org/stable/c/b8f3b8efa5f99081b14de1a7ffa68a81bf01bd48"
},
{
"url": "https://git.kernel.org/stable/c/22f8aa35964e8f2ab026578f45befc9605fd1b28"
}
],
"title": "tipc: fix infinite loop in __tipc_nl_compat_dumpit",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68313",
"datePublished": "2026-08-10T12:02:48.120Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:33:05.750Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68370 (GCVE-0-2026-68370)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
dummy_hcd embeds a single shared usb_request (dum->fifo_req) that the
"emulated single-request FIFO" fast-path in dummy_queue() reuses for
small IN transfers: it copies the caller's request into it
(req->req = *_req) and queues it, treating list_empty(&fifo_req.queue)
as "the slot is free".
The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows
the standard pattern: list_del_init(&req->queue) unlinks the request,
then the lock is dropped and usb_gadget_giveback_request() invokes
req->complete(). But list_del_init() makes fifo_req.queue look empty
*before* the completion callback returns, so a concurrent dummy_queue()
on another CPU sees the slot as free, reuses fifo_req and runs
req->req = *_req -- overwriting req->complete while dummy_timer is
mid-calling it. The indirect call then jumps to a clobbered pointer,
causing a general protection fault / page fault in dummy_timer
(syzkaller extid faf3a6cf579fc65591ca). The clobbering write is an
in-bounds memcpy on a live shared object, so KASAN cannot flag it.
Add a fifo_req_busy bit covering the shared request's whole lifetime:
set it in dummy_queue() when the FIFO fast-path takes fifo_req (making
it the fast-path guard, replacing the list_empty(&fifo_req.queue)
test), and clear it after the completion callback has returned, via a
dummy_giveback() helper used at all four gadget-request giveback
sites. The shared slot can no longer be reused until its completion
callback has finished.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/dummy_hcd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "16a685172abc9233728830e27d26ffa778975b51",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "95f30a21612cc65761c58ba044b1767699437317",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3cab0e5498d0fbb21fe1a9181f7bda9a844a697e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e2b2740f1242bc70b5b46da2cdbbaa419f490e59",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "67b589d09a96882d56842dced5698ed8dd06ce45",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e239ea91b48180ed48a86ac25643832a02c88456",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e24b33618231034bf01dfaff4fd3409d4b4d5b2e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d5e5cd3654d2b5359a12ea6586120f05b28634ee",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/dummy_hcd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: dummy_hcd: prevent fifo_req reuse during giveback\n\ndummy_hcd embeds a single shared usb_request (dum-\u003efifo_req) that the\n\"emulated single-request FIFO\" fast-path in dummy_queue() reuses for\nsmall IN transfers: it copies the caller\u0027s request into it\n(req-\u003ereq = *_req) and queues it, treating list_empty(\u0026fifo_req.queue)\nas \"the slot is free\".\n\nThe completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows\nthe standard pattern: list_del_init(\u0026req-\u003equeue) unlinks the request,\nthen the lock is dropped and usb_gadget_giveback_request() invokes\nreq-\u003ecomplete(). But list_del_init() makes fifo_req.queue look empty\n*before* the completion callback returns, so a concurrent dummy_queue()\non another CPU sees the slot as free, reuses fifo_req and runs\nreq-\u003ereq = *_req -- overwriting req-\u003ecomplete while dummy_timer is\nmid-calling it. The indirect call then jumps to a clobbered pointer,\ncausing a general protection fault / page fault in dummy_timer\n(syzkaller extid faf3a6cf579fc65591ca). The clobbering write is an\nin-bounds memcpy on a live shared object, so KASAN cannot flag it.\n\nAdd a fifo_req_busy bit covering the shared request\u0027s whole lifetime:\nset it in dummy_queue() when the FIFO fast-path takes fifo_req (making\nit the fast-path guard, replacing the list_empty(\u0026fifo_req.queue)\ntest), and clear it after the completion callback has returned, via a\ndummy_giveback() helper used at all four gadget-request giveback\nsites. The shared slot can no longer be reused until its completion\ncallback has finished."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - dummy_hcd is a purely virtual UDC/HCD pair with no physical port; both sides of the race are driven locally \u2014 gadget-side `usb_ep_queue()` via raw-gadget ioctls, gadgetfs/functionfs endpoint writes or configfs function traffic, and the host side by the in-software `dummy_timer`/URB path. No cable, hardware, or network access is involved, matching the AV:L used for other dummy_hcd/gadget bugs.\nAC:L - The attacker controls both sides of the race: it queues small IN requests on one CPU in a tight loop while the periodic 1 ms `dummy_timer` frame processing performs giveback on another, and the fast-path guard (`list_empty(\u0026fifo_req.queue)`) is cleared before the callback returns, so the window is entered on essentially every iteration and can be retried indefinitely.\nPR:L - No capability check exists anywhere on the path \u2014 `dummy_queue()` and the giveback sites perform none; reachability is gated only by node/mount permissions on /dev/raw-gadget, gadgetfs or the gadget configfs/functionfs tree, which on Android and embedded/industrial systems are routinely delegated to non-root system accounts, so basic local access suffices.\nUI:N - The attacker performs every step itself \u2014 enabling the gadget, queueing the IN transfers, and letting the emulated frame timer run \u2014 with no action required from any other user or victim.\nS:U - The corrupted object and the resulting control-flow hijack are entirely within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The in-flight copy overwrites `fifo_req.req.buf`, `length`, `actual` and `context` of the live shared request, so the completion path and the host-side `transfer()` memcpy operate with mismatched buffer/length/context pairs, letting an attacker steer reads out of unintended kernel memory and surface them through the emulated host transfer \u2014 a kernel memory disclosure primitive.\nI:H - `req-\u003ereq = *_req` clobbers the `complete` function pointer while `usb_gadget_giveback_request()` is dereferencing it, giving a torn/stale indirect call plus a `context` mismatch (type confusion) that is a direct control-flow hijack primitive; the same race also lets the shared `fifo_buf` be written under a stale length, yielding controllable kernel writes.\nA:H - The reported effect is a general protection fault / kernel page fault in `dummy_timer` (syzbot faf3a6cf579fc65591ca) from calling through the clobbered pointer, i.e. a kernel oops that an unprivileged local attacker can trigger repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:31.156Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/16a685172abc9233728830e27d26ffa778975b51"
},
{
"url": "https://git.kernel.org/stable/c/95f30a21612cc65761c58ba044b1767699437317"
},
{
"url": "https://git.kernel.org/stable/c/3cab0e5498d0fbb21fe1a9181f7bda9a844a697e"
},
{
"url": "https://git.kernel.org/stable/c/e2b2740f1242bc70b5b46da2cdbbaa419f490e59"
},
{
"url": "https://git.kernel.org/stable/c/67b589d09a96882d56842dced5698ed8dd06ce45"
},
{
"url": "https://git.kernel.org/stable/c/e239ea91b48180ed48a86ac25643832a02c88456"
},
{
"url": "https://git.kernel.org/stable/c/e24b33618231034bf01dfaff4fd3409d4b4d5b2e"
},
{
"url": "https://git.kernel.org/stable/c/d5e5cd3654d2b5359a12ea6586120f05b28634ee"
}
],
"title": "usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68370",
"datePublished": "2026-08-10T12:03:48.320Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:31.156Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53126 (GCVE-0-2026-53126)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-06-24 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()
Add the missing put_disk() on the error path in
blkcg_maybe_throttle_current(). When blkcg lookup, blkg lookup, or
blkg_tryget() fails, the function jumps to the out label which only
calls rcu_read_unlock() but does not release the disk reference acquired
by blkcg_schedule_throttle() via get_device(). Since current->throttle_disk
is already set to NULL before the lookup, blkcg_exit() cannot release
this reference either, causing the disk to never be freed.
Restore the reference release that was present as blk_put_queue() in the
original code but was inadvertently dropped during the conversion from
request_queue to gendisk.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"block/blk-cgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4048ed98860d3785645ebbd34f69566a6c7320c3",
"status": "affected",
"version": "f05837ed73d0c73e950b2d9f2612febb0d3d451e",
"versionType": "git"
},
{
"lessThan": "73a5af059905d171b398c8b2381632ee499948b5",
"status": "affected",
"version": "f05837ed73d0c73e950b2d9f2612febb0d3d451e",
"versionType": "git"
},
{
"lessThan": "b3e005f16cd98f815429a87aef4c61e9c140779f",
"status": "affected",
"version": "f05837ed73d0c73e950b2d9f2612febb0d3d451e",
"versionType": "git"
},
{
"lessThan": "000e8454692cab9d1f1b80130e2870e355301d06",
"status": "affected",
"version": "f05837ed73d0c73e950b2d9f2612febb0d3d451e",
"versionType": "git"
},
{
"lessThan": "23308af722fefed00af5f238024c11710938fba3",
"status": "affected",
"version": "f05837ed73d0c73e950b2d9f2612febb0d3d451e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"block/blk-cgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()\n\nAdd the missing put_disk() on the error path in\nblkcg_maybe_throttle_current(). When blkcg lookup, blkg lookup, or\nblkg_tryget() fails, the function jumps to the out label which only\ncalls rcu_read_unlock() but does not release the disk reference acquired\nby blkcg_schedule_throttle() via get_device(). Since current-\u003ethrottle_disk\nis already set to NULL before the lookup, blkcg_exit() cannot release\nthis reference either, causing the disk to never be freed.\n\nRestore the reference release that was present as blk_put_queue() in the\noriginal code but was inadvertently dropped during the conversion from\nrequest_queue to gendisk."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-24T16:30:54.594Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4048ed98860d3785645ebbd34f69566a6c7320c3"
},
{
"url": "https://git.kernel.org/stable/c/73a5af059905d171b398c8b2381632ee499948b5"
},
{
"url": "https://git.kernel.org/stable/c/b3e005f16cd98f815429a87aef4c61e9c140779f"
},
{
"url": "https://git.kernel.org/stable/c/000e8454692cab9d1f1b80130e2870e355301d06"
},
{
"url": "https://git.kernel.org/stable/c/23308af722fefed00af5f238024c11710938fba3"
}
],
"title": "blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53126",
"datePublished": "2026-06-24T16:30:54.594Z",
"dateReserved": "2026-06-09T07:44:35.386Z",
"dateUpdated": "2026-06-24T16:30:54.594Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64219 (GCVE-0-2026-64219)
Vulnerability from cvelistv5
Published
2026-07-24 15:23
Modified
2026-08-05 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async
[Why&How]
dc_process_dmub_aux_transfer_async() copies payload->length bytes into a
16-byte stack buffer (dpaux.data[16]) guarded only by an ASSERT(), which
is a no-op in release builds. If a caller ever passes length > 16 this
results in a stack buffer overflow via memcpy.
Additionally, link_index is used to dereference dc->links[] without
bounds checking against dc->link_count, risking an out-of-bounds access.
Replace the ASSERT with a hard runtime check that returns false when
payload->length exceeds the destination buffer size, and add a bounds
check for link_index before it is used.
(cherry picked from commit ba4caa9fecdf7a38f98c878ad05a8a64148b6881)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 Version: 4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 Version: 4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 Version: 4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 Version: 4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 Version: 4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 Version: 4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/core/dc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d6590e3f766e3111dd1beaf88b9384d117acfa6b",
"status": "affected",
"version": "4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6",
"versionType": "git"
},
{
"lessThan": "16a5fa57565afb6bf37e18129921c270c93d8e2b",
"status": "affected",
"version": "4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6",
"versionType": "git"
},
{
"lessThan": "90c398e822ca76e40548df0c061dd4f93ea92d71",
"status": "affected",
"version": "4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6",
"versionType": "git"
},
{
"lessThan": "3265f3ed373fb8048be713aadcdf702579a0e53d",
"status": "affected",
"version": "4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6",
"versionType": "git"
},
{
"lessThan": "1ecde19bfce6535bffddad1139ff466b6d401b8e",
"status": "affected",
"version": "4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6",
"versionType": "git"
},
{
"lessThan": "1c8c6e912f2945b2a3e669afca6b52174b88e86e",
"status": "affected",
"version": "4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6",
"versionType": "git"
},
{
"lessThan": "6c92f6d9600efa3ef0d9e560a2b52776d9803c29",
"status": "affected",
"version": "4f8e37dbaf584de6d38f58b3000b0bfd7eaf2ff6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/core/dc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async\n\n[Why\u0026How]\ndc_process_dmub_aux_transfer_async() copies payload-\u003elength bytes into a\n16-byte stack buffer (dpaux.data[16]) guarded only by an ASSERT(), which\nis a no-op in release builds. If a caller ever passes length \u003e 16 this\nresults in a stack buffer overflow via memcpy.\n\nAdditionally, link_index is used to dereference dc-\u003elinks[] without\nbounds checking against dc-\u003elink_count, risking an out-of-bounds access.\n\nReplace the ASSERT with a hard runtime check that returns false when\npayload-\u003elength exceeds the destination buffer size, and add a bounds\ncheck for link_index before it is used.\n\n(cherry picked from commit ba4caa9fecdf7a38f98c878ad05a8a64148b6881)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The closest attack surface is the local DRM DisplayPort AUX character-device path; no network protocol reaches this function. Physical USB4/DisplayPort devices can initiate AUX activity but cannot directly supply the vulnerable length or index.\nAC:H - All current callers cap transactions at 16 bytes, while link_index is derived from an internally created dc_link. Exploitation therefore requires an abnormal internal caller or corrupted state that the attacker cannot directly create.\nPR:L - Reaching the relevant DRM/AUX interfaces requires local device access, but the traced path contains no administrative capability or init-namespace privilege check. Basic session or device-ACL access is therefore sufficient.\nUI:N - Once the attacker has local device access and the required abnormal state exists, the vulnerable copy or dereference executes without further victim action.\nS:U - The corruption occurs within the host kernel and does not inherently cross a separate virtualization, IOMMU, or other security authority boundary.\nC:H - A length greater than 40 can copy payload-controlled bytes beyond the 64-byte stack command and overwrite control data. Successful control-flow hijacking would permit arbitrary kernel-memory disclosure.\nI:H - The unbounded stack write can overwrite saved state and potentially enable kernel code execution; an invalid link_index can also dereference a wild pointer. This supports complete integrity impact.\nA:H - FORTIFY converts a sufficiently large copy into a kernel panic, while unfortified stack corruption, stack-canary failure, or the unchecked link dereference can cause an oops or crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:40:07.374Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d6590e3f766e3111dd1beaf88b9384d117acfa6b"
},
{
"url": "https://git.kernel.org/stable/c/16a5fa57565afb6bf37e18129921c270c93d8e2b"
},
{
"url": "https://git.kernel.org/stable/c/90c398e822ca76e40548df0c061dd4f93ea92d71"
},
{
"url": "https://git.kernel.org/stable/c/3265f3ed373fb8048be713aadcdf702579a0e53d"
},
{
"url": "https://git.kernel.org/stable/c/1ecde19bfce6535bffddad1139ff466b6d401b8e"
},
{
"url": "https://git.kernel.org/stable/c/1c8c6e912f2945b2a3e669afca6b52174b88e86e"
},
{
"url": "https://git.kernel.org/stable/c/6c92f6d9600efa3ef0d9e560a2b52776d9803c29"
}
],
"title": "drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64219",
"datePublished": "2026-07-24T15:23:06.379Z",
"dateReserved": "2026-07-19T15:36:31.770Z",
"dateUpdated": "2026-08-05T12:40:07.374Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68293 (GCVE-0-2026-68293)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
The MCIA register can return up to 32 dwords (128 bytes) when the device
advertises the mcia_32dwords capability, but struct
mlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just
12 dwords (48 bytes) of data.
mlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then
memcpy()s that many bytes out of the register, potentially reading past
the end of the 'out' buffer. On kernels built with FORTIFY_SOURCE this
is caught as a buffer overflow while reading the module EEPROM via
ethtool:
detected buffer overflow in memcpy
kernel BUG at lib/string_helpers.c:1048!
RIP: 0010:fortify_panic+0x13/0x20
Call Trace:
mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]
mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]
mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]
eeprom_prepare_data+0xf3/0x170
ethnl_default_doit+0xf1/0x3b0
Extend the mcia_reg layout to 32 dwords.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/port.c",
"include/linux/mlx5/mlx5_ifc.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5be4eebd5a3a198dab0adcd550e1cadca79bdfed",
"status": "affected",
"version": "271907ee2f29cd1078fd219f0778fd824fb1971c",
"versionType": "git"
},
{
"lessThan": "87b39a8c875ca744b7de69af0a8ef8874cffccf1",
"status": "affected",
"version": "271907ee2f29cd1078fd219f0778fd824fb1971c",
"versionType": "git"
},
{
"lessThan": "88b2a16ddac3357e3f1d528e758b51e2c945d546",
"status": "affected",
"version": "271907ee2f29cd1078fd219f0778fd824fb1971c",
"versionType": "git"
},
{
"lessThan": "11c057d23465c7a5817a7284c896d19d54c0b616",
"status": "affected",
"version": "271907ee2f29cd1078fd219f0778fd824fb1971c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/port.c",
"include/linux/mlx5/mlx5_ifc.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix MCIA register buffer overflow on 32 dword reads\n\nThe MCIA register can return up to 32 dwords (128 bytes) when the device\nadvertises the mcia_32dwords capability, but struct\nmlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just\n12 dwords (48 bytes) of data.\n\nmlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then\nmemcpy()s that many bytes out of the register, potentially reading past\nthe end of the \u0027out\u0027 buffer. On kernels built with FORTIFY_SOURCE this\nis caught as a buffer overflow while reading the module EEPROM via\nethtool:\n\n detected buffer overflow in memcpy\n kernel BUG at lib/string_helpers.c:1048!\n RIP: 0010:fortify_panic+0x13/0x20\n Call Trace:\n mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]\n mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]\n mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]\n eeprom_prepare_data+0xf3/0x170\n ethnl_default_doit+0xf1/0x3b0\n\nExtend the mcia_reg layout to 32 dwords."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local ethtool interfaces on the mlx5 netdev \u2014 the ETHTOOL_MSG_MODULE_EEPROM_GET genetlink message or the ETHTOOL_GMODULEEEPROM ioctl on a socket. No remote peer or received packet can trigger it.\nAC:L - A single ethtool module-EEPROM read of 128 bytes deterministically triggers the over-read on any adapter whose firmware advertises mcia_32dwords, which is the normal case on modern ConnectX hardware with a transceiver installed. No race, no memory-layout grooming, fully repeatable.\nPR:L - Both entry points check ns_capable(net-\u003euser_ns, CAP_NET_ADMIN), which is namespace-relative, so the root of an unprivileged user namespace owning a netns that holds an mlx5 VF/subfunction netdev (a standard SR-IOV container setup) can trigger it without any privilege in the initial namespace.\nUI:N - The attacker triggers the read entirely on their own by issuing an ethtool query; no action by another user or administrator is needed.\nS:U - The out-of-bounds read and its consequences are confined to the kernel of the same host; no VM, IOMMU, or other security-authority boundary is crossed.\nC:H - Up to 80 bytes of kernel stack adjacent to the 64-byte \u0027out\u0027 buffer are memcpy()\u0027d into the EEPROM data returned to userspace, disclosing saved registers, pointers and potentially return addresses or the stack canary \u2014 enough to defeat KASLR and stack protection and aid further exploitation.\nI:N - The defect is purely a read overflow; the destination buffer is sized from the caller\u0027s own request length, so no kernel memory is written out of bounds and no data is modified.\nA:H - On the widely enabled CONFIG_FORTIFY_SOURCE the copy hits fortify_panic(), producing a kernel BUG/oops in mlx5_query_mcia() while rtnl/netdev locks are held (per the reported trace), wedging networking and panicking outright with panic_on_oops."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:29.111Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5be4eebd5a3a198dab0adcd550e1cadca79bdfed"
},
{
"url": "https://git.kernel.org/stable/c/87b39a8c875ca744b7de69af0a8ef8874cffccf1"
},
{
"url": "https://git.kernel.org/stable/c/88b2a16ddac3357e3f1d528e758b51e2c945d546"
},
{
"url": "https://git.kernel.org/stable/c/11c057d23465c7a5817a7284c896d19d54c0b616"
}
],
"title": "net/mlx5: Fix MCIA register buffer overflow on 32 dword reads",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68293",
"datePublished": "2026-08-10T12:02:26.414Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-17T05:02:29.111Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64097 (GCVE-0-2026-64097)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Validate GPIO pin LUT table size before iterating
[Why&How]
The GPIO pin table parsers in get_gpio_i2c_info() and
bios_parser_get_gpio_pin_info() derive an element count from the VBIOS
table_header.structuresize field, then iterate over gpio_pin[] entries.
However, GET_IMAGE() only validates that the table header itself fits
within the BIOS image. If the VBIOS reports a structuresize larger than
the actual mapped data, the loop reads past the end of the BIOS image,
causing an out-of-bounds read.
Fix this by calling bios_get_image() to validate that the full claimed
structuresize is accessible within the BIOS image before entering the
loop in both functions.
(cherry picked from commit ba5e95b43b773ae1bf1f66ee6b31eb774e65afe3)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1 Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1 Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1 Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1 Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1 Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/bios/bios_parser2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9900f6954be779011e7c2cd42addd87baf028bc5",
"status": "affected",
"version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
"versionType": "git"
},
{
"lessThan": "fb30a3890d62fd50a95aef684faf64a307592e42",
"status": "affected",
"version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
"versionType": "git"
},
{
"lessThan": "67461e0c15335894cc5d3b84cda823bf8cbdc886",
"status": "affected",
"version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
"versionType": "git"
},
{
"lessThan": "7ca695b3122297b06a3ed605bbe1cd32c85d9f5a",
"status": "affected",
"version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
"versionType": "git"
},
{
"lessThan": "f2a4827e980ba07de4391fa84d9c39a12726bdd7",
"status": "affected",
"version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
"versionType": "git"
},
{
"lessThan": "86d2b20644b11d21fe52c596e6e922b4590a3e3f",
"status": "affected",
"version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/bios/bios_parser2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Validate GPIO pin LUT table size before iterating\n\n[Why\u0026How]\nThe GPIO pin table parsers in get_gpio_i2c_info() and\nbios_parser_get_gpio_pin_info() derive an element count from the VBIOS\ntable_header.structuresize field, then iterate over gpio_pin[] entries.\nHowever, GET_IMAGE() only validates that the table header itself fits\nwithin the BIOS image. If the VBIOS reports a structuresize larger than\nthe actual mapped data, the loop reads past the end of the BIOS image,\ncausing an out-of-bounds read.\n\nFix this by calling bios_get_image() to validate that the full claimed\nstructuresize is accessible within the BIOS image before entering the\nloop in both functions.\n\n(cherry picked from commit ba5e95b43b773ae1bf1f66ee6b31eb774e65afe3)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the amdgpu DRM/display stack when the kernel parses VBIOS GPIO tables during connector/link setup (dc_create \u2192 link_create \u2192 get_gpio_i2c_info()/bios_parser_get_gpio_pin_info()); there is no network, Bluetooth, or USB packet path to this code.\nAC:L - Once a GPU carries a VBIOS with an inflated gpio_pin_lut structuresize, the derived loop count is fully attacker-controlled and the out-of-bounds read triggers deterministically on driver probe or display link initialization without races or layout-dependent conditions.\nPR:L - No capability checks guard the call path; any local user with ordinary access to the AMDGPU DRM device (typical video/render group membership) reaches the vulnerable parsers during normal display initialization, while a malicious VBIOS can be preinstalled via physical GPU reprogramming, supply-chain compromise, or prior privileged vbflash without ongoing root at trigger time.\nUI:N - Exploitation requires no victim interaction beyond system/driver startup; on laptops and servers with AMD GPUs the vulnerable parsing runs automatically during amdgpu module load and connector enumeration, including built-in eDP paths.\nS:U - Impact stays within kernel/GPU driver context on the same machine; corrupted VBIOS parsing does not cross a VM-host, container, or IOMMU security boundary even in SR-IOV or passthrough deployments.\nC:H - The loop performs an out-of-bounds read past the validated GPIO pin LUT when structuresize overstates the table, potentially reading adjacent kernel heap memory beyond the kmalloc\u0027d VBIOS image and feeding attacker-influenced bytes into subsequent GPIO register-index lookups.\nI:H - Mis-parsed out-of-bounds gpio_pin_assignment entries supply data_a_reg_index and gpio_bitshift values that drive MMIO/GPIO configuration (DDC, HPD, I2C pin setup), enabling arbitrary display-engine register targeting and memory-corruption-class integrity impact rather than a benign read-only fault.\nA:H - Invalid register offsets and masks derived from out-of-bounds data can hang or fault the display subsystem and broader kernel (GPU reset, oops, or denial of service), and uncontrolled reads past the VBIOS buffer boundary can provoke crashes under memory-hardening or on marginal hardware."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:11.518Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9900f6954be779011e7c2cd42addd87baf028bc5"
},
{
"url": "https://git.kernel.org/stable/c/fb30a3890d62fd50a95aef684faf64a307592e42"
},
{
"url": "https://git.kernel.org/stable/c/67461e0c15335894cc5d3b84cda823bf8cbdc886"
},
{
"url": "https://git.kernel.org/stable/c/7ca695b3122297b06a3ed605bbe1cd32c85d9f5a"
},
{
"url": "https://git.kernel.org/stable/c/f2a4827e980ba07de4391fa84d9c39a12726bdd7"
},
{
"url": "https://git.kernel.org/stable/c/86d2b20644b11d21fe52c596e6e922b4590a3e3f"
}
],
"title": "drm/amd/display: Validate GPIO pin LUT table size before iterating",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64097",
"datePublished": "2026-07-19T15:40:03.599Z",
"dateReserved": "2026-07-19T07:54:57.033Z",
"dateUpdated": "2026-08-05T12:39:11.518Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40022 (GCVE-0-2025-40022)
Vulnerability from cvelistv5
Published
2025-10-24 12:24
Modified
2026-09-08 08:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Fix incorrect boolean values in af_alg_ctx
Commit 1b34cbbf4f01 ("crypto: af_alg - Disallow concurrent writes in
af_alg_sendmsg") changed some fields from bool to 1-bit bitfields of
type u32.
However, some assignments to these fields, specifically 'more' and
'merge', assign values greater than 1. These relied on C's implicit
conversion to bool, such that zero becomes false and nonzero becomes
true.
With a 1-bit bitfields of type u32 instead, mod 2 of the value is taken
instead, resulting in 0 being assigned in some cases when 1 was intended.
Fix this by restoring the bool type.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce Version: e4c1ec11132ec466f7362a95f36a506ce4dc08c9 Version: 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8 Version: 7c4491b5644e3a3708f3dbd7591be0a570135b84 Version: 9aee87da5572b3a14075f501752e209801160d3d Version: 45bcf60fe49b37daab1acee57b27211ad1574042 Version: 1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:42:43.608Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/crypto/if_alg.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3a21698ace915a445bce2d0dcfc84b6d2199baf7",
"status": "affected",
"version": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
"versionType": "git"
},
{
"lessThan": "d382d6daf0184490f366562469a5673f65ee2662",
"status": "affected",
"version": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
"versionType": "git"
},
{
"lessThan": "54506c6335690f4ef1b9f154e34f5a604c72c1ed",
"status": "affected",
"version": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
"versionType": "git"
},
{
"lessThan": "8703940bd30b5ad94408d28d7192db2491cd3592",
"status": "affected",
"version": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
"versionType": "git"
},
{
"lessThan": "316b090c2fee964c307a634fecc7df269664b158",
"status": "affected",
"version": "9aee87da5572b3a14075f501752e209801160d3d",
"versionType": "git"
},
{
"lessThan": "fbe96bd25423e61273d8831e995260b429d850b6",
"status": "affected",
"version": "45bcf60fe49b37daab1acee57b27211ad1574042",
"versionType": "git"
},
{
"lessThan": "d0ca0df179c4b21e2a6c4a4fb637aa8fa14575cb",
"status": "affected",
"version": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/crypto/if_alg.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6.1.155",
"status": "affected",
"version": "6.1.154",
"versionType": "semver"
},
{
"lessThan": "6.6.109",
"status": "affected",
"version": "6.6.108",
"versionType": "semver"
},
{
"lessThan": "6.12.50",
"status": "affected",
"version": "6.12.49",
"versionType": "semver"
},
{
"lessThan": "6.16.10",
"status": "affected",
"version": "6.16.9",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.155",
"versionStartIncluding": "6.1.154",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.109",
"versionStartIncluding": "6.6.108",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.50",
"versionStartIncluding": "6.12.49",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16.10",
"versionStartIncluding": "6.16.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Fix incorrect boolean values in af_alg_ctx\n\nCommit 1b34cbbf4f01 (\"crypto: af_alg - Disallow concurrent writes in\naf_alg_sendmsg\") changed some fields from bool to 1-bit bitfields of\ntype u32.\n\nHowever, some assignments to these fields, specifically \u0027more\u0027 and\n\u0027merge\u0027, assign values greater than 1. These relied on C\u0027s implicit\nconversion to bool, such that zero becomes false and nonzero becomes\ntrue.\n\nWith a 1-bit bitfields of type u32 instead, mod 2 of the value is taken\ninstead, resulting in 0 being assigned in some cases when 1 was intended.\n\nFix this by restoring the bool type."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T21:40:58.053Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3a21698ace915a445bce2d0dcfc84b6d2199baf7"
},
{
"url": "https://git.kernel.org/stable/c/d382d6daf0184490f366562469a5673f65ee2662"
},
{
"url": "https://git.kernel.org/stable/c/54506c6335690f4ef1b9f154e34f5a604c72c1ed"
},
{
"url": "https://git.kernel.org/stable/c/8703940bd30b5ad94408d28d7192db2491cd3592"
},
{
"url": "https://git.kernel.org/stable/c/316b090c2fee964c307a634fecc7df269664b158"
},
{
"url": "https://git.kernel.org/stable/c/fbe96bd25423e61273d8831e995260b429d850b6"
},
{
"url": "https://git.kernel.org/stable/c/d0ca0df179c4b21e2a6c4a4fb637aa8fa14575cb"
}
],
"title": "crypto: af_alg - Fix incorrect boolean values in af_alg_ctx",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40022",
"datePublished": "2025-10-24T12:24:57.875Z",
"dateReserved": "2025-04-16T07:20:57.152Z",
"dateUpdated": "2026-09-08T08:42:43.608Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64472 (GCVE-0-2026-64472)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vfio/mlx5: Fix racy bitfields and tighten struct layout
Bitfield operations are not atomic, they use a read-modify-write
pattern, therefore we should be careful not to pack bitfields that
can be concurrently updated into the same storage unit.
This split takes a binary approach: flags that are only modified
pre/post open/close remain bitfields, flags modified from user
action, including actions that reach across to another device (ex.
reset) use dedicated storage units.
Note mlx5_vhca_page_tracker.status is relocated to fill the alignment
hole this split exposes.
Bitfield justifications:
migrate_cap: written only in mlx5vf_cmd_set_migratable() at probe
chunk_mode: written only in mlx5vf_cmd_set_migratable() at probe
mig_state_cap: written only in mlx5vf_cmd_set_migratable() at probe
Dedicated storage units:
mdev_detach: written in the VF attach/detach event notifier
mlx5fv_vf_event() at runtime
log_active: written in mlx5vf_start_page_tracker()/
mlx5vf_stop_page_tracker() during runtime dirty tracking
deferred_reset: written in mlx5vf_state_mutex_unlock()/
mlx5vf_pci_aer_reset_done() during runtime reset handling
is_err: set by tracker error handling and dirty-log polling at runtime
object_changed: set by tracker event handling and cleared by dirty-log
polling at runtime
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 61a2f1460fd03285ea34c1a235f2f50f71e13a1f Version: 61a2f1460fd03285ea34c1a235f2f50f71e13a1f Version: 61a2f1460fd03285ea34c1a235f2f50f71e13a1f Version: 61a2f1460fd03285ea34c1a235f2f50f71e13a1f Version: 61a2f1460fd03285ea34c1a235f2f50f71e13a1f Version: 61a2f1460fd03285ea34c1a235f2f50f71e13a1f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/vfio/pci/mlx5/cmd.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1dd99b8f4e143592e12e5a77e7b538bc698116cb",
"status": "affected",
"version": "61a2f1460fd03285ea34c1a235f2f50f71e13a1f",
"versionType": "git"
},
{
"lessThan": "f1db80a67da928a92ba460ede1be52d8941f46be",
"status": "affected",
"version": "61a2f1460fd03285ea34c1a235f2f50f71e13a1f",
"versionType": "git"
},
{
"lessThan": "399d806f998f7a25405fc1b97227e579aead24af",
"status": "affected",
"version": "61a2f1460fd03285ea34c1a235f2f50f71e13a1f",
"versionType": "git"
},
{
"lessThan": "7ed120b1a007bace57c461805519d70e1af44e59",
"status": "affected",
"version": "61a2f1460fd03285ea34c1a235f2f50f71e13a1f",
"versionType": "git"
},
{
"lessThan": "39d163627b51886492bf31f66cb02c94613d2287",
"status": "affected",
"version": "61a2f1460fd03285ea34c1a235f2f50f71e13a1f",
"versionType": "git"
},
{
"lessThan": "f2365a63b02ddea32e7db78b742c2503ec7b81f1",
"status": "affected",
"version": "61a2f1460fd03285ea34c1a235f2f50f71e13a1f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/vfio/pci/mlx5/cmd.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/mlx5: Fix racy bitfields and tighten struct layout\n\nBitfield operations are not atomic, they use a read-modify-write\npattern, therefore we should be careful not to pack bitfields that\ncan be concurrently updated into the same storage unit.\n\nThis split takes a binary approach: flags that are only modified\npre/post open/close remain bitfields, flags modified from user\naction, including actions that reach across to another device (ex.\nreset) use dedicated storage units.\n\nNote mlx5_vhca_page_tracker.status is relocated to fill the alignment\nhole this split exposes.\n\nBitfield justifications:\n\n migrate_cap: written only in mlx5vf_cmd_set_migratable() at probe\n chunk_mode: written only in mlx5vf_cmd_set_migratable() at probe\n mig_state_cap: written only in mlx5vf_cmd_set_migratable() at probe\n\nDedicated storage units:\n\n mdev_detach: written in the VF attach/detach event notifier\n mlx5fv_vf_event() at runtime\n log_active: written in mlx5vf_start_page_tracker()/\n mlx5vf_stop_page_tracker() during runtime dirty tracking\n deferred_reset: written in mlx5vf_state_mutex_unlock()/\n mlx5vf_pci_aer_reset_done() during runtime reset handling\n is_err: set by tracker error handling and dirty-log polling at runtime\n object_changed: set by tracker event handling and cleared by dirty-log\n polling at runtime"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:18.199Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1dd99b8f4e143592e12e5a77e7b538bc698116cb"
},
{
"url": "https://git.kernel.org/stable/c/f1db80a67da928a92ba460ede1be52d8941f46be"
},
{
"url": "https://git.kernel.org/stable/c/399d806f998f7a25405fc1b97227e579aead24af"
},
{
"url": "https://git.kernel.org/stable/c/7ed120b1a007bace57c461805519d70e1af44e59"
},
{
"url": "https://git.kernel.org/stable/c/39d163627b51886492bf31f66cb02c94613d2287"
},
{
"url": "https://git.kernel.org/stable/c/f2365a63b02ddea32e7db78b742c2503ec7b81f1"
}
],
"title": "vfio/mlx5: Fix racy bitfields and tighten struct layout",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64472",
"datePublished": "2026-07-25T08:51:35.978Z",
"dateReserved": "2026-07-19T15:36:31.790Z",
"dateUpdated": "2026-08-17T04:56:18.199Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63810 (GCVE-0-2026-63810)
Vulnerability from cvelistv5
Published
2026-07-19 12:02
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
block: Avoid mounting the bdev pseudo-filesystem in userspace
The bdev pseudo-filesystem is an internal kernel filesystem with which
userspace should not interfere. Unregister it so that userspace cannot
even attempt to mount it.
This fixes a bug [1] that occurs when attempting to access files,
because the system call move_mount() uses pointers declared in the
inode_operations structure, which for the bdev pseudo-filesystem
are always equal to 0. `inode->i_op = &empty_iops;`
[1]
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor instruction fetch in kernel mode
#PF: error_code(0x0010) - not-present page
PGD 23380067 P4D 23380067 PUD 23381067 PMD 0
Oops: 0010 [#1] PREEMPT SMP KASAN NOPTI
CPU: 2 PID: 17125 Comm: syz-executor.0 Not tainted 6.1.155-syzkaller-00350-g84221fde2681 #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014
RIP: 0010:0x0
Call Trace:
<TASK>
lookup_open.isra.0+0x700/0x1180 fs/namei.c:3460
open_last_lookups fs/namei.c:3550 [inline]
path_openat+0x953/0x2700 fs/namei.c:3780
do_filp_open+0x1c5/0x410 fs/namei.c:3810
do_sys_openat2+0x171/0x4d0 fs/open.c:1318
do_sys_open fs/open.c:1334 [inline]
__do_sys_openat fs/open.c:1350 [inline]
__se_sys_openat fs/open.c:1345 [inline]
__x64_sys_openat+0x13c/0x1f0 fs/open.c:1345
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x6e/0xd8
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:20.561Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"block/bdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3d3fcf23993bb756de2f912ab631cfdcc4746554",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "99cde0a7b1e98fd3970aabef1300918e91698dd5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1a02a5028bd6dead1f8503854ef3168d651cd417",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "197971e6ffc0a6356b2ba2b22beb42bc0f7e412d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3804e6de30ae7b053d53341d9d6944356cf23b40",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "717f721eb67d2dacd3ed5f7495aef2f442e84ce4",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f73aa66dffcb8e61e78f01b56163ec16a15d06d2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"block/bdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Avoid mounting the bdev pseudo-filesystem in userspace\n\nThe bdev pseudo-filesystem is an internal kernel filesystem with which\nuserspace should not interfere. Unregister it so that userspace cannot\neven attempt to mount it.\n\nThis fixes a bug [1] that occurs when attempting to access files,\nbecause the system call move_mount() uses pointers declared in the\ninode_operations structure, which for the bdev pseudo-filesystem\nare always equal to 0. `inode-\u003ei_op = \u0026empty_iops;`\n\n[1]\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n #PF: supervisor instruction fetch in kernel mode\n #PF: error_code(0x0010) - not-present page\n PGD 23380067 P4D 23380067 PUD 23381067 PMD 0\n Oops: 0010 [#1] PREEMPT SMP KASAN NOPTI\n CPU: 2 PID: 17125 Comm: syz-executor.0 Not tainted 6.1.155-syzkaller-00350-g84221fde2681 #0\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\n RIP: 0010:0x0\n\n Call Trace:\n \u003cTASK\u003e\n lookup_open.isra.0+0x700/0x1180 fs/namei.c:3460\n open_last_lookups fs/namei.c:3550 [inline]\n path_openat+0x953/0x2700 fs/namei.c:3780\n do_filp_open+0x1c5/0x410 fs/namei.c:3810\n do_sys_openat2+0x171/0x4d0 fs/open.c:1318\n do_sys_open fs/open.c:1334 [inline]\n __do_sys_openat fs/open.c:1350 [inline]\n __se_sys_openat fs/open.c:1345 [inline]\n __x64_sys_openat+0x13c/0x1f0 fs/open.c:1345\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:16.632Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3d3fcf23993bb756de2f912ab631cfdcc4746554"
},
{
"url": "https://git.kernel.org/stable/c/99cde0a7b1e98fd3970aabef1300918e91698dd5"
},
{
"url": "https://git.kernel.org/stable/c/1a02a5028bd6dead1f8503854ef3168d651cd417"
},
{
"url": "https://git.kernel.org/stable/c/197971e6ffc0a6356b2ba2b22beb42bc0f7e412d"
},
{
"url": "https://git.kernel.org/stable/c/3804e6de30ae7b053d53341d9d6944356cf23b40"
},
{
"url": "https://git.kernel.org/stable/c/717f721eb67d2dacd3ed5f7495aef2f442e84ce4"
},
{
"url": "https://git.kernel.org/stable/c/f73aa66dffcb8e61e78f01b56163ec16a15d06d2"
}
],
"title": "block: Avoid mounting the bdev pseudo-filesystem in userspace",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63810",
"datePublished": "2026-07-19T12:02:12.484Z",
"dateReserved": "2026-07-19T07:54:57.013Z",
"dateUpdated": "2026-09-08T08:50:20.561Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64317 (GCVE-0-2026-64317)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
isofs: bound Rock Ridge symlink components to the SL record
get_symlink_chunk() and the SL handling in
parse_rock_ridge_inode_internal() walk the variable-length components of
a Rock Ridge "SL" (symbolic link) record. Each component is a two-byte
header (flags, len) followed by len bytes of text, so it occupies
slp->len + 2 bytes. Both loops read slp->len and advance to the next
component, and get_symlink_chunk() additionally does
memcpy(rpnt, slp->text, slp->len), but neither checks that the component
lies within the SL record before dereferencing it.
A crafted SL record whose component declares a len that runs past the
record (rr->len) therefore triggers an out-of-bounds read of up to 255
bytes. When the record sits at the tail of its backing buffer - for
example a small kmalloc()ed continuation block reached through a CE
record - the read crosses the allocation; get_symlink_chunk() then
copies the out-of-bounds bytes into the symlink body returned to user
space by readlink(), disclosing adjacent kernel memory.
ISO 9660 images are routinely mounted from untrusted removable media -
desktop environments auto-mount them (e.g. via udisks2) without
CAP_SYS_ADMIN - so the record contents are attacker-controlled.
Reject any component that does not fit in the remaining record bytes
before using it. In get_symlink_chunk() return NULL, like the existing
output-buffer (plimit) checks, so a malformed record makes readlink()
fail with -EIO rather than silently returning a truncated target; in
parse_rock_ridge_inode_internal() stop the inode-size walk.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:23.371Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/isofs/rock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1015e1c4b2fadd9c09704e24738e46598778c869",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "36fe7d25dbc40da0c6b1dd4513a4f69ac6164eee",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a22cb6bb54dc167047ea9e70d97dfbc2c15649e3",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b736b12108fd116c41777628f5a333791604df26",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6bf41db09ef935d76fcc84ccf213b42c18de95ee",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b5699642640d6cff357638738c5293985cd5a53d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9830725078c8483c6831ec10222ae724806ea36b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5fa1d6a5ec2356d2107dead614437c66fa7138b1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/isofs/rock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: bound Rock Ridge symlink components to the SL record\n\nget_symlink_chunk() and the SL handling in\nparse_rock_ridge_inode_internal() walk the variable-length components of\na Rock Ridge \"SL\" (symbolic link) record. Each component is a two-byte\nheader (flags, len) followed by len bytes of text, so it occupies\nslp-\u003elen + 2 bytes. Both loops read slp-\u003elen and advance to the next\ncomponent, and get_symlink_chunk() additionally does\nmemcpy(rpnt, slp-\u003etext, slp-\u003elen), but neither checks that the component\nlies within the SL record before dereferencing it.\n\nA crafted SL record whose component declares a len that runs past the\nrecord (rr-\u003elen) therefore triggers an out-of-bounds read of up to 255\nbytes. When the record sits at the tail of its backing buffer - for\nexample a small kmalloc()ed continuation block reached through a CE\nrecord - the read crosses the allocation; get_symlink_chunk() then\ncopies the out-of-bounds bytes into the symlink body returned to user\nspace by readlink(), disclosing adjacent kernel memory.\n\nISO 9660 images are routinely mounted from untrusted removable media -\ndesktop environments auto-mount them (e.g. via udisks2) without\nCAP_SYS_ADMIN - so the record contents are attacker-controlled.\n\nReject any component that does not fit in the remaining record bytes\nbefore using it. In get_symlink_chunk() return NULL, like the existing\noutput-buffer (plimit) checks, so a malformed record makes readlink()\nfail with -EIO rather than silently returning a truncated target; in\nparse_rock_ridge_inode_internal() stop the inode-size walk."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - An active unprivileged local user can use UDisks2 to mount an attacker-created ISO image and invoke readlink(); ISOFS is not directly mountable through an unprivileged user namespace.\nAC:L - The attacker fully controls the SL component length and CE continuation layout, reliably triggering the out-of-bounds read without a race or an uncontrollable condition.\nPR:L - Direct mounting requires CAP_SYS_ADMIN in the initial user namespace, but common UDisks2 policies permit an active ordinary desktop user to create a loop device and mount the image without administrator authentication.\nUI:N - The local attacker can mount the crafted image and read the symlink themselves, requiring no action by another user.\nS:U - The disclosure and possible crash occur within the host kernel\u0027s existing security authority and do not cross a virtualization or comparable scope boundary.\nC:H - Up to 255 bytes per malformed SL component are copied from beyond a controllably sized kernel allocation into readlink() output; repeated components or attempts can disclose kernel pointers, secrets, and substantial adjacent heap data.\nI:N - The flaw performs an out-of-bounds source read while all destination writes remain bounded to the symlink page, providing no kernel-memory overwrite or control-flow modification primitive.\nA:H - The out-of-bounds memcpy can cross into inaccessible or allocator-guarded memory and cause a kernel oops or panic, and a local attacker can trigger repeated allocations and reads."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:17.683Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1015e1c4b2fadd9c09704e24738e46598778c869"
},
{
"url": "https://git.kernel.org/stable/c/36fe7d25dbc40da0c6b1dd4513a4f69ac6164eee"
},
{
"url": "https://git.kernel.org/stable/c/a22cb6bb54dc167047ea9e70d97dfbc2c15649e3"
},
{
"url": "https://git.kernel.org/stable/c/b736b12108fd116c41777628f5a333791604df26"
},
{
"url": "https://git.kernel.org/stable/c/6bf41db09ef935d76fcc84ccf213b42c18de95ee"
},
{
"url": "https://git.kernel.org/stable/c/b5699642640d6cff357638738c5293985cd5a53d"
},
{
"url": "https://git.kernel.org/stable/c/9830725078c8483c6831ec10222ae724806ea36b"
},
{
"url": "https://git.kernel.org/stable/c/5fa1d6a5ec2356d2107dead614437c66fa7138b1"
}
],
"title": "isofs: bound Rock Ridge symlink components to the SL record",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64317",
"datePublished": "2026-07-25T08:49:47.067Z",
"dateReserved": "2026-07-19T15:36:31.779Z",
"dateUpdated": "2026-09-08T08:50:23.371Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43014 (GCVE-0-2026-43014)
Vulnerability from cvelistv5
Published
2026-05-01 14:15
Modified
2026-05-11 22:16
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: macb: properly unregister fixed rate clocks
The additional resources allocated with clk_register_fixed_rate() need
to be released with clk_unregister_fixed_rate(), otherwise they are lost.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 83a77e9ec4150ee4acc635638f7dedd9da523a26 Version: 83a77e9ec4150ee4acc635638f7dedd9da523a26 Version: 83a77e9ec4150ee4acc635638f7dedd9da523a26 Version: 83a77e9ec4150ee4acc635638f7dedd9da523a26 Version: 83a77e9ec4150ee4acc635638f7dedd9da523a26 Version: 83a77e9ec4150ee4acc635638f7dedd9da523a26 Version: 83a77e9ec4150ee4acc635638f7dedd9da523a26 Version: 83a77e9ec4150ee4acc635638f7dedd9da523a26 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cadence/macb_pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "54c6f0e7682433abed0304ac2f5cb71a92d4b366",
"status": "affected",
"version": "83a77e9ec4150ee4acc635638f7dedd9da523a26",
"versionType": "git"
},
{
"lessThan": "015aa24d3721a05b40935b8af78b49cadf616b8d",
"status": "affected",
"version": "83a77e9ec4150ee4acc635638f7dedd9da523a26",
"versionType": "git"
},
{
"lessThan": "ec1be2ce0d94506f11b22066fd6dc5eb4341b14f",
"status": "affected",
"version": "83a77e9ec4150ee4acc635638f7dedd9da523a26",
"versionType": "git"
},
{
"lessThan": "e1f6f47d6e60d51c3294e5b85787e9aee24c450e",
"status": "affected",
"version": "83a77e9ec4150ee4acc635638f7dedd9da523a26",
"versionType": "git"
},
{
"lessThan": "e35dbfdb1b7710f04ff5c9972ea04971d823a22d",
"status": "affected",
"version": "83a77e9ec4150ee4acc635638f7dedd9da523a26",
"versionType": "git"
},
{
"lessThan": "5392a5174df4f5a2fad2f00e8c617394d0efe031",
"status": "affected",
"version": "83a77e9ec4150ee4acc635638f7dedd9da523a26",
"versionType": "git"
},
{
"lessThan": "6ec567425c057fd850651ee09b31d059ef960e0f",
"status": "affected",
"version": "83a77e9ec4150ee4acc635638f7dedd9da523a26",
"versionType": "git"
},
{
"lessThan": "f0f367a4f459cc8118aadc43c6bba53c60d93f8d",
"status": "affected",
"version": "83a77e9ec4150ee4acc635638f7dedd9da523a26",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cadence/macb_pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.253",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.168",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.134",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.81",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.22",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.253",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.168",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.134",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.81",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.22",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.12",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: properly unregister fixed rate clocks\n\nThe additional resources allocated with clk_register_fixed_rate() need\nto be released with clk_unregister_fixed_rate(), otherwise they are lost."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:16:02.195Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/54c6f0e7682433abed0304ac2f5cb71a92d4b366"
},
{
"url": "https://git.kernel.org/stable/c/015aa24d3721a05b40935b8af78b49cadf616b8d"
},
{
"url": "https://git.kernel.org/stable/c/ec1be2ce0d94506f11b22066fd6dc5eb4341b14f"
},
{
"url": "https://git.kernel.org/stable/c/e1f6f47d6e60d51c3294e5b85787e9aee24c450e"
},
{
"url": "https://git.kernel.org/stable/c/e35dbfdb1b7710f04ff5c9972ea04971d823a22d"
},
{
"url": "https://git.kernel.org/stable/c/5392a5174df4f5a2fad2f00e8c617394d0efe031"
},
{
"url": "https://git.kernel.org/stable/c/6ec567425c057fd850651ee09b31d059ef960e0f"
},
{
"url": "https://git.kernel.org/stable/c/f0f367a4f459cc8118aadc43c6bba53c60d93f8d"
}
],
"title": "net: macb: properly unregister fixed rate clocks",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43014",
"datePublished": "2026-05-01T14:15:19.571Z",
"dateReserved": "2026-05-01T14:12:55.974Z",
"dateUpdated": "2026-05-11T22:16:02.195Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43278 (GCVE-0-2026-43278)
Vulnerability from cvelistv5
Published
2026-05-06 11:29
Modified
2026-08-05 12:27
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dm: clear cloned request bio pointer when last clone bio completes
Stale rq->bio values have been observed to cause double-initialization of
cloned bios in request-based device-mapper targets, leading to
use-after-free and double-free scenarios.
One such case occurs when using dm-multipath on top of a PCIe NVMe
namespace, where cloned request bios are freed during
blk_complete_request(), but rq->bio is left intact. Subsequent clone
teardown then attempts to free the same bios again via
blk_rq_unprep_clone().
The resulting double-free path looks like:
nvme_pci_complete_batch()
nvme_complete_batch()
blk_mq_end_request_batch()
blk_complete_request() // called on a DM clone request
bio_endio() // first free of all clone bios
...
rq->end_io() // end_clone_request()
dm_complete_request(tio->orig)
dm_softirq_done()
dm_done()
dm_end_request()
blk_rq_unprep_clone() // second free of clone bios
Fix this by clearing the clone request's bio pointer when the last cloned
bio completes, ensuring that later teardown paths do not attempt to free
already-released bios.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ab3e1d3bbab9e973aeb4dd4603251578658a47ff Version: ab3e1d3bbab9e973aeb4dd4603251578658a47ff Version: ab3e1d3bbab9e973aeb4dd4603251578658a47ff Version: ab3e1d3bbab9e973aeb4dd4603251578658a47ff Version: ab3e1d3bbab9e973aeb4dd4603251578658a47ff Version: ab3e1d3bbab9e973aeb4dd4603251578658a47ff |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/dm-rq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8d9ddad561136f7e6a9346767bf97b4d79e38e67",
"status": "affected",
"version": "ab3e1d3bbab9e973aeb4dd4603251578658a47ff",
"versionType": "git"
},
{
"lessThan": "7daf279c674d515fb22a727a7bbc92aeb35c5442",
"status": "affected",
"version": "ab3e1d3bbab9e973aeb4dd4603251578658a47ff",
"versionType": "git"
},
{
"lessThan": "e2e738e8dfbbf83bd2bae0467ec4420cc52da42a",
"status": "affected",
"version": "ab3e1d3bbab9e973aeb4dd4603251578658a47ff",
"versionType": "git"
},
{
"lessThan": "b1c1a2637ebd675aa2d71fee8c70da8791d73850",
"status": "affected",
"version": "ab3e1d3bbab9e973aeb4dd4603251578658a47ff",
"versionType": "git"
},
{
"lessThan": "83d72091804600ead96dc9e9f518ea56cb4942f6",
"status": "affected",
"version": "ab3e1d3bbab9e973aeb4dd4603251578658a47ff",
"versionType": "git"
},
{
"lessThan": "fb8a6c18fb9a6561f7a15b58b272442b77a242dd",
"status": "affected",
"version": "ab3e1d3bbab9e973aeb4dd4603251578658a47ff",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/dm-rq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm: clear cloned request bio pointer when last clone bio completes\n\nStale rq-\u003ebio values have been observed to cause double-initialization of\ncloned bios in request-based device-mapper targets, leading to\nuse-after-free and double-free scenarios.\n\nOne such case occurs when using dm-multipath on top of a PCIe NVMe\nnamespace, where cloned request bios are freed during\nblk_complete_request(), but rq-\u003ebio is left intact. Subsequent clone\nteardown then attempts to free the same bios again via\nblk_rq_unprep_clone().\n\nThe resulting double-free path looks like:\n\n nvme_pci_complete_batch()\n nvme_complete_batch()\n blk_mq_end_request_batch()\n blk_complete_request() // called on a DM clone request\n bio_endio() // first free of all clone bios\n ...\n rq-\u003eend_io() // end_clone_request()\n dm_complete_request(tio-\u003eorig)\n dm_softirq_done()\n dm_done()\n dm_end_request()\n blk_rq_unprep_clone() // second free of clone bios\n\nFix this by clearing the clone request\u0027s bio pointer when the last cloned\nbio completes, ensuring that later teardown paths do not attempt to free\nalready-released bios."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable request-based device-mapper path is reached by local block I/O, such as reads or writes to a filesystem backed by dm-multipath. It is not itself a network protocol handler, even though network services may indirectly generate disk I/O.\nAC:L - On an affected request-based dm-multipath stack over blk-mq/NVMe, ordinary I/O can drive the deterministic completion path that frees the clone bios and then tears down the clone. No attacker-uncontrolled race is required.\nPR:L - Creating or reconfiguring DM devices requires CAP_SYS_ADMIN, but triggering the bug only requires the ability to issue I/O to an existing affected mapped device, for example through files the local user can read or write. Thus a basic unprivileged local user can reach the vulnerable path.\nUI:N - The attacker can trigger the I/O directly through their own syscalls. No separate victim action is required.\nS:U - The impact remains within the kernel/host security authority. This is a standard local kernel memory-corruption issue, not a VM escape or cross-authority boundary bypass.\nC:H - The stale cloned bio pointer causes use-after-free/double-free of kernel heap objects from the DM bioset. Per kernel CVSS guidance, such memory corruption is treated as capable of enabling high-impact information disclosure.\nI:H - The double-free/use-after-free can corrupt allocator state or allow overlapping/reused kernel objects, which is defensibly exploitable for arbitrary memory modification or code execution. Per guidance, UAF/double-free memory corruption warrants high integrity impact.\nA:H - Even without full exploitation, the double-free/use-after-free can trigger kernel memory corruption, oops, or panic during I/O completion. Repeated attacker-controlled I/O can repeatedly hit the vulnerable path."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:27:00.162Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8d9ddad561136f7e6a9346767bf97b4d79e38e67"
},
{
"url": "https://git.kernel.org/stable/c/7daf279c674d515fb22a727a7bbc92aeb35c5442"
},
{
"url": "https://git.kernel.org/stable/c/e2e738e8dfbbf83bd2bae0467ec4420cc52da42a"
},
{
"url": "https://git.kernel.org/stable/c/b1c1a2637ebd675aa2d71fee8c70da8791d73850"
},
{
"url": "https://git.kernel.org/stable/c/83d72091804600ead96dc9e9f518ea56cb4942f6"
},
{
"url": "https://git.kernel.org/stable/c/fb8a6c18fb9a6561f7a15b58b272442b77a242dd"
}
],
"title": "dm: clear cloned request bio pointer when last clone bio completes",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43278",
"datePublished": "2026-05-06T11:29:00.193Z",
"dateReserved": "2026-05-01T14:12:55.998Z",
"dateUpdated": "2026-08-05T12:27:00.162Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68197 (GCVE-0-2026-68197)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on
bss_desc->bcn_ht_cap being present, but then dereferences a different
pointer, bss_desc->bcn_ht_oper:
if (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) &&
bss_desc->bcn_ht_cap &&
ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param))
bcn_ht_cap and bcn_ht_oper are populated independently while parsing the
associated AP's beacon in mwifiex_update_bss_desc_with_ie(): an AP that
advertises an HT Capabilities element but no HT Operation element leaves
bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a
peer while associated to such an AP then dereferences the NULL
bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the
driver NULL-checks it first.
Guard on the pointer that is actually dereferenced.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/tdls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e1770f7410b4232a0267924f99751dc9c5ca31af",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "8c2058717fd06f05d421c2d3adf1dff3c3abcda1",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "fba7eb7b248ea0618235f504158b685d752a153a",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "eb42c3c8fd479166c42984728754cd779c71fd60",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "45011e4d9ba3f2182e5df64be65888044fa20771",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "9375a4ea4121625ef27a46b74781cda66a5cc61b",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "cca4398aa305c22016d1714f388e2fa6ea4e5ad4",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "c3d68e294cbb6a4090bb219d3dcaca85a011809b",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/tdls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper\n\nmwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on\nbss_desc-\u003ebcn_ht_cap being present, but then dereferences a different\npointer, bss_desc-\u003ebcn_ht_oper:\n\n\tif (ISSUPP_CHANWIDTH40(priv-\u003eadapter-\u003ehw_dot_11n_dev_cap) \u0026\u0026\n\t bss_desc-\u003ebcn_ht_cap \u0026\u0026\n\t ISALLOWED_CHANWIDTH40(bss_desc-\u003ebcn_ht_oper-\u003eht_param))\n\nbcn_ht_cap and bcn_ht_oper are populated independently while parsing the\nassociated AP\u0027s beacon in mwifiex_update_bss_desc_with_ie(): an AP that\nadvertises an HT Capabilities element but no HT Operation element leaves\nbcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a\npeer while associated to such an AP then dereferences the NULL\nbcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the\ndriver NULL-checks it first.\n\nGuard on the pointer that is actually dereferenced.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:16.085Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e1770f7410b4232a0267924f99751dc9c5ca31af"
},
{
"url": "https://git.kernel.org/stable/c/8c2058717fd06f05d421c2d3adf1dff3c3abcda1"
},
{
"url": "https://git.kernel.org/stable/c/fba7eb7b248ea0618235f504158b685d752a153a"
},
{
"url": "https://git.kernel.org/stable/c/eb42c3c8fd479166c42984728754cd779c71fd60"
},
{
"url": "https://git.kernel.org/stable/c/45011e4d9ba3f2182e5df64be65888044fa20771"
},
{
"url": "https://git.kernel.org/stable/c/9375a4ea4121625ef27a46b74781cda66a5cc61b"
},
{
"url": "https://git.kernel.org/stable/c/cca4398aa305c22016d1714f388e2fa6ea4e5ad4"
},
{
"url": "https://git.kernel.org/stable/c/c3d68e294cbb6a4090bb219d3dcaca85a011809b"
}
],
"title": "wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68197",
"datePublished": "2026-08-10T12:00:15.750Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:16.085Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64217 (GCVE-0-2026-64217)
Vulnerability from cvelistv5
Published
2026-07-24 15:23
Modified
2026-08-05 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix overrun check in netfs_extract_user_iter()
Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills
pages[], then those pages don't get included in the iterator constructed at
the end of the function. If there was an overfill, memory corruption has
already happened.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/netfs/iterator.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "00efe58bbdcc93272d579ca24bfc912563f4a204",
"status": "affected",
"version": "85dd2c8ff368b1446be9febde84afe1d7aec4261",
"versionType": "git"
},
{
"lessThan": "96cc3beb2390ba9f9c128c5733c0ccfe450dd4f9",
"status": "affected",
"version": "85dd2c8ff368b1446be9febde84afe1d7aec4261",
"versionType": "git"
},
{
"lessThan": "afeb32d9bf9aaeea51d0f723a19f14afb73bd94d",
"status": "affected",
"version": "85dd2c8ff368b1446be9febde84afe1d7aec4261",
"versionType": "git"
},
{
"lessThan": "f48b9157f0f611fa436c360648603d5ded719b12",
"status": "affected",
"version": "85dd2c8ff368b1446be9febde84afe1d7aec4261",
"versionType": "git"
},
{
"lessThan": "0ef37eef83fad3542ee06db2940433ae1a92b39d",
"status": "affected",
"version": "85dd2c8ff368b1446be9febde84afe1d7aec4261",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/netfs/iterator.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix overrun check in netfs_extract_user_iter()\n\nFix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills\npages[], then those pages don\u0027t get included in the iterator constructed at\nthe end of the function. If there was an overfill, memory corruption has\nalready happened."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable helper is reached through local direct or unbuffered I/O against CIFS/SMB3, AFS, or 9P files. Remote peers cannot directly control the local user iterator that triggers extraction.\nAC:L - The attacker controls and can repeatedly submit the UBUF or IOVEC layout, and corruption occurs synchronously once the overfill condition is reached. No race, timing window, or victim-controlled state is required.\nPR:L - An ordinary unprivileged process with permission to access a file on an existing affected mount can reach the helper. No capability or administrative privilege is checked on the I/O path.\nUI:N - The attacker directly opens and performs I/O on the accessible file without requiring another user to act. An existing affected mount is a deployment prerequisite, not per-attack victim interaction.\nS:U - The corruption compromises the same host kernel that processes the local I/O. It does not inherently cross a VM, IOMMU, or other distinct security authority.\nC:H - The overfill writes page pointers beyond the allocated kernel buffer and the malformed bvec can subsequently access unpopulated descriptors. Exploitation of this kernel heap corruption can expose arbitrary kernel memory.\nI:H - The bug produces an out-of-bounds kernel heap write and can cause adjacent memory to be interpreted as bvec descriptors. Heap grooming could turn this into arbitrary memory modification or control-flow hijacking.\nA:H - The corruption can cause a kernel oops, panic, or hang, while aborted extraction can also leak pinned pages. An attacker can repeat the triggering I/O to sustain denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:40:05.203Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/00efe58bbdcc93272d579ca24bfc912563f4a204"
},
{
"url": "https://git.kernel.org/stable/c/96cc3beb2390ba9f9c128c5733c0ccfe450dd4f9"
},
{
"url": "https://git.kernel.org/stable/c/afeb32d9bf9aaeea51d0f723a19f14afb73bd94d"
},
{
"url": "https://git.kernel.org/stable/c/f48b9157f0f611fa436c360648603d5ded719b12"
},
{
"url": "https://git.kernel.org/stable/c/0ef37eef83fad3542ee06db2940433ae1a92b39d"
}
],
"title": "netfs: Fix overrun check in netfs_extract_user_iter()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64217",
"datePublished": "2026-07-24T15:23:05.261Z",
"dateReserved": "2026-07-19T15:36:31.770Z",
"dateUpdated": "2026-08-05T12:40:05.203Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68117 (GCVE-0-2026-68117)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
When tipc_sk_create() fails to insert the new socket (tipc_sk_insert()
returns non-zero), its error path frees the sk with sk_free() but leaves
sock->sk pointing at the freed object:
if (tipc_sk_insert(tsk)) {
sk_free(sk);
pr_warn("Socket create failed; port number exhausted\n");
return -EINVAL;
}
This is harmless for plain socket(): the syscall layer clears sock->ops
before releasing, so tipc_release() is never called. It is not harmless
on the accept() path. tipc_accept() creates the pre-allocated child
socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves
new_sock->sk dangling and new_sock->ops non-NULL, and do_accept() then
fput()s the new file, so __sock_release() -> tipc_release() runs
lock_sock(new_sock->sk) on the freed sk -- a use-after-free write of the
sk_lock spinlock.
tipc_release() already guards this exact "failed accept() releases a
pre-allocated child" case with "if (sk == NULL) return 0;", but the
guard is bypassed because tipc_sk_create() left sock->sk non-NULL
(dangling) rather than NULL.
Clear sock->sk on the failed-insert path so the existing tipc_release()
NULL check fires and the use-after-free is avoided.
The tipc_sk_insert() failure is reached when the per-netns socket
rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M
elements) -- i.e. once a netns holds ~2M TIPC sockets every insert
returns -E2BIG.
BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839)
Write of size 8 at addr ffff8880047cdc38 by task init/1
lock_sock_nested (net/core/sock.c:3839)
tipc_release (net/tipc/socket.c:638)
__sock_release (net/socket.c:710)
sock_close (net/socket.c:1501)
__fput (fs/file_table.c:512)
Allocated by task 1:
sk_alloc (net/core/sock.c:2308)
tipc_sk_create (net/tipc/socket.c:487)
tipc_accept (net/tipc/socket.c:2744)
do_accept (net/socket.c:2034)
Freed by task 1:
__sk_destruct (net/core/sock.c:2391)
tipc_sk_create (net/tipc/socket.c:504)
tipc_accept (net/tipc/socket.c:2744)
do_accept (net/socket.c:2034)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: efa78f2ae363428525fb4981bb63c555ee79f3c7 Version: 833ecd0eae76eadf81d6d747bb5bc992d1151867 Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 638fa20b618b2bbcf86da71231624cc82121a036 Version: 7bc9e7f70bc57d8f02ffea2a42094281effb15ef Version: ef488669b2652bde5b6ee5a409a5b048a2a50db4 Version: 4919d82f7041157a421ca9bf39a78551d5ad8a1b Version: 3b2957fc09fe1ac7f07f40dd50dd5f93e3f3a7a2 Version: 5.10.132 ≤ Version: 5.15.56 ≤ Version: 4.9.324 ≤ Version: 4.14.289 ≤ Version: 4.19.253 ≤ Version: 5.4.207 ≤ Version: 5.18.13 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "efebc23e9b29e3e5a9e2127dd066929f7f0d315e",
"status": "affected",
"version": "efa78f2ae363428525fb4981bb63c555ee79f3c7",
"versionType": "git"
},
{
"lessThan": "8d6f26d48e61ef34f1921289401dbf36b10816af",
"status": "affected",
"version": "833ecd0eae76eadf81d6d747bb5bc992d1151867",
"versionType": "git"
},
{
"lessThan": "82f59aa27f33bd014a7d8739371ab5712d15e33b",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "b07d87b31631edb6529e6cdcca790a7489d1250d",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "dd29891ed840f6b8d020b759d0dc4a00b1d6e4ea",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "5f5a41a48dbf9eda57b67ce23e548602cf7195a6",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "f9596b1566616a8be0592dbceccb6344a7c6f6bb",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "ba0533fc163f905fe817cfabdf8ed4058da44800",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"status": "affected",
"version": "638fa20b618b2bbcf86da71231624cc82121a036",
"versionType": "git"
},
{
"status": "affected",
"version": "7bc9e7f70bc57d8f02ffea2a42094281effb15ef",
"versionType": "git"
},
{
"status": "affected",
"version": "ef488669b2652bde5b6ee5a409a5b048a2a50db4",
"versionType": "git"
},
{
"status": "affected",
"version": "4919d82f7041157a421ca9bf39a78551d5ad8a1b",
"versionType": "git"
},
{
"status": "affected",
"version": "3b2957fc09fe1ac7f07f40dd50dd5f93e3f3a7a2",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.132",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.56",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.324",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.289",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.253",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.207",
"versionType": "semver"
},
{
"lessThan": "5.19",
"status": "affected",
"version": "5.18.13",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.132",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.56",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.324",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.289",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.253",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.207",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.18.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: clear sock-\u003esk on the failed-insert path in tipc_sk_create()\n\nWhen tipc_sk_create() fails to insert the new socket (tipc_sk_insert()\nreturns non-zero), its error path frees the sk with sk_free() but leaves\nsock-\u003esk pointing at the freed object:\n\n\tif (tipc_sk_insert(tsk)) {\n\t\tsk_free(sk);\n\t\tpr_warn(\"Socket create failed; port number exhausted\\n\");\n\t\treturn -EINVAL;\n\t}\n\nThis is harmless for plain socket(): the syscall layer clears sock-\u003eops\nbefore releasing, so tipc_release() is never called. It is not harmless\non the accept() path. tipc_accept() creates the pre-allocated child\nsocket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves\nnew_sock-\u003esk dangling and new_sock-\u003eops non-NULL, and do_accept() then\nfput()s the new file, so __sock_release() -\u003e tipc_release() runs\nlock_sock(new_sock-\u003esk) on the freed sk -- a use-after-free write of the\nsk_lock spinlock.\n\ntipc_release() already guards this exact \"failed accept() releases a\npre-allocated child\" case with \"if (sk == NULL) return 0;\", but the\nguard is bypassed because tipc_sk_create() left sock-\u003esk non-NULL\n(dangling) rather than NULL.\n\nClear sock-\u003esk on the failed-insert path so the existing tipc_release()\nNULL check fires and the use-after-free is avoided.\n\nThe tipc_sk_insert() failure is reached when the per-netns socket\nrhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M\nelements) -- i.e. once a netns holds ~2M TIPC sockets every insert\nreturns -E2BIG.\n\n BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839)\n Write of size 8 at addr ffff8880047cdc38 by task init/1\n lock_sock_nested (net/core/sock.c:3839)\n tipc_release (net/tipc/socket.c:638)\n __sock_release (net/socket.c:710)\n sock_close (net/socket.c:1501)\n __fput (fs/file_table.c:512)\n Allocated by task 1:\n sk_alloc (net/core/sock.c:2308)\n tipc_sk_create (net/tipc/socket.c:487)\n tipc_accept (net/tipc/socket.c:2744)\n do_accept (net/socket.c:2034)\n Freed by task 1:\n __sk_destruct (net/core/sock.c:2391)\n tipc_sk_create (net/tipc/socket.c:504)\n tipc_accept (net/tipc/socket.c:2744)\n do_accept (net/socket.c:2034)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit in tipc_accept() when a listening SOCK_STREAM/SOCK_SEQPACKET socket accepts an incoming TIPC connection; peers reach this path over default UDP/Ethernet bearers (e.g. UDP/6118) without local syscall access.\nAC:L - An attacker can deterministically fill the per-netns TIPC socket rhashtable (~2M entries) by opening many sockets or connections, then trigger the failed-insert accept() cleanup path that performs lock_sock() on the freed sk.\nPR:N - No elevated Linux capabilities are required to create AF_TIPC stream/seqpacket sockets or send unauthenticated TIPC SYN traffic to a listening cluster service; only LSM policy may restrict access.\nUI:N - Exploitation needs no end-user action beyond a server\u2019s normal accept() loop processing inbound TIPC connection requests queued by the network stack.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security domain; impact is kernel privilege escalation or crash, not a VM/hypervisor or IOMMU boundary crossing.\nC:H - tipc_release() calls lock_sock() on a freed struct sock, a slab use-after-free that can be groomed for arbitrary kernel memory disclosure via controlled reuse of the freed socket object.\nI:H - The UAF performs an 8-byte write to sk_lock on freed memory during socket teardown, enabling heap corruption and potential arbitrary kernel write or code execution primitives.\nA:H - KASAN reports slab-use-after-free in lock_sock_nested during tipc_release on the failed accept() path, causing kernel oops/panic and denial of service even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:29.277Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/efebc23e9b29e3e5a9e2127dd066929f7f0d315e"
},
{
"url": "https://git.kernel.org/stable/c/8d6f26d48e61ef34f1921289401dbf36b10816af"
},
{
"url": "https://git.kernel.org/stable/c/82f59aa27f33bd014a7d8739371ab5712d15e33b"
},
{
"url": "https://git.kernel.org/stable/c/b07d87b31631edb6529e6cdcca790a7489d1250d"
},
{
"url": "https://git.kernel.org/stable/c/dd29891ed840f6b8d020b759d0dc4a00b1d6e4ea"
},
{
"url": "https://git.kernel.org/stable/c/5f5a41a48dbf9eda57b67ce23e548602cf7195a6"
},
{
"url": "https://git.kernel.org/stable/c/f9596b1566616a8be0592dbceccb6344a7c6f6bb"
},
{
"url": "https://git.kernel.org/stable/c/ba0533fc163f905fe817cfabdf8ed4058da44800"
}
],
"title": "tipc: clear sock-\u003esk on the failed-insert path in tipc_sk_create()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68117",
"datePublished": "2026-08-10T11:58:36.675Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:29.277Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68081 (GCVE-0-2026-68081)
Vulnerability from cvelistv5
Published
2026-08-08 09:17
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
Put all vmcs12 pages if KVM synthesizes a nested VM-Exit due to invalid
guest while emulating VMLAUNCH or VMRESUME. The invalid guest state path
doesn't use nested_vmx_vmexit() as that API is intended to be used if and
only if L2 is active, and the open coded equivalent neglects to put the
vmcs12 pages. Failure to put the vmcs12 pages leaks any pinned pages
(and/or mappings) if L1 retries VMLAUNCH/VMRESUME.
Note, the !from_vmenter scenario doesn't suffer the same problem, as
vmx_get_nested_state_pages() only gets/pins/maps the vmcs12 pages if L2 is
active, i.e. if a "full" VM-Exit is guaranteed before KVM will retry
getting vmcs12 pages.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/vmx/nested.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7996013b85687034d2e820cef94d6404192e3a3d",
"status": "affected",
"version": "96c66e87deeeb3cc78a3b82a1de8e365eec206c1",
"versionType": "git"
},
{
"lessThan": "2c87a087c20632d68920272173b5d7c47f9bcf70",
"status": "affected",
"version": "96c66e87deeeb3cc78a3b82a1de8e365eec206c1",
"versionType": "git"
},
{
"lessThan": "2f2312c422fd2695da772cecb30c69994b795964",
"status": "affected",
"version": "96c66e87deeeb3cc78a3b82a1de8e365eec206c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/vmx/nested.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state\n\nPut all vmcs12 pages if KVM synthesizes a nested VM-Exit due to invalid\nguest while emulating VMLAUNCH or VMRESUME. The invalid guest state path\ndoesn\u0027t use nested_vmx_vmexit() as that API is intended to be used if and\nonly if L2 is active, and the open coded equivalent neglects to put the\nvmcs12 pages. Failure to put the vmcs12 pages leaks any pinned pages\n(and/or mappings) if L1 retries VMLAUNCH/VMRESUME.\n\nNote, the !from_vmenter scenario doesn\u0027t suffer the same problem, as\nvmx_get_nested_state_pages() only gets/pins/maps the vmcs12 pages if L2 is\nactive, i.e. if a \"full\" VM-Exit is guaranteed before KVM will retry\ngetting vmcs12 pages."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:28.608Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7996013b85687034d2e820cef94d6404192e3a3d"
},
{
"url": "https://git.kernel.org/stable/c/2c87a087c20632d68920272173b5d7c47f9bcf70"
},
{
"url": "https://git.kernel.org/stable/c/2f2312c422fd2695da772cecb30c69994b795964"
}
],
"title": "KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68081",
"datePublished": "2026-08-08T09:17:44.795Z",
"dateReserved": "2026-07-30T09:28:09.367Z",
"dateUpdated": "2026-08-17T04:58:28.608Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53163 (GCVE-0-2026-53163)
Vulnerability from cvelistv5
Published
2026-06-25 08:38
Modified
2026-07-24 14:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
syzbot triggered the following splat in remove_waiter() via
FUTEX_CMP_REQUEUE_PI:
KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]
class_raw_spinlock_constructor
remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561
rt_mutex_start_proxy_lock+0x103/0x120
futex_requeue+0x10e4/0x20d0
__x64_sys_futex+0x34f/0x4d0
task_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,
leaving waiter->task nil, where 3bfdc63936dd ("rtmutex: Use waiter::task instead
of current in remove_waiter()") made this fatal.
Furthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter()
upon a successfully grabbing the rtmutex. 1a1fb985f2e2 ("futex: Handle early deadlock
return correctly"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock()
(where 'ret' was only ever 0 or < 0) into the wrapper. Tighten this check to
account for try_to_take_rt_mutex().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f3fa3424bceb128d2be4b3745506b22844b87db7 Version: 838ce5cb5d93c3ab8b27e75bc6ad905a94b752fd Version: d8cce4773c2b23d819baf5abedc62f7b430e8745 Version: 8a1fc8d698ac5e5916e3082a0f74450d71f9611f Version: 6d52dfcb2a5db86e346cf51f8fcf2071b8085166 Version: 3fb7394a837740770f0d6b4b30567e60786a63f2 Version: 88614876370aac8ad1050ad785a4c095ba17ac11 Version: 3bfdc63936dd4773109b7b8c280c0f3b5ae7d349 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/locking/rtmutex.c",
"kernel/locking/rtmutex_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bfbc047ceb42c0e1fac8f3a155d4548a8bbe76b1",
"status": "affected",
"version": "f3fa3424bceb128d2be4b3745506b22844b87db7",
"versionType": "git"
},
{
"lessThan": "4ffacf76a457b7ca8ac05f5df8740b0d8f53574a",
"status": "affected",
"version": "838ce5cb5d93c3ab8b27e75bc6ad905a94b752fd",
"versionType": "git"
},
{
"lessThan": "4afda3a1da02129568a3a2f1898aa13e6763bcba",
"status": "affected",
"version": "d8cce4773c2b23d819baf5abedc62f7b430e8745",
"versionType": "git"
},
{
"lessThan": "6707d7e0b71748cb3cd95bad81dae5fe1b3c8f48",
"status": "affected",
"version": "8a1fc8d698ac5e5916e3082a0f74450d71f9611f",
"versionType": "git"
},
{
"lessThan": "5799f9bd7fee40370b93ab1ddf001cdc7017c14d",
"status": "affected",
"version": "6d52dfcb2a5db86e346cf51f8fcf2071b8085166",
"versionType": "git"
},
{
"lessThan": "a388e3dfaf9538a680de5ed43a8ebb5dd45b6e53",
"status": "affected",
"version": "3fb7394a837740770f0d6b4b30567e60786a63f2",
"versionType": "git"
},
{
"lessThan": "55363fa0a04524d11efeaadee734d2db1756ed27",
"status": "affected",
"version": "88614876370aac8ad1050ad785a4c095ba17ac11",
"versionType": "git"
},
{
"lessThan": "40a25d59e85b3c8709ac2424d44f65610467871e",
"status": "affected",
"version": "3bfdc63936dd4773109b7b8c280c0f3b5ae7d349",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/locking/rtmutex.c",
"kernel/locking/rtmutex_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6.1.177",
"status": "affected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThan": "6.6.144",
"status": "affected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThan": "6.12.95",
"status": "affected",
"version": "6.12.86",
"versionType": "semver"
},
{
"lessThan": "6.18.36",
"status": "affected",
"version": "6.18.27",
"versionType": "semver"
},
{
"lessThan": "7.0.13",
"status": "affected",
"version": "7.0.4",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "6.1.175",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.6.140",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.12.86",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "6.18.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "7.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/rtmutex: Skip remove_waiter() when waiter is not enqueued\n\nsyzbot triggered the following splat in remove_waiter() via\nFUTEX_CMP_REQUEUE_PI:\n\n KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]\n class_raw_spinlock_constructor\n remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561\n rt_mutex_start_proxy_lock+0x103/0x120\n futex_requeue+0x10e4/0x20d0\n __x64_sys_futex+0x34f/0x4d0\n\ntask_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,\nleaving waiter-\u003etask nil, where 3bfdc63936dd (\"rtmutex: Use waiter::task instead\nof current in remove_waiter()\") made this fatal.\n\nFurthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter()\nupon a successfully grabbing the rtmutex. 1a1fb985f2e2 (\"futex: Handle early deadlock\nreturn correctly\"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock()\n(where \u0027ret\u0027 was only ever 0 or \u003c 0) into the wrapper. Tighten this check to\naccount for try_to_take_rt_mutex()."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-24T14:33:48.972Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bfbc047ceb42c0e1fac8f3a155d4548a8bbe76b1"
},
{
"url": "https://git.kernel.org/stable/c/4ffacf76a457b7ca8ac05f5df8740b0d8f53574a"
},
{
"url": "https://git.kernel.org/stable/c/4afda3a1da02129568a3a2f1898aa13e6763bcba"
},
{
"url": "https://git.kernel.org/stable/c/6707d7e0b71748cb3cd95bad81dae5fe1b3c8f48"
},
{
"url": "https://git.kernel.org/stable/c/5799f9bd7fee40370b93ab1ddf001cdc7017c14d"
},
{
"url": "https://git.kernel.org/stable/c/a388e3dfaf9538a680de5ed43a8ebb5dd45b6e53"
},
{
"url": "https://git.kernel.org/stable/c/55363fa0a04524d11efeaadee734d2db1756ed27"
},
{
"url": "https://git.kernel.org/stable/c/40a25d59e85b3c8709ac2424d44f65610467871e"
}
],
"title": "locking/rtmutex: Skip remove_waiter() when waiter is not enqueued",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53163",
"datePublished": "2026-06-25T08:38:44.108Z",
"dateReserved": "2026-06-09T07:44:35.388Z",
"dateUpdated": "2026-07-24T14:33:48.972Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64185 (GCVE-0-2026-64185)
Vulnerability from cvelistv5
Published
2026-07-19 15:41
Modified
2026-07-19 15:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sysfs: don't remove existing directory on update failure
When sysfs_update_group() is called for a named group and create_files()
fails (e.g. -ENOMEM), internal_create_group() calls kernfs_remove(kn) on
the group directory. In the update path, kn was obtained via
kernfs_find_and_get() and refers to a directory that already existed
before this call. Removing it silently destroys a sysfs group that the
caller did not create.
Only remove the directory if we created it ourselves. On update failure
the directory remains as it is left empty by remove_files() inside
create_files(), but can be repopulated by a retry.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c855cf2759d27142f771173d9fd8e7fdf9cf5138 Version: c855cf2759d27142f771173d9fd8e7fdf9cf5138 Version: c855cf2759d27142f771173d9fd8e7fdf9cf5138 Version: c855cf2759d27142f771173d9fd8e7fdf9cf5138 Version: c855cf2759d27142f771173d9fd8e7fdf9cf5138 Version: c855cf2759d27142f771173d9fd8e7fdf9cf5138 Version: c855cf2759d27142f771173d9fd8e7fdf9cf5138 Version: c855cf2759d27142f771173d9fd8e7fdf9cf5138 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/sysfs/group.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c5e125c828b701afaf7493b42a14aa89362ff36d",
"status": "affected",
"version": "c855cf2759d27142f771173d9fd8e7fdf9cf5138",
"versionType": "git"
},
{
"lessThan": "ccadd32cc1263802a5969c9efe0e96225450428c",
"status": "affected",
"version": "c855cf2759d27142f771173d9fd8e7fdf9cf5138",
"versionType": "git"
},
{
"lessThan": "14f2c14ae86c4af17a0a9f8ab46dacf2d5fd1d8a",
"status": "affected",
"version": "c855cf2759d27142f771173d9fd8e7fdf9cf5138",
"versionType": "git"
},
{
"lessThan": "31527d80234caf83dc96ad478645e57df9de4472",
"status": "affected",
"version": "c855cf2759d27142f771173d9fd8e7fdf9cf5138",
"versionType": "git"
},
{
"lessThan": "57b285e0368290aa55f79ba11419b96d0ebdb418",
"status": "affected",
"version": "c855cf2759d27142f771173d9fd8e7fdf9cf5138",
"versionType": "git"
},
{
"lessThan": "48fa96538bd2868034d33429e4565fda384d0736",
"status": "affected",
"version": "c855cf2759d27142f771173d9fd8e7fdf9cf5138",
"versionType": "git"
},
{
"lessThan": "708f6926f61f71e09b5e9fd668b9882ccd46e69f",
"status": "affected",
"version": "c855cf2759d27142f771173d9fd8e7fdf9cf5138",
"versionType": "git"
},
{
"lessThan": "237557b8a81ab948e8332f7c0058e758f081c0a3",
"status": "affected",
"version": "c855cf2759d27142f771173d9fd8e7fdf9cf5138",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/sysfs/group.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsysfs: don\u0027t remove existing directory on update failure\n\nWhen sysfs_update_group() is called for a named group and create_files()\nfails (e.g. -ENOMEM), internal_create_group() calls kernfs_remove(kn) on\nthe group directory. In the update path, kn was obtained via\nkernfs_find_and_get() and refers to a directory that already existed\nbefore this call. Removing it silently destroys a sysfs group that the\ncaller did not create.\n\nOnly remove the directory if we created it ourselves. On update failure\nthe directory remains as it is left empty by remove_files() inside\ncreate_files(), but can be repopulated by a retry."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:41:07.340Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c5e125c828b701afaf7493b42a14aa89362ff36d"
},
{
"url": "https://git.kernel.org/stable/c/ccadd32cc1263802a5969c9efe0e96225450428c"
},
{
"url": "https://git.kernel.org/stable/c/14f2c14ae86c4af17a0a9f8ab46dacf2d5fd1d8a"
},
{
"url": "https://git.kernel.org/stable/c/31527d80234caf83dc96ad478645e57df9de4472"
},
{
"url": "https://git.kernel.org/stable/c/57b285e0368290aa55f79ba11419b96d0ebdb418"
},
{
"url": "https://git.kernel.org/stable/c/48fa96538bd2868034d33429e4565fda384d0736"
},
{
"url": "https://git.kernel.org/stable/c/708f6926f61f71e09b5e9fd668b9882ccd46e69f"
},
{
"url": "https://git.kernel.org/stable/c/237557b8a81ab948e8332f7c0058e758f081c0a3"
}
],
"title": "sysfs: don\u0027t remove existing directory on update failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64185",
"datePublished": "2026-07-19T15:41:07.340Z",
"dateReserved": "2026-07-19T07:54:57.039Z",
"dateUpdated": "2026-07-19T15:41:07.340Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68124 (GCVE-0-2026-68124)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mctp: serial: handle zero-length frames to prevent rx buffer overflow
The MCTP serial receive state machine reads a frame length byte in
mctp_serial_push_header() case 2 and validates it upper-bound-only:
if (c > MCTP_SERIAL_FRAME_MTU) {
dev->rxstate = STATE_ERR;
} else {
dev->rxlen = c;
dev->rxpos = 0;
dev->rxstate = STATE_DATA;
...
}
A length of zero passes this check, so rxlen is set to 0 and the state
machine advances to STATE_DATA. In mctp_serial_push() STATE_DATA, the
incoming byte is stored and rxpos incremented before the terminator is
dev->rxbuf[dev->rxpos] = c;
dev->rxpos++;
dev->rxstate = STATE_DATA;
if (dev->rxpos == dev->rxlen) {
dev->rxpos = 0;
dev->rxstate = STATE_TRAILER;
}
With rxlen == 0 the "rxpos == rxlen" terminator can never fire (rxpos is
already 1 on the first data byte), so subsequent bytes are written past
the end of the fixed 74-byte rxbuf, which is the last member of the
netdev private area. Every following data byte is an attacker-controlled
1-byte out-of-bounds heap write, and the overflow continues until a
frame (0x7e) or escape byte resets the parser -- effectively unbounded.
Reaching this requires CAP_NET_ADMIN to attach the N_MCTP line
discipline and bring the resulting mctpserialN netdev up, after which
the bytes arrive via the tty receive path.
Route a zero-length frame straight to STATE_TRAILER instead of
STATE_DATA. The trailer/framing bytes are still consumed, and the frame
resolves to a zero-length skb that the MCTP core rejects; the parser
never enters STATE_DATA with rxlen == 0, so the out-of-bounds write can
no longer occur.
KASAN, on a frame of 0x7e 0x01 0x00 followed by data bytes (before this
change):
UBSAN: array-index-out-of-bounds in drivers/net/mctp/mctp-serial.c:370
index 74 is out of range for type 'u8 [74]'
BUG: KASAN: slab-out-of-bounds in mctp_serial_tty_receive_buf
Write of size 1 at addr ... by task kworker/u16:0
mctp_serial_tty_receive_buf
tty_ldisc_receive_buf
flush_to_ldisc
Allocated by task 152:
alloc_netdev_mqs
mctp_serial_open
v2: route zero-length frames to STATE_TRAILER instead of STATE_ERR so
the trailer/framing bytes are still consumed (Jeremy Kerr).
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/mctp/mctp-serial.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "64b96ae7912244d55257aa330d9569ee0a8f8d99",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "36dc6d6964a3b90411cc7944cd9b8b6f67b9807b",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "68819427bc07eca7963a9e8be19e5272cc29186c",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "f80ba170d7b3a44e3d244a2c8e06031d61bf3b23",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "06a6b606129c8a25cd457760f5370f3ff01fe05d",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "793b9b729f1e8de57be8c8daf1a9838be96cabed",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/mctp/mctp-serial.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp: serial: handle zero-length frames to prevent rx buffer overflow\n\nThe MCTP serial receive state machine reads a frame length byte in\nmctp_serial_push_header() case 2 and validates it upper-bound-only:\n\n\tif (c \u003e MCTP_SERIAL_FRAME_MTU) {\n\t\tdev-\u003erxstate = STATE_ERR;\n\t} else {\n\t\tdev-\u003erxlen = c;\n\t\tdev-\u003erxpos = 0;\n\t\tdev-\u003erxstate = STATE_DATA;\n\t\t...\n\t}\n\nA length of zero passes this check, so rxlen is set to 0 and the state\nmachine advances to STATE_DATA. In mctp_serial_push() STATE_DATA, the\nincoming byte is stored and rxpos incremented before the terminator is\n\n\tdev-\u003erxbuf[dev-\u003erxpos] = c;\n\tdev-\u003erxpos++;\n\tdev-\u003erxstate = STATE_DATA;\n\tif (dev-\u003erxpos == dev-\u003erxlen) {\n\t\tdev-\u003erxpos = 0;\n\t\tdev-\u003erxstate = STATE_TRAILER;\n\t}\n\nWith rxlen == 0 the \"rxpos == rxlen\" terminator can never fire (rxpos is\nalready 1 on the first data byte), so subsequent bytes are written past\nthe end of the fixed 74-byte rxbuf, which is the last member of the\nnetdev private area. Every following data byte is an attacker-controlled\n1-byte out-of-bounds heap write, and the overflow continues until a\nframe (0x7e) or escape byte resets the parser -- effectively unbounded.\n\nReaching this requires CAP_NET_ADMIN to attach the N_MCTP line\ndiscipline and bring the resulting mctpserialN netdev up, after which\nthe bytes arrive via the tty receive path.\n\nRoute a zero-length frame straight to STATE_TRAILER instead of\nSTATE_DATA. The trailer/framing bytes are still consumed, and the frame\nresolves to a zero-length skb that the MCTP core rejects; the parser\nnever enters STATE_DATA with rxlen == 0, so the out-of-bounds write can\nno longer occur.\n\nKASAN, on a frame of 0x7e 0x01 0x00 followed by data bytes (before this\nchange):\n\n UBSAN: array-index-out-of-bounds in drivers/net/mctp/mctp-serial.c:370\n index 74 is out of range for type \u0027u8 [74]\u0027\n BUG: KASAN: slab-out-of-bounds in mctp_serial_tty_receive_buf\n Write of size 1 at addr ... by task kworker/u16:0\n mctp_serial_tty_receive_buf\n tty_ldisc_receive_buf\n flush_to_ldisc\n Allocated by task 152:\n alloc_netdev_mqs\n mctp_serial_open\n\nv2: route zero-length frames to STATE_TRAILER instead of STATE_ERR so\n the trailer/framing bytes are still consumed (Jeremy Kerr).\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.6,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is triggered in mctp_serial_tty_receive_buf() by crafted DSP0253 serial frames; on BMC/datacenter systems MCTP-over-serial links management controllers on a shared management LAN, letting an adjacent unauthenticated peer inject 0x7e/0x01/0x00 frames without using host syscalls.\nAC:L - Exploitation is deterministic: a zero-length length byte bypasses the upper-bound check, then each following serial byte is a controlled 1-byte heap OOB write until 0x7e/0x7d resets the parser; no races or attacker-uncontrollable memory layout are required.\nPR:N - Triggering the overflow only requires delivering malicious serial bytes to an already-configured, running mctpserial netdev; a remote/adjacent MCTP peer or compromised management controller needs no Linux host credentials, CAP_NET_ADMIN, or root on the victim.\nUI:N - No victim user action is required at exploit time; administrative enablement of MCTP serial is deployment configuration, not end-user interaction under CVSS.\nS:C - Kconfig documents virtio-serial VM interconnect for MCTP serial; a malicious guest sending crafted frames to the host-side mctpserial binding can corrupt host kernel heap memory, crossing the guest/host virtualization security boundary.\nC:H - Each overflow byte is attacker-controlled and the write stream is effectively unbounded past the 74-byte rxbuf (last netdev private field), enabling slab-out-of-bounds corruption that can be leveraged for arbitrary kernel memory disclosure.\nI:H - Sustained attacker-controlled out-of-bounds heap writes can corrupt adjacent kmalloc objects, function pointers, and netdev state, providing a standard path to arbitrary kernel write and privilege-escalating code execution.\nA:H - KASAN/UBSAN report slab-out-of-bounds and array-index-out-of-bounds in mctp_serial_tty_receive_buf via flush_to_ldisc; continued overflow reliably causes kernel oops/panic or hang during tty receive processing."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:36.851Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/64b96ae7912244d55257aa330d9569ee0a8f8d99"
},
{
"url": "https://git.kernel.org/stable/c/36dc6d6964a3b90411cc7944cd9b8b6f67b9807b"
},
{
"url": "https://git.kernel.org/stable/c/68819427bc07eca7963a9e8be19e5272cc29186c"
},
{
"url": "https://git.kernel.org/stable/c/f80ba170d7b3a44e3d244a2c8e06031d61bf3b23"
},
{
"url": "https://git.kernel.org/stable/c/06a6b606129c8a25cd457760f5370f3ff01fe05d"
},
{
"url": "https://git.kernel.org/stable/c/793b9b729f1e8de57be8c8daf1a9838be96cabed"
}
],
"title": "mctp: serial: handle zero-length frames to prevent rx buffer overflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68124",
"datePublished": "2026-08-10T11:58:44.997Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:36.851Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64470 (GCVE-0-2026-64470)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btusb: fix use-after-free on marvell probe failure
Make sure to stop any TX URBs submitted during Marvell OOB wakeup
configuration on later probe failures to avoid use-after-free in the
completion callback.
This issue was reported by Sashiko while reviewing a fix for a wakeup
source leak in the btusb probe errors paths.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a4ccc9e33d2f01532bcceb621ea06bbf4db6efac Version: a4ccc9e33d2f01532bcceb621ea06bbf4db6efac Version: a4ccc9e33d2f01532bcceb621ea06bbf4db6efac Version: a4ccc9e33d2f01532bcceb621ea06bbf4db6efac Version: a4ccc9e33d2f01532bcceb621ea06bbf4db6efac Version: a4ccc9e33d2f01532bcceb621ea06bbf4db6efac Version: a4ccc9e33d2f01532bcceb621ea06bbf4db6efac Version: a4ccc9e33d2f01532bcceb621ea06bbf4db6efac |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1edd524de5cc8143ece9c42c466346983dc5b5ed",
"status": "affected",
"version": "a4ccc9e33d2f01532bcceb621ea06bbf4db6efac",
"versionType": "git"
},
{
"lessThan": "0ccb1cb0a464dab78284c34196cd3e8e18bab4c4",
"status": "affected",
"version": "a4ccc9e33d2f01532bcceb621ea06bbf4db6efac",
"versionType": "git"
},
{
"lessThan": "631de465aba7f8ae46478bf5f598111412e8eff8",
"status": "affected",
"version": "a4ccc9e33d2f01532bcceb621ea06bbf4db6efac",
"versionType": "git"
},
{
"lessThan": "6e1b10df890f4663cb38af9fc1c93d36747b75af",
"status": "affected",
"version": "a4ccc9e33d2f01532bcceb621ea06bbf4db6efac",
"versionType": "git"
},
{
"lessThan": "92c736866244340497a8a65afe2ac25354c2bf5e",
"status": "affected",
"version": "a4ccc9e33d2f01532bcceb621ea06bbf4db6efac",
"versionType": "git"
},
{
"lessThan": "a7e941a395711791c7e98d9870c6562c2c9e9ef2",
"status": "affected",
"version": "a4ccc9e33d2f01532bcceb621ea06bbf4db6efac",
"versionType": "git"
},
{
"lessThan": "838c917a2f16eefe68def800ebf48a2af591149a",
"status": "affected",
"version": "a4ccc9e33d2f01532bcceb621ea06bbf4db6efac",
"versionType": "git"
},
{
"lessThan": "c5b600a3c05b1a7a110d558df935a8fc8a471c79",
"status": "affected",
"version": "a4ccc9e33d2f01532bcceb621ea06bbf4db6efac",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: fix use-after-free on marvell probe failure\n\nMake sure to stop any TX URBs submitted during Marvell OOB wakeup\nconfiguration on later probe failures to avoid use-after-free in the\ncompletion callback.\n\nThis issue was reported by Sashiko while reviewing a fix for a wakeup\nsource leak in the btusb probe errors paths."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:16.023Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1edd524de5cc8143ece9c42c466346983dc5b5ed"
},
{
"url": "https://git.kernel.org/stable/c/0ccb1cb0a464dab78284c34196cd3e8e18bab4c4"
},
{
"url": "https://git.kernel.org/stable/c/631de465aba7f8ae46478bf5f598111412e8eff8"
},
{
"url": "https://git.kernel.org/stable/c/6e1b10df890f4663cb38af9fc1c93d36747b75af"
},
{
"url": "https://git.kernel.org/stable/c/92c736866244340497a8a65afe2ac25354c2bf5e"
},
{
"url": "https://git.kernel.org/stable/c/a7e941a395711791c7e98d9870c6562c2c9e9ef2"
},
{
"url": "https://git.kernel.org/stable/c/838c917a2f16eefe68def800ebf48a2af591149a"
},
{
"url": "https://git.kernel.org/stable/c/c5b600a3c05b1a7a110d558df935a8fc8a471c79"
}
],
"title": "Bluetooth: btusb: fix use-after-free on marvell probe failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64470",
"datePublished": "2026-07-25T08:51:34.673Z",
"dateReserved": "2026-07-19T15:36:31.790Z",
"dateUpdated": "2026-08-17T04:56:16.023Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64603 (GCVE-0-2026-64603)
Vulnerability from cvelistv5
Published
2026-08-06 07:13
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: intel-hid: Protect ACPI notify handler against recursion
Since commit e2ffcda16290 ("ACPI: OSL: Allow Notify () handlers to run on
all CPUs") ACPI notify handlers like the intel-hid notify_handler() may
run on multiple CPU cores racing with themselves.
On convertibles and detachables (matched by DMI chassis-type 31 and 32 in
dmi_auto_add_switch[]) the SW_TABLET_MODE input device is registered
lazily from notify_handler() on the first tablet-mode event, via
intel_hid_switches_setup(). When two such events race on different CPUs
both can pass the !priv->switches check and register the priv->switches
input device twice, resulting in a duplicate sysfs entry and a subsequent
NULL pointer dereference.
This is the same class of bug fixed by commit e075c3b13a0a ("platform/x86:
intel-vbtn: Protect ACPI notify handler against recursion") for the
sibling intel-vbtn driver.
Protect intel-hid notify_handler() from racing with itself with a mutex
to fix this.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/platform/x86/intel/hid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a6402808e552e44e9c26a9fe8395ac11703d5800",
"status": "affected",
"version": "e2ffcda1629012a2c1a3706432bc45fdc899a584",
"versionType": "git"
},
{
"lessThan": "86df6499dfd232fbc1c82c0d6eb9322ca67b8cd0",
"status": "affected",
"version": "e2ffcda1629012a2c1a3706432bc45fdc899a584",
"versionType": "git"
},
{
"lessThan": "eace3b3e729d5ba11794d69acfafb58a7950217c",
"status": "affected",
"version": "e2ffcda1629012a2c1a3706432bc45fdc899a584",
"versionType": "git"
},
{
"lessThan": "c085d82613d5618814b84406c8b2d64f1bc305e7",
"status": "affected",
"version": "e2ffcda1629012a2c1a3706432bc45fdc899a584",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/platform/x86/intel/hid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: intel-hid: Protect ACPI notify handler against recursion\n\nSince commit e2ffcda16290 (\"ACPI: OSL: Allow Notify () handlers to run on\nall CPUs\") ACPI notify handlers like the intel-hid notify_handler() may\nrun on multiple CPU cores racing with themselves.\n\nOn convertibles and detachables (matched by DMI chassis-type 31 and 32 in\ndmi_auto_add_switch[]) the SW_TABLET_MODE input device is registered\nlazily from notify_handler() on the first tablet-mode event, via\nintel_hid_switches_setup(). When two such events race on different CPUs\nboth can pass the !priv-\u003eswitches check and register the priv-\u003eswitches\ninput device twice, resulting in a duplicate sysfs entry and a subsequent\nNULL pointer dereference.\n\nThis is the same class of bug fixed by commit e075c3b13a0a (\"platform/x86:\nintel-vbtn: Protect ACPI notify handler against recursion\") for the\nsibling intel-vbtn driver.\n\nProtect intel-hid notify_handler() from racing with itself with a mutex\nto fix this."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:26.397Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a6402808e552e44e9c26a9fe8395ac11703d5800"
},
{
"url": "https://git.kernel.org/stable/c/86df6499dfd232fbc1c82c0d6eb9322ca67b8cd0"
},
{
"url": "https://git.kernel.org/stable/c/eace3b3e729d5ba11794d69acfafb58a7950217c"
},
{
"url": "https://git.kernel.org/stable/c/c085d82613d5618814b84406c8b2d64f1bc305e7"
}
],
"title": "platform/x86: intel-hid: Protect ACPI notify handler against recursion",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64603",
"datePublished": "2026-08-06T07:13:55.114Z",
"dateReserved": "2026-07-19T15:36:31.799Z",
"dateUpdated": "2026-08-17T04:58:26.397Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74296 (GCVE-0-2026-74296)
Vulnerability from cvelistv5
Published
2026-08-15 05:58
Modified
2026-08-17 05:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
Free the UAR index returned by the hardware.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0 Version: 4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0 Version: 4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0 Version: 4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0 Version: 4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0 Version: 4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/mlx5/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "80f1f49f53a42733e60c90e0ec545e647969214d",
"status": "affected",
"version": "4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0",
"versionType": "git"
},
{
"lessThan": "aabfc845838ef453f1d22d7665596f9cc48be7dd",
"status": "affected",
"version": "4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0",
"versionType": "git"
},
{
"lessThan": "6f83de384ca582fa87b4c2b0d03bd1ed3bf9a2ee",
"status": "affected",
"version": "4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0",
"versionType": "git"
},
{
"lessThan": "d3ff718c0c7153e2641e6a09507bace14fc5c402",
"status": "affected",
"version": "4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0",
"versionType": "git"
},
{
"lessThan": "ef369446f62903ea079e8a7954b5bf8bb8300fe3",
"status": "affected",
"version": "4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0",
"versionType": "git"
},
{
"lessThan": "449ae7927152e46acbe5f19f97eafdae6d3a96b1",
"status": "affected",
"version": "4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/mlx5/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.16"
},
{
"lessThan": "4.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Release the HW\u2011provided UAR index rather than the SW one\n\nFree the UAR index returned by the hardware."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local mmap(2) on an opened mlx5 uverbs file descriptor (/dev/infiniband/uverbs*); the bug is in uar_mmap() error cleanup and is not reachable via remote RDMA/network packet handling.\nAC:L - An attacker who can open uverbs and issue MLX5_IB_MMAP_ALLOC_WC can reliably reach the faulty cleanup by forcing rdma_user_mmap_io()/io_remap_pfn_range() to fail (e.g., memory or VMA map pressure), and controls all syscall parameters for the race-free trigger.\nPR:L - Any unprivileged local user with access to the mlx5 RDMA character device (default 0666 uverbs nodes on shared HPC/cloud compute nodes with ConnectX NICs) can alloc a context and mmap; no real-root or CAP_SYS_ADMIN capability is required.\nUI:N - Exploitation is fully attacker-driven through uverbs open, alloc_ucontext, and mmap syscalls; no victim interaction such as mounting filesystems or opening files is needed.\nS:U - Impact is confined to kernel/driver and RDMA device resource integrity on the host; it does not cross a VM-hypervisor or IOMMU security boundary into a different authority.\nC:H - Deallocating the wrong hardware UAR index frees another context\u0027s live UAR while the attacker-allocated UAR leaks, creating a cross-context UAR use-after-free that can expose other users\u0027 MMIO doorbell/register mappings and device state.\nI:H - UAR pages provide userspace MMIO write access to mlx5 doorbells and control registers; corrupting or reassigning UAR ownership enables arbitrary device register/DMA manipulation and is exploitable for privilege escalation beyond simple data tampering.\nA:H - Freeing an in-use hardware UAR from another context can cause kernel oops/panic, NIC hangs, or repeated crashes when victims continue doorbell/MMIO access through stale mappings."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:45:34.579Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/80f1f49f53a42733e60c90e0ec545e647969214d"
},
{
"url": "https://git.kernel.org/stable/c/aabfc845838ef453f1d22d7665596f9cc48be7dd"
},
{
"url": "https://git.kernel.org/stable/c/6f83de384ca582fa87b4c2b0d03bd1ed3bf9a2ee"
},
{
"url": "https://git.kernel.org/stable/c/d3ff718c0c7153e2641e6a09507bace14fc5c402"
},
{
"url": "https://git.kernel.org/stable/c/ef369446f62903ea079e8a7954b5bf8bb8300fe3"
},
{
"url": "https://git.kernel.org/stable/c/449ae7927152e46acbe5f19f97eafdae6d3a96b1"
}
],
"title": "RDMA/mlx5: Release the HW\u2011provided UAR index rather than the SW one",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74296",
"datePublished": "2026-08-15T05:58:00.758Z",
"dateReserved": "2026-08-15T05:44:03.882Z",
"dateUpdated": "2026-08-17T05:45:34.579Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64597 (GCVE-0-2026-64597)
Vulnerability from cvelistv5
Published
2026-08-06 07:13
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_close() replay
A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_close_init() fails before the next send, cleanup
retains the previous buffer type and frees that response again.
Reset response bookkeeping before each attempt to prevent the stale free.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 433042a91f9373241307725b52de573933ffedbf Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 6.6.32 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "037511726228aaf165c7067ff2bfc88eaecdf1f3",
"status": "affected",
"version": "433042a91f9373241307725b52de573933ffedbf",
"versionType": "git"
},
{
"lessThan": "0aa97edf7c347c0f54e7e60c4740574b8120c66a",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "d15d83125007f673aec4323e1bbbaaffbe87ea13",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "b18ed621dbfceecea5539848cddcb9272c9a61e1",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "f96e1cdcb63ed3321142ff2fcdf784e32cda8fee",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.32",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double-free in SMB2_close() replay\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_close_init() fails before the next send, cleanup\nretains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious or compromised SMB server triggers the double-free via crafted SMB2 CLOSE responses over the network, returning replayable NTSTATUS values that map to -EAGAIN/-ECONNABORTED while leaving a response buffer for the client to free.\nAC:L - The attacking server controls both sides of the sequence by returning a replayable CLOSE status with a response buffer, then dropping or forcing reconnect so SMB2_close_init fails before the next send, and can repeat until the stale free occurs.\nPR:N - The attacking SMB endpoint needs no account or privileges on the victim client; once an SMB session and handle exist, the server alone drives the vulnerable CLOSE replay path.\nUI:N - On an already mounted or automounted share, background paths such as cached-directory close and cancelled-close work, as well as routine service file closes, can invoke SMB2_close without interactive user action at exploit time.\nS:U - The mempool double-free corrupts kernel memory within the same host kernel security authority and does not inherently cross a VM, IOMMU, or sandbox boundary.\nC:H - Double-free of a CIFS small/large response buffer can create overlapping live allocations and use-after-free reads, enabling disclosure of arbitrary kernel memory.\nI:H - Reallocation of the freed mempool object with attacker-controlled network data can corrupt live kernel objects or allocator metadata, enabling arbitrary writes and control-flow hijacking.\nA:H - The duplicate free can immediately trigger allocator BUG diagnostics, heap corruption, oops, or panic, and the server can retrigger the path repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:19.742Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/037511726228aaf165c7067ff2bfc88eaecdf1f3"
},
{
"url": "https://git.kernel.org/stable/c/0aa97edf7c347c0f54e7e60c4740574b8120c66a"
},
{
"url": "https://git.kernel.org/stable/c/d15d83125007f673aec4323e1bbbaaffbe87ea13"
},
{
"url": "https://git.kernel.org/stable/c/b18ed621dbfceecea5539848cddcb9272c9a61e1"
},
{
"url": "https://git.kernel.org/stable/c/f96e1cdcb63ed3321142ff2fcdf784e32cda8fee"
}
],
"title": "smb: client: fix double-free in SMB2_close() replay",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64597",
"datePublished": "2026-08-06T07:13:52.117Z",
"dateReserved": "2026-07-19T15:36:31.799Z",
"dateUpdated": "2026-08-17T04:58:19.742Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72500 (GCVE-0-2026-72500)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
Free the toggle page only after firmware teardown completes so that
an NQ interrupt arriving during bnxt_qplib_destroy_srq() won't write
the toggle values to an already-freed page. Move free_page() after
bnxt_qplib_destroy_srq().
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/ib_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "104a7ff382a58a83cae018925e3574c784e8274c",
"status": "affected",
"version": "181028a0d84cdcc7ac86d05cc49eaa416ce85c8b",
"versionType": "git"
},
{
"lessThan": "0adcd67f3d6f84835be682da0153f57f5c2f8036",
"status": "affected",
"version": "181028a0d84cdcc7ac86d05cc49eaa416ce85c8b",
"versionType": "git"
},
{
"lessThan": "131e2918b9b0529687e67e2e58047304027f095a",
"status": "affected",
"version": "181028a0d84cdcc7ac86d05cc49eaa416ce85c8b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/ib_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Free SRQ toggle page after firmware teardown\n\nFree the toggle page only after firmware teardown completes so that\nan NQ interrupt arriving during bnxt_qplib_destroy_srq() won\u0027t write\nthe toggle values to an already-freed page. Move free_page() after\nbnxt_qplib_destroy_srq()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is triggered by destroying a user SRQ through the RDMA uverbs ioctl on /dev/infiniband/uverbs*; although RoCE peers can generate SRQ/NQ events, the premature free_page() only occurs in this local destroy path, not from remote packet handling alone.\nAC:L - An attacker controls SRQ teardown timing via ibv_destroy_srq and can reliably create the race by keeping QPs/posted receives active and/or soliciting SRQ threshold events (including from a cooperating RoCE peer) while destroy_srq runs through bnxt_qplib_destroy_srq firmware teardown.\nPR:L - Exploitation requires only local RDMA verbs access to create/destroy a user SRQ on a Gen P7 bnxt_re device; uverbs char devices are created world-accessible (0666) and RDMA is commonly granted to unprivileged HPC/cloud/Kubernetes workload users rather than real root.\nUI:N - No victim interaction is required beyond the attacker (or compromised local workload) invoking SRQ destroy on resources it already controls; remote peers may assist timing but do not need the victim to click, mount, or open files.\nS:C - On Kubernetes/HPC hosts that expose bnxt_re to containers/pods, triggering this host-kernel UAF from an unprivileged RDMA-enabled workload can corrupt host memory and enable container-to-host sandbox escape beyond the workload security boundary.\nC:H - This is a kernel write-after-free: an NQ interrupt writes a toggle value into a page already returned to the buddy allocator, enabling corruption of subsequently reallocated kernel objects and classic UAF-based information disclosure primitives.\nI:H - The interrupt path performs a controlled 4-byte write to freed kernel memory during destroy_srq, providing a heap corruption primitive that can be developed into arbitrary kernel write or code execution rather than being limited to a benign crash.\nA:H - Writing to a freed page during interrupt handling can oops/panic the kernel immediately, and repeated SRQ create/destroy cycles let an attacker reliably induce host-level denial of service on RDMA-enabled systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:45:01.023Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/104a7ff382a58a83cae018925e3574c784e8274c"
},
{
"url": "https://git.kernel.org/stable/c/0adcd67f3d6f84835be682da0153f57f5c2f8036"
},
{
"url": "https://git.kernel.org/stable/c/131e2918b9b0529687e67e2e58047304027f095a"
}
],
"title": "RDMA/bnxt_re: Free SRQ toggle page after firmware teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72500",
"datePublished": "2026-08-15T05:57:32.341Z",
"dateReserved": "2026-08-09T03:40:39.937Z",
"dateUpdated": "2026-08-17T05:45:01.023Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63969 (GCVE-0-2026-63969)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-07-19 14:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix possible infinite loop in rt6_fill_node()
Sashiko reported this issue [1]. Apply the same fix as
commit f8d8ce1b515a ("ipv6: fix possible infinite loop in fib6_info_uses_dev()").
Writers holding tb6_lock can list_del_rcu(&rt->fib6_siblings)
without waiting for RCU readers; rt->fib6_siblings.next then still
points into the old ring and this softirq-side walker never reaches
&rt->fib6_siblings, causing a CPU stall. fib6_del_route() always
WRITE_ONCE()s rt->fib6_nsiblings to 0 before list_del_rcu(), so an
inside-loop check is a reliable detach signal.
[1] https://sashiko.dev/#/patchset/20260526020227.4857-1-jiayuan.chen%40linux.dev
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0ec61c9f3583b76aebdbb271f5c0d3fcccd48b2 Version: 52da02521ede55fb86546c3fffd9377b3261b91f Version: 34a949e7a0869dfa31a40416d2a56973fae1807b Version: d9ccb18f83ea2bb654289b6ecf014fd267cc988b Version: d9ccb18f83ea2bb654289b6ecf014fd267cc988b Version: d9ccb18f83ea2bb654289b6ecf014fd267cc988b Version: 11edcd026012ac18acee0f1514db3ed1b160fc6f Version: 6.1.128 ≤ Version: 6.6.75 ≤ Version: 6.12.2 ≤ Version: 6.11.11 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b014a63d2f2c2c767762b548381882dfb1655529",
"status": "affected",
"version": "d0ec61c9f3583b76aebdbb271f5c0d3fcccd48b2",
"versionType": "git"
},
{
"lessThan": "279853aec9f58d5cd723e6e5617c1c3337b30383",
"status": "affected",
"version": "52da02521ede55fb86546c3fffd9377b3261b91f",
"versionType": "git"
},
{
"lessThan": "c65b1f60237daac7c56c2652e064cc566a45dc81",
"status": "affected",
"version": "34a949e7a0869dfa31a40416d2a56973fae1807b",
"versionType": "git"
},
{
"lessThan": "dc36a04621dcc2447dae428709207810b6c06e14",
"status": "affected",
"version": "d9ccb18f83ea2bb654289b6ecf014fd267cc988b",
"versionType": "git"
},
{
"lessThan": "5e40de719ee76b8d96e2556ce36dbd3bd07bf37d",
"status": "affected",
"version": "d9ccb18f83ea2bb654289b6ecf014fd267cc988b",
"versionType": "git"
},
{
"lessThan": "9f72412bcf60144f252b0d6205106abf14344abc",
"status": "affected",
"version": "d9ccb18f83ea2bb654289b6ecf014fd267cc988b",
"versionType": "git"
},
{
"status": "affected",
"version": "11edcd026012ac18acee0f1514db3ed1b160fc6f",
"versionType": "git"
},
{
"lessThan": "6.1.176",
"status": "affected",
"version": "6.1.128",
"versionType": "semver"
},
{
"lessThan": "6.6.143",
"status": "affected",
"version": "6.6.75",
"versionType": "semver"
},
{
"lessThan": "6.12.93",
"status": "affected",
"version": "6.12.2",
"versionType": "semver"
},
{
"lessThan": "6.12",
"status": "affected",
"version": "6.11.11",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "6.1.128",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "6.6.75",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "6.12.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.11.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible infinite loop in rt6_fill_node()\n\nSashiko reported this issue [1]. Apply the same fix as\ncommit f8d8ce1b515a (\"ipv6: fix possible infinite loop in fib6_info_uses_dev()\").\n\nWriters holding tb6_lock can list_del_rcu(\u0026rt-\u003efib6_siblings)\nwithout waiting for RCU readers; rt-\u003efib6_siblings.next then still\npoints into the old ring and this softirq-side walker never reaches\n\u0026rt-\u003efib6_siblings, causing a CPU stall. fib6_del_route() always\nWRITE_ONCE()s rt-\u003efib6_nsiblings to 0 before list_del_rcu(), so an\ninside-loop check is a reliable detach signal.\n\n[1] https://sashiko.dev/#/patchset/20260526020227.4857-1-jiayuan.chen%40linux.dev"
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:55:56.330Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b014a63d2f2c2c767762b548381882dfb1655529"
},
{
"url": "https://git.kernel.org/stable/c/279853aec9f58d5cd723e6e5617c1c3337b30383"
},
{
"url": "https://git.kernel.org/stable/c/c65b1f60237daac7c56c2652e064cc566a45dc81"
},
{
"url": "https://git.kernel.org/stable/c/dc36a04621dcc2447dae428709207810b6c06e14"
},
{
"url": "https://git.kernel.org/stable/c/5e40de719ee76b8d96e2556ce36dbd3bd07bf37d"
},
{
"url": "https://git.kernel.org/stable/c/9f72412bcf60144f252b0d6205106abf14344abc"
}
],
"title": "ipv6: fix possible infinite loop in rt6_fill_node()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63969",
"datePublished": "2026-07-19T14:55:56.330Z",
"dateReserved": "2026-07-19T07:54:57.024Z",
"dateUpdated": "2026-07-19T14:55:56.330Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64421 (GCVE-0-2026-64421)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: nxp: imx8-isi: Fix use-after-free on remove
KASAN reports a slab-use-after-free in __media_entity_remove_link()
during rmmod of imx8_isi:
BUG: KASAN: slab-use-after-free in __media_entity_remove_link+0x608/0x650
Read of size 2 at addr ffff0000d47cb02a by task rmmod/724
Call trace:
__media_entity_remove_link+0x608/0x650
__media_entity_remove_links+0x78/0x144
__media_device_unregister_entity+0x150/0x280
media_device_unregister_entity+0x48/0x68
v4l2_device_unregister_subdev+0x158/0x300
v4l2_async_unbind_subdev_one+0x22c/0x358
v4l2_async_nf_unbind_all_subdevs+0xfc/0x1c0
v4l2_async_nf_unregister+0x5c/0x14c
mxc_isi_remove+0x124/0x2a0 [imx8_isi]
Allocated by task 249:
__kmalloc_noprof+0x27c/0x690
mxc_isi_crossbar_init+0x22c/0x560 [imx8_isi]
Freed by task 724:
kfree+0x1e4/0x5b0
mxc_isi_crossbar_cleanup+0x34/0x80 [imx8_isi]
mxc_isi_remove+0x11c/0x2a0 [imx8_isi]
The problem is that mxc_isi_remove() calls mxc_isi_crossbar_cleanup()
before mxc_isi_v4l2_cleanup(). The crossbar cleanup frees the media
entity pads, but the subsequent v4l2 cleanup still tries to remove
media links that reference those pads.
Fix this by calling mxc_isi_v4l2_cleanup() before
mxc_isi_crossbar_cleanup() to ensure all media entities are properly
unregistered while the pads are still valid.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nxp/imx8-isi/imx8-isi-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d22fb719654bfde6f682c9f14629f5f9534175b7",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "ba2aa5d325270cd965c44458c5ff5ab555e6af51",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "ef382a6baf0a95cf199fdf6bba2fd08e58b0a249",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "c12a5b2261351cd3b03921ce4720332ff5184b50",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "b670bf89824ede5d07d20bb9bfbafb754846081d",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nxp/imx8-isi/imx8-isi-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: nxp: imx8-isi: Fix use-after-free on remove\n\nKASAN reports a slab-use-after-free in __media_entity_remove_link()\nduring rmmod of imx8_isi:\n\n BUG: KASAN: slab-use-after-free in __media_entity_remove_link+0x608/0x650\n Read of size 2 at addr ffff0000d47cb02a by task rmmod/724\n\n Call trace:\n __media_entity_remove_link+0x608/0x650\n __media_entity_remove_links+0x78/0x144\n __media_device_unregister_entity+0x150/0x280\n media_device_unregister_entity+0x48/0x68\n v4l2_device_unregister_subdev+0x158/0x300\n v4l2_async_unbind_subdev_one+0x22c/0x358\n v4l2_async_nf_unbind_all_subdevs+0xfc/0x1c0\n v4l2_async_nf_unregister+0x5c/0x14c\n mxc_isi_remove+0x124/0x2a0 [imx8_isi]\n\n Allocated by task 249:\n __kmalloc_noprof+0x27c/0x690\n mxc_isi_crossbar_init+0x22c/0x560 [imx8_isi]\n\n Freed by task 724:\n kfree+0x1e4/0x5b0\n mxc_isi_crossbar_cleanup+0x34/0x80 [imx8_isi]\n mxc_isi_remove+0x11c/0x2a0 [imx8_isi]\n\nThe problem is that mxc_isi_remove() calls mxc_isi_crossbar_cleanup()\nbefore mxc_isi_v4l2_cleanup(). The crossbar cleanup frees the media\nentity pads, but the subsequent v4l2 cleanup still tries to remove\nmedia links that reference those pads.\n\nFix this by calling mxc_isi_v4l2_cleanup() before\nmxc_isi_crossbar_cleanup() to ensure all media entities are properly\nunregistered while the pads are still valid."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:21.058Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d22fb719654bfde6f682c9f14629f5f9534175b7"
},
{
"url": "https://git.kernel.org/stable/c/ba2aa5d325270cd965c44458c5ff5ab555e6af51"
},
{
"url": "https://git.kernel.org/stable/c/ef382a6baf0a95cf199fdf6bba2fd08e58b0a249"
},
{
"url": "https://git.kernel.org/stable/c/c12a5b2261351cd3b03921ce4720332ff5184b50"
},
{
"url": "https://git.kernel.org/stable/c/b670bf89824ede5d07d20bb9bfbafb754846081d"
}
],
"title": "media: nxp: imx8-isi: Fix use-after-free on remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64421",
"datePublished": "2026-07-25T08:50:59.926Z",
"dateReserved": "2026-07-19T15:36:31.786Z",
"dateUpdated": "2026-08-17T04:55:21.058Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74567 (GCVE-0-2026-74567)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
keys: fix out-of-bounds read in keyring_get_key_chunk()
For description-level chunks keyring_get_key_chunk() advances the read
pointer by level * sizeof(long) past the inline prefix but only
bounds-checks the prefix, so a long enough key description is read past
its kmemdup(desc, desc_len + 1) allocation. Compute the full byte
offset and bounds-check the description against it before reading.
The walk only reaches a description-level chunk when two keys collide
through the hash, x, type and domain_tag chunks, so this is reached from
an unprivileged add_key(2) with a crafted pair of same-type keys whose
index hashes collide; KASAN reports a slab-out-of-bounds read.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/keys/keyring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4c0c26f751e50d3027eacc4d7d0fabc31f1d7e6b",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "79916f40d4ab1b4ae694d8c024fd179454bfe46e",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "e5b01998cef8d7f613200230ccaadebe5de9135c",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "d1933e03e8c74a018550c31a393b79c4d95bff40",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "3a744838453fb9309ce5a5526d3252e211d60152",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "e9417d21a22ad2ec398e78fcf084b717ce92cf2f",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "8dba33c1e779d0fb9a2acb31e354cf0fc0229111",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "63918731f9ae25b5deb022f118e941e6dddfcef4",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/keys/keyring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: fix out-of-bounds read in keyring_get_key_chunk()\n\nFor description-level chunks keyring_get_key_chunk() advances the read\npointer by level * sizeof(long) past the inline prefix but only\nbounds-checks the prefix, so a long enough key description is read past\nits kmemdup(desc, desc_len + 1) allocation. Compute the full byte\noffset and bounds-check the description against it before reading.\n\nThe walk only reaches a description-level chunk when two keys collide\nthrough the hash, x, type and domain_tag chunks, so this is reached from\nan unprivileged add_key(2) with a crafted pair of same-type keys whose\nindex hashes collide; KASAN reports a slab-out-of-bounds read."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only through local key-management syscalls (add_key, keyctl link/search) that walk the keyring assoc_array in security/keys/keyring.c; the keys subsystem has no network-facing handler or remote packet path.\nAC:L - An attacker fully controls both key descriptions and can offline-compute a same-type pair whose index collides through hash, x, type and domain_tag yet differs later, deterministically forcing description-level chunks without races or uncontrollable layout.\nPR:L - The fix commit and add_key path confirm any unprivileged local user can add crafted keys to their own session/user keyring (lookup_user_key with KEY_NEED_WRITE); no real-root capability or init-namespace privilege is required.\nUI:N - Exploitation is self-contained: the attacker issues add_key twice with crafted colliding descriptions into a writable keyring they own; no action by another user or administrator is required.\nS:U - The out-of-bounds slab read and any disclosed data remain within the host kernel\u0027s security authority; this is standard local kernel memory access, not a VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - keyring_get_key_chunk() reads up to a word past the kmemdup(desc,desc_len+1) allocation when the offset includes level*sizeof(long), yielding an adjacent-heap read primitive that can disclose kernel pointers and other sensitive slab contents.\nI:N - This is a read-only out-of-bounds access with no kernel memory write, type confusion, or control-flow hijack; the bug discloses data but does not directly modify kernel or victim integrity.\nA:H - KASAN reports slab-out-of-bounds on trigger, and reading beyond the description allocation can fault at slab/page boundaries; the add_key insertion path is trivially repeatable for denial-of-service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:39:09.169Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4c0c26f751e50d3027eacc4d7d0fabc31f1d7e6b"
},
{
"url": "https://git.kernel.org/stable/c/79916f40d4ab1b4ae694d8c024fd179454bfe46e"
},
{
"url": "https://git.kernel.org/stable/c/e5b01998cef8d7f613200230ccaadebe5de9135c"
},
{
"url": "https://git.kernel.org/stable/c/d1933e03e8c74a018550c31a393b79c4d95bff40"
},
{
"url": "https://git.kernel.org/stable/c/3a744838453fb9309ce5a5526d3252e211d60152"
},
{
"url": "https://git.kernel.org/stable/c/e9417d21a22ad2ec398e78fcf084b717ce92cf2f"
},
{
"url": "https://git.kernel.org/stable/c/8dba33c1e779d0fb9a2acb31e354cf0fc0229111"
},
{
"url": "https://git.kernel.org/stable/c/63918731f9ae25b5deb022f118e941e6dddfcef4"
}
],
"title": "keys: fix out-of-bounds read in keyring_get_key_chunk()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74567",
"datePublished": "2026-08-15T12:28:08.240Z",
"dateReserved": "2026-08-15T05:44:03.917Z",
"dateUpdated": "2026-08-19T16:39:09.169Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53337 (GCVE-0-2026-53337)
Vulnerability from cvelistv5
Published
2026-07-01 13:32
Modified
2026-07-01 13:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: bonding: fix NULL pointer dereference in bond_do_ioctl()
In bond_do_ioctl(), slave_dev is obtained via __dev_get_by_name() which
can return NULL if the requested interface name does not exist. However,
the subsequent slave_dbg() call is placed before the NULL check:
slave_dev = __dev_get_by_name(net, ifr->ifr_slave);
slave_dbg(bond_dev, slave_dev, "slave_dev=%p:\n", slave_dev); //here
if (!slave_dev)
return -ENODEV;
The slave_dbg() macro expands to netdev_dbg(bond_dev, "(slave %s): " fmt,
(slave_dev)->name, ...) which unconditionally dereferences slave_dev->name
before the NULL check is performed. This results in a NULL pointer
dereference kernel oops when a user calls bonding ioctl (e.g.
SIOCBONDENSLAVE, SIOCBONDRELEASE, etc.) with a non-existent slave
interface name.
This is reachable from userspace via the bonding ioctl interface with
CAP_NET_ADMIN capability, making it a potential local denial-of-service
vector.
Fix by moving the slave_dbg() call after the NULL check.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e2a7420df2e01370b40e4cf7b85ab9a885c6d755 Version: e2a7420df2e01370b40e4cf7b85ab9a885c6d755 Version: e2a7420df2e01370b40e4cf7b85ab9a885c6d755 Version: e2a7420df2e01370b40e4cf7b85ab9a885c6d755 Version: e2a7420df2e01370b40e4cf7b85ab9a885c6d755 Version: e2a7420df2e01370b40e4cf7b85ab9a885c6d755 Version: e2a7420df2e01370b40e4cf7b85ab9a885c6d755 Version: e2a7420df2e01370b40e4cf7b85ab9a885c6d755 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1b7558c85493467b2ea20738866b822db6442034",
"status": "affected",
"version": "e2a7420df2e01370b40e4cf7b85ab9a885c6d755",
"versionType": "git"
},
{
"lessThan": "b02b2e3e876c18733b868a29064abd11cdbf8feb",
"status": "affected",
"version": "e2a7420df2e01370b40e4cf7b85ab9a885c6d755",
"versionType": "git"
},
{
"lessThan": "66693957bacd1c9dae6188a7312d6be69a221f2d",
"status": "affected",
"version": "e2a7420df2e01370b40e4cf7b85ab9a885c6d755",
"versionType": "git"
},
{
"lessThan": "a629418d463fb50d132a1aa063b0105857311e5f",
"status": "affected",
"version": "e2a7420df2e01370b40e4cf7b85ab9a885c6d755",
"versionType": "git"
},
{
"lessThan": "c2cfe290fdb1c32a4f4eb2b8ca3f363b305d21ba",
"status": "affected",
"version": "e2a7420df2e01370b40e4cf7b85ab9a885c6d755",
"versionType": "git"
},
{
"lessThan": "bcb8fad90f27300add583a8371db504b766d95c7",
"status": "affected",
"version": "e2a7420df2e01370b40e4cf7b85ab9a885c6d755",
"versionType": "git"
},
{
"lessThan": "b0878106ddc486375084145848ff255dedfff46a",
"status": "affected",
"version": "e2a7420df2e01370b40e4cf7b85ab9a885c6d755",
"versionType": "git"
},
{
"lessThan": "a764b0e8317a863006e05732e1aefe821b9d8c2d",
"status": "affected",
"version": "e2a7420df2e01370b40e4cf7b85ab9a885c6d755",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bonding: fix NULL pointer dereference in bond_do_ioctl()\n\nIn bond_do_ioctl(), slave_dev is obtained via __dev_get_by_name() which\ncan return NULL if the requested interface name does not exist. However,\nthe subsequent slave_dbg() call is placed before the NULL check:\n\n slave_dev = __dev_get_by_name(net, ifr-\u003eifr_slave);\n slave_dbg(bond_dev, slave_dev, \"slave_dev=%p:\\n\", slave_dev); //here\n if (!slave_dev)\n return -ENODEV;\n\nThe slave_dbg() macro expands to netdev_dbg(bond_dev, \"(slave %s): \" fmt,\n(slave_dev)-\u003ename, ...) which unconditionally dereferences slave_dev-\u003ename\nbefore the NULL check is performed. This results in a NULL pointer\ndereference kernel oops when a user calls bonding ioctl (e.g.\nSIOCBONDENSLAVE, SIOCBONDRELEASE, etc.) with a non-existent slave\ninterface name.\n\nThis is reachable from userspace via the bonding ioctl interface with\nCAP_NET_ADMIN capability, making it a potential local denial-of-service\nvector.\n\nFix by moving the slave_dbg() call after the NULL check."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-01T13:32:19.046Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1b7558c85493467b2ea20738866b822db6442034"
},
{
"url": "https://git.kernel.org/stable/c/b02b2e3e876c18733b868a29064abd11cdbf8feb"
},
{
"url": "https://git.kernel.org/stable/c/66693957bacd1c9dae6188a7312d6be69a221f2d"
},
{
"url": "https://git.kernel.org/stable/c/a629418d463fb50d132a1aa063b0105857311e5f"
},
{
"url": "https://git.kernel.org/stable/c/c2cfe290fdb1c32a4f4eb2b8ca3f363b305d21ba"
},
{
"url": "https://git.kernel.org/stable/c/bcb8fad90f27300add583a8371db504b766d95c7"
},
{
"url": "https://git.kernel.org/stable/c/b0878106ddc486375084145848ff255dedfff46a"
},
{
"url": "https://git.kernel.org/stable/c/a764b0e8317a863006e05732e1aefe821b9d8c2d"
}
],
"title": "net: bonding: fix NULL pointer dereference in bond_do_ioctl()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53337",
"datePublished": "2026-07-01T13:32:19.046Z",
"dateReserved": "2026-06-09T07:44:35.399Z",
"dateUpdated": "2026-07-01T13:32:19.046Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64323 (GCVE-0-2026-64323)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
udf: validate VAT header length against the VAT inode size
udf_load_vat() takes the virtual partition's start offset straight from
the on-disk VAT 2.0 header without checking it against the VAT inode
size:
map->s_type_specific.s_virtual.s_start_offset =
le16_to_cpu(vat20->lengthHeader);
map->s_type_specific.s_virtual.s_num_entries =
(sbi->s_vat_inode->i_size -
map->s_type_specific.s_virtual.s_start_offset) >> 2;
lengthHeader is a fully attacker-controlled 16-bit value. If it exceeds
the VAT inode size, the s_num_entries subtraction underflows to a huge
count, which defeats the "block > s_num_entries" bound in
udf_get_pblock_virt15(); and on the ICB-inline path that function reads
((__le32 *)(iinfo->i_data + s_start_offset))[block]
so a large s_start_offset indexes past the inode's in-ICB data. Mounting
a crafted UDF image with a virtual (VAT) partition then triggers an
out-of-bounds read.
Reject a VAT whose header length does not leave room for at least one
entry within the VAT inode.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fa5e08156335d0687c85b4e724db9448fb166601 Version: fa5e08156335d0687c85b4e724db9448fb166601 Version: fa5e08156335d0687c85b4e724db9448fb166601 Version: fa5e08156335d0687c85b4e724db9448fb166601 Version: fa5e08156335d0687c85b4e724db9448fb166601 Version: fa5e08156335d0687c85b4e724db9448fb166601 Version: fa5e08156335d0687c85b4e724db9448fb166601 Version: fa5e08156335d0687c85b4e724db9448fb166601 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/udf/super.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934",
"status": "affected",
"version": "fa5e08156335d0687c85b4e724db9448fb166601",
"versionType": "git"
},
{
"lessThan": "883962731420ec271ed8c1cd76524f4b17faa982",
"status": "affected",
"version": "fa5e08156335d0687c85b4e724db9448fb166601",
"versionType": "git"
},
{
"lessThan": "2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63",
"status": "affected",
"version": "fa5e08156335d0687c85b4e724db9448fb166601",
"versionType": "git"
},
{
"lessThan": "bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb",
"status": "affected",
"version": "fa5e08156335d0687c85b4e724db9448fb166601",
"versionType": "git"
},
{
"lessThan": "55287a3555ff0515b3aff181d2c08c0462a41709",
"status": "affected",
"version": "fa5e08156335d0687c85b4e724db9448fb166601",
"versionType": "git"
},
{
"lessThan": "e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad",
"status": "affected",
"version": "fa5e08156335d0687c85b4e724db9448fb166601",
"versionType": "git"
},
{
"lessThan": "74580fdf022909e184223cacc364feb826982d96",
"status": "affected",
"version": "fa5e08156335d0687c85b4e724db9448fb166601",
"versionType": "git"
},
{
"lessThan": "d8202786b3d75125c84ebc4de6d946f92fde0ee8",
"status": "affected",
"version": "fa5e08156335d0687c85b4e724db9448fb166601",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/udf/super.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.26"
},
{
"lessThan": "2.6.26",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.26",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: validate VAT header length against the VAT inode size\n\nudf_load_vat() takes the virtual partition\u0027s start offset straight from\nthe on-disk VAT 2.0 header without checking it against the VAT inode\nsize:\n\n\tmap-\u003es_type_specific.s_virtual.s_start_offset =\n\t\tle16_to_cpu(vat20-\u003elengthHeader);\n\tmap-\u003es_type_specific.s_virtual.s_num_entries =\n\t\t(sbi-\u003es_vat_inode-\u003ei_size -\n\t\t\tmap-\u003es_type_specific.s_virtual.s_start_offset) \u003e\u003e 2;\n\nlengthHeader is a fully attacker-controlled 16-bit value. If it exceeds\nthe VAT inode size, the s_num_entries subtraction underflows to a huge\ncount, which defeats the \"block \u003e s_num_entries\" bound in\nudf_get_pblock_virt15(); and on the ICB-inline path that function reads\n\n\t((__le32 *)(iinfo-\u003ei_data + s_start_offset))[block]\n\nso a large s_start_offset indexes past the inode\u0027s in-ICB data. Mounting\na crafted UDF image with a virtual (VAT) partition then triggers an\nout-of-bounds read.\n\nReject a VAT whose header length does not leave room for at least one\nentry within the VAT inode."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable parser is reached by mounting a crafted local UDF image or removable volume; no network-facing protocol reaches it.\nAC:L - The VAT type, inline allocation, header length, and virtual block index are attacker-controlled on disk, with no race or uncontrollable condition required.\nPR:L - Although direct mounting requires init-namespace CAP_SYS_ADMIN, common UDisks/polkit deployments let an active unprivileged local user create a loop device and request the mount.\nUI:N - In the low-privilege UDisks scenario, the attacker can initiate the mount and trigger VAT resolution without another user\u0027s action.\nS:U - The vulnerable UDF parser and affected kernel resources remain within the host kernel\u0027s security authority.\nC:H - The underflow permits repeatable 32-bit reads at attacker-selected offsets potentially many gigabytes beyond the VAT buffer, enabling disclosure of kernel memory.\nI:N - The primitive only reads a mapping value, and virtual UDF partitions are forcibly read-only; no kernel-memory write primitive results.\nA:H - A sufficiently large attacker-selected index can fault in kernel context and cause an oops or panic, enabling repeatable system-wide denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:25.005Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934"
},
{
"url": "https://git.kernel.org/stable/c/883962731420ec271ed8c1cd76524f4b17faa982"
},
{
"url": "https://git.kernel.org/stable/c/2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63"
},
{
"url": "https://git.kernel.org/stable/c/bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb"
},
{
"url": "https://git.kernel.org/stable/c/55287a3555ff0515b3aff181d2c08c0462a41709"
},
{
"url": "https://git.kernel.org/stable/c/e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad"
},
{
"url": "https://git.kernel.org/stable/c/74580fdf022909e184223cacc364feb826982d96"
},
{
"url": "https://git.kernel.org/stable/c/d8202786b3d75125c84ebc4de6d946f92fde0ee8"
}
],
"title": "udf: validate VAT header length against the VAT inode size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64323",
"datePublished": "2026-07-25T08:49:51.097Z",
"dateReserved": "2026-07-19T15:36:31.780Z",
"dateUpdated": "2026-08-17T04:53:25.005Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64188 (GCVE-0-2026-64188)
Vulnerability from cvelistv5
Published
2026-07-20 16:27
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
rmnet_dellink() removes the endpoint from the hash table with
hlist_del_init_rcu() and then immediately frees it with kfree(). However,
RCU readers on the receive path (rmnet_rx_handler ->
__rmnet_map_ingress_handler) may still hold a reference to the endpoint and
dereference ep->egress_dev after the memory has been freed. The endpoint is
a kmalloc-32 object, and the stale read at offset 8 corresponds to the
egress_dev pointer.
BUG: unable to handle page fault for address: ffffffffde942eef
Oops: 0002 [#1] SMP NOPTI
CPU: 1 UID: 0 PID: 137 Comm: poc_write Not tainted 7.0.0+ #4 PREEMPTLAZY
RIP: 0010:rmnet_vnd_rx_fixup (rmnet_vnd.c:27)
Call Trace:
<TASK>
__rmnet_map_ingress_handler (rmnet_handlers.c:48 rmnet_handlers.c:101)
rmnet_rx_handler (rmnet_handlers.c:129 rmnet_handlers.c:235)
__netif_receive_skb_core.constprop.0 (net/core/dev.c:6096)
__netif_receive_skb_one_core (net/core/dev.c:6208)
netif_receive_skb (net/core/dev.c:6467)
tun_get_user (drivers/net/tun.c:1955)
tun_chr_write_iter (drivers/net/tun.c:2003)
vfs_write (fs/read_write.c:688)
ksys_write (fs/read_write.c:740)
</TASK>
Add an rcu_head field to struct rmnet_endpoint and replace kfree() with
kfree_rcu() so the endpoint memory remains valid through the RCU grace
period. Also remove the rmnet_vnd_dellink() call and inline only the
nr_rmnet_devs decrement, since rmnet_vnd_dellink() would set
ep->egress_dev to NULL during the grace period, creating a data race
with lockless readers.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ceed73a2cf4aff2921802aa3d21d45280677547d Version: ceed73a2cf4aff2921802aa3d21d45280677547d Version: ceed73a2cf4aff2921802aa3d21d45280677547d Version: ceed73a2cf4aff2921802aa3d21d45280677547d Version: ceed73a2cf4aff2921802aa3d21d45280677547d Version: ceed73a2cf4aff2921802aa3d21d45280677547d Version: ceed73a2cf4aff2921802aa3d21d45280677547d Version: ceed73a2cf4aff2921802aa3d21d45280677547d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/qualcomm/rmnet/rmnet_config.c",
"drivers/net/ethernet/qualcomm/rmnet/rmnet_config.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c4e676c3505c5058922dc1a6f1ded795f6758135",
"status": "affected",
"version": "ceed73a2cf4aff2921802aa3d21d45280677547d",
"versionType": "git"
},
{
"lessThan": "9918698cf3aee4032e12bb42fd5a951dc465339b",
"status": "affected",
"version": "ceed73a2cf4aff2921802aa3d21d45280677547d",
"versionType": "git"
},
{
"lessThan": "310b93246bfec7d4452507e0c15477377ed9f025",
"status": "affected",
"version": "ceed73a2cf4aff2921802aa3d21d45280677547d",
"versionType": "git"
},
{
"lessThan": "1078ae8175777e80c9637996fb4a46c55f0ce576",
"status": "affected",
"version": "ceed73a2cf4aff2921802aa3d21d45280677547d",
"versionType": "git"
},
{
"lessThan": "41e06fcc5df0774d212e70c5b503fc769492bce3",
"status": "affected",
"version": "ceed73a2cf4aff2921802aa3d21d45280677547d",
"versionType": "git"
},
{
"lessThan": "8b17adf6d4fb6bf61fa4c3f58366a7c082799a71",
"status": "affected",
"version": "ceed73a2cf4aff2921802aa3d21d45280677547d",
"versionType": "git"
},
{
"lessThan": "f193e38cb257d033060b63f1cfd94af076b3a2ab",
"status": "affected",
"version": "ceed73a2cf4aff2921802aa3d21d45280677547d",
"versionType": "git"
},
{
"lessThan": "d00c953a8f69921f484b629801766da68f27f658",
"status": "affected",
"version": "ceed73a2cf4aff2921802aa3d21d45280677547d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/qualcomm/rmnet/rmnet_config.c",
"drivers/net/ethernet/qualcomm/rmnet/rmnet_config.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.260",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.37",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.260",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.37",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.14",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()\n\nrmnet_dellink() removes the endpoint from the hash table with\nhlist_del_init_rcu() and then immediately frees it with kfree(). However,\nRCU readers on the receive path (rmnet_rx_handler -\u003e\n__rmnet_map_ingress_handler) may still hold a reference to the endpoint and\ndereference ep-\u003eegress_dev after the memory has been freed. The endpoint is\na kmalloc-32 object, and the stale read at offset 8 corresponds to the\negress_dev pointer.\n\n BUG: unable to handle page fault for address: ffffffffde942eef\n Oops: 0002 [#1] SMP NOPTI\n CPU: 1 UID: 0 PID: 137 Comm: poc_write Not tainted 7.0.0+ #4 PREEMPTLAZY\n RIP: 0010:rmnet_vnd_rx_fixup (rmnet_vnd.c:27)\n Call Trace:\n \u003cTASK\u003e\n __rmnet_map_ingress_handler (rmnet_handlers.c:48 rmnet_handlers.c:101)\n rmnet_rx_handler (rmnet_handlers.c:129 rmnet_handlers.c:235)\n __netif_receive_skb_core.constprop.0 (net/core/dev.c:6096)\n __netif_receive_skb_one_core (net/core/dev.c:6208)\n netif_receive_skb (net/core/dev.c:6467)\n tun_get_user (drivers/net/tun.c:1955)\n tun_chr_write_iter (drivers/net/tun.c:2003)\n vfs_write (fs/read_write.c:688)\n ksys_write (fs/read_write.c:740)\n \u003c/TASK\u003e\n\nAdd an rcu_head field to struct rmnet_endpoint and replace kfree() with\nkfree_rcu() so the endpoint memory remains valid through the RCU grace\nperiod. Also remove the rmnet_vnd_dellink() call and inline only the\nnr_rmnet_devs decrement, since rmnet_vnd_dellink() would set\nep-\u003eegress_dev to NULL during the grace period, creating a data race\nwith lockless readers."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The complete exploit path is local: attacker-written frames enter through TUN while RTM_DELLINK over NETLINK_ROUTE invokes rmnet_dellink(); remote traffic alone cannot perform the required endpoint deletion.\nAC:L - The attacker controls both sides of the race by concurrently injecting crafted MAP frames and deleting or recreating the RMNET link, allowing repeated attempts without an uncontrollable condition.\nPR:L - Deletion requires CAP_NET_ADMIN in the route socket\u0027s network namespace, which an unprivileged user can obtain through a private user and network namespace to create TUN and RMNET devices.\nUI:N - No separate victim action is required because the attacker directly performs link setup, packet injection, and deletion.\nS:U - Exploitation compromises the kernel within the same security authority and does not cross a VM, IOMMU, or comparable scope boundary.\nC:H - The freed kmalloc-32 endpoint can be reclaimed with attacker-influenced contents, making the stale egress_dev pointer usable for forged-object dereferences and access to sensitive kernel memory.\nI:H - The corrupted egress_dev pointer reaches rmnet_vnd_rx_fixup, where derived per-CPU statistics pointers are written, providing a plausible path to arbitrary memory corruption and control-flow hijacking.\nA:H - The demonstrated race causes a page fault and kernel Oops in rmnet_vnd_rx_fixup, and it can be triggered repeatedly to crash the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:57.703Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c4e676c3505c5058922dc1a6f1ded795f6758135"
},
{
"url": "https://git.kernel.org/stable/c/9918698cf3aee4032e12bb42fd5a951dc465339b"
},
{
"url": "https://git.kernel.org/stable/c/310b93246bfec7d4452507e0c15477377ed9f025"
},
{
"url": "https://git.kernel.org/stable/c/1078ae8175777e80c9637996fb4a46c55f0ce576"
},
{
"url": "https://git.kernel.org/stable/c/41e06fcc5df0774d212e70c5b503fc769492bce3"
},
{
"url": "https://git.kernel.org/stable/c/8b17adf6d4fb6bf61fa4c3f58366a7c082799a71"
},
{
"url": "https://git.kernel.org/stable/c/f193e38cb257d033060b63f1cfd94af076b3a2ab"
},
{
"url": "https://git.kernel.org/stable/c/d00c953a8f69921f484b629801766da68f27f658"
}
],
"title": "net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64188",
"datePublished": "2026-07-20T16:27:47.216Z",
"dateReserved": "2026-07-19T07:54:57.040Z",
"dateUpdated": "2026-08-05T12:39:57.703Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68389 (GCVE-0-2026-68389)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_qca: Clear memdump state on invalid dump size
qca_controller_memdump() allocates qca->qca_memdump before processing
the first dump packet. For a sequence-zero packet it then disables IBS,
marks memdump collection active, and reads the advertised dump size.
If the controller reports a zero dump size, the error path frees the
local qca_memdump object and returns without clearing qca->qca_memdump
or undoing the collection state. A later memdump work item initializes
its local pointer from qca->qca_memdump and skips allocation when that
pointer is non-NULL, so it can operate on freed memory. The stale
collection and IBS-disabled flags can also leave waiters or later
transmit handling blocked behind an aborted dump.
Clear the saved pointer and memdump state before returning from the
invalid-size path, matching the cleanup used when hci_devcd_init() fails.
A static analysis checker reported the stale memdump state, and manual
source review confirmed the invalid-size failure path.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/hci_qca.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5a3945e8dea6c9a8ec9e981169ac9487e1d6ad6a",
"status": "affected",
"version": "06d3fdfcdf5cefb06f2024b9d3dad356779399cf",
"versionType": "git"
},
{
"lessThan": "069258d5111eed9ac9586bee42d03d38e2975715",
"status": "affected",
"version": "06d3fdfcdf5cefb06f2024b9d3dad356779399cf",
"versionType": "git"
},
{
"lessThan": "cefb44c367b2b52e50f97bc8526d39df9bcf5e60",
"status": "affected",
"version": "06d3fdfcdf5cefb06f2024b9d3dad356779399cf",
"versionType": "git"
},
{
"lessThan": "2363a757694752426fc47f3eadde15cf5f791fa5",
"status": "affected",
"version": "06d3fdfcdf5cefb06f2024b9d3dad356779399cf",
"versionType": "git"
},
{
"lessThan": "bf587a10c33e5571a299742e45bc18960b9912e7",
"status": "affected",
"version": "06d3fdfcdf5cefb06f2024b9d3dad356779399cf",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/hci_qca.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_qca: Clear memdump state on invalid dump size\n\nqca_controller_memdump() allocates qca-\u003eqca_memdump before processing\nthe first dump packet. For a sequence-zero packet it then disables IBS,\nmarks memdump collection active, and reads the advertised dump size.\n\nIf the controller reports a zero dump size, the error path frees the\nlocal qca_memdump object and returns without clearing qca-\u003eqca_memdump\nor undoing the collection state. A later memdump work item initializes\nits local pointer from qca-\u003eqca_memdump and skips allocation when that\npointer is non-NULL, so it can operate on freed memory. The stale\ncollection and IBS-disabled flags can also leave waiters or later\ntransmit handling blocked behind an aborted dump.\n\nClear the saved pointer and memdump state before returning from the\ninvalid-size path, matching the cleanup used when hci_devcd_init() fails.\n\nA static analysis checker reported the stale memdump state, and manual\nsource review confirmed the invalid-size failure path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable memdump packets arrive as QCA vendor HCI events (QCA_SSR_DUMP_HANDLE) emitted by the Bluetooth controller after a firmware crash/SSR, a state a nearby attacker induces or controls by attacking QCA controller firmware over the radio link, matching the CNA convention of scoring controller-event-driven Bluetooth driver bugs as Adjacent.\nAC:L - An attacker controlling the controller-to-host HCI stream deterministically triggers the flaw by sending a sequence-0 memdump packet with dump_size 0 followed by any further memdump packet; there is no race and no attacker-uncontrollable timing or memory-layout precondition.\nPR:N - No host credentials or authentication are needed: the memdump event is consumed unconditionally by qca_recv_event() on the driver receive path with no pairing, bonding, or capability check before qca_controller_memdump() runs.\nUI:N - SSR/memdump handling is fully automatic \u2014 qca_controller_memdump_event() queues the work item on receipt, so no local user has to open, mount, or confirm anything.\nS:U - The dangling pointer, use-after-free writes, and double free all occur in the host kernel\u0027s own heap and authority; no VM escape, IOMMU bypass, or sandbox boundary is crossed.\nC:H - The stale qca-\u003eqca_memdump gives a use-after-free on a kmalloc-16 object that an attacker can reclaim with another kernel allocation, and the freed fields (received_dump/ram_dump_size) then drive hci_devcd_append() length arithmetic, yielding attacker-influenced kernel memory disclosure per UAF exploitation.\nI:H - The reused freed object receives attacker-supplied 32-bit values (ram_dump_size straight from the packet, plus current_seq_no/received_dump) and is later kfree()d again, providing a controlled heap write and double-free primitive usable for arbitrary write and control-flow hijack.\nA:H - Beyond the use-after-free/double-free oops (KASAN slab-use-after-free), the uncleared QCA_MEMDUMP_COLLECTION and QCA_IBS_DISABLED flags leave wait_on_bit_timeout() waiters and the IBS transmit path stalled behind an aborted dump, persistently wedging the Bluetooth device."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:36.839Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5a3945e8dea6c9a8ec9e981169ac9487e1d6ad6a"
},
{
"url": "https://git.kernel.org/stable/c/069258d5111eed9ac9586bee42d03d38e2975715"
},
{
"url": "https://git.kernel.org/stable/c/cefb44c367b2b52e50f97bc8526d39df9bcf5e60"
},
{
"url": "https://git.kernel.org/stable/c/2363a757694752426fc47f3eadde15cf5f791fa5"
},
{
"url": "https://git.kernel.org/stable/c/bf587a10c33e5571a299742e45bc18960b9912e7"
}
],
"title": "Bluetooth: hci_qca: Clear memdump state on invalid dump size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68389",
"datePublished": "2026-08-10T12:04:08.306Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-17T05:04:36.839Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53091 (GCVE-0-2026-53091)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-09-10 12:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: pull headers in qdisc_pkt_len_segs_init()
Most ndo_start_xmit() methods expects headers of gso packets
to be already in skb->head.
net/core/tso.c users are particularly at risk, because tso_build_hdr()
does a memcpy(hdr, skb->data, hdr_len);
qdisc_pkt_len_segs_init() already does a dissection of gso packets.
Use pskb_may_pull() instead of skb_header_pointer() to make
sure drivers do not have to reimplement this.
Some malicious packets could be fed, detect them so that we can
drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.
References
Impacted products
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10.2"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:6.12.0-211.53.1.el10_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:8::nfv"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.162.1.rt7.503.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.162.1.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unknown",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-06-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel\u0027s handling of Generic Segmentation Offload (GSO) packet headers. This vulnerability occurs when the `qdisc_pkt_len_segs_init()` function does not properly pull headers into the expected memory location, which can lead to incorrect processing by network drivers. A remote attacker could exploit this by sending specially crafted malicious packets, potentially causing a denial of service (DoS) or other unexpected system behavior."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Important"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-131",
"description": "Incorrect Calculation of Buffer Size",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T12:04:47.741Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-53091"
},
{
"name": "RHBZ#2492270",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492270"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53091.json"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:65334"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:66325"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:66324"
}
],
"solutions": [
{
"lang": "en",
"value": "RHSA-2026:65334: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10)"
},
{
"lang": "en",
"value": "RHSA-2026:66325: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:66324: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8)"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: net: pull headers in qdisc_pkt_len_segs_init()",
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/dropreason-core.h",
"net/core/dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a",
"status": "affected",
"version": "e876f208af18b074f800656e4d1b99da75b2135f",
"versionType": "git"
},
{
"lessThan": "7fb4c19670110f052c04e1ec1d2b953b9f4f57e4",
"status": "affected",
"version": "e876f208af18b074f800656e4d1b99da75b2135f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/dropreason-core.h",
"net/core/dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: pull headers in qdisc_pkt_len_segs_init()\n\nMost ndo_start_xmit() methods expects headers of gso packets\nto be already in skb-\u003ehead.\n\nnet/core/tso.c users are particularly at risk, because tso_build_hdr()\ndoes a memcpy(hdr, skb-\u003edata, hdr_len);\n\nqdisc_pkt_len_segs_init() already does a dissection of gso packets.\n\nUse pskb_may_pull() instead of skb_header_pointer() to make\nsure drivers do not have to reimplement this.\n\nSome malicious packets could be fed, detect them so that we can\ndrop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached through local transmit paths such as AF_PACKET, TUN/TAP, or guest virtio/tap injection where an attacker can supply GSO metadata. Ordinary remote packets do not carry this malformed skb/GSO state on the wire.\nAC:L - No race or external timing condition is required. The attacker controls the GSO header metadata and packet layout needed to make qdisc accept a header that later TX code expects to be linear.\nPR:L - AF_PACKET requires CAP_NET_RAW in the target network namespace, and TUN/TAP style paths require CAP_NET_ADMIN or access to an existing tap/tun file descriptor. These are reachable as low privilege in user-namespace or guest/tap deployments rather than requiring init-namespace root in the highest reasonable scenario.\nUI:N - No victim user action is needed once the attacker can inject the crafted local/guest packet. The transmit path processes the skb automatically.\nS:C - In virtualization deployments, a guest-controlled GSO packet can be processed by the host kernel tap/vhost transmit path and affect host kernel memory or availability. That crosses the guest-to-host security boundary.\nC:H - TSO helpers copy header bytes directly from skb-\u003edata, so a header accepted via skb_header_pointer() but not pulled into skb-\u003ehead can leak adjacent kernel memory into transmitted segment headers. This is an out-of-bounds kernel read and is scored High.\nI:N - The investigated primitive is incorrect header linearity causing out-of-bounds reads and crashes, not a demonstrated attacker-controlled write or protected data modification. I did not find a reliable integrity-impacting write primitive from this fix.\nA:H - Malformed GSO packets can trigger kernel faults or invalid driver/TSO behavior during transmit, including panics reported for this issue. Repeated local injection can therefore cause high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:33:18.759Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a"
},
{
"url": "https://git.kernel.org/stable/c/7fb4c19670110f052c04e1ec1d2b953b9f4f57e4"
}
],
"title": "net: pull headers in qdisc_pkt_len_segs_init()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53091",
"datePublished": "2026-06-24T16:30:30.290Z",
"dateReserved": "2026-06-09T07:44:35.384Z",
"dateUpdated": "2026-09-10T12:04:47.741Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68250 (GCVE-0-2026-68250)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit ae658afc7f47f6147371ec42cc6b1a793dfdb5af)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "55995d8da162acbadfd5fb0f08675e8e1c0bdb63",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "f718334e4aa3768f6e68d235945eca2987c6687c",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "6d27435df2a4ca4945f4313344a5da5bc6b54075",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "01dfea84df919cfbec4064151d327480ae5c120d",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "b665c1845488c6cd869da3d31b5978015977f898",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "09da54636bac146c1a3c461c4e7eb08d355bb86e",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "2051bbbfbd44ff51637b01a5a3dbee6630f90d57",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "b9dd618a635d39fbb211454b6e8837b2a7f10fb0",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit ae658afc7f47f6147371ec42cc6b1a793dfdb5af)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:21.015Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/55995d8da162acbadfd5fb0f08675e8e1c0bdb63"
},
{
"url": "https://git.kernel.org/stable/c/f718334e4aa3768f6e68d235945eca2987c6687c"
},
{
"url": "https://git.kernel.org/stable/c/6d27435df2a4ca4945f4313344a5da5bc6b54075"
},
{
"url": "https://git.kernel.org/stable/c/01dfea84df919cfbec4064151d327480ae5c120d"
},
{
"url": "https://git.kernel.org/stable/c/b665c1845488c6cd869da3d31b5978015977f898"
},
{
"url": "https://git.kernel.org/stable/c/09da54636bac146c1a3c461c4e7eb08d355bb86e"
},
{
"url": "https://git.kernel.org/stable/c/2051bbbfbd44ff51637b01a5a3dbee6630f90d57"
},
{
"url": "https://git.kernel.org/stable/c/b9dd618a635d39fbb211454b6e8837b2a7f10fb0"
}
],
"title": "drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68250",
"datePublished": "2026-08-10T12:01:16.435Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:21.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74582 (GCVE-0-2026-74582)
Vulnerability from cvelistv5
Published
2026-08-21 16:31
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
packet: use consistent hard_header_len in non-ring send paths
packet_snd() reads dev->hard_header_len multiple times while allocating
and constructing an skb. Device reconfiguration can change this value
concurrently, for example through bonding device type changes.
For SOCK_RAW, packet_snd() can save a larger value in reserve and later
allocate headroom using a smaller value. Moving skb->data back by reserve
then places it before skb->head, and the following copy from userspace can
attempt an out-of-bounds write.
packet_sendmsg_spkt() has the same issue because it calculates its
reservation and header offset from separate reads before dropping the RCU
read lock to allocate the skb.
Add LL_RESERVED_SPACE_EX() for callers that already saved a header length.
Read hard_header_len once in packet_snd() and use it for allocation and
construction. In packet_sendmsg_spkt(), preserve the allocation-time value
through the device lookup retry.
The separate SOCK_DGRAM consistency problem between hard_header_len and
header_ops->create is not addressed here.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: d9fb8cc230b2a4757e9fe4f81468f81212d4deaa Version: 6190cce26e40bf71c4d375b21eea74bb07b6a0f3 Version: 01a658c1b9d4b5393c38d5a92d9112ab1425382a Version: 8809ae6747e760e6f1d2453ceb08c9bcc4939766 Version: 4.4.133 ≤ Version: 4.9.103 ≤ Version: 4.14.44 ≤ Version: 4.16.12 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/netdevice.h",
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bcd4df60ac9481b1ceffdfe5ec38fe51dcaae812",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "78a47127e33c340bc6d38dcc4552a094b4f5cc77",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "142e287b3a25cfe909215177c23243e7fc5ae2b1",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "91f041451f967cd87ed722a8f43c0b767a64f1a0",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "9052756290962ffb9a661bcf319e92dedaaedfed",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "5bb10753d428aadfc356a2bfe9acea09c82a62ec",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "b06b6fce6d7deaf7238e09b48ce3b1125ff41acd",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "03390aa32e669cc4ecd7d34108e2e1afc13d689d",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"status": "affected",
"version": "d9fb8cc230b2a4757e9fe4f81468f81212d4deaa",
"versionType": "git"
},
{
"status": "affected",
"version": "6190cce26e40bf71c4d375b21eea74bb07b6a0f3",
"versionType": "git"
},
{
"status": "affected",
"version": "01a658c1b9d4b5393c38d5a92d9112ab1425382a",
"versionType": "git"
},
{
"status": "affected",
"version": "8809ae6747e760e6f1d2453ceb08c9bcc4939766",
"versionType": "git"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.133",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.103",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.44",
"versionType": "semver"
},
{
"lessThan": "4.17",
"status": "affected",
"version": "4.16.12",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/netdevice.h",
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.133",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.103",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.44",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.16.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npacket: use consistent hard_header_len in non-ring send paths\n\npacket_snd() reads dev-\u003ehard_header_len multiple times while allocating\nand constructing an skb. Device reconfiguration can change this value\nconcurrently, for example through bonding device type changes.\n\nFor SOCK_RAW, packet_snd() can save a larger value in reserve and later\nallocate headroom using a smaller value. Moving skb-\u003edata back by reserve\nthen places it before skb-\u003ehead, and the following copy from userspace can\nattempt an out-of-bounds write.\n\npacket_sendmsg_spkt() has the same issue because it calculates its\nreservation and header offset from separate reads before dropping the RCU\nread lock to allocate the skb.\n\nAdd LL_RESERVED_SPACE_EX() for callers that already saved a header length.\nRead hard_header_len once in packet_snd() and use it for allocation and\nconstruction. In packet_sendmsg_spkt(), preserve the allocation-time value\nthrough the device lookup retry.\n\nThe separate SOCK_DGRAM consistency problem between hard_header_len and\nheader_ops-\u003ecreate is not addressed here."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is in packet_snd() and packet_sendmsg_spkt() on the local AF_PACKET sendmsg() transmit path; it is not triggered by processing remotely received network traffic or pre-authentication network services.\nAC:L - An attacker in a user+network namespace can open an AF_PACKET SOCK_RAW socket and concurrently reconfigure the bound netdev (bonding/VLAN/macvlan/team) to change hard_header_len, controlling both sides of the race without external timing.\nPR:L - Exploitation requires CAP_NET_RAW to create AF_PACKET sockets and CAP_NET_ADMIN to change netdev hard_header_len; both are obtainable by an unprivileged user inside a user namespace without init-namespace root.\nUI:N - No victim interaction is required; the attacker triggers the bug using their own packet socket sendmsg calls and concurrent netdev reconfiguration threads.\nS:U - Impact is kernel heap corruption and local privilege escalation within the same kernel security domain; it does not constitute a VM escape, sandbox breakout, or IOMMU boundary bypass.\nC:H - Racing hard_header_len can place skb-\u003edata before skb-\u003ehead, and skb_copy_datagram_from_iter/memcpy_from_msg then writes attacker-controlled data outside the skb buffer, corrupting adjacent slab objects and enabling kernel memory disclosure.\nI:H - Inconsistent hard_header_len between skb allocation and header adjustment causes out-of-bounds kernel heap writes of attacker-controlled packet data, yielding corruption primitives suitable for control-flow hijacking and local privilege escalation.\nA:H - Out-of-bounds skb buffer writes corrupt kmalloc metadata and can trigger kernel oops/panic, causing reliable denial of service even when full exploitation is not completed."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:47.499Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bcd4df60ac9481b1ceffdfe5ec38fe51dcaae812"
},
{
"url": "https://git.kernel.org/stable/c/78a47127e33c340bc6d38dcc4552a094b4f5cc77"
},
{
"url": "https://git.kernel.org/stable/c/142e287b3a25cfe909215177c23243e7fc5ae2b1"
},
{
"url": "https://git.kernel.org/stable/c/91f041451f967cd87ed722a8f43c0b767a64f1a0"
},
{
"url": "https://git.kernel.org/stable/c/9052756290962ffb9a661bcf319e92dedaaedfed"
},
{
"url": "https://git.kernel.org/stable/c/5bb10753d428aadfc356a2bfe9acea09c82a62ec"
},
{
"url": "https://git.kernel.org/stable/c/b06b6fce6d7deaf7238e09b48ce3b1125ff41acd"
},
{
"url": "https://git.kernel.org/stable/c/03390aa32e669cc4ecd7d34108e2e1afc13d689d"
}
],
"title": "packet: use consistent hard_header_len in non-ring send paths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74582",
"datePublished": "2026-08-21T16:31:55.283Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-27T12:39:47.499Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64341 (GCVE-0-2026-64341)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: iowarrior: fix use-after-free on disconnect race
mutex_unlock() may access the mutex structure after releasing the lock
and therefore cannot be used to manage lifetime of objects directly
(unlike spinlocks and refcounts). [1][2]
Use a kref to release the driver data to avoid use-after-free in
mutex_unlock() when release() races with disconnect().
[1] a51749ab34d9 ("locking/mutex: Document that mutex_unlock() is non-atomic")
[2] 2b9d9e0a9ba0 ("locking/mutex: Clarify that mutex_unlock(), and most
other sleeping locks, can still use the lock object
after it's unlocked")
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/iowarrior.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3c0a7b29ebb391d5f50b115e86f842b709195b08",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
},
{
"lessThan": "71590982700fdeb39a37a500c877228b0140978e",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
},
{
"lessThan": "c602254ba4c10f60a73cd99d147874f86a3f485c",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/iowarrior.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.21"
},
{
"lessThan": "2.6.21",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.21",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: iowarrior: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n other sleeping locks, can still use the lock object\n after it\u0027s unlocked\")"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:44.970Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3c0a7b29ebb391d5f50b115e86f842b709195b08"
},
{
"url": "https://git.kernel.org/stable/c/71590982700fdeb39a37a500c877228b0140978e"
},
{
"url": "https://git.kernel.org/stable/c/c602254ba4c10f60a73cd99d147874f86a3f485c"
}
],
"title": "USB: iowarrior: fix use-after-free on disconnect race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64341",
"datePublished": "2026-07-25T08:50:04.512Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:44.970Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64571 (GCVE-0-2026-64571)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
p54_rx_eeprom_readback() copies the requested EEPROM slice out of a
device-supplied readback frame without checking that the skb actually holds
that many bytes. Commit da1b9a55ff11 ("wifi: p54: prevent buffer-overflow in
p54_rx_eeprom_readback()") closed the destination overflow by copying a
fixed priv->eeprom_slice_size (and rejecting a mismatched advertised len),
but the source side is still unbounded: nothing verifies the frame is long
enough to supply that many bytes.
A malicious USB device can send a short frame whose advertised len matches
priv->eeprom_slice_size while the payload is truncated. The equality check
passes and memcpy() reads past the end of the skb, leaking adjacent heap:
BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)
Read of size 1016 at addr ffff88800f077114 by task swapper/0/0
Call Trace:
<IRQ>
...
__asan_memcpy (mm/kasan/shadow.c:105)
p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)
p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)
__usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)
...
</IRQ>
The buggy address belongs to the object at ffff88800f0770c0
which belongs to the cache skbuff_small_head of size 704
The buggy address is located 84 bytes inside of
allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)
Check that the slice fits in the skb before copying.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intersil/p54/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7a456ffcd20bd92ad0ef46c1aaa0e39e3be1f7e7",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "88f7044f92b8326fbfab26d0d8ed297c367ebb76",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "f21b7e096fe5371bf697cd410537fb434a763f5e",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "25c3b85af3fc4f8043159b14e65790fc3bbdaf48",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "f46f8f9c43fd02f4dd5f716d4bda296a523c04f0",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "d38f5d868a0a4770e3bcd0925e16c46acdbc9509",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "9096e1f7014174067239a63df18ae5f28301990d",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intersil/p54/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"lessThan": "2.6.28",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate RX frame length in p54_rx_eeprom_readback()\n\np54_rx_eeprom_readback() copies the requested EEPROM slice out of a\ndevice-supplied readback frame without checking that the skb actually holds\nthat many bytes. Commit da1b9a55ff11 (\"wifi: p54: prevent buffer-overflow in\np54_rx_eeprom_readback()\") closed the destination overflow by copying a\nfixed priv-\u003eeeprom_slice_size (and rejecting a mismatched advertised len),\nbut the source side is still unbounded: nothing verifies the frame is long\nenough to supply that many bytes.\n\nA malicious USB device can send a short frame whose advertised len matches\npriv-\u003eeeprom_slice_size while the payload is truncated. The equality check\npasses and memcpy() reads past the end of the skb, leaking adjacent heap:\n\n BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n Read of size 1016 at addr ffff88800f077114 by task swapper/0/0\n Call Trace:\n \u003cIRQ\u003e\n ...\n __asan_memcpy (mm/kasan/shadow.c:105)\n p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)\n __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)\n ...\n \u003c/IRQ\u003e\n\n The buggy address belongs to the object at ffff88800f0770c0\n which belongs to the cache skbuff_small_head of size 704\n The buggy address is located 84 bytes inside of\n allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)\n\nCheck that the slice fits in the skb before copying."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:46.775Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7a456ffcd20bd92ad0ef46c1aaa0e39e3be1f7e7"
},
{
"url": "https://git.kernel.org/stable/c/88f7044f92b8326fbfab26d0d8ed297c367ebb76"
},
{
"url": "https://git.kernel.org/stable/c/f21b7e096fe5371bf697cd410537fb434a763f5e"
},
{
"url": "https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48"
},
{
"url": "https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0"
},
{
"url": "https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509"
},
{
"url": "https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d"
},
{
"url": "https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea"
}
],
"title": "wifi: p54: validate RX frame length in p54_rx_eeprom_readback()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64571",
"datePublished": "2026-08-05T08:08:08.466Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:46.775Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68184 (GCVE-0-2026-68184)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
mmc_ioctl_cdrom_volume() first reads the audio control mode page into a
32-byte stack buffer with cgc->buflen set to 24. If the device reports a
block descriptor, the function increases cgc->buflen to include that
descriptor and reads the page again.
For CDROMVOLCTRL, the function then builds a MODE SELECT parameter list
by moving cgc->buffer forward by offset - 8 bytes. This drops the block
descriptor from the outgoing payload and leaves a new 8-byte mode
parameter header in front of the audio control page. However, cgc->buflen
is left unchanged.
With a standard 8-byte block descriptor, cgc->buffer points at buffer + 8
but cgc->buflen remains 32. cdrom_mode_select() therefore asks the low
level packet path to write 32 bytes from that adjusted pointer, reading 8
bytes past the end of the 32-byte stack buffer.
This is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on
drives that return a non-zero block descriptor length, which helps explain
why it has gone unnoticed. The overread is also sent to the device as
extra MODE SELECT payload, so it may not produce an obvious local failure.
Reduce cgc->buflen by the same amount as the buffer pointer adjustment so
the MODE SELECT transfer covers only the intended parameter list.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/cdrom/cdrom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45c65df5339deea3cf204902aac383fe995941a7",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0329b661349f42f9616f2733da67edffbbb8455d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e150c9a10baee55d3bfbc96dbe66b205e8b4fd44",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7344c84e32413e5c8832f74b8a612b0194e5c051",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "35b68e24c5a69fa4545f46f05f6c849223034cb6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d43c5c0c935522deae7339e0c2399365f3bf0016",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f3e2715a150066f09aa82c30fa983fb184ad6dd5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b27e195d4db8dea263050bdbeb11881b2999c9c6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/cdrom/cdrom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncdrom: fix stack out-of-bounds read in CDROMVOLCTRL\n\nmmc_ioctl_cdrom_volume() first reads the audio control mode page into a\n32-byte stack buffer with cgc-\u003ebuflen set to 24. If the device reports a\nblock descriptor, the function increases cgc-\u003ebuflen to include that\ndescriptor and reads the page again.\n\nFor CDROMVOLCTRL, the function then builds a MODE SELECT parameter list\nby moving cgc-\u003ebuffer forward by offset - 8 bytes. This drops the block\ndescriptor from the outgoing payload and leaves a new 8-byte mode\nparameter header in front of the audio control page. However, cgc-\u003ebuflen\nis left unchanged.\n\nWith a standard 8-byte block descriptor, cgc-\u003ebuffer points at buffer + 8\nbut cgc-\u003ebuflen remains 32. cdrom_mode_select() therefore asks the low\nlevel packet path to write 32 bytes from that adjusted pointer, reading 8\nbytes past the end of the 32-byte stack buffer.\n\nThis is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on\ndrives that return a non-zero block descriptor length, which helps explain\nwhy it has gone unnoticed. The overread is also sent to the device as\nextra MODE SELECT payload, so it may not produce an obvious local failure.\n\nReduce cgc-\u003ebuflen by the same amount as the buffer pointer adjustment so\nthe MODE SELECT transfer covers only the intended parameter list."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:51.908Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45c65df5339deea3cf204902aac383fe995941a7"
},
{
"url": "https://git.kernel.org/stable/c/0329b661349f42f9616f2733da67edffbbb8455d"
},
{
"url": "https://git.kernel.org/stable/c/e150c9a10baee55d3bfbc96dbe66b205e8b4fd44"
},
{
"url": "https://git.kernel.org/stable/c/7344c84e32413e5c8832f74b8a612b0194e5c051"
},
{
"url": "https://git.kernel.org/stable/c/35b68e24c5a69fa4545f46f05f6c849223034cb6"
},
{
"url": "https://git.kernel.org/stable/c/d43c5c0c935522deae7339e0c2399365f3bf0016"
},
{
"url": "https://git.kernel.org/stable/c/f3e2715a150066f09aa82c30fa983fb184ad6dd5"
},
{
"url": "https://git.kernel.org/stable/c/b27e195d4db8dea263050bdbeb11881b2999c9c6"
}
],
"title": "cdrom: fix stack out-of-bounds read in CDROMVOLCTRL",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68184",
"datePublished": "2026-08-10T11:59:56.319Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:51.908Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64482 (GCVE-0-2026-64482)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: gus: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails.
snd_gf1_pcm_volume_control() does not check the return value before
dereferencing kctl->id.index, which can lead to a NULL pointer
dereference.
Add a NULL check after snd_ctl_new1() and return -ENOMEM if it fails.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c35034fd6446afaf408d5ab296068e32c775c965 Version: c5ae57b1bb99bd6f50b90428fabde397c2aeba0f Version: c5ae57b1bb99bd6f50b90428fabde397c2aeba0f Version: c5ae57b1bb99bd6f50b90428fabde397c2aeba0f Version: c5ae57b1bb99bd6f50b90428fabde397c2aeba0f Version: c5ae57b1bb99bd6f50b90428fabde397c2aeba0f Version: a1374d2683442633f8ad2169f8f31df45048e008 Version: 6.1.34 ≤ Version: 6.3.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/isa/gus/gus_pcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97f6bdf5d5ded2e37f358cacb5a95f1393356604",
"status": "affected",
"version": "c35034fd6446afaf408d5ab296068e32c775c965",
"versionType": "git"
},
{
"lessThan": "eccf8e91266e39f6f15637702a04a1d344833fe2",
"status": "affected",
"version": "c5ae57b1bb99bd6f50b90428fabde397c2aeba0f",
"versionType": "git"
},
{
"lessThan": "fc5d4f27ca1293bc1379ef8fff691c30d9803ca2",
"status": "affected",
"version": "c5ae57b1bb99bd6f50b90428fabde397c2aeba0f",
"versionType": "git"
},
{
"lessThan": "5e74e5e8cb7cc25f7a89f59abaf3489bf0c6f4a0",
"status": "affected",
"version": "c5ae57b1bb99bd6f50b90428fabde397c2aeba0f",
"versionType": "git"
},
{
"lessThan": "465075c6835103821d725c13f8c545898e5f2636",
"status": "affected",
"version": "c5ae57b1bb99bd6f50b90428fabde397c2aeba0f",
"versionType": "git"
},
{
"lessThan": "c7fa99d30c7a166a5e5db5a585ce7501ff68326b",
"status": "affected",
"version": "c5ae57b1bb99bd6f50b90428fabde397c2aeba0f",
"versionType": "git"
},
{
"status": "affected",
"version": "a1374d2683442633f8ad2169f8f31df45048e008",
"versionType": "git"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.34",
"versionType": "semver"
},
{
"lessThan": "6.4",
"status": "affected",
"version": "6.3.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/isa/gus/gus_pcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: gus: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_gf1_pcm_volume_control() does not check the return value before\ndereferencing kctl-\u003eid.index, which can lead to a NULL pointer\ndereference.\n\nAdd a NULL check after snd_ctl_new1() and return -ENOMEM if it fails."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:29.187Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97f6bdf5d5ded2e37f358cacb5a95f1393356604"
},
{
"url": "https://git.kernel.org/stable/c/eccf8e91266e39f6f15637702a04a1d344833fe2"
},
{
"url": "https://git.kernel.org/stable/c/fc5d4f27ca1293bc1379ef8fff691c30d9803ca2"
},
{
"url": "https://git.kernel.org/stable/c/5e74e5e8cb7cc25f7a89f59abaf3489bf0c6f4a0"
},
{
"url": "https://git.kernel.org/stable/c/465075c6835103821d725c13f8c545898e5f2636"
},
{
"url": "https://git.kernel.org/stable/c/c7fa99d30c7a166a5e5db5a585ce7501ff68326b"
}
],
"title": "ALSA: gus: check snd_ctl_new1() return value",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64482",
"datePublished": "2026-07-25T08:51:43.128Z",
"dateReserved": "2026-07-19T15:36:31.791Z",
"dateUpdated": "2026-08-17T04:56:29.187Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64559 (GCVE-0-2026-64559)
Vulnerability from cvelistv5
Published
2026-07-29 16:31
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
Explicitly check the buffer length request structure provided by
user-space and fail, if it exceeds the buffer size.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/pkey_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0a9e34ccbe772b8f321388cdbdf4f22b94e513e7",
"status": "affected",
"version": "8fcc231ce3bea12b78bb94b280cdc03cff342435",
"versionType": "git"
},
{
"lessThan": "693bf91d4db134f9b1c2840c8e287eee3d993bac",
"status": "affected",
"version": "8fcc231ce3bea12b78bb94b280cdc03cff342435",
"versionType": "git"
},
{
"lessThan": "7e7e03848c918aa0acad5ffd75d929e3afec1554",
"status": "affected",
"version": "8fcc231ce3bea12b78bb94b280cdc03cff342435",
"versionType": "git"
},
{
"lessThan": "b3d4ab2d7df9426f7f1d3671d7e2108f2ca6e970",
"status": "affected",
"version": "8fcc231ce3bea12b78bb94b280cdc03cff342435",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/pkey_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Check length in PKEY_VERIFYPROTK ioctl\n\nExplicitly check the buffer length request structure provided by\nuser-space and fail, if it exceeds the buffer size."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is reached only through the PKEY_VERIFYPROTK ioctl on the /dev/pkey character device, which requires local access to the system. There is no network-facing path to this code.\nAC:L - Triggering is fully deterministic \u2014 a single ioctl with protkey.len set to 0x20000010 wraps the u32 multiplication to a legal 128-bit keytype and drives the unchecked memcpy; no race, timing, or uncontrollable memory-layout condition is involved.\nPR:L - The pkey miscdevice is registered with .mode = 0666 and neither the open handler nor pkey_unlocked_ioctl performs any capability check, so any unprivileged local user (including a normal shell user on a shared IBM Z LPAR or z/VM guest) can issue the ioctl.\nUI:N - The attacker performs the entire attack via its own ioctl call; no action by any other user or administrator is needed.\nS:U - The out-of-bounds read and write are confined to kernel memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The unchecked memcpy performs a huge out-of-bounds read that walks off the 64-byte on-stack protkey buffer through the entire kernel stack, relocating arbitrary kernel stack contents \u2014 including protected key material handled by this crypto driver \u2014 into heap objects, an unbounded kernel memory disclosure primitive.\nI:H - This is a massive slab out-of-bounds write into an 80-byte kmalloc-96 allocation whose first 64 bytes are entirely attacker-supplied and whose subsequent bytes come from groomable kernel-stack data, corrupting adjacent slab objects and providing a heap-overflow primitive suitable for control-flow hijacking.\nA:H - The smallest length that bypasses the keytype check requests a 512 MB copy, so the source pointer inevitably hits the VMAP_STACK guard page, producing an unhandled kernel fault/oops and panic after wide-scale heap corruption \u2014 a guaranteed, repeatable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:37.809Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0a9e34ccbe772b8f321388cdbdf4f22b94e513e7"
},
{
"url": "https://git.kernel.org/stable/c/693bf91d4db134f9b1c2840c8e287eee3d993bac"
},
{
"url": "https://git.kernel.org/stable/c/7e7e03848c918aa0acad5ffd75d929e3afec1554"
},
{
"url": "https://git.kernel.org/stable/c/b3d4ab2d7df9426f7f1d3671d7e2108f2ca6e970"
}
],
"title": "s390/pkey: Check length in PKEY_VERIFYPROTK ioctl",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64559",
"datePublished": "2026-07-29T16:31:22.195Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-08-17T04:57:37.809Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64098 (GCVE-0-2026-64098)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/virtio: use uninterruptible resv lock for plane updates
virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock
the framebuffer BO's dma_resv via virtio_gpu_array_lock_resv() and
ignore its return value. The function can fail with -EINTR from
dma_resv_lock_interruptible() (signal during lock wait) or with
-ENOMEM from dma_resv_reserve_fences() (fence slot allocation),
leaving the resv lock not held. The queue path then walks the object
array and calls dma_resv_add_fence(), which requires the lock held;
with lockdep enabled this trips dma_resv_assert_held():
WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840
Call Trace:
virtio_gpu_array_add_fence
virtio_gpu_queue_ctrl_sgs
virtio_gpu_queue_fenced_ctrl_buffer
virtio_gpu_cursor_plane_update
drm_atomic_helper_commit_planes
drm_atomic_helper_commit_tail
commit_tail
drm_atomic_helper_commit
drm_atomic_commit
drm_atomic_helper_update_plane
__setplane_atomic
drm_mode_cursor_universal
drm_mode_cursor_common
drm_mode_cursor_ioctl
drm_ioctl
__x64_sys_ioctl
Beyond the WARN, mutating the dma_resv fence list without the lock
races with concurrent readers/writers and can corrupt the list.
Both call sites run inside the .atomic_update plane callback, which
DRM atomic helpers do not allow to fail (by the time it runs, the
commit has been signed off to userspace and there is no clean
rollback path). Moving the lock acquisition to .prepare_fb was
rejected because the broader lock scope deadlocks against other BO
locking paths in the same atomic commit.
Introduce virtio_gpu_lock_one_resv_uninterruptible() that uses
dma_resv_lock() instead of dma_resv_lock_interruptible(). This
eliminates the -EINTR failure mode -- the realistic syzbot trigger
-- without extending the lock hold across the commit. The helper
locks a single BO and rejects nents > 1 with -EINVAL; both fix
sites lock exactly one BO.
Use it from virtio_gpu_cursor_plane_update() and
virtio_gpu_resource_flush(); check the return value to handle the
remaining -ENOMEM case from dma_resv_reserve_fences() by freeing
the objs and skipping the plane update for that frame. The
framebuffer BOs touched here are not shared with other contexts
and lock contention is expected to be brief, so the loss of
signal-interruptibility is acceptable.
Other callers of virtio_gpu_array_lock_resv() (the ioctl paths)
continue to use the interruptible variant.
The bug was reported by syzbot, triggered via fault injection
(fail_nth) on the DRM_IOCTL_MODE_CURSOR path, which forces the
-ENOMEM branch in dma_resv_reserve_fences().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5cfd31c5b3a321aed0c9621b7b45efa2942056f8 Version: 5cfd31c5b3a321aed0c9621b7b45efa2942056f8 Version: 5cfd31c5b3a321aed0c9621b7b45efa2942056f8 Version: 5cfd31c5b3a321aed0c9621b7b45efa2942056f8 Version: 5cfd31c5b3a321aed0c9621b7b45efa2942056f8 Version: 5cfd31c5b3a321aed0c9621b7b45efa2942056f8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/virtio/virtgpu_drv.h",
"drivers/gpu/drm/virtio/virtgpu_gem.c",
"drivers/gpu/drm/virtio/virtgpu_plane.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c86077d512ee980cc91322211d35dbcd3175f64c",
"status": "affected",
"version": "5cfd31c5b3a321aed0c9621b7b45efa2942056f8",
"versionType": "git"
},
{
"lessThan": "21ab64c77a30d56efc506c8fa2ad8959f8ce3d36",
"status": "affected",
"version": "5cfd31c5b3a321aed0c9621b7b45efa2942056f8",
"versionType": "git"
},
{
"lessThan": "7930eee22cd3df61e85be8aa512032ab303b7167",
"status": "affected",
"version": "5cfd31c5b3a321aed0c9621b7b45efa2942056f8",
"versionType": "git"
},
{
"lessThan": "8fadd01cf461fee5bb11506621339c548447e5c7",
"status": "affected",
"version": "5cfd31c5b3a321aed0c9621b7b45efa2942056f8",
"versionType": "git"
},
{
"lessThan": "a2359a411b15f495d12cfda6a7db6855ebb7f90f",
"status": "affected",
"version": "5cfd31c5b3a321aed0c9621b7b45efa2942056f8",
"versionType": "git"
},
{
"lessThan": "9af1b6e175c82daf4b423da339a722d8e67a735a",
"status": "affected",
"version": "5cfd31c5b3a321aed0c9621b7b45efa2942056f8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/virtio/virtgpu_drv.h",
"drivers/gpu/drm/virtio/virtgpu_gem.c",
"drivers/gpu/drm/virtio/virtgpu_plane.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: use uninterruptible resv lock for plane updates\n\nvirtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock\nthe framebuffer BO\u0027s dma_resv via virtio_gpu_array_lock_resv() and\nignore its return value. The function can fail with -EINTR from\ndma_resv_lock_interruptible() (signal during lock wait) or with\n-ENOMEM from dma_resv_reserve_fences() (fence slot allocation),\nleaving the resv lock not held. The queue path then walks the object\narray and calls dma_resv_add_fence(), which requires the lock held;\nwith lockdep enabled this trips dma_resv_assert_held():\n\n WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840\n Call Trace:\n virtio_gpu_array_add_fence\n virtio_gpu_queue_ctrl_sgs\n virtio_gpu_queue_fenced_ctrl_buffer\n virtio_gpu_cursor_plane_update\n drm_atomic_helper_commit_planes\n drm_atomic_helper_commit_tail\n commit_tail\n drm_atomic_helper_commit\n drm_atomic_commit\n drm_atomic_helper_update_plane\n __setplane_atomic\n drm_mode_cursor_universal\n drm_mode_cursor_common\n drm_mode_cursor_ioctl\n drm_ioctl\n __x64_sys_ioctl\n\nBeyond the WARN, mutating the dma_resv fence list without the lock\nraces with concurrent readers/writers and can corrupt the list.\n\nBoth call sites run inside the .atomic_update plane callback, which\nDRM atomic helpers do not allow to fail (by the time it runs, the\ncommit has been signed off to userspace and there is no clean\nrollback path). Moving the lock acquisition to .prepare_fb was\nrejected because the broader lock scope deadlocks against other BO\nlocking paths in the same atomic commit.\n\nIntroduce virtio_gpu_lock_one_resv_uninterruptible() that uses\ndma_resv_lock() instead of dma_resv_lock_interruptible(). This\neliminates the -EINTR failure mode -- the realistic syzbot trigger\n-- without extending the lock hold across the commit. The helper\nlocks a single BO and rejects nents \u003e 1 with -EINVAL; both fix\nsites lock exactly one BO.\n\nUse it from virtio_gpu_cursor_plane_update() and\nvirtio_gpu_resource_flush(); check the return value to handle the\nremaining -ENOMEM case from dma_resv_reserve_fences() by freeing\nthe objs and skipping the plane update for that frame. The\nframebuffer BOs touched here are not shared with other contexts\nand lock contention is expected to be brief, so the loss of\nsignal-interruptibility is acceptable.\n\nOther callers of virtio_gpu_array_lock_resv() (the ioctl paths)\ncontinue to use the interruptible variant.\n\nThe bug was reported by syzbot, triggered via fault injection\n(fail_nth) on the DRM_IOCTL_MODE_CURSOR path, which forces the\n-ENOMEM branch in dma_resv_reserve_fences()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through local DRM ioctl syscalls (DRM_IOCTL_MODE_CURSOR and DRM_MASTER modesetting ioctls) on /dev/dri/card0, not via any network-facing kernel service.\nAC:L - An attacker can reliably trigger the bug by signaling a thread blocked in dma_resv_lock_interruptible (-EINTR), forcing memory pressure for -ENOMEM, or running concurrent plane updates to race the unlocked fence-list mutation.\nPR:L - Exploitation requires DRM master on the virtio-gpu device, which a local user with standard DRI access (video/render group membership on typical virtio-gpu VMs) can obtain when no compositor holds master; this is not init-namespace root.\nUI:N - Triggering the bug requires only attacker-initiated DRM ioctl calls (cursor/plane updates); no action by another user or victim is needed.\nS:U - The corruption occurs within the same kernel security domain (guest or host) that issued the ioctl; virtio-gpu runs in the guest kernel and this does not cross a VM/hypervisor boundary to the host.\nC:H - Mutating the dma_resv fence list without holding the lock races with concurrent readers and can corrupt kernel heap metadata, which is reasonably leverageable for arbitrary memory disclosure.\nI:H - The same unlocked fence-list corruption can corrupt kernel pointers and synchronization state, providing a plausible path to arbitrary kernel writes or control-flow hijacking.\nA:H - The bug produces kernel WARN/oops under lockdep and fence-list corruption can cause kernel crashes, hangs, or panics during subsequent dma_resv operations."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:12.587Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c86077d512ee980cc91322211d35dbcd3175f64c"
},
{
"url": "https://git.kernel.org/stable/c/21ab64c77a30d56efc506c8fa2ad8959f8ce3d36"
},
{
"url": "https://git.kernel.org/stable/c/7930eee22cd3df61e85be8aa512032ab303b7167"
},
{
"url": "https://git.kernel.org/stable/c/8fadd01cf461fee5bb11506621339c548447e5c7"
},
{
"url": "https://git.kernel.org/stable/c/a2359a411b15f495d12cfda6a7db6855ebb7f90f"
},
{
"url": "https://git.kernel.org/stable/c/9af1b6e175c82daf4b423da339a722d8e67a735a"
}
],
"title": "drm/virtio: use uninterruptible resv lock for plane updates",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64098",
"datePublished": "2026-07-19T15:40:04.264Z",
"dateReserved": "2026-07-19T07:54:57.033Z",
"dateUpdated": "2026-08-05T12:39:12.587Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72389 (GCVE-0-2026-72389)
Vulnerability from cvelistv5
Published
2026-08-15 05:56
Modified
2026-08-17 05:43
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bridge: stp: Fix a potential use-after-free when deleting a bridge
The three STP timers are not supposed to be armed while the bridge is
administratively down. They are synchronously deactivated when the
bridge is put administratively down and the various call sites check for
'IFF_UP' before arming them.
This check is missing from br_topology_change_detection() and it is
possible to engineer a situation in which the topology change timer is
armed while the bridge is administratively down, resulting in a
use-after-free [1] when the bridge is deleted.
Fix by adding the missing check and for good measures synchronously
shutdown the three timers when the bridge is deleted.
[1]
ODEBUG: free active (active state 0) object: ffff88811662b9b0 object type: timer_list hint: br_topology_change_timer_expired (net/bridge/br_stp_timer.c:120)
WARNING: lib/debugobjects.c:629 at debug_print_object+0x1bc/0x450, CPU#9: ip/359
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bridge/br_if.c",
"net/bridge/br_stp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c86579b0a2d201792bcb59316629f4ba4758cfc8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "297a747f59bff6573196d7236178144d66524e68",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "4c40eec06eeac37c58e47a6058eb32901218d5d4",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "39283907a25e5caf0f2bd2947f6e56644b01e2b7",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b4b3458ef88df4798632619f018791d4344bcd92",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "40cbfa3a28e0919469d1b086629bb3ce38a83593",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2a00517db8de4be7df3d483b215c5544fb30a191",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bridge/br_if.c",
"net/bridge/br_stp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: stp: Fix a potential use-after-free when deleting a bridge\n\nThe three STP timers are not supposed to be armed while the bridge is\nadministratively down. They are synchronously deactivated when the\nbridge is put administratively down and the various call sites check for\n\u0027IFF_UP\u0027 before arming them.\n\nThis check is missing from br_topology_change_detection() and it is\npossible to engineer a situation in which the topology change timer is\narmed while the bridge is administratively down, resulting in a\nuse-after-free [1] when the bridge is deleted.\n\nFix by adding the missing check and for good measures synchronously\nshutdown the three timers when the bridge is deleted.\n\n[1]\nODEBUG: free active (active state 0) object: ffff88811662b9b0 object type: timer_list hint: br_topology_change_timer_expired (net/bridge/br_stp_timer.c:120)\nWARNING: lib/debugobjects.c:629 at debug_print_object+0x1bc/0x450, CPU#9: ip/359"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation is via local RTNETLINK/ioctl to create a down bridge, enable kernel STP, enslave ports, and delete the bridge; remote STP BPDU handling is blocked when IFF_UP is clear, so the arming path that leaves timers active on a down bridge is local.\nAC:L - The public PoC uses a reliable, attacker-controlled netlink sequence (down bridge + kernel STP + port state progression + dellink) without winning races; per-port forward-delay timers deterministically reach br_topology_change_detection and arm topology_change_timer before deletion.\nPR:L - All reachable paths (RTM_NEWLINK/DELLINK, IFLA_BR_STP_STATE, enslaving ports) require CAP_NET_ADMIN, which unprivileged users can obtain in user/network namespaces (unshare -Urn, Kubernetes NET_ADMIN, LXC/libvirt network namespaces).\nUI:N - Triggering requires only programmatic bridge configuration by the attacker; no victim must click, mount, or open anything beyond the attacker\u0027s own netlink operations.\nS:U - Impact is kernel memory corruption and privilege escalation within the same kernel/host security domain; it does not cross a VM, container-to-host, or IOMMU boundary by itself.\nC:H - Use-after-free of the net_device/net_bridge kmalloc object lets an attacker reclaim freed slab memory and obtain arbitrary kernel read/disclosure primitives from corrupted timer and bridge structures.\nI:H - Disclosed analysis and PoC show the dangling timer callback can hijack control flow by reclaiming the freed object with attacker-controlled data, replacing the timer function pointer for arbitrary kernel code execution.\nA:H - Deleting the bridge with active STP timers queued causes the per-CPU timer wheel to invoke callbacks on freed memory, producing kernel BUG/oops/panics and denial of service even if full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:43:35.297Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c86579b0a2d201792bcb59316629f4ba4758cfc8"
},
{
"url": "https://git.kernel.org/stable/c/297a747f59bff6573196d7236178144d66524e68"
},
{
"url": "https://git.kernel.org/stable/c/4c40eec06eeac37c58e47a6058eb32901218d5d4"
},
{
"url": "https://git.kernel.org/stable/c/39283907a25e5caf0f2bd2947f6e56644b01e2b7"
},
{
"url": "https://git.kernel.org/stable/c/b4b3458ef88df4798632619f018791d4344bcd92"
},
{
"url": "https://git.kernel.org/stable/c/40cbfa3a28e0919469d1b086629bb3ce38a83593"
},
{
"url": "https://git.kernel.org/stable/c/2a00517db8de4be7df3d483b215c5544fb30a191"
}
],
"title": "bridge: stp: Fix a potential use-after-free when deleting a bridge",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72389",
"datePublished": "2026-08-15T05:56:18.553Z",
"dateReserved": "2026-08-09T03:40:39.923Z",
"dateUpdated": "2026-08-17T05:43:35.297Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64134 (GCVE-0-2026-64134)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Don't setup bogus iov_iter for silencing
At transition to the iov_iter for PCM data transfer, we blindly
applied the iov_iter setup also for silencing (i.e. data = NULL), and
it leads to a calculation of bogus iov_iter. Fortunately this didn't
cause troubles on most of architectures but it goes wrong on RISC-V
now, causing a NULL dereference.
Handle the NULL data case to treat the silencing in interleaved_copy()
for addressing the bug above. noninterleaved_copy() has already the
NULL data handling, so it doesn't need changes.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/core/pcm_lib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "41a766c647294842c9b17672449f8e011048cba9",
"status": "affected",
"version": "cf393babb37a1679a1ec1d864df1090353465e23",
"versionType": "git"
},
{
"lessThan": "ce836587e594af39ff048d9b29dee0f5f10692c9",
"status": "affected",
"version": "cf393babb37a1679a1ec1d864df1090353465e23",
"versionType": "git"
},
{
"lessThan": "feff0251386aa6bb180a0a1cf7c1f91ba868113d",
"status": "affected",
"version": "cf393babb37a1679a1ec1d864df1090353465e23",
"versionType": "git"
},
{
"lessThan": "c9f6768515818d71bdfc20119a81f3332c53b9c6",
"status": "affected",
"version": "cf393babb37a1679a1ec1d864df1090353465e23",
"versionType": "git"
},
{
"lessThan": "e4d3386b74fba8e01280484b67ee481ece00201e",
"status": "affected",
"version": "cf393babb37a1679a1ec1d864df1090353465e23",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/core/pcm_lib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Don\u0027t setup bogus iov_iter for silencing\n\nAt transition to the iov_iter for PCM data transfer, we blindly\napplied the iov_iter setup also for silencing (i.e. data = NULL), and\nit leads to a calculation of bogus iov_iter. Fortunately this didn\u0027t\ncause troubles on most of architectures but it goes wrong on RISC-V\nnow, causing a NULL dereference.\n\nHandle the NULL data case to treat the silencing in interleaved_copy()\nfor addressing the bug above. noninterleaved_copy() has already the\nNULL data handling, so it doesn\u0027t need changes."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only via local ALSA PCM interfaces\u2014opening `/dev/snd/pcmC*D*p`, `write()`/`ioctl()` on that device, or OSS PCM emulation\u2014not via any network-facing kernel protocol.\nAC:L - An attacker with PCM device access can reliably trigger silencing by setting `silence_size \u003e 0` via `SNDRV_PCM_IOCTL_SW_PARAMS`, using OSS playback (which auto-enables silence), calling `snd_pcm_lib_write()` with a NULL buffer, or starting playback so `snd_pcm_playback_silence()` runs on interleaved streams.\nPR:L - Exploitation requires a local process able to open and configure a PCM playback stream (typically any logged-in desktop/mobile user with audio device access via the `audio` group, seat ACL, or equivalent permissions), not root or special capabilities.\nUI:N - Triggering the bug requires only programmatic PCM playback/silencing operations; no victim interaction such as mounting a filesystem or opening a malicious file is needed.\nS:U - Impact is confined to kernel memory safety within the ALSA PCM subsystem on the local host; it does not cross a security boundary such as VM escape, sandbox escape, or IOMMU bypass.\nC:H - Passing `data=NULL` through `do_transfer()` constructs a bogus `iov_iter` with a NULL base pointer; this is a kernel memory-safety defect in the iterator layer that can cause out-of-bounds or NULL-based reads when iterator helpers dereference the malformed state, not merely a benign error return.\nI:H - The same bogus `iov_iter` setup supplies invalid source/destination metadata to the kernel copy path; if iterator operations proceed on the malformed structure, uncontrolled kernel writes are possible, and the identical NULL-handling gap in `noninterleaved_copy()` confirms this silencing path was always meant to bypass `do_transfer()`.\nA:H - On RISC-V the defect manifests as a kernel NULL pointer dereference during silencing, causing an oops/panic and denial of service; the bug is also reachable on every architecture where interleaved PCM silencing is used."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:36.211Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/41a766c647294842c9b17672449f8e011048cba9"
},
{
"url": "https://git.kernel.org/stable/c/ce836587e594af39ff048d9b29dee0f5f10692c9"
},
{
"url": "https://git.kernel.org/stable/c/feff0251386aa6bb180a0a1cf7c1f91ba868113d"
},
{
"url": "https://git.kernel.org/stable/c/c9f6768515818d71bdfc20119a81f3332c53b9c6"
},
{
"url": "https://git.kernel.org/stable/c/e4d3386b74fba8e01280484b67ee481ece00201e"
}
],
"title": "ALSA: pcm: Don\u0027t setup bogus iov_iter for silencing",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64134",
"datePublished": "2026-07-19T15:40:28.974Z",
"dateReserved": "2026-07-19T07:54:57.036Z",
"dateUpdated": "2026-08-05T12:39:36.211Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64088 (GCVE-0-2026-64088)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: tt: fix negative tt_buff_len
batadv_orig_node::tt_buff_len was declared as s16, but the field is never
intended to hold a negative value. When a value greater than 32767 is
assigned, it wraps to a negative signed integer.
In batadv_send_other_tt_response(), tt_buff_len is temporarily widened to
s32. The incorrectly negative s16 value propagates into the s32, causing
batadv_tt_prepare_tvlv_global_data() to allocate a full sized buffer but
populates only a small portion of it with the collected changeset. All
remaining bits are kept uninitialized.
Using an u16 avoids this type confusion and ensures that no (negative) sign
extension is performed in batadv_send_other_tt_response().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a73105b8d4c765d9ebfb664d0a66802127d8e4c7 Version: a73105b8d4c765d9ebfb664d0a66802127d8e4c7 Version: a73105b8d4c765d9ebfb664d0a66802127d8e4c7 Version: a73105b8d4c765d9ebfb664d0a66802127d8e4c7 Version: a73105b8d4c765d9ebfb664d0a66802127d8e4c7 Version: a73105b8d4c765d9ebfb664d0a66802127d8e4c7 Version: a73105b8d4c765d9ebfb664d0a66802127d8e4c7 Version: a73105b8d4c765d9ebfb664d0a66802127d8e4c7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/batman-adv/types.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4c4c2f340f4c27373bfcac8dc5032ce7bb474e47",
"status": "affected",
"version": "a73105b8d4c765d9ebfb664d0a66802127d8e4c7",
"versionType": "git"
},
{
"lessThan": "33e5ede7ce6d92e531920d4bbd6d3e18ef1c6430",
"status": "affected",
"version": "a73105b8d4c765d9ebfb664d0a66802127d8e4c7",
"versionType": "git"
},
{
"lessThan": "3c96dff00998314983b68a3e7caac07a66ebe496",
"status": "affected",
"version": "a73105b8d4c765d9ebfb664d0a66802127d8e4c7",
"versionType": "git"
},
{
"lessThan": "32edd2a28e112064020a2f319a8cb8a9e5a09767",
"status": "affected",
"version": "a73105b8d4c765d9ebfb664d0a66802127d8e4c7",
"versionType": "git"
},
{
"lessThan": "4dab98961426d0cf6a1599cda6950b7596ca2fcd",
"status": "affected",
"version": "a73105b8d4c765d9ebfb664d0a66802127d8e4c7",
"versionType": "git"
},
{
"lessThan": "730de8733dd90f70d7580a9b329b971f8e1474a2",
"status": "affected",
"version": "a73105b8d4c765d9ebfb664d0a66802127d8e4c7",
"versionType": "git"
},
{
"lessThan": "ed28ead3420c373a7928622f114bc6168075d1e1",
"status": "affected",
"version": "a73105b8d4c765d9ebfb664d0a66802127d8e4c7",
"versionType": "git"
},
{
"lessThan": "b64963a2ceeb7529310b6cf253a1e540784422f4",
"status": "affected",
"version": "a73105b8d4c765d9ebfb664d0a66802127d8e4c7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/batman-adv/types.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"lessThan": "3.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: fix negative tt_buff_len\n\nbatadv_orig_node::tt_buff_len was declared as s16, but the field is never\nintended to hold a negative value. When a value greater than 32767 is\nassigned, it wraps to a negative signed integer.\n\nIn batadv_send_other_tt_response(), tt_buff_len is temporarily widened to\ns32. The incorrectly negative s16 value propagates into the s32, causing\nbatadv_tt_prepare_tvlv_global_data() to allocate a full sized buffer but\npopulates only a small portion of it with the collected changeset. All\nremaining bits are kept uninitialized.\n\nUsing an u16 avoids this type confusion and ensures that no (negative) sign\nextension is performed in batadv_send_other_tt_response()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Batman-adv processes attacker-controlled translation-table TVLV traffic from mesh peers over WiFi/Ethernet L2; exploitation requires the attacker to be on the same wireless or LAN segment as the victim mesh node, matching the Adjacent definition for WiFi/L2 mesh protocols.\nAC:L - An adjacent mesh attacker can send unauthenticated TT_REQUEST/TT_RESPONSE/OGM TVLV packets to populate `tt_buff_len` and then trigger `batadv_send_other_tt_response()` without depending on victim-controlled timing or memory layout.\nPR:N - The vulnerable path is reached from pre-authentication mesh control-plane packet handling (`batadv_recv_unicast_tvlv` \u2192 `batadv_tt_tvlv_unicast_handler_v1`); no Linux credentials or capabilities are required on the victim host beyond having an active batman-adv mesh interface.\nUI:N - Exploitation requires only crafted mesh protocol packets from an adjacent attacker; no victim user action (opening files, clicking links, etc.) is needed at attack time.\nS:U - Impact is confined to kernel memory disclosure/corruption and potential local privilege escalation within the same kernel security authority; it does not cross VM, container, or IOMMU boundaries.\nC:H - Sign-extended negative `tt_buff_len` causes `batadv_tt_prepare_tvlv_global_data()` to allocate a large buffer but only partially fill it, leaving the remainder uninitialized and transmitted to the requester in the TT_RESPONSE via `batadv_tvlv_unicast_send()`.\nI:H - The same type confusion passes a negative `s16` length to `memcpy()`, which promotes to a very large `size_t` and can cause out-of-bounds reads/writes from the undersized `tt_buff` allocation, enabling heap memory corruption.\nA:H - The malformed `memcpy()` and associated heap corruption can trigger kernel oops/panic on the responding mesh node, and the bug class inherently threatens system availability even when not fully weaponized."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:05.060Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4c4c2f340f4c27373bfcac8dc5032ce7bb474e47"
},
{
"url": "https://git.kernel.org/stable/c/33e5ede7ce6d92e531920d4bbd6d3e18ef1c6430"
},
{
"url": "https://git.kernel.org/stable/c/3c96dff00998314983b68a3e7caac07a66ebe496"
},
{
"url": "https://git.kernel.org/stable/c/32edd2a28e112064020a2f319a8cb8a9e5a09767"
},
{
"url": "https://git.kernel.org/stable/c/4dab98961426d0cf6a1599cda6950b7596ca2fcd"
},
{
"url": "https://git.kernel.org/stable/c/730de8733dd90f70d7580a9b329b971f8e1474a2"
},
{
"url": "https://git.kernel.org/stable/c/ed28ead3420c373a7928622f114bc6168075d1e1"
},
{
"url": "https://git.kernel.org/stable/c/b64963a2ceeb7529310b6cf253a1e540784422f4"
}
],
"title": "batman-adv: tt: fix negative tt_buff_len",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64088",
"datePublished": "2026-07-19T15:39:58.084Z",
"dateReserved": "2026-07-19T07:54:57.032Z",
"dateUpdated": "2026-08-05T12:39:05.060Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64565 (GCVE-0-2026-64565)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
The `ims_pcu_process_data()` processes incoming URB data byte by byte.
However, it fails to check if the `read_pos` index exceeds
IMS_PCU_BUF_SIZE.
If a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE,
`read_pos` will increment indefinitely. Moreover, since `read_pos` is
located immediately after `read_buf`, the attacker can overwrite
`read_pos` itself to arbitrarily control the index.
This manipulated `read_pos` is subsequently used in
`ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a
heap buffer overflow.
Specifically, an attacker can overwrite the `cmd_done.wait.head` located
at offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`.
Consequently, when the driver calls `complete(&pcu->cmd_done)`, it
triggers a control flow hijack by using the manipulated pointer.
Fix this by adding a bounds check for `read_pos` before writing to
`read_buf`. If the packet is too long, discard it, log a warning,
and reset the parser state.
[dtor: factor out resetting packet state, reset checksum as well]
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/misc/ims-pcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "06cfff93fd40441292567b999091beab11c74504",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "992a7173364dcf63e30012af43da3c2f279839f9",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "3a801bc75ba1d121d0ed60e7234f93ba5651d87d",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "40bbbf2e91fd60715525bf0405c67876af817edf",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "d03a740e087de7dcb2a26dc1123377bd3d1d84ca",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "875115b82c295277b81b6dfee7debc725f44e854",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/misc/ims-pcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()\n\nThe `ims_pcu_process_data()` processes incoming URB data byte by byte.\nHowever, it fails to check if the `read_pos` index exceeds\nIMS_PCU_BUF_SIZE.\n\nIf a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE,\n`read_pos` will increment indefinitely. Moreover, since `read_pos` is\nlocated immediately after `read_buf`, the attacker can overwrite\n`read_pos` itself to arbitrarily control the index.\n\nThis manipulated `read_pos` is subsequently used in\n`ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a\nheap buffer overflow.\n\nSpecifically, an attacker can overwrite the `cmd_done.wait.head` located\nat offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`.\nConsequently, when the driver calls `complete(\u0026pcu-\u003ecmd_done)`, it\ntriggers a control flow hijack by using the manipulated pointer.\n\nFix this by adding a bounds check for `read_pos` before writing to\n`read_buf`. If the packet is too long, discard it, log a warning,\nand reset the parser state.\n\n[dtor: factor out resetting packet state, reset checksum as well]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:39.404Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/06cfff93fd40441292567b999091beab11c74504"
},
{
"url": "https://git.kernel.org/stable/c/992a7173364dcf63e30012af43da3c2f279839f9"
},
{
"url": "https://git.kernel.org/stable/c/3a801bc75ba1d121d0ed60e7234f93ba5651d87d"
},
{
"url": "https://git.kernel.org/stable/c/40bbbf2e91fd60715525bf0405c67876af817edf"
},
{
"url": "https://git.kernel.org/stable/c/ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49"
},
{
"url": "https://git.kernel.org/stable/c/d03a740e087de7dcb2a26dc1123377bd3d1d84ca"
},
{
"url": "https://git.kernel.org/stable/c/875115b82c295277b81b6dfee7debc725f44e854"
}
],
"title": "Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64565",
"datePublished": "2026-08-04T06:23:24.089Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:39.404Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63888 (GCVE-0-2026-63888)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
Two latent bugs in the Text-phase handler, both present since the
original LIO integration in commit e48354ce078c ("iscsi-target: Add
iSCSI fabric support for target v4.1"):
1) DataDigest CRC buffer overread (4 bytes past text_in).
text_in is kzalloc()'d at ALIGN(payload_length, 4). rx_size is then
incremented by ISCSI_CRC_LEN to make room for the received DataDigest
in the iovec, but the same (now-bumped) rx_size is passed as the
buffer length to iscsit_crc_buf():
if (conn->conn_ops->DataDigest) {
...
rx_size += ISCSI_CRC_LEN;
}
...
if (conn->conn_ops->DataDigest) {
data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL);
iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so
when DataDigest is negotiated it reads 4 bytes past the end of the
text_in allocation. KASAN reproduces this directly on the unpatched
mainline tree as slab-out-of-bounds in crc32c() called from the Text
PDU path. The OOB bytes feed crc32c() and are then compared against
the initiator-supplied checksum, so the value does not flow back to
the attacker, but the kernel does read past the buffer on every Text
PDU with DataDigest=CRC32C.
Fix by passing the actual padded payload length
(ALIGN(payload_length, 4)) that was used for the kzalloc().
2) Stale cmd->text_in_ptr re-free (double-free) on ERL>0 bad DataDigest
drop.
On DataDigest mismatch with ErrorRecoveryLevel > 0 the handler
silently drops the PDU and lets the initiator plug the CmdSN gap:
kfree(text_in);
return 0;
cmd->text_in_ptr still points at the freed buffer. The next Text
Request on the same ITT re-enters iscsit_setup_text_cmd(), which
unconditionally does
kfree(cmd->text_in_ptr);
cmd->text_in_ptr = NULL;
freeing the same pointer a second time. Session teardown via
iscsit_release_cmd() has the same shape and hits the same double-free
if the connection is dropped before a second Text Request arrives.
On an unmodified mainline tree the bug-1 CRC overread fires first on
the initial valid Text Request and perturbs the subsequent state, so
#4 was isolated by building a kernel with only the bug-1 hunk of this
patch applied plus temporary printk() observability around the three
relevant kfree() sites. The observability prints are not part of
this patch. On that build, a three-PDU Text Request sequence after
login produces two back-to-back splats:
BUG: KASAN: double-free in iscsit_setup_text_cmd+0x??
BUG: KASAN: double-free in iscsit_release_cmd+0x??
showing the same pointer freed in the ERL>0 drop path and again in
iscsit_setup_text_cmd() (next Text Request on the same ITT) and once
more in iscsit_release_cmd() (session teardown). On distro kernels
with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free
becomes a remote kernel BUG(); on non-hardened kernels it corrupts
the slab freelist.
Fix by clearing cmd->text_in_ptr after the kfree() in the ERL>0 drop
path. With both hunks applied #4 is directly observable on the stock
tree without observability printks; fixing bug-1 alone would mask #4
less, not more, so the hunks are submitted together.
Both fixes are one-liners. The Text PDU state machine is unchanged and
the wire protocol is unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/target/iscsi/iscsi_target.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f7948af0dd03de84079dcd4dc215a69fd6fbb95d",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "badf178b76b0690851df00f4ca9cf2eb8eb0f963",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "6e22a1cdcc8277af4acc43710577157b77a02c5d",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "d3e9b79aa794f7a23e82de4d710e7d2df610e349",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "ec9f19d52074a191ed1756ed4a7d39fff1a2085c",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "89c81d1228c00fa6dd91de6c1c5aa1ef8a7875e3",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "5118ea225fe63b44207ba88047e4866e1ea43812",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "778c2ab142c625a8a8afa570e0f9b7873f445d99",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/target/iscsi/iscsi_target.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"lessThan": "3.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()\n\nTwo latent bugs in the Text-phase handler, both present since the\noriginal LIO integration in commit e48354ce078c (\"iscsi-target: Add\niSCSI fabric support for target v4.1\"):\n\n1) DataDigest CRC buffer overread (4 bytes past text_in).\n\n text_in is kzalloc()\u0027d at ALIGN(payload_length, 4). rx_size is then\n incremented by ISCSI_CRC_LEN to make room for the received DataDigest\n in the iovec, but the same (now-bumped) rx_size is passed as the\n buffer length to iscsit_crc_buf():\n\n if (conn-\u003econn_ops-\u003eDataDigest) {\n ...\n rx_size += ISCSI_CRC_LEN;\n }\n ...\n if (conn-\u003econn_ops-\u003eDataDigest) {\n data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL);\n\n iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so\n when DataDigest is negotiated it reads 4 bytes past the end of the\n text_in allocation. KASAN reproduces this directly on the unpatched\n mainline tree as slab-out-of-bounds in crc32c() called from the Text\n PDU path. The OOB bytes feed crc32c() and are then compared against\n the initiator-supplied checksum, so the value does not flow back to\n the attacker, but the kernel does read past the buffer on every Text\n PDU with DataDigest=CRC32C.\n\n Fix by passing the actual padded payload length\n (ALIGN(payload_length, 4)) that was used for the kzalloc().\n\n2) Stale cmd-\u003etext_in_ptr re-free (double-free) on ERL\u003e0 bad DataDigest\n drop.\n\n On DataDigest mismatch with ErrorRecoveryLevel \u003e 0 the handler\n silently drops the PDU and lets the initiator plug the CmdSN gap:\n\n kfree(text_in);\n return 0;\n\n cmd-\u003etext_in_ptr still points at the freed buffer. The next Text\n Request on the same ITT re-enters iscsit_setup_text_cmd(), which\n unconditionally does\n\n kfree(cmd-\u003etext_in_ptr);\n cmd-\u003etext_in_ptr = NULL;\n\n freeing the same pointer a second time. Session teardown via\n iscsit_release_cmd() has the same shape and hits the same double-free\n if the connection is dropped before a second Text Request arrives.\n\n On an unmodified mainline tree the bug-1 CRC overread fires first on\n the initial valid Text Request and perturbs the subsequent state, so\n #4 was isolated by building a kernel with only the bug-1 hunk of this\n patch applied plus temporary printk() observability around the three\n relevant kfree() sites. The observability prints are not part of\n this patch. On that build, a three-PDU Text Request sequence after\n login produces two back-to-back splats:\n\n BUG: KASAN: double-free in iscsit_setup_text_cmd+0x??\n BUG: KASAN: double-free in iscsit_release_cmd+0x??\n\n showing the same pointer freed in the ERL\u003e0 drop path and again in\n iscsit_setup_text_cmd() (next Text Request on the same ITT) and once\n more in iscsit_release_cmd() (session teardown). On distro kernels\n with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free\n becomes a remote kernel BUG(); on non-hardened kernels it corrupts\n the slab freelist.\n\n Fix by clearing cmd-\u003etext_in_ptr after the kfree() in the ERL\u003e0 drop\n path. With both hunks applied #4 is directly observable on the stock\n tree without observability printks; fixing bug-1 alone would mask #4\n less, not more, so the hunks are submitted together.\n\nBoth fixes are one-liners. The Text PDU state machine is unchanged and\nthe wire protocol is unaffected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in the in-kernel LIO iSCSI target, reachable by sending iSCSI Text PDUs over TCP after connection setup on the network-facing iSCSI portal (typically port 3260), analogous to nfsd/ksmbd network exposure.\nAC:L - An attacker fully controls login parameter negotiation (DataDigest=CRC32C) and subsequent Text PDU content; the CRC overread fires deterministically on every qualifying Text PDU, and the double-free is reliably triggered by sending a bad DataDigest followed by another Text PDU on the same ITT when ERL\u003e0.\nPR:N - No Linux OS privileges are required; the default discovery session permits unauthenticated login (AuthMethod=None, authentication disabled), after which SendTargets Text requests reach the vulnerable handler without any credentials.\nUI:N - Exploitation requires only crafted iSCSI protocol traffic from the attacker; no victim user action such as mounting a filesystem or clicking a link is needed.\nS:U - The vulnerability corrupts kernel heap memory within the iSCSI target subsystem on the host; it does not cross a VM, container, or IOMMU security boundary.\nC:H - The CRC path performs a slab out-of-bounds read past the text_in allocation, and the double-free is a use-after-free class bug that reads freed heap metadata; per kernel guidance both OOB reads and UAFs warrant High confidentiality impact.\nI:H - The double-free corrupts the slab freelist (triggering CONFIG_SLAB_FREELIST_HARDENED BUG() on hardened kernels), providing a classic heap corruption primitive that can be leveraged for arbitrary kernel memory writes and code execution.\nA:H - The double-free provably crashes the kernel (KASAN splat or SLAB_FREELIST_HARDENED BUG()), and the heap corruption can cause kernel panics; any UAF is scored as High availability impact per kernel guidance."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:36:57.546Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f7948af0dd03de84079dcd4dc215a69fd6fbb95d"
},
{
"url": "https://git.kernel.org/stable/c/badf178b76b0690851df00f4ca9cf2eb8eb0f963"
},
{
"url": "https://git.kernel.org/stable/c/6e22a1cdcc8277af4acc43710577157b77a02c5d"
},
{
"url": "https://git.kernel.org/stable/c/d3e9b79aa794f7a23e82de4d710e7d2df610e349"
},
{
"url": "https://git.kernel.org/stable/c/ec9f19d52074a191ed1756ed4a7d39fff1a2085c"
},
{
"url": "https://git.kernel.org/stable/c/89c81d1228c00fa6dd91de6c1c5aa1ef8a7875e3"
},
{
"url": "https://git.kernel.org/stable/c/5118ea225fe63b44207ba88047e4866e1ea43812"
},
{
"url": "https://git.kernel.org/stable/c/778c2ab142c625a8a8afa570e0f9b7873f445d99"
}
],
"title": "scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63888",
"datePublished": "2026-07-19T14:55:00.803Z",
"dateReserved": "2026-07-19T07:54:57.018Z",
"dateUpdated": "2026-08-05T12:36:57.546Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52994 (GCVE-0-2026-52994)
Vulnerability from cvelistv5
Published
2026-06-24 16:29
Modified
2026-06-24 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting
virtio_transport_init_zcopy_skb() uses iter->count as the size argument
for msg_zerocopy_realloc(), which in turn passes it to
mm_account_pinned_pages() for RLIMIT_MEMLOCK accounting. However, this
function is called after virtio_transport_fill_skb() has already consumed
the iterator via __zerocopy_sg_from_iter(), so on the last skb, iter->count
will be 0, skipping the RLIMIT_MEMLOCK enforcement.
Pass pkt_len (the total bytes being sent) as an explicit parameter to
virtio_transport_init_zcopy_skb() instead of reading the already-consumed
iter->count.
This matches TCP and UDP, which both call msg_zerocopy_realloc() with
the original message size.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/virtio_transport_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6af1736b5810bc8a4a43a8518530113f5a757dc1",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
},
{
"lessThan": "d0117950075f0a9d5944980784c719d8ebcd4bff",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
},
{
"lessThan": "1cb36e252211506f51095fe7ced8286cc77b4c80",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/virtio_transport_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting\n\nvirtio_transport_init_zcopy_skb() uses iter-\u003ecount as the size argument\nfor msg_zerocopy_realloc(), which in turn passes it to\nmm_account_pinned_pages() for RLIMIT_MEMLOCK accounting. However, this\nfunction is called after virtio_transport_fill_skb() has already consumed\nthe iterator via __zerocopy_sg_from_iter(), so on the last skb, iter-\u003ecount\nwill be 0, skipping the RLIMIT_MEMLOCK enforcement.\n\nPass pkt_len (the total bytes being sent) as an explicit parameter to\nvirtio_transport_init_zcopy_skb() instead of reading the already-consumed\niter-\u003ecount.\n\nThis matches TCP and UDP, which both call msg_zerocopy_realloc() with\nthe original message size."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-24T16:29:07.360Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6af1736b5810bc8a4a43a8518530113f5a757dc1"
},
{
"url": "https://git.kernel.org/stable/c/d0117950075f0a9d5944980784c719d8ebcd4bff"
},
{
"url": "https://git.kernel.org/stable/c/1cb36e252211506f51095fe7ced8286cc77b4c80"
}
],
"title": "vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52994",
"datePublished": "2026-06-24T16:29:07.360Z",
"dateReserved": "2026-06-09T07:44:35.377Z",
"dateUpdated": "2026-06-24T16:29:07.360Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68086 (GCVE-0-2026-68086)
Vulnerability from cvelistv5
Published
2026-08-10 11:51
Modified
2026-08-10 11:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/khugepaged: write all dirty file folios when collapsing
[There is no upstream commit, as this code was removed by upstream
commit 044925f9b565 ("mm: fs: remove filemap_nr_thps*() functions and their users")]
As-is, khugepaged and writable-file opening exclude each other. A file
cannot be open writeable and have THPs (because the filesystem is not aware
of them). khugepaged will never collapse file pages for files that are
opened writeable. On an open(O_RDWR/O_WRONLY), the page cache for that
particular file is dropped. This is fine because nothing could've been
dirtied.
However, there is an edge-case: collapse_file() might not be able to
coexist with concurrent writers, but it can coexist with dirty folios
(from previous writers). Therefore, the following can happen:
open(file, O_RDWR)
write(file)
close(file)
madvise(file_mapping, MADV_COLLAPSE, some non-dirty range)
open(file, O_RDWR)
nr_thps > 0
truncate_inode_pages()
/* THPs are cleared out, but so are the dirty folios */
When this edge-case happens, there is data loss, as the dirty folios are
fully discarded.
Fix it by fully writing back the page cache (and waiting) when collapsing
file THPs. Doing so provides the guarantee that no dirty folio will be
observed while there are active THPs. To fully ensure this is safe, the
invalidate_lock needs to be held while doing the writeout, so that
do_dentry_open()'s page cache truncation excludes this write-and-wait.
As a side effect, move the nr_thps counter bumping outside the i_pages
lock. This is correct since the counter itself is an atomic_t and the
producer <-> consumer correctness is provided by a full memory barrier:
smp_mb() in collapse_file()/memory barrier implied by full ordering in
get_write_access() -> atomic_inc_unless_negative().
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/khugepaged.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2dfe9f5c91d0963058f8a5e46e1c2a908382cc46",
"status": "affected",
"version": "99cb0dbd47a15d395bf3faa78dc122bc5efe3fc0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/khugepaged.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/khugepaged: write all dirty file folios when collapsing\n\n[There is no upstream commit, as this code was removed by upstream\n commit 044925f9b565 (\"mm: fs: remove filemap_nr_thps*() functions and their users\")]\n\nAs-is, khugepaged and writable-file opening exclude each other. A file\ncannot be open writeable and have THPs (because the filesystem is not aware\nof them). khugepaged will never collapse file pages for files that are\nopened writeable. On an open(O_RDWR/O_WRONLY), the page cache for that\nparticular file is dropped. This is fine because nothing could\u0027ve been\ndirtied.\n\nHowever, there is an edge-case: collapse_file() might not be able to\ncoexist with concurrent writers, but it can coexist with dirty folios\n(from previous writers). Therefore, the following can happen:\n\nopen(file, O_RDWR)\nwrite(file)\nclose(file)\nmadvise(file_mapping, MADV_COLLAPSE, some non-dirty range)\nopen(file, O_RDWR)\n nr_thps \u003e 0\n truncate_inode_pages()\n /* THPs are cleared out, but so are the dirty folios */\n\nWhen this edge-case happens, there is data loss, as the dirty folios are\nfully discarded.\n\nFix it by fully writing back the page cache (and waiting) when collapsing\nfile THPs. Doing so provides the guarantee that no dirty folio will be\nobserved while there are active THPs. To fully ensure this is safe, the\ninvalidate_lock needs to be held while doing the writeout, so that\ndo_dentry_open()\u0027s page cache truncation excludes this write-and-wait.\n\nAs a side effect, move the nr_thps counter bumping outside the i_pages\nlock. This is correct since the counter itself is an atomic_t and the\nproducer \u003c-\u003e consumer correctness is provided by a full memory barrier:\nsmp_mb() in collapse_file()/memory barrier implied by full ordering in\nget_write_access() -\u003e atomic_inc_unless_negative()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-10T11:51:40.304Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2dfe9f5c91d0963058f8a5e46e1c2a908382cc46"
}
],
"title": "mm/khugepaged: write all dirty file folios when collapsing",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68086",
"datePublished": "2026-08-10T11:51:40.304Z",
"dateReserved": "2026-07-30T09:28:09.367Z",
"dateUpdated": "2026-08-10T11:51:40.304Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53228 (GCVE-0-2026-53228)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-08-05 12:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: sit: reload inner IPv6 header after GSO offloads
ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function
entry and continues using it after iptunnel_handle_offloads().
For GSO skbs, iptunnel_handle_offloads() calls skb_header_unclone().
When the skb header is cloned, skb_header_unclone() can call
pskb_expand_head(), which may move the skb head. The pskb_expand_head()
contract requires pointers into the skb header to be reloaded after the
call.
If the later skb_realloc_headroom() branch is not taken, SIT uses the
stale iph6 pointer to read the inner hop limit and DS field. That can
read from a freed skb head after the old head's remaining clone is
released.
Reload iph6 after the offload helper succeeds and before subsequent
reads from the inner IPv6 header. Keep the existing reload after
skb_realloc_headroom(), since that branch can also replace the skb.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 14909664e4e192f4c6f6fcdccd9919af7cf783ab Version: 14909664e4e192f4c6f6fcdccd9919af7cf783ab Version: 14909664e4e192f4c6f6fcdccd9919af7cf783ab Version: 14909664e4e192f4c6f6fcdccd9919af7cf783ab Version: 14909664e4e192f4c6f6fcdccd9919af7cf783ab Version: 14909664e4e192f4c6f6fcdccd9919af7cf783ab Version: 14909664e4e192f4c6f6fcdccd9919af7cf783ab Version: 14909664e4e192f4c6f6fcdccd9919af7cf783ab |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/sit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fddd41445a0537b093e6b3f6232c9933cad1e48b",
"status": "affected",
"version": "14909664e4e192f4c6f6fcdccd9919af7cf783ab",
"versionType": "git"
},
{
"lessThan": "1132e5edc2866c3530be17622153a597095f0e43",
"status": "affected",
"version": "14909664e4e192f4c6f6fcdccd9919af7cf783ab",
"versionType": "git"
},
{
"lessThan": "9c67b44edb3598d234efae6e44649eb993c03da5",
"status": "affected",
"version": "14909664e4e192f4c6f6fcdccd9919af7cf783ab",
"versionType": "git"
},
{
"lessThan": "0bfa7bba1f41aaf5f0604dc712bb4701493e3aa0",
"status": "affected",
"version": "14909664e4e192f4c6f6fcdccd9919af7cf783ab",
"versionType": "git"
},
{
"lessThan": "59f80c919713250fe5d25a4d9aea4e49580fa1d4",
"status": "affected",
"version": "14909664e4e192f4c6f6fcdccd9919af7cf783ab",
"versionType": "git"
},
{
"lessThan": "2fa49b2715e1bad12ce3b0fa64e234d9582c8193",
"status": "affected",
"version": "14909664e4e192f4c6f6fcdccd9919af7cf783ab",
"versionType": "git"
},
{
"lessThan": "cb658c2f5f7977c2a1c77c9f239f4bc8196edb5c",
"status": "affected",
"version": "14909664e4e192f4c6f6fcdccd9919af7cf783ab",
"versionType": "git"
},
{
"lessThan": "f0e42f0c4337b1f220de1ddd63f47197c7dee4de",
"status": "affected",
"version": "14909664e4e192f4c6f6fcdccd9919af7cf783ab",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/sit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"lessThan": "3.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sit: reload inner IPv6 header after GSO offloads\n\nipip6_tunnel_xmit() caches the inner IPv6 header pointer at function\nentry and continues using it after iptunnel_handle_offloads().\n\nFor GSO skbs, iptunnel_handle_offloads() calls skb_header_unclone().\nWhen the skb header is cloned, skb_header_unclone() can call\npskb_expand_head(), which may move the skb head. The pskb_expand_head()\ncontract requires pointers into the skb header to be reloaded after the\ncall.\n\nIf the later skb_realloc_headroom() branch is not taken, SIT uses the\nstale iph6 pointer to read the inner hop limit and DS field. That can\nread from a freed skb head after the old head\u0027s remaining clone is\nreleased.\n\nReload iph6 after the offload helper succeeds and before subsequent\nreads from the inner IPv6 header. Keep the existing reload after\nskb_realloc_headroom(), since that branch can also replace the skb."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable SIT transmit path can be reached by network-triggered IPv6 traffic in a reasonable deployment where a public service or router sends large TCP/GSO packets through a configured SIT tunnel.\nAC:L - There is no race or fragile timing requirement; GSO and header-cloned TCP skbs are normal for large TCP transmissions, and the attacker can repeatedly trigger them with network traffic.\nPR:N - In the network-triggered scenario, the attacker does not need local privileges or authentication; the required SIT configuration is an environmental precondition on the victim.\nUI:N - No victim user action is required beyond the system processing network traffic through the configured SIT tunnel.\nS:U - The impact remains within the kernel and its networking security authority, with no VM, IOMMU, or separate security-scope boundary crossed.\nC:H - The stale inner IPv6 header pointer can read from freed skb head memory after `skb_header_unclone()`/`pskb_expand_head()`, making this a kernel use-after-free read. Per kernel CVSS guidance, use-after-free conditions are scored with high confidentiality impact.\nI:H - Although the immediate stale access feeds header fields, it is a kernel use-after-free in attacker-triggerable networking memory, and kernel UAFs are treated as potentially exploitable for heap manipulation and integrity compromise.\nA:H - Use-after-free in the kernel networking transmit path can lead to oops, panic, or repeated crash conditions, especially under memory debugging or unfavorable heap reuse."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:34:20.273Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fddd41445a0537b093e6b3f6232c9933cad1e48b"
},
{
"url": "https://git.kernel.org/stable/c/1132e5edc2866c3530be17622153a597095f0e43"
},
{
"url": "https://git.kernel.org/stable/c/9c67b44edb3598d234efae6e44649eb993c03da5"
},
{
"url": "https://git.kernel.org/stable/c/0bfa7bba1f41aaf5f0604dc712bb4701493e3aa0"
},
{
"url": "https://git.kernel.org/stable/c/59f80c919713250fe5d25a4d9aea4e49580fa1d4"
},
{
"url": "https://git.kernel.org/stable/c/2fa49b2715e1bad12ce3b0fa64e234d9582c8193"
},
{
"url": "https://git.kernel.org/stable/c/cb658c2f5f7977c2a1c77c9f239f4bc8196edb5c"
},
{
"url": "https://git.kernel.org/stable/c/f0e42f0c4337b1f220de1ddd63f47197c7dee4de"
}
],
"title": "ipv6: sit: reload inner IPv6 header after GSO offloads",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53228",
"datePublished": "2026-06-25T08:39:27.893Z",
"dateReserved": "2026-06-09T07:44:35.393Z",
"dateUpdated": "2026-08-05T12:34:20.273Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64497 (GCVE-0-2026-64497)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iio: chemical: scd30: Cleanup initializations and fix sign-extension bug
Include linux/bitfield.h for FIELD_GET().
Create new macros for bit manipulation in combination with manual bit
manipulation being replaced with FIELD_GET().
The current variable declaration and initializations are barely readable
and use comma separations across multiple lines. Refactor the
initializations so that mantissa and exp have separate declarations and
sign gets initialized later.
In addition (and due to the nature of the cleanup), fix a sign-extension
bug where, float32 would get bitwise anded with ~BIT(31)
(which is 0xFFFFFFFF7FFFFFFF) which corrupted the exponent.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 64b3d8b1b0f5c16c19045785e4da8391ae35ec99 Version: 64b3d8b1b0f5c16c19045785e4da8391ae35ec99 Version: 64b3d8b1b0f5c16c19045785e4da8391ae35ec99 Version: 64b3d8b1b0f5c16c19045785e4da8391ae35ec99 Version: 64b3d8b1b0f5c16c19045785e4da8391ae35ec99 Version: 64b3d8b1b0f5c16c19045785e4da8391ae35ec99 Version: 64b3d8b1b0f5c16c19045785e4da8391ae35ec99 Version: 64b3d8b1b0f5c16c19045785e4da8391ae35ec99 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iio/chemical/scd30_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0ccff849bde90973e6c13a666f6ceab5c55b30d4",
"status": "affected",
"version": "64b3d8b1b0f5c16c19045785e4da8391ae35ec99",
"versionType": "git"
},
{
"lessThan": "1821bcacd8ac5b214c53be16cbb8172bf193f0b6",
"status": "affected",
"version": "64b3d8b1b0f5c16c19045785e4da8391ae35ec99",
"versionType": "git"
},
{
"lessThan": "40bb0fdb37f441c9c9f52bf58bbd8a0ca3cc9598",
"status": "affected",
"version": "64b3d8b1b0f5c16c19045785e4da8391ae35ec99",
"versionType": "git"
},
{
"lessThan": "b131f0011dfef72350f4e3f11df94dc3e6b46065",
"status": "affected",
"version": "64b3d8b1b0f5c16c19045785e4da8391ae35ec99",
"versionType": "git"
},
{
"lessThan": "8d4a46e971cf846bda98b20d4cabfa21c1276e5f",
"status": "affected",
"version": "64b3d8b1b0f5c16c19045785e4da8391ae35ec99",
"versionType": "git"
},
{
"lessThan": "82accdd57404399eddf3d56fd9beda7c61307388",
"status": "affected",
"version": "64b3d8b1b0f5c16c19045785e4da8391ae35ec99",
"versionType": "git"
},
{
"lessThan": "d49ff54b2784aa56a7c97982de713604de89d23a",
"status": "affected",
"version": "64b3d8b1b0f5c16c19045785e4da8391ae35ec99",
"versionType": "git"
},
{
"lessThan": "60d877910a43c305b5165131b258a17b1d772d57",
"status": "affected",
"version": "64b3d8b1b0f5c16c19045785e4da8391ae35ec99",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iio/chemical/scd30_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: scd30: Cleanup initializations and fix sign-extension bug\n\nInclude linux/bitfield.h for FIELD_GET().\n\nCreate new macros for bit manipulation in combination with manual bit\nmanipulation being replaced with FIELD_GET().\n\nThe current variable declaration and initializations are barely readable\nand use comma separations across multiple lines. Refactor the\ninitializations so that mantissa and exp have separate declarations and\nsign gets initialized later.\n\nIn addition (and due to the nature of the cleanup), fix a sign-extension\nbug where, float32 would get bitwise anded with ~BIT(31)\n(which is 0xFFFFFFFF7FFFFFFF) which corrupted the exponent."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:45.940Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0ccff849bde90973e6c13a666f6ceab5c55b30d4"
},
{
"url": "https://git.kernel.org/stable/c/1821bcacd8ac5b214c53be16cbb8172bf193f0b6"
},
{
"url": "https://git.kernel.org/stable/c/40bb0fdb37f441c9c9f52bf58bbd8a0ca3cc9598"
},
{
"url": "https://git.kernel.org/stable/c/b131f0011dfef72350f4e3f11df94dc3e6b46065"
},
{
"url": "https://git.kernel.org/stable/c/8d4a46e971cf846bda98b20d4cabfa21c1276e5f"
},
{
"url": "https://git.kernel.org/stable/c/82accdd57404399eddf3d56fd9beda7c61307388"
},
{
"url": "https://git.kernel.org/stable/c/d49ff54b2784aa56a7c97982de713604de89d23a"
},
{
"url": "https://git.kernel.org/stable/c/60d877910a43c305b5165131b258a17b1d772d57"
}
],
"title": "iio: chemical: scd30: Cleanup initializations and fix sign-extension bug",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64497",
"datePublished": "2026-07-25T08:51:53.917Z",
"dateReserved": "2026-07-19T15:36:31.792Z",
"dateUpdated": "2026-08-17T04:56:45.940Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68091 (GCVE-0-2026-68091)
Vulnerability from cvelistv5
Published
2026-08-10 11:51
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: wacom: stop hardware after post-start probe failures
wacom_parse_and_register() starts HID hardware before registering inputs
and initializing pad LEDs/remotes. Those later steps can fail, but their
error paths currently release Wacom resources without stopping the HID
hardware.
Route post-hid_hw_start() failures through hid_hw_stop() before
releasing driver resources.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f304eb483393f135ab479d02da6f5dc7d9b51cd6 Version: 853307924a9003b3142b5253b1caa6625fbad9fc Version: e5c6c8ef3e4d3a88407404daafbf2c6be62f2185 Version: fc41101a94b11cd0d5ad8e213b2b6965f248d653 Version: c1d6708bf0d3dd976460d435373cf5abf21ce258 Version: c1d6708bf0d3dd976460d435373cf5abf21ce258 Version: c1d6708bf0d3dd976460d435373cf5abf21ce258 Version: c1d6708bf0d3dd976460d435373cf5abf21ce258 Version: d943536197c1a05e377452af4ec7942e11d018f4 Version: dbaca8fa9ec2c5aa55ec515686ce3b9007554eab Version: 79187e8099a9feb550916dbfb962497522022b6d Version: 5.10.210 ≤ Version: 5.15.149 ≤ Version: 6.1.79 ≤ Version: 6.6.18 ≤ Version: 4.19.307 ≤ Version: 5.4.269 ≤ Version: 6.7.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/wacom_sys.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5a7ca028facf04921b2c1c2e4d1ee7f282510555",
"status": "affected",
"version": "f304eb483393f135ab479d02da6f5dc7d9b51cd6",
"versionType": "git"
},
{
"lessThan": "3e6473a4f0596182acdda5219b4bebfbee76514f",
"status": "affected",
"version": "853307924a9003b3142b5253b1caa6625fbad9fc",
"versionType": "git"
},
{
"lessThan": "46d8b8c85ae0589fb85746a64e8908160e52aac3",
"status": "affected",
"version": "e5c6c8ef3e4d3a88407404daafbf2c6be62f2185",
"versionType": "git"
},
{
"lessThan": "1a1ebdcb56ae58a0ee2c54dd15d75121e30424e3",
"status": "affected",
"version": "fc41101a94b11cd0d5ad8e213b2b6965f248d653",
"versionType": "git"
},
{
"lessThan": "75eb2173b63ab41c24d80cd641af18f3c117a267",
"status": "affected",
"version": "c1d6708bf0d3dd976460d435373cf5abf21ce258",
"versionType": "git"
},
{
"lessThan": "416095e9a6037b4b39fcadd0d2bd77a8852211ec",
"status": "affected",
"version": "c1d6708bf0d3dd976460d435373cf5abf21ce258",
"versionType": "git"
},
{
"lessThan": "e2cc711a9df37f359159b21db56cea9c21f58a9c",
"status": "affected",
"version": "c1d6708bf0d3dd976460d435373cf5abf21ce258",
"versionType": "git"
},
{
"lessThan": "ec2612b8ad9e642596db011dd8b6568ef1edeaa1",
"status": "affected",
"version": "c1d6708bf0d3dd976460d435373cf5abf21ce258",
"versionType": "git"
},
{
"status": "affected",
"version": "d943536197c1a05e377452af4ec7942e11d018f4",
"versionType": "git"
},
{
"status": "affected",
"version": "dbaca8fa9ec2c5aa55ec515686ce3b9007554eab",
"versionType": "git"
},
{
"status": "affected",
"version": "79187e8099a9feb550916dbfb962497522022b6d",
"versionType": "git"
},
{
"lessThan": "5.10.261",
"status": "affected",
"version": "5.10.210",
"versionType": "semver"
},
{
"lessThan": "5.15.212",
"status": "affected",
"version": "5.15.149",
"versionType": "semver"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.79",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.18",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.307",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.269",
"versionType": "semver"
},
{
"lessThan": "6.8",
"status": "affected",
"version": "6.7.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/wacom_sys.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.10.210",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.15.149",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.79",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.307",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.269",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.7.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: wacom: stop hardware after post-start probe failures\n\nwacom_parse_and_register() starts HID hardware before registering inputs\nand initializing pad LEDs/remotes. Those later steps can fail, but their\nerror paths currently release Wacom resources without stopping the HID\nhardware.\n\nRoute post-hid_hw_start() failures through hid_hw_stop() before\nreleasing driver resources.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The flaw is in the Wacom HID driver probe path reached when a Wacom-class HID device is connected; Bluetooth Wacom tablets are widely deployed and let an adjacent attacker deliver crafted HID traffic without USB port access.\nAC:L - A malicious or fuzzed Wacom HID device can steer probe through post-hid_hw_start() failure paths and the scheduled init_work, reliably leaving HID hardware active after driver teardown.\nPR:N - Exploitation requires only presenting a rogue Wacom HID device over Bluetooth or USB; no prior local account, capability, or namespace privilege on the victim host is needed.\nUI:N - No victim interaction is required beyond the attacker initiating device connection; probe failure and continued HID activity occur automatically on the kernel hotplug path.\nS:U - Impact is kernel memory corruption and privilege escalation within the host kernel, not crossing a VM, container, or IOMMU security boundary.\nC:H - Continued HID callbacks and delayed work after wacom_release_resources() create a use-after-free on freed driver allocations, enabling arbitrary kernel memory disclosure.\nI:H - The dangling hardware/workqueue activity against freed Wacom state is a heap use-after-free that can be leveraged for arbitrary kernel writes and code execution.\nA:H - Accessing freed probe resources from still-running HID hardware or init_work can cause kernel oops, panic, or hang, producing complete system denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:39.275Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5a7ca028facf04921b2c1c2e4d1ee7f282510555"
},
{
"url": "https://git.kernel.org/stable/c/3e6473a4f0596182acdda5219b4bebfbee76514f"
},
{
"url": "https://git.kernel.org/stable/c/46d8b8c85ae0589fb85746a64e8908160e52aac3"
},
{
"url": "https://git.kernel.org/stable/c/1a1ebdcb56ae58a0ee2c54dd15d75121e30424e3"
},
{
"url": "https://git.kernel.org/stable/c/75eb2173b63ab41c24d80cd641af18f3c117a267"
},
{
"url": "https://git.kernel.org/stable/c/416095e9a6037b4b39fcadd0d2bd77a8852211ec"
},
{
"url": "https://git.kernel.org/stable/c/e2cc711a9df37f359159b21db56cea9c21f58a9c"
},
{
"url": "https://git.kernel.org/stable/c/ec2612b8ad9e642596db011dd8b6568ef1edeaa1"
}
],
"title": "HID: wacom: stop hardware after post-start probe failures",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68091",
"datePublished": "2026-08-10T11:51:46.683Z",
"dateReserved": "2026-07-30T09:28:09.367Z",
"dateUpdated": "2026-08-17T04:58:39.275Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64128 (GCVE-0-2026-64128)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
ISO data PDUs carry a packet-boundary flag indicating START, CONT, END
or SINGLE. The ISO_CONT branch of iso_recv() guards against a missing
ISO_START by checking conn->rx_len before touching conn->rx_skb, but
ISO_END does not.
If a peer sends an ISO_END as the first packet on a fresh ISO
connection, conn->rx_skb is still NULL and conn->rx_len is zero, so
skb_put(conn->rx_skb, ...) dereferences NULL and oopses. For BIS,
where receivers sync to a broadcaster without pairing, any broadcaster
on the air can trigger this.
Mirror the ISO_CONT check at the top of ISO_END so a stray end fragment
is logged and dropped instead of crashing the host.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ccf74f2390d60a2f9a75ef496d2564abb478f46a Version: ccf74f2390d60a2f9a75ef496d2564abb478f46a Version: ccf74f2390d60a2f9a75ef496d2564abb478f46a Version: ccf74f2390d60a2f9a75ef496d2564abb478f46a Version: ccf74f2390d60a2f9a75ef496d2564abb478f46a Version: ccf74f2390d60a2f9a75ef496d2564abb478f46a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/iso.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1c3d1e1696b72579b970e17999c503a14535205b",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
},
{
"lessThan": "3af41ee7ebecb0d5c8a504861f6cfad31345310f",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
},
{
"lessThan": "39f4a82e80c8f5ed2d6952d73fbafc895721a728",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
},
{
"lessThan": "61f2410a96dee808029e2ae4d6ef2dd635f3477f",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
},
{
"lessThan": "e3a799881c12d27596232636a607e2e3fa448d63",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
},
{
"lessThan": "84c24fb151fc1179355296d7ff29129ac7c42129",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/iso.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: drop ISO_END frames received without prior ISO_START\n\nISO data PDUs carry a packet-boundary flag indicating START, CONT, END\nor SINGLE. The ISO_CONT branch of iso_recv() guards against a missing\nISO_START by checking conn-\u003erx_len before touching conn-\u003erx_skb, but\nISO_END does not.\n\nIf a peer sends an ISO_END as the first packet on a fresh ISO\nconnection, conn-\u003erx_skb is still NULL and conn-\u003erx_len is zero, so\nskb_put(conn-\u003erx_skb, ...) dereferences NULL and oopses. For BIS,\nwhere receivers sync to a broadcaster without pairing, any broadcaster\non the air can trigger this.\n\nMirror the ISO_CONT check at the top of ISO_END so a stray end fragment\nis logged and dropped instead of crashing the host."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:24.678Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1c3d1e1696b72579b970e17999c503a14535205b"
},
{
"url": "https://git.kernel.org/stable/c/3af41ee7ebecb0d5c8a504861f6cfad31345310f"
},
{
"url": "https://git.kernel.org/stable/c/39f4a82e80c8f5ed2d6952d73fbafc895721a728"
},
{
"url": "https://git.kernel.org/stable/c/61f2410a96dee808029e2ae4d6ef2dd635f3477f"
},
{
"url": "https://git.kernel.org/stable/c/e3a799881c12d27596232636a607e2e3fa448d63"
},
{
"url": "https://git.kernel.org/stable/c/84c24fb151fc1179355296d7ff29129ac7c42129"
}
],
"title": "Bluetooth: ISO: drop ISO_END frames received without prior ISO_START",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64128",
"datePublished": "2026-07-19T15:40:24.678Z",
"dateReserved": "2026-07-19T07:54:57.036Z",
"dateUpdated": "2026-07-19T15:40:24.678Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64503 (GCVE-0-2026-64503)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
kxsd9_write_raw() takes a runtime PM reference with pm_runtime_get_sync()
but returns -EINVAL directly when a scale with a non-zero integer part is
requested, skipping the matching pm_runtime_put_autosuspend(). This leaks
a runtime PM usage-counter reference on every such write, after which the
device can no longer autosuspend.
Set the error code and fall through to the existing put instead of
returning early.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0 Version: 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0 Version: 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0 Version: 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0 Version: 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0 Version: 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0 Version: 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0 Version: 9a9a369d6178dd4e263c49085ce1b37e1e8f63a0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iio/accel/kxsd9.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a93fd69c1ab0854ac4f5b8439c26dfadb25dfd20",
"status": "affected",
"version": "9a9a369d6178dd4e263c49085ce1b37e1e8f63a0",
"versionType": "git"
},
{
"lessThan": "eeece4a85ece6f3837c75ef26a9b2bf5a1d0fcfc",
"status": "affected",
"version": "9a9a369d6178dd4e263c49085ce1b37e1e8f63a0",
"versionType": "git"
},
{
"lessThan": "191fcfeb729ededd8dd2a999c6bf351ddfa0cec7",
"status": "affected",
"version": "9a9a369d6178dd4e263c49085ce1b37e1e8f63a0",
"versionType": "git"
},
{
"lessThan": "36154171385a8a2444a4b3c6eaa0c5294cb02478",
"status": "affected",
"version": "9a9a369d6178dd4e263c49085ce1b37e1e8f63a0",
"versionType": "git"
},
{
"lessThan": "223703d6e8bed50b6a0b47e160877909518d94b9",
"status": "affected",
"version": "9a9a369d6178dd4e263c49085ce1b37e1e8f63a0",
"versionType": "git"
},
{
"lessThan": "6293211d142605bec435229ef0aa3668b8964164",
"status": "affected",
"version": "9a9a369d6178dd4e263c49085ce1b37e1e8f63a0",
"versionType": "git"
},
{
"lessThan": "13a91e8631cfeb68e5b7fd6687f194f5a86e83fe",
"status": "affected",
"version": "9a9a369d6178dd4e263c49085ce1b37e1e8f63a0",
"versionType": "git"
},
{
"lessThan": "44a5fd874bb6873bdaec59f722c1d57832fbc9df",
"status": "affected",
"version": "9a9a369d6178dd4e263c49085ce1b37e1e8f63a0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iio/accel/kxsd9.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: accel: kxsd9: fix runtime PM imbalance on write_raw() error\n\nkxsd9_write_raw() takes a runtime PM reference with pm_runtime_get_sync()\nbut returns -EINVAL directly when a scale with a non-zero integer part is\nrequested, skipping the matching pm_runtime_put_autosuspend(). This leaks\na runtime PM usage-counter reference on every such write, after which the\ndevice can no longer autosuspend.\n\nSet the error code and fall through to the existing put instead of\nreturning early."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:53.290Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a93fd69c1ab0854ac4f5b8439c26dfadb25dfd20"
},
{
"url": "https://git.kernel.org/stable/c/eeece4a85ece6f3837c75ef26a9b2bf5a1d0fcfc"
},
{
"url": "https://git.kernel.org/stable/c/191fcfeb729ededd8dd2a999c6bf351ddfa0cec7"
},
{
"url": "https://git.kernel.org/stable/c/36154171385a8a2444a4b3c6eaa0c5294cb02478"
},
{
"url": "https://git.kernel.org/stable/c/223703d6e8bed50b6a0b47e160877909518d94b9"
},
{
"url": "https://git.kernel.org/stable/c/6293211d142605bec435229ef0aa3668b8964164"
},
{
"url": "https://git.kernel.org/stable/c/13a91e8631cfeb68e5b7fd6687f194f5a86e83fe"
},
{
"url": "https://git.kernel.org/stable/c/44a5fd874bb6873bdaec59f722c1d57832fbc9df"
}
],
"title": "iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64503",
"datePublished": "2026-07-25T08:51:58.186Z",
"dateReserved": "2026-07-19T15:36:31.793Z",
"dateUpdated": "2026-08-17T04:56:53.290Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64576 (GCVE-0-2026-64576)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nexthop: initialize extack in nh_res_bucket_migrate()
nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
call_nexthop_res_bucket_notifiers(). When
nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns
-ENOMEM), the error is propagated back before any notifier sets
extack._msg, and the error path formats the stale pointer with
pr_err_ratelimited("%s\n", extack._msg). With CONFIG_INIT_STACK_NONE
this dereferences uninitialized stack memory:
Oops: general protection fault, probably for non-canonical address ...
KASAN: maybe wild-memory-access in range [...]
RIP: 0010:string (lib/vsprintf.c:730)
vsnprintf (lib/vsprintf.c:2945)
_printk (kernel/printk/printk.c:2504)
nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)
nh_res_table_upkeep (net/ipv4/nexthop.c:1866)
rtm_new_nexthop (net/ipv4/nexthop.c:3323)
rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)
netlink_sendmsg (net/netlink/af_netlink.c:1900)
Kernel panic - not syncing: Fatal exception
Zero-initialize extack so _msg is NULL on error paths that never set it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/nexthop.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eacd2e2117e8682f937967fda1022e7f1c22d91a",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "37bbd7e1d8df0bec3d187e961783e20c30533d2c",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "c0936c131a71657afc635d0db2ab096d15d473e1",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "d536bf205c71f700f6de2086038c3e1d77724715",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "18506d7263768d76ac8e057ba55a4d9da50aad66",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "6347c5314cee49f364aaf2e40ff15415a57a116e",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/nexthop.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: initialize extack in nh_res_bucket_migrate()\n\nnh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to\ncall_nexthop_res_bucket_notifiers(). When\nnh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns\n-ENOMEM), the error is propagated back before any notifier sets\nextack._msg, and the error path formats the stale pointer with\npr_err_ratelimited(\"%s\\n\", extack._msg). With CONFIG_INIT_STACK_NONE\nthis dereferences uninitialized stack memory:\n\n Oops: general protection fault, probably for non-canonical address ...\n KASAN: maybe wild-memory-access in range [...]\n RIP: 0010:string (lib/vsprintf.c:730)\n vsnprintf (lib/vsprintf.c:2945)\n _printk (kernel/printk/printk.c:2504)\n nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)\n nh_res_table_upkeep (net/ipv4/nexthop.c:1866)\n rtm_new_nexthop (net/ipv4/nexthop.c:3323)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n Kernel panic - not syncing: Fatal exception\n\nZero-initialize extack so _msg is NULL on error paths that never set it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via local RTM_NEWNEXTHOP over rtnetlink (sendmsg \u2192 rtnetlink_rcv_msg \u2192 rtm_new_nexthop \u2192 nh_res_table_upkeep \u2192 nh_res_bucket_migrate), not by processing remote packets.\nAC:L - An attacker can create resilient nexthop groups, ensure notifiers are registered (e.g. VXLAN pernet init), force bucket migration, and induce the kzalloc -ENOMEM path; stack contents are groomable, with no attacker-independent condition required.\nPR:L - rtnetlink_rcv_msg requires CAP_NET_ADMIN via netlink_net_capable() against the socket netns user_ns, which an unprivileged user obtains with unshare -Urn, so privileges are Low not High.\nUI:N - The attacker issues the netlink nexthop configuration and triggers migration themselves; no victim action is required.\nS:U - Impact stays within the host kernel networking authority; this is a local DoS/disclosure bug, not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - pr_err_ratelimited(\"%s\") dereferences an uninitialized extack._msg pointer as a C string, enabling an attacker-groomable wild kernel read into the log, consistent with treating unbounded wild/OOB reads as Confidentiality High.\nI:N - The defect only reads through the stale _msg pointer for printing; there is no write, free, or other memory-corruption integrity primitive.\nA:H - The wild %s dereference causes a general protection fault / KASAN wild-memory-access and kernel panic, as shown in the fix commit report, so Availability is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:57.222Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eacd2e2117e8682f937967fda1022e7f1c22d91a"
},
{
"url": "https://git.kernel.org/stable/c/37bbd7e1d8df0bec3d187e961783e20c30533d2c"
},
{
"url": "https://git.kernel.org/stable/c/c0936c131a71657afc635d0db2ab096d15d473e1"
},
{
"url": "https://git.kernel.org/stable/c/3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d"
},
{
"url": "https://git.kernel.org/stable/c/d536bf205c71f700f6de2086038c3e1d77724715"
},
{
"url": "https://git.kernel.org/stable/c/18506d7263768d76ac8e057ba55a4d9da50aad66"
},
{
"url": "https://git.kernel.org/stable/c/6347c5314cee49f364aaf2e40ff15415a57a116e"
}
],
"title": "nexthop: initialize extack in nh_res_bucket_migrate()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64576",
"datePublished": "2026-08-05T08:09:32.529Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:28:57.222Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64001 (GCVE-0-2026-64001)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-07-19 14:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: oss: Fix setup list UAF on proc write error
snd_pcm_oss_proc_write() links a newly allocated setup entry into the
OSS setup list before duplicating the task name. If the task-name
allocation fails, the error path frees the already linked entry and
leaves setup_list pointing at freed memory.
A later OSS device open can then walk the stale list entry in
snd_pcm_oss_look_for_setup() and dereference freed memory.
Allocate the task name and initialize the setup entry before publishing
the entry on setup_list. Also fetch the initial proc read iterator only
after taking setup_mutex, so all setup_list traversal follows the same
list lifetime rules.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/core/oss/pcm_oss.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8be4efd0dc0093eb7a02ad1aac936bca2a1f04ce",
"status": "affected",
"version": "060d77b9c04acd7aef60790398a53f731db8c8fe",
"versionType": "git"
},
{
"lessThan": "e13922bb97b4e6f94f8ac02d034f2d4bd65eeb3c",
"status": "affected",
"version": "060d77b9c04acd7aef60790398a53f731db8c8fe",
"versionType": "git"
},
{
"lessThan": "be387230dc22d870afd0e5d35912b07c2bc323bd",
"status": "affected",
"version": "060d77b9c04acd7aef60790398a53f731db8c8fe",
"versionType": "git"
},
{
"lessThan": "4cc54bdd54b337e77115be5b55577d1c58608eae",
"status": "affected",
"version": "060d77b9c04acd7aef60790398a53f731db8c8fe",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/core/oss/pcm_oss.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.17"
},
{
"lessThan": "2.6.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: oss: Fix setup list UAF on proc write error\n\nsnd_pcm_oss_proc_write() links a newly allocated setup entry into the\nOSS setup list before duplicating the task name. If the task-name\nallocation fails, the error path frees the already linked entry and\nleaves setup_list pointing at freed memory.\n\nA later OSS device open can then walk the stale list entry in\nsnd_pcm_oss_look_for_setup() and dereference freed memory.\n\nAllocate the task name and initialize the setup entry before publishing\nthe entry on setup_list. Also fetch the initial proc read iterator only\nafter taking setup_mutex, so all setup_list traversal follows the same\nlist lifetime rules."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:56:18.816Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8be4efd0dc0093eb7a02ad1aac936bca2a1f04ce"
},
{
"url": "https://git.kernel.org/stable/c/e13922bb97b4e6f94f8ac02d034f2d4bd65eeb3c"
},
{
"url": "https://git.kernel.org/stable/c/be387230dc22d870afd0e5d35912b07c2bc323bd"
},
{
"url": "https://git.kernel.org/stable/c/4cc54bdd54b337e77115be5b55577d1c58608eae"
}
],
"title": "ALSA: pcm: oss: Fix setup list UAF on proc write error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64001",
"datePublished": "2026-07-19T14:56:18.816Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-07-19T14:56:18.816Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68414 (GCVE-0-2026-68414)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: cancel sched scan results work on unregister
cfg80211_sched_scan_results() can queue rdev->sched_scan_res_wk from a
driver result notification while a scheduled scan request is present. The
work callback recovers the containing cfg80211_registered_device and then
locks the wiphy and walks the scheduled-scan request list.
wiphy_unregister() already makes the wiphy unreachable and drains rdev work
items before cfg80211_dev_free() can release the object, but it does not
drain sched_scan_res_wk. A queued or running result work item can therefore
cross the unregister/free boundary and access freed rdev state.
The buggy scenario involves two paths, with each column showing the order
within that path:
scheduled-scan result path: unregister/free path:
1. cfg80211_sched_scan_results() 1. interface teardown stops and
queues rdev->sched_scan_res_wk. removes the scheduled scan request.
2. cfg80211_wq starts the work 2. wiphy_unregister() drains other
item and recovers rdev. rdev work items.
3. The worker locks rdev->wiphy 3. cfg80211_dev_free() destroys and
and walks rdev state. frees rdev.
Cancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev
work items. cancel_work_sync() removes a pending result notification and
waits for an already running callback, so cfg80211_dev_free() cannot free
rdev while this work item is still active.
Validation reproduced this kernel report:
BUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530
Workqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211]
Read of size 8
Call trace:
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x630
cfg80211_sched_scan_results_wk+0x4a6/0x530
srso_alias_return_thunk+0x5/0xfbef5
__virt_addr_valid+0x224/0x430
kasan_report+0xac/0xe0
lockdep_hardirqs_on_prepare+0xea/0x1a0
process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212)
lock_is_held_type+0x8f/0x100
worker_thread+0x5ad/0xfd0
__kthread_parkme+0xc6/0x200
kthread+0x31e/0x410
trace_hardirqs_on+0x1a/0x170
ret_from_fork+0x576/0x810
__switch_to+0x57e/0xe20
__switch_to_asm+0x33/0x70
ret_from_fork_asm+0x1a/0x30
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c0fa1f3a4b021a5c6373169fd6c9bb4261d676a0",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "b51b42b974461fd0f688baad85f10e2b8ab215c5",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "3368457b4871ae8f0f88d19c9a3e6270e850ede6",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "308ffdf575560d7e7b8b21f1e3ca6276630f73bf",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "9293574ac208d18c11073538851fb69355beb3b5",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "b119c70b24776c8ab2a2c0515397b3b0ad4e66cd",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "edf0730be33696a1bd142792830d392129e495cc",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.0"
},
{
"lessThan": "3.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: cancel sched scan results work on unregister\n\ncfg80211_sched_scan_results() can queue rdev-\u003esched_scan_res_wk from a\ndriver result notification while a scheduled scan request is present. The\nwork callback recovers the containing cfg80211_registered_device and then\nlocks the wiphy and walks the scheduled-scan request list.\n\nwiphy_unregister() already makes the wiphy unreachable and drains rdev work\nitems before cfg80211_dev_free() can release the object, but it does not\ndrain sched_scan_res_wk. A queued or running result work item can therefore\ncross the unregister/free boundary and access freed rdev state.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nscheduled-scan result path: unregister/free path:\n1. cfg80211_sched_scan_results() 1. interface teardown stops and\n queues rdev-\u003esched_scan_res_wk. removes the scheduled scan request.\n2. cfg80211_wq starts the work 2. wiphy_unregister() drains other\n item and recovers rdev. rdev work items.\n3. The worker locks rdev-\u003ewiphy 3. cfg80211_dev_free() destroys and\n and walks rdev state. frees rdev.\n\nCancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev\nwork items. cancel_work_sync() removes a pending result notification and\nwaits for an already running callback, so cfg80211_dev_free() cannot free\nrdev while this work item is still active.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530\nWorkqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211]\nRead of size 8\nCall trace:\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x630\n cfg80211_sched_scan_results_wk+0x4a6/0x530\n srso_alias_return_thunk+0x5/0xfbef5\n __virt_addr_valid+0x224/0x430\n kasan_report+0xac/0xe0\n lockdep_hardirqs_on_prepare+0xea/0x1a0\n process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212)\n lock_is_held_type+0x8f/0x100\n worker_thread+0x5ad/0xfd0\n __kthread_parkme+0xc6/0x200\n kthread+0x31e/0x410\n trace_hardirqs_on+0x1a/0x170\n ret_from_fork+0x576/0x810\n __switch_to+0x57e/0xe20\n __switch_to_asm+0x33/0x70\n ret_from_fork_asm+0x1a/0x30"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The work item is queued from driver PNO/background-scan match notifications that are produced by received 802.11 frames, so an attacker within WiFi range can drive cfg80211_sched_scan_results() by beaconing SSIDs matching the device\u0027s scheduled-scan match set. This is 802.11 frame injection, i.e. adjacent network reach.\nAC:H - The UAF requires the result-notification work to be queued or running exactly while wiphy_unregister()/cfg80211_dev_free() tears the rdev down; the attacker can drive and time the result notifications but cannot force the device-removal/module-unload half of the race, which is a condition outside their control.\nPR:N - No credentials or association are needed \u2014 an unauthenticated attacker in range simply transmits beacons/probe responses matching the scheduled scan already running on the victim (started by the system\u0027s normal wpa_supplicant/NetworkManager PNO), and the driver notifies cfg80211 unconditionally.\nUI:N - Scheduled scan runs continuously in the background on typical laptop, phone and embedded WiFi deployments, and the unregister side is a system/device event; no victim action such as opening a file or mounting anything is required.\nS:U - The freed object and all corrupted state are cfg80211 kernel structures, so the impact stays within the kernel\u0027s own security authority with no crossing of a VM, IOMMU or sandbox boundary.\nC:H - The worker reads freed rdev memory and then feeds freed scheduled-scan request contents into nl80211_send_sched_scan(), leaking reclaimed slab data to userspace netlink listeners; a controlled reallocation of the freed rdev gives an arbitrary-read style disclosure primitive.\nI:H - After the free the worker performs writes into the freed object \u2014 mutex_lock on rdev-\u003ewiphy.mtx, spin_lock on rdev-\u003ebss_lock, clearing req-\u003ereport_results, and list/refcount manipulation in __cfg80211_bss_expire() \u2014 which corrupts whatever object reclaims the slab and is leverageable for control-flow hijack via heap spraying.\nA:H - The confirmed KASAN use-after-free in cfg80211_sched_scan_results_wk() corrupts and dereferences freed memory from a workqueue context, reliably producing an oops/panic and taking down the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:12.312Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c0fa1f3a4b021a5c6373169fd6c9bb4261d676a0"
},
{
"url": "https://git.kernel.org/stable/c/b51b42b974461fd0f688baad85f10e2b8ab215c5"
},
{
"url": "https://git.kernel.org/stable/c/3368457b4871ae8f0f88d19c9a3e6270e850ede6"
},
{
"url": "https://git.kernel.org/stable/c/308ffdf575560d7e7b8b21f1e3ca6276630f73bf"
},
{
"url": "https://git.kernel.org/stable/c/9293574ac208d18c11073538851fb69355beb3b5"
},
{
"url": "https://git.kernel.org/stable/c/b119c70b24776c8ab2a2c0515397b3b0ad4e66cd"
},
{
"url": "https://git.kernel.org/stable/c/edf0730be33696a1bd142792830d392129e495cc"
}
],
"title": "wifi: cfg80211: cancel sched scan results work on unregister",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68414",
"datePublished": "2026-08-10T12:04:34.459Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:12.312Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74488 (GCVE-0-2026-74488)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
mwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with
ieee80211_amsdu_to_8023s() and walks the resulting subframes. For each
subframe it passes the subframe data pointer to
mwifiex_process_tdls_action_frame(), but pairs it with skb->len, the
length of the A-MSDU parent, instead of rx_skb->len:
rx_skb = __skb_dequeue(&list);
rx_hdr = (struct rx_packet_hdr *)rx_skb->data;
if (ISSUPP_TDLS_ENABLED(priv->adapter->fw_cap_info) &&
ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) {
mwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr,
skb->len);
}
The parent is not a valid description of that buffer, and may not be
valid memory at all. ieee80211_amsdu_to_8023s() ends with
if (!reuse_skb)
dev_kfree_skb(skb);
and it only sets reuse_skb when the parent is linear, is not a
head_frag, and is being consumed as the *last* subframe. So when the
parent does not qualify for reuse it has already been freed, and the
read of skb->len is a use-after-free. When it is reused, skb->len is
the length of the last subframe, applied to every earlier subframe,
which over-states the buffer whenever an earlier subframe is shorter.
The callee cannot absorb a wrong length, because it derives its own
ceiling from the value it is given. Each frame type computes
ies_len = len - sizeof(struct ethhdr) - TDLS_*_FIX_LEN;
and the element walk is then bounded entirely against that ceiling,
for (end = pos + ies_len; pos + 1 < end; pos += 2 + pos[1]) {
u8 ie_len = pos[1];
if (pos + 2 + ie_len > end)
break;
so a too-large len moves end past the end of the subframe and the walk
reads and copies beyond it. The A-MSDU layout is chosen by the sender,
which makes the difference between the last subframe and a shorter
earlier one remotely selectable. Reaching this requires TDLS support in
firmware and the TDLS ethertype on the subframe.
The other caller, mwifiex_process_rx_packet(), is correct: it passes a
pointer and a length that describe the same region of the RX buffer.
Pass rx_skb->len, the length of the subframe actually being parsed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "707664027bb9307f7268eda403af7c4ccd9b8644",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "3b02275833a0d3e6583627995d614fa99bdf364f",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "a1f0f7dc7eb15754e6931b433edb7beb754c996a",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "25e5a3fe4f15e30f74eca42cbf3bcc3a3fbeda79",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "ece2ebb34247d573142617dfc534a9dc11ba59be",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "c9dcfe6b8b71369e1d732e2ff622c3696a2f032c",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "5a21ab03829cb6d2682c127f22e2b9cd63b4393f",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "99a948382af8a225e2d5e54a7052158cd6281cc6",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames\n\nmwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with\nieee80211_amsdu_to_8023s() and walks the resulting subframes. For each\nsubframe it passes the subframe data pointer to\nmwifiex_process_tdls_action_frame(), but pairs it with skb-\u003elen, the\nlength of the A-MSDU parent, instead of rx_skb-\u003elen:\n\n\trx_skb = __skb_dequeue(\u0026list);\n\trx_hdr = (struct rx_packet_hdr *)rx_skb-\u003edata;\n\tif (ISSUPP_TDLS_ENABLED(priv-\u003eadapter-\u003efw_cap_info) \u0026\u0026\n\t ntohs(rx_hdr-\u003eeth803_hdr.h_proto) == ETH_P_TDLS) {\n\t\tmwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr,\n\t\t\t\t\t\t skb-\u003elen);\n\t}\n\nThe parent is not a valid description of that buffer, and may not be\nvalid memory at all. ieee80211_amsdu_to_8023s() ends with\n\n\tif (!reuse_skb)\n\t\tdev_kfree_skb(skb);\n\nand it only sets reuse_skb when the parent is linear, is not a\nhead_frag, and is being consumed as the *last* subframe. So when the\nparent does not qualify for reuse it has already been freed, and the\nread of skb-\u003elen is a use-after-free. When it is reused, skb-\u003elen is\nthe length of the last subframe, applied to every earlier subframe,\nwhich over-states the buffer whenever an earlier subframe is shorter.\n\nThe callee cannot absorb a wrong length, because it derives its own\nceiling from the value it is given. Each frame type computes\n\n\ties_len = len - sizeof(struct ethhdr) - TDLS_*_FIX_LEN;\n\nand the element walk is then bounded entirely against that ceiling,\n\n\tfor (end = pos + ies_len; pos + 1 \u003c end; pos += 2 + pos[1]) {\n\t\tu8 ie_len = pos[1];\n\n\t\tif (pos + 2 + ie_len \u003e end)\n\t\t\tbreak;\n\nso a too-large len moves end past the end of the subframe and the walk\nreads and copies beyond it. The A-MSDU layout is chosen by the sender,\nwhich makes the difference between the last subframe and a shorter\nearlier one remotely selectable. Reaching this requires TDLS support in\nfirmware and the TDLS ethertype on the subframe.\n\nThe other caller, mwifiex_process_rx_packet(), is correct: it passes a\npointer and a length that describe the same region of the RX buffer.\n\nPass rx_skb-\u003elen, the length of the subframe actually being parsed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is reached when the mwifiex driver processes attacker-supplied A-MSDU TDLS frames received over WiFi from a nearby peer, AP, or injector on the same wireless segment, which is an adjacent RF attack vector rather than remote Internet or local syscall access.\nAC:L - Once TDLS-capable mwifiex firmware receives an A-MSDU, the attacker fully controls subframe sizes and TDLS content to trigger either the skb use-after-free or the overstated-length out-of-bounds parse reliably without depending on uncontrollable timing or memory layout.\nPR:N - Exploitation requires only the ability to deliver crafted 802.11 data frames to the victim radio; it does not require any local account, capability, or root access on the Linux host and is not gated by user-namespace privilege boundaries.\nUI:N - No victim user action beyond normal wireless operation is required; the driver parses malicious TDLS subframes automatically during receive and A-MSDU decomposition before forwarding traffic to the network stack.\nS:U - Impact is confined to kernel memory corruption and driver state within the host kernel security authority; it does not by itself cross a VM, container, or IOMMU boundary to affect a separate security domain.\nC:H - The skb use-after-free reads freed sk_buff metadata and the inflated length drives an out-of-bounds IE walk that reads kernel memory beyond the subframe, including attacker-positioned bytes from subsequent A-MSDU subframes, enabling substantial information disclosure.\nI:H - The same out-of-bounds parse copies attacker-controlled IE data from beyond the subframe into heap-allocated sta_node/tdls_cap structures via memcpy, providing a memory-corruption primitive that can be developed into arbitrary kernel write or code execution.\nA:H - Reading skb-\u003elen after the parent A-MSDU skb may already be freed can immediately fault or corrupt memory, and the out-of-bounds TDLS element parsing can provoke kernel oopses or panics even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:43.361Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/707664027bb9307f7268eda403af7c4ccd9b8644"
},
{
"url": "https://git.kernel.org/stable/c/3b02275833a0d3e6583627995d614fa99bdf364f"
},
{
"url": "https://git.kernel.org/stable/c/a1f0f7dc7eb15754e6931b433edb7beb754c996a"
},
{
"url": "https://git.kernel.org/stable/c/25e5a3fe4f15e30f74eca42cbf3bcc3a3fbeda79"
},
{
"url": "https://git.kernel.org/stable/c/ece2ebb34247d573142617dfc534a9dc11ba59be"
},
{
"url": "https://git.kernel.org/stable/c/c9dcfe6b8b71369e1d732e2ff622c3696a2f032c"
},
{
"url": "https://git.kernel.org/stable/c/5a21ab03829cb6d2682c127f22e2b9cd63b4393f"
},
{
"url": "https://git.kernel.org/stable/c/99a948382af8a225e2d5e54a7052158cd6281cc6"
}
],
"title": "wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74488",
"datePublished": "2026-08-15T12:27:18.867Z",
"dateReserved": "2026-08-15T05:44:03.905Z",
"dateUpdated": "2026-08-19T16:37:43.361Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63887 (GCVE-0-2026-63887)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
iscsi_encode_text_output() concatenates "key=value\0" records into
login->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer
allocated in iscsit_alloc_login_setup_buffer(). The three sprintf() call
sites in this function (lines 1398, 1411, 1424 in v7.1-rc2) never check
the remaining buffer capacity:
*length += sprintf(output_buf, "%s=%s", er->key, er->value);
*length += 1;
output_buf = textbuf + *length;
The 8192-byte ceiling at iscsi_target_check_login_request() bounds the
*input* Login PDU payload, but a single PDU can carry up to 2048 minimal
four-byte "a=b\0" pairs, each unknown key expanding to a 16-byte
"a=NotUnderstood\0" output record via iscsi_add_notunderstood_response().
2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB
heap overrun in the kmalloc-8k slab.
The fix introduces a static iscsi_encode_text_record() helper that uses
snprintf() with a per-call bounds check against the remaining buffer,
and threads a u32 textbuf_size parameter through
iscsi_encode_text_output(). Both call sites in
iscsi_target_handle_csg_zero() (PHASE_SECURITY) and
iscsi_target_handle_csg_one() (PHASE_OPERATIONAL) pass
MAX_KEY_VALUE_PAIRS. On overflow the encoder logs the condition, calls
iscsi_release_extra_responses() to drop queued records, and returns -1;
both caller sites now emit ISCSI_STATUS_CLS_INITIATOR_ERR /
ISCSI_LOGIN_STATUS_INIT_ERR via iscsit_tx_login_rsp() before returning,
so the initiator sees an explicit failed-login response rather than a
silent connection drop. (Prior to this patch only the PHASE_OPERATIONAL
caller did that; the PHASE_SECURITY caller is converted to the same
shape.)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 Version: e48354ce078c079996f89d715dfa44814b4eba01 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/target/iscsi/iscsi_target_nego.c",
"drivers/target/iscsi/iscsi_target_parameters.c",
"drivers/target/iscsi/iscsi_target_parameters.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cb84e974fb172bc71386289f37b78ea679410b39",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "b19382dfc6e7dee6d3859ba44b6ca29e97a51627",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "efe633e600a0ac68357206fede21b1ac8178f3b8",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "4e9f0c4a645c995bc75c06c7b3644254ffb4c76b",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "30bf335e8fe170322080ee001f05ca29c50680b3",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "594a40360012ce5f94c715d5e3b20fa3af7d525a",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "26e4a304b7e6f1338c675d527608d32549c091db",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
},
{
"lessThan": "bf33e01f88388c43e285492a63e539df6ffed64c",
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/target/iscsi/iscsi_target_nego.c",
"drivers/target/iscsi/iscsi_target_parameters.c",
"drivers/target/iscsi/iscsi_target_parameters.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"lessThan": "3.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf\n\niscsi_encode_text_output() concatenates \"key=value\\0\" records into\nlogin-\u003ersp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer\nallocated in iscsit_alloc_login_setup_buffer(). The three sprintf() call\nsites in this function (lines 1398, 1411, 1424 in v7.1-rc2) never check\nthe remaining buffer capacity:\n\n\t*length += sprintf(output_buf, \"%s=%s\", er-\u003ekey, er-\u003evalue);\n\t*length += 1;\n\toutput_buf = textbuf + *length;\n\nThe 8192-byte ceiling at iscsi_target_check_login_request() bounds the\n*input* Login PDU payload, but a single PDU can carry up to 2048 minimal\nfour-byte \"a=b\\0\" pairs, each unknown key expanding to a 16-byte\n\"a=NotUnderstood\\0\" output record via iscsi_add_notunderstood_response().\n2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB\nheap overrun in the kmalloc-8k slab.\n\nThe fix introduces a static iscsi_encode_text_record() helper that uses\nsnprintf() with a per-call bounds check against the remaining buffer,\nand threads a u32 textbuf_size parameter through\niscsi_encode_text_output(). Both call sites in\niscsi_target_handle_csg_zero() (PHASE_SECURITY) and\niscsi_target_handle_csg_one() (PHASE_OPERATIONAL) pass\nMAX_KEY_VALUE_PAIRS. On overflow the encoder logs the condition, calls\niscsi_release_extra_responses() to drop queued records, and returns -1;\nboth caller sites now emit ISCSI_STATUS_CLS_INITIATOR_ERR /\nISCSI_LOGIN_STATUS_INIT_ERR via iscsit_tx_login_rsp() before returning,\nso the initiator sees an explicit failed-login response rather than a\nsilent connection drop. (Prior to this patch only the PHASE_OPERATIONAL\ncaller did that; the PHASE_SECURITY caller is converted to the same\nshape.)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The Linux iSCSI target (LIO) is an in-kernel SCSI target that accepts remote TCP connections on the iSCSI portal (typically port 3260); crafted Login PDUs reach the vulnerable encoder via the normal network receive and login-negotiation path.\nAC:L - Once an iSCSI target portal is reachable, an attacker can reliably trigger the overflow by sending a single Login PDU packed with unknown key=value pairs; no races or victim-dependent timing are required.\nPR:N - The heap overflow occurs during login negotiation before iSCSI authentication completes; a discovery-session login requires only InitiatorName and SessionType with no credentials, initiator ACL, or local privileges.\nUI:N - Exploitation requires only network packets sent by the attacker; no action from a legitimate user or administrator is needed beyond the target already exposing its iSCSI portal.\nS:U - The corruption is confined to kernel heap memory in the iSCSI target/login context and does not cross a VM, container, or IOMMU security boundary by itself.\nC:H - A ~24 KiB out-of-bounds write into the kmalloc-8k slab can corrupt adjacent kernel objects and be leveraged for arbitrary memory disclosure, not merely a bounded leak.\nI:H - The unbounded sprintf heap overrun is a large out-of-bounds write that can corrupt adjacent heap metadata or objects to achieve arbitrary kernel memory modification and potential code execution.\nA:H - Corrupting kmalloc-8k heap objects during login response encoding can cause kernel oops, BUG, or panic, and the attack can be repeated against an exposed iSCSI target."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:36:56.451Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cb84e974fb172bc71386289f37b78ea679410b39"
},
{
"url": "https://git.kernel.org/stable/c/b19382dfc6e7dee6d3859ba44b6ca29e97a51627"
},
{
"url": "https://git.kernel.org/stable/c/efe633e600a0ac68357206fede21b1ac8178f3b8"
},
{
"url": "https://git.kernel.org/stable/c/4e9f0c4a645c995bc75c06c7b3644254ffb4c76b"
},
{
"url": "https://git.kernel.org/stable/c/30bf335e8fe170322080ee001f05ca29c50680b3"
},
{
"url": "https://git.kernel.org/stable/c/594a40360012ce5f94c715d5e3b20fa3af7d525a"
},
{
"url": "https://git.kernel.org/stable/c/26e4a304b7e6f1338c675d527608d32549c091db"
},
{
"url": "https://git.kernel.org/stable/c/bf33e01f88388c43e285492a63e539df6ffed64c"
}
],
"title": "scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63887",
"datePublished": "2026-07-19T14:55:00.114Z",
"dateReserved": "2026-07-19T07:54:57.018Z",
"dateUpdated": "2026-08-05T12:36:56.451Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64243 (GCVE-0-2026-64243)
Vulnerability from cvelistv5
Published
2026-07-24 15:27
Modified
2026-08-05 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: codecs: simple-mux: Fix enum control bounds check
simple_mux_control_put() rejects values greater than e->items, but
enum control values are zero based. For the two-entry mux used by this
driver, valid values are 0 and 1, so value 2 must be rejected as well.
Accepting e->items can store an invalid mux state, pass it to the GPIO
setter, and pass it on to the DAPM mux update path where it is used as
an index into the enum text array.
Use the same >= e->items check used by the ASoC enum helpers.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 342fbb7578d1741ff646d7b08e14e8753267b9fa Version: 342fbb7578d1741ff646d7b08e14e8753267b9fa Version: 342fbb7578d1741ff646d7b08e14e8753267b9fa Version: 342fbb7578d1741ff646d7b08e14e8753267b9fa Version: 342fbb7578d1741ff646d7b08e14e8753267b9fa Version: 342fbb7578d1741ff646d7b08e14e8753267b9fa Version: 342fbb7578d1741ff646d7b08e14e8753267b9fa |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/simple-mux.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6fb653b62f169f6050fac45b56bf21ad097e19f6",
"status": "affected",
"version": "342fbb7578d1741ff646d7b08e14e8753267b9fa",
"versionType": "git"
},
{
"lessThan": "d8cc3e747b002a8b965c529de79c0654675b9a1a",
"status": "affected",
"version": "342fbb7578d1741ff646d7b08e14e8753267b9fa",
"versionType": "git"
},
{
"lessThan": "5fe860af8630cf7c78523cbd68e5a234743585aa",
"status": "affected",
"version": "342fbb7578d1741ff646d7b08e14e8753267b9fa",
"versionType": "git"
},
{
"lessThan": "2ff3ac6f7664fe5639cad01712ac5e021fa7939c",
"status": "affected",
"version": "342fbb7578d1741ff646d7b08e14e8753267b9fa",
"versionType": "git"
},
{
"lessThan": "164dcbec9632ca93ae313e6da6e4e05584fa0f02",
"status": "affected",
"version": "342fbb7578d1741ff646d7b08e14e8753267b9fa",
"versionType": "git"
},
{
"lessThan": "05ef77f02607a3dc5d7f9762cb990f76843315d4",
"status": "affected",
"version": "342fbb7578d1741ff646d7b08e14e8753267b9fa",
"versionType": "git"
},
{
"lessThan": "f63ad68e18d774a5d15cd7e405ead63f6b322679",
"status": "affected",
"version": "342fbb7578d1741ff646d7b08e14e8753267b9fa",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/simple-mux.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: simple-mux: Fix enum control bounds check\n\nsimple_mux_control_put() rejects values greater than e-\u003eitems, but\nenum control values are zero based. For the two-entry mux used by this\ndriver, valid values are 0 and 1, so value 2 must be rejected as well.\n\nAccepting e-\u003eitems can store an invalid mux state, pass it to the GPIO\nsetter, and pass it on to the DAPM mux update path where it is used as\nan index into the enum text array.\n\nUse the same \u003e= e-\u003eitems check used by the ASoC enum helpers."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - An attacker reaches the flaw through SNDRV_CTL_IOCTL_ELEM_WRITE on the local ALSA control device; no network or physical-input path invokes this callback.\nAC:L - Supplying the single invalid enum value 2 directly triggers the vulnerable path on an affected non-hardened build, without a race or conditions outside the attacker\u2019s control.\nPR:L - The ioctl requires ordinary access to /dev/snd/controlC*, commonly granted to the active local user or audio group, and the kernel path performs no capability or namespace checks.\nUI:N - After obtaining control-device access, the attacker can issue the ioctl directly without any action by another user.\nS:U - The vulnerable ALSA driver and the resulting kernel impacts remain within the host kernel\u2019s security authority and do not cross a virtualization or IOMMU boundary.\nC:H - The invalid index performs an out-of-bounds pointer read and then dereferences that pointer through strcmp(); following the required conservative treatment of kernel out-of-bounds reads, confidentiality is scored High.\nI:N - There is no out-of-bounds write or attacker-controlled write primitive; value 2 is stored in-bounds and the GPIO layer normalizes it to the same Boolean state as valid value 1.\nA:H - The out-of-bounds text pointer commonly resolves to NULL or another invalid address and is dereferenced by strcmp(), causing a kernel oops and potentially a full panic on panic-on-oops systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:40:14.935Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6fb653b62f169f6050fac45b56bf21ad097e19f6"
},
{
"url": "https://git.kernel.org/stable/c/d8cc3e747b002a8b965c529de79c0654675b9a1a"
},
{
"url": "https://git.kernel.org/stable/c/5fe860af8630cf7c78523cbd68e5a234743585aa"
},
{
"url": "https://git.kernel.org/stable/c/2ff3ac6f7664fe5639cad01712ac5e021fa7939c"
},
{
"url": "https://git.kernel.org/stable/c/164dcbec9632ca93ae313e6da6e4e05584fa0f02"
},
{
"url": "https://git.kernel.org/stable/c/05ef77f02607a3dc5d7f9762cb990f76843315d4"
},
{
"url": "https://git.kernel.org/stable/c/f63ad68e18d774a5d15cd7e405ead63f6b322679"
}
],
"title": "ASoC: codecs: simple-mux: Fix enum control bounds check",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64243",
"datePublished": "2026-07-24T15:27:45.311Z",
"dateReserved": "2026-07-19T15:36:31.772Z",
"dateUpdated": "2026-08-05T12:40:14.935Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64524 (GCVE-0-2026-64524)
Vulnerability from cvelistv5
Published
2026-07-25 09:20
Modified
2026-08-05 12:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/hyperv: validate resolution_count and fix WIN8 fallback
A SYNTHVID_RESOLUTION_RESPONSE with resolution_count > 64 walks past
the supported_resolution[SYNTHVID_MAX_RESOLUTION_COUNT] array in the
parse loop. Bound resolution_count against the array size, folded
into the existing zero-check.
When the WIN10 resolution probe fails, the caller in
hyperv_connect_vsp() left hv->screen_*_max / preferred_* unpopulated,
which sets mode_config.max_width / max_height to 0 and makes
drm_internal_framebuffer_create() reject every userspace framebuffer
with -EINVAL. The pre-WIN10 branch had the same gap for
preferred_width / preferred_height. Use a single post-probe fallback
guarded by screen_width_max == 0 so both paths converge on the WIN8
defaults.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/hyperv/hyperv_drm_proto.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "96f7de3172d4aa878b7f87173b2b3507c350fcd6",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "bc573752f3dac0d1ab8df7078c1851bc76717653",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "1fb565b77b8f44afabb02de6310065f109d89e94",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "a321c908f2eeea01539668eb270d074d9b88e490",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "9c698b2c43c2667c34f5336bf46ad5786216ac2a",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "8a114b25b5521eae451b13bce98ae978624962e5",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "13d33b9ef67066c77c84273fac5a1d3fde3533d1",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/hyperv/hyperv_drm_proto.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/hyperv: validate resolution_count and fix WIN8 fallback\n\nA SYNTHVID_RESOLUTION_RESPONSE with resolution_count \u003e 64 walks past\nthe supported_resolution[SYNTHVID_MAX_RESOLUTION_COUNT] array in the\nparse loop. Bound resolution_count against the array size, folded\ninto the existing zero-check.\n\nWhen the WIN10 resolution probe fails, the caller in\nhyperv_connect_vsp() left hv-\u003escreen_*_max / preferred_* unpopulated,\nwhich sets mode_config.max_width / max_height to 0 and makes\ndrm_internal_framebuffer_create() reject every userspace framebuffer\nwith -EINVAL. The pre-WIN10 branch had the same gap for\npreferred_width / preferred_height. Use a single post-probe fallback\nguarded by screen_width_max == 0 so both paths converge on the WIN8\ndefaults."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The malicious resolution response must originate from the local Hyper-V synthetic-video backend over VMBus; it is not reachable through a network protocol or guest userspace ioctl.\nAC:L - The backend can deterministically trigger the flaw by returning a resolution_count from 65 through 255 during the normal WIN10+ probe or resume exchange, without a race or unpredictable condition.\nPR:N - The guest accepts the VMBus response without authentication, capability checks, or guest credentials; a malicious or compromised backend requires no privileges within the vulnerable guest.\nUI:N - The response is processed automatically during device probing or resume, without any victim action.\nS:U - The vulnerable parser and the affected DRM and kernel resources are within the same guest-kernel security authority; this does not produce a guest-to-host escape.\nC:H - A count of 255 causes 191 additional four-byte entries to be read beyond the declared array, substantially exceeding a small bounded disclosure and allowing out-of-bounds kernel data to influence observable display state.\nI:N - The invalid accesses are reads, and their results are written only to the intended resolution fields; no out-of-bounds write, use-after-free, or control-flow corruption was found.\nA:H - Bounds-instrumented hardened kernels can oops when index 64 is reached, while a failed or malformed resolution probe can leave zero maximum dimensions and make every userspace framebuffer creation fail."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:42:37.752Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/96f7de3172d4aa878b7f87173b2b3507c350fcd6"
},
{
"url": "https://git.kernel.org/stable/c/bc573752f3dac0d1ab8df7078c1851bc76717653"
},
{
"url": "https://git.kernel.org/stable/c/1fb565b77b8f44afabb02de6310065f109d89e94"
},
{
"url": "https://git.kernel.org/stable/c/a321c908f2eeea01539668eb270d074d9b88e490"
},
{
"url": "https://git.kernel.org/stable/c/9c698b2c43c2667c34f5336bf46ad5786216ac2a"
},
{
"url": "https://git.kernel.org/stable/c/8a114b25b5521eae451b13bce98ae978624962e5"
},
{
"url": "https://git.kernel.org/stable/c/13d33b9ef67066c77c84273fac5a1d3fde3533d1"
}
],
"title": "drm/hyperv: validate resolution_count and fix WIN8 fallback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64524",
"datePublished": "2026-07-25T09:20:48.193Z",
"dateReserved": "2026-07-19T15:36:31.794Z",
"dateUpdated": "2026-08-05T12:42:37.752Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68249 (GCVE-0-2026-68249)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit 8d144a0eb09537055841af48c9e7c2d4cd48e84d)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5960a8b54a19367540d93980a4d0e9edbb8acf4e",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "0c0dcc146f0c3091a9ef416cb8bbfdf5b5e169d5",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "84254337df02406996068315c2b6f06d8cc64452",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "f6212bc1bbd936fd9f7d77168b0c8b0019477b64",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "28337e5d7df429bac7de64b17f1a595147778caa",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "d20b5c139b2906bcd8ab4bfe5b8be500318161d1",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "0027cb19b0449ad6babedb1af285a713ab05c97f",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "9e98ed3113943257ad6e5c1e6beddbdb482a70ad",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit 8d144a0eb09537055841af48c9e7c2d4cd48e84d)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:18.750Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5960a8b54a19367540d93980a4d0e9edbb8acf4e"
},
{
"url": "https://git.kernel.org/stable/c/0c0dcc146f0c3091a9ef416cb8bbfdf5b5e169d5"
},
{
"url": "https://git.kernel.org/stable/c/84254337df02406996068315c2b6f06d8cc64452"
},
{
"url": "https://git.kernel.org/stable/c/f6212bc1bbd936fd9f7d77168b0c8b0019477b64"
},
{
"url": "https://git.kernel.org/stable/c/28337e5d7df429bac7de64b17f1a595147778caa"
},
{
"url": "https://git.kernel.org/stable/c/d20b5c139b2906bcd8ab4bfe5b8be500318161d1"
},
{
"url": "https://git.kernel.org/stable/c/0027cb19b0449ad6babedb1af285a713ab05c97f"
},
{
"url": "https://git.kernel.org/stable/c/9e98ed3113943257ad6e5c1e6beddbdb482a70ad"
}
],
"title": "drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68249",
"datePublished": "2026-08-10T12:01:15.453Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:18.750Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68300 (GCVE-0-2026-68300)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: auth: verify auth requirement when auth_chunk is NULL
sctp_auth_chunk_verify() returns true unconditionally when
chunk->auth_chunk is NULL, silently skipping authentication.
This is incorrect when:
1. skb_clone() failed in the BH receive path, leaving auth_chunk
NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new
connections, so the early sctp_auth_recv_cid() check cannot
catch this.
2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never
called and auth_chunk remains NULL.
Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL:
if authentication is required, return false to drop the chunk;
otherwise continue normally.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a129792b3aef15002746c13522781d92ed3522c3",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "5a022ac51ad83b4ce6c898f4b9eefc65bd26b247",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "6caf0e8590c0bf05a76b0d387726adf3a6f3725c",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "ec2e157fc9678a9bc411305a25aec3fd337d7efb",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "28c5fdce9dd955d2baf5e28987819b6d7cfaf646",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "18957373920caf5cdaf5cf32e5d1d7a99ca7700a",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "83f5031f2a6a49d696eb4cc0898345d12f9c6451",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "8e04823c120b376ef7dab14b60ebf6823aa16c14",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: auth: verify auth requirement when auth_chunk is NULL\n\nsctp_auth_chunk_verify() returns true unconditionally when\nchunk-\u003eauth_chunk is NULL, silently skipping authentication.\nThis is incorrect when:\n\n1. skb_clone() failed in the BH receive path, leaving auth_chunk\n NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new\n connections, so the early sctp_auth_recv_cid() check cannot\n catch this.\n\n2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never\n called and auth_chunk remains NULL.\n\nFix by checking sctp_auth_recv_cid() when auth_chunk is NULL:\nif authentication is required, return false to drop the chunk;\notherwise continue normally."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code is SCTP COOKIE-ECHO chunk processing in the kernel\u0027s SCTP state machine, reached directly from packets received on the network from any remote peer over an arbitrarily routed SCTP connection.\nAC:L - The attacker deterministically triggers the bypass by completing a normal INIT/INIT-ACK exchange with the AUTH extension advertised and then sending COOKIE-ECHO with no preceding AUTH chunk; no race, no memory-layout dependency, and every step is under the attacker\u0027s control.\nPR:N - This is the pre-authentication association-establishment path itself; the attacker needs no credentials, no shared SCTP-AUTH key, and no account, since the bug is precisely that the required authentication is skipped.\nUI:N - The listening SCTP endpoint processes the crafted COOKIE-ECHO automatically in the receive path; no action by any local user or administrator is needed.\nS:U - The bypass affects the SCTP association and the application relying on it within the same host security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - An unauthenticated peer is admitted as an apparently authenticated one, and because peer.auth_capable is set the SCTP_AUTH_NO_AUTH notification is suppressed so the application cannot detect it, giving the attacker full read access to all data the service sends on that association.\nI:H - The attacker can inject arbitrary SCTP data and control chunks into the service as a trusted, supposedly key-verified peer, and can use the dupcook restart path to update or replace an existing association\u0027s state without authentication.\nA:H - Authenticating COOKIE-ECHO is the RFC 4895 defense against unauthorized association restart; bypassing it lets an attacker reset/take over an established association, dropping its queued state and denying service to the legitimate peer, and lets unauthorized peers consume association and accept-queue resources on an endpoint meant to admit only key-holding peers."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:51.209Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a129792b3aef15002746c13522781d92ed3522c3"
},
{
"url": "https://git.kernel.org/stable/c/5a022ac51ad83b4ce6c898f4b9eefc65bd26b247"
},
{
"url": "https://git.kernel.org/stable/c/6caf0e8590c0bf05a76b0d387726adf3a6f3725c"
},
{
"url": "https://git.kernel.org/stable/c/ec2e157fc9678a9bc411305a25aec3fd337d7efb"
},
{
"url": "https://git.kernel.org/stable/c/28c5fdce9dd955d2baf5e28987819b6d7cfaf646"
},
{
"url": "https://git.kernel.org/stable/c/18957373920caf5cdaf5cf32e5d1d7a99ca7700a"
},
{
"url": "https://git.kernel.org/stable/c/83f5031f2a6a49d696eb4cc0898345d12f9c6451"
},
{
"url": "https://git.kernel.org/stable/c/8e04823c120b376ef7dab14b60ebf6823aa16c14"
}
],
"title": "sctp: auth: verify auth requirement when auth_chunk is NULL",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68300",
"datePublished": "2026-08-10T12:02:34.168Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:51.209Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64114 (GCVE-0-2026-64114)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: raw: reject IP_HDRINCL packets with ihl < 5
raw_send_hdrinc() validates that the caller-supplied IPv4 header
fits within the message length:
iphlen = iph->ihl * 4;
err = -EINVAL;
if (iphlen > length)
goto error_free;
if (iphlen >= sizeof(*iph)) {
/* fix up saddr, tot_len, id, csum, transport_header */
}
It does not, however, reject ihl < 5. For such a packet the
"if (iphlen >= sizeof(*iph))" branch is skipped, leaving the
crafted iphdr untouched, but the packet is still handed to
__ip_local_out() and onward. Downstream consumers that read
iph->ihl assume a sane value: net/ipv4/ah4.c:ah_output() in
particular subtracts sizeof(struct iphdr) from top_iph->ihl * 4
and passes the (signed-int-negative, then cast to size_t)
result to memcpy(), producing an OOB access of length close to
SIZE_MAX and a host kernel panic.
An IPv4 header with ihl < 5 is malformed by definition (RFC 791:
"Internet Header Length is the length of the internet header in
32 bit words ... Note that the minimum value for a correct header
is 5."). The kernel should not be willing to inject such a
packet into its own output path.
Reject "iphlen < sizeof(*iph)" alongside the existing
"iphlen > length" check. This matches the principle that locally
constructed packets that re-enter the IP stack must pass the same
basic sanity tests that a foreign packet would be subjected to.
Once this lands, the "if (iphlen >= sizeof(*iph))" wrapper around
the fixup branch becomes redundant; left in place to keep the
patch minimal and backport-friendly. A follow-up can unwrap it.
Note that commit 86f4c90a1c5c ("ipv4, ipv6: ensure raw socket
message is big enough to hold an IP header") ensures the message
buffer is large enough to hold an iphdr, but does not constrain
the self-reported iph->ihl.
Reachability: the malformed packet source is any caller with
CAP_NET_RAW, including an unprivileged process in a user+net
namespace on a kernel with CONFIG_USER_NS=y. The reproduced AH
crash also requires a matching xfrm AH policy on the outgoing
route; a container granted CAP_NET_ADMIN can install that state
and policy in its netns. Loopback bypasses xfrm_output, so the
trigger uses a real netdev.
Reproduced on UML + KASAN: kernel-mode fault at addr 0x0 with
memcpy_orig at the crash site. Same shape reproduces inside a
rootless Docker container with --cap-add NET_ADMIN on a stock
distro kernel.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/raw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1065b9efa4126df559b03a849c139ecfae92cd25",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "bc20dbd48c26e743f7e0845020c11ed2ce8b15ee",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5a564f737ec54d63e8ee221d3ff396d07586d464",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3c5411fa4944ed99af3d9d1de750ea8169b6dac9",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "145e9afa5b905229b4788bb72c3255f5a5f77508",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7725cd3b471740fd23d25ed1da722c671fb2a5d3",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "bbe0be67de296176e7243c76e3d9f02f6ae9ff0b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "915fab69823a14c170dbaa3b41978768e0fe62fc",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/raw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: raw: reject IP_HDRINCL packets with ihl \u003c 5\n\nraw_send_hdrinc() validates that the caller-supplied IPv4 header\nfits within the message length:\n\n iphlen = iph-\u003eihl * 4;\n err = -EINVAL;\n if (iphlen \u003e length)\n goto error_free;\n\n if (iphlen \u003e= sizeof(*iph)) {\n /* fix up saddr, tot_len, id, csum, transport_header */\n }\n\nIt does not, however, reject ihl \u003c 5. For such a packet the\n\"if (iphlen \u003e= sizeof(*iph))\" branch is skipped, leaving the\ncrafted iphdr untouched, but the packet is still handed to\n__ip_local_out() and onward. Downstream consumers that read\niph-\u003eihl assume a sane value: net/ipv4/ah4.c:ah_output() in\nparticular subtracts sizeof(struct iphdr) from top_iph-\u003eihl * 4\nand passes the (signed-int-negative, then cast to size_t)\nresult to memcpy(), producing an OOB access of length close to\nSIZE_MAX and a host kernel panic.\n\nAn IPv4 header with ihl \u003c 5 is malformed by definition (RFC 791:\n\"Internet Header Length is the length of the internet header in\n32 bit words ... Note that the minimum value for a correct header\nis 5.\"). The kernel should not be willing to inject such a\npacket into its own output path.\n\nReject \"iphlen \u003c sizeof(*iph)\" alongside the existing\n\"iphlen \u003e length\" check. This matches the principle that locally\nconstructed packets that re-enter the IP stack must pass the same\nbasic sanity tests that a foreign packet would be subjected to.\n\nOnce this lands, the \"if (iphlen \u003e= sizeof(*iph))\" wrapper around\nthe fixup branch becomes redundant; left in place to keep the\npatch minimal and backport-friendly. A follow-up can unwrap it.\n\nNote that commit 86f4c90a1c5c (\"ipv4, ipv6: ensure raw socket\nmessage is big enough to hold an IP header\") ensures the message\nbuffer is large enough to hold an iphdr, but does not constrain\nthe self-reported iph-\u003eihl.\n\nReachability: the malformed packet source is any caller with\nCAP_NET_RAW, including an unprivileged process in a user+net\nnamespace on a kernel with CONFIG_USER_NS=y. The reproduced AH\ncrash also requires a matching xfrm AH policy on the outgoing\nroute; a container granted CAP_NET_ADMIN can install that state\nand policy in its netns. Loopback bypasses xfrm_output, so the\ntrigger uses a real netdev.\n\nReproduced on UML + KASAN: kernel-mode fault at addr 0x0 with\nmemcpy_orig at the crash site. Same shape reproduces inside a\nrootless Docker container with --cap-add NET_ADMIN on a stock\ndistro kernel."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscalls (socket/sendmsg on a raw IP_HDRINCL socket); malformed packets are injected locally into the output path, not via remote network ingress which validates ihl \u003e= 5.\nAC:L - The attacker fully controls the crafted header ihl value and can install the required xfrm AH policy and route via CAP_NET_ADMIN in their own network namespace, making exploitation reliable without conditions outside attacker control.\nPR:L - Triggering requires CAP_NET_RAW for raw sockets and CAP_NET_ADMIN to install xfrm AH policy, both obtainable by an unprivileged user via user+network namespaces or a container granted NET_ADMIN without init-namespace root.\nUI:N - No victim interaction is required; the attacker sends the malformed packet directly through their own raw socket and configured IPsec policy.\nS:U - Impact is kernel memory corruption and panic within the same kernel security boundary; this is not a VM escape, sandbox escape, or cross-authority boundary violation.\nC:H - The integer underflow in ah_output() memcpy length produces an out-of-bounds read of near SIZE_MAX bytes, providing an arbitrary kernel memory read primitive beyond any bounded disclosure.\nI:H - The same memcpy with underflowed length causes a massive out-of-bounds write that can corrupt adjacent kernel heap memory and be leveraged for control-flow hijacking.\nA:H - The OOB memcpy reliably causes a kernel-mode fault and host panic, as reproduced with KASAN and in a rootless Docker container, denying all system availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:23.263Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1065b9efa4126df559b03a849c139ecfae92cd25"
},
{
"url": "https://git.kernel.org/stable/c/bc20dbd48c26e743f7e0845020c11ed2ce8b15ee"
},
{
"url": "https://git.kernel.org/stable/c/5a564f737ec54d63e8ee221d3ff396d07586d464"
},
{
"url": "https://git.kernel.org/stable/c/3c5411fa4944ed99af3d9d1de750ea8169b6dac9"
},
{
"url": "https://git.kernel.org/stable/c/145e9afa5b905229b4788bb72c3255f5a5f77508"
},
{
"url": "https://git.kernel.org/stable/c/7725cd3b471740fd23d25ed1da722c671fb2a5d3"
},
{
"url": "https://git.kernel.org/stable/c/bbe0be67de296176e7243c76e3d9f02f6ae9ff0b"
},
{
"url": "https://git.kernel.org/stable/c/915fab69823a14c170dbaa3b41978768e0fe62fc"
}
],
"title": "ipv4: raw: reject IP_HDRINCL packets with ihl \u003c 5",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64114",
"datePublished": "2026-07-19T15:40:14.854Z",
"dateReserved": "2026-07-19T07:54:57.035Z",
"dateUpdated": "2026-08-05T12:39:23.263Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68127 (GCVE-0-2026-68127)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ila: reload IPv6 header after pskb_may_pull in checksum adjust
ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling
pskb_may_pull(). On a non-linear skb whose transport header sits in a page
fragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head()
and free the old skb head, leaving ip6h dangling; the following
get_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator()
uses ip6h (and the iaddr derived from it) again after the csum-adjust
call and additionally writes the new locator through that pointer.
Impact: a remote IPv6 packet routed through a configured ILA
csum-adjust-transport route or receive-side mapping triggers a
slab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or
mapping requires CAP_NET_ADMIN to configure, but trigger packets are
unauthenticated once it exists.
Reload ip6h after each pskb_may_pull() in ila_csum_adjust_transport()
before the csum-diff read. In ila_update_ipv6_locator() only the
ILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in
that case alone before the destination-address write; the neutral-map
modes never pull and keep their cached pointers.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/ila/ila_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e451a904606c571f731ef7a06b3398619dce5300",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "1eadcb43893b897ade85ac5bf5c618054bc3c655",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "ba353caafb06ccee57b78d3254e3cebf1dea4a93",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "896a9512d0d83c2a4b357e5585b7b62a8e3f95c1",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "7097a0280b178237265681be66d1bef11d15894b",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "472aba2603ca74c4f7722cb0c0296942b0776b8d",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "92d3817649df2b0b6a008a686c8275c88d7ef594",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/ila/ila_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nila: reload IPv6 header after pskb_may_pull in checksum adjust\n\nila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling\npskb_may_pull(). On a non-linear skb whose transport header sits in a page\nfragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head()\nand free the old skb head, leaving ip6h dangling; the following\nget_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator()\nuses ip6h (and the iaddr derived from it) again after the csum-adjust\ncall and additionally writes the new locator through that pointer.\n\nImpact: a remote IPv6 packet routed through a configured ILA\ncsum-adjust-transport route or receive-side mapping triggers a\nslab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or\nmapping requires CAP_NET_ADMIN to configure, but trigger packets are\nunauthenticated once it exists.\n\nReload ip6h after each pskb_may_pull() in ila_csum_adjust_transport()\nbefore the csum-diff read. In ila_update_ipv6_locator() only the\nILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in\nthat case alone before the destination-address write; the neutral-map\nmodes never pull and keep their cached pointers."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached from ipv6_rcv() through NF_INET_PRE_ROUTING (ila_nf_input) or IPv6 routing/LWT input/output when remote IPv6 packets matching a configured ILA csum-adjust-transport mapping or route are processed; no local syscall is required on internet-facing routers, gateways, or NVO3/overlay hosts.\nAC:L - Once ILA csum-adjust-transport is configured, a remote attacker can reliably send IPv6 TCP/UDP/ICMPv6 packets whose transport headers live in skb page fragments so pskb_may_pull() reallocates the head; they control packet layout and can retry without races or uncontrollable memory layout.\nPR:N - Trigger packets are processed unauthenticated on the network datapath; although ILA routes/mappings require CAP_NET_ADMIN to install, that is operator infrastructure (also obtainable in a user netns), not a privilege the remote attacker needs to send the malformed IPv6 packets that hit ila_update_ipv6_locator().\nUI:N - No victim user action is required beyond normal IPv6 packet delivery; exploitation is fully automated once the affected ILA configuration exists and the attacker sends crafted packets to the host.\nS:U - The slab use-after-free corrupts kernel packet-processing memory within the host kernel security authority; it is not a VM escape, container breakout, or IOMMU/DMA boundary bypass.\nC:H - ila_csum_adjust_transport() reads the cached IPv6 header via get_csum_diff(ip6h, p) after pskb_may_pull() frees the old skb head, causing a slab use-after-free read of freed memory that can disclose kernel heap contents.\nI:H - ila_update_ipv6_locator() then writes iaddr-\u003eloc = p-\u003elocator through the same stale iaddr pointer derived from the freed header, giving a slab use-after-free write primitive that can be leveraged for arbitrary memory corruption and control-flow hijacking.\nA:H - The freed skb-head slab use-after-free was reproduced under KASAN and can cause kernel oops/panic during IPv6 receive/forwarding; even unsuccessful exploitation typically crashes or destabilizes the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:41.771Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e451a904606c571f731ef7a06b3398619dce5300"
},
{
"url": "https://git.kernel.org/stable/c/1eadcb43893b897ade85ac5bf5c618054bc3c655"
},
{
"url": "https://git.kernel.org/stable/c/ba353caafb06ccee57b78d3254e3cebf1dea4a93"
},
{
"url": "https://git.kernel.org/stable/c/896a9512d0d83c2a4b357e5585b7b62a8e3f95c1"
},
{
"url": "https://git.kernel.org/stable/c/7097a0280b178237265681be66d1bef11d15894b"
},
{
"url": "https://git.kernel.org/stable/c/472aba2603ca74c4f7722cb0c0296942b0776b8d"
},
{
"url": "https://git.kernel.org/stable/c/c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc"
},
{
"url": "https://git.kernel.org/stable/c/92d3817649df2b0b6a008a686c8275c88d7ef594"
}
],
"title": "ila: reload IPv6 header after pskb_may_pull in checksum adjust",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68127",
"datePublished": "2026-08-10T11:58:48.489Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:41.771Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68434 (GCVE-0-2026-68434)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
Commit b1b4efea05a5 ("serial: 8250_mid: Disable DMA for selected
platforms") replaced the dnv_board setup and exit callbacks with
PTR_IF(false, ...), which evaluates to NULL. However, the three call
sites in mid8250_probe() and mid8250_remove() unconditionally
dereference these function pointers without NULL checks, causing a NULL
pointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon
D (ICX-D/CDF), or Snowridge (SNR) platform.
Fix this by adding the missing NULL checks before calling the setup and
exit callbacks.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 763d61ded752fbb3116efc951eff4363f237b7e0 Version: c7d190bb07bf4e3b217c69370e94d1b4c80a40ad Version: 0b3ed3fa227ba778cabed96e7f8d84addb8bdf9c Version: 587afb06a5d1dc5092d3d9e9ac3ccf22094d50c6 Version: 977855894bca4b87afa50d21e3f3e85a5a0e901f Version: 1cd54e217c6e2cdb794a897b2f855e13ffcee586 Version: 9690e8a342632344984af72bc56b7a1fba61e6cb Version: b1b4efea05a56c0995e4702a86d6624b4fdff32f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/serial/8250/8250_mid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bdaa8871b53fe9b1730ef64dda2fcd662fd83339",
"status": "affected",
"version": "763d61ded752fbb3116efc951eff4363f237b7e0",
"versionType": "git"
},
{
"lessThan": "f85a42fb90399dedcf81c146d09c07e4548b1e8c",
"status": "affected",
"version": "c7d190bb07bf4e3b217c69370e94d1b4c80a40ad",
"versionType": "git"
},
{
"lessThan": "4ea933a36a14bec19b71025cdd8407bafbd67ec1",
"status": "affected",
"version": "0b3ed3fa227ba778cabed96e7f8d84addb8bdf9c",
"versionType": "git"
},
{
"lessThan": "1096397c31f6bffa95e77bdd18fbca085be83e10",
"status": "affected",
"version": "587afb06a5d1dc5092d3d9e9ac3ccf22094d50c6",
"versionType": "git"
},
{
"lessThan": "600dcd548fb2b00a69f447684f52ba45d5a3540e",
"status": "affected",
"version": "977855894bca4b87afa50d21e3f3e85a5a0e901f",
"versionType": "git"
},
{
"lessThan": "b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56",
"status": "affected",
"version": "1cd54e217c6e2cdb794a897b2f855e13ffcee586",
"versionType": "git"
},
{
"lessThan": "8cbad52ccfa6a7f089cfab34979bc6cc3bff25be",
"status": "affected",
"version": "9690e8a342632344984af72bc56b7a1fba61e6cb",
"versionType": "git"
},
{
"lessThan": "7fb13fd7e9a59a37cd911efff83abe19e3ee029d",
"status": "affected",
"version": "b1b4efea05a56c0995e4702a86d6624b4fdff32f",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/serial/8250/8250_mid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5.10.266",
"status": "affected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThan": "7.1.6",
"status": "affected",
"version": "7.1.4",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10.261",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.212",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.178",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.145",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.96",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.1.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms\n\nCommit b1b4efea05a5 (\"serial: 8250_mid: Disable DMA for selected\nplatforms\") replaced the dnv_board setup and exit callbacks with\nPTR_IF(false, ...), which evaluates to NULL. However, the three call\nsites in mid8250_probe() and mid8250_remove() unconditionally\ndereference these function pointers without NULL checks, causing a NULL\npointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon\nD (ICX-D/CDF), or Snowridge (SNR) platform.\n\nFix this by adding the missing NULL checks before calling the setup and\nexit callbacks."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:23.299Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bdaa8871b53fe9b1730ef64dda2fcd662fd83339"
},
{
"url": "https://git.kernel.org/stable/c/f85a42fb90399dedcf81c146d09c07e4548b1e8c"
},
{
"url": "https://git.kernel.org/stable/c/4ea933a36a14bec19b71025cdd8407bafbd67ec1"
},
{
"url": "https://git.kernel.org/stable/c/1096397c31f6bffa95e77bdd18fbca085be83e10"
},
{
"url": "https://git.kernel.org/stable/c/600dcd548fb2b00a69f447684f52ba45d5a3540e"
},
{
"url": "https://git.kernel.org/stable/c/b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56"
},
{
"url": "https://git.kernel.org/stable/c/8cbad52ccfa6a7f089cfab34979bc6cc3bff25be"
},
{
"url": "https://git.kernel.org/stable/c/7fb13fd7e9a59a37cd911efff83abe19e3ee029d"
}
],
"title": "serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68434",
"datePublished": "2026-08-12T00:07:21.897Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-23T12:46:23.299Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46242 (GCVE-0-2026-46242)
Vulnerability from cvelistv5
Published
2026-05-30 12:13
Modified
2026-08-05 12:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
eventpoll: fix ep_remove struct eventpoll / struct file UAF
ep_remove() (via ep_remove_file()) cleared file->f_ep under
file->f_lock but then kept using @file inside the critical section
(is_file_epoll(), hlist_del_rcu() through the head, spin_unlock).
A concurrent __fput() taking the eventpoll_release() fastpath in
that window observed the transient NULL, skipped
eventpoll_release_file() and ran to f_op->release / file_free().
For the epoll-watches-epoll case, f_op->release is
ep_eventpoll_release() -> ep_clear_and_put() -> ep_free(), which
kfree()s the watched struct eventpoll. Its embedded ->refs
hlist_head is exactly where epi->fllink.pprev points, so the
subsequent hlist_del_rcu()'s "*pprev = next" scribbles into freed
kmalloc-192 memory.
In addition, struct file is SLAB_TYPESAFE_BY_RCU, so the slot
backing @file could be recycled by alloc_empty_file() --
reinitializing f_lock and f_ep -- while ep_remove() is still
nominally inside that lock. The upshot is an attacker-controllable
kmem_cache_free() against the wrong slab cache.
Pin @file via epi_fget() at the top of ep_remove() and gate the
critical section on the pin succeeding. With the pin held @file
cannot reach refcount zero, which holds __fput() off and
transitively keeps the watched struct eventpoll alive across the
hlist_del_rcu() and the f_lock use, closing both UAFs.
If the pin fails @file has already reached refcount zero and its
__fput() is in flight. Because we bailed before clearing f_ep,
that path takes the eventpoll_release() slow path into
eventpoll_release_file() and blocks on ep->mtx until the waiter
side's ep_clear_and_put() drops it. The bailed epi's share of
ep->refcount stays intact, so the trailing ep_refcount_dec_and_test()
in ep_clear_and_put() cannot free the eventpoll out from under
eventpoll_release_file(); the orphaned epi is then cleaned up
there.
A successful pin also proves we are not racing
eventpoll_release_file() on this epi, so drop the now-redundant
re-check of epi->dying under f_lock. The cheap lockless
READ_ONCE(epi->dying) fast-path bailout stays.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a1f93804449d13f97dabd4b996817de4bf1ed67a Version: 58c9b016e12855286370dfb704c08498edbc857a Version: 58c9b016e12855286370dfb704c08498edbc857a Version: 58c9b016e12855286370dfb704c08498edbc857a Version: 58c9b016e12855286370dfb704c08498edbc857a Version: 58c9b016e12855286370dfb704c08498edbc857a Version: f2451def095c1743adcfcb0cb5dadc86034e162a Version: 6.1.175 ≤ Version: 5.15.209 ≤ |
||
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-07-09T00:31:40.940Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/07/08/14"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/eventpoll.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3e1144d2515d28e4312e663ea05eac203101491d",
"status": "affected",
"version": "a1f93804449d13f97dabd4b996817de4bf1ed67a",
"versionType": "git"
},
{
"lessThan": "2de4db145b2992da496fea6c51f9839be678ae24",
"status": "affected",
"version": "58c9b016e12855286370dfb704c08498edbc857a",
"versionType": "git"
},
{
"lessThan": "9324de74a3a59b9fde9b62ee45ebaa71458ba2e5",
"status": "affected",
"version": "58c9b016e12855286370dfb704c08498edbc857a",
"versionType": "git"
},
{
"lessThan": "ef4ca02e95363e78977ca04340d44fe3b4b2b81f",
"status": "affected",
"version": "58c9b016e12855286370dfb704c08498edbc857a",
"versionType": "git"
},
{
"lessThan": "ced39b6a8062bac5c18a1c3df85634107eb8664a",
"status": "affected",
"version": "58c9b016e12855286370dfb704c08498edbc857a",
"versionType": "git"
},
{
"lessThan": "a6dc643c69311677c574a0f17a3f4d66a5f3744b",
"status": "affected",
"version": "58c9b016e12855286370dfb704c08498edbc857a",
"versionType": "git"
},
{
"status": "affected",
"version": "f2451def095c1743adcfcb0cb5dadc86034e162a",
"versionType": "git"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.209",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/eventpoll.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.175",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.209",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\neventpoll: fix ep_remove struct eventpoll / struct file UAF\n\nep_remove() (via ep_remove_file()) cleared file-\u003ef_ep under\nfile-\u003ef_lock but then kept using @file inside the critical section\n(is_file_epoll(), hlist_del_rcu() through the head, spin_unlock).\nA concurrent __fput() taking the eventpoll_release() fastpath in\nthat window observed the transient NULL, skipped\neventpoll_release_file() and ran to f_op-\u003erelease / file_free().\n\nFor the epoll-watches-epoll case, f_op-\u003erelease is\nep_eventpoll_release() -\u003e ep_clear_and_put() -\u003e ep_free(), which\nkfree()s the watched struct eventpoll. Its embedded -\u003erefs\nhlist_head is exactly where epi-\u003efllink.pprev points, so the\nsubsequent hlist_del_rcu()\u0027s \"*pprev = next\" scribbles into freed\nkmalloc-192 memory.\n\nIn addition, struct file is SLAB_TYPESAFE_BY_RCU, so the slot\nbacking @file could be recycled by alloc_empty_file() --\nreinitializing f_lock and f_ep -- while ep_remove() is still\nnominally inside that lock. The upshot is an attacker-controllable\nkmem_cache_free() against the wrong slab cache.\n\nPin @file via epi_fget() at the top of ep_remove() and gate the\ncritical section on the pin succeeding. With the pin held @file\ncannot reach refcount zero, which holds __fput() off and\ntransitively keeps the watched struct eventpoll alive across the\nhlist_del_rcu() and the f_lock use, closing both UAFs.\n\nIf the pin fails @file has already reached refcount zero and its\n__fput() is in flight. Because we bailed before clearing f_ep,\nthat path takes the eventpoll_release() slow path into\neventpoll_release_file() and blocks on ep-\u003emtx until the waiter\nside\u0027s ep_clear_and_put() drops it. The bailed epi\u0027s share of\nep-\u003erefcount stays intact, so the trailing ep_refcount_dec_and_test()\nin ep_clear_and_put() cannot free the eventpoll out from under\neventpoll_release_file(); the orphaned epi is then cleaned up\nthere.\n\nA successful pin also proves we are not racing\neventpoll_release_file() on this epi, so drop the now-redundant\nre-check of epi-\u003edying under f_lock. The cheap lockless\nREAD_ONCE(epi-\u003edying) fast-path bailout stays."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscalls (`epoll_create1`, `epoll_ctl`, `close`) on nested epoll fds; there is no network, adjacent-radio, or physical-device path to the buggy `ep_remove`/`eventpoll_release` race.\nAC:L - An unprivileged attacker can drive both sides of the race (e.g., one thread `EPOLL_CTL_DEL` or closing the outer epoll while another closes the inner epoll fd) and retry until the transient `f_ep == NULL` window is hit, consistent with multi-threaded epoll workloads.\nPR:L - No capabilities or root are required; any local UID that may create epoll fds (including inside user namespaces/containers) can register nested epoll and trigger the concurrent remove/close paths.\nUI:N - No victim action is required beyond the attacker running their own concurrent epoll setup and close/DEL operations on the same host.\nS:U - Impact is kernel heap corruption and potential privilege escalation within the same kernel security domain, not a documented cross-boundary escape (e.g., guest-to-host or sandbox breakout).\nC:H - The bug is a use-after-free on `struct eventpoll` and potentially recycled `struct file` objects, which can be turned into arbitrary kernel memory disclosure via heap grooming and UAF reads.\nI:H - Concurrent teardown allows `hlist_del_rcu()` to write `*pprev` into freed kmalloc-192 memory and enables attacker-controllable `kmem_cache_free()` on the wrong cache, supporting arbitrary write/control-flow hijack primitives.\nA:H - The race causes invalid writes to freed memory and slab corruption, which routinely provokes kernel oops/panic or severe instability even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:30:41.557Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3e1144d2515d28e4312e663ea05eac203101491d"
},
{
"url": "https://git.kernel.org/stable/c/2de4db145b2992da496fea6c51f9839be678ae24"
},
{
"url": "https://git.kernel.org/stable/c/9324de74a3a59b9fde9b62ee45ebaa71458ba2e5"
},
{
"url": "https://git.kernel.org/stable/c/ef4ca02e95363e78977ca04340d44fe3b4b2b81f"
},
{
"url": "https://git.kernel.org/stable/c/ced39b6a8062bac5c18a1c3df85634107eb8664a"
},
{
"url": "https://git.kernel.org/stable/c/a6dc643c69311677c574a0f17a3f4d66a5f3744b"
}
],
"title": "eventpoll: fix ep_remove struct eventpoll / struct file UAF",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46242",
"datePublished": "2026-05-30T12:13:45.594Z",
"dateReserved": "2026-05-13T15:03:33.107Z",
"dateUpdated": "2026-08-05T12:30:41.557Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64343 (GCVE-0-2026-64343)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: ldusb: fix use-after-free on disconnect race
mutex_unlock() may access the mutex structure after releasing the lock
and therefore cannot be used to manage lifetime of objects directly
(unlike spinlocks and refcounts). [1][2]
Use a kref to release the driver data to avoid use-after-free in
mutex_unlock() when release() races with disconnect().
[1] a51749ab34d9 ("locking/mutex: Document that mutex_unlock() is
non-atomic")
[2] 2b9d9e0a9ba0 ("locking/mutex: Clarify that mutex_unlock(), and most
other sleeping locks, can still use the lock object
after it's unlocked")
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ce0d7d3f575fc1ba6a89c3c651e710355590daff Version: ce0d7d3f575fc1ba6a89c3c651e710355590daff Version: ce0d7d3f575fc1ba6a89c3c651e710355590daff Version: ce0d7d3f575fc1ba6a89c3c651e710355590daff Version: ce0d7d3f575fc1ba6a89c3c651e710355590daff Version: ce0d7d3f575fc1ba6a89c3c651e710355590daff Version: ce0d7d3f575fc1ba6a89c3c651e710355590daff Version: ce0d7d3f575fc1ba6a89c3c651e710355590daff |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/ldusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fc55923a972e715f9a27187b47d4920709e23d85",
"status": "affected",
"version": "ce0d7d3f575fc1ba6a89c3c651e710355590daff",
"versionType": "git"
},
{
"lessThan": "e5a9bdce4bfd3e2226b5f3df5fb8385d6935ee69",
"status": "affected",
"version": "ce0d7d3f575fc1ba6a89c3c651e710355590daff",
"versionType": "git"
},
{
"lessThan": "af59829e67e11ba2511a9f8e4b9111afc7d1f550",
"status": "affected",
"version": "ce0d7d3f575fc1ba6a89c3c651e710355590daff",
"versionType": "git"
},
{
"lessThan": "02ca08fff74cf9b0a3c4d2cacde1c6edeeb95bb4",
"status": "affected",
"version": "ce0d7d3f575fc1ba6a89c3c651e710355590daff",
"versionType": "git"
},
{
"lessThan": "d8f69404e1d671326f86d378b9f5bfbd56490e9d",
"status": "affected",
"version": "ce0d7d3f575fc1ba6a89c3c651e710355590daff",
"versionType": "git"
},
{
"lessThan": "2107a4fc8ff1cf1d52f416c1e5cc8e97413a5915",
"status": "affected",
"version": "ce0d7d3f575fc1ba6a89c3c651e710355590daff",
"versionType": "git"
},
{
"lessThan": "a3e794136ab5e3ad1e7019175a4b837aec86db4b",
"status": "affected",
"version": "ce0d7d3f575fc1ba6a89c3c651e710355590daff",
"versionType": "git"
},
{
"lessThan": "19bdfc7b3c179331eafa423d87e1336f43bbfeb8",
"status": "affected",
"version": "ce0d7d3f575fc1ba6a89c3c651e710355590daff",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/ldusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.26"
},
{
"lessThan": "2.6.26",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.26",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: ldusb: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is\n non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n other sleeping locks, can still use the lock object\n after it\u0027s unlocked\")"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:47.172Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fc55923a972e715f9a27187b47d4920709e23d85"
},
{
"url": "https://git.kernel.org/stable/c/e5a9bdce4bfd3e2226b5f3df5fb8385d6935ee69"
},
{
"url": "https://git.kernel.org/stable/c/af59829e67e11ba2511a9f8e4b9111afc7d1f550"
},
{
"url": "https://git.kernel.org/stable/c/02ca08fff74cf9b0a3c4d2cacde1c6edeeb95bb4"
},
{
"url": "https://git.kernel.org/stable/c/d8f69404e1d671326f86d378b9f5bfbd56490e9d"
},
{
"url": "https://git.kernel.org/stable/c/2107a4fc8ff1cf1d52f416c1e5cc8e97413a5915"
},
{
"url": "https://git.kernel.org/stable/c/a3e794136ab5e3ad1e7019175a4b837aec86db4b"
},
{
"url": "https://git.kernel.org/stable/c/19bdfc7b3c179331eafa423d87e1336f43bbfeb8"
}
],
"title": "USB: ldusb: fix use-after-free on disconnect race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64343",
"datePublished": "2026-07-25T08:50:05.828Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:47.172Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-39939 (GCVE-0-2025-39939)
Vulnerability from cvelistv5
Published
2025-10-04 07:31
Modified
2026-08-05 12:06
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/s390: Fix memory corruption when using identity domain
zpci_get_iommu_ctrs() returns counter information to be reported as part
of device statistics; these counters are stored as part of the s390_domain.
The problem, however, is that the identity domain is not backed by an
s390_domain and so the conversion via to_s390_domain() yields a bad address
that is zero'd initially and read on-demand later via a sysfs read.
These counters aren't necessary for the identity domain; just return NULL
in this case.
This issue was discovered via KASAN with reports that look like:
BUG: KASAN: global-out-of-bounds in zpci_fmb_enable_device
when using the identity domain for a device on s390.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iommu/s390-iommu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "17a58caf3863163c4a84a218a9649be2c8061443",
"status": "affected",
"version": "64af12c6ec3afd7d44bc8b2044eee59f98059087",
"versionType": "git"
},
{
"lessThan": "b3506e9bcc777ed6af2ab631c86a9990ed97b474",
"status": "affected",
"version": "64af12c6ec3afd7d44bc8b2044eee59f98059087",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iommu/s390-iommu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"lessThan": "6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.16.*",
"status": "unaffected",
"version": "6.16.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.17",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16.9",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17",
"versionStartIncluding": "6.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/s390: Fix memory corruption when using identity domain\n\nzpci_get_iommu_ctrs() returns counter information to be reported as part\nof device statistics; these counters are stored as part of the s390_domain.\nThe problem, however, is that the identity domain is not backed by an\ns390_domain and so the conversion via to_s390_domain() yields a bad address\nthat is zero\u0027d initially and read on-demand later via a sysfs read.\nThese counters aren\u0027t necessary for the identity domain; just return NULL\nin this case.\n\nThis issue was discovered via KASAN with reports that look like:\nBUG: KASAN: global-out-of-bounds in zpci_fmb_enable_device\nwhen using the identity domain for a device on s390."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is s390 PCI/IOMMU infrastructure reached through local interfaces only \u2014 `pci_enable_device()` on driver bind and the debugfs `/sys/kernel/debug/pci/\u003cdev\u003e/statistics` file. There is no network-facing path to `zpci_get_iommu_ctrs()`.\nAC:L - Once a device uses the identity domain, the out-of-bounds access is fully deterministic \u2014 no race to win and no attacker-uninfluenceable memory layout \u2014 corrupting the same fixed 40-byte region on every `zpci_fmb_enable_device()` call and leaking it on every statistics read. Passthrough mode is a supported, documented runtime option on s390, not an obscure debug-only Kconfig.\nPR:L - The corrupting write happens automatically during normal `pci_enable_device()` at boot/driver bind with no attacker action at all, and the disclosure file is created world-readable (`S_IFREG | S_IRUGO | S_IWUSR`), so an unprivileged local user on a system with a traversable debugfs can harvest the leaked kernel global memory. No capability check gates `zpci_get_iommu_ctrs()` itself.\nUI:N - No victim action is needed; the counter reset fires on device enable and the OOB read happens on a plain file read. Nothing requires a second user to mount, open, or configure anything.\nS:U - The corruption and disclosure are confined to kernel `.data` within the kernel\u0027s own security authority \u2014 the bug mislocates statistics counters and does not alter IOMMU translation or bypass the DMA isolation boundary. Standard kernel-internal memory corruption is Unchanged scope.\nC:H - `pci_sw_counter_show()` reads 40 bytes past the end of `s390_identity_domain` and prints them verbatim to userspace, disclosing adjacent kernel global data such as `blocking_domain`\u0027s `ops`/`owner` function-pointer and structure pointers \u2014 a direct kernel address leak defeating KASLR and exposing kernel state.\nI:H - Five `atomic64_set()` calls zero 40 bytes of adjacent kernel global memory, overwriting live control structures \u2014 at +16 past the object this lands exactly on an `iommu_domain`\u0027s `const struct iommu_domain_ops *ops` field, nulling a function-pointer table. This is genuine kernel memory corruption of security-relevant control data, as the commit subject states.\nA:H - Zeroing adjacent globals (e.g. `blocking_domain.ops`) produces NULL-pointer dereferences in `__iommu_attach_device()` when the blocking/release domain is later attached, and KASAN reports a `global-out-of-bounds` BUG in `zpci_fmb_enable_device`. Both result in a kernel oops/panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:06:14.864Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/17a58caf3863163c4a84a218a9649be2c8061443"
},
{
"url": "https://git.kernel.org/stable/c/b3506e9bcc777ed6af2ab631c86a9990ed97b474"
}
],
"title": "iommu/s390: Fix memory corruption when using identity domain",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-39939",
"datePublished": "2025-10-04T07:31:02.521Z",
"dateReserved": "2025-04-16T07:20:57.148Z",
"dateUpdated": "2026-08-05T12:06:14.864Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52925 (GCVE-0-2026-52925)
Vulnerability from cvelistv5
Published
2026-06-24 07:14
Modified
2026-06-24 07:14
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vrf: Fix a potential NPD when removing a port from a VRF
RCU readers that identified a net device as a VRF port using
netif_is_l3_slave() assume that a subsequent call to
netdev_master_upper_dev_get_rcu() will return a VRF device. They then
continue to dereference its l3mdev operations.
This assumption is not always correct and can result in a NPD [1]. There
is no RCU synchronization when removing a port from a VRF, so it is
possible for an RCU reader to see a new master device (e.g., a bridge)
that does not have l3mdev operations.
Fix by adding RCU synchronization after clearing the IFF_L3MDEV_SLAVE
flag. Skip this synchronization when a net device is removed from a VRF
as part of its deletion and when the VRF device itself is deleted. In
the latter case an RCU grace period will pass by the time RTNL is
released.
[1]
BUG: kernel NULL pointer dereference, address: 0000000000000000
[...]
RIP: 0010:l3mdev_fib_table_rcu (net/l3mdev/l3mdev.c:181)
[...]
Call Trace:
<TASK>
l3mdev_fib_table_by_index (net/l3mdev/l3mdev.c:201 net/l3mdev/l3mdev.c:189)
__inet_bind (net/ipv4/af_inet.c:499 (discriminator 3))
inet_bind_sk (net/ipv4/af_inet.c:469)
__sys_bind (./include/linux/file.h:62 (discriminator 1) ./include/linux/file.h:83 (discriminator 1) net/socket.c:1951 (discriminator 1))
__x64_sys_bind (net/socket.c:1969 (discriminator 1) net/socket.c:1967 (discriminator 1) net/socket.c:1967 (discriminator 1))
do_syscall_64 (arch/x86/entry/syscall_64.c:63 (discriminator 1) arch/x86/entry/syscall_64.c:94 (discriminator 1))
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fdeea7be88b12742bfd50d9e19a06c0d2e702400 Version: fdeea7be88b12742bfd50d9e19a06c0d2e702400 Version: fdeea7be88b12742bfd50d9e19a06c0d2e702400 Version: fdeea7be88b12742bfd50d9e19a06c0d2e702400 Version: fdeea7be88b12742bfd50d9e19a06c0d2e702400 Version: fdeea7be88b12742bfd50d9e19a06c0d2e702400 Version: fdeea7be88b12742bfd50d9e19a06c0d2e702400 Version: fdeea7be88b12742bfd50d9e19a06c0d2e702400 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vrf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2c022f582fd16a470df6ed9e7fb7e9fc48946d49",
"status": "affected",
"version": "fdeea7be88b12742bfd50d9e19a06c0d2e702400",
"versionType": "git"
},
{
"lessThan": "4ab6fc60ed5a0344b60711b09bff1dc238d8d6a4",
"status": "affected",
"version": "fdeea7be88b12742bfd50d9e19a06c0d2e702400",
"versionType": "git"
},
{
"lessThan": "468defa0b70902a22f4478c1207624bc1b31c124",
"status": "affected",
"version": "fdeea7be88b12742bfd50d9e19a06c0d2e702400",
"versionType": "git"
},
{
"lessThan": "3db8d078f7f652379ee394132b169d304f6eb4c1",
"status": "affected",
"version": "fdeea7be88b12742bfd50d9e19a06c0d2e702400",
"versionType": "git"
},
{
"lessThan": "8c2b792f04a3db97c9d8d2a45817e93f8884baf5",
"status": "affected",
"version": "fdeea7be88b12742bfd50d9e19a06c0d2e702400",
"versionType": "git"
},
{
"lessThan": "a7a97f2303e63ede105c1d55ef53dc497364e11d",
"status": "affected",
"version": "fdeea7be88b12742bfd50d9e19a06c0d2e702400",
"versionType": "git"
},
{
"lessThan": "d47204c127992da0c976ac9747070a575912e0fe",
"status": "affected",
"version": "fdeea7be88b12742bfd50d9e19a06c0d2e702400",
"versionType": "git"
},
{
"lessThan": "2674d603a9e6970463b2b9ebcf8e31e90beae169",
"status": "affected",
"version": "fdeea7be88b12742bfd50d9e19a06c0d2e702400",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vrf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvrf: Fix a potential NPD when removing a port from a VRF\n\nRCU readers that identified a net device as a VRF port using\nnetif_is_l3_slave() assume that a subsequent call to\nnetdev_master_upper_dev_get_rcu() will return a VRF device. They then\ncontinue to dereference its l3mdev operations.\n\nThis assumption is not always correct and can result in a NPD [1]. There\nis no RCU synchronization when removing a port from a VRF, so it is\npossible for an RCU reader to see a new master device (e.g., a bridge)\nthat does not have l3mdev operations.\n\nFix by adding RCU synchronization after clearing the IFF_L3MDEV_SLAVE\nflag. Skip this synchronization when a net device is removed from a VRF\nas part of its deletion and when the VRF device itself is deleted. In\nthe latter case an RCU grace period will pass by the time RTNL is\nreleased.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 0000000000000000\n[...]\nRIP: 0010:l3mdev_fib_table_rcu (net/l3mdev/l3mdev.c:181)\n[...]\nCall Trace:\n\u003cTASK\u003e\nl3mdev_fib_table_by_index (net/l3mdev/l3mdev.c:201 net/l3mdev/l3mdev.c:189)\n__inet_bind (net/ipv4/af_inet.c:499 (discriminator 3))\ninet_bind_sk (net/ipv4/af_inet.c:469)\n__sys_bind (./include/linux/file.h:62 (discriminator 1) ./include/linux/file.h:83 (discriminator 1) net/socket.c:1951 (discriminator 1))\n__x64_sys_bind (net/socket.c:1969 (discriminator 1) net/socket.c:1967 (discriminator 1) net/socket.c:1967 (discriminator 1))\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 (discriminator 1) arch/x86/entry/syscall_64.c:94 (discriminator 1))\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)"
}
],
"providerMetadata": {
"dateUpdated": "2026-06-24T07:14:19.351Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2c022f582fd16a470df6ed9e7fb7e9fc48946d49"
},
{
"url": "https://git.kernel.org/stable/c/4ab6fc60ed5a0344b60711b09bff1dc238d8d6a4"
},
{
"url": "https://git.kernel.org/stable/c/468defa0b70902a22f4478c1207624bc1b31c124"
},
{
"url": "https://git.kernel.org/stable/c/3db8d078f7f652379ee394132b169d304f6eb4c1"
},
{
"url": "https://git.kernel.org/stable/c/8c2b792f04a3db97c9d8d2a45817e93f8884baf5"
},
{
"url": "https://git.kernel.org/stable/c/a7a97f2303e63ede105c1d55ef53dc497364e11d"
},
{
"url": "https://git.kernel.org/stable/c/d47204c127992da0c976ac9747070a575912e0fe"
},
{
"url": "https://git.kernel.org/stable/c/2674d603a9e6970463b2b9ebcf8e31e90beae169"
}
],
"title": "vrf: Fix a potential NPD when removing a port from a VRF",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52925",
"datePublished": "2026-06-24T07:14:19.351Z",
"dateReserved": "2026-06-09T07:44:35.368Z",
"dateUpdated": "2026-06-24T07:14:19.351Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68216 (GCVE-0-2026-68216)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: pwc: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
pwc's start_streaming() had two early returns that hit this trap:
-ENODEV when the USB device was already disconnected, and -ERESTARTSYS
when mutex_lock_interruptible() was interrupted by a signal. Call the
existing pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED
before returning (matching the state already used by the
pwc_isoc_init() error path in the same function).
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d552852bf76b7dfb35b4593fc874d8dd2f1b1bf3",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "0362ae30b61b3053ee3095c1b8f179197ec4f539",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "fa78e590852751d3ad32f33f6b4e210fe6ccbe9b",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "f2f9fcacd81953dde6cb86312ab13ca13e689664",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "5d7cc2634c3843a1414a0f6407aa17f1f91dee60",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "cb16b79a2be2cec9c3ebe4147490817c4d8b1de3",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "a4f8f629983f643333e49df90557805469bcbb25",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "975b2ee20e569d47821e4f6c9761b4664d48a6a4",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pwc: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\npwc\u0027s start_streaming() had two early returns that hit this trap:\n-ENODEV when the USB device was already disconnected, and -ERESTARTSYS\nwhen mutex_lock_interruptible() was interrupted by a signal. Call the\nexisting pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED\nbefore returning (matching the state already used by the\npwc_isoc_init() error path in the same function).\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the VIDIOC_STREAMON ioctl on a local V4L2 device node (/dev/videoN) exposed by the pwc USB webcam driver, so the attacker needs local access to the system rather than network reachability.\nAC:L - The -ERESTARTSYS path is triggered deterministically by the attacker: hold pdev-\u003ev4l2_lock from a second thread/fd and send a signal to the thread blocked in mutex_lock_interruptible() inside start_streaming(), so both sides of the timing window are attacker-controlled and repeatable.\nPR:L - Only an unprivileged local account with access to the video device node (typical for desktop, kiosk and embedded video appliances, where the video group or logind ACLs grant it) is needed; no capabilities or root are required.\nUI:N - The attacker performs the entire sequence (REQBUFS, QBUF, STREAMON, signal delivery) from its own process; no action by any other user is needed.\nS:U - The buffer-accounting breakage and the resulting list corruption stay within the kernel\u0027s own security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Buffers left on pdev-\u003equeued_bufs after vb2 has already reclaimed them to QUEUED are re-linked on the next STREAMON, so the same pwc_frame_buf can be filled and completed while vb2 considers it userspace-owned, allowing an attacker to read kernel-managed frame data through stale mmap\u0027ed buffers.\nI:H - The double list_add_tail() of an already-linked buf-\u003elist node corrupts the driver\u0027s queued-buffer list and desynchronizes vb2\u0027s owned_by_drv_count, giving overlapping kernel/userspace ownership of buffer objects that can be leveraged for controlled modification of kernel-side state.\nA:H - Each attempt fires WARN_ON(owned_by_drv_count) in vb2_start_streaming(), which panics the machine on panic_on_warn kernels, and the leaked/corrupted buffer list additionally leads to lost buffers and unstable streaming state on subsequent STREAMON/STREAMOFF cycles."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:47.114Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d552852bf76b7dfb35b4593fc874d8dd2f1b1bf3"
},
{
"url": "https://git.kernel.org/stable/c/0362ae30b61b3053ee3095c1b8f179197ec4f539"
},
{
"url": "https://git.kernel.org/stable/c/fa78e590852751d3ad32f33f6b4e210fe6ccbe9b"
},
{
"url": "https://git.kernel.org/stable/c/f2f9fcacd81953dde6cb86312ab13ca13e689664"
},
{
"url": "https://git.kernel.org/stable/c/5d7cc2634c3843a1414a0f6407aa17f1f91dee60"
},
{
"url": "https://git.kernel.org/stable/c/cb16b79a2be2cec9c3ebe4147490817c4d8b1de3"
},
{
"url": "https://git.kernel.org/stable/c/a4f8f629983f643333e49df90557805469bcbb25"
},
{
"url": "https://git.kernel.org/stable/c/975b2ee20e569d47821e4f6c9761b4664d48a6a4"
}
],
"title": "media: pwc: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68216",
"datePublished": "2026-08-10T12:00:35.592Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:47.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64563 (GCVE-0-2026-64563)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rhashtable: clear stale iter->p on table restart
rhashtable_walk_start_check() has two restart paths when resuming a walk.
When iter->walker.tbl is valid, it re-validates iter->p against the table
and sets iter->p = NULL if the object is gone. When iter->walker.tbl is
NULL (table was freed during resize), it resets slot and skip but forgets
to clear iter->p.
rhashtable_walk_next() then dereferences the stale iter->p, reading
freed memory. This is a use-after-free.
Any caller that does multi-fragment rhashtable walks across
walk_stop/walk_start boundaries is affected. Concrete cases include
netlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC
(tipc_nl_sk_walk in net/tipc/socket.c).
Crash stack (netlink_diag):
BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0
Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)
Call Trace:
rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)
__netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)
netlink_diag_dump+0xc2/0x240
netlink_dump+0x5bc/0x1270
netlink_recvmsg+0x7a3/0x980
sock_recvmsg+0x1bc/0x200
__sys_recvfrom+0x1d4/0x2c0
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"lib/rhashtable.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ba510b5e9fe396497d31162acb579f210adfe6c8",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "a0406c40c6638c5ae50257db6297b2fba6c9ba16",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "0955b65c2b47c30b439e2cf1b1e375073aa0413a",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "c39643ad99fea749be50615550e8f0e6d6e60694",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "042fda5c088015f18838e5c692659a7be60aeb26",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "3ff7c1dbf722cf3fa538672452ba182318e0fcc3",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "8173f7e2ce67e6ca1d4763f3da14e5b01ce77456",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"lib/rhashtable.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrhashtable: clear stale iter-\u003ep on table restart\n\nrhashtable_walk_start_check() has two restart paths when resuming a walk.\nWhen iter-\u003ewalker.tbl is valid, it re-validates iter-\u003ep against the table\nand sets iter-\u003ep = NULL if the object is gone. When iter-\u003ewalker.tbl is\nNULL (table was freed during resize), it resets slot and skip but forgets\nto clear iter-\u003ep.\n\nrhashtable_walk_next() then dereferences the stale iter-\u003ep, reading\nfreed memory. This is a use-after-free.\n\nAny caller that does multi-fragment rhashtable walks across\nwalk_stop/walk_start boundaries is affected. Concrete cases include\nnetlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC\n(tipc_nl_sk_walk in net/tipc/socket.c).\n\nCrash stack (netlink_diag):\n BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0\n Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)\n Call Trace:\n rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)\n __netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)\n netlink_diag_dump+0xc2/0x240\n netlink_dump+0x5bc/0x1270\n netlink_recvmsg+0x7a3/0x980\n sock_recvmsg+0x1bc/0x200\n __sys_recvfrom+0x1d4/0x2c0"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via local netlink sock_diag dumps (e.g. netlink_diag over NETLINK_SOCK_DIAG) and similar local dump walkers such as TIPC_NL_SOCK_GET; not reachable from remote packet processing.\nAC:L - Attacker controls both sides of the race by running a multi-fragment rhashtable dump while concurrently creating/destroying netlink (or TIPC) sockets to force table resize and free the walked object.\nPR:L - An unprivileged local user can open NETLINK_SOCK_DIAG and dump without CAP_NET_ADMIN; CAP_NET_ADMIN is only required for SOCK_DESTROY, and TIPC_NL_SOCK_GET likewise has no admin permission flag.\nUI:N - Exploitation requires only attacker-issued syscalls (netlink dump plus concurrent socket churn); no victim action is needed.\nS:U - Impact is memory corruption within the host kernel authority (local privilege escalation/crash), not a cross-boundary escape such as guest-to-host or IOMMU bypass.\nC:H - Use-after-free read of a freed hashed object (e.g. netlink_sock) can be reclaimed via heap spray, yielding an arbitrary read primitive through subsequent walk/diag use of the corrupted pointer.\nI:H - UAF on a reclaimable slab object enables heap spraying and fake-object injection into the walk path, which can be leveraged for arbitrary write or control-flow hijacking.\nA:H - The demonstrated KASAN slab-use-after-free in rhashtable_walk_next can oops/panic the kernel, and UAFs remain crashable even when not fully exploited."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:34.797Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ba510b5e9fe396497d31162acb579f210adfe6c8"
},
{
"url": "https://git.kernel.org/stable/c/a0406c40c6638c5ae50257db6297b2fba6c9ba16"
},
{
"url": "https://git.kernel.org/stable/c/0955b65c2b47c30b439e2cf1b1e375073aa0413a"
},
{
"url": "https://git.kernel.org/stable/c/c39643ad99fea749be50615550e8f0e6d6e60694"
},
{
"url": "https://git.kernel.org/stable/c/042fda5c088015f18838e5c692659a7be60aeb26"
},
{
"url": "https://git.kernel.org/stable/c/3ff7c1dbf722cf3fa538672452ba182318e0fcc3"
},
{
"url": "https://git.kernel.org/stable/c/4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3"
},
{
"url": "https://git.kernel.org/stable/c/8173f7e2ce67e6ca1d4763f3da14e5b01ce77456"
}
],
"title": "rhashtable: clear stale iter-\u003ep on table restart",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64563",
"datePublished": "2026-08-04T06:23:22.601Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:34.797Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74548 (GCVE-0-2026-74548)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
forcedeth: fix UAF of txrx_stats in nv_remove
nv_remove() frees the per-CPU txrx_stats before unregister_netdev().
Until unregister completes, ndo_get_stats64, the NAPI/xmit data path,
and nv_close()/drain may still access txrx_stats, leading to a
use-after-free.
Free the stats only after unregister_netdev().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/nvidia/forcedeth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cdf864d5d3c813ae1876f2bacc1cf3ac3c66dfc9",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "7c22b4ee0bd003cecfc14ca28981cb213e201f70",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "d51ce7a63b76eda02cabfed1b0cc277b2f5c9bcc",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "cf2dcde2284562ff87830ca0b7fa2b06e95aef1e",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "c9d24a205fd508b9999fcab6aca4c590490a12cf",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "ae20a8a4de06a289d40b0a0633d8d573f1fcb049",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "201e05aa531eba0dfe2ee05b4e178f6ffa12c8b1",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "22666ba1420164753d7b0f5a841986b25ace5435",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/nvidia/forcedeth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nforcedeth: fix UAF of txrx_stats in nv_remove\n\nnv_remove() frees the per-CPU txrx_stats before unregister_netdev().\nUntil unregister completes, ndo_get_stats64, the NAPI/xmit data path,\nand nv_close()/drain may still access txrx_stats, leading to a\nuse-after-free.\n\nFree the stats only after unregister_netdev()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is opened in nv_remove() during local PCI/driver teardown (sysfs unbind, module unload, or hot-unplug); although NAPI/xmit and stats readers can run concurrently on still-registered netdev traffic, there is no standalone remote path into nv_remove itself.\nAC:L - Once teardown starts, unregister_netdev() deterministically calls nv_close()\u2192nv_drain_tx(), which increments freed txrx_stats when TX skbs remain, and an attacker can also drive the race by timing unbind against stats polling or packet I/O they control.\nPR:L - Privileged teardown opens the window, but unprivileged peers can supply the concurrent netdev access (rtnetlink/sysfs stats via nv_get_stats64, and RX/TX on the still-up interface) that performs the UAF; per CNA driver-removal UAF precedent and the higher-severity tiebreak, PR:L.\nUI:N - No separate victim action is required beyond routine driver removal or module unload on a live interface; monitoring daemons and network traffic can hit the freed stats automatically during the unregister window without user cooperation.\nS:U - Impact is kernel heap corruption and crash/privilege escalation within the host kernel security authority; it does not cross VM, hypervisor, IOMMU, or container sandbox boundaries.\nC:H - The bug is a kmalloc-backed per-CPU UAF: nv_get_stats64 reads freed nv_txrx_stats counters via per_cpu_ptr(), and once the slab is reallocated an attacker can obtain arbitrary kernel memory disclosure.\nI:H - Freed txrx_stats are updated from NAPI/xmit and nv_drain_tx() via __this_cpu_inc/add on attacker-influenced traffic, enabling heap grooming and controlled writes through the dangling per-CPU pointer for code execution.\nA:H - Use-after-free dereferences of txrx_stats during netdev teardown reliably cause kernel oops/panic (as in the fix description), and even unsuccessful exploitation still crashes the system when concurrent RX/TX or drain paths touch freed memory."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:39.684Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cdf864d5d3c813ae1876f2bacc1cf3ac3c66dfc9"
},
{
"url": "https://git.kernel.org/stable/c/7c22b4ee0bd003cecfc14ca28981cb213e201f70"
},
{
"url": "https://git.kernel.org/stable/c/d51ce7a63b76eda02cabfed1b0cc277b2f5c9bcc"
},
{
"url": "https://git.kernel.org/stable/c/cf2dcde2284562ff87830ca0b7fa2b06e95aef1e"
},
{
"url": "https://git.kernel.org/stable/c/c9d24a205fd508b9999fcab6aca4c590490a12cf"
},
{
"url": "https://git.kernel.org/stable/c/ae20a8a4de06a289d40b0a0633d8d573f1fcb049"
},
{
"url": "https://git.kernel.org/stable/c/201e05aa531eba0dfe2ee05b4e178f6ffa12c8b1"
},
{
"url": "https://git.kernel.org/stable/c/22666ba1420164753d7b0f5a841986b25ace5435"
}
],
"title": "forcedeth: fix UAF of txrx_stats in nv_remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74548",
"datePublished": "2026-08-15T12:27:56.387Z",
"dateReserved": "2026-08-15T05:44:03.915Z",
"dateUpdated": "2026-08-19T16:38:39.684Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52990 (GCVE-0-2026-52990)
Vulnerability from cvelistv5
Published
2026-06-24 16:29
Modified
2026-06-24 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fsnotify: fix inode reference leak in fsnotify_recalc_mask()
fsnotify_recalc_mask() fails to handle the return value of
__fsnotify_recalc_mask(), which may return an inode pointer that needs
to be released via fsnotify_drop_object() when the connector's HAS_IREF
flag transitions from set to cleared.
This manifests as a hung task with the following call trace:
INFO: task umount:1234 blocked for more than 120 seconds.
Call Trace:
__schedule
schedule
fsnotify_sb_delete
generic_shutdown_super
kill_anon_super
cleanup_mnt
task_work_run
do_exit
do_group_exit
The race window that triggers the iref leak:
Thread A (adding mark) Thread B (removing mark)
────────────────────── ────────────────────────
fsnotify_add_mark_locked():
fsnotify_add_mark_list():
spin_lock(conn->lock)
add mark_B(evictable) to list
spin_unlock(conn->lock)
return
/* ---- gap: no lock held ---- */
fsnotify_detach_mark(mark_A):
spin_lock(mark_A->lock)
clear ATTACHED flag on mark_A
spin_unlock(mark_A->lock)
fsnotify_put_mark(mark_A)
fsnotify_recalc_mask():
spin_lock(conn->lock)
__fsnotify_recalc_mask():
/* mark_A skipped: ATTACHED cleared */
/* only mark_B(evictable) remains */
want_iref = false
has_iref = true /* not yet cleared */
-> HAS_IREF transitions true -> false
-> returns inode pointer
spin_unlock(conn->lock)
/* BUG: return value discarded!
* iput() and fsnotify_put_sb_watched_objects()
* are never called */
Fix this by deferring the transition true -> false of HAS_IREF flag from
fsnotify_recalc_mask() (Thread A) to fsnotify_put_mark() (thread B).
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c3638b5b13740fa31762d414bbce8b7a694e582a Version: c3638b5b13740fa31762d414bbce8b7a694e582a Version: c3638b5b13740fa31762d414bbce8b7a694e582a Version: c3638b5b13740fa31762d414bbce8b7a694e582a Version: ff34ebaa6f6dc1eebce6a8d6f12a1566f33d00fe Version: 4f145b67c075324b13d6ae7d5abb6e7a1dbac26d Version: 5.10.220 ≤ Version: 5.15.154 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/notify/mark.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8c8afa6444e6bdc145d2bf2f3aeeca6da3e36b42",
"status": "affected",
"version": "c3638b5b13740fa31762d414bbce8b7a694e582a",
"versionType": "git"
},
{
"lessThan": "b740cc86816bbc87902ae9db74cd21abde3c8d63",
"status": "affected",
"version": "c3638b5b13740fa31762d414bbce8b7a694e582a",
"versionType": "git"
},
{
"lessThan": "5c80289503da3658e3df80280598c68d181eadbd",
"status": "affected",
"version": "c3638b5b13740fa31762d414bbce8b7a694e582a",
"versionType": "git"
},
{
"lessThan": "4aca914ac152f5d055ddcb36704d1e539ac08977",
"status": "affected",
"version": "c3638b5b13740fa31762d414bbce8b7a694e582a",
"versionType": "git"
},
{
"status": "affected",
"version": "ff34ebaa6f6dc1eebce6a8d6f12a1566f33d00fe",
"versionType": "git"
},
{
"status": "affected",
"version": "4f145b67c075324b13d6ae7d5abb6e7a1dbac26d",
"versionType": "git"
},
{
"lessThan": "5.11",
"status": "affected",
"version": "5.10.220",
"versionType": "semver"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.154",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/notify/mark.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.10.220",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.154",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfsnotify: fix inode reference leak in fsnotify_recalc_mask()\n\nfsnotify_recalc_mask() fails to handle the return value of\n__fsnotify_recalc_mask(), which may return an inode pointer that needs\nto be released via fsnotify_drop_object() when the connector\u0027s HAS_IREF\nflag transitions from set to cleared.\n\nThis manifests as a hung task with the following call trace:\n\n INFO: task umount:1234 blocked for more than 120 seconds.\n Call Trace:\n __schedule\n schedule\n fsnotify_sb_delete\n generic_shutdown_super\n kill_anon_super\n cleanup_mnt\n task_work_run\n do_exit\n do_group_exit\n\nThe race window that triggers the iref leak:\n\n Thread A (adding mark) Thread B (removing mark)\n \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500 \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\n fsnotify_add_mark_locked():\n fsnotify_add_mark_list():\n spin_lock(conn-\u003elock)\n add mark_B(evictable) to list\n spin_unlock(conn-\u003elock)\n return\n\n /* ---- gap: no lock held ---- */\n\n fsnotify_detach_mark(mark_A):\n spin_lock(mark_A-\u003elock)\n clear ATTACHED flag on mark_A\n spin_unlock(mark_A-\u003elock)\n fsnotify_put_mark(mark_A)\n\n fsnotify_recalc_mask():\n spin_lock(conn-\u003elock)\n __fsnotify_recalc_mask():\n /* mark_A skipped: ATTACHED cleared */\n /* only mark_B(evictable) remains */\n want_iref = false\n has_iref = true /* not yet cleared */\n -\u003e HAS_IREF transitions true -\u003e false\n -\u003e returns inode pointer\n spin_unlock(conn-\u003elock)\n /* BUG: return value discarded!\n * iput() and fsnotify_put_sb_watched_objects()\n * are never called */\n\nFix this by deferring the transition true -\u003e false of HAS_IREF flag from\nfsnotify_recalc_mask() (Thread A) to fsnotify_put_mark() (thread B)."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-24T16:29:04.148Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8c8afa6444e6bdc145d2bf2f3aeeca6da3e36b42"
},
{
"url": "https://git.kernel.org/stable/c/b740cc86816bbc87902ae9db74cd21abde3c8d63"
},
{
"url": "https://git.kernel.org/stable/c/5c80289503da3658e3df80280598c68d181eadbd"
},
{
"url": "https://git.kernel.org/stable/c/4aca914ac152f5d055ddcb36704d1e539ac08977"
}
],
"title": "fsnotify: fix inode reference leak in fsnotify_recalc_mask()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52990",
"datePublished": "2026-06-24T16:29:04.148Z",
"dateReserved": "2026-06-09T07:44:35.376Z",
"dateUpdated": "2026-06-24T16:29:04.148Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64541 (GCVE-0-2026-64541)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
smc_cdc_rx_handler() looks up the connection by token under the link
group's conns_lock, drops the lock, and then dereferences conn and the
smc_sock derived from it, ending in sock_hold(&smc->sk) inside
smc_cdc_msg_recv(). No reference is held across the lock release.
The only reference pinning the socket while the connection is
discoverable in the link group is taken in smc_lgr_register_conn()
(sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both
under conns_lock. Once the handler drops conns_lock, a concurrent
close() -> smc_release() -> smc_conn_free() -> smc_lgr_unregister_conn()
can drop that reference and free the smc_sock, so the handler's later
sock_hold() runs on freed memory:
WARNING: lib/refcount.c:25 at refcount_warn_saturate
Workqueue: rxe_wq do_work
refcount_warn_saturate (lib/refcount.c:25)
smc_cdc_msg_recv (net/smc/smc_cdc.c:430)
smc_cdc_rx_handler (net/smc/smc_cdc.c:502)
smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445)
tasklet_action_common (kernel/softirq.c:938)
handle_softirqs (kernel/softirq.c:622)
Kernel panic - not syncing: panic_on_warn set
Only SMC-R is affected. The SMC-D receive tasklet is stopped by
tasklet_kill(&conn->rx_tsklet) in smc_conn_free() before the connection
is unregistered, so it cannot run concurrently with the free.
Take the socket reference while still holding conns_lock, so the
registration reference can no longer be the last one, and drop it once
the handler is done.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d7b0e37c1ac152905b18a5b9506179091a35b0b6 Version: d7b0e37c1ac152905b18a5b9506179091a35b0b6 Version: d7b0e37c1ac152905b18a5b9506179091a35b0b6 Version: d7b0e37c1ac152905b18a5b9506179091a35b0b6 Version: d7b0e37c1ac152905b18a5b9506179091a35b0b6 Version: d7b0e37c1ac152905b18a5b9506179091a35b0b6 Version: d7b0e37c1ac152905b18a5b9506179091a35b0b6 Version: d7b0e37c1ac152905b18a5b9506179091a35b0b6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/smc_cdc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8de4f665d0febfb92803dece377791a563fc7041",
"status": "affected",
"version": "d7b0e37c1ac152905b18a5b9506179091a35b0b6",
"versionType": "git"
},
{
"lessThan": "8145b432136285e01091815b48ceb2dae261f262",
"status": "affected",
"version": "d7b0e37c1ac152905b18a5b9506179091a35b0b6",
"versionType": "git"
},
{
"lessThan": "1951bffbc6493ec34cff3956b29d4bc6606904a6",
"status": "affected",
"version": "d7b0e37c1ac152905b18a5b9506179091a35b0b6",
"versionType": "git"
},
{
"lessThan": "647b19e5cc145a2f1f685ae8ff3805a17356888c",
"status": "affected",
"version": "d7b0e37c1ac152905b18a5b9506179091a35b0b6",
"versionType": "git"
},
{
"lessThan": "472e9d7c0d5b03be3ff91ff941f57da822b031bc",
"status": "affected",
"version": "d7b0e37c1ac152905b18a5b9506179091a35b0b6",
"versionType": "git"
},
{
"lessThan": "3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb",
"status": "affected",
"version": "d7b0e37c1ac152905b18a5b9506179091a35b0b6",
"versionType": "git"
},
{
"lessThan": "ce5aa8084329351086894aa34d77e40301d5bd3d",
"status": "affected",
"version": "d7b0e37c1ac152905b18a5b9506179091a35b0b6",
"versionType": "git"
},
{
"lessThan": "9d160b35cc34a2ba8229d07651468a7848325135",
"status": "affected",
"version": "d7b0e37c1ac152905b18a5b9506179091a35b0b6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/smc_cdc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket\n\nsmc_cdc_rx_handler() looks up the connection by token under the link\ngroup\u0027s conns_lock, drops the lock, and then dereferences conn and the\nsmc_sock derived from it, ending in sock_hold(\u0026smc-\u003esk) inside\nsmc_cdc_msg_recv(). No reference is held across the lock release.\n\nThe only reference pinning the socket while the connection is\ndiscoverable in the link group is taken in smc_lgr_register_conn()\n(sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both\nunder conns_lock. Once the handler drops conns_lock, a concurrent\nclose() -\u003e smc_release() -\u003e smc_conn_free() -\u003e smc_lgr_unregister_conn()\ncan drop that reference and free the smc_sock, so the handler\u0027s later\nsock_hold() runs on freed memory:\n\n WARNING: lib/refcount.c:25 at refcount_warn_saturate\n Workqueue: rxe_wq do_work\n refcount_warn_saturate (lib/refcount.c:25)\n smc_cdc_msg_recv (net/smc/smc_cdc.c:430)\n smc_cdc_rx_handler (net/smc/smc_cdc.c:502)\n smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445)\n tasklet_action_common (kernel/softirq.c:938)\n handle_softirqs (kernel/softirq.c:622)\n Kernel panic - not syncing: panic_on_warn set\n\nOnly SMC-R is affected. The SMC-D receive tasklet is stopped by\ntasklet_kill(\u0026conn-\u003erx_tsklet) in smc_conn_free() before the connection\nis unregistered, so it cannot run concurrently with the free.\n\nTake the socket reference while still holding conns_lock, so the\nregistration reference can no longer be the last one, and drop it once\nthe handler is done."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable handler is driven entirely by a CDC control message sent by the remote SMC-R peer over the RDMA link, with an attacker-chosen `token` field and no local syscall involvement. SMC-R runs over RoCEv2 (IP/UDP-routable, port 4791) with the CLC handshake over plain TCP, and SMC-Rv2 explicitly supports non-local/routed peers, so the attacker need not share an L2 segment.\nAC:L - The attacker controls both sides of the race: it chooses when to emit CDC messages and which connection to target (the alert token is disclosed to it in the CLC accept/confirm), and it can drive the teardown side itself via CDC close/abort flags into `smc_close_passive_work()` or a stale seqno with `failover_validation` into `abort_work` -\u003e `smc_conn_kill()`. The race can be retried indefinitely across many connections in the same link group, and was reproduced in practice with soft-RoCE.\nPR:N - Establishing an SMC-R connection to a listening SMC socket requires no credentials \u2014 SMC has no authentication layer of its own, exactly like plain TCP. Everything after connection establishment (sending CDC messages with a chosen token, signalling close/abort) is available to an unauthenticated peer.\nUI:N - The CDC message is processed in a softirq tasklet from the RDMA completion queue with no involvement from any local user or application action. No victim interaction of any kind is needed.\nS:U - The corruption is confined to kernel memory within the same security authority; there is no VM, IOMMU, or sandbox boundary crossed. This is a standard in-kernel use-after-free.\nC:H - The freed `smc_sock` is reused type-safely as another live socket, so attacker-supplied cursors applied by `smc_cdc_msg_recv_action()` break the `0 \u003c= bytes_to_rcv \u003c= rmb_desc-\u003elen` invariant and make `smc_rx_recvmsg()` hand stale RMB contents to userspace, while the urgent-data path reads `*(base + conn-\u003eurg_curs.count - 1)` at an attacker-chosen offset. Once the slab page is reclaimed after the RCU grace period, reuse is unconstrained, giving a general kernel-memory read primitive.\nI:H - `sock_hold()` on an already-zero refcount followed by `sock_put()` re-enters `sk_free()`, yielding a double free, and the handler additionally writes `sk_err`/`sk_shutdown`, makes indirect calls through `sk_data_ready()`/`sk_write_space()`, and `queue_work()`s a freed `work_struct`. These are classic heap-spray and control-flow-hijack primitives leading to arbitrary kernel write.\nA:H - The reported symptom is `refcount_warn_saturate` from `smc_cdc_msg_recv()`, which is an immediate kernel panic on `panic_on_warn` systems, and dereferencing freed memory in softirq context otherwise oopses. The attacker can trigger it repeatedly without authentication."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:17.774Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8de4f665d0febfb92803dece377791a563fc7041"
},
{
"url": "https://git.kernel.org/stable/c/8145b432136285e01091815b48ceb2dae261f262"
},
{
"url": "https://git.kernel.org/stable/c/1951bffbc6493ec34cff3956b29d4bc6606904a6"
},
{
"url": "https://git.kernel.org/stable/c/647b19e5cc145a2f1f685ae8ff3805a17356888c"
},
{
"url": "https://git.kernel.org/stable/c/472e9d7c0d5b03be3ff91ff941f57da822b031bc"
},
{
"url": "https://git.kernel.org/stable/c/3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb"
},
{
"url": "https://git.kernel.org/stable/c/ce5aa8084329351086894aa34d77e40301d5bd3d"
},
{
"url": "https://git.kernel.org/stable/c/9d160b35cc34a2ba8229d07651468a7848325135"
}
],
"title": "net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64541",
"datePublished": "2026-07-27T20:10:34.439Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:17.774Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63973 (GCVE-0-2026-63973)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-07-19 14:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Add NULL guards in teardown path to prevent panic on attach failure
When queue allocation fails partway through, the error cleanup frees
and NULLs apc->tx_qp and apc->rxqs. Multiple teardown paths such as
mana_remove(), mana_change_mtu() recovery, and internal error handling
in mana_alloc_queues() can subsequently call into functions that
dereference these pointers without NULL checks:
- mana_chn_setxdp() dereferences apc->rxqs[0], causing a NULL pointer
dereference panic (CR2: 0000000000000000 at mana_chn_setxdp+0x26).
- mana_destroy_vport() iterates apc->rxqs without a NULL check.
- mana_fence_rqs() iterates apc->rxqs without a NULL check.
- mana_dealloc_queues() iterates apc->tx_qp without a NULL check.
Add NULL guards for apc->rxqs in mana_fence_rqs(),
mana_destroy_vport(), and before the mana_chn_setxdp() call. Add a
NULL guard for apc->tx_qp in mana_dealloc_queues() to skip TX queue
draining when TX queues were never allocated or already freed.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/mana_en.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "da7e4a1aaf397af6a094f640c92d6bc7564c10db",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "95e414f8324385771bdfd6d497a01d5593813ccb",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "26a96fa81496afe7d162d172ccdc8cb9dbc685d2",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "da87896f34e0a51489811d1a684e2953099ca98f",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "0a9c520fdcb1cb2e79c163c12d359b5e1ee40007",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "17bfe0a8c014ee1d542ad352cd6a0a505361664a",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/mana_en.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Add NULL guards in teardown path to prevent panic on attach failure\n\nWhen queue allocation fails partway through, the error cleanup frees\nand NULLs apc-\u003etx_qp and apc-\u003erxqs. Multiple teardown paths such as\nmana_remove(), mana_change_mtu() recovery, and internal error handling\nin mana_alloc_queues() can subsequently call into functions that\ndereference these pointers without NULL checks:\n\n- mana_chn_setxdp() dereferences apc-\u003erxqs[0], causing a NULL pointer\n dereference panic (CR2: 0000000000000000 at mana_chn_setxdp+0x26).\n- mana_destroy_vport() iterates apc-\u003erxqs without a NULL check.\n- mana_fence_rqs() iterates apc-\u003erxqs without a NULL check.\n- mana_dealloc_queues() iterates apc-\u003etx_qp without a NULL check.\n\nAdd NULL guards for apc-\u003erxqs in mana_fence_rqs(),\nmana_destroy_vport(), and before the mana_chn_setxdp() call. Add a\nNULL guard for apc-\u003etx_qp in mana_dealloc_queues() to skip TX queue\ndraining when TX queues were never allocated or already freed."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:55:59.263Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/da7e4a1aaf397af6a094f640c92d6bc7564c10db"
},
{
"url": "https://git.kernel.org/stable/c/95e414f8324385771bdfd6d497a01d5593813ccb"
},
{
"url": "https://git.kernel.org/stable/c/26a96fa81496afe7d162d172ccdc8cb9dbc685d2"
},
{
"url": "https://git.kernel.org/stable/c/da87896f34e0a51489811d1a684e2953099ca98f"
},
{
"url": "https://git.kernel.org/stable/c/0a9c520fdcb1cb2e79c163c12d359b5e1ee40007"
},
{
"url": "https://git.kernel.org/stable/c/17bfe0a8c014ee1d542ad352cd6a0a505361664a"
}
],
"title": "net: mana: Add NULL guards in teardown path to prevent panic on attach failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63973",
"datePublished": "2026-07-19T14:55:59.263Z",
"dateReserved": "2026-07-19T07:54:57.024Z",
"dateUpdated": "2026-07-19T14:55:59.263Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72498 (GCVE-0-2026-72498)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:15
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Avoid displaying the kernel pointer
While dumping the info on MR using the rdma tool, we
dump the mr_hwq which is a kernel pointer. There is
no need to expose this value for end user. So avoid
it.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "95d46a8d3ba9fdbe356fe7ed0117bc78dac9d557",
"status": "affected",
"version": "7363eb76b7f3b860ecfb8fcaf537e143bfd725bd",
"versionType": "git"
},
{
"lessThan": "0c403e0786768d88cabe0ccf4e45425da2fd8841",
"status": "affected",
"version": "7363eb76b7f3b860ecfb8fcaf537e143bfd725bd",
"versionType": "git"
},
{
"lessThan": "7d70c704a06f620d5d421ab76bac5e225bfb4308",
"status": "affected",
"version": "7363eb76b7f3b860ecfb8fcaf537e143bfd725bd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Avoid displaying the kernel pointer\n\nWhile dumping the info on MR using the rdma tool, we\ndump the mr_hwq which is a kernel pointer. There is\nno need to expose this value for end user. So avoid\nit."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:15:51.400Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/95d46a8d3ba9fdbe356fe7ed0117bc78dac9d557"
},
{
"url": "https://git.kernel.org/stable/c/0c403e0786768d88cabe0ccf4e45425da2fd8841"
},
{
"url": "https://git.kernel.org/stable/c/7d70c704a06f620d5d421ab76bac5e225bfb4308"
}
],
"title": "RDMA/bnxt_re: Avoid displaying the kernel pointer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72498",
"datePublished": "2026-08-15T05:57:31.037Z",
"dateReserved": "2026-08-09T03:40:39.937Z",
"dateUpdated": "2026-08-17T05:15:51.400Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64334 (GCVE-0-2026-64334)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: digi_acceleport: fix hard lockup on disconnect
If submitting the OOB write urb fails persistently (e.g if the device is
being disconnected) the driver would loop indefinitely with interrupts
disabled.
Check for urb submission errors when sending OOB commands to avoid
hanging if, for example, open(), set_termios() or close() races with a
physical disconnect.
This is issue was flagged by Sashiko when reviewing an unrelated change
to the driver.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/digi_acceleport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6e51147c2744d15730084dc89cc99180d3de4184",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6a8592ace932081ea11aea41c460a1ca0f6344a4",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5a82d842e8c35227d7227f19e5e654df1451782c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "bcfeae431db9986c2b313e6a760f2ac8df61e138",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2067b3838da6e4af03bae3630414193188d754b2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2b7dc482f859f2d027db07ff0efc1c5df5b3451a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "79bc131df0e50f8f663c1fdbbe952aaf193a8d39",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5c1ea24b53bf3bfb859f0a05573997487975da23",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/digi_acceleport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: digi_acceleport: fix hard lockup on disconnect\n\nIf submitting the OOB write urb fails persistently (e.g if the device is\nbeing disconnected) the driver would loop indefinitely with interrupts\ndisabled.\n\nCheck for urb submission errors when sending OOB commands to avoid\nhanging if, for example, open(), set_termios() or close() races with a\nphysical disconnect.\n\nThis is issue was flagged by Sashiko when reviewing an unrelated change\nto the driver."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:37.202Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6e51147c2744d15730084dc89cc99180d3de4184"
},
{
"url": "https://git.kernel.org/stable/c/6a8592ace932081ea11aea41c460a1ca0f6344a4"
},
{
"url": "https://git.kernel.org/stable/c/5a82d842e8c35227d7227f19e5e654df1451782c"
},
{
"url": "https://git.kernel.org/stable/c/bcfeae431db9986c2b313e6a760f2ac8df61e138"
},
{
"url": "https://git.kernel.org/stable/c/2067b3838da6e4af03bae3630414193188d754b2"
},
{
"url": "https://git.kernel.org/stable/c/2b7dc482f859f2d027db07ff0efc1c5df5b3451a"
},
{
"url": "https://git.kernel.org/stable/c/79bc131df0e50f8f663c1fdbbe952aaf193a8d39"
},
{
"url": "https://git.kernel.org/stable/c/5c1ea24b53bf3bfb859f0a05573997487975da23"
}
],
"title": "USB: serial: digi_acceleport: fix hard lockup on disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64334",
"datePublished": "2026-07-25T08:50:00.229Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:37.202Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74321 (GCVE-0-2026-74321)
Vulnerability from cvelistv5
Published
2026-08-15 05:58
Modified
2026-08-17 05:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
In the beginning of the loop, we try to obtain a locked delayed ref head,
if 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(),
which can return an error pointer. If the error pointer is -EAGAIN we do
a continue and go back to the beginning of the loop, which will not try
again to call btrfs_select_ref_head() since 'locked_ref' is no longer
NULL but it's ERR_PTR(-EAGAIN), and then we do:
spin_lock(&locked_ref->lock);
against a ERR_PTR(-EAGAIN) value, generating an invalid pointer
dereference.
Fix this by ensuring that 'locked_ref' is set to NULL when
btrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count'
as well, to prevent infinite looping. We do this by doing a goto to the
bottom of the loop that already sets 'locked_ref' to NULL and does a
cond_resched(), with an increment to 'count' right before the goto.
These measures were in place before the refactoring in commit 0110a4c43451
("btrfs: refactor __btrfs_run_delayed_refs loop") but were unintentionally
lost afterwards.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/extent-tree.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c372ca227e16bace86f1df1fa4ae6849e2fcfa28",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "a71143590ce9764dbcb47617647592ff8b4d48bc",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "65770111a2d47c2b15e20b2ba92bb12198f289d4",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "015dc4a1e0c2cba551d4620eba13d26d5081dc34",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "ba9fa2ff5981589bb49094d3358c339b37c47f53",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "9faa6b69ad73f03c7bde53e07d75a28822dc9a1a",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/extent-tree.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()\n\nIn the beginning of the loop, we try to obtain a locked delayed ref head,\nif \u0027locked_ref\u0027 is currently NULL, by calling btrfs_select_ref_head(),\nwhich can return an error pointer. If the error pointer is -EAGAIN we do\na continue and go back to the beginning of the loop, which will not try\nagain to call btrfs_select_ref_head() since \u0027locked_ref\u0027 is no longer\nNULL but it\u0027s ERR_PTR(-EAGAIN), and then we do:\n\n spin_lock(\u0026locked_ref-\u003elock);\n\nagainst a ERR_PTR(-EAGAIN) value, generating an invalid pointer\ndereference.\n\nFix this by ensuring that \u0027locked_ref\u0027 is set to NULL when\nbtrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing \u0027count\u0027\nas well, to prevent infinite looping. We do this by doing a goto to the\nbottom of the loop that already sets \u0027locked_ref\u0027 to NULL and does a\ncond_resched(), with an increment to \u0027count\u0027 right before the goto.\nThese measures were in place before the refactoring in commit 0110a4c43451\n(\"btrfs: refactor __btrfs_run_delayed_refs loop\") but were unintentionally\nlost afterwards."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On storage servers exporting btrfs via nfsd or ksmbd, remote client write/fsync/unlink I/O reaches btrfs_run_delayed_refs() and __btrfs_run_delayed_refs() in the server kernel without any local syscall; this is the highest-impact but reasonable deployment for btrfs metadata processing.\nAC:L - -EAGAIN is returned when a concurrent task deletes the delayed-ref head during btrfs_delayed_ref_lock(); an attacker controls both sides by driving parallel writes/unlinks/fsync or multiple NFS/SMB clients, reliably hitting the documented race without uncontrollable layout or victim state.\nPR:N - Exploitation needs only network write access to an NFS or SMB export of the btrfs filesystem; no local account, Linux capability, or init-namespace privilege is required when the export permits client writes (including anonymous/guest exports common on NAS appliances).\nUI:N - The fault is triggered entirely by the attacker\u0027s own concurrent filesystem I/O against an already-exported btrfs volume; no separate victim must mount a filesystem, open a file, or perform any interactive action beyond the attacker\u0027s own operations.\nS:U - The invalid pointer dereference and resulting kernel oops occur within the host kernel\u0027s btrfs delayed-ref processing; no VM escape, IOMMU bypass, or cross-sandbox boundary is crossed.\nC:N - The bug dereferences ERR_PTR(-EAGAIN), a small negative sentinel address, not freed or attacker-controlled memory; spin_lock faults immediately without returning kernel data, so there is no information-disclosure or read primitive.\nI:N - This is a logic error causing an invalid pointer dereference, not a use-after-free, out-of-bounds write, or type confusion; no kernel memory is modified before the faulting access aborts execution.\nA:H - Dereferencing ERR_PTR(-EAGAIN) in spin_lock(\u0026locked_ref-\u003elock) causes a kernel oops/panic during delayed-ref processing, which can hang or crash the host and deny all service on the affected btrfs filesystem; the condition is repeatable with concurrent I/O."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:45:52.396Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c372ca227e16bace86f1df1fa4ae6849e2fcfa28"
},
{
"url": "https://git.kernel.org/stable/c/a71143590ce9764dbcb47617647592ff8b4d48bc"
},
{
"url": "https://git.kernel.org/stable/c/65770111a2d47c2b15e20b2ba92bb12198f289d4"
},
{
"url": "https://git.kernel.org/stable/c/015dc4a1e0c2cba551d4620eba13d26d5081dc34"
},
{
"url": "https://git.kernel.org/stable/c/ba9fa2ff5981589bb49094d3358c339b37c47f53"
},
{
"url": "https://git.kernel.org/stable/c/3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1"
},
{
"url": "https://git.kernel.org/stable/c/9faa6b69ad73f03c7bde53e07d75a28822dc9a1a"
},
{
"url": "https://git.kernel.org/stable/c/486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae"
}
],
"title": "btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74321",
"datePublished": "2026-08-15T05:58:17.485Z",
"dateReserved": "2026-08-15T05:44:03.884Z",
"dateUpdated": "2026-08-17T05:45:52.396Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68372 (GCVE-0-2026-68372)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: core: port: Deattach Type-C connector on component unbind
connector_unbind() is the mirror of connector_bind(), but it is missing
the symmetric call to typec_deattach() that connector_bind() makes via:
if (port_dev->child)
typec_attach(port_dev->connector, &port_dev->child->dev);
When a Thunderbolt dock is unplugged, two teardown paths race:
1. The component framework calls connector_unbind() first, which sets
port_dev->connector = NULL without calling typec_deattach(). This
leaves port->usb2_dev/port->usb3_dev in struct typec_port pointing at
the USB device that is about to be freed.
2. usb_disconnect() then calls typec_deattach(port_dev->connector, ...),
but port_dev->connector is already NULL, so the call is a no-op and
port->usb2_dev is never cleared.
3. Concurrently, UCSI detects a PD partner-disconnect event and calls
typec_unregister_partner(), which reads port->usb2_dev (now a dangling
pointer to freed memory) and passes it to typec_partner_unlink_device()
-> sysfs_remove_link() -> dev_name() on the freed device, corrupting
the typec/UCSI partner state.
This corruption leaves the Thunderbolt tunnel in an inconsistent state on
the next dock hot-plug. On affected hardware the dock's I225/igc NIC fails
to enumerate: AER fires a slot reset while the igc driver is still
initialising ("PCIe link lost"), and the subsequent igc_reset attempt hits
igc_rd32 on an already-detached device:
igc 0000:2e:00.0 eth0: PCIe link lost, device now detached
igc: Failed to read reg 0x0!
WARNING: CPU: 9 PID: 129 at drivers/net/ethernet/intel/igc/igc_main.c:7005
igc_rd32+0xa4/0xc0 [igc]
Call Trace:
igc_disable_pcie_master+0x16/0xa0 [igc]
igc_reset_hw_base+0x14/0x170 [igc]
igc_reset+0x63/0x110 [igc]
igc_io_slot_reset+0x9e/0xd0 [igc]
report_slot_reset+0x5d/0xc0
pcie_do_recovery+0x209/0x400
aer_isr_one_error_type+0x235/0x430
aer_isr+0x4e/0x80
irq_thread+0xf4/0x1f0
4. UCSI later handles the PD partner-disconnect and calls
typec_unregister_partner(), which still sees the stale port->usb2_dev
and tries to remove its sysfs link a second time:
kernfs: can not remove 'typec', no directory
WARNING: CPU: 6 PID: 55 at fs/kernfs/dir.c:1706 kernfs_remove_by_name_ns+0xe9/0xf0
Workqueue: events ucsi_handle_connector_change [typec_ucsi]
Call Trace:
sysfs_remove_link+0x19/0x50
typec_unregister_partner+0x6e/0x120 [typec]
ucsi_unregister_partner+0x107/0x150 [typec_ucsi]
ucsi_handle_connector_change+0x3ec/0x490 [typec_ucsi]
process_one_work+0x18e/0x3e0
worker_thread+0x2e3/0x420
kthread+0x10a/0x230
ret_from_fork+0x121/0x140
ret_from_fork_asm+0x1a/0x30
With worse timing the same stale pointer is dereferenced after the
backing memory is freed, turning the warning into a use-after-free.
Fix the asymmetry: call typec_deattach() before clearing
port_dev->connector, matching what connector_bind() does on the bind side.
typec_partner_deattach() is already protected by port->partner_link_lock,
so it serialises safely with the concurrent typec_unregister_partner() path.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/core/port.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "78d361e60caf1999d51bda0e1b1004f5d39fcfbc",
"status": "affected",
"version": "11110783f5ea866318831a56353c6f1c3fc0d8ed",
"versionType": "git"
},
{
"lessThan": "7714fb896ed308cf13d32d317040adc4f200b8e4",
"status": "affected",
"version": "11110783f5ea866318831a56353c6f1c3fc0d8ed",
"versionType": "git"
},
{
"lessThan": "e00109b5adf71635919248e9ab6300a662e6a3e8",
"status": "affected",
"version": "11110783f5ea866318831a56353c6f1c3fc0d8ed",
"versionType": "git"
},
{
"lessThan": "e0b291fe117964037e0ba382eff4bb365d531c3a",
"status": "affected",
"version": "11110783f5ea866318831a56353c6f1c3fc0d8ed",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/core/port.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: port: Deattach Type-C connector on component unbind\n\nconnector_unbind() is the mirror of connector_bind(), but it is missing\nthe symmetric call to typec_deattach() that connector_bind() makes via:\n\n if (port_dev-\u003echild)\n typec_attach(port_dev-\u003econnector, \u0026port_dev-\u003echild-\u003edev);\n\nWhen a Thunderbolt dock is unplugged, two teardown paths race:\n\n1. The component framework calls connector_unbind() first, which sets\n port_dev-\u003econnector = NULL without calling typec_deattach(). This\n leaves port-\u003eusb2_dev/port-\u003eusb3_dev in struct typec_port pointing at\n the USB device that is about to be freed.\n\n2. usb_disconnect() then calls typec_deattach(port_dev-\u003econnector, ...),\n but port_dev-\u003econnector is already NULL, so the call is a no-op and\n port-\u003eusb2_dev is never cleared.\n\n3. Concurrently, UCSI detects a PD partner-disconnect event and calls\n typec_unregister_partner(), which reads port-\u003eusb2_dev (now a dangling\n pointer to freed memory) and passes it to typec_partner_unlink_device()\n -\u003e sysfs_remove_link() -\u003e dev_name() on the freed device, corrupting\n the typec/UCSI partner state.\n\nThis corruption leaves the Thunderbolt tunnel in an inconsistent state on\nthe next dock hot-plug. On affected hardware the dock\u0027s I225/igc NIC fails\nto enumerate: AER fires a slot reset while the igc driver is still\ninitialising (\"PCIe link lost\"), and the subsequent igc_reset attempt hits\nigc_rd32 on an already-detached device:\n\n igc 0000:2e:00.0 eth0: PCIe link lost, device now detached\n igc: Failed to read reg 0x0!\n WARNING: CPU: 9 PID: 129 at drivers/net/ethernet/intel/igc/igc_main.c:7005\n igc_rd32+0xa4/0xc0 [igc]\n Call Trace:\n igc_disable_pcie_master+0x16/0xa0 [igc]\n igc_reset_hw_base+0x14/0x170 [igc]\n igc_reset+0x63/0x110 [igc]\n igc_io_slot_reset+0x9e/0xd0 [igc]\n report_slot_reset+0x5d/0xc0\n pcie_do_recovery+0x209/0x400\n aer_isr_one_error_type+0x235/0x430\n aer_isr+0x4e/0x80\n irq_thread+0xf4/0x1f0\n\n4. UCSI later handles the PD partner-disconnect and calls\n typec_unregister_partner(), which still sees the stale port-\u003eusb2_dev\n and tries to remove its sysfs link a second time:\n\n kernfs: can not remove \u0027typec\u0027, no directory\n WARNING: CPU: 6 PID: 55 at fs/kernfs/dir.c:1706 kernfs_remove_by_name_ns+0xe9/0xf0\n Workqueue: events ucsi_handle_connector_change [typec_ucsi]\n Call Trace:\n sysfs_remove_link+0x19/0x50\n typec_unregister_partner+0x6e/0x120 [typec]\n ucsi_unregister_partner+0x107/0x150 [typec_ucsi]\n ucsi_handle_connector_change+0x3ec/0x490 [typec_ucsi]\n process_one_work+0x18e/0x3e0\n worker_thread+0x2e3/0x420\n kthread+0x10a/0x230\n ret_from_fork+0x121/0x140\n ret_from_fork_asm+0x1a/0x30\n\n With worse timing the same stale pointer is dereferenced after the\n backing memory is freed, turning the warning into a use-after-free.\n\nFix the asymmetry: call typec_deattach() before clearing\nport_dev-\u003econnector, matching what connector_bind() does on the bind side.\ntypec_partner_deattach() is already protected by port-\u003epartner_link_lock,\nso it serialises safely with the concurrent typec_unregister_partner() path."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:17.570Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/78d361e60caf1999d51bda0e1b1004f5d39fcfbc"
},
{
"url": "https://git.kernel.org/stable/c/7714fb896ed308cf13d32d317040adc4f200b8e4"
},
{
"url": "https://git.kernel.org/stable/c/e00109b5adf71635919248e9ab6300a662e6a3e8"
},
{
"url": "https://git.kernel.org/stable/c/e0b291fe117964037e0ba382eff4bb365d531c3a"
}
],
"title": "usb: core: port: Deattach Type-C connector on component unbind",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68372",
"datePublished": "2026-08-10T12:03:50.292Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-17T05:04:17.570Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64322 (GCVE-0-2026-64322)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
udf: validate sparing table length as an entry count, not a byte count
udf_load_sparable_map() accepts a sparing table when
sizeof(*st) + le16_to_cpu(st->reallocationTableLen) > sb->s_blocksize
is false, i.e. it treats reallocationTableLen as a number of BYTES that
must fit in the block. But the table is walked as an array of 8-byte
sparingEntry elements:
for (i = 0; i < le16_to_cpu(st->reallocationTableLen); i++) {
struct sparingEntry *entry = &st->mapEntry[i];
... entry->origLocation ...
}
in udf_get_pblock_spar15() and udf_relocate_blocks(). A
reallocationTableLen of N therefore passes the check whenever
sizeof(*st) + N <= blocksize, yet the consumers index
sizeof(*st) + N * sizeof(struct sparingEntry) bytes -- up to ~8x the
block. On a crafted UDF image this is an out-of-bounds read in
udf_get_pblock_spar15(); udf_relocate_blocks() additionally feeds the
same length to udf_update_tag(), whose crc_itu_t() reads far past the
block, and its memmove() through st->mapEntry[] is an out-of-bounds
write.
Validate reallocationTableLen as the entry count it is, with
struct_size().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 Version: 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 Version: 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 Version: 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 Version: 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 Version: 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 Version: 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 Version: 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 Version: e240873cb4a9fd18de60a817100a96fe670d4359 Version: 9ae30e324a96d0328a575329d7a95a09b3318601 Version: b1c5701ad6b3e5d21d16f65475651cfaaa41e7aa Version: a9f1af04f086656246f30354fb4564ce3b08c4a0 Version: 4836ee563d65bb492f907cbe267a5761b9693e4d Version: 2.6.32.60 ≤ Version: 2.6.34.14 ≤ Version: 3.0.37 ≤ Version: 3.2.23 ≤ Version: 3.4.5 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/udf/super.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e",
"status": "affected",
"version": "1df2ae31c724e57be9d7ac00d78db8a5dabdd050",
"versionType": "git"
},
{
"lessThan": "0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9",
"status": "affected",
"version": "1df2ae31c724e57be9d7ac00d78db8a5dabdd050",
"versionType": "git"
},
{
"lessThan": "2d726135099313958f8975532a2e15322ff150ce",
"status": "affected",
"version": "1df2ae31c724e57be9d7ac00d78db8a5dabdd050",
"versionType": "git"
},
{
"lessThan": "7285276aa50d2839afb5957ffd491ad282dc8f72",
"status": "affected",
"version": "1df2ae31c724e57be9d7ac00d78db8a5dabdd050",
"versionType": "git"
},
{
"lessThan": "2a219acb2ce674d99bbd1b7b35ed8c384dac7200",
"status": "affected",
"version": "1df2ae31c724e57be9d7ac00d78db8a5dabdd050",
"versionType": "git"
},
{
"lessThan": "04f4599a9efb90992d072a814960edf0cd62805d",
"status": "affected",
"version": "1df2ae31c724e57be9d7ac00d78db8a5dabdd050",
"versionType": "git"
},
{
"lessThan": "7f7774b9da0ef17b87bfa238cf966ad0b3376150",
"status": "affected",
"version": "1df2ae31c724e57be9d7ac00d78db8a5dabdd050",
"versionType": "git"
},
{
"lessThan": "3ec997bd5508e9b25210b5bbec89031629cdb093",
"status": "affected",
"version": "1df2ae31c724e57be9d7ac00d78db8a5dabdd050",
"versionType": "git"
},
{
"status": "affected",
"version": "e240873cb4a9fd18de60a817100a96fe670d4359",
"versionType": "git"
},
{
"status": "affected",
"version": "9ae30e324a96d0328a575329d7a95a09b3318601",
"versionType": "git"
},
{
"status": "affected",
"version": "b1c5701ad6b3e5d21d16f65475651cfaaa41e7aa",
"versionType": "git"
},
{
"status": "affected",
"version": "a9f1af04f086656246f30354fb4564ce3b08c4a0",
"versionType": "git"
},
{
"status": "affected",
"version": "4836ee563d65bb492f907cbe267a5761b9693e4d",
"versionType": "git"
},
{
"lessThan": "2.6.33",
"status": "affected",
"version": "2.6.32.60",
"versionType": "semver"
},
{
"lessThan": "2.6.35",
"status": "affected",
"version": "2.6.34.14",
"versionType": "semver"
},
{
"lessThan": "3.1",
"status": "affected",
"version": "3.0.37",
"versionType": "semver"
},
{
"lessThan": "3.3",
"status": "affected",
"version": "3.2.23",
"versionType": "semver"
},
{
"lessThan": "3.5",
"status": "affected",
"version": "3.4.5",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/udf/super.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.6.32.60",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.6.34.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.0.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.2.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: validate sparing table length as an entry count, not a byte count\n\nudf_load_sparable_map() accepts a sparing table when\n\n\tsizeof(*st) + le16_to_cpu(st-\u003ereallocationTableLen) \u003e sb-\u003es_blocksize\n\nis false, i.e. it treats reallocationTableLen as a number of BYTES that\nmust fit in the block. But the table is walked as an array of 8-byte\nsparingEntry elements:\n\n\tfor (i = 0; i \u003c le16_to_cpu(st-\u003ereallocationTableLen); i++) {\n\t\tstruct sparingEntry *entry = \u0026st-\u003emapEntry[i];\n\t\t... entry-\u003eorigLocation ...\n\t}\n\nin udf_get_pblock_spar15() and udf_relocate_blocks(). A\nreallocationTableLen of N therefore passes the check whenever\nsizeof(*st) + N \u003c= blocksize, yet the consumers index\nsizeof(*st) + N * sizeof(struct sparingEntry) bytes -- up to ~8x the\nblock. On a crafted UDF image this is an out-of-bounds read in\nudf_get_pblock_spar15(); udf_relocate_blocks() additionally feeds the\nsame length to udf_update_tag(), whose crc_itu_t() reads far past the\nblock, and its memmove() through st-\u003emapEntry[] is an out-of-bounds\nwrite.\n\nValidate reallocationTableLen as the entry count it is, with\nstruct_size()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - A crafted UDF image must be presented and mounted as local loop or removable block media; no network-facing path reaches this parser.\nAC:L - The attacker deterministically controls the entry count, table contents, block size, and accessed packet, with no race or condition outside attacker control.\nPR:L - Direct mounting requires initial-namespace CAP_SYS_ADMIN and user namespaces do not help, but common UDisks/polkit configurations let an active unprivileged local user mount attacker-controlled loop or removable media through a privileged broker.\nUI:N - The local attacker can request the brokered mount and trigger block translation themselves, requiring no action by a separate victim.\nS:U - Exploitation compromises the host kernel within its existing security authority and does not inherently cross a VM, IOMMU, or other scope boundary.\nC:H - The malformed count permits reads up to roughly eight times beyond the block, and relocation can expose adjacent kernel data through copied entries or returned mapping values.\nI:H - udf_relocate_blocks performs an out-of-bounds origLocation store and attacker-sized memmove through mapEntry[], potentially corrupting adjacent kernel pages and enabling control-flow hijacking.\nA:H - The extensive out-of-bounds reads and writes can reliably cause a kernel oops, panic, or fatal memory corruption."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:23.900Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e"
},
{
"url": "https://git.kernel.org/stable/c/0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9"
},
{
"url": "https://git.kernel.org/stable/c/2d726135099313958f8975532a2e15322ff150ce"
},
{
"url": "https://git.kernel.org/stable/c/7285276aa50d2839afb5957ffd491ad282dc8f72"
},
{
"url": "https://git.kernel.org/stable/c/2a219acb2ce674d99bbd1b7b35ed8c384dac7200"
},
{
"url": "https://git.kernel.org/stable/c/04f4599a9efb90992d072a814960edf0cd62805d"
},
{
"url": "https://git.kernel.org/stable/c/7f7774b9da0ef17b87bfa238cf966ad0b3376150"
},
{
"url": "https://git.kernel.org/stable/c/3ec997bd5508e9b25210b5bbec89031629cdb093"
}
],
"title": "udf: validate sparing table length as an entry count, not a byte count",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64322",
"datePublished": "2026-07-25T08:49:50.180Z",
"dateReserved": "2026-07-19T15:36:31.780Z",
"dateUpdated": "2026-08-17T04:53:23.900Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64602 (GCVE-0-2026-64602)
Vulnerability from cvelistv5
Published
2026-08-06 07:13
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: spear: Initialize completion before requesting IRQ
In the report from Jaeyoung Chung:
"spear_adc_probe() in drivers/iio/adc/spear_adc.c registers its
interrupt handler with devm_request_irq() before it initializes
st->completion with init_completion(). If an interrupt arrives after
devm_request_irq() and before init_completion(), the handler calls
complete() on an uninitialized completion, causing a kernel panic.
The probe path, in spear_adc_probe():
iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */
...
retval = devm_request_irq(&pdev->dev, irq, spear_adc_isr, 0,
LPC32XXAD_NAME, st); /* register handler */
...
init_completion(&st->completion); /* initialize completion */
spear_adc_isr() calls complete():
complete(&st->completion);
If the device raises an interrupt before init_completion() runs,
complete() acquires the uninitialized wait.lock and walks the zeroed
task_list in swake_up_locked(). The zeroed task_list makes list_empty()
return false, so swake_up_locked() dereferences a NULL list entry,
triggering a KASAN wild-memory-access."
Fix the chance of a spurious IRQ causing an uninitialized pointer
dereference by moving init_completion() above devm_request_irq().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed Version: b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed Version: b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed Version: b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed Version: b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed Version: b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed Version: b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed Version: b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iio/adc/spear_adc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "aea8ae6c4d3ed58d9223360f758df6bd8b90c608",
"status": "affected",
"version": "b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed",
"versionType": "git"
},
{
"lessThan": "67a49ab41320b3f721ce4be7447754ff040acbd5",
"status": "affected",
"version": "b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed",
"versionType": "git"
},
{
"lessThan": "a50757398794aaa25f908b96c6733e045466cba4",
"status": "affected",
"version": "b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed",
"versionType": "git"
},
{
"lessThan": "f3f90bc7b38ba3ff14f131cea0f8eb77624787a8",
"status": "affected",
"version": "b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed",
"versionType": "git"
},
{
"lessThan": "37077d8271b1f24894fbc21bca1c4cd337525d31",
"status": "affected",
"version": "b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed",
"versionType": "git"
},
{
"lessThan": "bbfebae473ac2c8a194523b29ccb9b45f02f134c",
"status": "affected",
"version": "b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed",
"versionType": "git"
},
{
"lessThan": "eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4",
"status": "affected",
"version": "b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed",
"versionType": "git"
},
{
"lessThan": "3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0",
"status": "affected",
"version": "b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iio/adc/spear_adc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: spear: Initialize completion before requesting IRQ\n\nIn the report from Jaeyoung Chung:\n\n\"spear_adc_probe() in drivers/iio/adc/spear_adc.c registers its\ninterrupt handler with devm_request_irq() before it initializes\nst-\u003ecompletion with init_completion(). If an interrupt arrives after\ndevm_request_irq() and before init_completion(), the handler calls\ncomplete() on an uninitialized completion, causing a kernel panic.\n\nThe probe path, in spear_adc_probe():\n\n iodev = devm_iio_device_alloc(\u0026pdev-\u003edev, sizeof(*st)); /* st kzalloc-zeroed */\n ...\n retval = devm_request_irq(\u0026pdev-\u003edev, irq, spear_adc_isr, 0,\n LPC32XXAD_NAME, st); /* register handler */\n ...\n init_completion(\u0026st-\u003ecompletion); /* initialize completion */\n\nspear_adc_isr() calls complete():\n\n complete(\u0026st-\u003ecompletion);\n\nIf the device raises an interrupt before init_completion() runs,\ncomplete() acquires the uninitialized wait.lock and walks the zeroed\ntask_list in swake_up_locked(). The zeroed task_list makes list_empty()\nreturn false, so swake_up_locked() dereferences a NULL list entry,\ntriggering a KASAN wild-memory-access.\"\n\nFix the chance of a spurious IRQ causing an uninitialized pointer\ndereference by moving init_completion() above devm_request_irq()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:25.306Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/aea8ae6c4d3ed58d9223360f758df6bd8b90c608"
},
{
"url": "https://git.kernel.org/stable/c/67a49ab41320b3f721ce4be7447754ff040acbd5"
},
{
"url": "https://git.kernel.org/stable/c/a50757398794aaa25f908b96c6733e045466cba4"
},
{
"url": "https://git.kernel.org/stable/c/f3f90bc7b38ba3ff14f131cea0f8eb77624787a8"
},
{
"url": "https://git.kernel.org/stable/c/37077d8271b1f24894fbc21bca1c4cd337525d31"
},
{
"url": "https://git.kernel.org/stable/c/bbfebae473ac2c8a194523b29ccb9b45f02f134c"
},
{
"url": "https://git.kernel.org/stable/c/eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4"
},
{
"url": "https://git.kernel.org/stable/c/3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0"
}
],
"title": "iio: adc: spear: Initialize completion before requesting IRQ",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64602",
"datePublished": "2026-08-06T07:13:54.519Z",
"dateReserved": "2026-07-19T15:36:31.799Z",
"dateUpdated": "2026-08-17T04:58:25.306Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68113 (GCVE-0-2026-68113)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit f952076f76d62f783e8ba4995a7c400d39354ccf)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eef69b826b2036314b59020dfa6083fc859bfcc1",
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"versionType": "git"
},
{
"lessThan": "987bedd3ea89d747d1c5ab708ce3293e2f033b6c",
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"versionType": "git"
},
{
"lessThan": "81597685c0d73b9c2e1a89c12c576ab80d1c00f4",
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"versionType": "git"
},
{
"lessThan": "cd3b3efa1ced05528d9128755338baa62a6b562d",
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit f952076f76d62f783e8ba4995a7c400d39354ccf)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:38.263Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eef69b826b2036314b59020dfa6083fc859bfcc1"
},
{
"url": "https://git.kernel.org/stable/c/987bedd3ea89d747d1c5ab708ce3293e2f033b6c"
},
{
"url": "https://git.kernel.org/stable/c/81597685c0d73b9c2e1a89c12c576ab80d1c00f4"
},
{
"url": "https://git.kernel.org/stable/c/cd3b3efa1ced05528d9128755338baa62a6b562d"
}
],
"title": "drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68113",
"datePublished": "2026-08-10T11:58:31.059Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-18T06:55:38.263Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64277 (GCVE-0-2026-64277)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
rmi_f3a_initialize() takes the GPIO count from the device query register
(f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127).
rmi_f3a_map_gpios() then allocates gpio_key_map with
min(gpio_count, TRACKSTICK_RANGE_END) == at most 6 entries, but
rmi_f3a_attention() iterates the full gpio_count and dereferences
gpio_key_map[i], and input->keycodemax is set to the full gpio_count
while input->keycode points at the 6-entry allocation.
A device that reports gpio_count > 6 therefore causes an out-of-bounds
read of gpio_key_map[] on every attention interrupt, and out-of-bounds
accesses through the input core's default keymap ioctls: EVIOCGKEYCODE
reads past the buffer (leaking adjacent slab memory to user space) and
EVIOCSKEYCODE writes a caller-controlled value past it, for any process
able to open the evdev node, since input_default_getkeycode() and
input_default_setkeycode() only bound the index against keycodemax.
Size the keymap for the full gpio_count. The mapping loop is unchanged:
it still assigns only the first min(gpio_count, TRACKSTICK_RANGE_END)
entries; the remaining slots stay KEY_RESERVED (devm_kcalloc zero-fills)
and are skipped when reporting.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9e4c596bfd004f447a652205163234dfd4aafa69 Version: 9e4c596bfd004f447a652205163234dfd4aafa69 Version: 9e4c596bfd004f447a652205163234dfd4aafa69 Version: 9e4c596bfd004f447a652205163234dfd4aafa69 Version: 9e4c596bfd004f447a652205163234dfd4aafa69 Version: 9e4c596bfd004f447a652205163234dfd4aafa69 Version: 9e4c596bfd004f447a652205163234dfd4aafa69 Version: 9e4c596bfd004f447a652205163234dfd4aafa69 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f3a.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "502ad7caaa1a445b734c827fa256e5311df67e3d",
"status": "affected",
"version": "9e4c596bfd004f447a652205163234dfd4aafa69",
"versionType": "git"
},
{
"lessThan": "3480e24bc4e178aaa009edb25b6ee12df199e210",
"status": "affected",
"version": "9e4c596bfd004f447a652205163234dfd4aafa69",
"versionType": "git"
},
{
"lessThan": "35ed74d32d8260bdfb14a94caf402bf0866bdeec",
"status": "affected",
"version": "9e4c596bfd004f447a652205163234dfd4aafa69",
"versionType": "git"
},
{
"lessThan": "ba57f430328534501962d60d651e385ffd7af9ca",
"status": "affected",
"version": "9e4c596bfd004f447a652205163234dfd4aafa69",
"versionType": "git"
},
{
"lessThan": "850117b637bcb1dcc14be0cf09ac819a8707b42c",
"status": "affected",
"version": "9e4c596bfd004f447a652205163234dfd4aafa69",
"versionType": "git"
},
{
"lessThan": "8db211aed83733073b0814adaeeab61d4521474e",
"status": "affected",
"version": "9e4c596bfd004f447a652205163234dfd4aafa69",
"versionType": "git"
},
{
"lessThan": "64fb0e1161ccc6b9e48b8df61f07d3c34c01ec42",
"status": "affected",
"version": "9e4c596bfd004f447a652205163234dfd4aafa69",
"versionType": "git"
},
{
"lessThan": "57c10915f2c16c90e0d46ad00876bf39ece40fc2",
"status": "affected",
"version": "9e4c596bfd004f447a652205163234dfd4aafa69",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f3a.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - bound the F3A keymap to the GPIO count\n\nrmi_f3a_initialize() takes the GPIO count from the device query register\n(f3a-\u003egpio_count = buf \u0026 RMI_F3A_GPIO_COUNT, range 0..127).\nrmi_f3a_map_gpios() then allocates gpio_key_map with\nmin(gpio_count, TRACKSTICK_RANGE_END) == at most 6 entries, but\nrmi_f3a_attention() iterates the full gpio_count and dereferences\ngpio_key_map[i], and input-\u003ekeycodemax is set to the full gpio_count\nwhile input-\u003ekeycode points at the 6-entry allocation.\n\nA device that reports gpio_count \u003e 6 therefore causes an out-of-bounds\nread of gpio_key_map[] on every attention interrupt, and out-of-bounds\naccesses through the input core\u0027s default keymap ioctls: EVIOCGKEYCODE\nreads past the buffer (leaking adjacent slab memory to user space) and\nEVIOCSKEYCODE writes a caller-controlled value past it, for any process\nable to open the evdev node, since input_default_getkeycode() and\ninput_default_setkeycode() only bound the index against keycodemax.\n\nSize the keymap for the full gpio_count. The mapping loop is unchanged:\nit still assigns only the first min(gpio_count, TRACKSTICK_RANGE_END)\nentries; the remaining slots stay KEY_RESERVED (devm_kcalloc zero-fills)\nand are skipped when reporting."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The highest-severity defensible path is local: a process that can open the affected RMI touchpad\u0027s evdev node can invoke the vulnerable keymap ioctls. A malicious USB RMI device is also a physical trigger, but the local ioctl path is more severe.\nAC:L - On a vulnerable device reporting more than six GPIOs, selecting any keymap index from 6 through gpio_count-1 deterministically accesses beyond the allocation. No race or condition outside the attacker\u0027s control is required.\nPR:L - The evdev keymap ioctl path has no capability or authentication check; only ordinary device-node access controls apply. An unprivileged user with seat, ACL, or input-device access can exploit it without administrative capabilities.\nUI:N - The attacker directly issues EVIOCGKEYCODE or EVIOCSKEYCODE after opening the node. No action by another user is required.\nS:U - Exploitation compromises the host kernel within the same security authority. It does not inherently cross a VM, IOMMU, or other separate security boundary.\nC:H - EVIOCGKEYCODE can disclose successive 16-bit words across as much as 242 bytes beyond the six-entry keymap, exposing adjacent slab contents and potentially kernel pointers. The accompanying corruption can also support stronger disclosure primitives.\nI:H - EVIOCSKEYCODE provides indexed, caller-controlled 16-bit writes throughout the out-of-bounds range. This heap corruption can overwrite adjacent pointers or control data and plausibly enable kernel code execution.\nA:H - The controlled heap overwrite can corrupt adjacent slab objects and cause a kernel oops or panic, while device attention interrupts repeatedly exercise the out-of-bounds read. The failure can be triggered repeatedly without victim interaction."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:32.147Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/502ad7caaa1a445b734c827fa256e5311df67e3d"
},
{
"url": "https://git.kernel.org/stable/c/3480e24bc4e178aaa009edb25b6ee12df199e210"
},
{
"url": "https://git.kernel.org/stable/c/35ed74d32d8260bdfb14a94caf402bf0866bdeec"
},
{
"url": "https://git.kernel.org/stable/c/ba57f430328534501962d60d651e385ffd7af9ca"
},
{
"url": "https://git.kernel.org/stable/c/850117b637bcb1dcc14be0cf09ac819a8707b42c"
},
{
"url": "https://git.kernel.org/stable/c/8db211aed83733073b0814adaeeab61d4521474e"
},
{
"url": "https://git.kernel.org/stable/c/64fb0e1161ccc6b9e48b8df61f07d3c34c01ec42"
},
{
"url": "https://git.kernel.org/stable/c/57c10915f2c16c90e0d46ad00876bf39ece40fc2"
}
],
"title": "Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64277",
"datePublished": "2026-07-25T08:49:21.936Z",
"dateReserved": "2026-07-19T15:36:31.776Z",
"dateUpdated": "2026-08-17T04:52:32.147Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64496 (GCVE-0-2026-64496)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iio: event: Fix event FIFO reset race
`iio_event_getfd()` creates the event file descriptor with
`anon_inode_getfd()`, which allocates a new fd, creates the anonymous
file and installs it in the process fd table before returning to the
caller.
The IIO code resets the event FIFO after `anon_inode_getfd()` has returned,
but before `IIO_GET_EVENT_FD_IOCTL` has copied the fd number to userspace.
But since fd tables are shared between threads, another thread can guess
the newly allocated fd number and issue a `read()` on it as soon as the fd
has been installed.
This means the `kfifo_to_user()` in `iio_event_chrdev_read()` can run in
parallel with the `kfifo_reset_out()` in `iio_event_getfd()`.
The kfifo documentation says that `kfifo_reset_out()` is only safe when it
is called from the reader thread and there is only one concurrent reader.
Otherwise it is dangerous and must be handled in the same way as
`kfifo_reset()`.
If that happens, `kfifo_to_user()` can advance the FIFO `out` index based
on state from before the reset, after the reset has already moved the `out`
index to the current `in` index. That can leave the FIFO with an `out`
index past the `in` index. A later `read()` can then see an underflowed
FIFO length and copy more data than the event FIFO buffer contains. This
can result in an out-of-bounds read and leak adjacent kernel memory to
userspace.
Move the FIFO reset before `anon_inode_getfd()`. At that point the event fd is
marked busy, but the new fd has not been installed yet, so userspace cannot
access it while the FIFO is reset.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b91accafbb1031b80d22ad83576877ff2f8b4774 Version: b91accafbb1031b80d22ad83576877ff2f8b4774 Version: b91accafbb1031b80d22ad83576877ff2f8b4774 Version: b91accafbb1031b80d22ad83576877ff2f8b4774 Version: b91accafbb1031b80d22ad83576877ff2f8b4774 Version: b91accafbb1031b80d22ad83576877ff2f8b4774 Version: b91accafbb1031b80d22ad83576877ff2f8b4774 Version: b91accafbb1031b80d22ad83576877ff2f8b4774 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iio/industrialio-event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9dc84ba4be5bbeb29ee49efe6cea2cb32c461424",
"status": "affected",
"version": "b91accafbb1031b80d22ad83576877ff2f8b4774",
"versionType": "git"
},
{
"lessThan": "d16a702ca7d29c0b7a9b509339d1b044a1cadb32",
"status": "affected",
"version": "b91accafbb1031b80d22ad83576877ff2f8b4774",
"versionType": "git"
},
{
"lessThan": "a13ef1adbc62085b21b546b07b0be7e2fbf52150",
"status": "affected",
"version": "b91accafbb1031b80d22ad83576877ff2f8b4774",
"versionType": "git"
},
{
"lessThan": "0d4a646d7f87ea3625fafe387043fddc6a2f5e7f",
"status": "affected",
"version": "b91accafbb1031b80d22ad83576877ff2f8b4774",
"versionType": "git"
},
{
"lessThan": "72c6aa8e0d74eab91b8694cde97dec088c248fee",
"status": "affected",
"version": "b91accafbb1031b80d22ad83576877ff2f8b4774",
"versionType": "git"
},
{
"lessThan": "9edefd4c56bee3fe331e0355d1f10a533134999d",
"status": "affected",
"version": "b91accafbb1031b80d22ad83576877ff2f8b4774",
"versionType": "git"
},
{
"lessThan": "f187dc5a4c4846ffa07d9bda6e760837ed005574",
"status": "affected",
"version": "b91accafbb1031b80d22ad83576877ff2f8b4774",
"versionType": "git"
},
{
"lessThan": "af791d295737ea6b6ff2c8d8488462a49c14af01",
"status": "affected",
"version": "b91accafbb1031b80d22ad83576877ff2f8b4774",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iio/industrialio-event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.15"
},
{
"lessThan": "3.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: event: Fix event FIFO reset race\n\n`iio_event_getfd()` creates the event file descriptor with\n`anon_inode_getfd()`, which allocates a new fd, creates the anonymous\nfile and installs it in the process fd table before returning to the\ncaller.\n\nThe IIO code resets the event FIFO after `anon_inode_getfd()` has returned,\nbut before `IIO_GET_EVENT_FD_IOCTL` has copied the fd number to userspace.\nBut since fd tables are shared between threads, another thread can guess\nthe newly allocated fd number and issue a `read()` on it as soon as the fd\nhas been installed.\n\nThis means the `kfifo_to_user()` in `iio_event_chrdev_read()` can run in\nparallel with the `kfifo_reset_out()` in `iio_event_getfd()`.\n\nThe kfifo documentation says that `kfifo_reset_out()` is only safe when it\nis called from the reader thread and there is only one concurrent reader.\nOtherwise it is dangerous and must be handled in the same way as\n`kfifo_reset()`.\n\nIf that happens, `kfifo_to_user()` can advance the FIFO `out` index based\non state from before the reset, after the reset has already moved the `out`\nindex to the current `in` index. That can leave the FIFO with an `out`\nindex past the `in` index. A later `read()` can then see an underflowed\nFIFO length and copy more data than the event FIFO buffer contains. This\ncan result in an out-of-bounds read and leak adjacent kernel memory to\nuserspace.\n\nMove the FIFO reset before `anon_inode_getfd()`. At that point the event fd is\nmarked busy, but the new fd has not been installed yet, so userspace cannot\naccess it while the FIFO is reset."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation uses local open(), ioctl(), and read() operations on /dev/iio:deviceX; no network-reachable path exists.\nAC:L - The attacker controls both racing threads and can predict the lowest available event fd, repeatedly race its installation, and stall the read using a userspace page fault.\nPR:L - The kernel path has no capability or authentication check; an ordinary user granted device-node access can invoke the vulnerable ioctl and read operations.\nUI:N - No victim action is required, and supported IIO drivers can generate events automatically through sensor interrupts.\nS:U - The vulnerability affects the kernel hosting the attacking process and does not inherently cross a VM, IOMMU, or separate security-authority boundary.\nC:H - The underflowed FIFO length permits an attacker-sized out-of-bounds read beyond the 256-byte event buffer, exposing adjacent kernel heap memory and potentially sensitive pointers or data.\nI:N - The path copies kernel data to userspace and corrupts only the FIFO read index; masked FIFO accesses provide no out-of-bounds write or control-flow modification primitive.\nA:H - An oversized read crossing the containing slab object triggers BUG() with hardened usercopy, causing a kernel oops or panic and allowing repeated denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:44.840Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9dc84ba4be5bbeb29ee49efe6cea2cb32c461424"
},
{
"url": "https://git.kernel.org/stable/c/d16a702ca7d29c0b7a9b509339d1b044a1cadb32"
},
{
"url": "https://git.kernel.org/stable/c/a13ef1adbc62085b21b546b07b0be7e2fbf52150"
},
{
"url": "https://git.kernel.org/stable/c/0d4a646d7f87ea3625fafe387043fddc6a2f5e7f"
},
{
"url": "https://git.kernel.org/stable/c/72c6aa8e0d74eab91b8694cde97dec088c248fee"
},
{
"url": "https://git.kernel.org/stable/c/9edefd4c56bee3fe331e0355d1f10a533134999d"
},
{
"url": "https://git.kernel.org/stable/c/f187dc5a4c4846ffa07d9bda6e760837ed005574"
},
{
"url": "https://git.kernel.org/stable/c/af791d295737ea6b6ff2c8d8488462a49c14af01"
}
],
"title": "iio: event: Fix event FIFO reset race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64496",
"datePublished": "2026-07-25T08:51:53.194Z",
"dateReserved": "2026-07-19T15:36:31.792Z",
"dateUpdated": "2026-08-17T04:56:44.840Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68406 (GCVE-0-2026-68406)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: validate PMSR FTM preamble range
PMSR FTM request parsing accepts preamble values outside the
enumerated nl80211 preamble range.
Reject out-of-range values before using them in the parser capability
bit test using the policy.
[drop unnecessary check]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "73ada9f23c2c7fac74474ea2a38ceb265bae17f1",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "2b97fa1bce7731f6a244f3d4407c61858f09b93f",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "9b33f260db3971f572dda0b45dd28d477cf51ed1",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "44ea65d779e2d23b2264fea6af2d0c666a3ec9fb",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "922d71fbaf99c1d5318151a0cb0a42ad448d07d9",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "cfbda103aeae61071a122a6fc2bfe98cffbd7165",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "58320cb47df2accc7a20bb72c0150280732fa58f",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "36230936468f0ba4930e94aef496fc229d4bb951",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: validate PMSR FTM preamble range\n\nPMSR FTM request parsing accepts preamble values outside the\nenumerated nl80211 preamble range.\n\nReject out-of-range values before using them in the parser capability\nbit test using the policy.\n\n[drop unnecessary check]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:59.823Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/73ada9f23c2c7fac74474ea2a38ceb265bae17f1"
},
{
"url": "https://git.kernel.org/stable/c/2b97fa1bce7731f6a244f3d4407c61858f09b93f"
},
{
"url": "https://git.kernel.org/stable/c/9b33f260db3971f572dda0b45dd28d477cf51ed1"
},
{
"url": "https://git.kernel.org/stable/c/44ea65d779e2d23b2264fea6af2d0c666a3ec9fb"
},
{
"url": "https://git.kernel.org/stable/c/922d71fbaf99c1d5318151a0cb0a42ad448d07d9"
},
{
"url": "https://git.kernel.org/stable/c/cfbda103aeae61071a122a6fc2bfe98cffbd7165"
},
{
"url": "https://git.kernel.org/stable/c/58320cb47df2accc7a20bb72c0150280732fa58f"
},
{
"url": "https://git.kernel.org/stable/c/36230936468f0ba4930e94aef496fc229d4bb951"
}
],
"title": "wifi: cfg80211: validate PMSR FTM preamble range",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68406",
"datePublished": "2026-08-10T12:04:26.251Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:34:59.823Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43363 (GCVE-0-2026-43363)
Vulnerability from cvelistv5
Published
2026-05-08 14:21
Modified
2026-05-11 22:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
x86/apic: Disable x2apic on resume if the kernel expects so
When resuming from s2ram, firmware may re-enable x2apic mode, which may have
been disabled by the kernel during boot either because it doesn't support IRQ
remapping or for other reasons. This causes the kernel to continue using the
xapic interface, while the hardware is in x2apic mode, which causes hangs.
This happens on defconfig + bare metal + s2ram.
Fix this in lapic_resume() by disabling x2apic if the kernel expects it to be
disabled, i.e. when x2apic_mode = 0.
The ACPI v6.6 spec, Section 16.3 [1] says firmware restores either the
pre-sleep configuration or initial boot configuration for each CPU, including
MSR state:
When executing from the power-on reset vector as a result of waking from an
S2 or S3 sleep state, the platform firmware performs only the hardware
initialization required to restore the system to either the state the
platform was in prior to the initial operating system boot, or to the
pre-sleep configuration state. In multiprocessor systems, non-boot
processors should be placed in the same state as prior to the initial
operating system boot.
(further ahead)
If this is an S2 or S3 wake, then the platform runtime firmware restores
minimum context of the system before jumping to the waking vector. This
includes:
CPU configuration. Platform runtime firmware restores the pre-sleep
configuration or initial boot configuration of each CPU (MSR, MTRR,
firmware update, SMBase, and so on). Interrupts must be disabled (for
IA-32 processors, disabled by CLI instruction).
(and other things)
So at least as per the spec, re-enablement of x2apic by the firmware is
allowed if "x2apic on" is a part of the initial boot configuration.
[1] https://uefi.org/specs/ACPI/6.6/16_Waking_and_Sleeping.html#initialization
[ bp: Massage. ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6e1cb38a2aef7680975e71f23de187859ee8b158 Version: 6e1cb38a2aef7680975e71f23de187859ee8b158 Version: 6e1cb38a2aef7680975e71f23de187859ee8b158 Version: 6e1cb38a2aef7680975e71f23de187859ee8b158 Version: 6e1cb38a2aef7680975e71f23de187859ee8b158 Version: 6e1cb38a2aef7680975e71f23de187859ee8b158 Version: 6e1cb38a2aef7680975e71f23de187859ee8b158 Version: 6e1cb38a2aef7680975e71f23de187859ee8b158 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kernel/apic/apic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a6ad6f2e31b524cbb66b2f370bad0cf17d327e6c",
"status": "affected",
"version": "6e1cb38a2aef7680975e71f23de187859ee8b158",
"versionType": "git"
},
{
"lessThan": "3dd0812a7c764cd8f3b0182441ac22da0a7f3b09",
"status": "affected",
"version": "6e1cb38a2aef7680975e71f23de187859ee8b158",
"versionType": "git"
},
{
"lessThan": "965289b120cc68cca886c75219c68b8c15751d73",
"status": "affected",
"version": "6e1cb38a2aef7680975e71f23de187859ee8b158",
"versionType": "git"
},
{
"lessThan": "f591938072115bf08730b8530c67fab189cc6308",
"status": "affected",
"version": "6e1cb38a2aef7680975e71f23de187859ee8b158",
"versionType": "git"
},
{
"lessThan": "1a85f84214f9d790216547ac6086bf8033cd9e5a",
"status": "affected",
"version": "6e1cb38a2aef7680975e71f23de187859ee8b158",
"versionType": "git"
},
{
"lessThan": "11712c4eb384098db4cb08792e223c818b908c1a",
"status": "affected",
"version": "6e1cb38a2aef7680975e71f23de187859ee8b158",
"versionType": "git"
},
{
"lessThan": "1d8440c1e7c49715f937416ac90cf260f1f1712c",
"status": "affected",
"version": "6e1cb38a2aef7680975e71f23de187859ee8b158",
"versionType": "git"
},
{
"lessThan": "8cc7dd77a1466f0ec58c03478b2e735a5b289b96",
"status": "affected",
"version": "6e1cb38a2aef7680975e71f23de187859ee8b158",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kernel/apic/apic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"lessThan": "2.6.28",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.253",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.19",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.253",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.167",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.19",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.9",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "2.6.28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/apic: Disable x2apic on resume if the kernel expects so\n\nWhen resuming from s2ram, firmware may re-enable x2apic mode, which may have\nbeen disabled by the kernel during boot either because it doesn\u0027t support IRQ\nremapping or for other reasons. This causes the kernel to continue using the\nxapic interface, while the hardware is in x2apic mode, which causes hangs.\nThis happens on defconfig + bare metal + s2ram.\n\nFix this in lapic_resume() by disabling x2apic if the kernel expects it to be\ndisabled, i.e. when x2apic_mode = 0.\n\nThe ACPI v6.6 spec, Section 16.3 [1] says firmware restores either the\npre-sleep configuration or initial boot configuration for each CPU, including\nMSR state:\n\n When executing from the power-on reset vector as a result of waking from an\n S2 or S3 sleep state, the platform firmware performs only the hardware\n initialization required to restore the system to either the state the\n platform was in prior to the initial operating system boot, or to the\n pre-sleep configuration state. In multiprocessor systems, non-boot\n processors should be placed in the same state as prior to the initial\n operating system boot.\n\n (further ahead)\n\n If this is an S2 or S3 wake, then the platform runtime firmware restores\n minimum context of the system before jumping to the waking vector. This\n includes:\n\n\tCPU configuration. Platform runtime firmware restores the pre-sleep\n\tconfiguration or initial boot configuration of each CPU (MSR, MTRR,\n\tfirmware update, SMBase, and so on). Interrupts must be disabled (for\n\tIA-32 processors, disabled by CLI instruction).\n\n\t(and other things)\n\nSo at least as per the spec, re-enablement of x2apic by the firmware is\nallowed if \"x2apic on\" is a part of the initial boot configuration.\n\n [1] https://uefi.org/specs/ACPI/6.6/16_Waking_and_Sleeping.html#initialization\n\n [ bp: Massage. ]"
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:23:08.290Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a6ad6f2e31b524cbb66b2f370bad0cf17d327e6c"
},
{
"url": "https://git.kernel.org/stable/c/3dd0812a7c764cd8f3b0182441ac22da0a7f3b09"
},
{
"url": "https://git.kernel.org/stable/c/965289b120cc68cca886c75219c68b8c15751d73"
},
{
"url": "https://git.kernel.org/stable/c/f591938072115bf08730b8530c67fab189cc6308"
},
{
"url": "https://git.kernel.org/stable/c/1a85f84214f9d790216547ac6086bf8033cd9e5a"
},
{
"url": "https://git.kernel.org/stable/c/11712c4eb384098db4cb08792e223c818b908c1a"
},
{
"url": "https://git.kernel.org/stable/c/1d8440c1e7c49715f937416ac90cf260f1f1712c"
},
{
"url": "https://git.kernel.org/stable/c/8cc7dd77a1466f0ec58c03478b2e735a5b289b96"
}
],
"title": "x86/apic: Disable x2apic on resume if the kernel expects so",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43363",
"datePublished": "2026-05-08T14:21:16.986Z",
"dateReserved": "2026-05-01T14:12:56.005Z",
"dateUpdated": "2026-05-11T22:23:08.290Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64164 (GCVE-0-2026-64164)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
The trace event btrfs_sync_file() is called in an atomic context (all trace
events are) and its call to dput(), which is needed due to the call to
dget_parent(), can sleep, triggering a kernel splat.
This can be reproduced by enabling the trace event and running btrfs/056
from fstests for example. The splat shown in dmesg is the following:
[53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970
[53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io
[53.988] preempt_count: 2, expected: 0
[53.967] RCU nest depth: 0, expected: 0
[53.943] Preemption disabled at:
[53.944] [<0000000000000000>] 0x0
[54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G W 7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full)
[54.070] Tainted: [W]=WARN
[54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014
[54.072] Call Trace:
[54.074] <TASK>
[54.076] dump_stack_lvl+0x56/0x80
[54.079] __might_resched.cold+0xd6/0x10f
[54.072] dput.part.0+0x24/0x110
[54.078] trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs]
[54.089] btrfs_sync_file+0x1ed/0x530 [btrfs]
[54.087] ? __handle_mm_fault+0x8ae/0xed0
[54.089] btrfs_do_write_iter+0x172/0x210 [btrfs]
[54.091] vfs_write+0x21f/0x450
[54.094] __x64_sys_pwrite64+0x8d/0xc0
[54.096] ? do_user_addr_fault+0x20c/0x670
[54.099] do_syscall_64+0x60/0xf20
[54.092] ? clear_bhb_loop+0x60/0xb0
[54.094] entry_SYSCALL_64_after_hwframe+0x76/0x7e
So stop using dget_parent() and dput() and access the parent dentry
directly as dentry->d_parent. This is also what ext4 is doing in
its equivalent trace event ext4_sync_file_enter().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4a7bab35fad5251c8cb738161152578cd83b6b9c Version: 520e8b4bcf872a534a7bf61ccf880047642df296 Version: e252db8ca2a01f82d472091f35d549b313278636 Version: c09a7446aab5773f38d6abb25fce99b8e1dfbc97 Version: 32372781d664a9b03c40343e96c29d0a6139f97d Version: 2e4adfaec97ee053ad1bdfb5036845e66f7e0d8a Version: a85b46db143fda5869e7d8df8f258ccef5fa1719 Version: a85b46db143fda5869e7d8df8f258ccef5fa1719 Version: d110d7cdb045715c0b45b0dfd974525bb38f653d Version: 6.6.136 ≤ Version: 6.12.83 ≤ Version: 6.18.24 ≤ Version: 6.19.14 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/trace/events/btrfs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d78b0a80eac36879ef5478707135c446920e134b",
"status": "affected",
"version": "4a7bab35fad5251c8cb738161152578cd83b6b9c",
"versionType": "git"
},
{
"lessThan": "4361954f0e158af0530caa1e57f12b531be4658f",
"status": "affected",
"version": "520e8b4bcf872a534a7bf61ccf880047642df296",
"versionType": "git"
},
{
"lessThan": "6279992c9ba2774901c9d4dd4a481162e2534714",
"status": "affected",
"version": "e252db8ca2a01f82d472091f35d549b313278636",
"versionType": "git"
},
{
"lessThan": "26b2290baaf6da6add0f782a100766e686a33f4f",
"status": "affected",
"version": "c09a7446aab5773f38d6abb25fce99b8e1dfbc97",
"versionType": "git"
},
{
"lessThan": "12a0487945c09760a5968d9333383014ea294117",
"status": "affected",
"version": "32372781d664a9b03c40343e96c29d0a6139f97d",
"versionType": "git"
},
{
"lessThan": "c32a7e0e3c73c1c0768556a56bd78de9f7b83780",
"status": "affected",
"version": "2e4adfaec97ee053ad1bdfb5036845e66f7e0d8a",
"versionType": "git"
},
{
"lessThan": "0a96d9a85cd2240481297156b9bb72e10b7a8036",
"status": "affected",
"version": "a85b46db143fda5869e7d8df8f258ccef5fa1719",
"versionType": "git"
},
{
"lessThan": "c73370c677646e86fc4b1780fb07027bdf847375",
"status": "affected",
"version": "a85b46db143fda5869e7d8df8f258ccef5fa1719",
"versionType": "git"
},
{
"status": "affected",
"version": "d110d7cdb045715c0b45b0dfd974525bb38f653d",
"versionType": "git"
},
{
"lessThan": "6.6.142",
"status": "affected",
"version": "6.6.136",
"versionType": "semver"
},
{
"lessThan": "6.12.92",
"status": "affected",
"version": "6.12.83",
"versionType": "semver"
},
{
"lessThan": "6.18.34",
"status": "affected",
"version": "6.18.24",
"versionType": "semver"
},
{
"lessThan": "6.20",
"status": "affected",
"version": "6.19.14",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/trace/events/btrfs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.0"
},
{
"lessThan": "7.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.6.136",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.12.83",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.18.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.19.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()\n\nThe trace event btrfs_sync_file() is called in an atomic context (all trace\nevents are) and its call to dput(), which is needed due to the call to\ndget_parent(), can sleep, triggering a kernel splat.\n\nThis can be reproduced by enabling the trace event and running btrfs/056\nfrom fstests for example. The splat shown in dmesg is the following:\n\n [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970\n [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io\n [53.988] preempt_count: 2, expected: 0\n [53.967] RCU nest depth: 0, expected: 0\n [53.943] Preemption disabled at:\n [53.944] [\u003c0000000000000000\u003e] 0x0\n [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G W 7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full)\n [54.070] Tainted: [W]=WARN\n [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014\n [54.072] Call Trace:\n [54.074] \u003cTASK\u003e\n [54.076] dump_stack_lvl+0x56/0x80\n [54.079] __might_resched.cold+0xd6/0x10f\n [54.072] dput.part.0+0x24/0x110\n [54.078] trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs]\n [54.089] btrfs_sync_file+0x1ed/0x530 [btrfs]\n [54.087] ? __handle_mm_fault+0x8ae/0xed0\n [54.089] btrfs_do_write_iter+0x172/0x210 [btrfs]\n [54.091] vfs_write+0x21f/0x450\n [54.094] __x64_sys_pwrite64+0x8d/0xc0\n [54.096] ? do_user_addr_fault+0x20c/0x670\n [54.099] do_syscall_64+0x60/0xf20\n [54.092] ? clear_bhb_loop+0x60/0xb0\n [54.094] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nSo stop using dget_parent() and dput() and access the parent dentry\ndirectly as dentry-\u003ed_parent. This is also what ext4 is doing in\nits equivalent trace event ext4_sync_file_enter()."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:49.894Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d78b0a80eac36879ef5478707135c446920e134b"
},
{
"url": "https://git.kernel.org/stable/c/4361954f0e158af0530caa1e57f12b531be4658f"
},
{
"url": "https://git.kernel.org/stable/c/6279992c9ba2774901c9d4dd4a481162e2534714"
},
{
"url": "https://git.kernel.org/stable/c/26b2290baaf6da6add0f782a100766e686a33f4f"
},
{
"url": "https://git.kernel.org/stable/c/12a0487945c09760a5968d9333383014ea294117"
},
{
"url": "https://git.kernel.org/stable/c/c32a7e0e3c73c1c0768556a56bd78de9f7b83780"
},
{
"url": "https://git.kernel.org/stable/c/0a96d9a85cd2240481297156b9bb72e10b7a8036"
},
{
"url": "https://git.kernel.org/stable/c/c73370c677646e86fc4b1780fb07027bdf847375"
}
],
"title": "btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64164",
"datePublished": "2026-07-19T15:40:49.894Z",
"dateReserved": "2026-07-19T07:54:57.038Z",
"dateUpdated": "2026-07-19T15:40:49.894Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64099 (GCVE-0-2026-64099)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/v3d: Fix use-after-free of CPU job query arrays on error path
The CPU job ioctl's fail label calls kvfree() on cpu_job's timestamp and
performance query arrays after v3d_job_cleanup(), which drops the job's
last reference and frees cpu_job. Reading cpu_job at that point is a
use-after-free. Also, on the early v3d_job_init() failure path, it is a
NULL dereference, since v3d_job_deallocate() zeroes the local pointer.
In the success path, the arrays are released from the scheduler's
.free_job callback, but on the error path, they are freed manually, as
the job was never pushed to the scheduler. While the success path deals
with this correctly, the fail path doesn't.
On top of that, the manual kvfree() calls only free the array storage;
they don't drm_syncobj_put() the per-query syncobjs that
v3d_timestamp_query_info_free() and v3d_performance_query_info_free()
release on the success path. So the same fail path that triggers the
use-after-free also leaks one syncobj reference per query.
Unify the CPU job teardown into the CPU job's kref destructor, mirroring
v3d_render_job_free(). The scheduler's .free_job slot reverts to the
generic v3d_sched_job_free() and the fail label drops the manual
kvfree() calls, leaving a single teardown path that is reached from both
the scheduler and the ioctl error path. That removes the use-after-free,
the NULL dereference, and the syncobj leak by construction.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/v3d/v3d_sched.c",
"drivers/gpu/drm/v3d/v3d_submit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "acd55ea40d03e06f20a9986363019e0e5173990e",
"status": "affected",
"version": "9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f",
"versionType": "git"
},
{
"lessThan": "0f8efc45740b0628a787d1b0be8a0ddabd700625",
"status": "affected",
"version": "9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f",
"versionType": "git"
},
{
"lessThan": "69c2a1fec2e7ca25598180816f3bc56e1842eb41",
"status": "affected",
"version": "9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f",
"versionType": "git"
},
{
"lessThan": "b0fe80c0b9250b35e2211bf3117e7aca814a21b0",
"status": "affected",
"version": "9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/v3d/v3d_sched.c",
"drivers/gpu/drm/v3d/v3d_submit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix use-after-free of CPU job query arrays on error path\n\nThe CPU job ioctl\u0027s fail label calls kvfree() on cpu_job\u0027s timestamp and\nperformance query arrays after v3d_job_cleanup(), which drops the job\u0027s\nlast reference and frees cpu_job. Reading cpu_job at that point is a\nuse-after-free. Also, on the early v3d_job_init() failure path, it is a\nNULL dereference, since v3d_job_deallocate() zeroes the local pointer.\n\nIn the success path, the arrays are released from the scheduler\u0027s\n.free_job callback, but on the error path, they are freed manually, as\nthe job was never pushed to the scheduler. While the success path deals\nwith this correctly, the fail path doesn\u0027t.\n\nOn top of that, the manual kvfree() calls only free the array storage;\nthey don\u0027t drm_syncobj_put() the per-query syncobjs that\nv3d_timestamp_query_info_free() and v3d_performance_query_info_free()\nrelease on the success path. So the same fail path that triggers the\nuse-after-free also leaks one syncobj reference per query.\n\nUnify the CPU job teardown into the CPU job\u0027s kref destructor, mirroring\nv3d_render_job_free(). The scheduler\u0027s .free_job slot reverts to the\ngeneric v3d_sched_job_free() and the fail label drops the manual\nkvfree() calls, leaving a single teardown path that is reached from both\nthe scheduler and the ioctl error path. That removes the use-after-free,\nthe NULL dereference, and the syncobj leak by construction."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reachable only through the DRM_IOCTL_V3D_SUBMIT_CPU ioctl on /dev/dri/renderD*, requiring local access to the GPU render node; there is no network, adjacent-radio, or physical-device attack path to this code.\nAC:L - An attacker can deterministically trigger the vulnerable error path by submitting a crafted CPU job with timestamp/performance-query extensions and then forcing a controlled failure (e.g., invalid BO handle after v3d_job_init(), or a multisync init failure), without depending on races or external timing.\nPR:L - The ioctl is permitted on render nodes (DRM_RENDER_ALLOW | DRM_AUTH), which unprivileged local users on affected Broadcom V3D systems (e.g., Raspberry Pi users in the render/video group, GPU containers with /dev/dri passthrough) can open without real root in the init namespace.\nUI:N - Exploitation requires only the attacker\u0027s own ioctl submissions to the render node; no separate victim user action (opening files, mounting filesystems, clicking links) is needed beyond the attacker already having local GPU client access.\nS:U - Successful exploitation yields standard host-kernel memory corruption and privilege escalation within the same kernel security authority; it does not inherently cross a hypervisor/IOMMU boundary or constitute a VM escape on its own.\nC:H - The fail path performs a use-after-free read of freed cpu_job metadata to reach timestamp/performance query arrays, which per kernel UAF guidance enables arbitrary kernel memory disclosure via heap grooming and corrupted object interpretation.\nI:H - The same use-after-free on kernel heap objects can be leveraged for arbitrary kernel writes and control-flow hijacking through heap spraying and reuse of the freed cpu_job/query structures, not merely a bounded or cosmetic corruption.\nA:H - The vulnerable error path also NULL-dereferences cpu_job when v3d_job_init() fails after v3d_job_deallocate(), and the use-after-free itself can provoke kernel oops/panic, giving reliable high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:13.645Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/acd55ea40d03e06f20a9986363019e0e5173990e"
},
{
"url": "https://git.kernel.org/stable/c/0f8efc45740b0628a787d1b0be8a0ddabd700625"
},
{
"url": "https://git.kernel.org/stable/c/69c2a1fec2e7ca25598180816f3bc56e1842eb41"
},
{
"url": "https://git.kernel.org/stable/c/b0fe80c0b9250b35e2211bf3117e7aca814a21b0"
}
],
"title": "drm/v3d: Fix use-after-free of CPU job query arrays on error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64099",
"datePublished": "2026-07-19T15:40:04.925Z",
"dateReserved": "2026-07-19T07:54:57.033Z",
"dateUpdated": "2026-08-05T12:39:13.645Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63998 (GCVE-0-2026-63998)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-07-19 14:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ethtool: module: call ethnl_ops_complete() on module flash errors
When validate() fails we are skipping over ethnl_ops_complete()
even tho we already called ethnl_ops_begin().
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ethtool/module.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d9defbf8b62bde89e206d74c2a2b445b9ed66108",
"status": "affected",
"version": "32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e",
"versionType": "git"
},
{
"lessThan": "e96ef1a40dda5b637b1911cd950b11e9848de939",
"status": "affected",
"version": "32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e",
"versionType": "git"
},
{
"lessThan": "84371fb58423f997939aacdcbc02d128d76a54e5",
"status": "affected",
"version": "32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ethtool/module.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: module: call ethnl_ops_complete() on module flash errors\n\nWhen validate() fails we are skipping over ethnl_ops_complete()\neven tho we already called ethnl_ops_begin()."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:56:16.664Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d9defbf8b62bde89e206d74c2a2b445b9ed66108"
},
{
"url": "https://git.kernel.org/stable/c/e96ef1a40dda5b637b1911cd950b11e9848de939"
},
{
"url": "https://git.kernel.org/stable/c/84371fb58423f997939aacdcbc02d128d76a54e5"
}
],
"title": "ethtool: module: call ethnl_ops_complete() on module flash errors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63998",
"datePublished": "2026-07-19T14:56:16.664Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-07-19T14:56:16.664Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52977 (GCVE-0-2026-52977)
Vulnerability from cvelistv5
Published
2026-06-24 16:28
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
futex: Prevent lockup in requeue-PI during signal/ timeout wakeup
During wait-requeue-pi (task A) and requeue-PI (task B) the following
race can happen:
Task A Task B
futex_wait_requeue_pi()
futex_setup_timer()
futex_do_wait()
futex_requeue()
CLASS(hb, hb1)(&key1);
CLASS(hb, hb2)(&key2);
*timeout*
futex_requeue_pi_wakeup_sync()
requeue_state = Q_REQUEUE_PI_IGNORE
*blocks on hb->lock*
futex_proxy_trylock_atomic()
futex_requeue_pi_prepare()
Q_REQUEUE_PI_IGNORE => -EAGAIN
double_unlock_hb(hb1, hb2)
*retry*
Task B acquires both hb locks and attempts to acquire the PI-lock of the
top most waiter (task B). Task A is leaving early due to a signal/
timeout and started removing itself from the queue. It updates its
requeue_state but can not remove it from the list because this requires
the hb lock which is owned by task B.
Usually task A is able to swoop the lock after task B unlocked it.
However if task B is of higher priority then task A may not be able to
wake up in time and acquire the lock before task B gets it again.
Especially on a UP system where A is never scheduled.
As a result task A blocks on the lock and task B busy loops, trying to
make progress but live locks the system instead. Tragic.
This can be fixed by removing the top most waiter from the list in this
case. This allows task B to grab the next top waiter (if any) in the
next iteration and make progress.
Remove the top most waiter if futex_requeue_pi_prepare() fails.
Let the waiter conditionally remove itself from the list in
handle_early_requeue_pi_wakeup().
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 07d91ef510fb16a2e0ca7453222105835b7ba3b8 Version: 07d91ef510fb16a2e0ca7453222105835b7ba3b8 Version: 07d91ef510fb16a2e0ca7453222105835b7ba3b8 Version: 07d91ef510fb16a2e0ca7453222105835b7ba3b8 Version: 07d91ef510fb16a2e0ca7453222105835b7ba3b8 Version: 07d91ef510fb16a2e0ca7453222105835b7ba3b8 Version: 07d91ef510fb16a2e0ca7453222105835b7ba3b8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/futex/requeue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e5dbae3572757cecc3d3ec7cf96cbcc9cd9f016c",
"status": "affected",
"version": "07d91ef510fb16a2e0ca7453222105835b7ba3b8",
"versionType": "git"
},
{
"lessThan": "4e0ed44e51727d56244a822ab941efe507c47966",
"status": "affected",
"version": "07d91ef510fb16a2e0ca7453222105835b7ba3b8",
"versionType": "git"
},
{
"lessThan": "e3f95b1ba242e37093305812df7fdbe7288a43ac",
"status": "affected",
"version": "07d91ef510fb16a2e0ca7453222105835b7ba3b8",
"versionType": "git"
},
{
"lessThan": "0aacb6d18f76552e3e0ee25d9f40d21b3486f4cf",
"status": "affected",
"version": "07d91ef510fb16a2e0ca7453222105835b7ba3b8",
"versionType": "git"
},
{
"lessThan": "69a7cfc66405aeaa2483147653d031b3592ffc9c",
"status": "affected",
"version": "07d91ef510fb16a2e0ca7453222105835b7ba3b8",
"versionType": "git"
},
{
"lessThan": "0304d60abb9dcc02bc7fe6d1850f4ca206e8f1a0",
"status": "affected",
"version": "07d91ef510fb16a2e0ca7453222105835b7ba3b8",
"versionType": "git"
},
{
"lessThan": "bc7304f3ae20972d11db6e0b1b541c63feda5f05",
"status": "affected",
"version": "07d91ef510fb16a2e0ca7453222105835b7ba3b8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/futex/requeue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Prevent lockup in requeue-PI during signal/ timeout wakeup\n\nDuring wait-requeue-pi (task A) and requeue-PI (task B) the following\nrace can happen:\n\n Task A Task B\n futex_wait_requeue_pi()\n futex_setup_timer()\n futex_do_wait()\n futex_requeue()\n CLASS(hb, hb1)(\u0026key1);\n CLASS(hb, hb2)(\u0026key2);\n *timeout*\n futex_requeue_pi_wakeup_sync()\n requeue_state = Q_REQUEUE_PI_IGNORE\n\n *blocks on hb-\u003elock*\n\n futex_proxy_trylock_atomic()\n futex_requeue_pi_prepare()\n Q_REQUEUE_PI_IGNORE =\u003e -EAGAIN\n double_unlock_hb(hb1, hb2)\n *retry*\n\nTask B acquires both hb locks and attempts to acquire the PI-lock of the\ntop most waiter (task B). Task A is leaving early due to a signal/\ntimeout and started removing itself from the queue. It updates its\nrequeue_state but can not remove it from the list because this requires\nthe hb lock which is owned by task B.\n\nUsually task A is able to swoop the lock after task B unlocked it.\nHowever if task B is of higher priority then task A may not be able to\nwake up in time and acquire the lock before task B gets it again.\nEspecially on a UP system where A is never scheduled.\n\nAs a result task A blocks on the lock and task B busy loops, trying to\nmake progress but live locks the system instead. Tragic.\n\nThis can be fixed by removing the top most waiter from the list in this\ncase. This allows task B to grab the next top waiter (if any) in the\nnext iteration and make progress.\n\nRemove the top most waiter if futex_requeue_pi_prepare() fails.\nLet the waiter conditionally remove itself from the list in\nhandle_early_requeue_pi_wakeup()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:04.076Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e5dbae3572757cecc3d3ec7cf96cbcc9cd9f016c"
},
{
"url": "https://git.kernel.org/stable/c/4e0ed44e51727d56244a822ab941efe507c47966"
},
{
"url": "https://git.kernel.org/stable/c/e3f95b1ba242e37093305812df7fdbe7288a43ac"
},
{
"url": "https://git.kernel.org/stable/c/0aacb6d18f76552e3e0ee25d9f40d21b3486f4cf"
},
{
"url": "https://git.kernel.org/stable/c/69a7cfc66405aeaa2483147653d031b3592ffc9c"
},
{
"url": "https://git.kernel.org/stable/c/0304d60abb9dcc02bc7fe6d1850f4ca206e8f1a0"
},
{
"url": "https://git.kernel.org/stable/c/bc7304f3ae20972d11db6e0b1b541c63feda5f05"
}
],
"title": "futex: Prevent lockup in requeue-PI during signal/ timeout wakeup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52977",
"datePublished": "2026-06-24T16:28:53.937Z",
"dateReserved": "2026-06-09T07:44:35.376Z",
"dateUpdated": "2026-08-19T16:28:04.076Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63850 (GCVE-0-2026-63850)
Vulnerability from cvelistv5
Published
2026-07-19 14:04
Modified
2026-08-05 12:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring
VCN encoder and decoder rings do not support 64-bit user fence writes,
reject CS submissions with user fences.
(cherry picked from commit 49b1fbbb5a071197ee71e2d70959b1cb29bdc317)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/vcn_v5_0_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9f5a1459ecc3195282be617639d710b54779c9dc",
"status": "affected",
"version": "b6d1a06320519ac3bfda6ce81067a1bc409b9cff",
"versionType": "git"
},
{
"lessThan": "139a8a52ef4349c62129703b3a3e3a6ae4d634eb",
"status": "affected",
"version": "b6d1a06320519ac3bfda6ce81067a1bc409b9cff",
"versionType": "git"
},
{
"lessThan": "2c350f3cd94be847ac216e1358ec7001eaaf0934",
"status": "affected",
"version": "b6d1a06320519ac3bfda6ce81067a1bc409b9cff",
"versionType": "git"
},
{
"lessThan": "8cae0ce77de492d7c31c1532a2e80c0c6e7e58cb",
"status": "affected",
"version": "b6d1a06320519ac3bfda6ce81067a1bc409b9cff",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/vcn_v5_0_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit 49b1fbbb5a071197ee71e2d70959b1cb29bdc317)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached via the local DRM_IOCTL_AMDGPU_CS ioctl on an AMDGPU render node (/dev/dri/renderD*), submitting a command buffer with AMDGPU_CHUNK_ID_FENCE to the VCN v5.0.0 encoder ring.\nAC:L - An attacker with render-node access can deterministically submit a VCN encoder CS with a user-fence chunk; no race, special memory layout, or non-default kernel configuration is required beyond having affected AMD VCN 5.0.0 hardware.\nPR:L - Exploitation requires access to the AMDGPU DRM render node, which is available to unprivileged local users in the render/video group (or equivalent GPU access), not root or capabilities obtainable only in the init namespace.\nUI:N - No victim interaction is needed beyond the attacker already having GPU render-node access; exploitation is fully attacker-driven through ioctl submission.\nS:U - Impact is kernel/GPU memory corruption and privilege escalation within the same host security boundary; it does not inherently cross a VM, container, or IOMMU isolation boundary.\nC:H - Submitting an unsupported 64-bit user fence causes the VCN hardware to perform misdirected GPU memory writes, providing a memory-corruption primitive that can be leveraged for arbitrary kernel memory disclosure.\nI:H - The malformed fence write gives the attacker a GPU-initiated arbitrary write primitive within the GPU virtual address space, enabling memory corruption and potential kernel code execution.\nA:H - Malformed VCN fence commands can hang the GPU, trigger kernel oopses, or crash the system when the unsupported fence operation is processed by hardware."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:36:28.456Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9f5a1459ecc3195282be617639d710b54779c9dc"
},
{
"url": "https://git.kernel.org/stable/c/139a8a52ef4349c62129703b3a3e3a6ae4d634eb"
},
{
"url": "https://git.kernel.org/stable/c/2c350f3cd94be847ac216e1358ec7001eaaf0934"
},
{
"url": "https://git.kernel.org/stable/c/8cae0ce77de492d7c31c1532a2e80c0c6e7e58cb"
}
],
"title": "drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63850",
"datePublished": "2026-07-19T14:04:41.975Z",
"dateReserved": "2026-07-19T07:54:57.016Z",
"dateUpdated": "2026-08-05T12:36:28.456Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64087 (GCVE-0-2026-64087)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-07-19 15:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) reject implausible blackbox record_count
adm1266_nvmem_read_blackbox() loops over a record_count that comes
straight from byte 3 of the BLACKBOX_INFO response. The destination
buffer is data->dev_mem, sized for the nvmem cell's declared 2048
bytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64).
A device that reports a record_count greater than 32 -- whether due
to firmware bugs, bus corruption, or a non-responsive slave returning
0xff -- would walk read_buff past the end of the dev_mem allocation
on the trailing iterations.
Cap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here)
before entering the loop and return -EIO on any larger value, so a
malformed BLACKBOX_INFO response cannot drive the loop out of bounds.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "adcb163ad7cacca317872fc62bd8885e842e45e3",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "c2c56092710fe8a893b67b5a3d7e62808d02d84d",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "5469e1e7c411acc15fdd8262c99c3ebd9defd594",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "f85c81e93dbd6915970bd5f3bffcf62633c4c54c",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "0e791cd0140fb136083565aadfbe0f705aa260d0",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "75c862adf3d3caab4f49bb3530723c215376e37c",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "231db52a5b64d0a9769e298dadc148e1f79b26a6",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "4afca954622d672ea65ed961bed01cf91caa034e",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) reject implausible blackbox record_count\n\nadm1266_nvmem_read_blackbox() loops over a record_count that comes\nstraight from byte 3 of the BLACKBOX_INFO response. The destination\nbuffer is data-\u003edev_mem, sized for the nvmem cell\u0027s declared 2048\nbytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64).\nA device that reports a record_count greater than 32 -- whether due\nto firmware bugs, bus corruption, or a non-responsive slave returning\n0xff -- would walk read_buff past the end of the dev_mem allocation\non the trailing iterations.\n\nCap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here)\nbefore entering the loop and return -EIO on any larger value, so a\nmalformed BLACKBOX_INFO response cannot drive the loop out of bounds."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:39:57.371Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/adcb163ad7cacca317872fc62bd8885e842e45e3"
},
{
"url": "https://git.kernel.org/stable/c/c2c56092710fe8a893b67b5a3d7e62808d02d84d"
},
{
"url": "https://git.kernel.org/stable/c/5469e1e7c411acc15fdd8262c99c3ebd9defd594"
},
{
"url": "https://git.kernel.org/stable/c/f85c81e93dbd6915970bd5f3bffcf62633c4c54c"
},
{
"url": "https://git.kernel.org/stable/c/0e791cd0140fb136083565aadfbe0f705aa260d0"
},
{
"url": "https://git.kernel.org/stable/c/75c862adf3d3caab4f49bb3530723c215376e37c"
},
{
"url": "https://git.kernel.org/stable/c/231db52a5b64d0a9769e298dadc148e1f79b26a6"
},
{
"url": "https://git.kernel.org/stable/c/4afca954622d672ea65ed961bed01cf91caa034e"
}
],
"title": "hwmon: (pmbus/adm1266) reject implausible blackbox record_count",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64087",
"datePublished": "2026-07-19T15:39:57.371Z",
"dateReserved": "2026-07-19T07:54:57.032Z",
"dateUpdated": "2026-07-19T15:39:57.371Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68427 (GCVE-0-2026-68427)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
__host1x_bo_unpin() drops the last reference to the mapping and frees
it, so we can't dereference mapping afterwards. The cache itself
outlives the mapping, so use the cache local variable instead.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: af755456299d44e4ed6af3b7c70a7f03ea37fdf1 Version: 71c017b3f83ff72638f2a1b1d6d4e7bc61d30231 Version: 0e9dd7cfb9986b78cc81eca126ccfbf57f4c0602 Version: 8c0d3cf0d5108c96317e0eca92b60dd368867cef Version: df63c76f9c8d881ca7bce1aecfba512328d0527d Version: 3cbf5e3c46e66d9b3b6b91099bb720c6cb1be3bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/host1x/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "86a9bd8c8f422d5f3079da31e151868902fcc702",
"status": "affected",
"version": "af755456299d44e4ed6af3b7c70a7f03ea37fdf1",
"versionType": "git"
},
{
"lessThan": "abeff53233b984571b87582bb588b4b38ef4ea50",
"status": "affected",
"version": "71c017b3f83ff72638f2a1b1d6d4e7bc61d30231",
"versionType": "git"
},
{
"lessThan": "5b7e5f84d3d4cea10c3764d2da274810a7934228",
"status": "affected",
"version": "0e9dd7cfb9986b78cc81eca126ccfbf57f4c0602",
"versionType": "git"
},
{
"lessThan": "5f4de3c717d34a24d555af581947742980778c02",
"status": "affected",
"version": "8c0d3cf0d5108c96317e0eca92b60dd368867cef",
"versionType": "git"
},
{
"lessThan": "b773faa32b0a98c3eb2b50d96de631681e5d1157",
"status": "affected",
"version": "df63c76f9c8d881ca7bce1aecfba512328d0527d",
"versionType": "git"
},
{
"lessThan": "266cddf7bd0f6c79b6c0633aef742a22bf70265b",
"status": "affected",
"version": "3cbf5e3c46e66d9b3b6b91099bb720c6cb1be3bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/host1x/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThan": "7.1.6",
"status": "affected",
"version": "7.1.5",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.178",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.145",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.97",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.40",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.1.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings\n\n__host1x_bo_unpin() drops the last reference to the mapping and frees\nit, so we can\u0027t dereference mapping afterwards. The cache itself\noutlives the mapping, so use the cache local variable instead."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached only through the Tegra DRM/KMS device node (/dev/dri/card0): a local process pins a GEM buffer as a scanout framebuffer via an atomic commit and then destroys the handle, invoking tegra_bo_free_object() -\u003e host1x_bo_clear_cached_mappings(). No network or remote input reaches this code.\nAC:L - The use-after-free is unconditional and deterministic \u2014 every cached mapping freed by host1x_bo_clear_cached_mappings() is dereferenced again for the mutex_unlock. No race must be won and no special memory layout is needed; the attacker fully controls buffer creation, scanout pinning, and the destroy that triggers the free.\nPR:L - An unprivileged local user with access to the Tegra DRM device (video/graphics group, the logged-in console/compositor user on Android, automotive and embedded Tegra systems) can create GEM buffers, present them on a plane and free them. No root or CAP_SYS_ADMIN is required.\nUI:N - The attacking process performs the whole sequence itself \u2014 GEM allocation, atomic plane commit, and handle destruction \u2014 with no action by any other user or victim process.\nS:U - The corruption stays within the kernel\u0027s own memory and security authority; there is no crossing into another VM, IOMMU domain, or sandbox boundary.\nC:H - The freed host1x_bo_mapping is read after kfree() to obtain the cache pointer; with slab reuse the attacker can groom the freed object so the read returns attacker-influenced data, and the resulting UAF primitive can be leveraged to disclose kernel memory contents.\nI:H - mutex_unlock() writes to the lock word at the address read from freed memory, so a reallocated/poisoned mapping object yields a write through an attacker-influenceable pointer \u2014 a classic UAF write primitive usable for heap corruption and control-flow hijacking.\nA:H - Dereferencing the freed mapping reliably oopses under slab poisoning/KASAN, and unlocking a bogus mutex address corrupts kernel state, causing a panic or hang; the sequence can be repeated at will to keep the system down."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:22.452Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/86a9bd8c8f422d5f3079da31e151868902fcc702"
},
{
"url": "https://git.kernel.org/stable/c/abeff53233b984571b87582bb588b4b38ef4ea50"
},
{
"url": "https://git.kernel.org/stable/c/5b7e5f84d3d4cea10c3764d2da274810a7934228"
},
{
"url": "https://git.kernel.org/stable/c/5f4de3c717d34a24d555af581947742980778c02"
},
{
"url": "https://git.kernel.org/stable/c/b773faa32b0a98c3eb2b50d96de631681e5d1157"
},
{
"url": "https://git.kernel.org/stable/c/266cddf7bd0f6c79b6c0633aef742a22bf70265b"
}
],
"title": "gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68427",
"datePublished": "2026-08-10T12:04:47.915Z",
"dateReserved": "2026-07-30T09:28:09.392Z",
"dateUpdated": "2026-08-19T16:35:22.452Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68419 (GCVE-0-2026-68419)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: Prevent rereg_mr for non-mem regions
When a QP/CQ/SRQ is created, a two step process is used
where the buffer is allocated in userspace and explicitly
registered with the normal reg_mr mechanism prior to creating
the actual QP/CQ/SRQ object.
These special registrations are indicated via an ABI field
so the driver knows that they do not have a valid mkey and
to skip the actual CQP command submission.
Since these are real MR objects from the core's perspective,
it is possible for a user application to invoke rereg_mr on them
and cause a real CQP op to be emitted with the zero-initialized
mkey value of 0.
Fix this by preventing rereg_mr on these special regions.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 715fdb3b30541cc8180b7cdc6aa9f8c307afdf25 Version: 5ac388db27c443dadfbb0b8b23fa7ccf429d901a Version: 5ac388db27c443dadfbb0b8b23fa7ccf429d901a Version: 5ac388db27c443dadfbb0b8b23fa7ccf429d901a Version: 5ac388db27c443dadfbb0b8b23fa7ccf429d901a Version: 6.6.120 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/irdma/verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fb46d134e1b8690bed2da9005b36d32d2efd34ac",
"status": "affected",
"version": "715fdb3b30541cc8180b7cdc6aa9f8c307afdf25",
"versionType": "git"
},
{
"lessThan": "b5029e91c63406e4f4c8d58161048b41b6f0bd8c",
"status": "affected",
"version": "5ac388db27c443dadfbb0b8b23fa7ccf429d901a",
"versionType": "git"
},
{
"lessThan": "ca1c29f05274b737dc964e28b97803750d7cf7ec",
"status": "affected",
"version": "5ac388db27c443dadfbb0b8b23fa7ccf429d901a",
"versionType": "git"
},
{
"lessThan": "dbaa37e060918c45517786e37ecab0f300b48fa9",
"status": "affected",
"version": "5ac388db27c443dadfbb0b8b23fa7ccf429d901a",
"versionType": "git"
},
{
"lessThan": "a846aecb931b4d65d5eafa92a0623545af46d4f2",
"status": "affected",
"version": "5ac388db27c443dadfbb0b8b23fa7ccf429d901a",
"versionType": "git"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.120",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/irdma/verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.120",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Prevent rereg_mr for non-mem regions\n\nWhen a QP/CQ/SRQ is created, a two step process is used\nwhere the buffer is allocated in userspace and explicitly\nregistered with the normal reg_mr mechanism prior to creating\nthe actual QP/CQ/SRQ object.\n\nThese special registrations are indicated via an ABI field\nso the driver knows that they do not have a valid mkey and\nto skip the actual CQP command submission.\n\nSince these are real MR objects from the core\u0027s perspective,\nit is possible for a user application to invoke rereg_mr on them\nand cause a real CQP op to be emitted with the zero-initialized\nmkey value of 0.\n\nFix this by preventing rereg_mr on these special regions."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is reached through the ib_uverbs REREG_MR command on /dev/infiniband/uverbs*, a local character device; no network input reaches irdma_rereg_user_mr(). The resulting corrupt hardware STAG can later be abused over RDMA, but initial access is local.\nAC:L - The attacker fully controls every precondition: register a buffer with reg_type IRDMA_MEMREG_TYPE_QP/CQ/SRQ, then call rereg_mr on that handle. There is no race, no timing dependency and no reliance on memory layout the attacker cannot influence.\nPR:L - Only an open file descriptor on /dev/infiniband/uverbsN is needed; rdma-core udev rules ship these nodes world-accessible (0666) and they are routinely exposed to containers. ib_uverbs_rereg_mr() performs no capability check, only uobject ownership of the caller\u0027s own MR.\nUI:N - The attacker performs the entire sequence (reg_mr with a non-MEM reg_type, then rereg_mr) from its own process. No action by any other user or administrator is required.\nS:U - The corruption stays within the kernel/RDMA-device security authority managed by the same OS instance; there is no VM, IOMMU or hypervisor boundary crossed by the erroneous CQP command.\nC:H - Programming HW STAG index 0 with attacker-chosen remote-read rights, combined with dereg_mr never invalidating it, leaves a live hardware mapping over PBLEs and umem pages that are freed and reused, giving RDMA-read access to recycled kernel/other-process memory; it can also collide with another process\u0027s MR at stag index 0.\nI:H - The same stale/hijacked STAG can carry IB_ACCESS_REMOTE_WRITE, and the IB_MR_REREG_TRANS path frees the PBLEs and releases the umem of a live QP/CQ/SRQ while hardware keeps DMAing into those pages, yielding device-driven writes into freed and reallocated kernel memory.\nA:H - Issuing a CQP op with a zero mkey corrupts device state and can fail the CQP op, triggering the driver\u0027s reset path; the DMA-after-free into recycled pages and the clobbering of another region\u0027s STAG readily produce kernel memory corruption, oops or full RDMA device reset."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:14.336Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fb46d134e1b8690bed2da9005b36d32d2efd34ac"
},
{
"url": "https://git.kernel.org/stable/c/b5029e91c63406e4f4c8d58161048b41b6f0bd8c"
},
{
"url": "https://git.kernel.org/stable/c/ca1c29f05274b737dc964e28b97803750d7cf7ec"
},
{
"url": "https://git.kernel.org/stable/c/dbaa37e060918c45517786e37ecab0f300b48fa9"
},
{
"url": "https://git.kernel.org/stable/c/a846aecb931b4d65d5eafa92a0623545af46d4f2"
}
],
"title": "RDMA/irdma: Prevent rereg_mr for non-mem regions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68419",
"datePublished": "2026-08-10T12:04:39.912Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-17T05:05:14.336Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68236 (GCVE-0-2026-68236)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: set new_stream to NULL after release
In dm_update_crtc_state(), the skip_modeset path releases new_stream
via dc_stream_release() but does not set the pointer to NULL.
If a later error (e.g., color management failure) triggers the fail
label, the error path calls dc_stream_release() again on the same
dangling pointer, causing a double release and potential use-after-free.
Fix this by setting new_stream to NULL after the initial release.
(cherry picked from commit 99f3af19073b3ddbfd96e789124cce12c4277b28)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ba8bf1dcbb44773e7a0fd13b42925c644e0d5e76",
"status": "affected",
"version": "9b690ef3c70422cdcd0cf912db33f2c92ef4a53f",
"versionType": "git"
},
{
"lessThan": "5182e442e61397d446c36995b8f5676942d35b82",
"status": "affected",
"version": "9b690ef3c70422cdcd0cf912db33f2c92ef4a53f",
"versionType": "git"
},
{
"lessThan": "679f23f0a3606afcef1ffabd72222f00a54ad9e3",
"status": "affected",
"version": "9b690ef3c70422cdcd0cf912db33f2c92ef4a53f",
"versionType": "git"
},
{
"lessThan": "0676fecbb5242aa22c057e78326d6d6041db034c",
"status": "affected",
"version": "9b690ef3c70422cdcd0cf912db33f2c92ef4a53f",
"versionType": "git"
},
{
"lessThan": "9fa26b9eed6195bf840f39ac183b9a6237548755",
"status": "affected",
"version": "9b690ef3c70422cdcd0cf912db33f2c92ef4a53f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: set new_stream to NULL after release\n\nIn dm_update_crtc_state(), the skip_modeset path releases new_stream\nvia dc_stream_release() but does not set the pointer to NULL.\n\nIf a later error (e.g., color management failure) triggers the fail\nlabel, the error path calls dc_stream_release() again on the same\ndangling pointer, causing a double release and potential use-after-free.\n\nFix this by setting new_stream to NULL after the initial release.\n\n(cherry picked from commit 99f3af19073b3ddbfd96e789124cce12c4277b28)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the DRM atomic modeset ioctl (DRM_IOCTL_MODE_ATOMIC) on a local /dev/dri/card* node of an AMD GPU; there is no network or remote input path into dm_update_crtc_state().\nAC:L - A single atomic commit that requests a mode change while attaching a wrong-sized DEGAMMA_LUT blob deterministically drives amdgpu_dm_check_crtc_color_mgmt() to -EINVAL and hits the double dc_stream_release(); no race and no uncontrolled precondition, and TEST_ONLY commits let the attacker repeat it freely to groom the heap.\nPR:L - The atomic ioctl is gated only by DRM master on the card node, which any unprivileged local user on a graphical seat or an unused VT can hold; no CAP_SYS_ADMIN or root is needed.\nUI:N - The attacker performs the whole sequence with its own ioctl calls; no action by another user or administrator is required, and TEST_ONLY commits do not even disturb the display.\nS:U - The corrupted dc_stream_state and the resulting freed-memory reuse stay within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The extra kref_put() frees the dc_stream_state while the CRTC state and the DC context still reference it; reading through those dangling pointers after the slab is reallocated leaks adjacent kernel object contents and pointers, and the attacker can spray to control what lands there.\nI:H - The reference-count underflow yields a use-after-free/double-free: subsequent kref_put() writes into reallocated slab memory and dc_stream_free() kfree()s an attacker-influenced update_scratch pointer, giving write and arbitrary-free primitives usable for privilege escalation.\nA:H - Even without exploitation the premature free causes dereference of freed stream/sink/link structures during atomic state unwind, producing a kernel oops or panic and killing the display pipeline; it can be triggered repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:25.183Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ba8bf1dcbb44773e7a0fd13b42925c644e0d5e76"
},
{
"url": "https://git.kernel.org/stable/c/5182e442e61397d446c36995b8f5676942d35b82"
},
{
"url": "https://git.kernel.org/stable/c/679f23f0a3606afcef1ffabd72222f00a54ad9e3"
},
{
"url": "https://git.kernel.org/stable/c/0676fecbb5242aa22c057e78326d6d6041db034c"
},
{
"url": "https://git.kernel.org/stable/c/9fa26b9eed6195bf840f39ac183b9a6237548755"
}
],
"title": "drm/amd/display: set new_stream to NULL after release",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68236",
"datePublished": "2026-08-10T12:01:01.114Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-17T05:01:25.183Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-23454 (GCVE-0-2026-23454)
Vulnerability from cvelistv5
Published
2026-04-03 15:15
Modified
2026-09-08 08:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown
A potential race condition exists in mana_hwc_destroy_channel() where
hwc->caller_ctx is freed before the HWC's Completion Queue (CQ) and
Event Queue (EQ) are destroyed. This allows an in-flight CQ interrupt
handler to dereference freed memory, leading to a use-after-free or
NULL pointer dereference in mana_hwc_handle_resp().
mana_smc_teardown_hwc() signals the hardware to stop but does not
synchronize against IRQ handlers already executing on other CPUs. The
IRQ synchronization only happens in mana_hwc_destroy_cq() via
mana_gd_destroy_eq() -> mana_gd_deregister_irq(). Since this runs
after kfree(hwc->caller_ctx), a concurrent mana_hwc_rx_event_handler()
can dereference freed caller_ctx (and rxq->msg_buf) in
mana_hwc_handle_resp().
Fix this by reordering teardown to reverse-of-creation order: destroy
the TX/RX work queues and CQ/EQ before freeing hwc->caller_ctx. This
ensures all in-flight interrupt handlers complete before the memory they
access is freed.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:46:20.496Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/hw_channel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b88edf12fc3779521ae5f6f1584153b15f7da6df",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "e23bf444512cb85d76012080a76cd1f9e967448e",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "249e905571583a434d4ea8d6f92ccc0eef337115",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "2b001901f689021acd7bf2dceed74a1bdcaaa1f9",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "afdb1533eb9c05432aeb793a7280fa827c502f5c",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "05d345719d85b927cba74afac4d5322de3aa4256",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "fa103fc8f56954a60699a29215cb713448a39e87",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/hw_channel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.20",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.167",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.20",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.10",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown\n\nA potential race condition exists in mana_hwc_destroy_channel() where\nhwc-\u003ecaller_ctx is freed before the HWC\u0027s Completion Queue (CQ) and\nEvent Queue (EQ) are destroyed. This allows an in-flight CQ interrupt\nhandler to dereference freed memory, leading to a use-after-free or\nNULL pointer dereference in mana_hwc_handle_resp().\n\nmana_smc_teardown_hwc() signals the hardware to stop but does not\nsynchronize against IRQ handlers already executing on other CPUs. The\nIRQ synchronization only happens in mana_hwc_destroy_cq() via\nmana_gd_destroy_eq() -\u003e mana_gd_deregister_irq(). Since this runs\nafter kfree(hwc-\u003ecaller_ctx), a concurrent mana_hwc_rx_event_handler()\ncan dereference freed caller_ctx (and rxq-\u003emsg_buf) in\nmana_hwc_handle_resp().\n\nFix this by reordering teardown to reverse-of-creation order: destroy\nthe TX/RX work queues and CQ/EQ before freeing hwc-\u003ecaller_ctx. This\nensures all in-flight interrupt handlers complete before the memory they\naccess is freed."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:07:18.149Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b88edf12fc3779521ae5f6f1584153b15f7da6df"
},
{
"url": "https://git.kernel.org/stable/c/e23bf444512cb85d76012080a76cd1f9e967448e"
},
{
"url": "https://git.kernel.org/stable/c/249e905571583a434d4ea8d6f92ccc0eef337115"
},
{
"url": "https://git.kernel.org/stable/c/2b001901f689021acd7bf2dceed74a1bdcaaa1f9"
},
{
"url": "https://git.kernel.org/stable/c/afdb1533eb9c05432aeb793a7280fa827c502f5c"
},
{
"url": "https://git.kernel.org/stable/c/05d345719d85b927cba74afac4d5322de3aa4256"
},
{
"url": "https://git.kernel.org/stable/c/fa103fc8f56954a60699a29215cb713448a39e87"
}
],
"title": "net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-23454",
"datePublished": "2026-04-03T15:15:36.189Z",
"dateReserved": "2026-01-13T15:37:46.020Z",
"dateUpdated": "2026-09-08T08:46:20.496Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64452 (GCVE-0-2026-64452)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
6lowpan: fix NHC entry use-after-free on error path
lowpan_nhc_do_uncompression() looks up an NHC descriptor while holding
lowpan_nhc_lock. If the descriptor has no uncompress callback, the error
path drops the lock before printing nhc->name.
lowpan_nhc_del() removes descriptors under the same lock and then relies
on synchronize_net() before the owning module can be unloaded. That only
waits for net RX RCU readers. lowpan_header_decompress() is also exported
and can be reached from callers that are not necessarily covered by the net
core RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive
path.
This leaves a race where one task drops lowpan_nhc_lock in the error path,
another task unregisters and frees the matching descriptor after
synchronize_net() returns, and the first task then dereferences nhc->name
for the warning.
With the post-unlock window widened, KASAN reports:
BUG: KASAN: slab-use-after-free in lowpan_nhc_do_uncompression+0x1f4/0x220
Read of size 8
lowpan_nhc_do_uncompression
lowpan_header_decompress
Fix this by printing the warning before dropping lowpan_nhc_lock, so the
descriptor name is read while unregister is still excluded. The malformed
packet is still rejected with -ENOTSUPP.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 92aa7c65d295f3cbb96904afe335f683e55584b8 Version: 92aa7c65d295f3cbb96904afe335f683e55584b8 Version: 92aa7c65d295f3cbb96904afe335f683e55584b8 Version: 92aa7c65d295f3cbb96904afe335f683e55584b8 Version: 92aa7c65d295f3cbb96904afe335f683e55584b8 Version: 92aa7c65d295f3cbb96904afe335f683e55584b8 Version: 92aa7c65d295f3cbb96904afe335f683e55584b8 Version: 92aa7c65d295f3cbb96904afe335f683e55584b8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/6lowpan/nhc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9c2f5c0829a8c8b904dae36be6d8056b719ac605",
"status": "affected",
"version": "92aa7c65d295f3cbb96904afe335f683e55584b8",
"versionType": "git"
},
{
"lessThan": "80b5c8779acee0550845394fb3e5176a398aa24c",
"status": "affected",
"version": "92aa7c65d295f3cbb96904afe335f683e55584b8",
"versionType": "git"
},
{
"lessThan": "cc27aea4d454abfb385ee2c9499c78b96db9b728",
"status": "affected",
"version": "92aa7c65d295f3cbb96904afe335f683e55584b8",
"versionType": "git"
},
{
"lessThan": "a8e3a94711134e898c6021a6b77374efa91b3639",
"status": "affected",
"version": "92aa7c65d295f3cbb96904afe335f683e55584b8",
"versionType": "git"
},
{
"lessThan": "593b78bb3c7ef0c6e9ae6fdf5afa80a5f7573168",
"status": "affected",
"version": "92aa7c65d295f3cbb96904afe335f683e55584b8",
"versionType": "git"
},
{
"lessThan": "0beccbcf50de125be5520d0ffc59af4bb8655482",
"status": "affected",
"version": "92aa7c65d295f3cbb96904afe335f683e55584b8",
"versionType": "git"
},
{
"lessThan": "b713aa0cc344f10f7a9928a230b5f5e780d04078",
"status": "affected",
"version": "92aa7c65d295f3cbb96904afe335f683e55584b8",
"versionType": "git"
},
{
"lessThan": "1720db928e5a58ca7d75ac1d514c3b73fd7061a7",
"status": "affected",
"version": "92aa7c65d295f3cbb96904afe335f683e55584b8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/6lowpan/nhc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\n6lowpan: fix NHC entry use-after-free on error path\n\nlowpan_nhc_do_uncompression() looks up an NHC descriptor while holding\nlowpan_nhc_lock. If the descriptor has no uncompress callback, the error\npath drops the lock before printing nhc-\u003ename.\n\nlowpan_nhc_del() removes descriptors under the same lock and then relies\non synchronize_net() before the owning module can be unloaded. That only\nwaits for net RX RCU readers. lowpan_header_decompress() is also exported\nand can be reached from callers that are not necessarily covered by the net\ncore RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive\npath.\n\nThis leaves a race where one task drops lowpan_nhc_lock in the error path,\nanother task unregisters and frees the matching descriptor after\nsynchronize_net() returns, and the first task then dereferences nhc-\u003ename\nfor the warning.\n\nWith the post-unlock window widened, KASAN reports:\n\n BUG: KASAN: slab-use-after-free in lowpan_nhc_do_uncompression+0x1f4/0x220\n Read of size 8\n lowpan_nhc_do_uncompression\n lowpan_header_decompress\n\nFix this by printing the warning before dropping lowpan_nhc_lock, so the\ndescriptor name is read while unregister is still excluded. The malformed\npacket is still rejected with -ENOTSUPP."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - An adjacent Bluetooth LE peer can deliver a crafted IPHC/NHC frame through the unauthenticated L2CAP IPSP receive path to the vulnerable decompressor.\nAC:H - Exploitation requires the matching loadable NHC descriptor to be unregistered and freed during the tiny post-unlock window, and the adjacent attacker cannot independently force that module-unload side of the race.\nPR:N - The Bluetooth packet-processing path requires no attacker privileges or authenticated pairing because the IPSP channel uses BT_SECURITY_LOW; CAP_SYS_MODULE belongs to the victim-side unload actor.\nUI:R - Successful triggering requires a victim administrator or module-management action to unload the matching NHC module while the malicious packet is being processed.\nS:U - The vulnerability compromises the affected host kernel without crossing a separate virtualization, IOMMU, or security-authority boundary.\nC:H - The freed descriptor\u0027s name pointer is dereferenced as a string, so reused contents can cause an unbounded kernel-memory read and disclosure through the kernel log.\nI:H - As a kernel-space use-after-free, freed-object replacement is conservatively treated as potentially enabling memory-corruption or control-flow compromise.\nA:H - Dereferencing an invalid freed descriptor or string pointer can produce a kernel oops or panic and render the system unavailable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:56.222Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9c2f5c0829a8c8b904dae36be6d8056b719ac605"
},
{
"url": "https://git.kernel.org/stable/c/80b5c8779acee0550845394fb3e5176a398aa24c"
},
{
"url": "https://git.kernel.org/stable/c/cc27aea4d454abfb385ee2c9499c78b96db9b728"
},
{
"url": "https://git.kernel.org/stable/c/a8e3a94711134e898c6021a6b77374efa91b3639"
},
{
"url": "https://git.kernel.org/stable/c/593b78bb3c7ef0c6e9ae6fdf5afa80a5f7573168"
},
{
"url": "https://git.kernel.org/stable/c/0beccbcf50de125be5520d0ffc59af4bb8655482"
},
{
"url": "https://git.kernel.org/stable/c/b713aa0cc344f10f7a9928a230b5f5e780d04078"
},
{
"url": "https://git.kernel.org/stable/c/1720db928e5a58ca7d75ac1d514c3b73fd7061a7"
}
],
"title": "6lowpan: fix NHC entry use-after-free on error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64452",
"datePublished": "2026-07-25T08:51:21.754Z",
"dateReserved": "2026-07-19T15:36:31.788Z",
"dateUpdated": "2026-08-17T04:55:56.222Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64224 (GCVE-0-2026-64224)
Vulnerability from cvelistv5
Published
2026-07-24 15:23
Modified
2026-07-24 15:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: fix double free in rvu_rep_rsrc_init()
rvu_rep_rsrc_init() allocates queue memory before calling
otx2_init_hw_resources(). When hardware resource setup fails,
otx2_init_hw_resources() already unwinds the partially initialized
SQ, CQ, and aura state before returning an error. The representor
error path then calls otx2_free_hw_resources() again and can free
the same resources a second time.
Fix this by splitting the cleanup labels so that a failure from
otx2_init_hw_resources() only releases queue memory. Keep the
otx2_free_hw_resources() call for failures that happen after
hardware resource initialization completed successfully.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1-rc3.
Runtime validation was not performed because reproducing this path
requires OcteonTX2 representor hardware.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/nic/rep.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8864b664d0443ecb8e56690e5546fcda5fe5e81b",
"status": "affected",
"version": "3937b7308d4fce2793fa7fa56ed0faf0f8b6dc7a",
"versionType": "git"
},
{
"lessThan": "eb72a65f2bb2cc059e2ca5d83de01fdf3ea602ad",
"status": "affected",
"version": "3937b7308d4fce2793fa7fa56ed0faf0f8b6dc7a",
"versionType": "git"
},
{
"lessThan": "e8fb3de2a8effcaf62bec2c56b93d8bb480371d1",
"status": "affected",
"version": "3937b7308d4fce2793fa7fa56ed0faf0f8b6dc7a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/nic/rep.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: fix double free in rvu_rep_rsrc_init()\n\nrvu_rep_rsrc_init() allocates queue memory before calling\notx2_init_hw_resources(). When hardware resource setup fails,\notx2_init_hw_resources() already unwinds the partially initialized\nSQ, CQ, and aura state before returning an error. The representor\nerror path then calls otx2_free_hw_resources() again and can free\nthe same resources a second time.\n\nFix this by splitting the cleanup labels so that a failure from\notx2_init_hw_resources() only releases queue memory. Keep the\notx2_free_hw_resources() call for failures that happen after\nhardware resource initialization completed successfully.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc3.\n\nRuntime validation was not performed because reproducing this path\nrequires OcteonTX2 representor hardware."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-24T15:23:09.209Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8864b664d0443ecb8e56690e5546fcda5fe5e81b"
},
{
"url": "https://git.kernel.org/stable/c/eb72a65f2bb2cc059e2ca5d83de01fdf3ea602ad"
},
{
"url": "https://git.kernel.org/stable/c/e8fb3de2a8effcaf62bec2c56b93d8bb480371d1"
}
],
"title": "octeontx2-pf: fix double free in rvu_rep_rsrc_init()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64224",
"datePublished": "2026-07-24T15:23:09.209Z",
"dateReserved": "2026-07-19T15:36:31.770Z",
"dateUpdated": "2026-07-24T15:23:09.209Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64442 (GCVE-0-2026-64442)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
Two IE parsing loops are missing the header bounds checks before they
dereference pIE->length:
- issue_assocreq() walks pmlmeinfo->network.ies to build the
association request. If the stored IE data ends with only an
element_id byte and no length byte, pIE->length is read one byte
past the end of the buffer.
- join_cmd_hdl() walks pnetwork->ies during station join and has
the same problem under the same conditions.
Both buffers are filled from AP beacon and probe-response frames, so a
malicious AP that sends a truncated final IE can trigger the issue.
Apply the two-guard pattern established in update_beacon_info():
1. Break if fewer than sizeof(*pIE) bytes remain.
2. Break if the IE's declared data extends past the buffer end.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bc881c9915c4468747d0ca5fd1abd7b313cfb0f4",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "605ebd94d0f469204f3c9f2f84acc71e43e2780f",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "a830bdc82461353bf7b1f8a2ad2689bf5d2de444",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "4c21eec80cf502d9ea18e0b946246b2376452786",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "ad2637c46ef8b8ae0894372a2d39fdfcdc420a1e",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "c38d16b1ffac385c9e4b38447cd5c46af1114b58",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "402f13ec95945f34a210b28df1f8740d3d4a58c5",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "ef61d628dfad38fead1fd2e08979ae9126d011d5",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()\n\nTwo IE parsing loops are missing the header bounds checks before they\ndereference pIE-\u003elength:\n\n - issue_assocreq() walks pmlmeinfo-\u003enetwork.ies to build the\n association request. If the stored IE data ends with only an\n element_id byte and no length byte, pIE-\u003elength is read one byte\n past the end of the buffer.\n\n - join_cmd_hdl() walks pnetwork-\u003eies during station join and has\n the same problem under the same conditions.\n\nBoth buffers are filled from AP beacon and probe-response frames, so a\nmalicious AP that sends a truncated final IE can trigger the issue.\n\nApply the two-guard pattern established in update_beacon_info():\n 1. Break if fewer than sizeof(*pIE) bytes remain.\n 2. Break if the IE\u0027s declared data extends past the buffer end."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - A malicious AP within WiFi radio range can supply crafted beacon or probe-response IEs that reach both vulnerable loops during connection.\nAC:L - The attacker directly controls the IE layout and declared lengths, and triggering requires no race or condition outside attacker control.\nPR:N - join_cmd_hdl() executes before authentication, while issue_assocreq() precedes WPA/802.1X credential verification; the rogue AP needs no valid credentials.\nUI:N - Devices can automatically reconnect to a rogue AP spoofing a saved SSID, so no contemporaneous victim action is required.\nS:U - The vulnerable parser and resulting impacts remain within the host kernel\u0027s existing security authority.\nC:H - A malicious length can cause reads of up to 255 bytes beyond the logical IE boundary, including kernel pointers or state, and issue_assocreq() can transmit those bytes to the attacking AP.\nI:N - The defect performs out-of-bounds reads and copies into legitimate destinations, without providing an out-of-bounds or arbitrary write primitive.\nA:H - The malformed lengths drive unchecked kernel-context reads through multiple handlers and can cause an oops or kernel fault; an adjacent attacker can repeat the trigger during connection attempts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:44.254Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bc881c9915c4468747d0ca5fd1abd7b313cfb0f4"
},
{
"url": "https://git.kernel.org/stable/c/605ebd94d0f469204f3c9f2f84acc71e43e2780f"
},
{
"url": "https://git.kernel.org/stable/c/a830bdc82461353bf7b1f8a2ad2689bf5d2de444"
},
{
"url": "https://git.kernel.org/stable/c/4c21eec80cf502d9ea18e0b946246b2376452786"
},
{
"url": "https://git.kernel.org/stable/c/ad2637c46ef8b8ae0894372a2d39fdfcdc420a1e"
},
{
"url": "https://git.kernel.org/stable/c/c38d16b1ffac385c9e4b38447cd5c46af1114b58"
},
{
"url": "https://git.kernel.org/stable/c/402f13ec95945f34a210b28df1f8740d3d4a58c5"
},
{
"url": "https://git.kernel.org/stable/c/ef61d628dfad38fead1fd2e08979ae9126d011d5"
}
],
"title": "staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64442",
"datePublished": "2026-07-25T08:51:14.535Z",
"dateReserved": "2026-07-19T15:36:31.788Z",
"dateUpdated": "2026-08-17T04:55:44.254Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64567 (GCVE-0-2026-64567)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: reject free space cache with more entries than pages
When loading a v1 free space cache, __load_free_space_cache() takes
num_entries and num_bitmaps straight from the on-disk
btrfs_free_space_header. That header is stored in the tree_root under a key
with type 0, which the tree-checker has no case for, so neither count is
validated before the load trusts it.
The load loops num_entries times and maps the next page whenever the current
one runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which
does io_ctl->pages[io_ctl->index++]. But pages[] is allocated in
io_ctl_init() from the cache inode's i_size, not from num_entries:
num_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);
io_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);
So if num_entries claims more records than the pages can hold, io_ctl->index
runs off the end of pages[]. The write side never hits this because
io_ctl_add_entry() and io_ctl_add_bitmap() both stop once
io_ctl->index >= io_ctl->num_pages; the read side just never had the same
check.
To trigger it, take a clean cache (num_entries = <N> here), set num_entries
in the header to 0x10000, and fix up the leaf checksum so it still passes
the tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and
pages[] is a 16-pointer (kmalloc-128) array. The load now tries to read
65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the
array:
BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)
Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58
io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)
__load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)
load_free_space_cache (fs/btrfs/free-space-cache.c:1017)
caching_thread (fs/btrfs/block-group.c:880)
btrfs_work_helper (fs/btrfs/async-thread.c:312)
process_one_work
worker_thread
kthread
ret_from_fork
free-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()
at line 565, which is why that is the frame KASAN names. The out-of-bounds
slot is then treated as a struct page and handed to crc32c(), so the bad
read turns into a GP fault.
Add the missing check to io_ctl_check_crc(), which is where both the entry
loop and the bitmap loop end up. When num_entries is too large the load now
fails like any corrupt cache: __load_free_space_cache() drops it and rebuilds
the free space from the extent tree, so a valid cache is never rejected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/free-space-cache.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8ded74c654a982dc8581a17b0caa7fcedb20de69",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "c9c38066b6446e83668c041702bb639b0ca49363",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "094734c7aaa2b36751dc32480a680a4952685e78",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "33878ba25e2638bc0c61623d7a05c9ca2b74c039",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "5e1b2ca6b34939e70fb0785e8222b53cf060016f",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "f9fef131fa3f59b857217f522fa5ea430d1b707c",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "a2d8d5647ed854e38f941741aea45b9eb15a6350",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/free-space-cache.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reject free space cache with more entries than pages\n\nWhen loading a v1 free space cache, __load_free_space_cache() takes\nnum_entries and num_bitmaps straight from the on-disk\nbtrfs_free_space_header. That header is stored in the tree_root under a key\nwith type 0, which the tree-checker has no case for, so neither count is\nvalidated before the load trusts it.\n\nThe load loops num_entries times and maps the next page whenever the current\none runs out, going through io_ctl_check_crc() -\u003e io_ctl_map_page(), which\ndoes io_ctl-\u003epages[io_ctl-\u003eindex++]. But pages[] is allocated in\nio_ctl_init() from the cache inode\u0027s i_size, not from num_entries:\n\n\tnum_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);\n\tio_ctl-\u003epages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);\n\nSo if num_entries claims more records than the pages can hold, io_ctl-\u003eindex\nruns off the end of pages[]. The write side never hits this because\nio_ctl_add_entry() and io_ctl_add_bitmap() both stop once\nio_ctl-\u003eindex \u003e= io_ctl-\u003enum_pages; the read side just never had the same\ncheck.\n\nTo trigger it, take a clean cache (num_entries = \u003cN\u003e here), set num_entries\nin the header to 0x10000, and fix up the leaf checksum so it still passes\nthe tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and\npages[] is a 16-pointer (kmalloc-128) array. The load now tries to read\n65536 entries, io_ctl-\u003eindex walks up to 16, and pages[16] is read past the\narray:\n\n BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58\n io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)\n load_free_space_cache (fs/btrfs/free-space-cache.c:1017)\n caching_thread (fs/btrfs/block-group.c:880)\n btrfs_work_helper (fs/btrfs/async-thread.c:312)\n process_one_work\n worker_thread\n kthread\n ret_from_fork\n\nfree-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()\nat line 565, which is why that is the frame KASAN names. The out-of-bounds\nslot is then treated as a struct page and handed to crc32c(), so the bad\nread turns into a GP fault.\n\nAdd the missing check to io_ctl_check_crc(), which is where both the entry\nloop and the bitmap loop end up. When num_entries is too large the load now\nfails like any corrupt cache: __load_free_space_cache() drops it and rebuilds\nthe free space from the extent tree, so a valid cache is never rejected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only by mounting a crafted btrfs image so caching_thread \u2192 load_free_space_cache \u2192 __load_free_space_cache runs; there is no network or adjacent protocol path into v1 free-space cache loading.\nAC:L - The attacker authors a v1 cache with inflated num_entries (and a matching leaf checksum); cache_generation auto-enables SPACE_CACHE on mount, and the OOB in io_ctl_check_crc/io_ctl_map_page is deterministic with no race or uncontrolled condition.\nPR:L - btrfs lacks FS_USERNS_MOUNT, but an unprivileged local user can loop-setup and mount a crafted image via udisks2/polkit on typical desktops/kiosks; real init-namespace root is not required.\nUI:N - In the loop/udisks mount scenario the attacker mounts the image themselves; no separate victim must open a file, click through a prompt, or otherwise interact.\nS:U - The slab OOB and resulting kernel memory misuse stay inside the host kernel\u0027s authority; no VM escape, IOMMU bypass, or sandbox boundary is crossed.\nC:H - An out-of-bounds pages[] read yields a forged struct page pointer that is passed to page_address/crc32c and then used as the source for further cache parsing, giving an arbitrary kernel-memory read primitive once adjacent slab contents are groomed.\nI:H - The forged page pointer continues into entry/bitmap load paths (including copy_page into kernel bitmaps and linking attacker-controlled free-space records), a memory-corruption primitive exploitable for arbitrary write and control-flow hijack.\nA:H - Without a valid page pointer the OOB dereference reliably faults (KASAN slab-OOB then GP fault on crc32c as in the report), crashing or oopsing the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:41.793Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8ded74c654a982dc8581a17b0caa7fcedb20de69"
},
{
"url": "https://git.kernel.org/stable/c/c9c38066b6446e83668c041702bb639b0ca49363"
},
{
"url": "https://git.kernel.org/stable/c/094734c7aaa2b36751dc32480a680a4952685e78"
},
{
"url": "https://git.kernel.org/stable/c/33878ba25e2638bc0c61623d7a05c9ca2b74c039"
},
{
"url": "https://git.kernel.org/stable/c/404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2"
},
{
"url": "https://git.kernel.org/stable/c/5e1b2ca6b34939e70fb0785e8222b53cf060016f"
},
{
"url": "https://git.kernel.org/stable/c/f9fef131fa3f59b857217f522fa5ea430d1b707c"
},
{
"url": "https://git.kernel.org/stable/c/a2d8d5647ed854e38f941741aea45b9eb15a6350"
}
],
"title": "btrfs: reject free space cache with more entries than pages",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64567",
"datePublished": "2026-08-05T08:08:06.015Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:41.793Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64551 (GCVE-0-2026-64551)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: validate STALE_COOKIE cause length before reading staleness
When an ERROR chunk with a STALE_COOKIE cause is received in the
COOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads the 4-byte Measure
of Staleness that follows the cause header:
err = (struct sctp_errhdr *)(chunk->skb->data);
stale = ntohl(*(__be32 *)((u8 *)err + sizeof(*err)));
err is the first cause in the chunk, not the STALE_COOKIE cause that
caused the dispatch, and nothing guarantees the staleness field is
present. sctp_walk_errors() only requires a cause to be as long as the
4-byte header, so for a STALE_COOKIE cause of length 4 the read runs
past the cause, and for a minimal ERROR chunk past skb->tail. The value
is echoed to the peer in the Cookie Preservative of the reply INIT,
leaking uninitialized memory.
sctp_sf_cookie_echoed_err() already walks to the STALE_COOKIE cause, so
check its length there and pass it to sctp_sf_do_5_2_6_stale(), which
reads that cause instead of the first one. A STALE_COOKIE cause too
short to hold the staleness field is discarded.
The read is reachable by any peer that can drive an association into
COOKIE_ECHOED, including an unprivileged process using a raw SCTP socket
in a user and network namespace.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6022da37786701df1fc5dd946a6dcba59d5473b1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "861f884f5471632c731cbbd612a1c072e391a624",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "588706ebaf8cdb4a4161602949eba365514b1db1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a257b41ddfe9e327b26581ad2777f04b23ac73f5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "08a8f2d13f703924316e9aeac863a88ef50990c7",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ebe0a55d954fa8da383b6192edb8f763dcb002d5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "bbd6b2ea966cf57b6ae095cf5a8dbc993cd197a0",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1cd23ca80784223fa2204e16203f754da4e821f8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate STALE_COOKIE cause length before reading staleness\n\nWhen an ERROR chunk with a STALE_COOKIE cause is received in the\nCOOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads the 4-byte Measure\nof Staleness that follows the cause header:\n\n\terr = (struct sctp_errhdr *)(chunk-\u003eskb-\u003edata);\n\tstale = ntohl(*(__be32 *)((u8 *)err + sizeof(*err)));\n\nerr is the first cause in the chunk, not the STALE_COOKIE cause that\ncaused the dispatch, and nothing guarantees the staleness field is\npresent. sctp_walk_errors() only requires a cause to be as long as the\n4-byte header, so for a STALE_COOKIE cause of length 4 the read runs\npast the cause, and for a minimal ERROR chunk past skb-\u003etail. The value\nis echoed to the peer in the Cookie Preservative of the reply INIT,\nleaking uninitialized memory.\n\nsctp_sf_cookie_echoed_err() already walks to the STALE_COOKIE cause, so\ncheck its length there and pass it to sctp_sf_do_5_2_6_stale(), which\nreads that cause instead of the first one. A STALE_COOKIE cause too\nshort to hold the staleness field is discarded.\n\nThe read is reachable by any peer that can drive an association into\nCOOKIE_ECHOED, including an unprivileged process using a raw SCTP socket\nin a user and network namespace."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code is in the SCTP receive-side state machine and is driven entirely by an attacker-crafted ERROR chunk arriving over the network; no local access is needed. Per kernel guidance, net/ stack bugs reachable via received packets (SCTP explicitly) are Network.\nAC:L - The attacker fully controls the trigger: acting as the SCTP peer it answers INIT with INIT-ACK to place the association in COOKIE_ECHOED, then sends a minimal ERROR chunk with a 4-byte STALE_COOKIE cause as the last chunk in the packet. There is no race, no memory-layout dependency, and the vtag needed is the one the victim itself advertised in its INIT.\nPR:N - SCTP association setup is unauthenticated; the only check is sctp_vtag_verify() against a tag the peer already received in the victim\u0027s INIT. The attacker needs no credentials or privileges on the target system.\nUI:N - No human user action is required \u2014 SCTP client daemons (SIGTRAN, Diameter, cluster transports) establish and retry associations automatically, and an on-path attacker can inject the ERROR into an in-progress handshake. In the local variant an unprivileged process creates both sides itself with no user involved.\nS:U - The out-of-bounds read and the resulting disclosure stay within the kernel\u0027s own security authority; no VM, sandbox, or IOMMU boundary is crossed.\nC:H - Uninitialized kernel memory past skb-\u003etail is read and then transmitted straight back to the attacker inside the reply INIT\u0027s Cookie Preservative parameter, and the attack can be repeated indefinitely to sample recycled network-buffer memory that may contain remnants of other connections\u0027 traffic. This is a remote, unauthenticated, repeatable kernel heap disclosure oracle, matching the C:H treatment given to the sibling SCTP uninit-read CVE-2026-53225.\nI:N - The bug is a pure read; nothing in kernel memory or in the victim\u0027s association state is modified. The only affected value is a protocol field in a packet sent to the attacker itself.\nA:H - The read runs past the end of the received packet data, a memory-safety violation whose target is not proven to remain inside the skb\u0027s allocation across all receive paths (GSO/frag_list segments, UDP-encapsulated and linearized skbs), so it can fault and oops; kernel guidance and the CNA\u0027s scoring of the equivalent SCTP out-of-bounds-read bug both treat this class as A:H."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:28.771Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6022da37786701df1fc5dd946a6dcba59d5473b1"
},
{
"url": "https://git.kernel.org/stable/c/861f884f5471632c731cbbd612a1c072e391a624"
},
{
"url": "https://git.kernel.org/stable/c/588706ebaf8cdb4a4161602949eba365514b1db1"
},
{
"url": "https://git.kernel.org/stable/c/a257b41ddfe9e327b26581ad2777f04b23ac73f5"
},
{
"url": "https://git.kernel.org/stable/c/08a8f2d13f703924316e9aeac863a88ef50990c7"
},
{
"url": "https://git.kernel.org/stable/c/ebe0a55d954fa8da383b6192edb8f763dcb002d5"
},
{
"url": "https://git.kernel.org/stable/c/bbd6b2ea966cf57b6ae095cf5a8dbc993cd197a0"
},
{
"url": "https://git.kernel.org/stable/c/1cd23ca80784223fa2204e16203f754da4e821f8"
}
],
"title": "sctp: validate STALE_COOKIE cause length before reading staleness",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64551",
"datePublished": "2026-07-27T20:10:40.012Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-08-17T04:57:28.771Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68204 (GCVE-0-2026-68204)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: vivid: check for vb2_is_busy() when toggling caps
The vivid_update_format_cap/out() functions must only be called if the
capture/output queue are not busy. But for the controls that select
the CROP/COMPOSE/SCALE capability that is not checked.
Only when streaming starts will they be set to 'grabbed' and it is
impossible to change the control, but between REQBUFS and STREAMON you
are still allowed to set these controls. Since vivid_update_format_cap/out
will change the format, this can cause unexpected results.
Besides adding these checks, also add a WARN_ON in
vivid_update_format_cap/out() if the queue is busy.
I'm 90% certain that this is the cause of this syzbot bug:
https://syzkaller.appspot.com/bug?extid=dac8f5eaa46837e97b89
But since we never have reproducers, it is hard to be certain. In any case,
these checks are needed regardless.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/test-drivers/vivid/vivid-ctrls.c",
"drivers/media/test-drivers/vivid/vivid-vid-cap.c",
"drivers/media/test-drivers/vivid/vivid-vid-out.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0a820f03727b509b887f3216a574062948761f34",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "bbc96bc75de0fcd9bb6ac48798b206e3b09ec865",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "6a5bc8aea111ccbca71ef2b9c868d5c81f2e89de",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "a9cd0e8fb0b21faaa71199d9d3feb305c18ff576",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "abaec6747304581f8d4a9936352fa10e13325f07",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "492c97cb50feaa60ccd7792d3d6b904ed8ec61bf",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "daf2d92669b4a659d805d88d811161c70cd325ee",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "c2d1a2130c93f6d758af58590b86b2254c7a1dec",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/test-drivers/vivid/vivid-ctrls.c",
"drivers/media/test-drivers/vivid/vivid-vid-cap.c",
"drivers/media/test-drivers/vivid/vivid-vid-out.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"lessThan": "3.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vivid: check for vb2_is_busy() when toggling caps\n\nThe vivid_update_format_cap/out() functions must only be called if the\ncapture/output queue are not busy. But for the controls that select\nthe CROP/COMPOSE/SCALE capability that is not checked.\n\nOnly when streaming starts will they be set to \u0027grabbed\u0027 and it is\nimpossible to change the control, but between REQBUFS and STREAMON you\nare still allowed to set these controls. Since vivid_update_format_cap/out\nwill change the format, this can cause unexpected results.\n\nBesides adding these checks, also add a WARN_ON in\nvivid_update_format_cap/out() if the queue is busy.\n\nI\u0027m 90% certain that this is the cause of this syzbot bug:\n\nhttps://syzkaller.appspot.com/bug?extid=dac8f5eaa46837e97b89\n\nBut since we never have reproducers, it is hard to be certain. In any case,\nthese checks are needed regardless."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached purely through local ioctls (VIDIOC_REQBUFS/PREPARE_BUF/S_EXT_CTRLS/STREAMON) on the /dev/videoN character device exposed by the vivid driver. There is no remote or network component.\nAC:L - The attacker fully controls both the initial buffer allocation size and the later geometry change, so the undersized-buffer overflow is produced deterministically by a fixed ioctl sequence with no race or memory-layout precondition.\nPR:L - No capability check exists on the V4L2 control or buffer ioctls; any process able to open /dev/videoN can trigger it, which on desktops/Android and container images with video devices bind-mounted means an ordinary unprivileged user (video group / logind ACL).\nUI:N - The entire sequence is performed by the attacking process itself against a device node it opens; no victim action or cooperation is needed.\nS:U - The corruption stays within the kernel\u0027s own memory and security authority; no VM, IOMMU or sandbox boundary is crossed by the overflow itself.\nC:H - The stale-geometry mismatch also drives out-of-bounds reads on the output path and lets adjacent kernel allocations be read back through the mmap\u0027ed plane, and the resulting heap corruption can be shaped into a broader kernel-memory disclosure primitive.\nI:H - The capture kthread writes a full frame using the enlarged geometry into a plane allocated for the smaller format, giving an out-of-bounds kernel write of attacker-chosen length and largely attacker-influenced (test-pattern) content, which is exploitable for kernel memory corruption.\nA:H - Overwriting memory past the vb2 plane reliably corrupts neighbouring allocations or hits a vmalloc guard page, producing KASAN splats, oopses and kernel panics; the post-fix WARN_ON also panics on panic_on_warn systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:23.943Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0a820f03727b509b887f3216a574062948761f34"
},
{
"url": "https://git.kernel.org/stable/c/bbc96bc75de0fcd9bb6ac48798b206e3b09ec865"
},
{
"url": "https://git.kernel.org/stable/c/6a5bc8aea111ccbca71ef2b9c868d5c81f2e89de"
},
{
"url": "https://git.kernel.org/stable/c/a9cd0e8fb0b21faaa71199d9d3feb305c18ff576"
},
{
"url": "https://git.kernel.org/stable/c/abaec6747304581f8d4a9936352fa10e13325f07"
},
{
"url": "https://git.kernel.org/stable/c/492c97cb50feaa60ccd7792d3d6b904ed8ec61bf"
},
{
"url": "https://git.kernel.org/stable/c/daf2d92669b4a659d805d88d811161c70cd325ee"
},
{
"url": "https://git.kernel.org/stable/c/c2d1a2130c93f6d758af58590b86b2254c7a1dec"
}
],
"title": "media: vivid: check for vb2_is_busy() when toggling caps",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68204",
"datePublished": "2026-08-10T12:00:23.311Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:23.943Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64358 (GCVE-0-2026-64358)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: mtk-jpeg: cancel workqueue on release for supported platforms only
Since a recent fix the mtk_jpeg_release function cancels any pending
or running work present in the driver workqueue using
cancel_work_sync function.
Currently, only the multicore based variants use this workqueue and they
have the jpeg_worker platform data field initialized with a workqueue
callback function. For the others, this field value remain NULL by
default.
The cancel_work_sync function is unconditionally called in
mtk_jpeg_release function, even for the variants that do not use the
workqueue. This call generates a WARN_ON print in __flush_work because
the workqueue callback function presence check fails in __flush_work
function (used by cancel_work_sync).
So, to avoid these warnings, call cancel_work_sync only if a workqueue
callback is defined in platform data.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2209fdae5c2f615930c9af1379c1cfca199ec5d8 Version: 0498b27a1542021d90269d58347501d4c3ccd84e Version: 26506a30e0e26d612f82a7bf0e395626968a44e6 Version: 34c519feef3e4fcff1078dc8bdb25fbbbd10303f Version: 34c519feef3e4fcff1078dc8bdb25fbbbd10303f Version: e78c39f720679fcf3a2eacd82725ec3ea2648301 Version: 6.6.140 ≤ Version: 6.12.86 ≤ Version: 6.18.27 ≤ Version: 7.0.4 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0fed0fc34ce734b4b8c2f6a467d38bddcb21dda9",
"status": "affected",
"version": "2209fdae5c2f615930c9af1379c1cfca199ec5d8",
"versionType": "git"
},
{
"lessThan": "ac0774961a6ea174a71d4ffa39966edafbf7662d",
"status": "affected",
"version": "0498b27a1542021d90269d58347501d4c3ccd84e",
"versionType": "git"
},
{
"lessThan": "973408ceab14555a8548b97c8cc7b54208c3f251",
"status": "affected",
"version": "26506a30e0e26d612f82a7bf0e395626968a44e6",
"versionType": "git"
},
{
"lessThan": "4c4b4af4a9f278da096f0dbdb6b59594701d29bf",
"status": "affected",
"version": "34c519feef3e4fcff1078dc8bdb25fbbbd10303f",
"versionType": "git"
},
{
"lessThan": "b1845a227fda37b2fe5327df3ca0015d7e290235",
"status": "affected",
"version": "34c519feef3e4fcff1078dc8bdb25fbbbd10303f",
"versionType": "git"
},
{
"status": "affected",
"version": "e78c39f720679fcf3a2eacd82725ec3ea2648301",
"versionType": "git"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThan": "6.12.96",
"status": "affected",
"version": "6.12.86",
"versionType": "semver"
},
{
"lessThan": "6.18.39",
"status": "affected",
"version": "6.18.27",
"versionType": "semver"
},
{
"lessThan": "7.1",
"status": "affected",
"version": "7.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"lessThan": "7.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.140",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.12.86",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.18.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mtk-jpeg: cancel workqueue on release for supported platforms only\n\nSince a recent fix the mtk_jpeg_release function cancels any pending\nor running work present in the driver workqueue using\ncancel_work_sync function.\nCurrently, only the multicore based variants use this workqueue and they\nhave the jpeg_worker platform data field initialized with a workqueue\ncallback function. For the others, this field value remain NULL by\ndefault.\nThe cancel_work_sync function is unconditionally called in\nmtk_jpeg_release function, even for the variants that do not use the\nworkqueue. This call generates a WARN_ON print in __flush_work because\nthe workqueue callback function presence check fails in __flush_work\nfunction (used by cancel_work_sync).\n\nSo, to avoid these warnings, call cancel_work_sync only if a workqueue\ncallback is defined in platform data."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:04.458Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0fed0fc34ce734b4b8c2f6a467d38bddcb21dda9"
},
{
"url": "https://git.kernel.org/stable/c/ac0774961a6ea174a71d4ffa39966edafbf7662d"
},
{
"url": "https://git.kernel.org/stable/c/973408ceab14555a8548b97c8cc7b54208c3f251"
},
{
"url": "https://git.kernel.org/stable/c/4c4b4af4a9f278da096f0dbdb6b59594701d29bf"
},
{
"url": "https://git.kernel.org/stable/c/b1845a227fda37b2fe5327df3ca0015d7e290235"
}
],
"title": "media: mtk-jpeg: cancel workqueue on release for supported platforms only",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64358",
"datePublished": "2026-07-25T08:50:15.303Z",
"dateReserved": "2026-07-19T15:36:31.782Z",
"dateUpdated": "2026-08-17T04:54:04.458Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63898 (GCVE-0-2026-63898)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-07-19 14:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: mct_u232: fix memory corruption with small endpoint
The driver overrides the maximum transfer size for a specific device
which only accepts 16 byte packets for its 32 byte bulk-out endpoint.
Make sure to never increase the maximum transfer size to prevent slab
corruption should a malicious device report a smaller endpoint max
packet size than expected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/mct_u232.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "94edbbc5fe00d03cfe1d4e690d7d2cd36317a935",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "bd2ddb3fe9052ad8703593bbec26ecc7ca92869e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "39e295a91e80f3b91f61c7ada2bde434dcaba20d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "90dbad14b109e5fdfb4934ff61e561d11ba3742d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6cb48f8890f9b2051d7c34823057296a536a31c5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d8fdf33d6fcfb90cbec26299baf2352c84b2d768",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "57f332af1745014cd7e40414814ffaa6bc7d3b5b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "915b36d701950503c4ea0f6e314b10868e59fce3",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/mct_u232.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: mct_u232: fix memory corruption with small endpoint\n\nThe driver overrides the maximum transfer size for a specific device\nwhich only accepts 16 byte packets for its 32 byte bulk-out endpoint.\n\nMake sure to never increase the maximum transfer size to prevent slab\ncorruption should a malicious device report a smaller endpoint max\npacket size than expected."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:55:07.452Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/94edbbc5fe00d03cfe1d4e690d7d2cd36317a935"
},
{
"url": "https://git.kernel.org/stable/c/bd2ddb3fe9052ad8703593bbec26ecc7ca92869e"
},
{
"url": "https://git.kernel.org/stable/c/39e295a91e80f3b91f61c7ada2bde434dcaba20d"
},
{
"url": "https://git.kernel.org/stable/c/90dbad14b109e5fdfb4934ff61e561d11ba3742d"
},
{
"url": "https://git.kernel.org/stable/c/6cb48f8890f9b2051d7c34823057296a536a31c5"
},
{
"url": "https://git.kernel.org/stable/c/d8fdf33d6fcfb90cbec26299baf2352c84b2d768"
},
{
"url": "https://git.kernel.org/stable/c/57f332af1745014cd7e40414814ffaa6bc7d3b5b"
},
{
"url": "https://git.kernel.org/stable/c/915b36d701950503c4ea0f6e314b10868e59fce3"
}
],
"title": "USB: serial: mct_u232: fix memory corruption with small endpoint",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63898",
"datePublished": "2026-07-19T14:55:07.452Z",
"dateReserved": "2026-07-19T07:54:57.019Z",
"dateUpdated": "2026-07-19T14:55:07.452Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68215 (GCVE-0-2026-68215)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: radio-si476x: Unregister v4l2_device on probe failure
si476x_radio_probe() registers radio->v4l2dev before allocating the V4L2
controls and before registering the video device. If any of those later
steps fails, probe returns through the exit label after freeing only the
control handler.
A failed probe does not call si476x_radio_remove(), so the
v4l2_device_unregister() there is not reached. This leaves the parent
device reference taken by v4l2_device_register() behind on the error path.
Unregister the V4L2 device in the probe error path after freeing the
controls.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/radio/radio-si476x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "828f8d2181aa09ff3d8b67e1d9c92d0dfc81026f",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "cac1c4f08cb2d8beaad16f7ddc7911f3711daa9f",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "7cf393f176317a126d71e88e4b6e25e83499b465",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "4ca9c9f12b1bc341a0a3bbbd2090fd182db53771",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "7ef9f1659404544a8dddd68842bafcb4a38197af",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "64cb15878b35e5574ff4f80a0b613a79e47867ba",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "730c235d7d2c80a401dac56b0f5066c889aa442d",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "436a693af04ffb889aaf87cb69ec1f2b21d3569c",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/radio/radio-si476x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: radio-si476x: Unregister v4l2_device on probe failure\n\nsi476x_radio_probe() registers radio-\u003ev4l2dev before allocating the V4L2\ncontrols and before registering the video device. If any of those later\nsteps fails, probe returns through the exit label after freeing only the\ncontrol handler.\n\nA failed probe does not call si476x_radio_remove(), so the\nv4l2_device_unregister() there is not reached. This leaves the parent\ndevice reference taken by v4l2_device_register() behind on the error path.\n\nUnregister the V4L2 device in the probe error path after freeing the\ncontrols."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:44.648Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/828f8d2181aa09ff3d8b67e1d9c92d0dfc81026f"
},
{
"url": "https://git.kernel.org/stable/c/cac1c4f08cb2d8beaad16f7ddc7911f3711daa9f"
},
{
"url": "https://git.kernel.org/stable/c/7cf393f176317a126d71e88e4b6e25e83499b465"
},
{
"url": "https://git.kernel.org/stable/c/4ca9c9f12b1bc341a0a3bbbd2090fd182db53771"
},
{
"url": "https://git.kernel.org/stable/c/7ef9f1659404544a8dddd68842bafcb4a38197af"
},
{
"url": "https://git.kernel.org/stable/c/64cb15878b35e5574ff4f80a0b613a79e47867ba"
},
{
"url": "https://git.kernel.org/stable/c/730c235d7d2c80a401dac56b0f5066c889aa442d"
},
{
"url": "https://git.kernel.org/stable/c/436a693af04ffb889aaf87cb69ec1f2b21d3569c"
}
],
"title": "media: radio-si476x: Unregister v4l2_device on probe failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68215",
"datePublished": "2026-08-10T12:00:34.560Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:44.648Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68444 (GCVE-0-2026-68444)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
ffa_partition_info_get() passes uuid_str directly to uuid_parse()
without a NULL check. When a caller passes NULL, uuid_parse() ->
__uuid_parse() -> uuid_is_valid() dereferences the pointer, causing
a kernel panic:
| Unable to handle kernel NULL pointer dereference at virtual address
| 0000000000000040
| pc : uuid_parse+0x40/0xac
| lr : ffa_partition_info_get+0x1c/0x94 [arm_ffa]
Add a NULL guard before uuid_parse() so a NULL argument returns
-ENODEV instead of crashing. Callers are expected to always supply
a valid partition UUID, so NULL is not a supported input.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/firmware/arm_ffa/driver.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7dfb020e3048411fbca91e9ad6174da9a2d3e2b3",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "ddf85f0c32e05baafbd9c3a44859858db90eec48",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "86f5ea90f73bb7154593bb96f3411e197f3d4fbe",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "7201e56e52d18abf4cd0a2fee45daf9dc08b5b97",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "996c5c19d5b5ac5b98a7b5a406b548305841c301",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "12a42c610e4432e7708cc48d607e5903fffe0aad",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/firmware/arm_ffa/driver.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()\n\nffa_partition_info_get() passes uuid_str directly to uuid_parse()\nwithout a NULL check. When a caller passes NULL, uuid_parse() -\u003e\n__uuid_parse() -\u003e uuid_is_valid() dereferences the pointer, causing\na kernel panic:\n\n | Unable to handle kernel NULL pointer dereference at virtual address\n | 0000000000000040\n | pc : uuid_parse+0x40/0xac\n | lr : ffa_partition_info_get+0x1c/0x94 [arm_ffa]\n\nAdd a NULL guard before uuid_parse() so a NULL argument returns\n-ENODEV instead of crashing. Callers are expected to always supply\na valid partition UUID, so NULL is not a supported input."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:38.125Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7dfb020e3048411fbca91e9ad6174da9a2d3e2b3"
},
{
"url": "https://git.kernel.org/stable/c/ddf85f0c32e05baafbd9c3a44859858db90eec48"
},
{
"url": "https://git.kernel.org/stable/c/86f5ea90f73bb7154593bb96f3411e197f3d4fbe"
},
{
"url": "https://git.kernel.org/stable/c/7201e56e52d18abf4cd0a2fee45daf9dc08b5b97"
},
{
"url": "https://git.kernel.org/stable/c/996c5c19d5b5ac5b98a7b5a406b548305841c301"
},
{
"url": "https://git.kernel.org/stable/c/12a42c610e4432e7708cc48d607e5903fffe0aad"
},
{
"url": "https://git.kernel.org/stable/c/8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8"
}
],
"title": "firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68444",
"datePublished": "2026-08-12T00:07:34.609Z",
"dateReserved": "2026-07-30T09:28:09.394Z",
"dateUpdated": "2026-08-19T16:35:38.125Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68339 (GCVE-0-2026-68339)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btusb: validate Realtek vendor event length
btusb_recv_event_realtek() reads the event code at data[0] and the Realtek
subevent code at data[2] before deciding whether to consume a vendor event
as a coredump.
For example, the two-byte event ff 00 contains a complete vendor-event
header declaring zero parameters. The old classifier still reads a
nonexistent third byte and can misclassify the event as a coredump if the
adjacent byte is 0x34.
Require the HCI event header and first parameter to be present before
inspecting the Realtek subevent code. Short events continue through the
normal HCI receive path, which owns their protocol validation.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8de58bfa26e028f99271dde5a92107cd07f5e063",
"status": "affected",
"version": "044014ce85a17c0b7fab8e5df0925792010c29b2",
"versionType": "git"
},
{
"lessThan": "400267bab0f4076088e163e58cad2bb41c3cf5e7",
"status": "affected",
"version": "044014ce85a17c0b7fab8e5df0925792010c29b2",
"versionType": "git"
},
{
"lessThan": "8881daaafadbe7fb2b7341d16a3949114409c90c",
"status": "affected",
"version": "044014ce85a17c0b7fab8e5df0925792010c29b2",
"versionType": "git"
},
{
"lessThan": "24b0758193d70da47ef8b979153d2a181dbdf34e",
"status": "affected",
"version": "044014ce85a17c0b7fab8e5df0925792010c29b2",
"versionType": "git"
},
{
"lessThan": "df541cd485ff80a5ddc579d99687bc7506df9851",
"status": "affected",
"version": "044014ce85a17c0b7fab8e5df0925792010c29b2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: validate Realtek vendor event length\n\nbtusb_recv_event_realtek() reads the event code at data[0] and the Realtek\nsubevent code at data[2] before deciding whether to consume a vendor event\nas a coredump.\n\nFor example, the two-byte event ff 00 contains a complete vendor-event\nheader declaring zero parameters. The old classifier still reads a\nnonexistent third byte and can misclassify the event as a coredump if the\nadjacent byte is 0x34.\n\nRequire the HCI event header and first parameter to be present before\ninspecting the Realtek subevent code. Short events continue through the\nnormal HCI receive path, which owns their protocol validation."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:38.589Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8de58bfa26e028f99271dde5a92107cd07f5e063"
},
{
"url": "https://git.kernel.org/stable/c/400267bab0f4076088e163e58cad2bb41c3cf5e7"
},
{
"url": "https://git.kernel.org/stable/c/8881daaafadbe7fb2b7341d16a3949114409c90c"
},
{
"url": "https://git.kernel.org/stable/c/24b0758193d70da47ef8b979153d2a181dbdf34e"
},
{
"url": "https://git.kernel.org/stable/c/df541cd485ff80a5ddc579d99687bc7506df9851"
}
],
"title": "Bluetooth: btusb: validate Realtek vendor event length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68339",
"datePublished": "2026-08-10T12:03:15.551Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-17T05:03:38.589Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72308 (GCVE-0-2026-72308)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
When mlxsw_sp_port_lag_index_get() fails, mlxsw_sp_port_lag_join()
returns an error without releasing the lag reference obtained by
the earlier mlxsw_sp_lag_get(). All other error paths in the
function jump to the cleanup label that ends with
mlxsw_sp_lag_put(), so this is a single missed release.
Fix the leak by replacing the bare 'return err' with a goto to the
existing error cleanup label, which will drop the reference safely.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlxsw/spectrum.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3fbeaa8ecd144ad593f9fa1ab4b40a780ad3700b",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "99ff5b0083eae6f774360c4ea6874604e6c9b553",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "9bf2d6eea26a226f8ebab7baea6f2b018f914560",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "8b3350eacd9df0597bfe36a594df7b9def0b3edf",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "1cf8a1af42b1f12a30b7abd34fe4fc23b3170e7e",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "2d8b3c3e129973a51ae924bdcf6993a76b828814",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "cab468c3c03f4bcd7530ce2783a4140da14efb7b",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "41c8c1d65b32beacd8d916a22457b4f6e47f45af",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlxsw/spectrum.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: fix refcount leak in mlxsw_sp_port_lag_join()\n\nWhen mlxsw_sp_port_lag_index_get() fails, mlxsw_sp_port_lag_join()\nreturns an error without releasing the lag reference obtained by\nthe earlier mlxsw_sp_lag_get(). All other error paths in the\nfunction jump to the cleanup label that ends with\nmlxsw_sp_lag_put(), so this is a single missed release.\n\nFix the leak by replacing the bare \u0027return err\u0027 with a goto to the\nexisting error cleanup label, which will drop the reference safely."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:14.564Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3fbeaa8ecd144ad593f9fa1ab4b40a780ad3700b"
},
{
"url": "https://git.kernel.org/stable/c/99ff5b0083eae6f774360c4ea6874604e6c9b553"
},
{
"url": "https://git.kernel.org/stable/c/9bf2d6eea26a226f8ebab7baea6f2b018f914560"
},
{
"url": "https://git.kernel.org/stable/c/8b3350eacd9df0597bfe36a594df7b9def0b3edf"
},
{
"url": "https://git.kernel.org/stable/c/1cf8a1af42b1f12a30b7abd34fe4fc23b3170e7e"
},
{
"url": "https://git.kernel.org/stable/c/2d8b3c3e129973a51ae924bdcf6993a76b828814"
},
{
"url": "https://git.kernel.org/stable/c/cab468c3c03f4bcd7530ce2783a4140da14efb7b"
},
{
"url": "https://git.kernel.org/stable/c/41c8c1d65b32beacd8d916a22457b4f6e47f45af"
}
],
"title": "mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72308",
"datePublished": "2026-08-15T05:55:25.260Z",
"dateReserved": "2026-08-09T03:40:39.918Z",
"dateUpdated": "2026-08-23T12:47:14.564Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68104 (GCVE-0-2026-68104)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
Call pm_genpd_remove() to unregister from global list prior to releasing
acp_genpd memory, and clear the pointer after free.
(cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4d7c10b0bf09d90c81818752decbdb1966b62702",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "493adf29d66f23888f0e29888b6bc9512acd0825",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "2e406b86144c1f732eb344f1f1e09043856cfc33",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "bdfc7f1e0900ef1361b828c4f69b72701f8a0a86",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "5c0a82283271759fff445ac27182072f200a888c",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "08fee493e0261f9e4120a5c8e7e42e8a723574e8",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "930a5dc3df4aa5e10393134bd5313d616dbebaf6",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "28c9b3c5dc35cc790d11e26ca3fc6e068be63998",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: invoke pm_genpd_remove() before freeing genpd\n\nCall pm_genpd_remove() to unregister from global list prior to releasing\nacp_genpd memory, and clear the pointer after free.\n\n(cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in acp_hw_fini during amdgpu driver teardown (amdgpu_pci_remove/amdgpu_driver_unload_kms), reachable via local PCI unbind/module unload or a failed amdgpu init cleanup after opening a DRM render node; there is no network-facing entry point.\nAC:L - Once the AMDGPU ACP block has been initialized, calling acp_hw_fini deterministically frees acp_genpd without unregistering it from the global genpd list; no race or special memory layout is required to leave a dangling list entry.\nPR:L - Unprivileged users with access to /dev/dri/renderD* can autoload amdgpu and trigger the fini path if initialization fails after ACP setup; the same bug also fires on privileged driver unload/hot-unplug teardown of AMDGPU on ACP-capable APUs (Carrizo/Stoney).\nUI:N - Exploitation does not require any victim interaction such as clicking links or mounting filesystems; triggering driver teardown or a failed init cleanup is sufficient once the attacker can open the DRM device or unload the driver.\nS:U - The use-after-free corrupts kernel heap metadata/objects in the same kernel security domain during AMDGPU/ACP teardown; it does not by itself cross VM, container, or IOMMU boundaries to impact a separate authority.\nC:H - Freeing the generic_pm_domain while it remains linked on the global gpd_list is a kernel use-after-free; subsequent genpd list walks can read attacker-influenced freed memory, enabling information disclosure and kernel pointer leaks.\nI:H - The dangling genpd entry allows the power-domain core to perform reads/writes through a freed acp_pm_domain/generic_pm_domain object, providing a standard heap UAF primitive that can be developed into arbitrary kernel memory corruption or code execution.\nA:H - Dereferencing the freed genpd from the global list during later power-management operations can cause kernel oops/panic or hang, and the UAF can be leveraged for a reliable denial-of-service even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:17.502Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4d7c10b0bf09d90c81818752decbdb1966b62702"
},
{
"url": "https://git.kernel.org/stable/c/493adf29d66f23888f0e29888b6bc9512acd0825"
},
{
"url": "https://git.kernel.org/stable/c/2e406b86144c1f732eb344f1f1e09043856cfc33"
},
{
"url": "https://git.kernel.org/stable/c/bdfc7f1e0900ef1361b828c4f69b72701f8a0a86"
},
{
"url": "https://git.kernel.org/stable/c/5c0a82283271759fff445ac27182072f200a888c"
},
{
"url": "https://git.kernel.org/stable/c/08fee493e0261f9e4120a5c8e7e42e8a723574e8"
},
{
"url": "https://git.kernel.org/stable/c/930a5dc3df4aa5e10393134bd5313d616dbebaf6"
},
{
"url": "https://git.kernel.org/stable/c/28c9b3c5dc35cc790d11e26ca3fc6e068be63998"
}
],
"title": "drm/amdgpu: invoke pm_genpd_remove() before freeing genpd",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68104",
"datePublished": "2026-08-10T11:58:20.614Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:17.502Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64011 (GCVE-0-2026-64011)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: Fix use-after-free in llcp_sock_release()
llcp_sock_release() unconditionally unlinks the socket from the local
sockets list. However, if the socket is still in connecting state, it
is on the connecting list.
Fix this by checking the socket state and unlinking from the correct list.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b4011239a08e7e6c2c6e970dfa9e8ecb73139261 Version: b4011239a08e7e6c2c6e970dfa9e8ecb73139261 Version: b4011239a08e7e6c2c6e970dfa9e8ecb73139261 Version: b4011239a08e7e6c2c6e970dfa9e8ecb73139261 Version: b4011239a08e7e6c2c6e970dfa9e8ecb73139261 Version: b4011239a08e7e6c2c6e970dfa9e8ecb73139261 Version: b4011239a08e7e6c2c6e970dfa9e8ecb73139261 Version: b4011239a08e7e6c2c6e970dfa9e8ecb73139261 Version: da989ee1c7702050741a551df6866cc1588f277b Version: 3.10.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "89ba026747019ee643d29407435ddc118e6ca908",
"status": "affected",
"version": "b4011239a08e7e6c2c6e970dfa9e8ecb73139261",
"versionType": "git"
},
{
"lessThan": "fb29f6bbe433f3decad227588809636c25f2a287",
"status": "affected",
"version": "b4011239a08e7e6c2c6e970dfa9e8ecb73139261",
"versionType": "git"
},
{
"lessThan": "2dfdaaf7d933b676124aadec6698825e95f94fe9",
"status": "affected",
"version": "b4011239a08e7e6c2c6e970dfa9e8ecb73139261",
"versionType": "git"
},
{
"lessThan": "e00f50f8697724a6f1d2d35744c1332c9912dac5",
"status": "affected",
"version": "b4011239a08e7e6c2c6e970dfa9e8ecb73139261",
"versionType": "git"
},
{
"lessThan": "cdc17e09a636c7f936f771902535a7515a7608fc",
"status": "affected",
"version": "b4011239a08e7e6c2c6e970dfa9e8ecb73139261",
"versionType": "git"
},
{
"lessThan": "912ebc49d4406a17fe73e5671d674fbc2f6b2634",
"status": "affected",
"version": "b4011239a08e7e6c2c6e970dfa9e8ecb73139261",
"versionType": "git"
},
{
"lessThan": "bc421d0826dedbba37580a25405eafb599e76d42",
"status": "affected",
"version": "b4011239a08e7e6c2c6e970dfa9e8ecb73139261",
"versionType": "git"
},
{
"lessThan": "f4268b466190dae95a7585f69b4f1f8ad097632c",
"status": "affected",
"version": "b4011239a08e7e6c2c6e970dfa9e8ecb73139261",
"versionType": "git"
},
{
"status": "affected",
"version": "da989ee1c7702050741a551df6866cc1588f277b",
"versionType": "git"
},
{
"lessThan": "3.11",
"status": "affected",
"version": "3.10.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.11"
},
{
"lessThan": "3.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.10.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: Fix use-after-free in llcp_sock_release()\n\nllcp_sock_release() unconditionally unlinks the socket from the local\nsockets list. However, if the socket is still in connecting state, it\nis on the connecting list.\n\nFix this by checking the socket state and unlinking from the correct list."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is triggered in llcp_sock_release() via the local close(2) syscall on an AF_NFC LLCP socket left in LLCP_CONNECTING after a non-blocking connect(); no remote network protocol reaches this unlink path directly.\nAC:L - An attacker fully controls the race by opening an LLCP socket, calling connect() with O_NONBLOCK, and immediately closing it; no privileged setup or uncontrollable memory-layout conditions are required beyond an active NFC DEP link.\nPR:L - SOCK_STREAM/SOCK_DGRAM LLCP sockets require no capability checks at creation or release (only SOCK_RAW needs CAP_NET_RAW), so any unprivileged local process in init_net can reach the vulnerable close() path once an NFC DEP session is up.\nUI:N - Exploitation requires only programmatic socket connect/close calls from a malicious local process; no victim user action (such as tapping, mounting, or opening a file) is needed at exploit time if an NFC link is already established.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security boundary and can lead to local privilege escalation, not a cross-boundary escape such as VM or sandbox breakout.\nC:H - This is a kernel heap use-after-free of struct nfc_llcp_sock; freed socket objects can be reallocated and read through subsequent list lookups or concurrent recv_cc()/recv_dm() processing, enabling arbitrary kernel memory disclosure.\nI:H - A use-after-free on a socket structure embedded in struct sock provides standard kernel heap-spray primitives that can be leveraged for arbitrary write and local privilege escalation via control-flow hijacking.\nA:H - The use-after-free can cause immediate kernel oops/panic during concurrent list traversal or socket teardown, and successful exploitation yields full kernel compromise with total system unavailability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:11.263Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/89ba026747019ee643d29407435ddc118e6ca908"
},
{
"url": "https://git.kernel.org/stable/c/fb29f6bbe433f3decad227588809636c25f2a287"
},
{
"url": "https://git.kernel.org/stable/c/2dfdaaf7d933b676124aadec6698825e95f94fe9"
},
{
"url": "https://git.kernel.org/stable/c/e00f50f8697724a6f1d2d35744c1332c9912dac5"
},
{
"url": "https://git.kernel.org/stable/c/cdc17e09a636c7f936f771902535a7515a7608fc"
},
{
"url": "https://git.kernel.org/stable/c/912ebc49d4406a17fe73e5671d674fbc2f6b2634"
},
{
"url": "https://git.kernel.org/stable/c/bc421d0826dedbba37580a25405eafb599e76d42"
},
{
"url": "https://git.kernel.org/stable/c/f4268b466190dae95a7585f69b4f1f8ad097632c"
}
],
"title": "nfc: llcp: Fix use-after-free in llcp_sock_release()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64011",
"datePublished": "2026-07-19T14:56:25.901Z",
"dateReserved": "2026-07-19T07:54:57.027Z",
"dateUpdated": "2026-08-05T12:38:11.263Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64113 (GCVE-0-2026-64113)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ixgbevf: fix use-after-free in VEPA multicast source pruning
ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's
own address (VEPA multicast workaround) by freeing the skb and
continuing to the next descriptor:
dev_kfree_skb_irq(skb);
continue;
The skb pointer is declared outside the while loop and persists across
iterations. Because the continue skips the "skb = NULL" reset at the
bottom of the loop, the next iteration enters the "else if (skb)" path
and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing
skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context.
The sibling driver iavf already handles this correctly by nulling the
pointer before continuing. Apply the same pattern here.
I do not have ixgbevf hardware; the bug was found by static analysis
(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool
corroboration with the highest score in the scan). The UAF was confirmed
under KASAN by loading a test module that reproduces the exact code
pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags):
BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000
Read of size 8 at addr 000000006163ae78 by task insmod/30
freed 208-byte region [000000006163adc0, 000000006163ae90)
QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF
driver does not include the VEPA source pruning path, so a full
end-to-end reproduction with emulated hardware was not possible.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bad17234ba702a50aeec50ab04724ee58af89607 Version: bad17234ba702a50aeec50ab04724ee58af89607 Version: bad17234ba702a50aeec50ab04724ee58af89607 Version: bad17234ba702a50aeec50ab04724ee58af89607 Version: bad17234ba702a50aeec50ab04724ee58af89607 Version: bad17234ba702a50aeec50ab04724ee58af89607 Version: bad17234ba702a50aeec50ab04724ee58af89607 Version: bad17234ba702a50aeec50ab04724ee58af89607 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/ixgbevf/ixgbevf_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb",
"status": "affected",
"version": "bad17234ba702a50aeec50ab04724ee58af89607",
"versionType": "git"
},
{
"lessThan": "6ef30384a50a50e4a484cddf341bc27de31aa3de",
"status": "affected",
"version": "bad17234ba702a50aeec50ab04724ee58af89607",
"versionType": "git"
},
{
"lessThan": "55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1",
"status": "affected",
"version": "bad17234ba702a50aeec50ab04724ee58af89607",
"versionType": "git"
},
{
"lessThan": "add70e2682c0ad3be2a5810bcf1bc13963ba4df9",
"status": "affected",
"version": "bad17234ba702a50aeec50ab04724ee58af89607",
"versionType": "git"
},
{
"lessThan": "a244395d8c563ed1bb26c3ef708db6aeeaa08084",
"status": "affected",
"version": "bad17234ba702a50aeec50ab04724ee58af89607",
"versionType": "git"
},
{
"lessThan": "dfef79e09ed2f5df975c98547f97f5d7f8982a24",
"status": "affected",
"version": "bad17234ba702a50aeec50ab04724ee58af89607",
"versionType": "git"
},
{
"lessThan": "e8768bcbe5cd30c4ea36a22022c9ffaa66903693",
"status": "affected",
"version": "bad17234ba702a50aeec50ab04724ee58af89607",
"versionType": "git"
},
{
"lessThan": "5d49b568c188dc77199d8d2b959c91da8cc27cf1",
"status": "affected",
"version": "bad17234ba702a50aeec50ab04724ee58af89607",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/ixgbevf/ixgbevf_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nixgbevf: fix use-after-free in VEPA multicast source pruning\n\nixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF\u0027s\nown address (VEPA multicast workaround) by freeing the skb and\ncontinuing to the next descriptor:\n\n dev_kfree_skb_irq(skb);\n continue;\n\nThe skb pointer is declared outside the while loop and persists across\niterations. Because the continue skips the \"skb = NULL\" reset at the\nbottom of the loop, the next iteration enters the \"else if (skb)\" path\nand calls ixgbevf_add_rx_frag() on the freed skb, dereferencing\nskb_shinfo(skb)-\u003enr_frags - a use-after-free in NAPI softirq context.\n\nThe sibling driver iavf already handles this correctly by nulling the\npointer before continuing. Apply the same pattern here.\n\nI do not have ixgbevf hardware; the bug was found by static analysis\n(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool\ncorroboration with the highest score in the scan). The UAF was confirmed\nunder KASAN by loading a test module that reproduces the exact code\npattern (alloc skb, kfree_skb, then read skb_shinfo(skb)-\u003enr_frags):\n\n BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000\n Read of size 8 at addr 000000006163ae78 by task insmod/30\n freed 208-byte region [000000006163adc0, 000000006163ae90)\n\nQEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF\ndriver does not include the VEPA source pruning path, so a full\nend-to-end reproduction with emulated hardware was not possible."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in the ixgbevf NAPI receive path triggered by incoming Ethernet frames delivered by the VF hardware; per kernel guidance, driver bugs reachable via received packets are scored as Network.\nAC:L - An attacker can reliably trigger the bug by sending a VEPA-reflected multicast/broadcast frame whose source MAC matches the VF address, then immediately sending a follow-on frame so the next loop iteration reuses the freed skb pointer in the same NAPI poll.\nPR:N - Exploitation requires only the ability to inject crafted L2 frames at the VF (e.g., a co-tenant VM on the same VLAN/cloud segment); no local account or capabilities on the victim system are needed.\nUI:N - No victim user action is required; the UAF occurs automatically during softirq packet processing once the crafted frames are received.\nS:U - Impact is kernel memory corruption within the same privilege domain (guest or host kernel running the VF driver), not a cross-VM/host security-boundary escape.\nC:H - The UAF reads freed slab memory via `skb_shinfo(skb)-\u003enr_frags` in `ixgbevf_add_rx_frag()`, which KASAN confirmed and which can be leveraged for arbitrary kernel memory disclosure.\nI:H - The same UAF path writes into the freed skb through `skb_add_rx_frag()` (fragment metadata, lengths), enabling heap corruption and potential control-flow hijack.\nA:H - Use-after-free in NAPI softirq context can cause kernel oops/panic during receive processing even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:22.189Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb"
},
{
"url": "https://git.kernel.org/stable/c/6ef30384a50a50e4a484cddf341bc27de31aa3de"
},
{
"url": "https://git.kernel.org/stable/c/55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1"
},
{
"url": "https://git.kernel.org/stable/c/add70e2682c0ad3be2a5810bcf1bc13963ba4df9"
},
{
"url": "https://git.kernel.org/stable/c/a244395d8c563ed1bb26c3ef708db6aeeaa08084"
},
{
"url": "https://git.kernel.org/stable/c/dfef79e09ed2f5df975c98547f97f5d7f8982a24"
},
{
"url": "https://git.kernel.org/stable/c/e8768bcbe5cd30c4ea36a22022c9ffaa66903693"
},
{
"url": "https://git.kernel.org/stable/c/5d49b568c188dc77199d8d2b959c91da8cc27cf1"
}
],
"title": "ixgbevf: fix use-after-free in VEPA multicast source pruning",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64113",
"datePublished": "2026-07-19T15:40:14.251Z",
"dateReserved": "2026-07-19T07:54:57.035Z",
"dateUpdated": "2026-08-05T12:39:22.189Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68322 (GCVE-0-2026-68322)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
When booting with the 'ipv6.disable=1' parameter, inet6_addr_lst
is never initialized because inet6_init() exits before addrconf_init()
is called to initialize it. An attempt to bind an RDS socket to
an ipv6 address results in a crash in __ipv6_chk_addr_and_flags()
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
RIP: 0010:__ipv6_chk_addr_and_flags+0x1df/0x7e0
Call Trace:
<TASK>
ipv6_chk_addr+0x3b/0x50
rds_tcp_laddr_check+0x155/0x3b0 [rds_tcp]
rds_trans_get_preferred+0x15d/0x2d0 [rds]
? trace_hardirqs_on+0x2d/0x110
rds_bind+0x1433/0x1d60 [rds]
? rds_remove_bound+0xd50/0xd50 [rds]
? aa_af_perm+0x250/0x250
? __might_fault+0xde/0x190
? __sys_bind+0x1dc/0x210
__sys_bind+0x1dc/0x210
? __ia32_sys_socketpair+0x100/0x100
? restore_fpregs_from_fpstate+0x53/0x100
__x64_sys_bind+0x73/0xb0
? syscall_enter_from_user_mode+0x1c/0x50
do_syscall_64+0x34/0x80
entry_SYSCALL_64_after_hwframe+0x6e/0xd8
RIP: 0033:0x7f47f8269ea9
</TASK>
The following code reproduces the issue:
struct sockaddr_in6 addr;
s = socket(PF_RDS, SOCK_SEQPACKET, 0);
memset(&addr, 0, sizeof(addr));
inet_pton(AF_INET6, ADDRESS, &addr.sin6_addr);
addr.sin6_family = AF_INET6;
addr.sin6_port = htons(PORT);
bind(s, &addr, sizeof(addr));
Found by InfoTeCS on behalf of Linux Verification Center
(linuxtesting.org) with Syzkaller.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rds/ib.c",
"net/rds/ib_cm.c",
"net/rds/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7809344be3f0c1bbfdfdde1cefafeec14bf52d51",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "438dec9b0a06bd1f8db8c58539c655e735e17367",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "b61c9eb5931bb7389bc104faacd8c17d910da65d",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "8e48d7ab1e01936a172ff31531904b003895fd8c",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "a8302e758050e6a922765aee8d220a4fd350f52d",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "f6787fdffcae5490c779f0f3f33b11597525d1ae",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "00d5707217b5972554898ff734ae7b71bce704e6",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "9c805e592a29be9e4e61ff1bd567da04aa8fd6f9",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rds/ib.c",
"net/rds/ib_cm.c",
"net/rds/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled\n\nWhen booting with the \u0027ipv6.disable=1\u0027 parameter, inet6_addr_lst\nis never initialized because inet6_init() exits before addrconf_init()\nis called to initialize it. An attempt to bind an RDS socket to\nan ipv6 address results in a crash in __ipv6_chk_addr_and_flags()\n\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nRIP: 0010:__ipv6_chk_addr_and_flags+0x1df/0x7e0\nCall Trace:\n \u003cTASK\u003e\n ipv6_chk_addr+0x3b/0x50\n rds_tcp_laddr_check+0x155/0x3b0 [rds_tcp]\n rds_trans_get_preferred+0x15d/0x2d0 [rds]\n ? trace_hardirqs_on+0x2d/0x110\n rds_bind+0x1433/0x1d60 [rds]\n ? rds_remove_bound+0xd50/0xd50 [rds]\n ? aa_af_perm+0x250/0x250\n ? __might_fault+0xde/0x190\n ? __sys_bind+0x1dc/0x210\n __sys_bind+0x1dc/0x210\n ? __ia32_sys_socketpair+0x100/0x100\n ? restore_fpregs_from_fpstate+0x53/0x100\n __x64_sys_bind+0x73/0xb0\n ? syscall_enter_from_user_mode+0x1c/0x50\n do_syscall_64+0x34/0x80\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\nRIP: 0033:0x7f47f8269ea9\n \u003c/TASK\u003e\n\nThe following code reproduces the issue:\n\nstruct sockaddr_in6 addr;\ns = socket(PF_RDS, SOCK_SEQPACKET, 0);\n\nmemset(\u0026addr, 0, sizeof(addr));\ninet_pton(AF_INET6, ADDRESS, \u0026addr.sin6_addr);\naddr.sin6_family = AF_INET6;\naddr.sin6_port = htons(PORT);\n\nbind(s, \u0026addr, sizeof(addr));\n\nFound by InfoTeCS on behalf of Linux Verification Center\n(linuxtesting.org) with Syzkaller."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:12.816Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7809344be3f0c1bbfdfdde1cefafeec14bf52d51"
},
{
"url": "https://git.kernel.org/stable/c/438dec9b0a06bd1f8db8c58539c655e735e17367"
},
{
"url": "https://git.kernel.org/stable/c/b61c9eb5931bb7389bc104faacd8c17d910da65d"
},
{
"url": "https://git.kernel.org/stable/c/8e48d7ab1e01936a172ff31531904b003895fd8c"
},
{
"url": "https://git.kernel.org/stable/c/a8302e758050e6a922765aee8d220a4fd350f52d"
},
{
"url": "https://git.kernel.org/stable/c/f6787fdffcae5490c779f0f3f33b11597525d1ae"
},
{
"url": "https://git.kernel.org/stable/c/00d5707217b5972554898ff734ae7b71bce704e6"
},
{
"url": "https://git.kernel.org/stable/c/9c805e592a29be9e4e61ff1bd567da04aa8fd6f9"
}
],
"title": "rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68322",
"datePublished": "2026-08-10T12:02:57.499Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:12.816Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74516 (GCVE-0-2026-74516)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
Always update x2APIC MSR intercepts for L1 when AVIC is deactivated, even
if L2 is active and KVM is using a separate MSR bitmap to run L2. If AVIC
is fully enabled prior to running L2, and is then inhibited while L2 is
active (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled,
but with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of
the host's APIC state, send arbitrary interrupts, change task priority, and
ultimately trivially DoS the host.
E.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with
CONFIG_HYPERV=n in the host kernel as a "safe" PoC, yields:
Spurious interrupt (vector 0xee) on CPU#425. Acked
And hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a
handler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:
------------[ cut here ]------------
WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940
CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S U
Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER
Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026
RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]
Call Trace:
<IRQ>
sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80
</IRQ>
<TASK>
asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20
RIP: 0010:vcpu_run+0x1430/0x1e40 [kvm]
kvm_arch_vcpu_ioctl_run+0x2c1/0x600 [kvm]
kvm_vcpu_ioctl+0x580/0x6b0 [kvm]
__se_sys_ioctl+0x6d/0xb0
do_syscall_64+0x10a/0x480
entry_SYSCALL_64_after_hwframe+0x4b/0x53
RIP: 0033:0x46ff4b
</TASK>
---[ end trace 0000000000000000 ]---
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 091abbf578f926e763adc0f577baeb7f405b4bdc Version: 091abbf578f926e763adc0f577baeb7f405b4bdc Version: 091abbf578f926e763adc0f577baeb7f405b4bdc Version: 091abbf578f926e763adc0f577baeb7f405b4bdc Version: 091abbf578f926e763adc0f577baeb7f405b4bdc Version: 091abbf578f926e763adc0f577baeb7f405b4bdc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/avic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4ca05385b3ddbd463be17c6d69ec76fca657081d",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
},
{
"lessThan": "6664a5aea45318f4ec156a729949b474dd6e3159",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
},
{
"lessThan": "f12373625b4dc9bcc89c41872648878c73bb9272",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
},
{
"lessThan": "7668c58dcf465559dc7a0d2e95e9cb79cf47454b",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
},
{
"lessThan": "89f9e8398e79c49886766fc24a84c37726231104",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
},
{
"lessThan": "7d3aae206663c4e006b25a1c7a20a4029e67da76",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/avic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active\n\nAlways update x2APIC MSR intercepts for L1 when AVIC is deactivated, even\nif L2 is active and KVM is using a separate MSR bitmap to run L2. If AVIC\nis fully enabled prior to running L2, and is then inhibited while L2 is\nactive (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled,\nbut with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of\nthe host\u0027s APIC state, send arbitrary interrupts, change task priority, and\nultimately trivially DoS the host.\n\nE.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with\nCONFIG_HYPERV=n in the host kernel as a \"safe\" PoC, yields:\n\n Spurious interrupt (vector 0xee) on CPU#425. Acked\n\nAnd hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a\nhandler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:\n\n ------------[ cut here ]------------\n WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940\n CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S U\n Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER\n Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026\n RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]\n Call Trace:\n \u003cIRQ\u003e\n sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80\n \u003c/IRQ\u003e\n \u003cTASK\u003e\n asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20\n RIP: 0010:vcpu_run+0x1430/0x1e40 [kvm]\n kvm_arch_vcpu_ioctl_run+0x2c1/0x600 [kvm]\n kvm_vcpu_ioctl+0x580/0x6b0 [kvm]\n __se_sys_ioctl+0x6d/0xb0\n do_syscall_64+0x10a/0x480\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n RIP: 0033:0x46ff4b\n \u003c/TASK\u003e\n ---[ end trace 0000000000000000 ]---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires triggering KVM nested SVM/AVIC paths via local /dev/kvm ioctls (KVM_CREATE_VM, KVM_CREATE_VCPU, KVM_RUN) from L1; there is no network, adjacent, or physical packet/device path to the vulnerable code.\nAC:L - An L1 attacker fully controls nested VM configuration (x2APIC, AVIC, L2 MSR bitmap, IRQ-window/ExtINT conditions) and can reliably reproduce AVIC inhibition while L2 is active without races or uncontrollable host state.\nPR:H - Reaching the bug requires running nested AMD KVM as L1 (nested virtualization enabled and control of a guest hypervisor), which is not available to an unprivileged host user or via user-namespace capabilities alone without delegated /dev/kvm access.\nUI:N - No victim interaction is required; exploitation is driven entirely by the attacker\u2019s nested hypervisor configuration and KVM_RUN operations once nested virtualization is available.\nS:C - The flaw lets an L1 nested guest hypervisor access the host\u2019s physical x2APIC MSRs, crossing the VM/host security boundary rather than staying within the guest\u2019s own security scope.\nC:H - With x2APIC MSR intercepts left disabled, L1 can read most of the host APIC state (IDs, IRR/ISR, timers, ICR), leaking sensitive host interrupt-controller information beyond the guest boundary.\nI:H - L1 can write host x2APIC MSRs to send arbitrary IPIs, change task priority, and invoke host interrupt vectors (e.g. posted-interrupt wakeup), enabling host integrity compromise beyond mere guest-local effects.\nA:H - Host availability is trivially impacted by injecting spurious or high-priority interrupts to host CPUs; the fix commit demonstrates host kernel warnings and spurious interrupt storms causing denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:16.902Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4ca05385b3ddbd463be17c6d69ec76fca657081d"
},
{
"url": "https://git.kernel.org/stable/c/6664a5aea45318f4ec156a729949b474dd6e3159"
},
{
"url": "https://git.kernel.org/stable/c/f12373625b4dc9bcc89c41872648878c73bb9272"
},
{
"url": "https://git.kernel.org/stable/c/7668c58dcf465559dc7a0d2e95e9cb79cf47454b"
},
{
"url": "https://git.kernel.org/stable/c/89f9e8398e79c49886766fc24a84c37726231104"
},
{
"url": "https://git.kernel.org/stable/c/7d3aae206663c4e006b25a1c7a20a4029e67da76"
}
],
"title": "KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74516",
"datePublished": "2026-08-15T12:27:36.200Z",
"dateReserved": "2026-08-15T05:44:03.910Z",
"dateUpdated": "2026-08-19T16:38:16.902Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64306 (GCVE-0-2026-64306)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: drbg - Fix returning success on failure in CTR_DRBG
drbg_ctr_generate() sometimes returns success when it fails, leaving the
output buffer uninitialized. Fix it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cde001e4c3c3625c60b68a83eb1f1c2572dee07a Version: cde001e4c3c3625c60b68a83eb1f1c2572dee07a Version: cde001e4c3c3625c60b68a83eb1f1c2572dee07a Version: cde001e4c3c3625c60b68a83eb1f1c2572dee07a Version: cde001e4c3c3625c60b68a83eb1f1c2572dee07a Version: cde001e4c3c3625c60b68a83eb1f1c2572dee07a Version: cde001e4c3c3625c60b68a83eb1f1c2572dee07a Version: cde001e4c3c3625c60b68a83eb1f1c2572dee07a Version: f60b0fa8bbddde66f1d197be07120264b555c84a Version: 3.12.44 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"crypto/drbg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "074db6db03a0aaa78f05ca9d4838053713796665",
"status": "affected",
"version": "cde001e4c3c3625c60b68a83eb1f1c2572dee07a",
"versionType": "git"
},
{
"lessThan": "7b03312491f9fe6ba4d60c4023e7e61d2d1fed96",
"status": "affected",
"version": "cde001e4c3c3625c60b68a83eb1f1c2572dee07a",
"versionType": "git"
},
{
"lessThan": "75597e8774f319152744d24e0683d9393540a951",
"status": "affected",
"version": "cde001e4c3c3625c60b68a83eb1f1c2572dee07a",
"versionType": "git"
},
{
"lessThan": "cc42fb40171c249bb859071d81b4eb007398a0bc",
"status": "affected",
"version": "cde001e4c3c3625c60b68a83eb1f1c2572dee07a",
"versionType": "git"
},
{
"lessThan": "bbbac12083eff489b35d848332f0dff311131344",
"status": "affected",
"version": "cde001e4c3c3625c60b68a83eb1f1c2572dee07a",
"versionType": "git"
},
{
"lessThan": "23b8b188cb32e5531d0f8d3af9506f8959cb369e",
"status": "affected",
"version": "cde001e4c3c3625c60b68a83eb1f1c2572dee07a",
"versionType": "git"
},
{
"lessThan": "a9e886f73dd717027028bb7e3bbca93601ecdfc7",
"status": "affected",
"version": "cde001e4c3c3625c60b68a83eb1f1c2572dee07a",
"versionType": "git"
},
{
"lessThan": "39a31ad9e2a5ed7e9c9c6f711dca96c8c8f5f26b",
"status": "affected",
"version": "cde001e4c3c3625c60b68a83eb1f1c2572dee07a",
"versionType": "git"
},
{
"status": "affected",
"version": "f60b0fa8bbddde66f1d197be07120264b555c84a",
"versionType": "git"
},
{
"lessThan": "3.13",
"status": "affected",
"version": "3.12.44",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"crypto/drbg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.12.44",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: drbg - Fix returning success on failure in CTR_DRBG\n\ndrbg_ctr_generate() sometimes returns success when it fails, leaving the\noutput buffer uninitialized. Fix it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:05.476Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/074db6db03a0aaa78f05ca9d4838053713796665"
},
{
"url": "https://git.kernel.org/stable/c/7b03312491f9fe6ba4d60c4023e7e61d2d1fed96"
},
{
"url": "https://git.kernel.org/stable/c/75597e8774f319152744d24e0683d9393540a951"
},
{
"url": "https://git.kernel.org/stable/c/cc42fb40171c249bb859071d81b4eb007398a0bc"
},
{
"url": "https://git.kernel.org/stable/c/bbbac12083eff489b35d848332f0dff311131344"
},
{
"url": "https://git.kernel.org/stable/c/23b8b188cb32e5531d0f8d3af9506f8959cb369e"
},
{
"url": "https://git.kernel.org/stable/c/a9e886f73dd717027028bb7e3bbca93601ecdfc7"
},
{
"url": "https://git.kernel.org/stable/c/39a31ad9e2a5ed7e9c9c6f711dca96c8c8f5f26b"
}
],
"title": "crypto: drbg - Fix returning success on failure in CTR_DRBG",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64306",
"datePublished": "2026-07-25T08:49:40.153Z",
"dateReserved": "2026-07-19T15:36:31.779Z",
"dateUpdated": "2026-08-17T04:53:05.476Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68261 (GCVE-0-2026-68261)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: fix error checking of pvr_vm_context_lookup()
Since pvr_vm_context_lookup() returns either NULL or a pointer, then stop
using IS_ERR() for checking the return value.
Using IS_ERR() leads to the kernel oops reported below. It can be
reproduced by passing an invalid VM context handle from userspace to the
DRM_IOCTL_PVR_CREATE_CONTEXT ioctl.
[ 92.733119] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000148
[ 92.742042] Mem abort info:
[ 92.744890] ESR = 0x0000000096000004
[ 92.748686] EC = 0x25: DABT (current EL), IL = 32 bits
[ 92.754020] SET = 0, FnV = 0
[ 92.757154] EA = 0, S1PTW = 0
[ 92.760337] FSC = 0x04: level 0 translation fault
[ 92.765243] Data abort info:
[ 92.768129] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000
[ 92.773626] CM = 0, WnR = 0, TnD = 0, TagAccess = 0
[ 92.778763] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
[ 92.784098] user pgtable: 4k pages, 48-bit VAs, pgdp=000000088ed23000
[ 92.790550] [0000000000000148] pgd=0000000000000000, p4d=0000000000000000
[ 92.797381] Internal error: Oops: 0000000096000004 [#1] SMP
[ 92.803027] Modules linked in: powervr
[ 92.852533] CPU: 0 UID: 0 PID: 409 Comm: triangle Not tainted 7.1.0-rc5-g98b46e693b91 #1 PREEMPT
[ 92.861385] Hardware name: Texas Instruments AM68 SK (DT)
[ 92.866766] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 92.873709] pc : pvr_vm_get_fw_mem_context+0x0/0xc [powervr]
[ 92.879376] lr : pvr_queue_create+0x26c/0x440 [powervr]
[ 92.884595] sp : ffff8000837fbb00
[ 92.887895] x29: ffff8000837fbb60 x28: 0000000000000000 x27: ffff8000837fbce8
[ 92.895015] x26: ffff000807f61a40 x25: ffff000807f61a00 x24: ffff000807f64400
[ 92.902135] x23: ffff00080a5ab000 x22: ffff800079b24730 x21: ffff000807f61800
[ 92.909254] x20: ffff00080999e680 x19: 0000000000000000 x18: 0000000000000000
[ 92.916373] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000001
[ 92.923492] x14: 0000000000000000 x13: 0000000000000002 x12: ffff80008145b298
[ 92.930611] x11: ffff8000844e5000 x10: ffff80008165a130 x9 : 0000000000000100
[ 92.937730] x8 : 0000000000000001 x7 : ffff0008076b27e0 x6 : ffff00080ec43b7c
[ 92.944850] x5 : ffff00080ec43b78 x4 : 0000000000000000 x3 : ffff00080999e680
[ 92.951968] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000
[ 92.959088] Call trace:
[ 92.961521] pvr_vm_get_fw_mem_context+0x0/0xc [powervr] (P)
[ 92.967173] pvr_context_create+0x190/0x410 [powervr]
[ 92.972218] pvr_ioctl_create_context+0x44/0x8c [powervr]
[ 92.977608] drm_ioctl_kernel+0xbc/0x124 [drm]
[ 92.982127] drm_ioctl+0x1f8/0x4dc [drm]
[ 92.986098] __arm64_sys_ioctl+0xac/0x104
[ 92.990102] invoke_syscall+0x54/0x10c
[ 92.993842] el0_svc_common.constprop.0+0x40/0xe0
[ 92.998532] do_el0_svc+0x1c/0x28
[ 93.001835] el0_svc+0x38/0x11c
[ 93.004969] el0t_64_sync_handler+0xa0/0xe4
[ 93.009139] el0t_64_sync+0x198/0x19c
[ 93.012792] Code: aa1703e0 d2800014 95cb0ba4 17ffffe8 (f940a400)
[ 93.018869] ---[ end trace 0000000000000000 ]---
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ce97192087c659f2e0c0c2a627330c7edcc9eeb3",
"status": "affected",
"version": "d2d79d29bb98a32c511f7339a8e93b47544fdeac",
"versionType": "git"
},
{
"lessThan": "c45fafa69fe3f79e319369cf665da89868e3ef98",
"status": "affected",
"version": "d2d79d29bb98a32c511f7339a8e93b47544fdeac",
"versionType": "git"
},
{
"lessThan": "401fbe3b6bbb6c94c24ee8843b7beed5111491ac",
"status": "affected",
"version": "d2d79d29bb98a32c511f7339a8e93b47544fdeac",
"versionType": "git"
},
{
"lessThan": "cf385cf6e713eba0720651174dac0b2d2f5bb8f8",
"status": "affected",
"version": "d2d79d29bb98a32c511f7339a8e93b47544fdeac",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: fix error checking of pvr_vm_context_lookup()\n\nSince pvr_vm_context_lookup() returns either NULL or a pointer, then stop\nusing IS_ERR() for checking the return value.\n\nUsing IS_ERR() leads to the kernel oops reported below. It can be\nreproduced by passing an invalid VM context handle from userspace to the\nDRM_IOCTL_PVR_CREATE_CONTEXT ioctl.\n\n[ 92.733119] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000148\n[ 92.742042] Mem abort info:\n[ 92.744890] ESR = 0x0000000096000004\n[ 92.748686] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 92.754020] SET = 0, FnV = 0\n[ 92.757154] EA = 0, S1PTW = 0\n[ 92.760337] FSC = 0x04: level 0 translation fault\n[ 92.765243] Data abort info:\n[ 92.768129] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 92.773626] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 92.778763] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 92.784098] user pgtable: 4k pages, 48-bit VAs, pgdp=000000088ed23000\n[ 92.790550] [0000000000000148] pgd=0000000000000000, p4d=0000000000000000\n[ 92.797381] Internal error: Oops: 0000000096000004 [#1] SMP\n[ 92.803027] Modules linked in: powervr\n[ 92.852533] CPU: 0 UID: 0 PID: 409 Comm: triangle Not tainted 7.1.0-rc5-g98b46e693b91 #1 PREEMPT\n[ 92.861385] Hardware name: Texas Instruments AM68 SK (DT)\n[ 92.866766] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 92.873709] pc : pvr_vm_get_fw_mem_context+0x0/0xc [powervr]\n[ 92.879376] lr : pvr_queue_create+0x26c/0x440 [powervr]\n[ 92.884595] sp : ffff8000837fbb00\n[ 92.887895] x29: ffff8000837fbb60 x28: 0000000000000000 x27: ffff8000837fbce8\n[ 92.895015] x26: ffff000807f61a40 x25: ffff000807f61a00 x24: ffff000807f64400\n[ 92.902135] x23: ffff00080a5ab000 x22: ffff800079b24730 x21: ffff000807f61800\n[ 92.909254] x20: ffff00080999e680 x19: 0000000000000000 x18: 0000000000000000\n[ 92.916373] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000001\n[ 92.923492] x14: 0000000000000000 x13: 0000000000000002 x12: ffff80008145b298\n[ 92.930611] x11: ffff8000844e5000 x10: ffff80008165a130 x9 : 0000000000000100\n[ 92.937730] x8 : 0000000000000001 x7 : ffff0008076b27e0 x6 : ffff00080ec43b7c\n[ 92.944850] x5 : ffff00080ec43b78 x4 : 0000000000000000 x3 : ffff00080999e680\n[ 92.951968] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000\n[ 92.959088] Call trace:\n[ 92.961521] pvr_vm_get_fw_mem_context+0x0/0xc [powervr] (P)\n[ 92.967173] pvr_context_create+0x190/0x410 [powervr]\n[ 92.972218] pvr_ioctl_create_context+0x44/0x8c [powervr]\n[ 92.977608] drm_ioctl_kernel+0xbc/0x124 [drm]\n[ 92.982127] drm_ioctl+0x1f8/0x4dc [drm]\n[ 92.986098] __arm64_sys_ioctl+0xac/0x104\n[ 92.990102] invoke_syscall+0x54/0x10c\n[ 92.993842] el0_svc_common.constprop.0+0x40/0xe0\n[ 92.998532] do_el0_svc+0x1c/0x28\n[ 93.001835] el0_svc+0x38/0x11c\n[ 93.004969] el0t_64_sync_handler+0xa0/0xe4\n[ 93.009139] el0t_64_sync+0x198/0x19c\n[ 93.012792] Code: aa1703e0 d2800014 95cb0ba4 17ffffe8 (f940a400)\n[ 93.018869] ---[ end trace 0000000000000000 ]---"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:53.453Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ce97192087c659f2e0c0c2a627330c7edcc9eeb3"
},
{
"url": "https://git.kernel.org/stable/c/c45fafa69fe3f79e319369cf665da89868e3ef98"
},
{
"url": "https://git.kernel.org/stable/c/401fbe3b6bbb6c94c24ee8843b7beed5111491ac"
},
{
"url": "https://git.kernel.org/stable/c/cf385cf6e713eba0720651174dac0b2d2f5bb8f8"
}
],
"title": "drm/imagination: fix error checking of pvr_vm_context_lookup()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68261",
"datePublished": "2026-08-10T12:01:35.600Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:01:53.453Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64137 (GCVE-0-2026-64137)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: require net admin for CIFS SWN netlink
CIFS_GENL_CMD_SWN_NOTIFY is the userspace witness-notify command. The
intended sender is the cifs.witness helper, but the generic-netlink
operation currently has no capability flag, so any local process can send
RESOURCE_CHANGE or CLIENT_MOVE notifications to the in-kernel witness
handler.
The same family exposes CIFS_GENL_MCGRP_SWN without multicast-group
capability flags. Register messages sent to that group include the witness
registration id and, for NTLM-authenticated mounts, the username, domain,
and password attributes copied from the CIFS session. An unprivileged
local process should not be able to join that group and receive those
messages.
Require CAP_NET_ADMIN for incoming SWN_NOTIFY commands with
GENL_ADMIN_PERM, and require CAP_NET_ADMIN over the network namespace for
joining the SWN multicast group with GENL_MCAST_CAP_NET_ADMIN. The
cifs.witness service runs with the privileges needed for both operations.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9cf7eb8919344932f909b2fac76296f7656fda8d",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "9919021a3b7974ae66a5f9915e3a48c10cfd409b",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "969bc6370334a5b4720c5470783295d6484bbc95",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "a3238b09c58f323e40743ce174cd0ab81b5c09ed",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "a8d17d22db591099519a89f14dd24810daba74c3",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "c2397b93fbb6f44a788fff30f99be2c20cc5e50f",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "d1ebfce2c1d161186a82e77590bf7da2ea1bce91",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: require net admin for CIFS SWN netlink\n\nCIFS_GENL_CMD_SWN_NOTIFY is the userspace witness-notify command. The\nintended sender is the cifs.witness helper, but the generic-netlink\noperation currently has no capability flag, so any local process can send\nRESOURCE_CHANGE or CLIENT_MOVE notifications to the in-kernel witness\nhandler.\n\nThe same family exposes CIFS_GENL_MCGRP_SWN without multicast-group\ncapability flags. Register messages sent to that group include the witness\nregistration id and, for NTLM-authenticated mounts, the username, domain,\nand password attributes copied from the CIFS session. An unprivileged\nlocal process should not be able to join that group and receive those\nmessages.\n\nRequire CAP_NET_ADMIN for incoming SWN_NOTIFY commands with\nGENL_ADMIN_PERM, and require CAP_NET_ADMIN over the network namespace for\njoining the SWN multicast group with GENL_MCAST_CAP_NET_ADMIN. The\ncifs.witness service runs with the privileges needed for both operations."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access via generic-netlink syscalls (socket/bind/sendmsg/setsockopt on NETLINK_GENERIC), not remote SMB or network packet handling.\nAC:L - An unprivileged attacker can reliably join the SWN multicast group and send crafted SWN_NOTIFY commands; registration IDs are exposed in multicast register messages, with no races or uncontrollable conditions.\nPR:L - Before the fix, no capability checks guarded SWN_NOTIFY or multicast group membership, so any unprivileged local user could exploit without CAP_NET_ADMIN or user-namespace tricks.\nUI:N - Exploitation is passive (multicast subscription) or active (netlink injection) and does not require any victim action at attack time beyond pre-existing witness-enabled CIFS mounts.\nS:U - Impact is confined to the local kernel/CIFS client security domain (credential theft and connection manipulation); it does not cross VM, container, or IOMMU boundaries.\nC:H - Multicast register messages disclose NTLM username, domain, and plaintext password from active CIFS witness sessions to any local subscriber.\nI:H - Forged CLIENT_MOVE notifications redirect SMB reconnects to attacker-controlled endpoints, compromising connection integrity and enabling MITM against mounted cluster shares.\nA:H - Forged RESOURCE_CHANGE notifications force CIFS reconnect cycles on all channels, enabling reliable denial-of-service against witness-enabled mounts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:38.366Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9cf7eb8919344932f909b2fac76296f7656fda8d"
},
{
"url": "https://git.kernel.org/stable/c/9919021a3b7974ae66a5f9915e3a48c10cfd409b"
},
{
"url": "https://git.kernel.org/stable/c/969bc6370334a5b4720c5470783295d6484bbc95"
},
{
"url": "https://git.kernel.org/stable/c/a3238b09c58f323e40743ce174cd0ab81b5c09ed"
},
{
"url": "https://git.kernel.org/stable/c/a8d17d22db591099519a89f14dd24810daba74c3"
},
{
"url": "https://git.kernel.org/stable/c/c2397b93fbb6f44a788fff30f99be2c20cc5e50f"
},
{
"url": "https://git.kernel.org/stable/c/d1ebfce2c1d161186a82e77590bf7da2ea1bce91"
}
],
"title": "smb: client: require net admin for CIFS SWN netlink",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64137",
"datePublished": "2026-07-19T15:40:31.045Z",
"dateReserved": "2026-07-19T07:54:57.037Z",
"dateUpdated": "2026-08-05T12:39:38.366Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74454 (GCVE-0-2026-74454)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
vc4_overflow_mem_work() points BPOA at a 512KB slot inside the 16MB
binner BO, but writes the size of the whole BO to BPOS. On every binner
out-of-memory event the PTB is therefore authorized to write tile lists
across all the other slots (which may hold the tile state, tile alloc and
overflow memory of in-flight jobs) and, for any slot but the first, past
the end of the binner BO into unrelated CMA memory.
Since CMA pages are recycled into page cache and user allocations, this
is arbitrary memory corruption by GPU DMA. In practice it shows up as GPU
hangs with corrupted control list pointers, userspace heap corruption, a
GPU that stays permanently wedged after the first hang, and occasional
full system crashes, whenever a job overflows the initial binner slot.
The bug dates back to the conversion from a dedicated overflow BO (where
writing the full BO size was correct) to the slotted binner BO.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_irq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bb5656ae063f2711f56438cf2f1f5b613aea5f12",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "2f2291a119e9a8b696ae8bb36e86b75d272ceaea",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "0badb30871004d34df87be33e853536f0b69885f",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "6cd5acf6f87c073622bd61e38fe99c47365cda9c",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "1e33ca7f44be64beed2735bb76b86eb65ba8c05b",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "6395789e4739aa5177bbec0fa0f07ccc38d249b0",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_irq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size\n\nvc4_overflow_mem_work() points BPOA at a 512KB slot inside the 16MB\nbinner BO, but writes the size of the whole BO to BPOS. On every binner\nout-of-memory event the PTB is therefore authorized to write tile lists\nacross all the other slots (which may hold the tile state, tile alloc and\noverflow memory of in-flight jobs) and, for any slot but the first, past\nthe end of the binner BO into unrelated CMA memory.\n\nSince CMA pages are recycled into page cache and user allocations, this\nis arbitrary memory corruption by GPU DMA. In practice it shows up as GPU\nhangs with corrupted control list pointers, userspace heap corruption, a\nGPU that stays permanently wedged after the first hang, and occasional\nfull system crashes, whenever a job overflows the initial binner slot.\n\nThe bug dates back to the conversion from a dedicated overflow BO (where\nwriting the full BO size was correct) to the slotted binner BO."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires submitting crafted GPU jobs through the VC4 DRM render node via DRM_IOCTL_VC4_SUBMIT_CL; the bug is reached in vc4_overflow_mem_work() after hardware raises V3D_INT_OUTOMEM, which is a local ioctl/syscall path, not a network protocol.\nAC:L - An attacker with render-node access can reliably trigger binner out-of-memory by submitting dense geometry that exhausts the 32-byte initial per-bin allocation, and can run concurrent jobs to force non-zero overflow slots; no race or rare layout conditions beyond attacker-controlled GPU workloads are required.\nPR:L - VC4_SUBMIT_CL is permitted on DRM render nodes (DRM_RENDER_ALLOW, no DRM_AUTH) and vc4_open() performs no extra capability checks; on Raspberry Pi and similar VC4 deployments, unprivileged users in the render/video group routinely have /dev/dri/renderD* access to reach this path.\nUI:N - No victim interaction is required when the attacker is a local unprivileged user with render-node access who directly opens /dev/dri/renderD* and submits a malicious binning command list designed to overflow the initial binner slot.\nS:U - The flaw causes GPU DMA to corrupt CMA memory used by the kernel and userspace, enabling standard local privilege escalation; it does not cross a VM, IOMMU, or hypervisor security boundary and stays within the kernel\u0027s security authority.\nC:H - On OUTOMEM, the driver programs BPOA to a 512KB slot but BPOS to the full 16MB BO, authorizing the PTB to DMA-write far beyond the slot into adjacent in-flight job data and unrelated CMA pages recycled into page cache and user allocations, enabling arbitrary kernel memory disclosure.\nI:H - The oversized BPOS grants the GPU PTB an out-of-bounds DMA write primitive across other binner slots and past the 16MB BO boundary into unrelated CMA memory, corrupting kernel structures and userspace heaps in ways suitable for arbitrary code execution and privilege escalation.\nA:H - The commit reports that triggering binner overflow causes GPU hangs with corrupted control-list pointers, permanently wedged GPUs after the first hang, userspace heap corruption, and occasional full system crashes, satisfying high availability impact from repeatable kernel/GPU failure."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:46.319Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bb5656ae063f2711f56438cf2f1f5b613aea5f12"
},
{
"url": "https://git.kernel.org/stable/c/2f2291a119e9a8b696ae8bb36e86b75d272ceaea"
},
{
"url": "https://git.kernel.org/stable/c/0badb30871004d34df87be33e853536f0b69885f"
},
{
"url": "https://git.kernel.org/stable/c/6cd5acf6f87c073622bd61e38fe99c47365cda9c"
},
{
"url": "https://git.kernel.org/stable/c/1e33ca7f44be64beed2735bb76b86eb65ba8c05b"
},
{
"url": "https://git.kernel.org/stable/c/6395789e4739aa5177bbec0fa0f07ccc38d249b0"
}
],
"title": "drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74454",
"datePublished": "2026-08-15T12:26:57.565Z",
"dateReserved": "2026-08-15T05:44:03.900Z",
"dateUpdated": "2026-08-19T16:36:46.319Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64554 (GCVE-0-2026-64554)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
br_ip6_fragment() gets prevhdr, a pointer into the skb head, from
ip6_find_1stfragopt(), then calls skb_checksum_help(). For a cloned skb
skb_checksum_help() reallocates the head via pskb_expand_head(), leaving
prevhdr dangling. It is later dereferenced in ip6_frag_next(), causing a
use-after-free write.
Save prevhdr's offset before skb_checksum_help() and recompute it after,
like commit ef0efcd3bd3f ("ipv6: Fix dangling pointer when ipv6
fragment").
BUG: KASAN: slab-use-after-free in ip6_frag_next (net/ipv6/ip6_output.c:857)
Write of size 1 at addr ffff888013ff5016 by task exploit/141
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
ip6_frag_next (net/ipv6/ip6_output.c:857)
br_ip6_fragment (net/ipv6/netfilter.c:212)
nf_ct_bridge_post (net/bridge/netfilter/nf_conntrack_bridge.c:407)
nf_hook_slow (net/netfilter/core.c:619)
br_forward_finish (net/bridge/br_forward.c:66)
__br_forward (net/bridge/br_forward.c:115)
maybe_deliver (net/bridge/br_forward.c:191)
br_flood (net/bridge/br_forward.c:245)
br_handle_frame_finish (net/bridge/br_input.c:229)
br_handle_frame (net/bridge/br_input.c:442)
...
packet_sendmsg (net/packet/af_packet.c:3114)
...
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Kernel panic - not syncing: Fatal exception in interrupt
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33 Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33 Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33 Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33 Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33 Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33 Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33 Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/netfilter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8c10778ec674b67a07ea042fcba64270f3f38a5a",
"status": "affected",
"version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
"versionType": "git"
},
{
"lessThan": "2731efa6364e47934c96eb69e01ea131e8af8030",
"status": "affected",
"version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
"versionType": "git"
},
{
"lessThan": "00c06ef8c018493943891a7d0ca82b71b24f3180",
"status": "affected",
"version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
"versionType": "git"
},
{
"lessThan": "c141f69d0a0fb16964dbc293650047e69bda8af7",
"status": "affected",
"version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
"versionType": "git"
},
{
"lessThan": "f2e6596d10783557aeb9668da2a3b4d19deb2001",
"status": "affected",
"version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
"versionType": "git"
},
{
"lessThan": "1c4f67c89fd27c4df4c70b135c2c59627698b3c0",
"status": "affected",
"version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
"versionType": "git"
},
{
"lessThan": "4ac981a8b7ce7aec99a52d08f8a8953e8e120067",
"status": "affected",
"version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
"versionType": "git"
},
{
"lessThan": "86f3ce81dd2b4b0aa2c3016c989a943e4b1b643d",
"status": "affected",
"version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/netfilter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()\n\nbr_ip6_fragment() gets prevhdr, a pointer into the skb head, from\nip6_find_1stfragopt(), then calls skb_checksum_help(). For a cloned skb\nskb_checksum_help() reallocates the head via pskb_expand_head(), leaving\nprevhdr dangling. It is later dereferenced in ip6_frag_next(), causing a\nuse-after-free write.\n\nSave prevhdr\u0027s offset before skb_checksum_help() and recompute it after,\nlike commit ef0efcd3bd3f (\"ipv6: Fix dangling pointer when ipv6\nfragment\").\n\n BUG: KASAN: slab-use-after-free in ip6_frag_next (net/ipv6/ip6_output.c:857)\n Write of size 1 at addr ffff888013ff5016 by task exploit/141\n Call Trace:\n ...\n kasan_report (mm/kasan/report.c:595)\n ip6_frag_next (net/ipv6/ip6_output.c:857)\n br_ip6_fragment (net/ipv6/netfilter.c:212)\n nf_ct_bridge_post (net/bridge/netfilter/nf_conntrack_bridge.c:407)\n nf_hook_slow (net/netfilter/core.c:619)\n br_forward_finish (net/bridge/br_forward.c:66)\n __br_forward (net/bridge/br_forward.c:115)\n maybe_deliver (net/bridge/br_forward.c:191)\n br_flood (net/bridge/br_forward.c:245)\n br_handle_frame_finish (net/bridge/br_input.c:229)\n br_handle_frame (net/bridge/br_input.c:442)\n ...\n packet_sendmsg (net/packet/af_packet.c:3114)\n ...\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n Kernel panic - not syncing: Fatal exception in interrupt"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable code is the bridge forwarding/refragmentation path, driven entirely by frames received on a bridge port from an L2 peer \u2014 typically a guest VM over tap/virtio or a container over veth, which per skbuff.h are exactly the sources that deliver CHECKSUM_PARTIAL skbs on receive. This is logically adjacent topology (bridged segment/overlay), not a routed internet path, so AV:A rather than N.\nAC:L - The attacker controls every precondition: send IPv6 fragments (forces conntrack reassembly and sets frag_max_size), set VIRTIO_NET_HDR_F_NEEDS_CSUM for CHECKSUM_PARTIAL, and target a broadcast/multicast/unknown-unicast MAC so br_flood calls deliver_clone() and makes the skb cloned. No race and no attacker-independent condition is involved; the corruption is deterministic once the packet is crafted.\nPR:N - A guest VM or container attached to the host bridge holds no credentials on the vulnerable host and needs none \u2014 it merely emits frames onto the segment. In the equivalent local variant the entire setup (bridge, veth, nft bridge conntrack, AF_PACKET with CAP_NET_RAW) is reachable from an unprivileged user namespace, so no real privilege is required either way.\nUI:N - The corruption happens automatically in softirq context while the bridge forwards the attacker\u0027s packet. No action by any user or administrator on the target is needed.\nS:U - The vulnerable component and the impacted resource are both the host kernel\u0027s network stack; no hypervisor, IOMMU, or sandbox boundary is bypassed by the bug itself. Standard kernel memory corruption is scored Unchanged.\nC:H - This is a use-after-free/out-of-bounds write on the slab; the freed skb head and the write target can be groomed by the attacker, and such heap corruption is routinely leveraged into arbitrary kernel memory disclosure. Per kernel scoring guidance, UAF/OOB corruption is High confidentiality impact.\nI:H - ip6_frag_next() writes NEXTHDR_FRAGMENT (0x2c) at skb_network_header(frag) plus an uncontrolled inter-allocation delta, giving a repeatable 1-byte heap write at a heap-groomable offset \u2014 once per emitted fragment. A controlled byte write into adjacent slab objects is a classic primitive for corrupting kernel data structures and escalating to control-flow hijack.\nA:H - KASAN reports a slab-use-after-free write followed by \"Kernel panic - not syncing: Fatal exception in interrupt\" because the fault occurs in softirq forwarding context, taking down the whole host rather than one task. The attacker can repeat it at will with a stream of crafted fragments."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:32.112Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8c10778ec674b67a07ea042fcba64270f3f38a5a"
},
{
"url": "https://git.kernel.org/stable/c/2731efa6364e47934c96eb69e01ea131e8af8030"
},
{
"url": "https://git.kernel.org/stable/c/00c06ef8c018493943891a7d0ca82b71b24f3180"
},
{
"url": "https://git.kernel.org/stable/c/c141f69d0a0fb16964dbc293650047e69bda8af7"
},
{
"url": "https://git.kernel.org/stable/c/f2e6596d10783557aeb9668da2a3b4d19deb2001"
},
{
"url": "https://git.kernel.org/stable/c/1c4f67c89fd27c4df4c70b135c2c59627698b3c0"
},
{
"url": "https://git.kernel.org/stable/c/4ac981a8b7ce7aec99a52d08f8a8953e8e120067"
},
{
"url": "https://git.kernel.org/stable/c/86f3ce81dd2b4b0aa2c3016c989a943e4b1b643d"
}
],
"title": "netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64554",
"datePublished": "2026-07-27T20:10:41.726Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-08-17T04:57:32.112Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-31759 (GCVE-0-2026-31759)
Vulnerability from cvelistv5
Published
2026-05-01 14:14
Modified
2026-05-11 22:15
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: ulpi: fix double free in ulpi_register_interface() error path
When device_register() fails, ulpi_register() calls put_device() on
ulpi->dev.
The device release callback ulpi_dev_release() drops the OF node
reference and frees ulpi, but the current error path in
ulpi_register_interface() then calls kfree(ulpi) again, causing a
double free.
Let put_device() handle the cleanup through ulpi_dev_release() and
avoid freeing ulpi again in ulpi_register_interface().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/common/ulpi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2f70ba9dae13a190673cc3f9b4aad52179738f60",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "ee248e6e941e4f2e634df2bd43e5f1ef810ab6df",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "272a9b26c336a295e4e209157fed809706c1b1f7",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "aaeae6533d77e6ed4def85baec01e2815ebbef61",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "8763f8317bb389aded32a32b08f6751cfff657d2",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "38c28fe25611099230f0965c925499bfcf46a795",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "a6e5461f076c2ef63159f18e5cdbd30b50f0bc15",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "01af542392b5d41fd659d487015a71f627accce3",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/common/ulpi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.253",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.168",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.134",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.81",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.22",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.253",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.168",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.134",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.81",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.22",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.12",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: ulpi: fix double free in ulpi_register_interface() error path\n\nWhen device_register() fails, ulpi_register() calls put_device() on\nulpi-\u003edev.\n\nThe device release callback ulpi_dev_release() drops the OF node\nreference and frees ulpi, but the current error path in\nulpi_register_interface() then calls kfree(ulpi) again, causing a\ndouble free.\n\nLet put_device() handle the cleanup through ulpi_dev_release() and\navoid freeing ulpi again in ulpi_register_interface()."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:15:15.896Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2f70ba9dae13a190673cc3f9b4aad52179738f60"
},
{
"url": "https://git.kernel.org/stable/c/ee248e6e941e4f2e634df2bd43e5f1ef810ab6df"
},
{
"url": "https://git.kernel.org/stable/c/272a9b26c336a295e4e209157fed809706c1b1f7"
},
{
"url": "https://git.kernel.org/stable/c/aaeae6533d77e6ed4def85baec01e2815ebbef61"
},
{
"url": "https://git.kernel.org/stable/c/8763f8317bb389aded32a32b08f6751cfff657d2"
},
{
"url": "https://git.kernel.org/stable/c/38c28fe25611099230f0965c925499bfcf46a795"
},
{
"url": "https://git.kernel.org/stable/c/a6e5461f076c2ef63159f18e5cdbd30b50f0bc15"
},
{
"url": "https://git.kernel.org/stable/c/01af542392b5d41fd659d487015a71f627accce3"
}
],
"title": "usb: ulpi: fix double free in ulpi_register_interface() error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-31759",
"datePublished": "2026-05-01T14:14:51.895Z",
"dateReserved": "2026-03-09T15:48:24.139Z",
"dateUpdated": "2026-05-11T22:15:15.896Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72288 (GCVE-0-2026-72288)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-17 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling
Hyunwoo Kim reports some really bad races should the following
situation occur:
- LPI-I is pending in vcpu-B's AP list
- vcpu-A writes to vcpu-B's RD to disable its LPIs
- vcpu-C moves I from B to C
If the last two race nicely enough, vgic_prune_ap_list() can drop
the irq and AP list locks, reacquire them, and in the interval
the irq has been freed. UAF follows.
The fix is two-fold:
- Before dropping the irq and ap_list locks, take a reference on
the irq
- Do not try to handle migration of the pending bit: there is no
expectation that this state is retained, as per the architecture
With that, we're sure that the interrupt is still around, and we
safely remove it from the AP list as it has no target at this
stage (unless another interrupt fires, but that's another story).
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/arm64/kvm/vgic/vgic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d19dca8194ebed371e624331c6be2cb73b562caf",
"status": "affected",
"version": "5dd4b924e390af426e424d5e52c1b4d1566af817",
"versionType": "git"
},
{
"lessThan": "b1a89d12d35a8256d2b170ced0b1c86851f3def2",
"status": "affected",
"version": "5dd4b924e390af426e424d5e52c1b4d1566af817",
"versionType": "git"
},
{
"lessThan": "7258770e5814f15e8308ebda82ac9acf6964ba8e",
"status": "affected",
"version": "5dd4b924e390af426e424d5e52c1b4d1566af817",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/arm64/kvm/vgic/vgic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling\n\nHyunwoo Kim reports some really bad races should the following\nsituation occur:\n\n- LPI-I is pending in vcpu-B\u0027s AP list\n- vcpu-A writes to vcpu-B\u0027s RD to disable its LPIs\n- vcpu-C moves I from B to C\n\nIf the last two race nicely enough, vgic_prune_ap_list() can drop\nthe irq and AP list locks, reacquire them, and in the interval\nthe irq has been freed. UAF follows.\n\nThe fix is two-fold:\n\n- Before dropping the irq and ap_list locks, take a reference on\n the irq\n\n- Do not try to handle migration of the pending bit: there is no\n expectation that this state is retained, as per the architecture\n\nWith that, we\u0027re sure that the interrupt is still around, and we\nsafely remove it from the AP list as it has no target at this\nstage (unless another interrupt fires, but that\u0027s another story)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only from KVM guest MMIO traps on GICv3 redistributor GICR_CTLR LPI-disable writes, ITS MOVI affinity changes, and vCPU-exit paths into vgic_prune_ap_list(); no network-facing host protocol is involved.\nAC:L - A guest controls all three racing vCPUs by pinning threads to concurrently issue ITS MOVI, cross-vCPU GICR_CTLR LPI-disable writes, and vCPU exits that invoke vgic_prune_ap_list(); the attacker creates and wins the race rather than depending on uncontrollable host timing.\nPR:N - No host privileges are required beyond running code in an assigned KVM guest (e.g. a cloud VM tenant on arm64); exploitation needs guest-kernel access to GIC/ITS MMIO, not host root or capabilities in the init namespace.\nUI:N - Exploitation is fully attacker-driven from within a multi-vCPU guest VM and does not require any victim user or administrator action on the host.\nS:C - The use-after-free corrupts host-kernel heap memory (struct vgic_irq) from guest-controlled VGIC operations, crossing the guest-to-host virtualization security boundary with VM-escape impact.\nC:H - vgic_flush_pending_lpis() can free the LPI vgic_irq while vgic_prune_ap_list() still dereferences it after reacquiring dropped locks, yielding a kernel heap use-after-free exploitable for arbitrary host memory disclosure via heap grooming.\nI:H - The dangling vgic_irq pointer permits attacker-influenced writes through irq_lock, list_head, vcpu, and target_vcpu fields during ap_list migration, enabling host control-flow or data corruption primitives.\nA:H - The race frees live kernel objects still referenced by the ap_list migration path, causing host kernel oops, panic, or hang during list_del, lock operations, or subsequent LPI delivery on arm64 KVM hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:42:23.669Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d19dca8194ebed371e624331c6be2cb73b562caf"
},
{
"url": "https://git.kernel.org/stable/c/b1a89d12d35a8256d2b170ced0b1c86851f3def2"
},
{
"url": "https://git.kernel.org/stable/c/7258770e5814f15e8308ebda82ac9acf6964ba8e"
}
],
"title": "KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72288",
"datePublished": "2026-08-15T05:55:10.256Z",
"dateReserved": "2026-08-09T03:40:39.917Z",
"dateUpdated": "2026-08-17T05:42:23.669Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68437 (GCVE-0-2026-68437)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: Fit paired fragment job in the correct CCCB
For geometry jobs with a paired fragment job, at the moment, the
DRM scheduler's prepare_job() callback:
- checks for internal (driver) dependencies for the geometry job;
- calls into pvr_queue_get_paired_frag_job_dep() to check for external
dependencies for the fragment job (the two jobs are submitted together
but the common scheduler code doesn't know about it, so this needs to
be done at this point in time);
- calls into the prepare_job() callback again, but for the fragment job,
to check its internal dependencies as well, passing the fragment job's
drm_sched_job and the geometry job's drm_sched_entity / pvr_queue.
The problem with the last step is that pvr_queue_prepare_job() doesn't
always take the mismatched fragment job and geometry queue into account,
in particular when checking whether there is space for the fragment
command to be submitted, so the code ends up checking for space in the
geometry (i.e. wrong) CCCB.
The rest of the nested prepare_job() callback happens to work fine at
the moment as the other internal dependencies are not relevant for a
paired fragment job.
Move the initialisation of a paired fragment job's done fence and CCCB
fence to pvr_queue_get_paired_frag_job_dep(), inferring the correct
queue from the fragment job itself.
This fixes cases where prepare_job() wrongly assumed that there was
enough space for a paired fragment job in its own CCCB, unblocking
run_job(), which then returned early without writing the full sequence
of commands to the CCCB.
The above lead to kernel warnings such as the following and potentially
job timeouts (depending on waiters on the missing commands):
[ 552.421075] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#2: kworker/u16:5/63
[ 552.421230] Modules linked in:
[ 552.421592] CPU: 2 UID: 0 PID: 63 Comm: kworker/u16:5 Tainted: G W 7.0.0-rc2-gc5d053e4dccb #39 PREEMPT
[ 552.421625] Tainted: [W]=WARN
[ 552.421637] Hardware name: Texas Instruments AM625 SK (DT)
[ 552.421655] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]
[ 552.421744] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 552.421766] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]
[ 552.421850] lr : pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr]
[ 552.421923] sp : ffff800084c47650
[ 552.421936] x29: ffff800084c47740 x28: 0000000000000df8 x27: ffff800088a77000
[ 552.421979] x26: 0000000000000030 x25: ffff800084c47680 x24: 0000000000001000
[ 552.422017] x23: ffff800084c47820 x22: 1ffff00010988ecc x21: 0000000000000008
[ 552.422055] x20: 0000000000000208 x19: ffff000006ad5a88 x18: 0000000000000000
[ 552.422093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000
[ 552.422130] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000
[ 552.422167] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3
[ 552.422204] x8 : 00000000f2f2f200 x7 : ffff700010988ecc x6 : 0000000000000008
[ 552.422241] x5 : 0000000000000000 x4 : 1ffff0001114ee00 x3 : 0000000000000000
[ 552.422278] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f
[ 552.422316] Call trace:
[ 552.422330] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)
[ 552.422411] pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr]
[ 552.422486] pvr_queue_run_job+0x3a4/0x990 [powervr]
[ 552.422562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched]
[ 552.422623] process_one_work+0x520/0x1288
[ 552.422657] worker_thread+0x3f0/0xb3c
[ 552.422679] kthread+0x334/0x3d8
[ 552.422706] ret_from_fork+0x10/0x20
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "15a9863929206911a08b6f62de9c5da6931dbc9e",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "e2c29d51c0f65459ae5bbf7ccc302df4c359c473",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "4ddf82c18ee4b3d14ec7fa002c4039b46c961abc",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "4baf9e70cb756d78dd56419f8baee2978a72d0c3",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Fit paired fragment job in the correct CCCB\n\nFor geometry jobs with a paired fragment job, at the moment, the\nDRM scheduler\u0027s prepare_job() callback:\n\n- checks for internal (driver) dependencies for the geometry job;\n- calls into pvr_queue_get_paired_frag_job_dep() to check for external\n dependencies for the fragment job (the two jobs are submitted together\n but the common scheduler code doesn\u0027t know about it, so this needs to\n be done at this point in time);\n- calls into the prepare_job() callback again, but for the fragment job,\n to check its internal dependencies as well, passing the fragment job\u0027s\n drm_sched_job and the geometry job\u0027s drm_sched_entity / pvr_queue.\n\nThe problem with the last step is that pvr_queue_prepare_job() doesn\u0027t\nalways take the mismatched fragment job and geometry queue into account,\nin particular when checking whether there is space for the fragment\ncommand to be submitted, so the code ends up checking for space in the\ngeometry (i.e. wrong) CCCB.\nThe rest of the nested prepare_job() callback happens to work fine at\nthe moment as the other internal dependencies are not relevant for a\npaired fragment job.\n\nMove the initialisation of a paired fragment job\u0027s done fence and CCCB\nfence to pvr_queue_get_paired_frag_job_dep(), inferring the correct\nqueue from the fragment job itself.\n\nThis fixes cases where prepare_job() wrongly assumed that there was\nenough space for a paired fragment job in its own CCCB, unblocking\nrun_job(), which then returned early without writing the full sequence\nof commands to the CCCB.\n\nThe above lead to kernel warnings such as the following and potentially\njob timeouts (depending on waiters on the missing commands):\n\n [ 552.421075] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#2: kworker/u16:5/63\n [ 552.421230] Modules linked in:\n [ 552.421592] CPU: 2 UID: 0 PID: 63 Comm: kworker/u16:5 Tainted: G W 7.0.0-rc2-gc5d053e4dccb #39 PREEMPT\n [ 552.421625] Tainted: [W]=WARN\n [ 552.421637] Hardware name: Texas Instruments AM625 SK (DT)\n [ 552.421655] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]\n [ 552.421744] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n [ 552.421766] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]\n [ 552.421850] lr : pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr]\n [ 552.421923] sp : ffff800084c47650\n [ 552.421936] x29: ffff800084c47740 x28: 0000000000000df8 x27: ffff800088a77000\n [ 552.421979] x26: 0000000000000030 x25: ffff800084c47680 x24: 0000000000001000\n [ 552.422017] x23: ffff800084c47820 x22: 1ffff00010988ecc x21: 0000000000000008\n [ 552.422055] x20: 0000000000000208 x19: ffff000006ad5a88 x18: 0000000000000000\n [ 552.422093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000\n [ 552.422130] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n [ 552.422167] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3\n [ 552.422204] x8 : 00000000f2f2f200 x7 : ffff700010988ecc x6 : 0000000000000008\n [ 552.422241] x5 : 0000000000000000 x4 : 1ffff0001114ee00 x3 : 0000000000000000\n [ 552.422278] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f\n [ 552.422316] Call trace:\n [ 552.422330] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)\n [ 552.422411] pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr]\n [ 552.422486] pvr_queue_run_job+0x3a4/0x990 [powervr]\n [ 552.422562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched]\n [ 552.422623] process_one_work+0x520/0x1288\n [ 552.422657] worker_thread+0x3f0/0xb3c\n [ 552.422679] kthread+0x334/0x3d8\n [ 552.422706] ret_from_fork+0x10/0x20"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:34.181Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/15a9863929206911a08b6f62de9c5da6931dbc9e"
},
{
"url": "https://git.kernel.org/stable/c/e2c29d51c0f65459ae5bbf7ccc302df4c359c473"
},
{
"url": "https://git.kernel.org/stable/c/4ddf82c18ee4b3d14ec7fa002c4039b46c961abc"
},
{
"url": "https://git.kernel.org/stable/c/4baf9e70cb756d78dd56419f8baee2978a72d0c3"
}
],
"title": "drm/imagination: Fit paired fragment job in the correct CCCB",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68437",
"datePublished": "2026-08-12T00:07:25.745Z",
"dateReserved": "2026-07-30T09:28:09.394Z",
"dateUpdated": "2026-08-17T05:05:34.181Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74571 (GCVE-0-2026-74571)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-17 05:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: skip global block reserve accounting for rescue mounts
[BUG]
Mounting with rescue=ibadroots after corrupting the block group tree
root triggers a NULL pointer dereference:
BUG: kernel NULL pointer dereference, address: 0000000000000100
RIP: 0010:btrfs_update_global_block_rsv+0x9d/0x1c0 [btrfs]
Call Trace:
fill_dummy_bgs+0xd4/0x120 [btrfs]
open_ctree+0xc6e/0x1ca0 [btrfs]
btrfs_get_tree+0x50d/0xa40 [btrfs]
The same crash occurs with a corrupted raid stripe tree root, via
btrfs_read_block_groups() instead of fill_dummy_bgs().
[CAUSE]
With rescue=ibadroots, btrfs_read_roots() allows the mount to continue
when either root cannot be read, leaving the corresponding root pointer
NULL while its on-disk feature bit remains set.
btrfs_update_global_block_rsv() then dereferences the missing root based
on the feature bit alone.
[FIX]
Rescue mounts are fully read-only and cannot start transactions, so the
global reserve is never consumed. Under btrfs_is_full_ro(), mark the
reserve as full and return before performing the accounting.
And since we need to check if the fs is mount fully RO, export
fs_is_full_ro() as btrfs_is_full_ro(), and move it to fs.h.
[ Squash the fs_is_full_ro() export commit into this one. ]
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/block-rsv.c",
"fs/btrfs/disk-io.c",
"fs/btrfs/fs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "076349e4c8d11f6b58c4549976a513b2b4dc6df2",
"status": "affected",
"version": "8dbfc14fc736eb701089aff09645c3d4ad3decb1",
"versionType": "git"
},
{
"lessThan": "51a0e8399858621442807a26057bcd1cd3ced046",
"status": "affected",
"version": "8dbfc14fc736eb701089aff09645c3d4ad3decb1",
"versionType": "git"
},
{
"status": "affected",
"version": "cbec34d3021d47007a0334c634f7053dbaf93d02",
"versionType": "git"
},
{
"status": "affected",
"version": "1e8087589b5cf6fa17adaf57b64cf1656d77dfec",
"versionType": "git"
},
{
"lessThan": "6.2",
"status": "affected",
"version": "6.1.43",
"versionType": "semver"
},
{
"lessThan": "6.5",
"status": "affected",
"version": "6.4.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/block-rsv.c",
"fs/btrfs/disk-io.c",
"fs/btrfs/fs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.1.43",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: skip global block reserve accounting for rescue mounts\n\n[BUG]\nMounting with rescue=ibadroots after corrupting the block group tree\nroot triggers a NULL pointer dereference:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000100\n RIP: 0010:btrfs_update_global_block_rsv+0x9d/0x1c0 [btrfs]\n Call Trace:\n fill_dummy_bgs+0xd4/0x120 [btrfs]\n open_ctree+0xc6e/0x1ca0 [btrfs]\n btrfs_get_tree+0x50d/0xa40 [btrfs]\n\nThe same crash occurs with a corrupted raid stripe tree root, via\nbtrfs_read_block_groups() instead of fill_dummy_bgs().\n\n[CAUSE]\nWith rescue=ibadroots, btrfs_read_roots() allows the mount to continue\nwhen either root cannot be read, leaving the corresponding root pointer\nNULL while its on-disk feature bit remains set.\n\nbtrfs_update_global_block_rsv() then dereferences the missing root based\non the feature bit alone.\n\n[FIX]\nRescue mounts are fully read-only and cannot start transactions, so the\nglobal reserve is never consumed. Under btrfs_is_full_ro(), mark the\nreserve as full and return before performing the accounting.\n\nAnd since we need to check if the fs is mount fully RO, export\nfs_is_full_ro() as btrfs_is_full_ro(), and move it to fs.h.\n\n[ Squash the fs_is_full_ro() export commit into this one. ]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:22:00.523Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/076349e4c8d11f6b58c4549976a513b2b4dc6df2"
},
{
"url": "https://git.kernel.org/stable/c/51a0e8399858621442807a26057bcd1cd3ced046"
}
],
"title": "btrfs: skip global block reserve accounting for rescue mounts",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74571",
"datePublished": "2026-08-15T12:28:10.711Z",
"dateReserved": "2026-08-15T05:44:03.917Z",
"dateUpdated": "2026-08-17T05:22:00.523Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63828 (GCVE-0-2026-63828)
Vulnerability from cvelistv5
Published
2026-07-19 12:02
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
apparmor: mediate the implicit connect of TCP fast open sendmsg
sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and
write(2): it opens the connection in the SYN. apparmor_socket_sendmsg()
only checks AA_MAY_SEND, so a profile that grants send but denies connect
lets a confined task open an outbound TCP/MPTCP connection that connect(2)
would have refused, bypassing connect mediation.
Mediate the implicit connect when MSG_FASTOPEN is set and a destination
is supplied. Add it to apparmor_socket_sendmsg() (not the shared
aa_sock_msg_perm() helper, which recvmsg also uses) and call aa_sk_perm()
directly, mirroring the selinux and tomoyo fixes. sk_is_tcp() does not
cover MPTCP fast open, so the SOCK_STREAM/IPPROTO_MPTCP arm is explicit.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cf60af03ca4e71134206809ea892e49b92a88896 Version: cf60af03ca4e71134206809ea892e49b92a88896 Version: cf60af03ca4e71134206809ea892e49b92a88896 Version: cf60af03ca4e71134206809ea892e49b92a88896 Version: cf60af03ca4e71134206809ea892e49b92a88896 Version: cf60af03ca4e71134206809ea892e49b92a88896 Version: cf60af03ca4e71134206809ea892e49b92a88896 Version: cf60af03ca4e71134206809ea892e49b92a88896 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/apparmor/lsm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a16714e7cf2baa98ba2efddd5d6cbac641f4e76b",
"status": "affected",
"version": "cf60af03ca4e71134206809ea892e49b92a88896",
"versionType": "git"
},
{
"lessThan": "20383429b56974507c465d016e5238b189f7a246",
"status": "affected",
"version": "cf60af03ca4e71134206809ea892e49b92a88896",
"versionType": "git"
},
{
"lessThan": "7f57428ce00891d26b0f087ef754a4d820ec83aa",
"status": "affected",
"version": "cf60af03ca4e71134206809ea892e49b92a88896",
"versionType": "git"
},
{
"lessThan": "faea60deaa05c76f0772650f42eafde12bd39d93",
"status": "affected",
"version": "cf60af03ca4e71134206809ea892e49b92a88896",
"versionType": "git"
},
{
"lessThan": "07b71c342382b854ab8030b244aeab6a7228ad7d",
"status": "affected",
"version": "cf60af03ca4e71134206809ea892e49b92a88896",
"versionType": "git"
},
{
"lessThan": "4a69b83045d3195d5b9a9b053ad840ddb2998b4e",
"status": "affected",
"version": "cf60af03ca4e71134206809ea892e49b92a88896",
"versionType": "git"
},
{
"lessThan": "45ebb934ea50b436ce49b2f159f090dab0d7fa28",
"status": "affected",
"version": "cf60af03ca4e71134206809ea892e49b92a88896",
"versionType": "git"
},
{
"lessThan": "4d587cd8a72155089a627130bbd4716ec0856e21",
"status": "affected",
"version": "cf60af03ca4e71134206809ea892e49b92a88896",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/apparmor/lsm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.6"
},
{
"lessThan": "3.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: mediate the implicit connect of TCP fast open sendmsg\n\nsendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and\nwrite(2): it opens the connection in the SYN. apparmor_socket_sendmsg()\nonly checks AA_MAY_SEND, so a profile that grants send but denies connect\nlets a confined task open an outbound TCP/MPTCP connection that connect(2)\nwould have refused, bypassing connect mediation.\n\nMediate the implicit connect when MSG_FASTOPEN is set and a destination\nis supplied. Add it to apparmor_socket_sendmsg() (not the shared\naa_sock_msg_perm() helper, which recvmsg also uses) and call aa_sk_perm()\ndirectly, mirroring the selinux and tomoyo fixes. sk_is_tcp() does not\ncover MPTCP fast open, so the SOCK_STREAM/IPPROTO_MPTCP arm is explicit."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a confined local process to invoke sendmsg(2)/sendto(2) with MSG_FASTOPEN; the vulnerable AppArmor LSM hook runs on the syscall path before TCP fast-open performs its implicit connect.\nAC:L - Any confined task that already has send permission can reliably trigger the bypass with a single sendmsg/sendto call using MSG_FASTOPEN and a destination address, with no race or special victim state required beyond TCP Fast Open client support.\nPR:L - The attacker must be an unprivileged process confined by an AppArmor profile that grants network send but denies connect (e.g., hardened Snap/sandboxed service profiles on Ubuntu); no real root or capabilities beyond normal confined-user execution are needed.\nUI:N - No victim interaction is required; the confined attacker process directly issues the bypassing syscall without needing another user or administrator to perform any action.\nS:C - Successful exploitation crosses the AppArmor confinement boundary, allowing a sandboxed task to establish outbound TCP/MPTCP connections that connect(2) mediation would have blocked, escaping the intended network policy scope.\nC:H - Bypassing connect mediation lets a confined process open TCP/MPTCP sessions to destinations policy forbids and read arbitrary response data from those services (internal APIs, metadata endpoints, C2 servers), constituting unauthorized information disclosure.\nI:H - The bypass enables unauthorized outbound connection establishment and transmission of arbitrary application data (including SYN-cookie data) to hosts explicitly denied by the AppArmor connect rule, violating integrity of the confinement policy.\nA:N - This is a pure LSM policy-bypass flaw with no kernel memory corruption, panic, oops, hang, or resource exhaustion; exploitation does not impact system availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:36.839Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a16714e7cf2baa98ba2efddd5d6cbac641f4e76b"
},
{
"url": "https://git.kernel.org/stable/c/20383429b56974507c465d016e5238b189f7a246"
},
{
"url": "https://git.kernel.org/stable/c/7f57428ce00891d26b0f087ef754a4d820ec83aa"
},
{
"url": "https://git.kernel.org/stable/c/faea60deaa05c76f0772650f42eafde12bd39d93"
},
{
"url": "https://git.kernel.org/stable/c/07b71c342382b854ab8030b244aeab6a7228ad7d"
},
{
"url": "https://git.kernel.org/stable/c/4a69b83045d3195d5b9a9b053ad840ddb2998b4e"
},
{
"url": "https://git.kernel.org/stable/c/45ebb934ea50b436ce49b2f159f090dab0d7fa28"
},
{
"url": "https://git.kernel.org/stable/c/4d587cd8a72155089a627130bbd4716ec0856e21"
}
],
"title": "apparmor: mediate the implicit connect of TCP fast open sendmsg",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63828",
"datePublished": "2026-07-19T12:02:22.644Z",
"dateReserved": "2026-07-19T07:54:57.014Z",
"dateUpdated": "2026-08-17T04:51:36.839Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64115 (GCVE-0-2026-64115)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vsock/vmci: fix UAF when peer resets connection during handshake
vmci_transport_recv_connecting_server() returned err = 0 for a peer
RST in its default switch arm:
err = pkt->type == VMCI_TRANSPORT_PACKET_TYPE_RST ? 0 : -EINVAL;
That made vmci_transport_recv_listen() skip vsock_remove_pending(),
leaving the pending socket on the listener's pending_links with
sk_state = TCP_CLOSE while destroy: still dropped the explicit
reference taken before schedule_delayed_work().
One second later vsock_pending_work() observed is_pending=true and
performed full cleanup: vsock_remove_pending() then the two trailing
sock_put(sk) calls -- the first reached refcount 0 and __sk_freed
the socket, and the second wrote into the freed object:
BUG: KASAN: slab-use-after-free in refcount_warn_saturate
Write of size 4 at addr ffff88800b1cac80 by task kworker
Workqueue: events vsock_pending_work
Treat peer RST like any other unexpected packet type (err = -EINVAL).
All destroy: arms now return err < 0, so vmci_transport_recv_listen()
removes pending from pending_links synchronously and
vsock_pending_work() takes the is_pending=false / !rejected branch,
dropping only its own work reference. This also closes the
multi-packet race Sashiko reported on v2: pending is removed from
the list before any subsequent packet can find it.
The pre-existing sk_acceptq_removed() gap on the err < 0 path of
vmci_transport_recv_listen() that Sashiko also noted is not
introduced or changed by this patch.
Tested on lts-6.12.79 with KASAN: 52/100 unpatched -> 0/100 patched.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d021c344051af91f42c5ba9fdedc176740cbd238 Version: d021c344051af91f42c5ba9fdedc176740cbd238 Version: d021c344051af91f42c5ba9fdedc176740cbd238 Version: d021c344051af91f42c5ba9fdedc176740cbd238 Version: d021c344051af91f42c5ba9fdedc176740cbd238 Version: d021c344051af91f42c5ba9fdedc176740cbd238 Version: d021c344051af91f42c5ba9fdedc176740cbd238 Version: d021c344051af91f42c5ba9fdedc176740cbd238 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/vmci_transport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1e19f08552b90070ed18bafb1763c78297823af6",
"status": "affected",
"version": "d021c344051af91f42c5ba9fdedc176740cbd238",
"versionType": "git"
},
{
"lessThan": "1dd531e28f61edd286edc486ab068f135b5ae1eb",
"status": "affected",
"version": "d021c344051af91f42c5ba9fdedc176740cbd238",
"versionType": "git"
},
{
"lessThan": "ecda37f8faab3220da199335e42564cb7a9ad145",
"status": "affected",
"version": "d021c344051af91f42c5ba9fdedc176740cbd238",
"versionType": "git"
},
{
"lessThan": "cc27e989a5dfdfcfc1cca7c3be27a0c7532b46cb",
"status": "affected",
"version": "d021c344051af91f42c5ba9fdedc176740cbd238",
"versionType": "git"
},
{
"lessThan": "47e63077605c6c2aa45b3df9847a8cdc1f1f6ef9",
"status": "affected",
"version": "d021c344051af91f42c5ba9fdedc176740cbd238",
"versionType": "git"
},
{
"lessThan": "440447699c681e26ed58e9c309cad718270a18b4",
"status": "affected",
"version": "d021c344051af91f42c5ba9fdedc176740cbd238",
"versionType": "git"
},
{
"lessThan": "9fe74e42914c851d68069713b7b917a9c33faf26",
"status": "affected",
"version": "d021c344051af91f42c5ba9fdedc176740cbd238",
"versionType": "git"
},
{
"lessThan": "99e22ddf4edb63dc8382bc028af928056d3450cf",
"status": "affected",
"version": "d021c344051af91f42c5ba9fdedc176740cbd238",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/vmci_transport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"lessThan": "3.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/vmci: fix UAF when peer resets connection during handshake\n\nvmci_transport_recv_connecting_server() returned err = 0 for a peer\nRST in its default switch arm:\n\n\terr = pkt-\u003etype == VMCI_TRANSPORT_PACKET_TYPE_RST ? 0 : -EINVAL;\n\nThat made vmci_transport_recv_listen() skip vsock_remove_pending(),\nleaving the pending socket on the listener\u0027s pending_links with\nsk_state = TCP_CLOSE while destroy: still dropped the explicit\nreference taken before schedule_delayed_work().\n\nOne second later vsock_pending_work() observed is_pending=true and\nperformed full cleanup: vsock_remove_pending() then the two trailing\nsock_put(sk) calls -- the first reached refcount 0 and __sk_freed\nthe socket, and the second wrote into the freed object:\n\n BUG: KASAN: slab-use-after-free in refcount_warn_saturate\n Write of size 4 at addr ffff88800b1cac80 by task kworker\n Workqueue: events vsock_pending_work\n\nTreat peer RST like any other unexpected packet type (err = -EINVAL).\nAll destroy: arms now return err \u003c 0, so vmci_transport_recv_listen()\nremoves pending from pending_links synchronously and\nvsock_pending_work() takes the is_pending=false / !rejected branch,\ndropping only its own work reference. This also closes the\nmulti-packet race Sashiko reported on v2: pending is removed from\nthe list before any subsequent packet can find it.\n\nThe pre-existing sk_acceptq_removed() gap on the err \u003c 0 path of\nvmci_transport_recv_listen() that Sashiko also noted is not\nintroduced or changed by this patch.\n\nTested on lts-6.12.79 with KASAN: 52/100 unpatched -\u003e 0/100 patched."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local AF_VSOCK syscalls (connect/close) to drive VMCI control packets; per kernel CVSS guidance, vsock is scored Local even when the peer is a VM guest reaching a host listener.\nAC:L - The attacker controls both sides of the handshake race by initiating a connection and aborting it with RST during TCP_SYN_SENT; KASAN testing showed 52/100 repro without conditions outside attacker control.\nPR:L - Any unprivileged local user inside a VM (or on the same host) can open AF_VSOCK sockets and connect to a listening peer without CAP_NET_ADMIN or other elevated privileges.\nUI:N - Exploitation requires only a victim service with a bound/listening vsock socket, which is normal background operation; no interactive victim action is needed.\nS:C - In the most severe reasonable VMware deployment, an unprivileged guest VM triggers kernel memory corruption on the hypervisor host via VMCI vsock, crossing the guest-to-host virtualisation security boundary analogous to KVM/Xen VM escape.\nC:H - The bug is a slab use-after-free on struct sock; UAF on kernel heap objects enables arbitrary memory read primitives through controlled reuse of the freed socket structure.\nI:H - The UAF involves a write to a freed object\u0027s refcount field and corrupts kernel heap metadata, providing a foundation for arbitrary write and kernel code execution via heap grooming.\nA:H - The vulnerability reliably triggers kernel UAF detected by KASAN (refcount write to freed memory on a kworker), which causes kernel oops/panic and denial of host availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:24.360Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1e19f08552b90070ed18bafb1763c78297823af6"
},
{
"url": "https://git.kernel.org/stable/c/1dd531e28f61edd286edc486ab068f135b5ae1eb"
},
{
"url": "https://git.kernel.org/stable/c/ecda37f8faab3220da199335e42564cb7a9ad145"
},
{
"url": "https://git.kernel.org/stable/c/cc27e989a5dfdfcfc1cca7c3be27a0c7532b46cb"
},
{
"url": "https://git.kernel.org/stable/c/47e63077605c6c2aa45b3df9847a8cdc1f1f6ef9"
},
{
"url": "https://git.kernel.org/stable/c/440447699c681e26ed58e9c309cad718270a18b4"
},
{
"url": "https://git.kernel.org/stable/c/9fe74e42914c851d68069713b7b917a9c33faf26"
},
{
"url": "https://git.kernel.org/stable/c/99e22ddf4edb63dc8382bc028af928056d3450cf"
}
],
"title": "vsock/vmci: fix UAF when peer resets connection during handshake",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64115",
"datePublished": "2026-07-19T15:40:15.513Z",
"dateReserved": "2026-07-19T07:54:57.035Z",
"dateUpdated": "2026-08-05T12:39:24.360Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74481 (GCVE-0-2026-74481)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/page_reporting: use system_freezable_wq to fix UAF during suspend
During PM freeze (e.g. S3 suspend or S4 hibernation), device drivers like
virtio_balloon reset their underlying virtio devices and delete their
virtqueues via vdev->config->del_vqs().
However, page reporting work (page_reporting_process) was scheduled on the
global system_wq. Because system_wq lacks the WQ_FREEZABLE flag, the PM
freezer skips it, leaving page_reporting_process active during suspend.
If pages are freed into the buddy allocator while suspending (for example,
when core MM invokes the balloon shrinker during S4 hibernation image
saving), page reporting triggers virtballoon_free_page_report() on deleted
virtqueues, resulting in a Use-After-Free / General Protection Fault:
[ 196.795226] general protection fault, probably for non-canonical address 0xaa1436fe70dae6df: 0000 [#1] SMP NOPTI
[ 196.825967] Workqueue: events page_reporting_process
[ 196.831038] RIP: 0010:virtqueue_add_split+0x233/0x4c0 [virtio_ring]
[ 196.927073] virtballoon_free_page_report+0x3a/0xe0 [virtio_balloon]
[ 196.946943] page_reporting_process+0x370/0x4f0
Fix this by switching page reporting work to system_freezable_wq. This
ensures that the PM freezer pauses page_reporting_process before device
drivers destroy their reporting virtqueues. Because the reporting worker
is frozen, memory reclamation/freeing (e.g. via shrinker execution) can
safely return pages to MM during freeze without triggering unfrozen
reporting work on deleted virtqueues.
This aligns with the driver's existing design. The comment in
virtballoon_freeze() states:
/*
* The workqueue is already frozen by the PM core before this
* function is called.
*/
Testing:
I have verified these fixes using Google’s virtualization infrastructure
by running continuous suspend/resume iterations (40+ cycles) while
churning memory using stress-ng (`stress-ng --vm 4 --vm-bytes 60%
--timeout 1`) to constantly create free pages for the buddy allocator. We
also set the `page_reporting_order` parameter to 0 to make the page
reporting worker highly sensitive, forcing it to pick up any 4K free
pages. This confirmed that the UAF crashes are no longer reproducible.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/page_reporting.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a4c60046052777ca1dcc83fe3ece2a5136b301f1",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "b2c094e98f8bb823b3ae475f7169fe2091c40c6d",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "992f270fd808338fbae1f498a5e325e7e2e20368",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "f978048326570047e8216e81a67f9c71ef2bb1b1",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "450f35f4d5a682a0796757e52295df58ddb63bc9",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "b11907c905fa08eda925395f0724b7a409870f65",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "faf439b5fa7b231120eac4f7a617e0bfd4f6f5c7",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "0b45f6927a14914ff685fe0e6f9d11232a1e03df",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/page_reporting.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_reporting: use system_freezable_wq to fix UAF during suspend\n\nDuring PM freeze (e.g. S3 suspend or S4 hibernation), device drivers like\nvirtio_balloon reset their underlying virtio devices and delete their\nvirtqueues via vdev-\u003econfig-\u003edel_vqs().\n\nHowever, page reporting work (page_reporting_process) was scheduled on the\nglobal system_wq. Because system_wq lacks the WQ_FREEZABLE flag, the PM\nfreezer skips it, leaving page_reporting_process active during suspend.\n\nIf pages are freed into the buddy allocator while suspending (for example,\nwhen core MM invokes the balloon shrinker during S4 hibernation image\nsaving), page reporting triggers virtballoon_free_page_report() on deleted\nvirtqueues, resulting in a Use-After-Free / General Protection Fault:\n\n [ 196.795226] general protection fault, probably for non-canonical address 0xaa1436fe70dae6df: 0000 [#1] SMP NOPTI\n [ 196.825967] Workqueue: events page_reporting_process\n [ 196.831038] RIP: 0010:virtqueue_add_split+0x233/0x4c0 [virtio_ring]\n [ 196.927073] virtballoon_free_page_report+0x3a/0xe0 [virtio_balloon]\n [ 196.946943] page_reporting_process+0x370/0x4f0\n\nFix this by switching page reporting work to system_freezable_wq. This\nensures that the PM freezer pauses page_reporting_process before device\ndrivers destroy their reporting virtqueues. Because the reporting worker\nis frozen, memory reclamation/freeing (e.g. via shrinker execution) can\nsafely return pages to MM during freeze without triggering unfrozen\nreporting work on deleted virtqueues.\n\nThis aligns with the driver\u0027s existing design. The comment in\nvirtballoon_freeze() states:\n /*\n * The workqueue is already frozen by the PM core before this\n * function is called.\n */\n\nTesting:\nI have verified these fixes using Google\u2019s virtualization infrastructure\nby running continuous suspend/resume iterations (40+ cycles) while\nchurning memory using stress-ng (`stress-ng --vm 4 --vm-bytes 60%\n--timeout 1`) to constantly create free pages for the buddy allocator. We\nalso set the `page_reporting_order` parameter to 0 to make the page\nreporting worker highly sensitive, forcing it to pick up any 4K free\npages. This confirmed that the UAF crashes are no longer reproducible."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is reached only through local PM suspend/hibernation and guest memory-free paths (__free_one_page -\u003e page_reporting_notify_free -\u003e page_reporting_process -\u003e virtballoon_free_page_report); it is not reachable via network protocols or remote packet handling.\nAC:L - An attacker with local access can reliably drive the race by churning memory (e.g. stress-ng) to flood page-reporting work while triggering or awaiting S3/S4 suspend, as demonstrated in the fix commit\u0027s reproduction on virtio-balloon VMs.\nPR:L - No real-root capability is required to exercise the memory-free entry path (normal unprivileged mmap/malloc/free syscalls), and many desktop deployments allow session users to initiate suspend via logind/polkit without full init-namespace root.\nUI:N - Exploitation does not require a separate victim action beyond the attacker (or system policy) initiating suspend/hibernation; automated cloud/VM suspend-resume cycles and scripted PM transitions suffice without interactive victim cooperation.\nS:U - Impact is confined to guest kernel memory corruption and crash inside the virtio-balloon/page-reporting subsystem; it does not cross a VM/host, IOMMU, or sandbox security boundary to affect resources outside the kernel\u0027s own authority.\nC:H - This is a kernel heap use-after-free on freed virtqueue metadata accessed through virtqueue_add_split; UAF of kernel objects can be leveraged for arbitrary kernel memory read/info disclosure beyond the observed GPF crash.\nI:H - UAF on virtqueue/vring kernel structures during virtqueue_add_split provides a memory-corruption primitive that can be developed into controlled kernel writes or code execution, not merely a benign crash.\nA:H - The bug provably causes a kernel general protection fault/oops in page_reporting_process during suspend (Workqueue: events), crashing or destabilizing the system and denying availability on every affected suspend/hibernation cycle."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:36.090Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a4c60046052777ca1dcc83fe3ece2a5136b301f1"
},
{
"url": "https://git.kernel.org/stable/c/b2c094e98f8bb823b3ae475f7169fe2091c40c6d"
},
{
"url": "https://git.kernel.org/stable/c/992f270fd808338fbae1f498a5e325e7e2e20368"
},
{
"url": "https://git.kernel.org/stable/c/f978048326570047e8216e81a67f9c71ef2bb1b1"
},
{
"url": "https://git.kernel.org/stable/c/450f35f4d5a682a0796757e52295df58ddb63bc9"
},
{
"url": "https://git.kernel.org/stable/c/b11907c905fa08eda925395f0724b7a409870f65"
},
{
"url": "https://git.kernel.org/stable/c/faf439b5fa7b231120eac4f7a617e0bfd4f6f5c7"
},
{
"url": "https://git.kernel.org/stable/c/0b45f6927a14914ff685fe0e6f9d11232a1e03df"
}
],
"title": "mm/page_reporting: use system_freezable_wq to fix UAF during suspend",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74481",
"datePublished": "2026-08-15T12:27:14.441Z",
"dateReserved": "2026-08-15T05:44:03.904Z",
"dateUpdated": "2026-08-19T16:37:36.090Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64004 (GCVE-0-2026-64004)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: fix locking in .getsockopt
Mirror iucv_sock_setsockopt() and wrap the whole switch in
lock_sock()/release_sock(). The pre-existing SO_MSGLIMIT-only lock
becomes redundant and is removed.
Any AF_IUCV HIPER user can potentially crash the kernel by racing
recvmsg() with getsockopt(SO_MSGSIZE): the SO_MSGSIZE arm dereferences
iucv->hs_dev->mtu after iucv_sock_close() (called from the racing
recvmsg()) has set hs_dev to NULL, producing a NULL pointer dereference
oops.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 51363b8751a673a00ad48eea895266396d53fa52 Version: 51363b8751a673a00ad48eea895266396d53fa52 Version: 51363b8751a673a00ad48eea895266396d53fa52 Version: 51363b8751a673a00ad48eea895266396d53fa52 Version: 51363b8751a673a00ad48eea895266396d53fa52 Version: 51363b8751a673a00ad48eea895266396d53fa52 Version: 51363b8751a673a00ad48eea895266396d53fa52 Version: 51363b8751a673a00ad48eea895266396d53fa52 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "884eb247b74d86db97e3a37f0d6fc8e1e83590dd",
"status": "affected",
"version": "51363b8751a673a00ad48eea895266396d53fa52",
"versionType": "git"
},
{
"lessThan": "45bb8de8c95d8899f4b8f61bd9bceb8132af73cb",
"status": "affected",
"version": "51363b8751a673a00ad48eea895266396d53fa52",
"versionType": "git"
},
{
"lessThan": "1fc30bd4e55e2dd622d2d366cecd732c1841bbee",
"status": "affected",
"version": "51363b8751a673a00ad48eea895266396d53fa52",
"versionType": "git"
},
{
"lessThan": "cd691beafea0dd779e69e81ccc26b0ab50efcb5e",
"status": "affected",
"version": "51363b8751a673a00ad48eea895266396d53fa52",
"versionType": "git"
},
{
"lessThan": "6e792b8dd3002bbc4136745928a9605df1a72b8a",
"status": "affected",
"version": "51363b8751a673a00ad48eea895266396d53fa52",
"versionType": "git"
},
{
"lessThan": "9817369243380e287ebe5525411557eaa3aa2a79",
"status": "affected",
"version": "51363b8751a673a00ad48eea895266396d53fa52",
"versionType": "git"
},
{
"lessThan": "69554adc7a6fa04ede3ad7512321d83748e3c920",
"status": "affected",
"version": "51363b8751a673a00ad48eea895266396d53fa52",
"versionType": "git"
},
{
"lessThan": "3589d20a666caf30ad100c960a2de7de390fce88",
"status": "affected",
"version": "51363b8751a673a00ad48eea895266396d53fa52",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.4"
},
{
"lessThan": "3.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: fix locking in .getsockopt\n\nMirror iucv_sock_setsockopt() and wrap the whole switch in\nlock_sock()/release_sock(). The pre-existing SO_MSGLIMIT-only lock\nbecomes redundant and is removed.\n\nAny AF_IUCV HIPER user can potentially crash the kernel by racing\nrecvmsg() with getsockopt(SO_MSGSIZE): the SO_MSGSIZE arm dereferences\niucv-\u003ehs_dev-\u003emtu after iucv_sock_close() (called from the racing\nrecvmsg()) has set hs_dev to NULL, producing a NULL pointer dereference\noops."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached through the getsockopt(2) syscall on an AF_IUCV HIPER socket; the generic socket layer does not acquire the socket lock before calling iucv_sock_getsockopt(), so exploitation requires local access to the socket file descriptor.\nAC:L - The attacker controls both sides of the race by running concurrent getsockopt(SO_MSGSIZE) and recvmsg()/close() threads on the same socket, making the window reliably winnable without external timing luck.\nPR:L - The fix commit explicitly states any AF_IUCV HIPER user can trigger the crash, and iucv_sock_create imposes no capability or root requirement beyond creating and binding a HiperSockets AF_IUCV socket on s390.\nUI:N - Exploitation requires no action from any other user; the attacker races their own syscalls on a socket they control.\nS:U - The impact is a kernel oops or crash within the same kernel security boundary, with no cross-VM, cross-container, or IOMMU boundary crossing.\nC:H - The unlocked TOCTOU between the hs_dev NULL check and dereference races with dev_put() freeing the net_device, creating a use-after-free read whose mtu field is copied to userspace via copy_to_user.\nI:H - Use-after-free on a freed net_device structure in kernel heap memory is a memory corruption primitive that could be further leveraged for control-flow hijacking, and per kernel CVSS guidance UAF bugs warrant High integrity impact.\nA:H - Successful exploitation produces a NULL pointer dereference oops or kernel panic, causing complete loss of availability on the affected IBM Z LPAR or guest."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:04.824Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/884eb247b74d86db97e3a37f0d6fc8e1e83590dd"
},
{
"url": "https://git.kernel.org/stable/c/45bb8de8c95d8899f4b8f61bd9bceb8132af73cb"
},
{
"url": "https://git.kernel.org/stable/c/1fc30bd4e55e2dd622d2d366cecd732c1841bbee"
},
{
"url": "https://git.kernel.org/stable/c/cd691beafea0dd779e69e81ccc26b0ab50efcb5e"
},
{
"url": "https://git.kernel.org/stable/c/6e792b8dd3002bbc4136745928a9605df1a72b8a"
},
{
"url": "https://git.kernel.org/stable/c/9817369243380e287ebe5525411557eaa3aa2a79"
},
{
"url": "https://git.kernel.org/stable/c/69554adc7a6fa04ede3ad7512321d83748e3c920"
},
{
"url": "https://git.kernel.org/stable/c/3589d20a666caf30ad100c960a2de7de390fce88"
}
],
"title": "net/iucv: fix locking in .getsockopt",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64004",
"datePublished": "2026-07-19T14:56:20.895Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-08-05T12:38:04.824Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64515 (GCVE-0-2026-64515)
Vulnerability from cvelistv5
Published
2026-07-25 09:14
Modified
2026-08-05 12:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix MLE defragmentation
If either reconf or EPCS multi-link element (MLE) is contained in
a non-transmitted profile, the defragmentation routine is called
with a pointer to the defragmented copy, but the original elements.
This is incorrect for two reasons:
- if the original defragmentation was needed, it will not find the
correct data
- if the original frame is at a higher address, the parsing will
potentially overrun the heap data (though given the layout of
the buffers, only into the new defragmentation buffer, and then
it has to stop and fail once that's filled with copied data.
Fix it by tracking the container along with the pointer and in
doing so also unify the two almost identical defragmentation
routines.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/parse.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1f573e17bcb7275ddd1c8f47f46ae0faf0e902a4",
"status": "affected",
"version": "4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff",
"versionType": "git"
},
{
"lessThan": "55c479aae99b120489a432db9c717484e523dfd6",
"status": "affected",
"version": "4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff",
"versionType": "git"
},
{
"lessThan": "722b3f86df80644463d29fe5451e30a617f74500",
"status": "affected",
"version": "4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff",
"versionType": "git"
},
{
"lessThan": "a74e893f30db64cdce0fc7a96d3baa417bcd55f5",
"status": "affected",
"version": "4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/parse.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix MLE defragmentation\n\nIf either reconf or EPCS multi-link element (MLE) is contained in\na non-transmitted profile, the defragmentation routine is called\nwith a pointer to the defragmented copy, but the original elements.\n\nThis is incorrect for two reasons:\n - if the original defragmentation was needed, it will not find the\n correct data\n - if the original frame is at a higher address, the parsing will\n potentially overrun the heap data (though given the layout of\n the buffers, only into the new defragmentation buffer, and then\n it has to stop and fail once that\u0027s filled with copied data.\n\nFix it by tracking the container along with the pointer and in\ndoing so also unify the two almost identical defragmentation\nroutines."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - An attacker within radio range can inject spoofed WiFi beacons containing the crafted MBSSID profile and MLE. This is an adjacent-network attack.\nAC:L - The required EHT non-transmitted-BSS state is a vulnerable deployment condition, while the attacker controls the element layout and can repeatedly transmit trigger frames. No uncontrollable race must be won.\nPR:N - The receive path has no capability, namespace, login, or protocol-authentication requirement. Unauthenticated beacons are processed unless optional beacon protection is enabled.\nUI:N - An associated or associating station processes received beacons automatically. No contemporaneous victim action is required.\nS:U - The vulnerable parser and the affected kernel networking and link-management resources share the same security authority. There is no VM, sandbox, or IOMMU boundary crossing.\nC:H - The wrong container bound permits a nontrivial out-of-bounds read past the logical profile into heap scratch data. Although the current layout confines traversal within the allocation, the overread is not strictly limited to a few bytes, requiring C:H under the specified guidance.\nI:L - Destination bounds prevent an arbitrary-address heap write or credible control-flow primitive. Incorrectly reconstructed or truncated MLE data can nevertheless cause limited unauthorized changes to MLO link-removal or QoS state.\nA:H - Repeated unauthenticated beacon injection can keep MLE parsing and link reconfiguration failing or remove usable links. In a WiFi-dependent device this can cause complete, persistent network-service loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:42:32.369Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1f573e17bcb7275ddd1c8f47f46ae0faf0e902a4"
},
{
"url": "https://git.kernel.org/stable/c/55c479aae99b120489a432db9c717484e523dfd6"
},
{
"url": "https://git.kernel.org/stable/c/722b3f86df80644463d29fe5451e30a617f74500"
},
{
"url": "https://git.kernel.org/stable/c/a74e893f30db64cdce0fc7a96d3baa417bcd55f5"
}
],
"title": "wifi: mac80211: fix MLE defragmentation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64515",
"datePublished": "2026-07-25T09:14:42.418Z",
"dateReserved": "2026-07-19T15:36:31.793Z",
"dateUpdated": "2026-08-05T12:42:32.369Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68251 (GCVE-0-2026-68251)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit c17a508a7d652da3728f8bbc481bfffe96d65a87)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e7575e1e654a7ec8cc5e170f6dc30c81c708ddda",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "2eb06c88426b6c8de602c608959f3a56ac51861e",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "e7f31c9a61533062a704f90b9f63064045249693",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "51fd52087165180967cf7d5ee99badee7e172ea0",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "9df8a7f09e305249872b536555793b28e77b7de9",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "ec42c96c322e5cc48099ab5e67b5cbe236cb1949",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit c17a508a7d652da3728f8bbc481bfffe96d65a87)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:23.355Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e7575e1e654a7ec8cc5e170f6dc30c81c708ddda"
},
{
"url": "https://git.kernel.org/stable/c/2eb06c88426b6c8de602c608959f3a56ac51861e"
},
{
"url": "https://git.kernel.org/stable/c/e7f31c9a61533062a704f90b9f63064045249693"
},
{
"url": "https://git.kernel.org/stable/c/51fd52087165180967cf7d5ee99badee7e172ea0"
},
{
"url": "https://git.kernel.org/stable/c/9df8a7f09e305249872b536555793b28e77b7de9"
},
{
"url": "https://git.kernel.org/stable/c/ec42c96c322e5cc48099ab5e67b5cbe236cb1949"
}
],
"title": "drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68251",
"datePublished": "2026-08-10T12:01:17.402Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:23.355Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68331 (GCVE-0-2026-68331)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-eth: put MAC endpoint device on disconnect
fsl_mc_get_endpoint() returns the MAC endpoint device with a reference
taken through device_find_child(). The Ethernet connect path stores that
device in mac->mc_dev and keeps it for the lifetime of the connected MAC
object.
However, the disconnect path only disconnects and closes the MAC before
freeing the dpaa2_mac object. It does not drop the endpoint device
reference stored in mac->mc_dev, so every successful connect leaks that
device reference when the MAC is later disconnected.
Drop the endpoint device reference after closing the MAC and before
freeing the dpaa2_mac object.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6b6ffdb9ca4547a3c4c274aa3e25b6c68dbc62e1",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "1974127776da46a000c61f36d4946799ea6d4f51",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "915012e923316b8b5d5bf8fc771617b47bd7572d",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "e23e4a3b9dfd893469c731318d409cdf04fb1ddf",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "f112df0744e2d77baa68eeebb860021bbaaa022a",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "a3cecf169cc652b558d08661bb6ce55e4c933ec0",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "b4b201cc93ff70150853aba03e14d314d1980ca0",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpaa2-eth: put MAC endpoint device on disconnect\n\nfsl_mc_get_endpoint() returns the MAC endpoint device with a reference\ntaken through device_find_child(). The Ethernet connect path stores that\ndevice in mac-\u003emc_dev and keeps it for the lifetime of the connected MAC\nobject.\n\nHowever, the disconnect path only disconnects and closes the MAC before\nfreeing the dpaa2_mac object. It does not drop the endpoint device\nreference stored in mac-\u003emc_dev, so every successful connect leaks that\ndevice reference when the MAC is later disconnected.\n\nDrop the endpoint device reference after closing the MAC and before\nfreeing the dpaa2_mac object."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:28.174Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6b6ffdb9ca4547a3c4c274aa3e25b6c68dbc62e1"
},
{
"url": "https://git.kernel.org/stable/c/1974127776da46a000c61f36d4946799ea6d4f51"
},
{
"url": "https://git.kernel.org/stable/c/915012e923316b8b5d5bf8fc771617b47bd7572d"
},
{
"url": "https://git.kernel.org/stable/c/e23e4a3b9dfd893469c731318d409cdf04fb1ddf"
},
{
"url": "https://git.kernel.org/stable/c/f112df0744e2d77baa68eeebb860021bbaaa022a"
},
{
"url": "https://git.kernel.org/stable/c/a3cecf169cc652b558d08661bb6ce55e4c933ec0"
},
{
"url": "https://git.kernel.org/stable/c/b4b201cc93ff70150853aba03e14d314d1980ca0"
}
],
"title": "dpaa2-eth: put MAC endpoint device on disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68331",
"datePublished": "2026-08-10T12:03:07.529Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:28.174Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53246 (GCVE-0-2026-53246)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-08-05 12:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
When a listening SCTP server processes a COOKIE_ECHO chunk, the cached
peer INIT chunk embedded after the cookie is parsed and its parameters
are later walked by sctp_process_init() using sctp_walk_params().
However, the chunk header length of this cached INIT chunk was not
validated against the remaining buffer in the COOKIE_ECHO payload. If
the length field is inflated, the parameter walk can run beyond the
actual received data, leading to out-of-bounds reads and potential
memory corruption during later parameter handling (e.g. STATE_COOKIE
processing and kmemdup() copies).
Add a bounds check in sctp_unpack_cookie() to ensure the cached INIT
chunk length does not exceed the available data in the COOKIE_ECHO
buffer before it is used.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cc272185c9a9a4b7febc2de52eeaa3d00f19091e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "edccbf3d63b0a3362bc916ea72edacc1e1ca456a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0861615c28de668669d748ef4eb913ea9262d13b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate cached peer INIT chunk length in COOKIE_ECHO processing\n\nWhen a listening SCTP server processes a COOKIE_ECHO chunk, the cached\npeer INIT chunk embedded after the cookie is parsed and its parameters\nare later walked by sctp_process_init() using sctp_walk_params().\n\nHowever, the chunk header length of this cached INIT chunk was not\nvalidated against the remaining buffer in the COOKIE_ECHO payload. If\nthe length field is inflated, the parameter walk can run beyond the\nactual received data, leading to out-of-bounds reads and potential\nmemory corruption during later parameter handling (e.g. STATE_COOKIE\nprocessing and kmemdup() copies).\n\nAdd a bounds check in sctp_unpack_cookie() to ensure the cached INIT\nchunk length does not exceed the available data in the COOKIE_ECHO\nbuffer before it is used."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable COOKIE_ECHO processing is reached by remote SCTP packets delivered through the IPv4/IPv6 SCTP protocol handlers to a listening SCTP endpoint.\nAC:L - In a deployment with SCTP cookie HMAC disabled, the attacker can obtain a cookie through the normal INIT/INIT_ACK exchange, modify the cached INIT length, and send the forged COOKIE_ECHO without races or conditions outside attacker control.\nPR:N - The path is pre-authentication network protocol handling for a listening SCTP server; no local account or SCTP authentication is required when cookie HMAC is disabled.\nUI:N - Exploitation only requires sending SCTP handshake packets to the target listener and does not require victim user action.\nS:U - The impact is within the Linux kernel/network stack security authority and does not cross a separate boundary such as guest-to-host or IOMMU isolation.\nC:H - The inflated cached INIT length drives out-of-bounds parameter walking and attacker-sized kmemdup() reads beyond the received skb, which can expose kernel memory.\nI:H - The bug is kernel memory-safety corruption during nested parameter handling, and the higher-severity choice is appropriate because attacker-controlled parsing and copies beyond the valid buffer can corrupt kernel association state and plausibly support stronger primitives.\nA:H - The out-of-bounds reads and large attacker-controlled copies can trigger kernel faults, KASAN splats, allocation failure paths, or repeated remote crashes of SCTP processing."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:34:30.435Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cc272185c9a9a4b7febc2de52eeaa3d00f19091e"
},
{
"url": "https://git.kernel.org/stable/c/edccbf3d63b0a3362bc916ea72edacc1e1ca456a"
},
{
"url": "https://git.kernel.org/stable/c/0861615c28de668669d748ef4eb913ea9262d13b"
}
],
"title": "sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53246",
"datePublished": "2026-06-25T08:39:39.896Z",
"dateReserved": "2026-06-09T07:44:35.394Z",
"dateUpdated": "2026-08-05T12:34:30.435Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43125 (GCVE-0-2026-43125)
Vulnerability from cvelistv5
Published
2026-05-06 11:27
Modified
2026-08-25 12:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dlm: validate length in dlm_search_rsb_tree
The len parameter in dlm_dump_rsb_name() is not validated and comes
from network messages. When it exceeds DLM_RESNAME_MAXLEN, it can
cause out-of-bounds write in dlm_search_rsb_tree().
Add length validation to prevent potential buffer overflow.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_extras_rt_els:7"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:3.10.0-1160.155.1.rt56.1307.el7",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_els:7"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:3.10.0-1160.154.1.el7",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:8::nfv"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.132.1.rt7.473.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.132.1.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_aus:8.6"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-372.198.1.el8_6",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_eus_long_life:8.6"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-372.198.1.el8_6",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_tus:8.8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-477.150.1.el8_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_e4s:8.8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-477.150.1.el8_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_e4s:8.8"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:9",
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-687.15.1.el9_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_e4s:9.2"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-284.178.1.el9_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_e4s:9.2::nfv"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-284.178.1.rt14.463.el9_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_e4s:9.2"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_e4s:9.4"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-427.136.1.el9_4",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_e4s:9.4"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_eus:9.6"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.6 Extended Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-570.125.1.el9_6",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_eus:9.6"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 9.6 Extended Update Support",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unknown",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-05-06T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel\u0027s Distributed Lock Manager (dlm) module. An attacker could send specially crafted network messages with an oversized length parameter to the dlm_dump_rsb_name() function. This lack of validation can lead to an out-of-bounds write in the dlm_search_rsb_tree() function, potentially causing a buffer overflow. This vulnerability could allow for denial of service or, in some cases, arbitrary code execution."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Important"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-130",
"description": "Improper Handling of Length Parameter Inconsistency",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T12:05:44.813Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-43125"
},
{
"name": "RHBZ#2467234",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467234"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43125.json"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:35844"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:41236"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:34095"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:36767"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:34094"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:25217"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:25121"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:55762"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:59091"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:33899"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:35863"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:55761"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:55837"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:56224"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:56225"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:55763"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:25120"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:33900"
}
],
"solutions": [
{
"lang": "en",
"value": "RHSA-2026:35844: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS)"
},
{
"lang": "en",
"value": "RHSA-2026:41236: Red Hat Enterprise Linux for Real Time (v. 7 ELS)"
},
{
"lang": "en",
"value": "RHSA-2026:34095: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2)"
},
{
"lang": "en",
"value": "RHSA-2026:36767: Red Hat Enterprise Linux AppStream E4S (v.9.4), Red Hat Enterprise Linux BaseOS E4S (v.9.4), Red Hat Enterprise Linux Real Time E4S (v.9.4), Red Hat Enterprise Linux Real Time for NFV E4S (v.9.4)"
},
{
"lang": "en",
"value": "RHSA-2026:34094: Red Hat CodeReady Linux Builder EUS (v.9.6), Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux BaseOS EUS (v.9.6), Red Hat Enterprise Linux Real Time EUS (v.9.6), Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6)"
},
{
"lang": "en",
"value": "RHSA-2026:25217: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9)"
},
{
"lang": "en",
"value": "RHSA-2026:25121: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:55762: Red Hat Enterprise Linux BaseOS (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:59091: Red Hat Enterprise Linux BaseOS AUS (v.8.4), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)"
},
{
"lang": "en",
"value": "RHSA-2026:33899: Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)"
},
{
"lang": "en",
"value": "RHSA-2026:35863: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8)"
},
{
"lang": "en",
"value": "RHSA-2026:55761: Red Hat Enterprise Linux BaseOS E4S (v.8.8)"
},
{
"lang": "en",
"value": "RHSA-2026:55837: Red Hat Enterprise Linux BaseOS E4S (v.9.2)"
},
{
"lang": "en",
"value": "RHSA-2026:56224: Red Hat Enterprise Linux BaseOS E4S (v.9.4)"
},
{
"lang": "en",
"value": "RHSA-2026:56225: Red Hat Enterprise Linux BaseOS EUS (v.9.6)"
},
{
"lang": "en",
"value": "RHSA-2026:55763: Red Hat Enterprise Linux BaseOS (v. 9)"
},
{
"lang": "en",
"value": "RHSA-2026:25120: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:33900: Red Hat Enterprise Linux Real Time E4S (v.9.2), Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-05-06T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-05-06T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: dlm: validate length in dlm_search_rsb_tree",
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/dlm/lock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "67288113c5e6cf9e659b4065c0ed6f16100e0c71",
"status": "affected",
"version": "7210cb7a72a22303cdb225bd1aea28697a17bbae",
"versionType": "git"
},
{
"lessThan": "082083c9fbd99422a0370fe2102144a231c9f5d6",
"status": "affected",
"version": "7210cb7a72a22303cdb225bd1aea28697a17bbae",
"versionType": "git"
},
{
"lessThan": "5f053a2e7209d326cbbc07738fa6d6893d307438",
"status": "affected",
"version": "7210cb7a72a22303cdb225bd1aea28697a17bbae",
"versionType": "git"
},
{
"lessThan": "080e5563f878c64e697b89e7439d730d0daad882",
"status": "affected",
"version": "7210cb7a72a22303cdb225bd1aea28697a17bbae",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/dlm/lock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.4"
},
{
"lessThan": "3.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "3.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: validate length in dlm_search_rsb_tree\n\nThe len parameter in dlm_dump_rsb_name() is not validated and comes\nfrom network messages. When it exceeds DLM_RESNAME_MAXLEN, it can\ncause out-of-bounds write in dlm_search_rsb_tree().\n\nAdd length validation to prevent potential buffer overflow."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable path is reached by DLM recovery messages received over the kernel DLM TCP/SCTP lowcomms transport from a remote cluster peer. Although the peer address must match configured cluster membership, the bug is triggered by network protocol data delivered to the target kernel.\nAC:L - A remote peer that can send DLM recovery traffic controls the malformed RCOM_LOOKUP packet, including the special debug rc_id and oversized length/name payload. The recovery-state gate is a normal DLM condition that a participating peer can plausibly induce or target, so exploitation does not depend on conditions outside attacker control.\nPR:N - The vulnerable receive path does not require credentials or privileges on the target system before parsing the packet. Cluster peer/source-address admission is not a privilege on the vulnerable host, and there is no DLM authentication check before the oversized name reaches the copy.\nUI:N - No victim user action is required once the target DLM lockspace is active and receiving cluster traffic. The attacker sends the malformed recovery message directly.\nS:U - The impact is compromise or crash of the target kernel within the same security authority. This is not a VM escape, IOMMU bypass, or other cross-scope boundary.\nC:H - The bug is a network-controlled stack buffer overflow in the kernel, copying up to socket-buffer-sized attacker data into a 64-byte resource-name key. Such memory corruption is defensibly exploitable for kernel information disclosure as part of code execution or memory disclosure primitives.\nI:H - The oversized memcpy can corrupt the kernel stack, including control data, from attacker-controlled network bytes. This supports arbitrary kernel memory modification or code execution in the highest reasonable scenario.\nA:H - Even without reliable code execution, the stack overflow can corrupt kernel control state and readily crash or panic the system. The malformed packet can be sent remotely whenever the vulnerable DLM receive path is reachable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:26:06.027Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/67288113c5e6cf9e659b4065c0ed6f16100e0c71"
},
{
"url": "https://git.kernel.org/stable/c/082083c9fbd99422a0370fe2102144a231c9f5d6"
},
{
"url": "https://git.kernel.org/stable/c/5f053a2e7209d326cbbc07738fa6d6893d307438"
},
{
"url": "https://git.kernel.org/stable/c/080e5563f878c64e697b89e7439d730d0daad882"
}
],
"title": "dlm: validate length in dlm_search_rsb_tree",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43125",
"datePublished": "2026-05-06T11:27:10.903Z",
"dateReserved": "2026-05-01T14:12:55.988Z",
"dateUpdated": "2026-08-25T12:05:44.813Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64408 (GCVE-0-2026-64408)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: bnep: pin L2CAP connection during netdev registration
bnep_add_connection() reads the L2CAP connection without holding the
channel lock, then passes its HCI device to register_netdev(). Controller
teardown can clear and release that connection concurrently, leaving the
network device registration path to dereference a freed parent device.
Take a reference to the L2CAP connection while holding the channel lock.
Retain it until register_netdev() has taken the parent device reference.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 65f53e9802dbfae0e5758a91793c3f5f8bece49b Version: 65f53e9802dbfae0e5758a91793c3f5f8bece49b Version: 65f53e9802dbfae0e5758a91793c3f5f8bece49b Version: 65f53e9802dbfae0e5758a91793c3f5f8bece49b Version: 65f53e9802dbfae0e5758a91793c3f5f8bece49b Version: 65f53e9802dbfae0e5758a91793c3f5f8bece49b Version: 65f53e9802dbfae0e5758a91793c3f5f8bece49b Version: 65f53e9802dbfae0e5758a91793c3f5f8bece49b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/bnep/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "390b5db3ff8745187f094c4e915663b7b1f98944",
"status": "affected",
"version": "65f53e9802dbfae0e5758a91793c3f5f8bece49b",
"versionType": "git"
},
{
"lessThan": "46a88784c4c9b96954dd86f747ce93f65efa1302",
"status": "affected",
"version": "65f53e9802dbfae0e5758a91793c3f5f8bece49b",
"versionType": "git"
},
{
"lessThan": "551ae773ec64045b4e72099132654887e0270bcc",
"status": "affected",
"version": "65f53e9802dbfae0e5758a91793c3f5f8bece49b",
"versionType": "git"
},
{
"lessThan": "ae215c5b6422d8eda443b861b124bd1be6969c31",
"status": "affected",
"version": "65f53e9802dbfae0e5758a91793c3f5f8bece49b",
"versionType": "git"
},
{
"lessThan": "df22adc7eafc22e651561813c11dc51a796b12ee",
"status": "affected",
"version": "65f53e9802dbfae0e5758a91793c3f5f8bece49b",
"versionType": "git"
},
{
"lessThan": "a6b22dbd80926556290ad2243be25218d6956a19",
"status": "affected",
"version": "65f53e9802dbfae0e5758a91793c3f5f8bece49b",
"versionType": "git"
},
{
"lessThan": "563a8573047182f550b1e1e030615755cd8c41da",
"status": "affected",
"version": "65f53e9802dbfae0e5758a91793c3f5f8bece49b",
"versionType": "git"
},
{
"lessThan": "bb067a99a0356196c0b89a95721985485ebce5a5",
"status": "affected",
"version": "65f53e9802dbfae0e5758a91793c3f5f8bece49b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/bnep/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.13"
},
{
"lessThan": "3.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: bnep: pin L2CAP connection during netdev registration\n\nbnep_add_connection() reads the L2CAP connection without holding the\nchannel lock, then passes its HCI device to register_netdev(). Controller\nteardown can clear and release that connection concurrently, leaving the\nnetwork device registration path to dereference a freed parent device.\n\nTake a reference to the L2CAP connection while holding the channel lock.\nRetain it until register_netdev() has taken the parent device reference."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - An adjacent Bluetooth peer can initiate a BNEP/PAN connection that causes privileged bluetoothd to issue BNEPCONNADD, then tear down the ACL link during netdev registration. Exploitation therefore requires Bluetooth radio adjacency.\nAC:L - The peer controls both the connection setup that triggers the ioctl and the competing disconnect, and can repeat attempts until the lifetime window is hit. No condition beyond the attacker\u0027s practical control is required.\nPR:N - The adjacent peer needs no Linux credentials or capabilities because root bluetoothd performs the CAP_NET_ADMIN ioctl on its behalf in an enabled, auto-authorized PAN deployment. The direct ioctl requires CAP_NET_ADMIN in the initial user namespace, but the adjacent path does not.\nUI:N - An enabled PAN service can automatically accept or pre-authorize connections, after which setup and teardown require no victim action. Prior service configuration is not user interaction during exploitation.\nS:U - The memory corruption occurs in the host kernel and compromises resources governed by that same kernel security authority. It does not cross a VM, IOMMU, or comparable security boundary.\nC:H - The stale parent points into a freed hci_conn allocation, and reclaiming that use-after-free object can enable disclosure of arbitrary kernel memory. Confidentiality impact is therefore High.\nI:H - device_add() calls get_device() on the freed parent, producing a refcount write into reclaimed memory and potentially further device-list corruption. The use-after-free can support arbitrary kernel-memory corruption or control-flow hijacking.\nA:H - The use-after-free can cause a kernel oops, panic, or corrupted device hierarchy during netdev registration. An adjacent peer can repeatedly initiate and terminate connections to crash the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:06.785Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/390b5db3ff8745187f094c4e915663b7b1f98944"
},
{
"url": "https://git.kernel.org/stable/c/46a88784c4c9b96954dd86f747ce93f65efa1302"
},
{
"url": "https://git.kernel.org/stable/c/551ae773ec64045b4e72099132654887e0270bcc"
},
{
"url": "https://git.kernel.org/stable/c/ae215c5b6422d8eda443b861b124bd1be6969c31"
},
{
"url": "https://git.kernel.org/stable/c/df22adc7eafc22e651561813c11dc51a796b12ee"
},
{
"url": "https://git.kernel.org/stable/c/a6b22dbd80926556290ad2243be25218d6956a19"
},
{
"url": "https://git.kernel.org/stable/c/563a8573047182f550b1e1e030615755cd8c41da"
},
{
"url": "https://git.kernel.org/stable/c/bb067a99a0356196c0b89a95721985485ebce5a5"
}
],
"title": "Bluetooth: bnep: pin L2CAP connection during netdev registration",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64408",
"datePublished": "2026-07-25T08:50:49.807Z",
"dateReserved": "2026-07-19T15:36:31.786Z",
"dateUpdated": "2026-08-17T04:55:06.785Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64495 (GCVE-0-2026-64495)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iio: gyro: bmg160: bail out when bandwidth/filter is not in table
bmg160_get_filter() walks bmg160_samp_freq_table[] looking for the entry
matching the bw_bits value read from the chip:
for (i = 0; i < ARRAY_SIZE(bmg160_samp_freq_table); ++i) {
if (bmg160_samp_freq_table[i].bw_bits == bw_bits)
break;
}
*val = bmg160_samp_freq_table[i].filter;
If no entry matches, i ends up equal to the array size and the next line
reads one slot past the end. bmg160_set_filter() has the same shape, driven
by 'val' instead of bw_bits.
smatch flags both:
drivers/iio/gyro/bmg160_core.c:204 bmg160_get_filter() error:
buffer overflow 'bmg160_samp_freq_table' 7 <= 7
drivers/iio/gyro/bmg160_core.c:222 bmg160_set_filter() error:
buffer overflow 'bmg160_samp_freq_table' 7 <= 7
Return -EINVAL when no entry matches.
The set_filter() path is reachable from userspace via the sysfs
in_anglvel_filter_low_pass_3db_frequency interface, so userspace can
trivially trigger the out-of-bounds read with a value that is not in
bmg160_samp_freq_table[].filter.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc Version: 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc Version: 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc Version: 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc Version: 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc Version: 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc Version: 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc Version: 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iio/gyro/bmg160_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1dc3a833be11e5d503038e3c701745fd0e03903c",
"status": "affected",
"version": "22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc",
"versionType": "git"
},
{
"lessThan": "77e56ebb1786f4296afd5fa46975a989b285ae65",
"status": "affected",
"version": "22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc",
"versionType": "git"
},
{
"lessThan": "029481cddb98697716f4bf3021d035eaf2ca0e1f",
"status": "affected",
"version": "22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc",
"versionType": "git"
},
{
"lessThan": "8d202515baea4e2e3be448d1590099af28f2346d",
"status": "affected",
"version": "22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc",
"versionType": "git"
},
{
"lessThan": "d85ee50f58dd83fe74f6d0bf8bd345c657b216e8",
"status": "affected",
"version": "22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc",
"versionType": "git"
},
{
"lessThan": "7bbf02b63961fc1768c9c654392c11f2077d4c59",
"status": "affected",
"version": "22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc",
"versionType": "git"
},
{
"lessThan": "6c8675468862161d1c59130266852b66867d3861",
"status": "affected",
"version": "22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc",
"versionType": "git"
},
{
"lessThan": "8320c77e67382d5d55d77043a5f60a867d408a2b",
"status": "affected",
"version": "22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iio/gyro/bmg160_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"lessThan": "3.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: gyro: bmg160: bail out when bandwidth/filter is not in table\n\nbmg160_get_filter() walks bmg160_samp_freq_table[] looking for the entry\nmatching the bw_bits value read from the chip:\n\n\tfor (i = 0; i \u003c ARRAY_SIZE(bmg160_samp_freq_table); ++i) {\n\t\tif (bmg160_samp_freq_table[i].bw_bits == bw_bits)\n\t\t\tbreak;\n\t}\n\t*val = bmg160_samp_freq_table[i].filter;\n\nIf no entry matches, i ends up equal to the array size and the next line\nreads one slot past the end. bmg160_set_filter() has the same shape, driven\nby \u0027val\u0027 instead of bw_bits.\n\nsmatch flags both:\n\n drivers/iio/gyro/bmg160_core.c:204 bmg160_get_filter() error:\n buffer overflow \u0027bmg160_samp_freq_table\u0027 7 \u003c= 7\n drivers/iio/gyro/bmg160_core.c:222 bmg160_set_filter() error:\n buffer overflow \u0027bmg160_samp_freq_table\u0027 7 \u003c= 7\n\nReturn -EINVAL when no entry matches.\n\nThe set_filter() path is reachable from userspace via the sysfs\nin_anglvel_filter_low_pass_3db_frequency interface, so userspace can\ntrivially trigger the out-of-bounds read with a value that is not in\nbmg160_samp_freq_table[].filter."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:43.712Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1dc3a833be11e5d503038e3c701745fd0e03903c"
},
{
"url": "https://git.kernel.org/stable/c/77e56ebb1786f4296afd5fa46975a989b285ae65"
},
{
"url": "https://git.kernel.org/stable/c/029481cddb98697716f4bf3021d035eaf2ca0e1f"
},
{
"url": "https://git.kernel.org/stable/c/8d202515baea4e2e3be448d1590099af28f2346d"
},
{
"url": "https://git.kernel.org/stable/c/d85ee50f58dd83fe74f6d0bf8bd345c657b216e8"
},
{
"url": "https://git.kernel.org/stable/c/7bbf02b63961fc1768c9c654392c11f2077d4c59"
},
{
"url": "https://git.kernel.org/stable/c/6c8675468862161d1c59130266852b66867d3861"
},
{
"url": "https://git.kernel.org/stable/c/8320c77e67382d5d55d77043a5f60a867d408a2b"
}
],
"title": "iio: gyro: bmg160: bail out when bandwidth/filter is not in table",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64495",
"datePublished": "2026-07-25T08:51:52.468Z",
"dateReserved": "2026-07-19T15:36:31.792Z",
"dateUpdated": "2026-08-17T04:56:43.712Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68281 (GCVE-0-2026-68281)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: Count paired job fence as dependency in prepare_job()
The DRM scheduler's prepare_job() callback counts the remaining
non-signaled native dependencies for a job, preventing job submission
until those (plus job data and fence update) can fit in the job queue's
CCCB.
This means checking which dependencies can be waited upon in the
firmware, i.e. whether they are backed by a UFO object, i.e. whether
their drm_sched_fence::parent has been assigned to a
pvr_queue_fence::base fence. That happens when the job owning the fence
is submitted to the firmware.
Paired geometry and fragment jobs are submitted at the same time, which
means the dependency between them can't be checked this way before
submission.
Update job_count_remaining_native_deps() to take into account the
dependency between paired jobs.
This fixes cases where prepare_job() underestimated the space left in
an almost full fragment CCCB, wrongly unblocking run_job(), which then
returned early without writing the full sequence of commands to the
CCCB.
The above lead to kernel warnings such as the following and potentially
job timeouts (depending on waiters on the missing commands):
[ 375.702979] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#1: kworker/u16:3/47
[ 375.703160] Modules linked in:
[ 375.703571] CPU: 1 UID: 0 PID: 47 Comm: kworker/u16:3 Tainted: G W 7.0.0-rc2-g817eb6b11ad5 #40 PREEMPT
[ 375.703613] Tainted: [W]=WARN
[ 375.703627] Hardware name: Texas Instruments AM625 SK (DT)
[ 375.703645] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]
[ 375.703741] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 375.703764] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]
[ 375.703847] lr : pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]
[ 375.703921] sp : ffff800084a97650
[ 375.703934] x29: ffff800084a97740 x28: 0000000000000958 x27: ffff80008565d000
[ 375.703979] x26: 0000000000000030 x25: ffff800084a97680 x24: 0000000000001000
[ 375.704017] x23: ffff800084a97820 x22: 1ffff00010952ecc x21: 0000000000000008
[ 375.704056] x20: 00000000000006a8 x19: ffff00002ff7da88 x18: 0000000000000000
[ 375.704093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000
[ 375.704132] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000
[ 375.704168] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3
[ 375.704206] x8 : 00000000f2f2f200 x7 : ffff700010952ecc x6 : 0000000000000008
[ 375.704243] x5 : 0000000000000000 x4 : 1ffff00010acba00 x3 : 0000000000000000
[ 375.704279] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f
[ 375.704317] Call trace:
[ 375.704331] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)
[ 375.704411] pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]
[ 375.704487] pvr_queue_run_job+0x3a4/0x990 [powervr]
[ 375.704562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched]
[ 375.704623] process_one_work+0x520/0x1288
[ 375.704658] worker_thread+0x3f0/0xb3c
[ 375.704680] kthread+0x334/0x3d8
[ 375.704706] ret_from_fork+0x10/0x20
[ 375.704736] ---[ end trace 0000000000000000 ]---
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "02b0da249c8f78d2bbf9f498bbd371c66142b0af",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "943fa73ea0efa335d9c1800fcfac47915de4ff89",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "a673171502e87acb5a9e2923f4cf9dce521fd05e",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "9cd74f935306cd857f46686975c43383e1d95f94",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Count paired job fence as dependency in prepare_job()\n\nThe DRM scheduler\u0027s prepare_job() callback counts the remaining\nnon-signaled native dependencies for a job, preventing job submission\nuntil those (plus job data and fence update) can fit in the job queue\u0027s\nCCCB.\n\nThis means checking which dependencies can be waited upon in the\nfirmware, i.e. whether they are backed by a UFO object, i.e. whether\ntheir drm_sched_fence::parent has been assigned to a\npvr_queue_fence::base fence. That happens when the job owning the fence\nis submitted to the firmware.\n\nPaired geometry and fragment jobs are submitted at the same time, which\nmeans the dependency between them can\u0027t be checked this way before\nsubmission.\n\nUpdate job_count_remaining_native_deps() to take into account the\ndependency between paired jobs.\n\nThis fixes cases where prepare_job() underestimated the space left in\nan almost full fragment CCCB, wrongly unblocking run_job(), which then\nreturned early without writing the full sequence of commands to the\nCCCB.\n\nThe above lead to kernel warnings such as the following and potentially\njob timeouts (depending on waiters on the missing commands):\n\n [ 375.702979] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#1: kworker/u16:3/47\n [ 375.703160] Modules linked in:\n [ 375.703571] CPU: 1 UID: 0 PID: 47 Comm: kworker/u16:3 Tainted: G W 7.0.0-rc2-g817eb6b11ad5 #40 PREEMPT\n [ 375.703613] Tainted: [W]=WARN\n [ 375.703627] Hardware name: Texas Instruments AM625 SK (DT)\n [ 375.703645] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]\n [ 375.703741] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n [ 375.703764] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]\n [ 375.703847] lr : pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]\n [ 375.703921] sp : ffff800084a97650\n [ 375.703934] x29: ffff800084a97740 x28: 0000000000000958 x27: ffff80008565d000\n [ 375.703979] x26: 0000000000000030 x25: ffff800084a97680 x24: 0000000000001000\n [ 375.704017] x23: ffff800084a97820 x22: 1ffff00010952ecc x21: 0000000000000008\n [ 375.704056] x20: 00000000000006a8 x19: ffff00002ff7da88 x18: 0000000000000000\n [ 375.704093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000\n [ 375.704132] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n [ 375.704168] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3\n [ 375.704206] x8 : 00000000f2f2f200 x7 : ffff700010952ecc x6 : 0000000000000008\n [ 375.704243] x5 : 0000000000000000 x4 : 1ffff00010acba00 x3 : 0000000000000000\n [ 375.704279] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f\n [ 375.704317] Call trace:\n [ 375.704331] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)\n [ 375.704411] pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]\n [ 375.704487] pvr_queue_run_job+0x3a4/0x990 [powervr]\n [ 375.704562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched]\n [ 375.704623] process_one_work+0x520/0x1288\n [ 375.704658] worker_thread+0x3f0/0xb3c\n [ 375.704680] kthread+0x334/0x3d8\n [ 375.704706] ret_from_fork+0x10/0x20\n [ 375.704736] ---[ end trace 0000000000000000 ]---"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:15.934Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/02b0da249c8f78d2bbf9f498bbd371c66142b0af"
},
{
"url": "https://git.kernel.org/stable/c/943fa73ea0efa335d9c1800fcfac47915de4ff89"
},
{
"url": "https://git.kernel.org/stable/c/a673171502e87acb5a9e2923f4cf9dce521fd05e"
},
{
"url": "https://git.kernel.org/stable/c/9cd74f935306cd857f46686975c43383e1d95f94"
}
],
"title": "drm/imagination: Count paired job fence as dependency in prepare_job()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68281",
"datePublished": "2026-08-10T12:02:13.103Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-17T05:02:15.934Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-45897 (GCVE-0-2026-45897)
Vulnerability from cvelistv5
Published
2026-05-27 12:17
Modified
2026-08-03 09:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_counter: serialize reset with spinlock
Add a global static spinlock to serialize counter fetch+reset
operations, preventing concurrent dump-and-reset from underrunning
values.
The lock is taken before fetching the total so that two parallel
resets cannot both read the same counter values and then both
subtract them.
A global lock is used for simplicity since resets are infrequent.
If this becomes a bottleneck, it can be replaced with a per-net
lock later.
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: fb1adb05ea87b6149e65a31e511756c4f470d0cd Version: f123293db16dcd0cd81b246ae60e6362f0025d0a Version: 6.1.107 ≤ Version: 6.6.48 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_counter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "48cf7918d10c66cb6b05226fa3fa5daf0c891089",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"lessThan": "cd968dcdec6aee79a2d399e4f6e0eca63c3b45e1",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"lessThan": "0cdc6d5a26f2d1f7f15a43526841b679445c32e2",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"lessThan": "779c60a5190c42689534172f4b49e927c9959e4e",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"status": "affected",
"version": "fb1adb05ea87b6149e65a31e511756c4f470d0cd",
"versionType": "git"
},
{
"status": "affected",
"version": "f123293db16dcd0cd81b246ae60e6362f0025d0a",
"versionType": "git"
},
{
"lessThan": "6.2",
"status": "affected",
"version": "6.1.107",
"versionType": "semver"
},
{
"lessThan": "6.7",
"status": "affected",
"version": "6.6.48",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_counter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.1.107",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.6.48",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_counter: serialize reset with spinlock\n\nAdd a global static spinlock to serialize counter fetch+reset\noperations, preventing concurrent dump-and-reset from underrunning\nvalues.\n\nThe lock is taken before fetching the total so that two parallel\nresets cannot both read the same counter values and then both\nsubtract them.\n\nA global lock is used for simplicity since resets are infrequent.\nIf this becomes a bottleneck, it can be replaced with a per-net\nlock later."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-03T09:32:30.454Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/48cf7918d10c66cb6b05226fa3fa5daf0c891089"
},
{
"url": "https://git.kernel.org/stable/c/cd968dcdec6aee79a2d399e4f6e0eca63c3b45e1"
},
{
"url": "https://git.kernel.org/stable/c/0cdc6d5a26f2d1f7f15a43526841b679445c32e2"
},
{
"url": "https://git.kernel.org/stable/c/779c60a5190c42689534172f4b49e927c9959e4e"
}
],
"title": "netfilter: nft_counter: serialize reset with spinlock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-45897",
"datePublished": "2026-05-27T12:17:07.038Z",
"dateReserved": "2026-05-13T15:03:33.083Z",
"dateUpdated": "2026-08-03T09:32:30.454Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-31531 (GCVE-0-2026-31531)
Vulnerability from cvelistv5
Published
2026-04-23 11:12
Modified
2026-05-11 22:10
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()
When querying a nexthop object via RTM_GETNEXTHOP, the kernel currently
allocates a fixed-size skb using NLMSG_GOODSIZE. While sufficient for
single nexthops and small Equal-Cost Multi-Path groups, this fixed
allocation fails for large nexthop groups like 512 nexthops.
This results in the following warning splat:
WARNING: net/ipv4/nexthop.c:3395 at rtm_get_nexthop+0x176/0x1c0, CPU#20: rep/4608
[...]
RIP: 0010:rtm_get_nexthop (net/ipv4/nexthop.c:3395)
[...]
Call Trace:
<TASK>
rtnetlink_rcv_msg (net/core/rtnetlink.c:6989)
netlink_rcv_skb (net/netlink/af_netlink.c:2550)
netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)
netlink_sendmsg (net/netlink/af_netlink.c:1894)
____sys_sendmsg (net/socket.c:721 net/socket.c:736 net/socket.c:2585)
___sys_sendmsg (net/socket.c:2641)
__sys_sendmsg (net/socket.c:2671)
do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
</TASK>
Fix this by allocating the size dynamically using nh_nlmsg_size() and
using nlmsg_new(), this is consistent with nexthop_notify() behavior. In
addition, adjust nh_nlmsg_size_grp() so it calculates the size needed
based on flags passed. While at it, also add the size of NHA_FDB for
nexthop group size calculation as it was missing too.
This cannot be reproduced via iproute2 as the group size is currently
limited and the command fails as follows:
addattr_l ERROR: message exceeded bound of 1048
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/nexthop.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "615517f3f8d53b0cf41507c7599971e17adfdfa5",
"status": "affected",
"version": "430a049190de3c9e219f43084de9f1122da04570",
"versionType": "git"
},
{
"lessThan": "40bd39e383a0478fd5c221f393df05fd9d70cfbc",
"status": "affected",
"version": "430a049190de3c9e219f43084de9f1122da04570",
"versionType": "git"
},
{
"lessThan": "635038fe19db391117e66b46bdc2b6e447ac801d",
"status": "affected",
"version": "430a049190de3c9e219f43084de9f1122da04570",
"versionType": "git"
},
{
"lessThan": "14cf0cd35361f4e94824bf8a42f72713d7702a73",
"status": "affected",
"version": "430a049190de3c9e219f43084de9f1122da04570",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/nexthop.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.83",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.24",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.83",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.24",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.14",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()\n\nWhen querying a nexthop object via RTM_GETNEXTHOP, the kernel currently\nallocates a fixed-size skb using NLMSG_GOODSIZE. While sufficient for\nsingle nexthops and small Equal-Cost Multi-Path groups, this fixed\nallocation fails for large nexthop groups like 512 nexthops.\n\nThis results in the following warning splat:\n\n WARNING: net/ipv4/nexthop.c:3395 at rtm_get_nexthop+0x176/0x1c0, CPU#20: rep/4608\n [...]\n RIP: 0010:rtm_get_nexthop (net/ipv4/nexthop.c:3395)\n [...]\n Call Trace:\n \u003cTASK\u003e\n rtnetlink_rcv_msg (net/core/rtnetlink.c:6989)\n netlink_rcv_skb (net/netlink/af_netlink.c:2550)\n netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\n netlink_sendmsg (net/netlink/af_netlink.c:1894)\n ____sys_sendmsg (net/socket.c:721 net/socket.c:736 net/socket.c:2585)\n ___sys_sendmsg (net/socket.c:2641)\n __sys_sendmsg (net/socket.c:2671)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n \u003c/TASK\u003e\n\nFix this by allocating the size dynamically using nh_nlmsg_size() and\nusing nlmsg_new(), this is consistent with nexthop_notify() behavior. In\naddition, adjust nh_nlmsg_size_grp() so it calculates the size needed\nbased on flags passed. While at it, also add the size of NHA_FDB for\nnexthop group size calculation as it was missing too.\n\nThis cannot be reproduced via iproute2 as the group size is currently\nlimited and the command fails as follows:\n\naddattr_l ERROR: message exceeded bound of 1048"
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:10:35.906Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/615517f3f8d53b0cf41507c7599971e17adfdfa5"
},
{
"url": "https://git.kernel.org/stable/c/40bd39e383a0478fd5c221f393df05fd9d70cfbc"
},
{
"url": "https://git.kernel.org/stable/c/635038fe19db391117e66b46bdc2b6e447ac801d"
},
{
"url": "https://git.kernel.org/stable/c/14cf0cd35361f4e94824bf8a42f72713d7702a73"
}
],
"title": "ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-31531",
"datePublished": "2026-04-23T11:12:44.143Z",
"dateReserved": "2026-03-09T15:48:24.112Z",
"dateUpdated": "2026-05-11T22:10:35.906Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64329 (GCVE-0-2026-64329)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
The threaded IRQ handler ccg_irq_handler() calls ucsi_notify_common(),
which on a connector-change event calls ucsi_connector_change() and
schedules connector work. In ucsi_ccg_remove(), ucsi_destroy() frees
uc->ucsi (kfree) before free_irq() is called, so a handler invocation
already in flight may access the freed object after ucsi_destroy().
CPU 0 (remove) | CPU 1 (threaded IRQ)
ucsi_destroy(uc->ucsi) | ccg_irq_handler()
kfree(ucsi) // FREE | ucsi_notify_common(uc->ucsi) // USE
Move free_irq() before ucsi_destroy() in the remove path. It is kept
after ucsi_unregister(): ucsi_unregister() cancels connector work whose
handler issues GET_CONNECTOR_STATUS through ucsi_send_command_common(),
which waits for a completion that is signalled from the IRQ handler, so
the IRQ must stay active until that work has been cancelled.
The probe error path already orders free_irq() before ucsi_destroy().
This bug was found by static analysis.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2 Version: e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2 Version: e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2 Version: e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2 Version: e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2 Version: e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2 Version: e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2 Version: e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/typec/ucsi/ucsi_ccg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f1adeb1ff8bef1467d6961059810795d02bbad5d",
"status": "affected",
"version": "e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2",
"versionType": "git"
},
{
"lessThan": "99381e762273a2410a3f0216000be32b013c0ea9",
"status": "affected",
"version": "e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2",
"versionType": "git"
},
{
"lessThan": "1a160076d3d0dcd4a98a4599ad96eec0790b099b",
"status": "affected",
"version": "e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2",
"versionType": "git"
},
{
"lessThan": "c32df11147822d22facee8fa30c2e8971d12f426",
"status": "affected",
"version": "e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2",
"versionType": "git"
},
{
"lessThan": "86c9ee928c4a370e323e432aaf8dca79c4ba7c85",
"status": "affected",
"version": "e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2",
"versionType": "git"
},
{
"lessThan": "f5c772b76bbd95de8be51cf849c6098f6af6fcf9",
"status": "affected",
"version": "e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2",
"versionType": "git"
},
{
"lessThan": "dbb500bad02146b388041877574829016591ddc8",
"status": "affected",
"version": "e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2",
"versionType": "git"
},
{
"lessThan": "1f0bdc2884b67de337215079bba166df0cdf4ac5",
"status": "affected",
"version": "e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/typec/ucsi/ucsi_ccg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove\n\nThe threaded IRQ handler ccg_irq_handler() calls ucsi_notify_common(),\nwhich on a connector-change event calls ucsi_connector_change() and\nschedules connector work. In ucsi_ccg_remove(), ucsi_destroy() frees\nuc-\u003eucsi (kfree) before free_irq() is called, so a handler invocation\nalready in flight may access the freed object after ucsi_destroy().\n\n CPU 0 (remove) | CPU 1 (threaded IRQ)\n ucsi_destroy(uc-\u003eucsi) | ccg_irq_handler()\n kfree(ucsi) // FREE | ucsi_notify_common(uc-\u003eucsi) // USE\n\nMove free_irq() before ucsi_destroy() in the remove path. It is kept\nafter ucsi_unregister(): ucsi_unregister() cancels connector work whose\nhandler issues GET_CONNECTOR_STATUS through ucsi_send_command_common(),\nwhich waits for a completion that is signalled from the IRQ handler, so\nthe IRQ must stay active until that work has been cancelled.\n\nThe probe error path already orders free_irq() before ucsi_destroy().\n\nThis bug was found by static analysis."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:31.661Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f1adeb1ff8bef1467d6961059810795d02bbad5d"
},
{
"url": "https://git.kernel.org/stable/c/99381e762273a2410a3f0216000be32b013c0ea9"
},
{
"url": "https://git.kernel.org/stable/c/1a160076d3d0dcd4a98a4599ad96eec0790b099b"
},
{
"url": "https://git.kernel.org/stable/c/c32df11147822d22facee8fa30c2e8971d12f426"
},
{
"url": "https://git.kernel.org/stable/c/86c9ee928c4a370e323e432aaf8dca79c4ba7c85"
},
{
"url": "https://git.kernel.org/stable/c/f5c772b76bbd95de8be51cf849c6098f6af6fcf9"
},
{
"url": "https://git.kernel.org/stable/c/dbb500bad02146b388041877574829016591ddc8"
},
{
"url": "https://git.kernel.org/stable/c/1f0bdc2884b67de337215079bba166df0cdf4ac5"
}
],
"title": "usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64329",
"datePublished": "2026-07-25T08:49:57.098Z",
"dateReserved": "2026-07-19T15:36:31.780Z",
"dateUpdated": "2026-08-17T04:53:31.661Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64127 (GCVE-0-2026-64127)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer
Commit 1c08108f3014 ("Bluetooth: L2CAP: Avoid -Wflex-array-member-not-at-end
warnings") converted the on-stack request PDU in l2cap_ecred_reconfigure()
from an explicit packed struct to DEFINE_RAW_FLEX(), but did not adjust the
size and source-pointer arguments to l2cap_send_cmd():
- struct {
- struct l2cap_ecred_reconf_req req;
- __le16 scid;
- } pdu;
+ DEFINE_RAW_FLEX(struct l2cap_ecred_reconf_req, pdu, scid, 1);
...
l2cap_send_cmd(conn, chan->ident, L2CAP_ECRED_RECONF_REQ,
sizeof(pdu), &pdu);
After the conversion, DEFINE_RAW_FLEX() expands to declare an anonymous
union pdu_u plus a local pointer "pdu" pointing at it. Therefore:
- sizeof(pdu) is now sizeof(struct l2cap_ecred_reconf_req *) = 8 on
64-bit (4 on 32-bit), not the 6 bytes of (mtu, mps, scid[1]).
- &pdu is the address of the local pointer's stack storage, not the
address of the request payload.
l2cap_send_cmd() forwards (data, count) to l2cap_build_cmd(), which calls
skb_put_data(skb, data, count). The L2CAP_ECRED_RECONFIGURE_REQ packet
body therefore contains 8 bytes copied from the kernel stack starting at
&pdu -- the 8 bytes overlap the pdu pointer's value, leaking a kernel
stack address to the paired Bluetooth peer. The intended (mtu, mps, scid)
fields are not transmitted at all, so the peer rejects the request as
malformed and the L2CAP_ECRED_RECONFIGURE feature itself has been broken
for the local-side initiator since the introducing commit landed.
The sibling site l2cap_ecred_conn_req() in the same commit was converted
correctly (sizeof(*pdu) + len, pdu); only this site was missed.
Restore the original semantics: pass the full flex-struct size via
struct_size(pdu, scid, 1) and the pdu pointer (the struct address) as
the source.
Validated on a stock 7.0-based host kernel via the real call path:
setsockopt(SOL_BLUETOOTH, BT_RCVMTU, ...) on a BT_CONNECTED
L2CAP_MODE_EXT_FLOWCTL socket emits an L2CAP_ECRED_RECONFIGURE_REQ
whose body is 8 bytes (the on-stack pdu local's value) rather than
the expected 6. Three captures from fresh socket / fresh hciemu peer
on the same host -- low bytes vary per call, high 0xffff confirms a
kernel virtual address (KASLR-randomised stack slot, not a fixed
string):
RECONF_REQ body (ident=0x02 len=8): 42 fb 54 af 0e ca ff ff
RECONF_REQ body (ident=0x02 len=8): 52 3d 2e af 0e ca ff ff
RECONF_REQ body (ident=0x02 len=8): b2 fc 5b af 0e ca ff ff
After this patch the body is 6 bytes carrying the expected
little-endian (mtu, mps, scid).
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ed5fcd2a26f0c16fc289c8cd6b03328a0582a687",
"status": "affected",
"version": "1c08108f3014881ad5f4c35a2abaf9c65475035d",
"versionType": "git"
},
{
"lessThan": "051922ab709c0a6917eae765c22481dfc68379e5",
"status": "affected",
"version": "1c08108f3014881ad5f4c35a2abaf9c65475035d",
"versionType": "git"
},
{
"lessThan": "356c9d1a1cbacd2a1640fff3c050e1c3472e924f",
"status": "affected",
"version": "1c08108f3014881ad5f4c35a2abaf9c65475035d",
"versionType": "git"
},
{
"lessThan": "3374ef8cf99368a40f7efd51a2a375a4c5dc6f0d",
"status": "affected",
"version": "1c08108f3014881ad5f4c35a2abaf9c65475035d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"lessThan": "6.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer\n\nCommit 1c08108f3014 (\"Bluetooth: L2CAP: Avoid -Wflex-array-member-not-at-end\nwarnings\") converted the on-stack request PDU in l2cap_ecred_reconfigure()\nfrom an explicit packed struct to DEFINE_RAW_FLEX(), but did not adjust the\nsize and source-pointer arguments to l2cap_send_cmd():\n\n - struct {\n - struct l2cap_ecred_reconf_req req;\n - __le16 scid;\n - } pdu;\n + DEFINE_RAW_FLEX(struct l2cap_ecred_reconf_req, pdu, scid, 1);\n ...\n l2cap_send_cmd(conn, chan-\u003eident, L2CAP_ECRED_RECONF_REQ,\n sizeof(pdu), \u0026pdu);\n\nAfter the conversion, DEFINE_RAW_FLEX() expands to declare an anonymous\nunion pdu_u plus a local pointer \"pdu\" pointing at it. Therefore:\n\n - sizeof(pdu) is now sizeof(struct l2cap_ecred_reconf_req *) = 8 on\n 64-bit (4 on 32-bit), not the 6 bytes of (mtu, mps, scid[1]).\n - \u0026pdu is the address of the local pointer\u0027s stack storage, not the\n address of the request payload.\n\nl2cap_send_cmd() forwards (data, count) to l2cap_build_cmd(), which calls\nskb_put_data(skb, data, count). The L2CAP_ECRED_RECONFIGURE_REQ packet\nbody therefore contains 8 bytes copied from the kernel stack starting at\n\u0026pdu -- the 8 bytes overlap the pdu pointer\u0027s value, leaking a kernel\nstack address to the paired Bluetooth peer. The intended (mtu, mps, scid)\nfields are not transmitted at all, so the peer rejects the request as\nmalformed and the L2CAP_ECRED_RECONFIGURE feature itself has been broken\nfor the local-side initiator since the introducing commit landed.\n\nThe sibling site l2cap_ecred_conn_req() in the same commit was converted\ncorrectly (sizeof(*pdu) + len, pdu); only this site was missed.\n\nRestore the original semantics: pass the full flex-struct size via\nstruct_size(pdu, scid, 1) and the pdu pointer (the struct address) as\nthe source.\n\nValidated on a stock 7.0-based host kernel via the real call path:\nsetsockopt(SOL_BLUETOOTH, BT_RCVMTU, ...) on a BT_CONNECTED\nL2CAP_MODE_EXT_FLOWCTL socket emits an L2CAP_ECRED_RECONFIGURE_REQ\nwhose body is 8 bytes (the on-stack pdu local\u0027s value) rather than\nthe expected 6. Three captures from fresh socket / fresh hciemu peer\non the same host -- low bytes vary per call, high 0xffff confirms a\nkernel virtual address (KASLR-randomised stack slot, not a fixed\nstring):\n\n RECONF_REQ body (ident=0x02 len=8): 42 fb 54 af 0e ca ff ff\n RECONF_REQ body (ident=0x02 len=8): 52 3d 2e af 0e ca ff ff\n RECONF_REQ body (ident=0x02 len=8): b2 fc 5b af 0e ca ff ff\n\nAfter this patch the body is 6 bytes carrying the expected\nlittle-endian (mtu, mps, scid)."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:23.960Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ed5fcd2a26f0c16fc289c8cd6b03328a0582a687"
},
{
"url": "https://git.kernel.org/stable/c/051922ab709c0a6917eae765c22481dfc68379e5"
},
{
"url": "https://git.kernel.org/stable/c/356c9d1a1cbacd2a1640fff3c050e1c3472e924f"
},
{
"url": "https://git.kernel.org/stable/c/3374ef8cf99368a40f7efd51a2a375a4c5dc6f0d"
}
],
"title": "Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64127",
"datePublished": "2026-07-19T15:40:23.960Z",
"dateReserved": "2026-07-19T07:54:57.036Z",
"dateUpdated": "2026-07-19T15:40:23.960Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68349 (GCVE-0-2026-68349)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: fix buffer overflow in rx_stream failover path
The failover continuation in carl9170_rx_stream() copies the full tlen
from the second USB transfer instead of capping at rx_failover_missing
bytes. When both transfers are near maximum size, the total exceeds the
65535-byte failover SKB, triggering skb_over_panic.
Limit the copy size to the missing byte count.
[Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5fb00a09e9b0375e1ad9d4fefc4a62a67e7ea658",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "48c81fb523ecdc6a4b8654944ff32e499f21e6d0",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "a1ce01764a812c22a47d30aea78e347aebd3eea1",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "5acfa18de66b6089b81c1c0bf1a3ae3c940ec39e",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "b9dfee5e63ee9b5c47be9e344ebc5bd3f43fca78",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "4503829843353dbb18b879c35be1cdfc9af677b7",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "21f59906ea75618fdd46a7e32754d54fbee083ea",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "a1a21995c2e1cc2ca6b2226cfe4f5f018370182a",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: fix buffer overflow in rx_stream failover path\n\nThe failover continuation in carl9170_rx_stream() copies the full tlen\nfrom the second USB transfer instead of capping at rx_failover_missing\nbytes. When both transfers are near maximum size, the total exceeds the\n65535-byte failover SKB, triggering skb_over_panic.\n\nLimit the copy size to the missing byte count.\n\n[Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:47.832Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5fb00a09e9b0375e1ad9d4fefc4a62a67e7ea658"
},
{
"url": "https://git.kernel.org/stable/c/48c81fb523ecdc6a4b8654944ff32e499f21e6d0"
},
{
"url": "https://git.kernel.org/stable/c/a1ce01764a812c22a47d30aea78e347aebd3eea1"
},
{
"url": "https://git.kernel.org/stable/c/5acfa18de66b6089b81c1c0bf1a3ae3c940ec39e"
},
{
"url": "https://git.kernel.org/stable/c/b9dfee5e63ee9b5c47be9e344ebc5bd3f43fca78"
},
{
"url": "https://git.kernel.org/stable/c/4503829843353dbb18b879c35be1cdfc9af677b7"
},
{
"url": "https://git.kernel.org/stable/c/21f59906ea75618fdd46a7e32754d54fbee083ea"
},
{
"url": "https://git.kernel.org/stable/c/a1a21995c2e1cc2ca6b2226cfe4f5f018370182a"
}
],
"title": "wifi: carl9170: fix buffer overflow in rx_stream failover path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68349",
"datePublished": "2026-08-10T12:03:26.166Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:47.832Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68272 (GCVE-0-2026-68272)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
Add a minimum-length check for the AMDGPU_CHUNK_ID_CP_GFX_SHADOW chunk in
amdgpu_cs_pass1(), matching the gate already present for the IB, FENCE and
BO_HANDLES chunk types.
The CP_GFX_SHADOW case previously shared a bare break with the dependency
and syncobj chunk types, which do not dereference a fixed-size struct. When
userspace submits this chunk with length_dw == 0, vmemdup_array_user() is
called with size 0 and returns ZERO_SIZE_PTR, which passes the IS_ERR()
check. amdgpu_cs_p2_shadow() then dereferences chunk->kdata as a struct
drm_amdgpu_cs_chunk_cp_gfx_shadow (reading shadow->flags), faulting on the
ZERO_SIZE_PTR and causing a NULL-pointer dereference.
This is reachable by an unprivileged process in the render group. Reject
undersized chunks with -EINVAL during pass1 so the bad submission is
rejected before pass2 ever dereferences the data.
(cherry picked from commit 7f61b2eef7415eccdb40850aca0de94211948657)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3f190956404da55560056ce20606010e18bc059c",
"status": "affected",
"version": "ac9287055ff16a092416c76a19006764e4c6a978",
"versionType": "git"
},
{
"lessThan": "2aa9ea2bd5146d237c8cc16d8737d878b0298a94",
"status": "affected",
"version": "ac9287055ff16a092416c76a19006764e4c6a978",
"versionType": "git"
},
{
"lessThan": "315d2e5741a81b0be763e80413a2677e22b7e596",
"status": "affected",
"version": "ac9287055ff16a092416c76a19006764e4c6a978",
"versionType": "git"
},
{
"lessThan": "24668ca3ec19434d7a9574bf9112f2b0614c3a4e",
"status": "affected",
"version": "ac9287055ff16a092416c76a19006764e4c6a978",
"versionType": "git"
},
{
"lessThan": "84c4c36acd5c4b2558b5069f869a165b2c655c84",
"status": "affected",
"version": "ac9287055ff16a092416c76a19006764e4c6a978",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1\n\nAdd a minimum-length check for the AMDGPU_CHUNK_ID_CP_GFX_SHADOW chunk in\namdgpu_cs_pass1(), matching the gate already present for the IB, FENCE and\nBO_HANDLES chunk types.\n\nThe CP_GFX_SHADOW case previously shared a bare break with the dependency\nand syncobj chunk types, which do not dereference a fixed-size struct. When\nuserspace submits this chunk with length_dw == 0, vmemdup_array_user() is\ncalled with size 0 and returns ZERO_SIZE_PTR, which passes the IS_ERR()\ncheck. amdgpu_cs_p2_shadow() then dereferences chunk-\u003ekdata as a struct\ndrm_amdgpu_cs_chunk_cp_gfx_shadow (reading shadow-\u003eflags), faulting on the\nZERO_SIZE_PTR and causing a NULL-pointer dereference.\n\nThis is reachable by an unprivileged process in the render group. Reject\nundersized chunks with -EINVAL during pass1 so the bad submission is\nrejected before pass2 ever dereferences the data.\n\n(cherry picked from commit 7f61b2eef7415eccdb40850aca0de94211948657)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:05.775Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3f190956404da55560056ce20606010e18bc059c"
},
{
"url": "https://git.kernel.org/stable/c/2aa9ea2bd5146d237c8cc16d8737d878b0298a94"
},
{
"url": "https://git.kernel.org/stable/c/315d2e5741a81b0be763e80413a2677e22b7e596"
},
{
"url": "https://git.kernel.org/stable/c/24668ca3ec19434d7a9574bf9112f2b0614c3a4e"
},
{
"url": "https://git.kernel.org/stable/c/84c4c36acd5c4b2558b5069f869a165b2c655c84"
}
],
"title": "drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68272",
"datePublished": "2026-08-10T12:01:47.708Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:02:05.775Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68325 (GCVE-0-2026-68325)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Bound the early ACPI HID map
The ivrs_acpihid command-line parser appends entries to a fixed
four-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET
parsers, it does not reject a fifth entry before incrementing the map size.
Check the capacity at the common found label before parsing the HID and
UID or writing the entry.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iommu/amd/init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9ae6b1b972ce01d3316c8a5f7f58c8b3668cc6bb",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "e5e0098f8cd82f8b3c8687a8f686309565d51745",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "afe7ea0520c49586703f210865ace2d70b017e48",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "1e31d2394e0db69541b1591d46c5ad6431c81db3",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "abe5d7962f09adada9c4fb25b816dddd3f97c55d",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "e5ebe8544df1a1c3611739a8622156094fe470df",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "030a8e84f8f1b6e96f469c84a13a225c3699910b",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "fb80117fddb5b477218dc99bb53911b72c3847f8",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iommu/amd/init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Bound the early ACPI HID map\n\nThe ivrs_acpihid command-line parser appends entries to a fixed\nfour-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET\nparsers, it does not reject a fifth entry before incrementing the map size.\n\nCheck the capacity at the common found label before parsing the HID and\nUID or writing the entry."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:18.080Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9ae6b1b972ce01d3316c8a5f7f58c8b3668cc6bb"
},
{
"url": "https://git.kernel.org/stable/c/e5e0098f8cd82f8b3c8687a8f686309565d51745"
},
{
"url": "https://git.kernel.org/stable/c/afe7ea0520c49586703f210865ace2d70b017e48"
},
{
"url": "https://git.kernel.org/stable/c/1e31d2394e0db69541b1591d46c5ad6431c81db3"
},
{
"url": "https://git.kernel.org/stable/c/abe5d7962f09adada9c4fb25b816dddd3f97c55d"
},
{
"url": "https://git.kernel.org/stable/c/e5ebe8544df1a1c3611739a8622156094fe470df"
},
{
"url": "https://git.kernel.org/stable/c/030a8e84f8f1b6e96f469c84a13a225c3699910b"
},
{
"url": "https://git.kernel.org/stable/c/fb80117fddb5b477218dc99bb53911b72c3847f8"
}
],
"title": "iommu/amd: Bound the early ACPI HID map",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68325",
"datePublished": "2026-08-10T12:03:01.384Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:18.080Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72123 (GCVE-0-2026-72123)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
Commit f1b4e32aca08 ("can: bcm: use call_rcu() instead of costly
synchronize_rcu()") replaced synchronize_rcu() in bcm_delete_rx_op()
with call_rcu() and introduced the RX_NO_AUTOTIMER flag.
However, this flag check was omitted for thrtimer in the packet rx
fast-path. During BCM RX operation teardown, a concurrent RCU reader
(bcm_rx_handler) can race and re-arm thrtimer via
bcm_rx_update_and_send() after call_rcu() has been scheduled. Once
the RCU grace period elapses, bcm_op is freed. The subsequently
firing thrtimer then dereferences the deallocated op, causing a UAF.
Adding flag checks to the rx fast-path (bcm_rx_update_and_send) does not
fully close the TOCTOU race and introduces latency for every CAN frame.
Conversely, calling hrtimer_cancel() directly inside the RCU callback
(softirq context) is fatal as hrtimer_cancel() can sleep, triggering
a "scheduling while atomic" panic.
Resolve this by deferring the timer cancellation and memory free to a
dedicated unbound workqueue (bcm_wq). The RCU callback now queues a
work item to bcm_wq, which safely cancels both timers and deallocates
memory in sleepable process context. A dedicated workqueue is used to
prevent system-wide WQ saturation and is cleanly flushed/destroyed
on module unload to avoid rmmod page faults.
Since the deferred work can now outlive the calling context by an
unbounded amount, also take a reference on op->sk when it is assigned
and drop it only once the deferred work has cancelled both timers, so a
socket can no longer be freed out from under a still-armed timer whose
callback (bcm_send_to_user()) dereferences op->sk.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 85cd41070df992d3c0dfd828866fdd243d3b774a Version: f34f2a18e47b73e48f90a757e1f4aaa8c7d665a1 Version: f1b4e32aca0811aa011c76e5d6cf2fa19224b386 Version: f1b4e32aca0811aa011c76e5d6cf2fa19224b386 Version: f1b4e32aca0811aa011c76e5d6cf2fa19224b386 Version: f1b4e32aca0811aa011c76e5d6cf2fa19224b386 Version: f1b4e32aca0811aa011c76e5d6cf2fa19224b386 Version: f1b4e32aca0811aa011c76e5d6cf2fa19224b386 Version: fbac09a3b8890003c0c55294c00709f3ae5501bb Version: 5b48f5711f1c630841ab78dcc061de902f0e37bf Version: edb4baffb9483141a50fb7f7146cfe4a4c0c2db8 Version: 5.10.130 ≤ Version: 5.15.54 ≤ Version: 4.19.252 ≤ Version: 5.4.205 ≤ Version: 5.18.11 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "de5fce46637de05bef56ec08528127676eb6fc9b",
"status": "affected",
"version": "85cd41070df992d3c0dfd828866fdd243d3b774a",
"versionType": "git"
},
{
"lessThan": "036a8c320ca11bc912e8027adcfad14b326f067e",
"status": "affected",
"version": "f34f2a18e47b73e48f90a757e1f4aaa8c7d665a1",
"versionType": "git"
},
{
"lessThan": "3cf4fd5316f449811d8baf1bc6978ef5a7b743a9",
"status": "affected",
"version": "f1b4e32aca0811aa011c76e5d6cf2fa19224b386",
"versionType": "git"
},
{
"lessThan": "4177762f70646ac48a2af382e45a795cbd295198",
"status": "affected",
"version": "f1b4e32aca0811aa011c76e5d6cf2fa19224b386",
"versionType": "git"
},
{
"lessThan": "6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f",
"status": "affected",
"version": "f1b4e32aca0811aa011c76e5d6cf2fa19224b386",
"versionType": "git"
},
{
"lessThan": "cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5",
"status": "affected",
"version": "f1b4e32aca0811aa011c76e5d6cf2fa19224b386",
"versionType": "git"
},
{
"lessThan": "ce2d4b121fb7545e1ed588e860c8e5fd5ad45224",
"status": "affected",
"version": "f1b4e32aca0811aa011c76e5d6cf2fa19224b386",
"versionType": "git"
},
{
"lessThan": "68973f9db76144825e4f35dfdc80fb8279eb2d57",
"status": "affected",
"version": "f1b4e32aca0811aa011c76e5d6cf2fa19224b386",
"versionType": "git"
},
{
"status": "affected",
"version": "fbac09a3b8890003c0c55294c00709f3ae5501bb",
"versionType": "git"
},
{
"status": "affected",
"version": "5b48f5711f1c630841ab78dcc061de902f0e37bf",
"versionType": "git"
},
{
"status": "affected",
"version": "edb4baffb9483141a50fb7f7146cfe4a4c0c2db8",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.130",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.54",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.252",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.205",
"versionType": "semver"
},
{
"lessThan": "5.19",
"status": "affected",
"version": "5.18.11",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.130",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.54",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.252",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.205",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.18.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF\n\nCommit f1b4e32aca08 (\"can: bcm: use call_rcu() instead of costly\nsynchronize_rcu()\") replaced synchronize_rcu() in bcm_delete_rx_op()\nwith call_rcu() and introduced the RX_NO_AUTOTIMER flag.\n\nHowever, this flag check was omitted for thrtimer in the packet rx\nfast-path. During BCM RX operation teardown, a concurrent RCU reader\n(bcm_rx_handler) can race and re-arm thrtimer via\nbcm_rx_update_and_send() after call_rcu() has been scheduled. Once\nthe RCU grace period elapses, bcm_op is freed. The subsequently\nfiring thrtimer then dereferences the deallocated op, causing a UAF.\n\nAdding flag checks to the rx fast-path (bcm_rx_update_and_send) does not\nfully close the TOCTOU race and introduces latency for every CAN frame.\nConversely, calling hrtimer_cancel() directly inside the RCU callback\n(softirq context) is fatal as hrtimer_cancel() can sleep, triggering\na \"scheduling while atomic\" panic.\n\nResolve this by deferring the timer cancellation and memory free to a\ndedicated unbound workqueue (bcm_wq). The RCU callback now queues a\nwork item to bcm_wq, which safely cancels both timers and deallocates\nmemory in sleepable process context. A dedicated workqueue is used to\nprevent system-wide WQ saturation and is cleanly flushed/destroyed\non module unload to avoid rmmod page faults.\n\nSince the deferred work can now outlive the calling context by an\nunbounded amount, also take a reference on op-\u003esk when it is assigned\nand drop it only once the deferred work has cancelled both timers, so a\nsocket can no longer be freed out from under a still-armed timer whose\ncallback (bcm_send_to_user()) dereferences op-\u003esk."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local BCM socket syscalls (sendmsg with RX_SETUP/SETTIMER/ival2 throttling and RX_DELETE); CAN frames can be injected locally via loopback without physical bus access.\nAC:L - The attacker controls both sides of the race by concurrently issuing RX_DELETE teardown and delivering matching CAN frames (e.g., via threads or paired BCM/RAW sockets), making the thrtimer re-arm UAF reliably triggerable.\nPR:L - No kernel capability check gates AF_CAN/CAN_BCM socket creation or bcm_sendmsg opcodes; any unprivileged local user with socket access (including via user namespaces with vcan) can reach the vulnerable path.\nUI:N - No victim interaction is required; the attacker self-triggers the race through their own BCM socket operations and locally injected CAN traffic.\nS:U - Impact is confined to kernel memory corruption and local privilege escalation within the same kernel security boundary, not a cross-boundary escape such as VM or IOMMU bypass.\nC:H - The thrtimer UAF dereferences freed bcm_op fields (locks, frame buffers, op-\u003esk) in bcm_rx_thr_handler/bcm_send_to_user, enabling attacker-controlled heap reuse and arbitrary kernel memory disclosure.\nI:H - UAF on the bcm_op slab object allows heap spraying to corrupt function pointers, timers, and sock structures, providing a standard path to arbitrary kernel writes and local privilege escalation.\nA:H - The freed-op dereference in the hrtimer softirq path causes kernel oops/panic under normal exploitation attempts, and successful memory corruption can crash or hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:18.988Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/de5fce46637de05bef56ec08528127676eb6fc9b"
},
{
"url": "https://git.kernel.org/stable/c/036a8c320ca11bc912e8027adcfad14b326f067e"
},
{
"url": "https://git.kernel.org/stable/c/3cf4fd5316f449811d8baf1bc6978ef5a7b743a9"
},
{
"url": "https://git.kernel.org/stable/c/4177762f70646ac48a2af382e45a795cbd295198"
},
{
"url": "https://git.kernel.org/stable/c/6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f"
},
{
"url": "https://git.kernel.org/stable/c/cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5"
},
{
"url": "https://git.kernel.org/stable/c/ce2d4b121fb7545e1ed588e860c8e5fd5ad45224"
},
{
"url": "https://git.kernel.org/stable/c/68973f9db76144825e4f35dfdc80fb8279eb2d57"
}
],
"title": "can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72123",
"datePublished": "2026-08-15T05:53:01.433Z",
"dateReserved": "2026-08-09T03:40:39.907Z",
"dateUpdated": "2026-08-19T16:36:18.988Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64577 (GCVE-0-2026-64577)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its
caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +
gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For
a 16-19 byte echo request the pull fails and returns NULL without
advancing skb->data; execution continues, and the following skb_push()
plus the IP header pushed by iptunnel_xmit() move skb->data below
skb->head, tripping skb_under_panic().
Fix it by dropping the packet when skb_pull_data() fails.
skbuff: skb_under_panic: ...
kernel BUG at net/core/skbuff.c:214!
Call Trace:
skb_push (net/core/skbuff.c:2648)
iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)
gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)
udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)
...
Kernel panic - not syncing: Fatal exception in interrupt
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/gtp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9033fe49926f0e7421fefee922dc086417e905cf",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "b3c733eaae7f362601c28ac1533d47a961cd3e1c",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "4fc7923871d176ce0e5fecf4a9b7bb915af790ed",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "961e9b1e33445f8e42859ecc020c9f60d8b69a8b",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "cf45d748e437b8dd2dd987f27ee79c8c86f95c88",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "cd170f051dba9ac146fabcd1b91726487c0cb9fa",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/gtp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: check skb_pull_data() return in gtp1u_send_echo_resp()\n\ngtp1u_send_echo_resp() ignores skb_pull_data()\u0027s return value. Its\ncaller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +\ngtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For\na 16-19 byte echo request the pull fails and returns NULL without\nadvancing skb-\u003edata; execution continues, and the following skb_push()\nplus the IP header pushed by iptunnel_xmit() move skb-\u003edata below\nskb-\u003ehead, tripping skb_under_panic().\n\nFix it by dropping the packet when skb_pull_data() fails.\n\n skbuff: skb_under_panic: ...\n kernel BUG at net/core/skbuff.c:214!\n Call Trace:\n skb_push (net/core/skbuff.c:2648)\n iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)\n gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)\n udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)\n ...\n Kernel panic - not syncing: Fatal exception in interrupt"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A crafted GTP-U Echo Request to UDP port 2152 reaches gtp_encap_recv \u2192 gtp1u_udp_encap_recv \u2192 gtp1u_send_echo_resp via the in-kernel UDP encap receive path, so a remote IP peer can trigger the bug without local access.\nAC:L - The attacker fully controls the packet: a 16\u201319 byte GTP-U Echo Request with the S flag set and TEID 0 reliably fails the unchecked 20-byte pull and drives the subsequent skb_push path into skb_under_panic with no race or external condition required.\nPR:N - GTP-U echo handling runs on unauthenticated received UDP datagrams once a GTP device with kernel-created sockets exists; the attacker needs no credentials or local privileges on the target.\nUI:N - No victim action is required; packet delivery to the GTP-U encap socket alone invokes the vulnerable echo-response path.\nS:U - Impact is a kernel BUG/panic in the host GTP/network stack within the same security authority; it does not cross a VM, IOMMU, or other separate boundary.\nC:N - The failure is a deterministic skb headroom underflow caught by skb_under_panic/BUG with no out-of-bounds read, UAF, or other information-disclosure primitive identified.\nI:N - skb_push detects data \u003c head and BUG()s before further attacker-controlled writes; this is an availability crash, not an exploitable write or control-flow hijack primitive.\nA:H - The commit-reproduced path hits skb_under_panic and a fatal kernel BUG in interrupt context, causing kernel panic and full denial of service that can be retriggered by further crafted echo requests."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:59.684Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9033fe49926f0e7421fefee922dc086417e905cf"
},
{
"url": "https://git.kernel.org/stable/c/b3c733eaae7f362601c28ac1533d47a961cd3e1c"
},
{
"url": "https://git.kernel.org/stable/c/4fc7923871d176ce0e5fecf4a9b7bb915af790ed"
},
{
"url": "https://git.kernel.org/stable/c/961e9b1e33445f8e42859ecc020c9f60d8b69a8b"
},
{
"url": "https://git.kernel.org/stable/c/cf45d748e437b8dd2dd987f27ee79c8c86f95c88"
},
{
"url": "https://git.kernel.org/stable/c/cd170f051dba9ac146fabcd1b91726487c0cb9fa"
}
],
"title": "gtp: check skb_pull_data() return in gtp1u_send_echo_resp()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64577",
"datePublished": "2026-08-05T08:09:33.135Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:28:59.684Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64403 (GCVE-0-2026-64403)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: validate option length before reading conf opt value
l2cap_get_conf_opt() derives the option length from the
attacker-controlled opt->len field and immediately dereferences
opt->val (as u8, get_unaligned_le16() or get_unaligned_le32(), or a
raw pointer for the default case) before any caller has confirmed
that opt->len bytes are present in the buffer. The callers
(l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and
l2cap_conf_rfc_get()) only detect a malformed option afterwards, once
the running length has gone negative, by which point the
out-of-bounds read has already executed.
An existing post-hoc length check keeps the garbage value from being
consumed, so this is not a data leak in the current control flow. It
is still a validate-after-use ordering bug: up to 4 bytes are read
past the end of the buffer before it is known to contain them, and it
is fragile to future changes in the callers.
Fix it at the source. Pass the end of the buffer into
l2cap_get_conf_opt() and refuse to touch opt->val unless the full
option (header + value) fits. Each caller computes an end pointer
once before the loop and checks the return value directly instead of
inferring the error from a negative length.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Version: 78c2887130f1a7d1883195732be1b6cdab667487 Version: ac7c597c465eb09391e40febbe088bdad601080b Version: ade4560e4fea198866e033fe1c02f063d6d7db2e Version: 99665dcf6ff803351b5e658f3a929cb498561e36 Version: 2b59d36f22622c92c0b06aee7571f0a86a217188 Version: 15d6538a0d6e0f6de5116081a948cba7cc3e1d3d Version: a556547bae00528f24b42786b41a14047db14b84 Version: 3.16.66 ≤ Version: 3.18.138 ≤ Version: 4.4.178 ≤ Version: 4.9.167 ≤ Version: 4.14.110 ≤ Version: 4.19.33 ≤ Version: 5.0.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cca81b4bc672604a84f6d224a55cc77ec7dee619",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "f70d4aa88068096f35d73e3a05eff33c0a16b9cd",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "7d871e969b941ce25653f7716203a0ea4d07ad4b",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "98d93c226bdfaa79bbdd86981921d7f106374225",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "996d3da39899aceb8f4910911a3f19a45a7d9d1b",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "73abbaf91aa33da87c008fb62c148ade561bb606",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "6b47bdaacfd0045687880177e0987055d8f4765a",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"lessThan": "687617555cedfb74c9e3cb85d759b908dcb17856",
"status": "affected",
"version": "7c9cbd0b5e38a1672fcd137894ace3b042dfbf69",
"versionType": "git"
},
{
"status": "affected",
"version": "78c2887130f1a7d1883195732be1b6cdab667487",
"versionType": "git"
},
{
"status": "affected",
"version": "ac7c597c465eb09391e40febbe088bdad601080b",
"versionType": "git"
},
{
"status": "affected",
"version": "ade4560e4fea198866e033fe1c02f063d6d7db2e",
"versionType": "git"
},
{
"status": "affected",
"version": "99665dcf6ff803351b5e658f3a929cb498561e36",
"versionType": "git"
},
{
"status": "affected",
"version": "2b59d36f22622c92c0b06aee7571f0a86a217188",
"versionType": "git"
},
{
"status": "affected",
"version": "15d6538a0d6e0f6de5116081a948cba7cc3e1d3d",
"versionType": "git"
},
{
"status": "affected",
"version": "a556547bae00528f24b42786b41a14047db14b84",
"versionType": "git"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.66",
"versionType": "semver"
},
{
"lessThan": "3.19",
"status": "affected",
"version": "3.18.138",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.178",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.167",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.110",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.33",
"versionType": "semver"
},
{
"lessThan": "5.1",
"status": "affected",
"version": "5.0.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.66",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.18.138",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.178",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.167",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.110",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.0.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: validate option length before reading conf opt value\n\nl2cap_get_conf_opt() derives the option length from the\nattacker-controlled opt-\u003elen field and immediately dereferences\nopt-\u003eval (as u8, get_unaligned_le16() or get_unaligned_le32(), or a\nraw pointer for the default case) before any caller has confirmed\nthat opt-\u003elen bytes are present in the buffer. The callers\n(l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and\nl2cap_conf_rfc_get()) only detect a malformed option afterwards, once\nthe running length has gone negative, by which point the\nout-of-bounds read has already executed.\n\nAn existing post-hoc length check keeps the garbage value from being\nconsumed, so this is not a data leak in the current control flow. It\nis still a validate-after-use ordering bug: up to 4 bytes are read\npast the end of the buffer before it is known to contain them, and it\nis fragile to future changes in the callers.\n\nFix it at the source. Pass the end of the buffer into\nl2cap_get_conf_opt() and refuse to touch opt-\u003eval unless the full\noption (header + value) fits. Each caller computes an end pointer\nonce before the loop and checks the return value directly instead of\ninferring the error from a negative length."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable parser processes attacker-controlled BR/EDR L2CAP configuration packets received from a Bluetooth peer within radio range.\nAC:L - A malformed option with a declared length exceeding the remaining buffer directly triggers the invalid read; no race or condition outside the attacker\u0027s control is required.\nPR:N - An unauthenticated Bluetooth peer can establish an SDP L2CAP channel, for which Linux bypasses the normal link-security check, and then submit configuration packets.\nUI:N - Once the Bluetooth interface is connectable with an applicable listening service, the peer can establish the channel and send the malformed option without victim action.\nS:U - The vulnerable Bluetooth parser and the resulting kernel impact are within the same host kernel security authority, without crossing a VM, sandbox, or IOMMU boundary.\nC:L - The invalid read is strictly bounded to at most four adjacent bytes. Although the post-hoc check prevents the value from being consumed in the current protocol flow, limited confidentiality impact is the higher defensible choice.\nI:N - The flaw performs only an out-of-bounds read, and the invalid value is discarded before option-specific processing; there is no memory write or control-flow corruption primitive.\nA:H - The invalid kernel read can produce an oops or panic when it reaches an inaccessible or hardened boundary, and an unauthenticated adjacent peer can repeatedly send malformed configuration options."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:01.248Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cca81b4bc672604a84f6d224a55cc77ec7dee619"
},
{
"url": "https://git.kernel.org/stable/c/f70d4aa88068096f35d73e3a05eff33c0a16b9cd"
},
{
"url": "https://git.kernel.org/stable/c/7d871e969b941ce25653f7716203a0ea4d07ad4b"
},
{
"url": "https://git.kernel.org/stable/c/98d93c226bdfaa79bbdd86981921d7f106374225"
},
{
"url": "https://git.kernel.org/stable/c/996d3da39899aceb8f4910911a3f19a45a7d9d1b"
},
{
"url": "https://git.kernel.org/stable/c/73abbaf91aa33da87c008fb62c148ade561bb606"
},
{
"url": "https://git.kernel.org/stable/c/6b47bdaacfd0045687880177e0987055d8f4765a"
},
{
"url": "https://git.kernel.org/stable/c/687617555cedfb74c9e3cb85d759b908dcb17856"
}
],
"title": "Bluetooth: L2CAP: validate option length before reading conf opt value",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64403",
"datePublished": "2026-07-25T08:50:45.796Z",
"dateReserved": "2026-07-19T15:36:31.785Z",
"dateUpdated": "2026-08-17T04:55:01.248Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68263 (GCVE-0-2026-68263)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: Fix double call to drm_sched_entity_fini()
Call sequence of double call:
pvr_context_destroy
pvr_context_kill_queues
pvr_queue_kill
drm_sched_entity_destroy
drm_sched_entity_fini // here
pvr_context_put
kref_put(..., pvr_context_release)
pvr_context_destroy_queues
pvr_queue_destroy
drm_sched_entity_fini // here
Call to drm_sched_entity_destroy() from pvr_context_kill_queues() calls
drm_sched_entity_flush() + drm_sched_entity_fini().
drm_sched_entity_flush() ensures all pending jobs are completed and
drm_sched_entity_fini() ensures no further submission is allowed as
per expectation from pvr_context_kill_queues(). Double call to
drm_sched_entity_fini() is misuse of the API so keep call only in
pvr_context_create() failure path.
Stack trace for issue with addition of refcounting for DRM entity
stats in commit fd177135f0e6 ("drm/sched: Account entity GPU time"):
[ 789.490527] ------------[ cut here ]------------
[ 789.490559] refcount_t: underflow; use-after-free.
[ 789.490657] WARNING: lib/refcount.c:28 at refcount_warn_saturate+0xf4/0x144, CPU#0: kworker/u16:1/440
[ 789.490695] Modules linked in: powervr drm_gpuvm drm_exec gpu_sched drm_shmem_helper xhci_plat_hcd xhci_hcd dwc3 usbcore usb_common snd_soc_simple_card snd_soc_simple_card_utils sa2ul sha512 sha256 dwc3_am62 sha1 authenc rti_wdt libsha512 at24 sch_fq_codel fuse dm_mod ipv6
[ 789.490798] CPU: 0 UID: 0 PID: 440 Comm: kworker/u16:1 Not tainted 7.0.0-rc7-02049-g5e2c0700091b #22 PREEMPT
[ 789.490809] Hardware name: Texas Instruments AM625 SK (DT)
[ 789.490815] Workqueue: powervr-sched pvr_queue_fence_release_work [powervr]
[ 789.490868] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 789.490876] pc : refcount_warn_saturate+0xf4/0x144
[ 789.490884] lr : refcount_warn_saturate+0xf4/0x144
[ 789.490892] sp : ffff8000822cbcc0
[ 789.490895] x29: ffff8000822cbcc0 x28: 0000000000000000 x27: 0000000000000000
[ 789.490909] x26: 0000000000000000 x25: ffff800081b1e338 x24: ffff000004541405
[ 789.490922] x23: ffff000004bea950 x22: ffff00000042e400 x21: ffff000007123e30
[ 789.490935] x20: ffff000007123000 x19: ffff000007a80d50 x18: fffffffffffe7768
[ 789.490948] x17: 74736574202c6e6f x16: 697461746e656d65 x15: ffff800081b269f0
[ 789.490962] x14: 0000000000000030 x13: ffff800081b26a70 x12: 0000000000000211
[ 789.490975] x11: 00000000000000c0 x10: 0000000000000b50 x9 : ffff8000822cbb30
[ 789.490988] x8 : ffff0000014e7bb0 x7 : ffff00007725e780 x6 : 0000000372a05f49
[ 789.491001] x5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000010
[ 789.491013] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0000014e7000
[ 789.491027] Call trace:
[ 789.491032] refcount_warn_saturate+0xf4/0x144 (P)
[ 789.491043] drm_sched_entity_fini+0x164/0x18c [gpu_sched]
[ 789.491081] pvr_queue_destroy+0x64/0x134 [powervr]
[ 789.491110] pvr_context_destroy_queues+0x34/0x64 [powervr]
[ 789.491138] pvr_context_release+0x70/0xac [powervr]
[ 789.491166] pvr_context_put.part.0+0x5c/0x7c [powervr]
[ 789.491193] pvr_context_put+0x14/0x24 [powervr]
[ 789.491221] pvr_queue_fence_release_work+0x20/0x38 [powervr]
[ 789.491249] process_one_work+0x160/0x4c4
[ 789.491264] worker_thread+0x188/0x310
[ 789.491276] kthread+0x130/0x13c
[ 789.491287] ret_from_fork+0x10/0x20
[ 789.491300] ---[ end trace 0000000000000000 ]---
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_context.c",
"drivers/gpu/drm/imagination/pvr_queue.c",
"drivers/gpu/drm/imagination/pvr_queue.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9be3f4bd6f514f69c51a8c77ea64fce2729dc7f4",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "c88fdbf3da26e0179629530cae7768cd3d4ead85",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "c1136d907fd04ca5c62ba11c1159b5fe65a1760c",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "4af24c27a39ba147a613a09e10b9e0f7294524c0",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_context.c",
"drivers/gpu/drm/imagination/pvr_queue.c",
"drivers/gpu/drm/imagination/pvr_queue.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Fix double call to drm_sched_entity_fini()\n\nCall sequence of double call:\npvr_context_destroy\n\u2003\u2003pvr_context_kill_queues\n\u2003\u2003\u2003\u2003pvr_queue_kill\n\u2003\u2003\u2003\u2003\u2003\u2003drm_sched_entity_destroy\n\u2003\u2003\u2003\u2003\u2003\u2003\u2003\u2003drm_sched_entity_fini // here\n\u2003\u2003pvr_context_put\n\u2003\u2003\u2003\u2003kref_put(..., pvr_context_release)\n\u2003\u2003\u2003\u2003\u2003\u2003pvr_context_destroy_queues\n\u2003\u2003\u2003\u2003\u2003\u2003\u2003\u2003pvr_queue_destroy\n\u2003\u2003\u2003\u2003\u2003\u2003\u2003\u2003\u2003\u2003drm_sched_entity_fini // here\n\nCall to drm_sched_entity_destroy() from pvr_context_kill_queues() calls\ndrm_sched_entity_flush() + drm_sched_entity_fini().\ndrm_sched_entity_flush() ensures all pending jobs are completed and\ndrm_sched_entity_fini() ensures no further submission is allowed as\nper expectation from pvr_context_kill_queues(). Double call to\ndrm_sched_entity_fini() is misuse of the API so keep call only in\npvr_context_create() failure path.\n\nStack trace for issue with addition of refcounting for DRM entity\nstats in commit fd177135f0e6 (\"drm/sched: Account entity GPU time\"):\n\n[ 789.490527] ------------[ cut here ]------------\n[ 789.490559] refcount_t: underflow; use-after-free.\n[ 789.490657] WARNING: lib/refcount.c:28 at refcount_warn_saturate+0xf4/0x144, CPU#0: kworker/u16:1/440\n[ 789.490695] Modules linked in: powervr drm_gpuvm drm_exec gpu_sched drm_shmem_helper xhci_plat_hcd xhci_hcd dwc3 usbcore usb_common snd_soc_simple_card snd_soc_simple_card_utils sa2ul sha512 sha256 dwc3_am62 sha1 authenc rti_wdt libsha512 at24 sch_fq_codel fuse dm_mod ipv6\n[ 789.490798] CPU: 0 UID: 0 PID: 440 Comm: kworker/u16:1 Not tainted 7.0.0-rc7-02049-g5e2c0700091b #22 PREEMPT\n[ 789.490809] Hardware name: Texas Instruments AM625 SK (DT)\n[ 789.490815] Workqueue: powervr-sched pvr_queue_fence_release_work [powervr]\n[ 789.490868] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 789.490876] pc : refcount_warn_saturate+0xf4/0x144\n[ 789.490884] lr : refcount_warn_saturate+0xf4/0x144\n[ 789.490892] sp : ffff8000822cbcc0\n[ 789.490895] x29: ffff8000822cbcc0 x28: 0000000000000000 x27: 0000000000000000\n[ 789.490909] x26: 0000000000000000 x25: ffff800081b1e338 x24: ffff000004541405\n[ 789.490922] x23: ffff000004bea950 x22: ffff00000042e400 x21: ffff000007123e30\n[ 789.490935] x20: ffff000007123000 x19: ffff000007a80d50 x18: fffffffffffe7768\n[ 789.490948] x17: 74736574202c6e6f x16: 697461746e656d65 x15: ffff800081b269f0\n[ 789.490962] x14: 0000000000000030 x13: ffff800081b26a70 x12: 0000000000000211\n[ 789.490975] x11: 00000000000000c0 x10: 0000000000000b50 x9 : ffff8000822cbb30\n[ 789.490988] x8 : ffff0000014e7bb0 x7 : ffff00007725e780 x6 : 0000000372a05f49\n[ 789.491001] x5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000010\n[ 789.491013] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0000014e7000\n[ 789.491027] Call trace:\n[ 789.491032] refcount_warn_saturate+0xf4/0x144 (P)\n[ 789.491043] drm_sched_entity_fini+0x164/0x18c [gpu_sched]\n[ 789.491081] pvr_queue_destroy+0x64/0x134 [powervr]\n[ 789.491110] pvr_context_destroy_queues+0x34/0x64 [powervr]\n[ 789.491138] pvr_context_release+0x70/0xac [powervr]\n[ 789.491166] pvr_context_put.part.0+0x5c/0x7c [powervr]\n[ 789.491193] pvr_context_put+0x14/0x24 [powervr]\n[ 789.491221] pvr_queue_fence_release_work+0x20/0x38 [powervr]\n[ 789.491249] process_one_work+0x160/0x4c4\n[ 789.491264] worker_thread+0x188/0x310\n[ 789.491276] kthread+0x130/0x13c\n[ 789.491287] ret_from_fork+0x10/0x20\n[ 789.491300] ---[ end trace 0000000000000000 ]---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the PowerVR DRM render node (/dev/dri/renderD*) via the DRM_IOCTL_PVR_CREATE_CONTEXT / SUBMIT_JOBS / DESTROY_CONTEXT ioctls or by closing the DRM file descriptor, which requires local access to the device.\nAC:L - pvr_context_destroy() unconditionally calls drm_sched_entity_destroy() (fini #1) and pvr_context_release() then calls drm_sched_entity_fini() again, so the extra stats kref put happens deterministically on every context teardown; the attacker also controls job submission, so keeping a job reference alive over the free window is trivially arranged.\nPR:L - All involved ioctls are marked DRM_RENDER_ALLOW, so any unprivileged local user (or sandboxed app on Android/embedded systems) that can open the render node \u2014 the normal configuration for graphics clients \u2014 can drive the path; no capability is required.\nUI:N - The attacker performs the whole sequence itself with open(), a few ioctls and close(); no action by another user or administrator is needed.\nS:U - The corruption stays within kernel memory managed by the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - The duplicate drm_sched_entity_stats_put() frees the kref\u0027d drm_sched_entity_stats slab object while in-flight jobs still hold pointers to it, so subsequent scheduler accesses read freed memory that an unprivileged process can reallocate and spray, allowing disclosure of arbitrary kernel data.\nI:H - After the premature free, drm_sched_entity_stats_job_add_gpu_time() takes stats-\u003elock and writes stats-\u003eruntime into reclaimed memory, giving a use-after-free write into an attacker-groomable kmalloc object that can be leveraged for privilege escalation.\nA:H - The refcount underflow triggers a WARNING splat and the resulting use-after-free on the entity stats object corrupts kernel heap state from the scheduler workqueue, readily causing an oops or panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:55.726Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9be3f4bd6f514f69c51a8c77ea64fce2729dc7f4"
},
{
"url": "https://git.kernel.org/stable/c/c88fdbf3da26e0179629530cae7768cd3d4ead85"
},
{
"url": "https://git.kernel.org/stable/c/c1136d907fd04ca5c62ba11c1159b5fe65a1760c"
},
{
"url": "https://git.kernel.org/stable/c/4af24c27a39ba147a613a09e10b9e0f7294524c0"
}
],
"title": "drm/imagination: Fix double call to drm_sched_entity_fini()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68263",
"datePublished": "2026-08-10T12:01:37.571Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:01:55.726Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68336 (GCVE-0-2026-68336)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bonding: fix devconf_all NULL dereference when IPv6 is disabled
When booting with the 'ipv6.disable=1' parameter, the devconf_all is
never initialized because inet6_init() exits before addrconf_init() is
called which initializes it. bond_send_validate(), however, will still
call bond_ns_send_all() even ipv6 is indeed disabled. It will lead to
NULL derefence of net->ipv6.devconf_all in ip6_pol_route().
BUG: kernel NULL pointer dereference, address: 000000000000000c
[...]
Workqueue: bond0 bond_arp_monitor [bonding]
RIP: 0010:ip6_pol_route+0x69/0x480
[...]
Call Trace:
<TASK>
? srso_return_thunk+0x5/0x5f
? __pfx_ip6_pol_route_output+0x10/0x10
fib6_rule_lookup+0xfe/0x260
? wakeup_preempt+0x8a/0x90
? srso_return_thunk+0x5/0x5f
? srso_return_thunk+0x5/0x5f
? sched_balance_rq+0x369/0x810
ip6_route_output_flags+0xd7/0x170
bond_ns_send_all+0xde/0x280 [bonding]
bond_ab_arp_probe+0x296/0x320 [bonding]
? srso_return_thunk+0x5/0x5f
bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]
process_one_work+0x196/0x370
worker_thread+0x1af/0x320
? srso_return_thunk+0x5/0x5f
? __pfx_worker_thread+0x10/0x10
kthread+0xe3/0x120
? __pfx_kthread+0x10/0x10
ret_from_fork+0x199/0x260
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Fix this by adding ipv6_mod_enabled() condition check in the caller.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "451c2d5422a309393aa8ae161fc1a527c2f19ab2",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "2a4bad24ac5296b262ad821aa5e08bb265e6b154",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "690ce66782778e8c4b1fdd79c0b0890a100e9522",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "992dce02bdabbd9883255ea9b36494e34a7821d7",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "738039ad21e20ca2c5bbde2f5a4f5ad5fb718038",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "1c975de3343cdef506f2eecc833cc1f14b0401c4",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix devconf_all NULL dereference when IPv6 is disabled\n\nWhen booting with the \u0027ipv6.disable=1\u0027 parameter, the devconf_all is\nnever initialized because inet6_init() exits before addrconf_init() is\ncalled which initializes it. bond_send_validate(), however, will still\ncall bond_ns_send_all() even ipv6 is indeed disabled. It will lead to\nNULL derefence of net-\u003eipv6.devconf_all in ip6_pol_route().\n\n BUG: kernel NULL pointer dereference, address: 000000000000000c\n [...]\n Workqueue: bond0 bond_arp_monitor [bonding]\n RIP: 0010:ip6_pol_route+0x69/0x480\n [...]\n Call Trace:\n \u003cTASK\u003e\n ? srso_return_thunk+0x5/0x5f\n ? __pfx_ip6_pol_route_output+0x10/0x10\n fib6_rule_lookup+0xfe/0x260\n ? wakeup_preempt+0x8a/0x90\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? sched_balance_rq+0x369/0x810\n ip6_route_output_flags+0xd7/0x170\n bond_ns_send_all+0xde/0x280 [bonding]\n bond_ab_arp_probe+0x296/0x320 [bonding]\n ? srso_return_thunk+0x5/0x5f\n bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]\n process_one_work+0x196/0x370\n worker_thread+0x1af/0x320\n ? srso_return_thunk+0x5/0x5f\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xe3/0x120\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x199/0x260\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e\n\nFix this by adding ipv6_mod_enabled() condition check in the caller."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:35.547Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/451c2d5422a309393aa8ae161fc1a527c2f19ab2"
},
{
"url": "https://git.kernel.org/stable/c/2a4bad24ac5296b262ad821aa5e08bb265e6b154"
},
{
"url": "https://git.kernel.org/stable/c/690ce66782778e8c4b1fdd79c0b0890a100e9522"
},
{
"url": "https://git.kernel.org/stable/c/992dce02bdabbd9883255ea9b36494e34a7821d7"
},
{
"url": "https://git.kernel.org/stable/c/738039ad21e20ca2c5bbde2f5a4f5ad5fb718038"
},
{
"url": "https://git.kernel.org/stable/c/1c975de3343cdef506f2eecc833cc1f14b0401c4"
}
],
"title": "bonding: fix devconf_all NULL dereference when IPv6 is disabled",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68336",
"datePublished": "2026-08-10T12:03:12.592Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:35.547Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64365 (GCVE-0-2026-64365)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: letsketch: fix UAF on inrange_timer at driver unbind
letsketch_driver does not provide a .remove callback, but
letsketch_probe() arms a per-device timer:
timer_setup(&data->inrange_timer, letsketch_inrange_timeout, 0);
The timer is re-armed from letsketch_raw_event() with a 100 ms
timeout on every pen-in-range report, and its callback dereferences
data->input_tablet to deliver a synthetic BTN_TOOL_PEN release.
letsketch_data is allocated with devm_kzalloc(), and its input_dev
fields are devm-allocated via letsketch_setup_input_tablet(). On
device unbind (USB unplug or rmmod), the HID core runs its default
teardown and devm cleanup frees both letsketch_data and the input
devices. Because no .remove callback exists, nothing drains the
timer first: if raw_event armed it within ~100 ms of the unbind,
the pending timer fires on freed memory. This is a UAF read of
data and of data->input_tablet, followed by input_report_key() /
input_sync() into the freed input_dev.
The same problem can occur on the probe error path: if
hid_hw_start() enabled I/O on an always-poll-quirk device and then
failed, raw_event may have armed the timer before devm releases
data.
Fix by adding a .remove callback that calls hid_hw_stop() first.
hid_hw_stop() synchronously kills the URBs that deliver raw_event(),
so once it returns no path can re-arm the timer. timer_shutdown_sync()
then drains any in-flight callback and permanently disables further
mod_timer() calls. Apply the same timer_shutdown_sync() in the probe
error path so the timer is guaranteed not to outlive data.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 33a5c2793451770cb6dcf0cc35c76cfd4b045513 Version: 33a5c2793451770cb6dcf0cc35c76cfd4b045513 Version: 33a5c2793451770cb6dcf0cc35c76cfd4b045513 Version: 33a5c2793451770cb6dcf0cc35c76cfd4b045513 Version: 33a5c2793451770cb6dcf0cc35c76cfd4b045513 Version: 33a5c2793451770cb6dcf0cc35c76cfd4b045513 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-letsketch.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2bb6e7143cf70ed281822d26c1848b2897ac36e9",
"status": "affected",
"version": "33a5c2793451770cb6dcf0cc35c76cfd4b045513",
"versionType": "git"
},
{
"lessThan": "523db788c0f84612707638e266e8957ca7e3a756",
"status": "affected",
"version": "33a5c2793451770cb6dcf0cc35c76cfd4b045513",
"versionType": "git"
},
{
"lessThan": "17f5928d7010bc9e002930326b59e60e40c09ee3",
"status": "affected",
"version": "33a5c2793451770cb6dcf0cc35c76cfd4b045513",
"versionType": "git"
},
{
"lessThan": "3eca1a8165b5e7996e699e9df76cb4645e184d42",
"status": "affected",
"version": "33a5c2793451770cb6dcf0cc35c76cfd4b045513",
"versionType": "git"
},
{
"lessThan": "df3d8aa1a9392da3de66398e7a03422463806b21",
"status": "affected",
"version": "33a5c2793451770cb6dcf0cc35c76cfd4b045513",
"versionType": "git"
},
{
"lessThan": "46c8beeccd8ab2c863827254a85ea877654a3534",
"status": "affected",
"version": "33a5c2793451770cb6dcf0cc35c76cfd4b045513",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-letsketch.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: letsketch: fix UAF on inrange_timer at driver unbind\n\nletsketch_driver does not provide a .remove callback, but\nletsketch_probe() arms a per-device timer:\n\n timer_setup(\u0026data-\u003einrange_timer, letsketch_inrange_timeout, 0);\n\nThe timer is re-armed from letsketch_raw_event() with a 100 ms\ntimeout on every pen-in-range report, and its callback dereferences\ndata-\u003einput_tablet to deliver a synthetic BTN_TOOL_PEN release.\n\nletsketch_data is allocated with devm_kzalloc(), and its input_dev\nfields are devm-allocated via letsketch_setup_input_tablet(). On\ndevice unbind (USB unplug or rmmod), the HID core runs its default\nteardown and devm cleanup frees both letsketch_data and the input\ndevices. Because no .remove callback exists, nothing drains the\ntimer first: if raw_event armed it within ~100 ms of the unbind,\nthe pending timer fires on freed memory. This is a UAF read of\ndata and of data-\u003einput_tablet, followed by input_report_key() /\ninput_sync() into the freed input_dev.\n\nThe same problem can occur on the probe error path: if\nhid_hw_start() enabled I/O on an always-poll-quirk device and then\nfailed, raw_event may have armed the timer before devm releases\ndata.\n\nFix by adding a .remove callback that calls hid_hw_stop() first.\nhid_hw_stop() synchronously kills the URBs that deliver raw_event(),\nso once it returns no path can re-arm the timer. timer_shutdown_sync()\nthen drains any in-flight callback and permanently disables further\nmod_timer() calls. Apply the same timer_shutdown_sync() in the probe\nerror path so the timer is guaranteed not to outlive data."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:13.108Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2bb6e7143cf70ed281822d26c1848b2897ac36e9"
},
{
"url": "https://git.kernel.org/stable/c/523db788c0f84612707638e266e8957ca7e3a756"
},
{
"url": "https://git.kernel.org/stable/c/17f5928d7010bc9e002930326b59e60e40c09ee3"
},
{
"url": "https://git.kernel.org/stable/c/3eca1a8165b5e7996e699e9df76cb4645e184d42"
},
{
"url": "https://git.kernel.org/stable/c/df3d8aa1a9392da3de66398e7a03422463806b21"
},
{
"url": "https://git.kernel.org/stable/c/46c8beeccd8ab2c863827254a85ea877654a3534"
}
],
"title": "HID: letsketch: fix UAF on inrange_timer at driver unbind",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64365",
"datePublished": "2026-07-25T08:50:20.039Z",
"dateReserved": "2026-07-19T15:36:31.783Z",
"dateUpdated": "2026-08-17T04:54:13.108Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64155 (GCVE-0-2026-64155)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix error path leaks in some WMI WOW calls
Fix two instances where we used to directly return the result of
ath11k_wmi_cmd_send(...). Because we did not check the return value, we
also did not free the skb in the error path.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 79802b13a492d0fdeb922e98628e5ff1a8b74026 Version: 79802b13a492d0fdeb922e98628e5ff1a8b74026 Version: 79802b13a492d0fdeb922e98628e5ff1a8b74026 Version: 79802b13a492d0fdeb922e98628e5ff1a8b74026 Version: 79802b13a492d0fdeb922e98628e5ff1a8b74026 Version: 79802b13a492d0fdeb922e98628e5ff1a8b74026 Version: 79802b13a492d0fdeb922e98628e5ff1a8b74026 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d6c7b8d0dc22c0a8743435db8f42d98524b70df3",
"status": "affected",
"version": "79802b13a492d0fdeb922e98628e5ff1a8b74026",
"versionType": "git"
},
{
"lessThan": "cd43d587dd333517c806cd24696e6e1a26b9951e",
"status": "affected",
"version": "79802b13a492d0fdeb922e98628e5ff1a8b74026",
"versionType": "git"
},
{
"lessThan": "3d675896ea03aca631852a2a7e91e6cb8f664967",
"status": "affected",
"version": "79802b13a492d0fdeb922e98628e5ff1a8b74026",
"versionType": "git"
},
{
"lessThan": "008955b1348452de25bc19d6e0f0f673d4cb9a3c",
"status": "affected",
"version": "79802b13a492d0fdeb922e98628e5ff1a8b74026",
"versionType": "git"
},
{
"lessThan": "acde4692afcdaea6de3e2996ddfaeaa7ae6b0130",
"status": "affected",
"version": "79802b13a492d0fdeb922e98628e5ff1a8b74026",
"versionType": "git"
},
{
"lessThan": "d618d322b95c80d5ad7091f35a7193e4050dcc27",
"status": "affected",
"version": "79802b13a492d0fdeb922e98628e5ff1a8b74026",
"versionType": "git"
},
{
"lessThan": "55dda532bbc261aef495e403c8900c5e2ab5fa34",
"status": "affected",
"version": "79802b13a492d0fdeb922e98628e5ff1a8b74026",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix error path leaks in some WMI WOW calls\n\nFix two instances where we used to directly return the result of\nath11k_wmi_cmd_send(...). Because we did not check the return value, we\nalso did not free the skb in the error path."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:43.545Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d6c7b8d0dc22c0a8743435db8f42d98524b70df3"
},
{
"url": "https://git.kernel.org/stable/c/cd43d587dd333517c806cd24696e6e1a26b9951e"
},
{
"url": "https://git.kernel.org/stable/c/3d675896ea03aca631852a2a7e91e6cb8f664967"
},
{
"url": "https://git.kernel.org/stable/c/008955b1348452de25bc19d6e0f0f673d4cb9a3c"
},
{
"url": "https://git.kernel.org/stable/c/acde4692afcdaea6de3e2996ddfaeaa7ae6b0130"
},
{
"url": "https://git.kernel.org/stable/c/d618d322b95c80d5ad7091f35a7193e4050dcc27"
},
{
"url": "https://git.kernel.org/stable/c/55dda532bbc261aef495e403c8900c5e2ab5fa34"
}
],
"title": "wifi: ath11k: fix error path leaks in some WMI WOW calls",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64155",
"datePublished": "2026-07-19T15:40:43.545Z",
"dateReserved": "2026-07-19T07:54:57.038Z",
"dateUpdated": "2026-07-19T15:40:43.545Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52956 (GCVE-0-2026-52956)
Vulnerability from cvelistv5
Published
2026-06-24 16:28
Modified
2026-08-05 12:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()
In __ceph_x_decrypt(), a part of the buffer p is interpreted as a
ceph_x_encrypt_header, and the magic field of this struct is accessed.
This happens without any guarantee that the buffer is large enough to
hold this struct. The function parameter ciphertext_len represents the
length of the ciphertext to decrypt and is guaranteed to be at most the
remaining size of the allocated buffer p. However, this value is not
necessarily greater than sizeof(ceph_x_encrypt_header). E.g., a message
frame of type FRAME_TAG_AUTH_REPLY_MORE, that is just as long to hold
the ciphertext at its end with a ciphertext_len of 8 or less, can
trigger an out-of-bounds memory access when accessing hdr->magic.
This patch fixes the issue by adding a check to ensure that the
decrypted plaintext in the buffer is large enough to represent at least
the ceph_x_encrypt_header.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/auth_x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c7e9b53aebe401970f1b5f5a01b4e021b18e8bb2",
"status": "affected",
"version": "e15fd0a11db00fc7f470a9fc804657ec3f6d04a5",
"versionType": "git"
},
{
"lessThan": "821365487aa58d06bda65c676ba215d506ba9768",
"status": "affected",
"version": "e15fd0a11db00fc7f470a9fc804657ec3f6d04a5",
"versionType": "git"
},
{
"status": "affected",
"version": "2982b9c92a66604ffb9fb2db54cf735133d1ef56",
"versionType": "git"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/auth_x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix potential out-of-bounds access in __ceph_x_decrypt()\n\nIn __ceph_x_decrypt(), a part of the buffer p is interpreted as a\nceph_x_encrypt_header, and the magic field of this struct is accessed.\nThis happens without any guarantee that the buffer is large enough to\nhold this struct. The function parameter ciphertext_len represents the\nlength of the ciphertext to decrypt and is guaranteed to be at most the\nremaining size of the allocated buffer p. However, this value is not\nnecessarily greater than sizeof(ceph_x_encrypt_header). E.g., a message\nframe of type FRAME_TAG_AUTH_REPLY_MORE, that is just as long to hold\nthe ciphertext at its end with a ciphertext_len of 8 or less, can\ntrigger an out-of-bounds memory access when accessing hdr-\u003emagic.\n\nThis patch fixes the issue by adding a check to ensure that the\ndecrypted plaintext in the buffer is large enough to represent at least\nthe ceph_x_encrypt_header."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable CephX decrypt path processes auth payloads received over the Ceph messenger TCP protocol from monitors/OSDs/MDSs. A malicious or compromised remote Ceph peer can supply the malformed auth frame during connection authentication.\nAC:L - The attacker controls the frame and ciphertext length needed to reach the missing plaintext-size check. No race or unusual victim state is required once the kernel client connects to the attacker-controlled peer.\nPR:N - The vulnerable parsing occurs in the authentication handshake before the remote peer has been authenticated by the kernel client. The attacker needs no privileges on the vulnerable system.\nUI:N - In a reasonable deployment, a configured kernel Ceph client connects or reconnects to its Ceph peers automatically. Exploitation does not require an interactive victim action at trigger time.\nS:U - The impact is within the kernel/client system processing the Ceph protocol. It does not cross a separate security authority such as a guest-to-host or IOMMU boundary.\nC:N - The bug is a bounded out-of-bounds read of the CephX encryption header magic field, but the read value is only compared internally and is not returned to the attacker. There is no practical information disclosure primitive.\nI:N - The vulnerable code performs no write based on the out-of-bounds access. The fix adds a read-side length check and there is no memory corruption or data modification path.\nA:H - The peer-controlled short plaintext can trigger an out-of-bounds kernel memory access in the auth receive path. Such kernel OOB accesses can produce an oops/panic or otherwise terminate the Ceph client connection, so availability impact is high."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:32:06.334Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c7e9b53aebe401970f1b5f5a01b4e021b18e8bb2"
},
{
"url": "https://git.kernel.org/stable/c/821365487aa58d06bda65c676ba215d506ba9768"
}
],
"title": "libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52956",
"datePublished": "2026-06-24T16:28:38.414Z",
"dateReserved": "2026-06-09T07:44:35.373Z",
"dateUpdated": "2026-08-05T12:32:06.334Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68129 (GCVE-0-2026-68129)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gve: fix Rx queue stall on alloc failure
When the system is under extreme memory pressure, page allocations can
fail during the Rx buffer refill loop. If the number of buffers posted
to hardware falls below a critical low threshold and the refill loop
exits due to allocation failures, the queue can stall:
1. The device drops incoming packets because there are no descriptors.
2. Since no packets are processed, no Rx completions are generated.
3. Because no completions occur, NAPI is never scheduled, preventing
the refill loop from running again even after memory is freed.
This results in a permanent queue stall.
Resolve this by introducing a starvation recovery timer for each Rx queue.
If the number of buffers posted to hardware falls below a critical low
threshold, start a timer to periodically reschedule NAPI. Once NAPI runs
and successfully refills the queue above the threshold, the timer is
not rescheduled.
The threshold is set to 32 because a single maximum-sized Receive Segment
Coalescing (RSC) packet can consume up to 19 descriptors in the Rx path.
Lower thresholds (such as 8 or 16) would be insufficient to process a
complete maximum-sized RSC packet, risking packet drops or unexpected
hardware behavior under memory pressure. Setting the threshold to 32
guarantees a safe margin to handle at least one full RSC packet.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/google/gve/gve.h",
"drivers/net/ethernet/google/gve/gve_rx_dqo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9db46e19e5d6bdcd4bf811284a5b0df1b984ef80",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "42d525e751c61b876b2b0ae4e71ba7a8ab0c2777",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "299d5728a7312fdd02059b074aebbe4ebbd391e4",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "0c317349b4baa5038d1fc373bf46d5a2419d1710",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "91e0249f3ef62b75fe8c9c9372eaba32876e4b3a",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "689b9f588d2d7323dc66293fe594a68d030f400f",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "b65352a1bac64442ad95e64f385b40ccb9f1b0db",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/google/gve/gve.h",
"drivers/net/ethernet/google/gve/gve_rx_dqo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngve: fix Rx queue stall on alloc failure\n\nWhen the system is under extreme memory pressure, page allocations can\nfail during the Rx buffer refill loop. If the number of buffers posted\nto hardware falls below a critical low threshold and the refill loop\nexits due to allocation failures, the queue can stall:\n\n1. The device drops incoming packets because there are no descriptors.\n2. Since no packets are processed, no Rx completions are generated.\n3. Because no completions occur, NAPI is never scheduled, preventing\n the refill loop from running again even after memory is freed.\n\nThis results in a permanent queue stall.\n\nResolve this by introducing a starvation recovery timer for each Rx queue.\nIf the number of buffers posted to hardware falls below a critical low\nthreshold, start a timer to periodically reschedule NAPI. Once NAPI runs\nand successfully refills the queue above the threshold, the timer is\nnot rescheduled.\n\nThe threshold is set to 32 because a single maximum-sized Receive Segment\nCoalescing (RSC) packet can consume up to 19 descriptors in the Rx path.\nLower thresholds (such as 8 or 16) would be insufficient to process a\ncomplete maximum-sized RSC packet, risking packet drops or unexpected\nhardware behavior under memory pressure. Setting the threshold to 32\nguarantees a safe margin to handle at least one full RSC packet."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in the gVNIC receive/refill path driven by incoming network traffic on internet-facing Google Cloud VMs; remote packets trigger NAPI polling that reaches gve_rx_post_buffers_dqo() where the stall occurs.\nAC:L - An attacker can reliably drive the vulnerable refill loop by sending high-volume traffic to exhaust RX page-pool buffers and pressure GFP_ATOMIC allocations; no race or rare layout is required beyond sustained network load.\nPR:N - Exploitation requires only the ability to send packets to the VM\u0027s gVNIC interface; no local account, capabilities, or authentication is needed on internet-reachable cloud instances.\nUI:N - No victim interaction is required; the permanent RX queue stall is triggered automatically during kernel packet receive processing under memory pressure.\nS:U - Impact is confined to the affected guest\u0027s network stack and does not cross VM, container, or IOMMU security boundaries; it is a guest-local denial of service, not an escape.\nC:N - This is a resource-management logic bug causing queue starvation with no out-of-bounds access, use-after-free, or information disclosure; no kernel or user memory is read by the attacker.\nI:N - The bug causes a permanent receive-queue stall without modifying kernel data structures, user data, or enabling code execution; there is no integrity impact beyond loss of connectivity.\nA:H - A failed refill below the 32-descriptor threshold permanently stalls the RX queue because no completions schedule NAPI again, causing lasting loss of network receive capability until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:44.226Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9db46e19e5d6bdcd4bf811284a5b0df1b984ef80"
},
{
"url": "https://git.kernel.org/stable/c/42d525e751c61b876b2b0ae4e71ba7a8ab0c2777"
},
{
"url": "https://git.kernel.org/stable/c/299d5728a7312fdd02059b074aebbe4ebbd391e4"
},
{
"url": "https://git.kernel.org/stable/c/0c317349b4baa5038d1fc373bf46d5a2419d1710"
},
{
"url": "https://git.kernel.org/stable/c/91e0249f3ef62b75fe8c9c9372eaba32876e4b3a"
},
{
"url": "https://git.kernel.org/stable/c/689b9f588d2d7323dc66293fe594a68d030f400f"
},
{
"url": "https://git.kernel.org/stable/c/b65352a1bac64442ad95e64f385b40ccb9f1b0db"
}
],
"title": "gve: fix Rx queue stall on alloc failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68129",
"datePublished": "2026-08-10T11:58:51.406Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:44.226Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64593 (GCVE-0-2026-64593)
Vulnerability from cvelistv5
Published
2026-08-06 07:13
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: do not trim a device which is not writeable
[BUG]
There is a bug report that btrfs/242 can randomly fail with the
following NULL pointer dereference:
run fstests btrfs/242 at 2026-06-01 10:25:08
BTRFS: device fsid d4d7f234-487c-4787-88e4-47a8b68c9874 devid 1 transid 9 /dev/sdc (8:32) scanned by mount (122609)
BTRFS info (device sdc): first mount of filesystem d4d7f234-487c-4787-88e4-47a8b68c9874
BTRFS info (device sdc): using crc32c checksum algorithm
BTRFS warning (device sdc): devid 2 uuid fbe72d72-3272-482d-80fb-ab88ed398192 is missing
BTRFS warning (device sdc): devid 2 uuid fbe72d72-3272-482d-80fb-ab88ed398192 is missing
BTRFS info (device sdc): allowing degraded mounts
BTRFS info (device sdc): turning on async discard
BTRFS info (device sdc): enabling free space tree
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000018
user pgtable: 4k pages, 48-bit VAs, pgdp=000000013fd6b000
CPU: 4 UID: 0 PID: 122625 Comm: fstrim Not tainted 7.0.10-2-default #1 PREEMPT(full) openSUSE Tumbleweed e9a5f6b24978fba3bf015a992f865837fdfff3dd
Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20250812-19.fc42 08/12/2025
pstate: 01400005 (nzcv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)
pc : btrfs_trim_fs+0x34c/0xa00 [btrfs]
lr : btrfs_trim_fs+0x1f0/0xa00 [btrfs]
Call trace:
btrfs_trim_fs+0x34c/0xa00 [btrfs f02c1d570ceea621c69d302ba75dd61868083840] (P)
btrfs_ioctl_fitrim+0xe8/0x178 [btrfs f02c1d570ceea621c69d302ba75dd61868083840]
btrfs_ioctl+0xdd4/0x2bd8 [btrfs f02c1d570ceea621c69d302ba75dd61868083840]
__arm64_sys_ioctl+0xac/0x108
invoke_syscall.constprop.0+0x5c/0xd0
el0_svc_common.constprop.0+0x40/0xf0
do_el0_svc+0x24/0x40
el0_svc+0x40/0x1d0
el0t_64_sync_handler+0xa0/0xe8
el0t_64_sync+0x1b0/0x1b8
Code: 17ffff83 f94017e0 f9002be0 f9402ea0 (f9400c00)
---[ end trace 0000000000000000 ]---
Also the reporter is very kind to test the following ASSERT() added to
btrfs_trim_free_extents_throttle():
ASSERT(device->bdev,
"devid=%llu path=%s dev_state=0x%lx\n",
device->devid, btrfs_dev_name(device), device->dev_state);
And it shows the following output:
assertion failed: device->bdev, in extent-tree.c:6630 (devid=2 path=/dev/sdd dev_state=0x82)
Which means the device->bdev is NULL, and the dev_state is
BTRFS_DEV_STATE_IN_FS_METADATA | BTRFS_DEV_STATE_ITEM_FOUND, without
BTRFS_DEV_STATE_WRITEABLE flag set.
[CAUSE]
The pc points to the following call chain:
btrfs_trim_fs()
|- btrfs_trim_free_extents()
|- btrfs_trim_free_extents_throttle()
|- bdev_max_discard_sectors(device->bdev)
So the NULL pointer dereference is caused by device->bdev being NULL.
This looks impossible by a quick glance, as just before calling
btrfs_trim_free_extents_throttle(), we have skipped any device that has
BTRFS_DEV_STATE_MISSING flag set.
However in this particular case, there is a window where the missing
device is later re-scanned, causing btrfs to remove the
BTRFS_DEV_STATE_MISSING flag:
btrfs_control_ioctl()
|- btrfs_scan_one_device()
|- device_list_add()
|- rcu_assign_pointer(device->name, name);
| This updates the missing device's path to the new good path.
|
|- clear_bit(BTRFS_DEV_STATE_MISSING, &device->dev_state)
This removes the BTRFS_DEV_STATE_MISSING flag.
This allows the missing device to re-appear and clear the
BTRFS_DEV_STATE_MISSING flag. However the device still does not have
the BTRFS_DEV_STATE_WRITEABLE flag set, nor is its bdev pointer updated.
The bdev pointer remains NULL, triggering the crash later.
[FIX]
This is a big de-synchronization between BTRFS_DEV_STATE_MISSING and
device->bdev pointer, and shows a gap in btrfs's re-appearing-device
handling.
The proper handling of re-appearing device will need quite some extra
work, which is out of the context of this small
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 499f377f49f085ee4aa214c738e948e88626f39b Version: 499f377f49f085ee4aa214c738e948e88626f39b Version: 499f377f49f085ee4aa214c738e948e88626f39b Version: 499f377f49f085ee4aa214c738e948e88626f39b Version: 499f377f49f085ee4aa214c738e948e88626f39b Version: 499f377f49f085ee4aa214c738e948e88626f39b Version: 499f377f49f085ee4aa214c738e948e88626f39b Version: 499f377f49f085ee4aa214c738e948e88626f39b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/extent-tree.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f41ae7e6664f3c4361129728f2c4d5f3ed995251",
"status": "affected",
"version": "499f377f49f085ee4aa214c738e948e88626f39b",
"versionType": "git"
},
{
"lessThan": "210af872eafa0cf572a84cb303c0f9d2914c1226",
"status": "affected",
"version": "499f377f49f085ee4aa214c738e948e88626f39b",
"versionType": "git"
},
{
"lessThan": "3d8fa4b828a86b33c60858e58aaab6df273ede05",
"status": "affected",
"version": "499f377f49f085ee4aa214c738e948e88626f39b",
"versionType": "git"
},
{
"lessThan": "9c894159c5b8adc84072e3af0e55b0473a69564e",
"status": "affected",
"version": "499f377f49f085ee4aa214c738e948e88626f39b",
"versionType": "git"
},
{
"lessThan": "02c903fc6fc7e16c5d1f22d18784f1208acf43e3",
"status": "affected",
"version": "499f377f49f085ee4aa214c738e948e88626f39b",
"versionType": "git"
},
{
"lessThan": "7a64521802997257b144e6edfb4e278dbeb972dd",
"status": "affected",
"version": "499f377f49f085ee4aa214c738e948e88626f39b",
"versionType": "git"
},
{
"lessThan": "b4af31b898a948e29861cb0bae734058f9a49d9b",
"status": "affected",
"version": "499f377f49f085ee4aa214c738e948e88626f39b",
"versionType": "git"
},
{
"lessThan": "1b1937eb08f51319bf71575484cde2b8c517aedc",
"status": "affected",
"version": "499f377f49f085ee4aa214c738e948e88626f39b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/extent-tree.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.3"
},
{
"lessThan": "4.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not trim a device which is not writeable\n\n[BUG]\nThere is a bug report that btrfs/242 can randomly fail with the\nfollowing NULL pointer dereference:\n\n run fstests btrfs/242 at 2026-06-01 10:25:08\n BTRFS: device fsid d4d7f234-487c-4787-88e4-47a8b68c9874 devid 1 transid 9 /dev/sdc (8:32) scanned by mount (122609)\n BTRFS info (device sdc): first mount of filesystem d4d7f234-487c-4787-88e4-47a8b68c9874\n BTRFS info (device sdc): using crc32c checksum algorithm\n BTRFS warning (device sdc): devid 2 uuid fbe72d72-3272-482d-80fb-ab88ed398192 is missing\n BTRFS warning (device sdc): devid 2 uuid fbe72d72-3272-482d-80fb-ab88ed398192 is missing\n BTRFS info (device sdc): allowing degraded mounts\n BTRFS info (device sdc): turning on async discard\n BTRFS info (device sdc): enabling free space tree\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000018\n user pgtable: 4k pages, 48-bit VAs, pgdp=000000013fd6b000\n CPU: 4 UID: 0 PID: 122625 Comm: fstrim Not tainted 7.0.10-2-default #1 PREEMPT(full) openSUSE Tumbleweed e9a5f6b24978fba3bf015a992f865837fdfff3dd\n Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20250812-19.fc42 08/12/2025\n pstate: 01400005 (nzcv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n pc : btrfs_trim_fs+0x34c/0xa00 [btrfs]\n lr : btrfs_trim_fs+0x1f0/0xa00 [btrfs]\n Call trace:\n btrfs_trim_fs+0x34c/0xa00 [btrfs f02c1d570ceea621c69d302ba75dd61868083840] (P)\n btrfs_ioctl_fitrim+0xe8/0x178 [btrfs f02c1d570ceea621c69d302ba75dd61868083840]\n btrfs_ioctl+0xdd4/0x2bd8 [btrfs f02c1d570ceea621c69d302ba75dd61868083840]\n __arm64_sys_ioctl+0xac/0x108\n invoke_syscall.constprop.0+0x5c/0xd0\n el0_svc_common.constprop.0+0x40/0xf0\n do_el0_svc+0x24/0x40\n el0_svc+0x40/0x1d0\n el0t_64_sync_handler+0xa0/0xe8\n el0t_64_sync+0x1b0/0x1b8\n Code: 17ffff83 f94017e0 f9002be0 f9402ea0 (f9400c00)\n ---[ end trace 0000000000000000 ]---\n\nAlso the reporter is very kind to test the following ASSERT() added to\nbtrfs_trim_free_extents_throttle():\n\n\tASSERT(device-\u003ebdev,\n\t \"devid=%llu path=%s dev_state=0x%lx\\n\",\n\t device-\u003edevid, btrfs_dev_name(device), device-\u003edev_state);\n\nAnd it shows the following output:\n\n assertion failed: device-\u003ebdev, in extent-tree.c:6630 (devid=2 path=/dev/sdd dev_state=0x82)\n\nWhich means the device-\u003ebdev is NULL, and the dev_state is\nBTRFS_DEV_STATE_IN_FS_METADATA | BTRFS_DEV_STATE_ITEM_FOUND, without\nBTRFS_DEV_STATE_WRITEABLE flag set.\n\n[CAUSE]\nThe pc points to the following call chain:\n\n btrfs_trim_fs()\n |- btrfs_trim_free_extents()\n |- btrfs_trim_free_extents_throttle()\n |- bdev_max_discard_sectors(device-\u003ebdev)\n\nSo the NULL pointer dereference is caused by device-\u003ebdev being NULL.\n\nThis looks impossible by a quick glance, as just before calling\nbtrfs_trim_free_extents_throttle(), we have skipped any device that has\nBTRFS_DEV_STATE_MISSING flag set.\n\nHowever in this particular case, there is a window where the missing\ndevice is later re-scanned, causing btrfs to remove the\nBTRFS_DEV_STATE_MISSING flag:\n\n btrfs_control_ioctl()\n |- btrfs_scan_one_device()\n |- device_list_add()\n |- rcu_assign_pointer(device-\u003ename, name);\n | This updates the missing device\u0027s path to the new good path.\n |\n |- clear_bit(BTRFS_DEV_STATE_MISSING, \u0026device-\u003edev_state)\n This removes the BTRFS_DEV_STATE_MISSING flag.\n\nThis allows the missing device to re-appear and clear the\nBTRFS_DEV_STATE_MISSING flag. However the device still does not have\nthe BTRFS_DEV_STATE_WRITEABLE flag set, nor is its bdev pointer updated.\n\nThe bdev pointer remains NULL, triggering the crash later.\n\n[FIX]\nThis is a big de-synchronization between BTRFS_DEV_STATE_MISSING and\ndevice-\u003ebdev pointer, and shows a gap in btrfs\u0027s re-appearing-device\nhandling.\n\nThe proper handling of re-appearing device will need quite some extra\nwork, which is out of the context of this small\n---truncated---"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:15.319Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f41ae7e6664f3c4361129728f2c4d5f3ed995251"
},
{
"url": "https://git.kernel.org/stable/c/210af872eafa0cf572a84cb303c0f9d2914c1226"
},
{
"url": "https://git.kernel.org/stable/c/3d8fa4b828a86b33c60858e58aaab6df273ede05"
},
{
"url": "https://git.kernel.org/stable/c/9c894159c5b8adc84072e3af0e55b0473a69564e"
},
{
"url": "https://git.kernel.org/stable/c/02c903fc6fc7e16c5d1f22d18784f1208acf43e3"
},
{
"url": "https://git.kernel.org/stable/c/7a64521802997257b144e6edfb4e278dbeb972dd"
},
{
"url": "https://git.kernel.org/stable/c/b4af31b898a948e29861cb0bae734058f9a49d9b"
},
{
"url": "https://git.kernel.org/stable/c/1b1937eb08f51319bf71575484cde2b8c517aedc"
}
],
"title": "btrfs: do not trim a device which is not writeable",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64593",
"datePublished": "2026-08-06T07:13:49.700Z",
"dateReserved": "2026-07-19T15:36:31.799Z",
"dateUpdated": "2026-08-17T04:58:15.319Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64029 (GCVE-0-2026-64029)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: seq: Serialize UMP output teardown with event_input
seq_ump_process_event() borrows client->out_rfile.output without
synchronizing with the first-open and last-close transition in
seq_ump_client_open() and seq_ump_client_close().
The last output unuse can therefore drop opened[STR_OUT] to zero and
release the rawmidi file while an in-flight event_input callback is still
inside snd_rawmidi_kernel_write(). That leaves the rawmidi substream
runtime exposed to teardown before the write path has taken its own
buffer reference.
Add a per-client rwlock for the event_input-visible output file. Publish
a newly opened output file under the write side, and hold the read side
from the output lookup through snd_rawmidi_kernel_write(). The last
output close copies and clears the visible output file under the write
side, then drops the lock and releases the saved rawmidi file. Use
IRQ-safe rwlock guards because event_input can also be reached from
atomic sequencer delivery.
The buggy scenario involves two paths, with each column showing the
order within that path:
path A label: event_input path path B label: last unuse path
1. seq_ump_process_event() reads 1. seq_ump_client_close()
client->out_rfile.output. drops opened[STR_OUT] to zero.
2. snd_rawmidi_kernel_write1() 2. snd_rawmidi_kernel_release()
has not yet pinned runtime. closes the output file.
3. The writer continues using 3. close_substream() frees
the borrowed substream. substream->runtime.
This keeps the output substream and runtime alive for the full
event_input write while keeping rawmidi release outside the rwlock.
KASAN reproduced this as a slab-use-after-free in
snd_rawmidi_kernel_write1(), with allocation through
seq_ump_use()/snd_seq_port_connect() and free through
seq_ump_unuse()/snd_seq_port_disconnect().
Validation reproduced this kernel report:
KASAN slab-use-after-free in snd_rawmidi_kernel_write1+0x9d/0x400
RIP: 0033:0x7f5528af837f
Read of size 8
Call trace:
dump_stack_lvl+0x73/0xb0 (?:?)
print_report+0xd1/0x650 (?:?)
srso_alias_return_thunk+0x5/0xfbef5 (?:?)
__virt_addr_valid+0x1a7/0x340 (?:?)
kasan_complete_mode_report_info+0x64/0x200 (?:?)
kasan_report+0xf7/0x130 (?:?)
snd_rawmidi_kernel_write1+0x9d/0x400 (?:?)
__asan_load8+0x82/0xb0 (?:?)
update_stack_state+0x1ef/0x2d0 (?:?)
snd_rawmidi_kernel_write+0x1a/0x20 (?:?)
seq_ump_process_event+0xd4/0x120 (sound/core/seq/seq_ump_client.c:82)
__snd_seq_deliver_single_event+0x8a/0xe0 (?:?)
snd_seq_deliver_from_ump+0x2b2/0xd60 (?:?)
lock_acquire+0x14e/0x2e0 (?:?)
find_held_lock+0x31/0x90 (?:?)
snd_seq_port_use_ptr+0xa6/0xe0 (?:?)
__kasan_check_write+0x18/0x20 (?:?)
do_raw_read_unlock+0x32/0xa0 (?:?)
_raw_read_unlock+0x26/0x50 (?:?)
snd_seq_deliver_single_event+0x45c/0x4b0 (?:?)
snd_seq_deliver_event+0x10d/0x1b0 (?:?)
snd_seq_client_enqueue_event+0x192/0x240 (?:?)
snd_seq_write+0x2cd/0x450 (?:?)
apparmor_file_permission+0x20/0x30 (?:?)
security_file_permission+0x51/0x60 (?:?)
vfs_write+0x1ce/0x850 (?:?)
__fget_files+0x12b/0x220 (?:?)
lock_release+0xc8/0x2a0 (?:?)
__rcu_read_unlock+0x74/0x2d0 (?:?)
__fget_files+0x135/0x220 (?:?)
ksys_write+0x15a/0x180 (?:?)
rcu_is_watching+0x24/0x60 (?:?)
__x64_sys_write+0x46/0x60 (?:?)
x64_sys_call+0x7d/0x20d0 (?:?)
do_syscall_64+0xc1/0x360 (arch/x86/entry/syscall_64.c:87)
entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/core/seq/seq_ump_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8ba1c4ddbb1c67d34bb440aecb9f5690ed3f64cb",
"status": "affected",
"version": "81fd444aa371261cd33f31d4ffd80faeeeab0cc9",
"versionType": "git"
},
{
"lessThan": "0cb1ad795570167558530d6194297ac2396a1991",
"status": "affected",
"version": "81fd444aa371261cd33f31d4ffd80faeeeab0cc9",
"versionType": "git"
},
{
"lessThan": "3aab4a58d23fb22dac5b558bbe5df1a8dad00b4b",
"status": "affected",
"version": "81fd444aa371261cd33f31d4ffd80faeeeab0cc9",
"versionType": "git"
},
{
"lessThan": "ef46b616a4c219185bbf10ebcbacb571583fd0e4",
"status": "affected",
"version": "81fd444aa371261cd33f31d4ffd80faeeeab0cc9",
"versionType": "git"
},
{
"lessThan": "60a1969fae6209644698fca91c185d153674f631",
"status": "affected",
"version": "81fd444aa371261cd33f31d4ffd80faeeeab0cc9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/core/seq/seq_ump_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Serialize UMP output teardown with event_input\n\nseq_ump_process_event() borrows client-\u003eout_rfile.output without\nsynchronizing with the first-open and last-close transition in\nseq_ump_client_open() and seq_ump_client_close().\n\nThe last output unuse can therefore drop opened[STR_OUT] to zero and\nrelease the rawmidi file while an in-flight event_input callback is still\ninside snd_rawmidi_kernel_write(). That leaves the rawmidi substream\nruntime exposed to teardown before the write path has taken its own\nbuffer reference.\n\nAdd a per-client rwlock for the event_input-visible output file. Publish\na newly opened output file under the write side, and hold the read side\nfrom the output lookup through snd_rawmidi_kernel_write(). The last\noutput close copies and clears the visible output file under the write\nside, then drops the lock and releases the saved rawmidi file. Use\nIRQ-safe rwlock guards because event_input can also be reached from\natomic sequencer delivery.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\npath A label: event_input path path B label: last unuse path\n1. seq_ump_process_event() reads 1. seq_ump_client_close()\n client-\u003eout_rfile.output. drops opened[STR_OUT] to zero.\n2. snd_rawmidi_kernel_write1() 2. snd_rawmidi_kernel_release()\n has not yet pinned runtime. closes the output file.\n3. The writer continues using 3. close_substream() frees\n the borrowed substream. substream-\u003eruntime.\n\nThis keeps the output substream and runtime alive for the full\nevent_input write while keeping rawmidi release outside the rwlock.\n\nKASAN reproduced this as a slab-use-after-free in\nsnd_rawmidi_kernel_write1(), with allocation through\nseq_ump_use()/snd_seq_port_connect() and free through\nseq_ump_unuse()/snd_seq_port_disconnect().\n\n\nValidation reproduced this kernel report:\nKASAN slab-use-after-free in snd_rawmidi_kernel_write1+0x9d/0x400\nRIP: 0033:0x7f5528af837f\nRead of size 8\nCall trace:\n dump_stack_lvl+0x73/0xb0 (?:?)\n print_report+0xd1/0x650 (?:?)\n srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n __virt_addr_valid+0x1a7/0x340 (?:?)\n kasan_complete_mode_report_info+0x64/0x200 (?:?)\n kasan_report+0xf7/0x130 (?:?)\n snd_rawmidi_kernel_write1+0x9d/0x400 (?:?)\n __asan_load8+0x82/0xb0 (?:?)\n update_stack_state+0x1ef/0x2d0 (?:?)\n snd_rawmidi_kernel_write+0x1a/0x20 (?:?)\n seq_ump_process_event+0xd4/0x120 (sound/core/seq/seq_ump_client.c:82)\n __snd_seq_deliver_single_event+0x8a/0xe0 (?:?)\n snd_seq_deliver_from_ump+0x2b2/0xd60 (?:?)\n lock_acquire+0x14e/0x2e0 (?:?)\n find_held_lock+0x31/0x90 (?:?)\n snd_seq_port_use_ptr+0xa6/0xe0 (?:?)\n __kasan_check_write+0x18/0x20 (?:?)\n do_raw_read_unlock+0x32/0xa0 (?:?)\n _raw_read_unlock+0x26/0x50 (?:?)\n snd_seq_deliver_single_event+0x45c/0x4b0 (?:?)\n snd_seq_deliver_event+0x10d/0x1b0 (?:?)\n snd_seq_client_enqueue_event+0x192/0x240 (?:?)\n snd_seq_write+0x2cd/0x450 (?:?)\n apparmor_file_permission+0x20/0x30 (?:?)\n security_file_permission+0x51/0x60 (?:?)\n vfs_write+0x1ce/0x850 (?:?)\n __fget_files+0x12b/0x220 (?:?)\n lock_release+0xc8/0x2a0 (?:?)\n __rcu_read_unlock+0x74/0x2d0 (?:?)\n __fget_files+0x135/0x220 (?:?)\n ksys_write+0x15a/0x180 (?:?)\n rcu_is_watching+0x24/0x60 (?:?)\n __x64_sys_write+0x46/0x60 (?:?)\n x64_sys_call+0x7d/0x20d0 (?:?)\n do_syscall_64+0xc1/0x360 (arch/x86/entry/syscall_64.c:87)\n entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access via the ALSA sequencer device node (/dev/snd/seq) using write(2) and port-subscription ioctls; there is no network, Bluetooth, or physical-device attack surface on the vulnerable code path.\nAC:L - The race is between concurrent UMP event delivery and the last output-port unsubscribe/close path, and a local attacker can control both sides with parallel threads (flood write() while repeatedly subscribing/unsubscribing to the UMP port).\nPR:L - Any local unprivileged user who can open /dev/snd/seq (typically membership in the audio group on desktop/workstation systems where UMP MIDI hardware is present) can create sequencer clients, subscribe to UMP kernel ports, and trigger the bug without real root or init-namespace capabilities.\nUI:N - Exploitation is fully attacker-driven through sequencer writes and subscription management; no victim interaction such as opening files, mounting filesystems, or plugging in devices is required beyond the UMP endpoint already being present on the system.\nS:U - Impact is confined to kernel memory corruption and potential local privilege escalation within the same kernel security boundary; this is not a VM escape, sandbox escape, or cross-authority boundary bypass.\nC:H - KASAN confirmed a slab use-after-free on freed substream runtime metadata in snd_rawmidi_kernel_write1(); UAF on kernel heap objects enables controlled reallocation and arbitrary kernel memory disclosure primitives.\nI:H - The UAF occurs inside snd_rawmidi_kernel_write1(), which performs memcpy() into runtime-\u003ebuffer using attacker-supplied UMP event payload, providing a plausible path to arbitrary kernel memory corruption and code execution beyond a simple crash.\nA:H - The confirmed KASAN slab-use-after-free in kernel write path causes kernel oops/panic; even without full exploitation, the bug reliably threatens system availability through kernel crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:23.130Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8ba1c4ddbb1c67d34bb440aecb9f5690ed3f64cb"
},
{
"url": "https://git.kernel.org/stable/c/0cb1ad795570167558530d6194297ac2396a1991"
},
{
"url": "https://git.kernel.org/stable/c/3aab4a58d23fb22dac5b558bbe5df1a8dad00b4b"
},
{
"url": "https://git.kernel.org/stable/c/ef46b616a4c219185bbf10ebcbacb571583fd0e4"
},
{
"url": "https://git.kernel.org/stable/c/60a1969fae6209644698fca91c185d153674f631"
}
],
"title": "ALSA: seq: Serialize UMP output teardown with event_input",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64029",
"datePublished": "2026-07-19T15:39:20.368Z",
"dateReserved": "2026-07-19T07:54:57.028Z",
"dateUpdated": "2026-08-05T12:38:23.130Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64331 (GCVE-0-2026-64331)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usbip: vudc: fix NULL deref in vep_dequeue()
vep_alloc_request() wasn't initializing vrequest->udc, so cancellations
on the FunctionFS AIO path were arriving in vep_dequeue without a valid
UDC reference.
Since vrequest->udc is never actually properly used anywhere, we opt to
remove it, and update vep_dequeue to obtain a reference to the udc with
ep_to_vudc(), consistent with the other vep_ ops.
AFAICT this bug has existed for ~10 years. Seems that nobody has really
stressed the FunctionFS AIO path on usbip's vudc.
I tested this fix in a QEMU aarch64 guest driving FunctionFS endpoints
via AIO. Before the fix, running `usbip attach` from the host would
cause the guest to oops with the following backtrace:
Call trace:
vep_dequeue+0x1c/0xe4 (P)
usb_ep_dequeue+0x14/0x20
ffs_aio_cancel+0x24/0x34
__arm64_sys_io_cancel+0xb0/0x124
do_el0_svc+0x68/0x100
el0_svc+0x18/0x5c
el0t_64_sync_handler+0x98/0xdc
el0t_64_sync+0x154/0x158
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b6a0ca11186759ad7045d68a5447b1e89f658384 Version: b6a0ca11186759ad7045d68a5447b1e89f658384 Version: b6a0ca11186759ad7045d68a5447b1e89f658384 Version: b6a0ca11186759ad7045d68a5447b1e89f658384 Version: b6a0ca11186759ad7045d68a5447b1e89f658384 Version: b6a0ca11186759ad7045d68a5447b1e89f658384 Version: b6a0ca11186759ad7045d68a5447b1e89f658384 Version: b6a0ca11186759ad7045d68a5447b1e89f658384 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/usbip/vudc.h",
"drivers/usb/usbip/vudc_dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9858c91d9ee6a13c45311569039413729fc9b757",
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"versionType": "git"
},
{
"lessThan": "1226293ec9bed3d4cc5b05eeeb811d315ca51652",
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"versionType": "git"
},
{
"lessThan": "3750f75f29f99c0223601e2ee73ad084adec47bd",
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"versionType": "git"
},
{
"lessThan": "d0ebf9cc7c2ddf95a7cfc654b940bdacb7edde97",
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"versionType": "git"
},
{
"lessThan": "0025276175fbbe0dcbf3f84d090b0adee769e9d9",
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"versionType": "git"
},
{
"lessThan": "347b59e9f96719d89b6ef555d02a18ada1a5846f",
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"versionType": "git"
},
{
"lessThan": "0443e4416aa1ee97748d1ed904eaf3352c60045e",
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"versionType": "git"
},
{
"lessThan": "c5371e0b91b24159a3ebaa61e70b0980bcf03c0a",
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/usbip/vudc.h",
"drivers/usb/usbip/vudc_dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusbip: vudc: fix NULL deref in vep_dequeue()\n\nvep_alloc_request() wasn\u0027t initializing vrequest-\u003eudc, so cancellations\non the FunctionFS AIO path were arriving in vep_dequeue without a valid\nUDC reference.\n\nSince vrequest-\u003eudc is never actually properly used anywhere, we opt to\nremove it, and update vep_dequeue to obtain a reference to the udc with\nep_to_vudc(), consistent with the other vep_ ops.\n\nAFAICT this bug has existed for ~10 years. Seems that nobody has really\nstressed the FunctionFS AIO path on usbip\u0027s vudc.\n\nI tested this fix in a QEMU aarch64 guest driving FunctionFS endpoints\nvia AIO. Before the fix, running `usbip attach` from the host would\ncause the guest to oops with the following backtrace:\n\nCall trace:\n vep_dequeue+0x1c/0xe4 (P)\n usb_ep_dequeue+0x14/0x20\n ffs_aio_cancel+0x24/0x34\n __arm64_sys_io_cancel+0xb0/0x124\n do_el0_svc+0x68/0x100\n el0_svc+0x18/0x5c\n el0t_64_sync_handler+0x98/0xdc\n el0t_64_sync+0x154/0x158"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:33.891Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9858c91d9ee6a13c45311569039413729fc9b757"
},
{
"url": "https://git.kernel.org/stable/c/1226293ec9bed3d4cc5b05eeeb811d315ca51652"
},
{
"url": "https://git.kernel.org/stable/c/3750f75f29f99c0223601e2ee73ad084adec47bd"
},
{
"url": "https://git.kernel.org/stable/c/d0ebf9cc7c2ddf95a7cfc654b940bdacb7edde97"
},
{
"url": "https://git.kernel.org/stable/c/0025276175fbbe0dcbf3f84d090b0adee769e9d9"
},
{
"url": "https://git.kernel.org/stable/c/347b59e9f96719d89b6ef555d02a18ada1a5846f"
},
{
"url": "https://git.kernel.org/stable/c/0443e4416aa1ee97748d1ed904eaf3352c60045e"
},
{
"url": "https://git.kernel.org/stable/c/c5371e0b91b24159a3ebaa61e70b0980bcf03c0a"
}
],
"title": "usbip: vudc: fix NULL deref in vep_dequeue()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64331",
"datePublished": "2026-07-25T08:49:58.370Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:33.891Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68308 (GCVE-0-2026-68308)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()
mt76_connac_get_he_phy_cap routine can theoretically return NULL so
check cap pointer before dereferencing it.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7996/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4fd85fd2373501b7386e93a5ce4a549d7c4e64e3",
"status": "affected",
"version": "98686cd21624c75a043e96812beadddf4f6f48e5",
"versionType": "git"
},
{
"lessThan": "8b8a079e22ce9fc3c0d05b148ef67e4c6e576678",
"status": "affected",
"version": "98686cd21624c75a043e96812beadddf4f6f48e5",
"versionType": "git"
},
{
"lessThan": "d14238523ca4c6f5fcb54d1920eb2f8525a7711f",
"status": "affected",
"version": "98686cd21624c75a043e96812beadddf4f6f48e5",
"versionType": "git"
},
{
"lessThan": "8bc7167e8a86489b7cb96a69cf1fb671d6df014b",
"status": "affected",
"version": "98686cd21624c75a043e96812beadddf4f6f48e5",
"versionType": "git"
},
{
"lessThan": "e858cf6bf99880343348ff1e8c942aaff1d9d592",
"status": "affected",
"version": "98686cd21624c75a043e96812beadddf4f6f48e5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7996/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()\n\nmt76_connac_get_he_phy_cap routine can theoretically return NULL so\ncheck cap pointer before dereferencing it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:00.803Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4fd85fd2373501b7386e93a5ce4a549d7c4e64e3"
},
{
"url": "https://git.kernel.org/stable/c/8b8a079e22ce9fc3c0d05b148ef67e4c6e576678"
},
{
"url": "https://git.kernel.org/stable/c/d14238523ca4c6f5fcb54d1920eb2f8525a7711f"
},
{
"url": "https://git.kernel.org/stable/c/8bc7167e8a86489b7cb96a69cf1fb671d6df014b"
},
{
"url": "https://git.kernel.org/stable/c/e858cf6bf99880343348ff1e8c942aaff1d9d592"
}
],
"title": "wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68308",
"datePublished": "2026-08-10T12:02:42.934Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-17T05:03:00.803Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63886 (GCVE-0-2026-63886)
Vulnerability from cvelistv5
Published
2026-07-19 14:54
Modified
2026-08-05 12:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Validate CHAP_R length before base64 decode
chap_server_compute_hash() allocates client_digest as
kzalloc(chap->digest_size) and then, for BASE64-encoded responses,
passes chap_r directly to chap_base64_decode() without checking whether
the input length could produce more than digest_size bytes of output.
chap_base64_decode() writes to the destination unconditionally as long
as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and
the "0b" prefix stripped by extract_param(), up to 127 base64 characters
can reach the decoder. 127 characters decode to 95 bytes. For SHA-256
(digest_size=32) this overflows client_digest by 63 bytes; for MD5
(digest_size=16) the overflow is 79 bytes.
The length check at line 344 fires after the write has already happened.
The HEX branch in the same switch statement already validates the length
up front. Apply the same approach to the BASE64 branch: strip trailing
base64 padding characters, then reject any input whose data length
exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder.
Stripping trailing '=' before the comparison handles both padded and
unpadded encodings. chap_base64_decode() already returns early on '=',
so the full original string is still passed to the decoder unchanged.
The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is
kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg at
CHAP_CHALLENGE_STR_LEN characters, so at most CHAP_CHALLENGE_STR_LEN-1
base64 characters reach the decoder. The maximum decoded size,
DIV_ROUND_UP((CHAP_CHALLENGE_STR_LEN-1) * 3, 4), is less than
CHAP_CHALLENGE_STR_LEN, so no overflow is possible there. A comment is
added at the call site to document this.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1e5733883421495908f3b90d9d807663038b4136 Version: 1e5733883421495908f3b90d9d807663038b4136 Version: 1e5733883421495908f3b90d9d807663038b4136 Version: 1e5733883421495908f3b90d9d807663038b4136 Version: 1e5733883421495908f3b90d9d807663038b4136 Version: 1e5733883421495908f3b90d9d807663038b4136 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/target/iscsi/iscsi_target_auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "82454e6f21e56ea9a0a9de7d0ff7e1dfb83e34d6",
"status": "affected",
"version": "1e5733883421495908f3b90d9d807663038b4136",
"versionType": "git"
},
{
"lessThan": "edd06675a02376ea8347dba7c29ad982ba5b36ee",
"status": "affected",
"version": "1e5733883421495908f3b90d9d807663038b4136",
"versionType": "git"
},
{
"lessThan": "bf154c657828ed05399bca5d98cf1611bb048b12",
"status": "affected",
"version": "1e5733883421495908f3b90d9d807663038b4136",
"versionType": "git"
},
{
"lessThan": "4a3a19c98a8207ad08bec554703d90f2c34a8cc6",
"status": "affected",
"version": "1e5733883421495908f3b90d9d807663038b4136",
"versionType": "git"
},
{
"lessThan": "c04e85799356120209b351a148ac2db888d5ffd9",
"status": "affected",
"version": "1e5733883421495908f3b90d9d807663038b4136",
"versionType": "git"
},
{
"lessThan": "85db7391310b1304d2dc8ae3b0b12105a9567147",
"status": "affected",
"version": "1e5733883421495908f3b90d9d807663038b4136",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/target/iscsi/iscsi_target_auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Validate CHAP_R length before base64 decode\n\nchap_server_compute_hash() allocates client_digest as\nkzalloc(chap-\u003edigest_size) and then, for BASE64-encoded responses,\npasses chap_r directly to chap_base64_decode() without checking whether\nthe input length could produce more than digest_size bytes of output.\n\nchap_base64_decode() writes to the destination unconditionally as long\nas there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and\nthe \"0b\" prefix stripped by extract_param(), up to 127 base64 characters\ncan reach the decoder. 127 characters decode to 95 bytes. For SHA-256\n(digest_size=32) this overflows client_digest by 63 bytes; for MD5\n(digest_size=16) the overflow is 79 bytes.\n\nThe length check at line 344 fires after the write has already happened.\n\nThe HEX branch in the same switch statement already validates the length\nup front. Apply the same approach to the BASE64 branch: strip trailing\nbase64 padding characters, then reject any input whose data length\nexceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder.\n\nStripping trailing \u0027=\u0027 before the comparison handles both padded and\nunpadded encodings. chap_base64_decode() already returns early on \u0027=\u0027,\nso the full original string is still passed to the decoder unchanged.\n\nThe mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is\nkzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg at\nCHAP_CHALLENGE_STR_LEN characters, so at most CHAP_CHALLENGE_STR_LEN-1\nbase64 characters reach the decoder. The maximum decoded size,\nDIV_ROUND_UP((CHAP_CHALLENGE_STR_LEN-1) * 3, 4), is less than\nCHAP_CHALLENGE_STR_LEN, so no overflow is possible there. A comment is\nadded at the call site to document this."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is triggered by a remote iSCSI initiator sending crafted CHAP login PDUs over TCP to the in-kernel LIO iSCSI target during the network login/authentication handshake.\nAC:L - Once an iSCSI target with CHAP is reachable, an attacker can reliably trigger the overflow by sending CHAP_R with a 0b-prefixed base64 string up to 127 characters; no race or special memory layout is required.\nPR:N - The heap overflow occurs during the CHAP authentication handshake before the password hash comparison succeeds, so exploitation is reachable by an unauthenticated remote network attacker who knows a configured CHAP username.\nUI:N - Exploitation requires only the attacker initiating an iSCSI login connection and sending malicious CHAP PDUs; no action from a victim user is needed.\nS:U - Successful exploitation corrupts kernel heap memory within the same kernel security boundary, enabling denial of service or kernel privilege escalation, not a cross-boundary escape such as VM guest-to-host.\nC:H - The out-of-bounds heap write corrupts adjacent kmalloc objects and can be leveraged for arbitrary kernel memory disclosure through heap grooming, consistent with heap overflow impact guidance.\nI:H - A controlled kernel heap out-of-bounds write of up to 79 bytes past a digest-sized buffer can corrupt adjacent structures and be developed into arbitrary code execution or kernel privilege escalation.\nA:H - The overflow causes slab-out-of-bounds writes confirmed by KASAN and can crash or destabilize the kernel during login processing, constituting high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:36:55.369Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/82454e6f21e56ea9a0a9de7d0ff7e1dfb83e34d6"
},
{
"url": "https://git.kernel.org/stable/c/edd06675a02376ea8347dba7c29ad982ba5b36ee"
},
{
"url": "https://git.kernel.org/stable/c/bf154c657828ed05399bca5d98cf1611bb048b12"
},
{
"url": "https://git.kernel.org/stable/c/4a3a19c98a8207ad08bec554703d90f2c34a8cc6"
},
{
"url": "https://git.kernel.org/stable/c/c04e85799356120209b351a148ac2db888d5ffd9"
},
{
"url": "https://git.kernel.org/stable/c/85db7391310b1304d2dc8ae3b0b12105a9567147"
}
],
"title": "scsi: target: iscsi: Validate CHAP_R length before base64 decode",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63886",
"datePublished": "2026-07-19T14:54:59.395Z",
"dateReserved": "2026-07-19T07:54:57.018Z",
"dateUpdated": "2026-08-05T12:36:55.369Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68199 (GCVE-0-2026-68199)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix OOB access from firmware ADDBA window size
aggr_recv_addba_req_evt() logs a debug message when the firmware-supplied
win_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not
return. The out-of-range win_sz is then used in TID_WINDOW_SZ() to
compute a kzalloc size and stored in rxtid->hold_q_sz, leading to
zero-size or overflowed allocations and subsequent out-of-bounds access.
Clean up any previously active aggregation session for the TID first,
then return early when win_sz is out of the valid range, instead of
proceeding with a broken allocation size.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c8e3ca7954d8233fbc54bd370c1827670f43c538",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "f480d9910fcfe326db3a6281df80e83af347193e",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "67bc9af4f41f2bdba20404fbd753b2a1bd6dd352",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "d4558c140782180e2c80a7588a4af9f8675adfc4",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "5a65fd4722416061698b0a3277222381efbc4882",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "58c6c8dc2e022e1b4f3dc58725a1ca49ff470f9c",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "cec0a487cf38ac1f9bca240ffe8a94c5014b72f2",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "44126b6994eeb28f2103b638e698f40a1244f327",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB access from firmware ADDBA window size\n\naggr_recv_addba_req_evt() logs a debug message when the firmware-supplied\nwin_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not\nreturn. The out-of-range win_sz is then used in TID_WINDOW_SZ() to\ncompute a kzalloc size and stored in rxtid-\u003ehold_q_sz, leading to\nzero-size or overflowed allocations and subsequent out-of-bounds access.\n\nClean up any previously active aggregation session for the TID first,\nthen return early when win_sz is out of the valid range, instead of\nproceeding with a broken allocation size."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Exploitation requires a malicious WiFi peer (rogue AP or associated client) to trigger ADDBA handling; firmware passes WMI_ADDBA_REQ_EVENTID over the radio link to the ath6kl driver, placing the attacker on the same wireless segment rather than a remote IP network path.\nAC:L - An adjacent attacker can reliably send crafted 802.11 ADDBA requests with out-of-range buffer/window sizes to firmware, which forwards the invalid win_sz to the host; no special memory layout, race, or rare timing is required beyond normal WiFi association.\nPR:N - No local Linux privileges are needed; any associated WiFi peer can induce the malformed ADDBA event. The bug is not reachable via user namespaces or unprivileged local syscalls without controlling the WiFi link/firmware messages.\nUI:N - Once the victim device is associated to WiFi (common on phones, embedded, and IoT), the attacker can send ADDBA and follow-up data frames without any additional victim action beyond routine wireless connectivity.\nS:U - Heap corruption and kernel privilege escalation occur within the same kernel security domain; this is not a VM escape, IOMMU bypass, or cross-authority sandbox breakout.\nC:H - Out-of-bounds access to hold_q allows reading/writing adjacent kernel heap memory (e.g., skb pointers and metadata); OOB kernel heap access is treated as arbitrary memory disclosure potential per kernel CVSS guidance.\nI:H - OOB writes to hold_q entries (struct sk_buff pointers, is_amsdu, seq_no) corrupt kernel heap state and can be leveraged for control-flow hijacking and local privilege escalation, not merely a bounded modification.\nA:H - Invalid win_sz can yield zero-size allocations and hold_q_sz=0 (divide-by-zero in AGGR_WIN_IDX) or inconsistent buffers, causing kernel oops/panic or persistent disruption when aggregation receives subsequent frames."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:18.842Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c8e3ca7954d8233fbc54bd370c1827670f43c538"
},
{
"url": "https://git.kernel.org/stable/c/f480d9910fcfe326db3a6281df80e83af347193e"
},
{
"url": "https://git.kernel.org/stable/c/67bc9af4f41f2bdba20404fbd753b2a1bd6dd352"
},
{
"url": "https://git.kernel.org/stable/c/d4558c140782180e2c80a7588a4af9f8675adfc4"
},
{
"url": "https://git.kernel.org/stable/c/5a65fd4722416061698b0a3277222381efbc4882"
},
{
"url": "https://git.kernel.org/stable/c/58c6c8dc2e022e1b4f3dc58725a1ca49ff470f9c"
},
{
"url": "https://git.kernel.org/stable/c/cec0a487cf38ac1f9bca240ffe8a94c5014b72f2"
},
{
"url": "https://git.kernel.org/stable/c/44126b6994eeb28f2103b638e698f40a1244f327"
}
],
"title": "wifi: ath6kl: fix OOB access from firmware ADDBA window size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68199",
"datePublished": "2026-08-10T12:00:18.278Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:18.842Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68312 (GCVE-0-2026-68312)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths
In cifs_close_deferred_file(), cifs_close_all_deferred_files(), and
cifs_close_deferred_file_under_dentry(), when a pending deferred close
is cancelled via cancel_delayed_work(), the subsequent kmalloc_obj() to
add the file to the local processing list may fail under memory pressure.
The loop breaks immediately, but the cancelled work is no longer pending
(it would have called _cifsFileInfo_put()), and the cfile is never added
to file_head for processing. The cifsFileInfo reference and the open
server handle both leak.
Fix by saving the cfile that failed allocation in a local variable,
breaking as before, and calling _cifsFileInfo_put() on it after
releasing the lock. Any files later in the iteration are unaffected
since their deferred work is still pending and will fire normally.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "32390b3f06f26e366cfb27dbac4bc0196c321535",
"status": "affected",
"version": "e3fc065682ebbbd15b0ce0036800f4acbf765d46",
"versionType": "git"
},
{
"lessThan": "c2f2e83e3bbc5483730fd4ee903182761f1ae50f",
"status": "affected",
"version": "e3fc065682ebbbd15b0ce0036800f4acbf765d46",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths\n\nIn cifs_close_deferred_file(), cifs_close_all_deferred_files(), and\ncifs_close_deferred_file_under_dentry(), when a pending deferred close\nis cancelled via cancel_delayed_work(), the subsequent kmalloc_obj() to\nadd the file to the local processing list may fail under memory pressure.\nThe loop breaks immediately, but the cancelled work is no longer pending\n(it would have called _cifsFileInfo_put()), and the cfile is never added\nto file_head for processing. The cifsFileInfo reference and the open\nserver handle both leak.\n\nFix by saving the cfile that failed allocation in a local variable,\nbreaking as before, and calling _cifsFileInfo_put() on it after\nreleasing the lock. Any files later in the iteration are unaffected\nsince their deferred work is still pending and will fire normally."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:08.764Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/32390b3f06f26e366cfb27dbac4bc0196c321535"
},
{
"url": "https://git.kernel.org/stable/c/c2f2e83e3bbc5483730fd4ee903182761f1ae50f"
}
],
"title": "cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68312",
"datePublished": "2026-08-10T12:02:46.907Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-17T05:03:08.764Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64362 (GCVE-0-2026-64362)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: lg-g15: cancel pending work on remove to fix a use-after-free
lg_g15_data is allocated with devm and holds a work item. The report
handlers schedule that work straight from device input.
lg_g15_event() and lg_g15_v2_event() do it on the backlight cycle key,
and lg_g510_leds_event() does it too. The worker dereferences the
lg_g15_data back through container_of.
The driver had no remove callback and never cancelled the work. So if a
report scheduled the work and the keyboard was then unplugged, devres
freed lg_g15_data while the work was still pending or running, and the
worker touched freed memory. This is a use-after-free. It is reachable
as a race on device unplug.
Add a remove callback that cancels the work before devres frees the
state. g15->work is only initialized for the models that schedule it
(G15, G15 v2, G510). The G13 and Z-10 leave it zeroed, so guard the
cancel on g15->work.func to avoid cancelling a work that was never set
up. The g15 NULL test mirrors the one already in lg_g15_raw_event().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 97b741aba918c4143f4208d2421d08ff215c1b49 Version: 97b741aba918c4143f4208d2421d08ff215c1b49 Version: 97b741aba918c4143f4208d2421d08ff215c1b49 Version: 97b741aba918c4143f4208d2421d08ff215c1b49 Version: 97b741aba918c4143f4208d2421d08ff215c1b49 Version: 97b741aba918c4143f4208d2421d08ff215c1b49 Version: 97b741aba918c4143f4208d2421d08ff215c1b49 Version: 97b741aba918c4143f4208d2421d08ff215c1b49 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-lg-g15.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3b9a3919aac6977262f04d5365c0456877522a44",
"status": "affected",
"version": "97b741aba918c4143f4208d2421d08ff215c1b49",
"versionType": "git"
},
{
"lessThan": "4aef9676c26dff8723b56834951cfc6b618f0986",
"status": "affected",
"version": "97b741aba918c4143f4208d2421d08ff215c1b49",
"versionType": "git"
},
{
"lessThan": "acce9dee807f21184fff19ad17c8ed464247e7f7",
"status": "affected",
"version": "97b741aba918c4143f4208d2421d08ff215c1b49",
"versionType": "git"
},
{
"lessThan": "33cd1a000daf929356aacf2b191d31714ff0615e",
"status": "affected",
"version": "97b741aba918c4143f4208d2421d08ff215c1b49",
"versionType": "git"
},
{
"lessThan": "dfc6e61f83113cc18346b6988f07271c0063357d",
"status": "affected",
"version": "97b741aba918c4143f4208d2421d08ff215c1b49",
"versionType": "git"
},
{
"lessThan": "4d0d51bc12d246accbfbb94de05d729c68c9b8fb",
"status": "affected",
"version": "97b741aba918c4143f4208d2421d08ff215c1b49",
"versionType": "git"
},
{
"lessThan": "8131f4226688c4be5f30874d167e44dab838eb09",
"status": "affected",
"version": "97b741aba918c4143f4208d2421d08ff215c1b49",
"versionType": "git"
},
{
"lessThan": "7705b4140d188ce22656f6e541ae7ef834c7e11a",
"status": "affected",
"version": "97b741aba918c4143f4208d2421d08ff215c1b49",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-lg-g15.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: lg-g15: cancel pending work on remove to fix a use-after-free\n\nlg_g15_data is allocated with devm and holds a work item. The report\nhandlers schedule that work straight from device input.\nlg_g15_event() and lg_g15_v2_event() do it on the backlight cycle key,\nand lg_g510_leds_event() does it too. The worker dereferences the\nlg_g15_data back through container_of.\n\nThe driver had no remove callback and never cancelled the work. So if a\nreport scheduled the work and the keyboard was then unplugged, devres\nfreed lg_g15_data while the work was still pending or running, and the\nworker touched freed memory. This is a use-after-free. It is reachable\nas a race on device unplug.\n\nAdd a remove callback that cancels the work before devres frees the\nstate. g15-\u003ework is only initialized for the models that schedule it\n(G15, G15 v2, G510). The G13 and Z-10 leave it zeroed, so guard the\ncancel on g15-\u003ework.func to avoid cancelling a work that was never set\nup. The g15 NULL test mirrors the one already in lg_g15_raw_event()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:08.962Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3b9a3919aac6977262f04d5365c0456877522a44"
},
{
"url": "https://git.kernel.org/stable/c/4aef9676c26dff8723b56834951cfc6b618f0986"
},
{
"url": "https://git.kernel.org/stable/c/acce9dee807f21184fff19ad17c8ed464247e7f7"
},
{
"url": "https://git.kernel.org/stable/c/33cd1a000daf929356aacf2b191d31714ff0615e"
},
{
"url": "https://git.kernel.org/stable/c/dfc6e61f83113cc18346b6988f07271c0063357d"
},
{
"url": "https://git.kernel.org/stable/c/4d0d51bc12d246accbfbb94de05d729c68c9b8fb"
},
{
"url": "https://git.kernel.org/stable/c/8131f4226688c4be5f30874d167e44dab838eb09"
},
{
"url": "https://git.kernel.org/stable/c/7705b4140d188ce22656f6e541ae7ef834c7e11a"
}
],
"title": "HID: lg-g15: cancel pending work on remove to fix a use-after-free",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64362",
"datePublished": "2026-07-25T08:50:18.008Z",
"dateReserved": "2026-07-19T15:36:31.783Z",
"dateUpdated": "2026-08-17T04:54:08.962Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64269 (GCVE-0-2026-64269)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
When the server answers an RTRS READ, rdma_write_sg() builds the source
scatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the
peer. Its length is taken directly from the wire descriptor:
plist->length = le32_to_cpu(id->rd_msg->desc[0].len);
rd_msg points into the chunk buffer that the remote peer filled via
RDMA-WRITE-WITH-IMM (rtrs_srv_rdma_done() -> process_io_req() ->
process_read()), so desc[0].len is attacker-controlled and, before this
change, was only rejected when zero. The source address is the fixed
chunk start (dma_addr[msg_id]) and the source lkey is the PD-wide
local_dma_lkey, which is not tied to the chunk's MR mapping, so the verbs
layer does not constrain the transfer length to max_chunk_size. msg_id
and off are bounded against queue_depth and max_chunk_size in
rtrs_srv_rdma_done(), but desc[0].len is a separate field that was not
checked against the chunk size.
A peer that advertises desc[0].len larger than max_chunk_size can make
the posted RDMA write read past the chunk's mapped region. The resulting
behaviour depends on the IOMMU configuration: with no IOMMU or in
passthrough mode the read may extend into memory adjacent to the chunk
and be returned to the peer, which can disclose host memory; with a
translating IOMMU the out-of-range access is expected to fault and abort
the connection. In either case the transfer exceeds what the protocol
permits and is driven by a remote peer.
Reject a descriptor length above max_chunk_size, mirroring the existing
off >= max_chunk_size bound in rtrs_srv_rdma_done(). Legitimate clients
do not exceed it: the client sets desc[0].len to its MR length, which is
capped at the negotiated max_io_size (max_chunk_size - MAX_HDR_SIZE).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9cb837480424e78ed585376f944088246685aec3 Version: 9cb837480424e78ed585376f944088246685aec3 Version: 9cb837480424e78ed585376f944088246685aec3 Version: 9cb837480424e78ed585376f944088246685aec3 Version: 9cb837480424e78ed585376f944088246685aec3 Version: 9cb837480424e78ed585376f944088246685aec3 Version: 9cb837480424e78ed585376f944088246685aec3 Version: 9cb837480424e78ed585376f944088246685aec3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/ulp/rtrs/rtrs-srv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a35b7a8728a53ddc80b323970689fa5985816836",
"status": "affected",
"version": "9cb837480424e78ed585376f944088246685aec3",
"versionType": "git"
},
{
"lessThan": "68c09762172f6224e9ddf9b0a60bacbb36e443eb",
"status": "affected",
"version": "9cb837480424e78ed585376f944088246685aec3",
"versionType": "git"
},
{
"lessThan": "6cada540150894e81042a0ae0c796a21a9a877da",
"status": "affected",
"version": "9cb837480424e78ed585376f944088246685aec3",
"versionType": "git"
},
{
"lessThan": "2912f3d40355dabc08fdbaaf2764d02445fe88dc",
"status": "affected",
"version": "9cb837480424e78ed585376f944088246685aec3",
"versionType": "git"
},
{
"lessThan": "6f40246f4312fdbab5a13cc440adebf95eb2aa66",
"status": "affected",
"version": "9cb837480424e78ed585376f944088246685aec3",
"versionType": "git"
},
{
"lessThan": "5a45d0aa1fa50a333ce5763ade744e2d89838667",
"status": "affected",
"version": "9cb837480424e78ed585376f944088246685aec3",
"versionType": "git"
},
{
"lessThan": "da3e44add94b05dfde56f898421922f5cf35705f",
"status": "affected",
"version": "9cb837480424e78ed585376f944088246685aec3",
"versionType": "git"
},
{
"lessThan": "963af8d97a8c6a117134a8d0db1415e0489200b1",
"status": "affected",
"version": "9cb837480424e78ed585376f944088246685aec3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/ulp/rtrs/rtrs-srv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg\n\nWhen the server answers an RTRS READ, rdma_write_sg() builds the source\nscatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the\npeer. Its length is taken directly from the wire descriptor:\n\n plist-\u003elength = le32_to_cpu(id-\u003erd_msg-\u003edesc[0].len);\n\nrd_msg points into the chunk buffer that the remote peer filled via\nRDMA-WRITE-WITH-IMM (rtrs_srv_rdma_done() -\u003e process_io_req() -\u003e\nprocess_read()), so desc[0].len is attacker-controlled and, before this\nchange, was only rejected when zero. The source address is the fixed\nchunk start (dma_addr[msg_id]) and the source lkey is the PD-wide\nlocal_dma_lkey, which is not tied to the chunk\u0027s MR mapping, so the verbs\nlayer does not constrain the transfer length to max_chunk_size. msg_id\nand off are bounded against queue_depth and max_chunk_size in\nrtrs_srv_rdma_done(), but desc[0].len is a separate field that was not\nchecked against the chunk size.\n\nA peer that advertises desc[0].len larger than max_chunk_size can make\nthe posted RDMA write read past the chunk\u0027s mapped region. The resulting\nbehaviour depends on the IOMMU configuration: with no IOMMU or in\npassthrough mode the read may extend into memory adjacent to the chunk\nand be returned to the peer, which can disclose host memory; with a\ntranslating IOMMU the out-of-range access is expected to fault and abort\nthe connection. In either case the transfer exceeds what the protocol\npermits and is driven by a remote peer.\n\nReject a descriptor length above max_chunk_size, mirroring the existing\noff \u003e= max_chunk_size bound in rtrs_srv_rdma_done(). Legitimate clients\ndo not exceed it: the client sets desc[0].len to its MR length, which is\ncapped at the negotiated max_io_size (max_chunk_size - MAX_HDR_SIZE)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - RTRS accepts network connections over routable RDMA transports including RoCE and iWARP, and the malicious descriptor is supplied by a remote peer.\nAC:L - The peer directly controls the descriptor length and destination buffer; no race, timing, or victim-controlled state is required in no-IOMMU, passthrough, or software-RDMA deployments.\nPR:N - The handshake validates protocol fields but performs no credential, capability, or authentication check before publishing chunk rkeys and accepting I/O requests.\nUI:N - After connecting, the attacker can submit the crafted RDMA READ request without any victim action.\nS:U - The vulnerable RTRS module and affected host memory remain within the kernel\u0027s security authority; a translating IOMMU prevents rather than permits crossing its isolation boundary.\nC:H - The PD-wide local DMA key does not constrain the attacker-supplied transfer length, permitting a broad out-of-bounds read of adjacent host memory that is returned to the peer.\nI:N - The malformed operation reads server memory and writes it only to the peer\u0027s registered destination; it provides no server-side memory-write primitive.\nA:H - Software-RDMA can CPU-copy through invalid pages and oops or crash, while hardware or IOMMU faults can abort paths. An unauthenticated peer can trigger the condition repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:35.835Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a35b7a8728a53ddc80b323970689fa5985816836"
},
{
"url": "https://git.kernel.org/stable/c/68c09762172f6224e9ddf9b0a60bacbb36e443eb"
},
{
"url": "https://git.kernel.org/stable/c/6cada540150894e81042a0ae0c796a21a9a877da"
},
{
"url": "https://git.kernel.org/stable/c/2912f3d40355dabc08fdbaaf2764d02445fe88dc"
},
{
"url": "https://git.kernel.org/stable/c/6f40246f4312fdbab5a13cc440adebf95eb2aa66"
},
{
"url": "https://git.kernel.org/stable/c/5a45d0aa1fa50a333ce5763ade744e2d89838667"
},
{
"url": "https://git.kernel.org/stable/c/da3e44add94b05dfde56f898421922f5cf35705f"
},
{
"url": "https://git.kernel.org/stable/c/963af8d97a8c6a117134a8d0db1415e0489200b1"
}
],
"title": "RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64269",
"datePublished": "2026-07-25T08:49:16.946Z",
"dateReserved": "2026-07-19T15:36:31.775Z",
"dateUpdated": "2026-08-23T12:45:35.835Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68366 (GCVE-0-2026-68366)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
uvc_send_response() builds the UVC control response from a user-supplied
struct uvc_request_data:
req->length = min_t(unsigned int, uvc->event_length, data->length);
...
memcpy(req->buf, data->data, req->length);
req->length is clamped to uvc->event_length, which is taken from the
host control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to
data->length, which comes from the UVCIOC_SEND_RESPONSE ioctl and is
only checked for being negative. The source buffer data->data is only
60 bytes, so a response with uvc->event_length and data->length both
greater than 60 makes memcpy() read past the end of data->data.
Clamp req->length to sizeof(data->data) as well.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/uvc_v4l2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eaf783c005299a702f2cc96b08cd21ede081f098",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "568e68d8f80395a64848aa2946af8ade72da0ffb",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "82ec2c1e456b17451f0736c3983402642f961733",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "662f6c6c6ff8a6c508e1646c09cae74e28f3cca6",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "1f03658f3e9b2f8fd1d1003ba389a0390b49a350",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "c8510fbbea09ef0170b56b14dc2b5890dc75be07",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "b70dc75e85ba968b7b76eebfe5d63000080b875b",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/uvc_v4l2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer\n\nuvc_send_response() builds the UVC control response from a user-supplied\nstruct uvc_request_data:\n\n\treq-\u003elength = min_t(unsigned int, uvc-\u003eevent_length, data-\u003elength);\n\t...\n\tmemcpy(req-\u003ebuf, data-\u003edata, req-\u003elength);\n\nreq-\u003elength is clamped to uvc-\u003eevent_length, which is taken from the\nhost control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to\ndata-\u003elength, which comes from the UVCIOC_SEND_RESPONSE ioctl and is\nonly checked for being negative. The source buffer data-\u003edata is only\n60 bytes, so a response with uvc-\u003eevent_length and data-\u003elength both\ngreater than 60 makes memcpy() read past the end of data-\u003edata.\n\nClamp req-\u003elength to sizeof(data-\u003edata) as well."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:23.776Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eaf783c005299a702f2cc96b08cd21ede081f098"
},
{
"url": "https://git.kernel.org/stable/c/568e68d8f80395a64848aa2946af8ade72da0ffb"
},
{
"url": "https://git.kernel.org/stable/c/82ec2c1e456b17451f0736c3983402642f961733"
},
{
"url": "https://git.kernel.org/stable/c/4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796"
},
{
"url": "https://git.kernel.org/stable/c/662f6c6c6ff8a6c508e1646c09cae74e28f3cca6"
},
{
"url": "https://git.kernel.org/stable/c/1f03658f3e9b2f8fd1d1003ba389a0390b49a350"
},
{
"url": "https://git.kernel.org/stable/c/c8510fbbea09ef0170b56b14dc2b5890dc75be07"
},
{
"url": "https://git.kernel.org/stable/c/b70dc75e85ba968b7b76eebfe5d63000080b875b"
}
],
"title": "usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68366",
"datePublished": "2026-08-10T12:03:43.304Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:23.776Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74563 (GCVE-0-2026-74563)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
rds_tcp_laddr_check() looks up a scoped IPv6 interface with
dev_get_by_index_rcu(), drops the RCU read-side lock, and only then
passes the bare struct net_device * into ipv6_chk_addr().
dev_get_by_index_rcu() only keeps the device alive within the same RCU
read-side section. After rcu_read_unlock(), a concurrent RTM_DELLINK can
free the net_device; ipv6_chk_addr() then dereferences the stale pointer
in __ipv6_chk_addr_and_flags() (e.g. l3mdev_master_dev_rcu(dev)), reading
freed memory.
Keep the RCU read-side lock held across the ipv6_chk_addr() call instead
of dropping it right after the lookup, so the device cannot be freed
while it is in use.
BUG: KASAN: slab-use-after-free in __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)
Read of size 8 at addr ffff8880106ec000 by task exploit/153
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
__ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)
ipv6_chk_addr (net/ipv6/addrconf.c:2031 net/ipv6/addrconf.c:1972)
rds_tcp_laddr_check (net/rds/tcp.c:370)
rds_bind (net/rds/bind.c:248)
__sys_bind (net/socket.c:1920)
__x64_sys_bind (net/socket.c:1956)
do_syscall_64 (arch/x86/entry/syscall_64.c:63)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rds/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f8a8977af2134a1d91e5f9773cb7d9d53278c830",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "ba95bce5dfe6e2ef602a87e0557225f2934ccb5c",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "c4933624a6f416ecfcc31ab58d585da1207a0597",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "76dd48886eeeb5fcf2b837d2f4c3d17eebeac9ef",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "f0d1fb05d70c8a561cd8d0473bcacafa2fc137ff",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "b1d480fce05f857dc438080cd8c9244b84a83494",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "8398bc477d3cb3e2b018a5aaac2bec0f69acda30",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "78f75d632f74b8de0f081a128588f7c37d0d1164",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rds/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()\n\nrds_tcp_laddr_check() looks up a scoped IPv6 interface with\ndev_get_by_index_rcu(), drops the RCU read-side lock, and only then\npasses the bare struct net_device * into ipv6_chk_addr().\n\ndev_get_by_index_rcu() only keeps the device alive within the same RCU\nread-side section. After rcu_read_unlock(), a concurrent RTM_DELLINK can\nfree the net_device; ipv6_chk_addr() then dereferences the stale pointer\nin __ipv6_chk_addr_and_flags() (e.g. l3mdev_master_dev_rcu(dev)), reading\nfreed memory.\n\nKeep the RCU read-side lock held across the ipv6_chk_addr() call instead\nof dropping it right after the lookup, so the device cannot be freed\nwhile it is in use.\n\n BUG: KASAN: slab-use-after-free in __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)\n Read of size 8 at addr ffff8880106ec000 by task exploit/153\n Call Trace:\n ...\n kasan_report (mm/kasan/report.c:595)\n __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)\n ipv6_chk_addr (net/ipv6/addrconf.c:2031 net/ipv6/addrconf.c:1972)\n rds_tcp_laddr_check (net/rds/tcp.c:370)\n rds_bind (net/rds/bind.c:248)\n __sys_bind (net/socket.c:1920)\n __x64_sys_bind (net/socket.c:1956)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The slab use-after-free is reached via the bind(2) syscall on an AF_RDS socket with a link-local IPv6 address and non-zero scope_id; the KASAN reproducer follows bind()-\u003erds_bind()-\u003erds_tcp_laddr_check(), requiring on-host access to race bind against RTM_DELLINK netlink deletion of the referenced netdev.\nAC:L - Exploitation requires racing rds_tcp_laddr_check() against RTM_DELLINK freeing the netdev; the attacker controls both sides by concurrently calling bind() and deleting the interface via netlink (e.g., a veth in a user namespace) and can retry until the race succeeds.\nPR:L - An unprivileged local user can create AF_RDS sockets and call bind(); the RTM_DELLINK race is achievable with CAP_NET_ADMIN obtainable inside an unprivileged user+network namespace (unshare -Urn), not requiring init-namespace root.\nUI:N - No victim interaction is required; exploitation is fully attacker-driven through bind/netlink syscalls without needing another user to mount a filesystem, click, or open a file.\nS:U - Impact is confined to kernel memory corruption and potential privilege escalation within the same kernel/host security boundary; this is not a VM-guest-to-host escape, sandbox escape, or cross-authority boundary crossing.\nC:H - The bug is a slab use-after-free read of a freed struct net_device in __ipv6_chk_addr_and_flags() via a stale pointer passed to ipv6_chk_addr(); UAF reads of kernel heap objects can disclose sensitive memory and enable further exploitation.\nI:H - Use-after-free on struct net_device heap memory provides memory corruption primitives that can be groomed for arbitrary kernel writes, control-flow hijacking, and local privilege escalation, not merely a bounded or transient error.\nA:H - The reported KASAN slab-use-after-free causes kernel oops/panic during the stale dereference in the IPv6 address-check path; UAF conditions are inherently crash-prone even when not fully weaponized for code execution."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:39:02.416Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f8a8977af2134a1d91e5f9773cb7d9d53278c830"
},
{
"url": "https://git.kernel.org/stable/c/ba95bce5dfe6e2ef602a87e0557225f2934ccb5c"
},
{
"url": "https://git.kernel.org/stable/c/c4933624a6f416ecfcc31ab58d585da1207a0597"
},
{
"url": "https://git.kernel.org/stable/c/76dd48886eeeb5fcf2b837d2f4c3d17eebeac9ef"
},
{
"url": "https://git.kernel.org/stable/c/f0d1fb05d70c8a561cd8d0473bcacafa2fc137ff"
},
{
"url": "https://git.kernel.org/stable/c/b1d480fce05f857dc438080cd8c9244b84a83494"
},
{
"url": "https://git.kernel.org/stable/c/8398bc477d3cb3e2b018a5aaac2bec0f69acda30"
},
{
"url": "https://git.kernel.org/stable/c/78f75d632f74b8de0f081a128588f7c37d0d1164"
}
],
"title": "rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74563",
"datePublished": "2026-08-15T12:28:05.768Z",
"dateReserved": "2026-08-15T05:44:03.916Z",
"dateUpdated": "2026-08-19T16:39:02.416Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74722 (GCVE-0-2026-74722)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-22 15:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix memory leak in btrfs_do_encoded_write()
Local fuzzing of 6.12.94 has found the following memory leak:
Unreferenced object 0xffff888018050a80 (size 64):
comm "syz.0.17", pid 10297, jiffies 4294953601
hex dump (first 32 bytes):
00 10 00 00 00 00 00 00 01 00 00 00 00 00 00 00 ................
10 0a 05 18 80 88 ff ff 10 0a 05 18 80 88 ff ff ................
backtrace (crc a8a6fc29):
kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]
slab_post_alloc_hook mm/slub.c:4152 [inline]
slab_alloc_node mm/slub.c:4197 [inline]
__kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358
kmalloc_noprof include/linux/slab.h:878 [inline]
extent_changeset_alloc fs/btrfs/extent_io.h:207 [inline]
qgroup_reserve_data+0x1c5/0x7d0 fs/btrfs/qgroup.c:4305
btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355
btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746
btrfs_encoded_write fs/btrfs/file.c:1482 [inline]
btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507
btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738
btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:906 [inline]
__se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892
do_syscall_x64 arch/x86/entry/common.c:47 [inline]
do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Unreferenced object 0xffff888018050a00 (size 64):
comm "syz.0.17", pid 10297, jiffies 4294953601
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 ff 0f 00 00 00 00 00 00 ................
90 0a 05 18 80 88 ff ff 90 0a 05 18 80 88 ff ff ................
backtrace (crc cb5c9580):
kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]
slab_post_alloc_hook mm/slub.c:4152 [inline]
slab_alloc_node mm/slub.c:4197 [inline]
__kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358
kmalloc_noprof include/linux/slab.h:878 [inline]
kzalloc_noprof include/linux/slab.h:1014 [inline]
ulist_prealloc+0x9c/0x110 fs/btrfs/ulist.c:114
extent_changeset_prealloc fs/btrfs/extent_io.h:217 [inline]
__set_extent_bit+0x16b/0x1a70 fs/btrfs/extent-io-tree.c:1086
set_record_extent_bits+0x50/0x90 fs/btrfs/extent-io-tree.c:1821
qgroup_reserve_data+0x274/0x7d0 fs/btrfs/qgroup.c:4312
btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355
btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746
btrfs_encoded_write fs/btrfs/file.c:1482 [inline]
btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507
btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738
btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:906 [inline]
__se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892
do_syscall_x64 arch/x86/entry/common.c:47 [inline]
do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Fix this by freeing an extent changeset before returning from
btrfs_do_encoded_write().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/inode.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f0da96ccb1b9f35f4d3d4540dcaab0969d9d6b0",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
},
{
"lessThan": "e2c7e88815edd5ecfb88e7660ab9fd42bda6bc47",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
},
{
"lessThan": "20c0eeb4313f9f89d47b80b672b5846f9827cb31",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
},
{
"lessThan": "24a8f2c29aebb753ccb962fbb25bae18d7978f6e",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
},
{
"lessThan": "60b50ceba6243802f8d2c0a9a7c2d549a93b1d64",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
},
{
"lessThan": "d2a4e4e626b2f4670b69b430c357f03f53eb6632",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/inode.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix memory leak in btrfs_do_encoded_write()\n\nLocal fuzzing of 6.12.94 has found the following memory leak:\n\nUnreferenced object 0xffff888018050a80 (size 64):\n comm \"syz.0.17\", pid 10297, jiffies 4294953601\n hex dump (first 32 bytes):\n 00 10 00 00 00 00 00 00 01 00 00 00 00 00 00 00 ................\n 10 0a 05 18 80 88 ff ff 10 0a 05 18 80 88 ff ff ................\n backtrace (crc a8a6fc29):\n kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]\n slab_post_alloc_hook mm/slub.c:4152 [inline]\n slab_alloc_node mm/slub.c:4197 [inline]\n __kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358\n kmalloc_noprof include/linux/slab.h:878 [inline]\n extent_changeset_alloc fs/btrfs/extent_io.h:207 [inline]\n qgroup_reserve_data+0x1c5/0x7d0 fs/btrfs/qgroup.c:4305\n btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355\n btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746\n btrfs_encoded_write fs/btrfs/file.c:1482 [inline]\n btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507\n btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738\n btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:47 [inline]\n do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUnreferenced object 0xffff888018050a00 (size 64):\n comm \"syz.0.17\", pid 10297, jiffies 4294953601\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 ff 0f 00 00 00 00 00 00 ................\n 90 0a 05 18 80 88 ff ff 90 0a 05 18 80 88 ff ff ................\n backtrace (crc cb5c9580):\n kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]\n slab_post_alloc_hook mm/slub.c:4152 [inline]\n slab_alloc_node mm/slub.c:4197 [inline]\n __kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358\n kmalloc_noprof include/linux/slab.h:878 [inline]\n kzalloc_noprof include/linux/slab.h:1014 [inline]\n ulist_prealloc+0x9c/0x110 fs/btrfs/ulist.c:114\n extent_changeset_prealloc fs/btrfs/extent_io.h:217 [inline]\n __set_extent_bit+0x16b/0x1a70 fs/btrfs/extent-io-tree.c:1086\n set_record_extent_bits+0x50/0x90 fs/btrfs/extent-io-tree.c:1821\n qgroup_reserve_data+0x274/0x7d0 fs/btrfs/qgroup.c:4312\n btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355\n btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746\n btrfs_encoded_write fs/btrfs/file.c:1482 [inline]\n btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507\n btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738\n btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:47 [inline]\n do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFix this by freeing an extent changeset before returning from\nbtrfs_do_encoded_write()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:33:14.582Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f0da96ccb1b9f35f4d3d4540dcaab0969d9d6b0"
},
{
"url": "https://git.kernel.org/stable/c/e2c7e88815edd5ecfb88e7660ab9fd42bda6bc47"
},
{
"url": "https://git.kernel.org/stable/c/20c0eeb4313f9f89d47b80b672b5846f9827cb31"
},
{
"url": "https://git.kernel.org/stable/c/24a8f2c29aebb753ccb962fbb25bae18d7978f6e"
},
{
"url": "https://git.kernel.org/stable/c/60b50ceba6243802f8d2c0a9a7c2d549a93b1d64"
},
{
"url": "https://git.kernel.org/stable/c/d2a4e4e626b2f4670b69b430c357f03f53eb6632"
}
],
"title": "btrfs: fix memory leak in btrfs_do_encoded_write()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74722",
"datePublished": "2026-08-22T15:33:14.582Z",
"dateReserved": "2026-08-15T05:44:03.929Z",
"dateUpdated": "2026-08-22T15:33:14.582Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-68214 (GCVE-0-2025-68214)
Vulnerability from cvelistv5
Published
2025-12-16 13:57
Modified
2026-05-23 16:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
timers: Fix NULL function pointer race in timer_shutdown_sync()
There is a race condition between timer_shutdown_sync() and timer
expiration that can lead to hitting a WARN_ON in expire_timers().
The issue occurs when timer_shutdown_sync() clears the timer function
to NULL while the timer is still running on another CPU. The race
scenario looks like this:
CPU0 CPU1
<SOFTIRQ>
lock_timer_base()
expire_timers()
base->running_timer = timer;
unlock_timer_base()
[call_timer_fn enter]
mod_timer()
...
timer_shutdown_sync()
lock_timer_base()
// For now, will not detach the timer but only clear its function to NULL
if (base->running_timer != timer)
ret = detach_if_pending(timer, base, true);
if (shutdown)
timer->function = NULL;
unlock_timer_base()
[call_timer_fn exit]
lock_timer_base()
base->running_timer = NULL;
unlock_timer_base()
...
// Now timer is pending while its function set to NULL.
// next timer trigger
<SOFTIRQ>
expire_timers()
WARN_ON_ONCE(!fn) // hit
...
lock_timer_base()
// Now timer will detach
if (base->running_timer != timer)
ret = detach_if_pending(timer, base, true);
if (shutdown)
timer->function = NULL;
unlock_timer_base()
The problem is that timer_shutdown_sync() clears the timer function
regardless of whether the timer is currently running. This can leave a
pending timer with a NULL function pointer, which triggers the
WARN_ON_ONCE(!fn) check in expire_timers().
Fix this by only clearing the timer function when actually detaching the
timer. If the timer is running, leave the function pointer intact, which is
safe because the timer will be properly detached when it finishes running.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: debbcf812d735003c96c5e5968a3cfa4e1fbd1af Version: 334c33aa487be406a149c8b87c38c8399d2dba8d Version: 0cc04e80458a822300b93f82ed861a513edde194 Version: 0cc04e80458a822300b93f82ed861a513edde194 Version: 0cc04e80458a822300b93f82ed861a513edde194 Version: 0cc04e80458a822300b93f82ed861a513edde194 Version: 6.1.158 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/time/timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ba43ac025c4318241f8edf94f31d2eebab86991b",
"status": "affected",
"version": "debbcf812d735003c96c5e5968a3cfa4e1fbd1af",
"versionType": "git"
},
{
"lessThan": "1a975716cc8977f461e45e28e3e5977d46ad7a6a",
"status": "affected",
"version": "334c33aa487be406a149c8b87c38c8399d2dba8d",
"versionType": "git"
},
{
"lessThan": "6665fbd7730b26d770c232b20d1b907e6a67a914",
"status": "affected",
"version": "0cc04e80458a822300b93f82ed861a513edde194",
"versionType": "git"
},
{
"lessThan": "176725f4848376530a0f0da9023f956afcc33585",
"status": "affected",
"version": "0cc04e80458a822300b93f82ed861a513edde194",
"versionType": "git"
},
{
"lessThan": "a01efa7a780c42ac5170a949bd95c9786ffcc60a",
"status": "affected",
"version": "0cc04e80458a822300b93f82ed861a513edde194",
"versionType": "git"
},
{
"lessThan": "20739af07383e6eb1ec59dcd70b72ebfa9ac362c",
"status": "affected",
"version": "0cc04e80458a822300b93f82ed861a513edde194",
"versionType": "git"
},
{
"lessThan": "6.1.159",
"status": "affected",
"version": "6.1.158",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/time/timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.159",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.118",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.60",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.159",
"versionStartIncluding": "6.1.158",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.118",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.60",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.10",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntimers: Fix NULL function pointer race in timer_shutdown_sync()\n\nThere is a race condition between timer_shutdown_sync() and timer\nexpiration that can lead to hitting a WARN_ON in expire_timers().\n\nThe issue occurs when timer_shutdown_sync() clears the timer function\nto NULL while the timer is still running on another CPU. The race\nscenario looks like this:\n\nCPU0\t\t\t\t\tCPU1\n\t\t\t\t\t\u003cSOFTIRQ\u003e\n\t\t\t\t\tlock_timer_base()\n\t\t\t\t\texpire_timers()\n\t\t\t\t\tbase-\u003erunning_timer = timer;\n\t\t\t\t\tunlock_timer_base()\n\t\t\t\t\t[call_timer_fn enter]\n\t\t\t\t\tmod_timer()\n\t\t\t\t\t...\ntimer_shutdown_sync()\nlock_timer_base()\n// For now, will not detach the timer but only clear its function to NULL\nif (base-\u003erunning_timer != timer)\n\tret = detach_if_pending(timer, base, true);\nif (shutdown)\n\ttimer-\u003efunction = NULL;\nunlock_timer_base()\n\t\t\t\t\t[call_timer_fn exit]\n\t\t\t\t\tlock_timer_base()\n\t\t\t\t\tbase-\u003erunning_timer = NULL;\n\t\t\t\t\tunlock_timer_base()\n\t\t\t\t\t...\n\t\t\t\t\t// Now timer is pending while its function set to NULL.\n\t\t\t\t\t// next timer trigger\n\t\t\t\t\t\u003cSOFTIRQ\u003e\n\t\t\t\t\texpire_timers()\n\t\t\t\t\tWARN_ON_ONCE(!fn) // hit\n\t\t\t\t\t...\nlock_timer_base()\n// Now timer will detach\nif (base-\u003erunning_timer != timer)\n\tret = detach_if_pending(timer, base, true);\nif (shutdown)\n\ttimer-\u003efunction = NULL;\nunlock_timer_base()\n\nThe problem is that timer_shutdown_sync() clears the timer function\nregardless of whether the timer is currently running. This can leave a\npending timer with a NULL function pointer, which triggers the\nWARN_ON_ONCE(!fn) check in expire_timers().\n\nFix this by only clearing the timer function when actually detaching the\ntimer. If the timer is running, leave the function pointer intact, which is\nsafe because the timer will be properly detached when it finishes running."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-23T16:02:22.475Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ba43ac025c4318241f8edf94f31d2eebab86991b"
},
{
"url": "https://git.kernel.org/stable/c/1a975716cc8977f461e45e28e3e5977d46ad7a6a"
},
{
"url": "https://git.kernel.org/stable/c/6665fbd7730b26d770c232b20d1b907e6a67a914"
},
{
"url": "https://git.kernel.org/stable/c/176725f4848376530a0f0da9023f956afcc33585"
},
{
"url": "https://git.kernel.org/stable/c/a01efa7a780c42ac5170a949bd95c9786ffcc60a"
},
{
"url": "https://git.kernel.org/stable/c/20739af07383e6eb1ec59dcd70b72ebfa9ac362c"
}
],
"title": "timers: Fix NULL function pointer race in timer_shutdown_sync()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-68214",
"datePublished": "2025-12-16T13:57:09.728Z",
"dateReserved": "2025-12-16T13:41:40.256Z",
"dateUpdated": "2026-05-23T16:02:22.475Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68106 (GCVE-0-2026-68106)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix division by zero with invalid uvd dimensions
When width or height is less than 16, width_in_mb or height_in_mb
becomes 0, leading to fs_in_mb being 0. This causes a division by
zero when calculating num_dpb_buffer in H264 and H264 Perf decode
paths.
Add validation to reject frames with width < 16 or height < 16
before performing any calculations that depend on these values.
V2: Format change - move up all vaiable definitions.
V3: Use warn_once to avoid spam.
(cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "004d0453cfef16f056cb7b8bc04f69f19cf9df32",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "00ee64910ecf748cc15b23bbcbea472c203ec1e8",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "81c9b4921f62d1642b9d775524ae9240e521a5ed",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "52f9a588296432accf2982f7d258192a37562f4f",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "a00946b5ab7c25da5685ca9c58f50ff6f43c0fdf",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "ffb33d466a68cea3e8a3dbed04d79037a3cbabd1",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "be725ab23aa45c11a5afef3e2a9f6d8c084ae5dc",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "0c01c811be47e6b146552dd59bfedbea8f09b8f4",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix division by zero with invalid uvd dimensions\n\nWhen width or height is less than 16, width_in_mb or height_in_mb\nbecomes 0, leading to fs_in_mb being 0. This causes a division by\nzero when calculating num_dpb_buffer in H264 and H264 Perf decode\npaths.\n\nAdd validation to reject frames with width \u003c 16 or height \u003c 16\nbefore performing any calculations that depend on these values.\n\nV2: Format change - move up all vaiable definitions.\nV3: Use warn_once to avoid spam.\n\n(cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only via the AMDGPU_CS DRM ioctl on a local render node (/dev/dri/renderD*), traversing amdgpu_cs_ioctl, amdgpu_cs_patch_ibs, amdgpu_uvd_ring_parse_cs, and amdgpu_uvd_cs_msg_decode; it is not reachable from any network-facing kernel service.\nAC:L - An attacker with render-node access fully controls the UVD decode message fields (stream_type H264/H264 Perf, width, height, level) in their own BO and can reliably trigger width or height \u003c 16 after creating a valid UVD session handle.\nPR:L - Exploitation requires only standard unprivileged local access to the AMDGPU DRM render node (DRM_AUTH|DRM_RENDER_ALLOW on AMDGPU_CS), not root or capabilities outside the render/video group; user namespaces do not grant this access by themselves.\nUI:N - No victim interaction is required; a local attacker can directly submit a crafted UVD command stream through AMDGPU_CS ioctl without needing another user to open media, mount a filesystem, or take any other action.\nS:U - Impact is confined to the kernel/GPU driver security domain on the local host (kernel oops or GPU memory corruption within the attacker\u0027s DRM client); it does not cross VM, IOMMU, or sandbox boundaries to affect a different security authority.\nC:H - On x86, kernel-mode divide-by-zero causes a fatal trap; on architectures where unsigned division by zero returns zero, underestimated DPB buffer sizes can pass validation, enabling GPU out-of-bounds reads of adjacent mapped buffers that may hold sensitive data.\nI:H - Underestimated buffer-size calculations from zero macroblock counts can let undersized DPB buffers pass kernel validation, permitting the UVD engine to perform out-of-bounds writes into adjacent GPU-mapped memory that could be leveraged for further memory corruption.\nA:H - Triggering the divide-by-zero in kernel context during CS parsing causes an x86 divide-error exception leading to die()/kernel oops, crashing or hanging the system; repeated submissions can deny GPU/video availability on affected UVD hardware (v3.1-v6.0)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:19.954Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/004d0453cfef16f056cb7b8bc04f69f19cf9df32"
},
{
"url": "https://git.kernel.org/stable/c/00ee64910ecf748cc15b23bbcbea472c203ec1e8"
},
{
"url": "https://git.kernel.org/stable/c/81c9b4921f62d1642b9d775524ae9240e521a5ed"
},
{
"url": "https://git.kernel.org/stable/c/52f9a588296432accf2982f7d258192a37562f4f"
},
{
"url": "https://git.kernel.org/stable/c/a00946b5ab7c25da5685ca9c58f50ff6f43c0fdf"
},
{
"url": "https://git.kernel.org/stable/c/ffb33d466a68cea3e8a3dbed04d79037a3cbabd1"
},
{
"url": "https://git.kernel.org/stable/c/be725ab23aa45c11a5afef3e2a9f6d8c084ae5dc"
},
{
"url": "https://git.kernel.org/stable/c/0c01c811be47e6b146552dd59bfedbea8f09b8f4"
}
],
"title": "drm/amdgpu: fix division by zero with invalid uvd dimensions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68106",
"datePublished": "2026-08-10T11:58:23.108Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:19.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68310 (GCVE-0-2026-68310)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7915: guard HE capability lookups
mt7915_mcu_bss_he_tlv() and mt7915_mcu_sta_bfer_tlv() both run after
checking HE support, then dereference the HE PHY capability returned by
mt76_connac_get_he_phy_cap(). That helper can return NULL when no
capability entry matches the vif type.
Fetch the capability before appending the TLV and skip the HE-specific
setup when no matching capability is available.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7915/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8d5f1f4d2ea2c9d626ccc28dba7ea0df862acc67",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "23a2b98e754da04e0e90314d5fa8ca44349590fb",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "a031f454f14e3e76ad03bcb23918e1a82b4b0869",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "871549814eb4da081f1e93cc0c7ea626a310a966",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "6f99a5667c6c7c3e0da1d3c4dc8dfb103042609e",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "8e9db062654a388d0fa587acbeeae68dd33eba41",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7915/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: guard HE capability lookups\n\nmt7915_mcu_bss_he_tlv() and mt7915_mcu_sta_bfer_tlv() both run after\nchecking HE support, then dereference the HE PHY capability returned by\nmt76_connac_get_he_phy_cap(). That helper can return NULL when no\ncapability entry matches the vif type.\n\nFetch the capability before appending the TLV and skip the HE-specific\nsetup when no matching capability is available."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:03.090Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8d5f1f4d2ea2c9d626ccc28dba7ea0df862acc67"
},
{
"url": "https://git.kernel.org/stable/c/23a2b98e754da04e0e90314d5fa8ca44349590fb"
},
{
"url": "https://git.kernel.org/stable/c/a031f454f14e3e76ad03bcb23918e1a82b4b0869"
},
{
"url": "https://git.kernel.org/stable/c/871549814eb4da081f1e93cc0c7ea626a310a966"
},
{
"url": "https://git.kernel.org/stable/c/6f99a5667c6c7c3e0da1d3c4dc8dfb103042609e"
},
{
"url": "https://git.kernel.org/stable/c/8e9db062654a388d0fa587acbeeae68dd33eba41"
}
],
"title": "wifi: mt76: mt7915: guard HE capability lookups",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68310",
"datePublished": "2026-08-10T12:02:44.917Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:33:03.090Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-31418 (GCVE-0-2026-31418)
Vulnerability from cvelistv5
Published
2026-04-13 13:21
Modified
2026-09-08 08:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: drop logically empty buckets in mtype_del
mtype_del() counts empty slots below n->pos in k, but it only drops the
bucket when both n->pos and k are zero. This misses buckets whose live
entries have all been removed while n->pos still points past deleted slots.
Treat a bucket as empty when all positions below n->pos are unused and
release it directly instead of shrinking it further.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 Version: 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 Version: 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 Version: 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 Version: 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 Version: 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 Version: 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 Version: 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 Version: 6c717726f341fd8f39a3ec2dcf5d98d9d28a2769 Version: d2997d64dfa65082236bca1efd596b6c935daf5e Version: 5.4.24 ≤ Version: 5.5.8 ≤ |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:46:55.323Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipset/ip_set_hash_gen.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c098ff857e7ca923539164af5b3c2fe3e8f8afaf",
"status": "affected",
"version": "8af1c6fbd9239877998c7f5a591cb2c88d41fb66",
"versionType": "git"
},
{
"lessThan": "58f3a14826d4e6b0d5421f1a64be280b48601ea2",
"status": "affected",
"version": "8af1c6fbd9239877998c7f5a591cb2c88d41fb66",
"versionType": "git"
},
{
"lessThan": "ad92ee87462f9a3061361d392e9dbfe2e5c1c9fb",
"status": "affected",
"version": "8af1c6fbd9239877998c7f5a591cb2c88d41fb66",
"versionType": "git"
},
{
"lessThan": "6cea34d7ec6829b62f521a37a287f670144a2233",
"status": "affected",
"version": "8af1c6fbd9239877998c7f5a591cb2c88d41fb66",
"versionType": "git"
},
{
"lessThan": "b7eef00f08b92b0b9efe8ae0df6d0005e6199323",
"status": "affected",
"version": "8af1c6fbd9239877998c7f5a591cb2c88d41fb66",
"versionType": "git"
},
{
"lessThan": "68ca0eea0af02bed36c5e2c13e9fa1647c31a7d4",
"status": "affected",
"version": "8af1c6fbd9239877998c7f5a591cb2c88d41fb66",
"versionType": "git"
},
{
"lessThan": "ceacaa76f221a6577aba945bb8873c2e640aeba4",
"status": "affected",
"version": "8af1c6fbd9239877998c7f5a591cb2c88d41fb66",
"versionType": "git"
},
{
"lessThan": "9862ef9ab0a116c6dca98842aab7de13a252ae02",
"status": "affected",
"version": "8af1c6fbd9239877998c7f5a591cb2c88d41fb66",
"versionType": "git"
},
{
"status": "affected",
"version": "6c717726f341fd8f39a3ec2dcf5d98d9d28a2769",
"versionType": "git"
},
{
"status": "affected",
"version": "d2997d64dfa65082236bca1efd596b6c935daf5e",
"versionType": "git"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.24",
"versionType": "semver"
},
{
"lessThan": "5.6",
"status": "affected",
"version": "5.5.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipset/ip_set_hash_gen.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.253",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.168",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.134",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.81",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.22",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.253",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.168",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.134",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.81",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.22",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.12",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: drop logically empty buckets in mtype_del\n\nmtype_del() counts empty slots below n-\u003epos in k, but it only drops the\nbucket when both n-\u003epos and k are zero. This misses buckets whose live\nentries have all been removed while n-\u003epos still points past deleted slots.\n\nTreat a bucket as empty when all positions below n-\u003epos are unused and\nrelease it directly instead of shrinking it further."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-23T16:04:57.387Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c098ff857e7ca923539164af5b3c2fe3e8f8afaf"
},
{
"url": "https://git.kernel.org/stable/c/58f3a14826d4e6b0d5421f1a64be280b48601ea2"
},
{
"url": "https://git.kernel.org/stable/c/ad92ee87462f9a3061361d392e9dbfe2e5c1c9fb"
},
{
"url": "https://git.kernel.org/stable/c/6cea34d7ec6829b62f521a37a287f670144a2233"
},
{
"url": "https://git.kernel.org/stable/c/b7eef00f08b92b0b9efe8ae0df6d0005e6199323"
},
{
"url": "https://git.kernel.org/stable/c/68ca0eea0af02bed36c5e2c13e9fa1647c31a7d4"
},
{
"url": "https://git.kernel.org/stable/c/ceacaa76f221a6577aba945bb8873c2e640aeba4"
},
{
"url": "https://git.kernel.org/stable/c/9862ef9ab0a116c6dca98842aab7de13a252ae02"
}
],
"title": "netfilter: ipset: drop logically empty buckets in mtype_del",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-31418",
"datePublished": "2026-04-13T13:21:05.316Z",
"dateReserved": "2026-03-09T15:48:24.087Z",
"dateUpdated": "2026-09-08T08:46:55.323Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64527 (GCVE-0-2026-64527)
Vulnerability from cvelistv5
Published
2026-07-25 09:20
Modified
2026-07-25 09:20
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/hyperv: validate VMBus packet size in receive callback
hyperv_receive_sub() reads msg->vid_hdr.type and dispatches into one
of four message-type branches without knowing how many bytes the host
wrote into hv->recv_buf. The completion path then runs
memcpy(hv->init_buf, msg, VMBUS_MAX_PACKET_SIZE), so the consumer that
wakes on wait_for_completion_timeout() can read up to 16 KiB of
residue from a prior message as if it were the response payload.
Pass bytes_recvd into hyperv_receive_sub() and reject any packet that
does not cover the pipe + synthvid header. A single switch on
msg->vid_hdr.type then computes the type-specific payload size: the
three completion-driving types (SYNTHVID_VERSION_RESPONSE,
SYNTHVID_RESOLUTION_RESPONSE, SYNTHVID_VRAM_LOCATION_ACK) fall through
to a shared exit that requires that size before memcpy/complete, while
SYNTHVID_FEATURE_CHANGE validates its own payload and returns before
reading is_dirt_needed. Unknown types are dropped.
SYNTHVID_RESOLUTION_RESPONSE is variable length: the host fills
resolution_count entries, not the full SYNTHVID_MAX_RESOLUTION_COUNT
array. Validate the fixed prefix first so resolution_count can be
read, bound it against the array, then require only the count-sized
array, so the shorter responses the host actually sends are accepted.
Only run the sub-handler when vmbus_recvpacket() returned success. The
memcpy length is bytes_recvd, which is bounded by VMBUS_MAX_PACKET_SIZE
only on a successful receive; on -ENOBUFS vmbus_recvpacket() instead
reports the required length, which can exceed hv->recv_buf, so copying
bytes_recvd would read and write past the 16 KiB buffers. Gating on the
success return keeps the copy bounded. The nonzero-return path is itself
a malformed-message case and is now logged rather than silently skipped;
channel recovery is not attempted.
Rejected packets are reported via drm_err_ratelimited() rather than
silently dropped, matching the CoCo-hardened pattern in
hv_kvp_onchannelcallback().
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 Version: 76c56a5affeba1e163b66b9d8cc192e6154466f0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/hyperv/hyperv_drm_proto.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "57d5d697642e05d5dd2d40660817765943dd709f",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "f5251226551bfec98c4705641b6f94ff1f238d91",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "049a6b474823049fe60212f25f26e4b30f44ee8f",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "588c84b461393ff1998ac7b97b04f953f642e0df",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "164dc7bf17609340233c6bf4f66bb7c7008a0511",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "c8974d96b6a5496f33dc69a3ce28a7bf5078def4",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
},
{
"lessThan": "7f87763f47a3c22fb50265a00619ef10f2394b18",
"status": "affected",
"version": "76c56a5affeba1e163b66b9d8cc192e6154466f0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/hyperv/hyperv_drm_proto.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/hyperv: validate VMBus packet size in receive callback\n\nhyperv_receive_sub() reads msg-\u003evid_hdr.type and dispatches into one\nof four message-type branches without knowing how many bytes the host\nwrote into hv-\u003erecv_buf. The completion path then runs\nmemcpy(hv-\u003einit_buf, msg, VMBUS_MAX_PACKET_SIZE), so the consumer that\nwakes on wait_for_completion_timeout() can read up to 16 KiB of\nresidue from a prior message as if it were the response payload.\n\nPass bytes_recvd into hyperv_receive_sub() and reject any packet that\ndoes not cover the pipe + synthvid header. A single switch on\nmsg-\u003evid_hdr.type then computes the type-specific payload size: the\nthree completion-driving types (SYNTHVID_VERSION_RESPONSE,\nSYNTHVID_RESOLUTION_RESPONSE, SYNTHVID_VRAM_LOCATION_ACK) fall through\nto a shared exit that requires that size before memcpy/complete, while\nSYNTHVID_FEATURE_CHANGE validates its own payload and returns before\nreading is_dirt_needed. Unknown types are dropped.\n\nSYNTHVID_RESOLUTION_RESPONSE is variable length: the host fills\nresolution_count entries, not the full SYNTHVID_MAX_RESOLUTION_COUNT\narray. Validate the fixed prefix first so resolution_count can be\nread, bound it against the array, then require only the count-sized\narray, so the shorter responses the host actually sends are accepted.\n\nOnly run the sub-handler when vmbus_recvpacket() returned success. The\nmemcpy length is bytes_recvd, which is bounded by VMBUS_MAX_PACKET_SIZE\nonly on a successful receive; on -ENOBUFS vmbus_recvpacket() instead\nreports the required length, which can exceed hv-\u003erecv_buf, so copying\nbytes_recvd would read and write past the 16 KiB buffers. Gating on the\nsuccess return keeps the copy bounded. The nonzero-return path is itself\na malformed-message case and is now logged rather than silently skipped;\nchannel recovery is not attempted.\n\nRejected packets are reported via drm_err_ratelimited() rather than\nsilently dropped, matching the CoCo-hardened pattern in\nhv_kvp_onchannelcallback()."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-25T09:20:51.078Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/57d5d697642e05d5dd2d40660817765943dd709f"
},
{
"url": "https://git.kernel.org/stable/c/f5251226551bfec98c4705641b6f94ff1f238d91"
},
{
"url": "https://git.kernel.org/stable/c/049a6b474823049fe60212f25f26e4b30f44ee8f"
},
{
"url": "https://git.kernel.org/stable/c/588c84b461393ff1998ac7b97b04f953f642e0df"
},
{
"url": "https://git.kernel.org/stable/c/164dc7bf17609340233c6bf4f66bb7c7008a0511"
},
{
"url": "https://git.kernel.org/stable/c/c8974d96b6a5496f33dc69a3ce28a7bf5078def4"
},
{
"url": "https://git.kernel.org/stable/c/7f87763f47a3c22fb50265a00619ef10f2394b18"
}
],
"title": "drm/hyperv: validate VMBus packet size in receive callback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64527",
"datePublished": "2026-07-25T09:20:51.078Z",
"dateReserved": "2026-07-19T15:36:31.794Z",
"dateUpdated": "2026-07-25T09:20:51.078Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68333 (GCVE-0-2026-68333)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: put MAC endpoint device on disconnect
fsl_mc_get_endpoint() returns the MAC endpoint device with a reference
taken through device_find_child(). The switch port connect path stores
that device in mac->mc_dev and keeps it for the lifetime of the connected
MAC object.
However, the disconnect path only closes the MAC and frees the dpaa2_mac
object. It does not drop the endpoint device reference stored in
mac->mc_dev, so every successful connect leaks that device reference when
the MAC is later disconnected.
Drop the endpoint device reference before freeing the dpaa2_mac object.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "196f7301537814bef0f5915f87cd73d6d1235c19",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "0e9a6811eb6198ab17538cd01fa155d133b238ed",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "680eecc850d36a280df9780496bc603fec17b2d6",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "26ac2d3602347f0377fbcd5214bc28a9d735ae68",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "c27694ff6748e08fcd2fdba89018439d75b8198f",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "4c1eabbef7a1707635652e956e39db1269c3af2b",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpaa2-switch: put MAC endpoint device on disconnect\n\nfsl_mc_get_endpoint() returns the MAC endpoint device with a reference\ntaken through device_find_child(). The switch port connect path stores\nthat device in mac-\u003emc_dev and keeps it for the lifetime of the connected\nMAC object.\n\nHowever, the disconnect path only closes the MAC and frees the dpaa2_mac\nobject. It does not drop the endpoint device reference stored in\nmac-\u003emc_dev, so every successful connect leaks that device reference when\nthe MAC is later disconnected.\n\nDrop the endpoint device reference before freeing the dpaa2_mac object."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:30.627Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/196f7301537814bef0f5915f87cd73d6d1235c19"
},
{
"url": "https://git.kernel.org/stable/c/0e9a6811eb6198ab17538cd01fa155d133b238ed"
},
{
"url": "https://git.kernel.org/stable/c/1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38"
},
{
"url": "https://git.kernel.org/stable/c/680eecc850d36a280df9780496bc603fec17b2d6"
},
{
"url": "https://git.kernel.org/stable/c/26ac2d3602347f0377fbcd5214bc28a9d735ae68"
},
{
"url": "https://git.kernel.org/stable/c/c27694ff6748e08fcd2fdba89018439d75b8198f"
},
{
"url": "https://git.kernel.org/stable/c/4c1eabbef7a1707635652e956e39db1269c3af2b"
}
],
"title": "dpaa2-switch: put MAC endpoint device on disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68333",
"datePublished": "2026-08-10T12:03:09.524Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:30.627Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68218 (GCVE-0-2026-68218)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: pci: dm1105: Free allocated workqueue
Destroy allocated workqueue in remove() callback to free its resources,
thus fixing memory leak.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/dm1105/dm1105.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "078e0750b5e60277e44d780d70c6997c46569df2",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "d97f2e37516aa151582c8b2296021332db6da906",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "df5cd8b30c750f4edd0766982437d3472a0dbbd4",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "46715fecc38a2d341c3ff680f295de6e8aec72c0",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "8d753c8c37afc0910ed5ddc014645b05d6266add",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "08ddfd628a2dbd9d385da677afccd893d0ab37e1",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "0c2b4c45fce012e88904b8c66b5cd786535c0b8c",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "1a65db225b25bb8c8febf16974c060e0cc242eb9",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/dm1105/dm1105.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.31"
},
{
"lessThan": "2.6.31",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.31",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pci: dm1105: Free allocated workqueue\n\nDestroy allocated workqueue in remove() callback to free its resources,\nthus fixing memory leak."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:50.280Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/078e0750b5e60277e44d780d70c6997c46569df2"
},
{
"url": "https://git.kernel.org/stable/c/d97f2e37516aa151582c8b2296021332db6da906"
},
{
"url": "https://git.kernel.org/stable/c/df5cd8b30c750f4edd0766982437d3472a0dbbd4"
},
{
"url": "https://git.kernel.org/stable/c/46715fecc38a2d341c3ff680f295de6e8aec72c0"
},
{
"url": "https://git.kernel.org/stable/c/8d753c8c37afc0910ed5ddc014645b05d6266add"
},
{
"url": "https://git.kernel.org/stable/c/08ddfd628a2dbd9d385da677afccd893d0ab37e1"
},
{
"url": "https://git.kernel.org/stable/c/0c2b4c45fce012e88904b8c66b5cd786535c0b8c"
},
{
"url": "https://git.kernel.org/stable/c/1a65db225b25bb8c8febf16974c060e0cc242eb9"
}
],
"title": "media: pci: dm1105: Free allocated workqueue",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68218",
"datePublished": "2026-08-10T12:00:38.175Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:50.280Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64584 (GCVE-0-2026-64584)
Vulnerability from cvelistv5
Published
2026-08-06 07:06
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_midi: cancel pending IN work before freeing the midi object
The f_midi driver embeds a work item (midi->work) whose handler,
f_midi_in_work(), dereferences the enclosing struct f_midi through
container_of(). This work is armed from two sites: f_midi_complete(),
on a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA
rawmidi output-stream start.
Neither f_midi_disable() nor f_midi_unbind() cancels midi->work.
f_midi_disable() only disables the endpoints and drains the in_req_fifo;
it does not synchronize the work item, and the sound card is released
asynchronously to the final free of the midi object.
The midi object is reference-counted (midi->free_ref) and is freed in
f_midi_free() only once both the usb_function reference and the rawmidi
private_data reference have been dropped. In f_midi_unbind(),
f_midi_disable() runs before the sound card is released, so while the
USB endpoints are already disabled the rawmidi device is still usable by
an open substream. A concurrent userspace write on such a substream can
reach f_midi_in_trigger() and queue midi->work again after
f_midi_disable() has returned. A work item armed this way may still be
pending when the last reference drops and f_midi_free() proceeds to
kfree(midi), letting f_midi_in_work() dereference the struct after it
has been freed, a use-after-free.
For this reason cancelling midi->work in f_midi_disable() would not be
sufficient: the ALSA trigger path can rearm the work after disable()
returns. Cancelling at the refcount-zero free site is the boundary
after which neither arming source can survive, because by then both
references that keep the midi object alive have been dropped: the USB
endpoints are already disabled and the rawmidi device has been released.
Fix this by calling cancel_work_sync(&midi->work) in the refcount-zero
block of f_midi_free(), before the embedded work_struct is freed along
with the rest of the structure. opts->lock is a sleeping mutex, so
calling cancel_work_sync() under it is permitted, and the handler takes
midi->transmit_lock rather than opts->lock, so no self-deadlock can
occur while it waits for a running instance of the work to finish.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3635523e9b96213969693c320302d536774d8e9b Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 89019ab7a64fcdf98a2ba7799e5c6aff58d4a05d Version: 5.10.235 ≤ Version: 5.4.291 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_midi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f3c6f2c38062703d3dc7f86958bb0790c6959add",
"status": "affected",
"version": "3635523e9b96213969693c320302d536774d8e9b",
"versionType": "git"
},
{
"lessThan": "df18150126f66817e4d3f79f309e9c92d6ff384e",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "620955b222c47332297d6bf38f78541aa699238a",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "380b4bef46c2eb260c7a9c6bb2c5be33ce5a38f9",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "87bc316dd6fc90072297c635e10b9aa6075ecda1",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "f45089eaad0a083d71d84ff175741d7e157d9b69",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "ac9a51d910bb7465c554c45320cb6c09f3d0b49d",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "5650c18d93a1db7e27cb5a40b394747eb4686d5b",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"status": "affected",
"version": "89019ab7a64fcdf98a2ba7799e5c6aff58d4a05d",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.235",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.291",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_midi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.235",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.291",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_midi: cancel pending IN work before freeing the midi object\n\nThe f_midi driver embeds a work item (midi-\u003ework) whose handler,\nf_midi_in_work(), dereferences the enclosing struct f_midi through\ncontainer_of(). This work is armed from two sites: f_midi_complete(),\non a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA\nrawmidi output-stream start.\n\nNeither f_midi_disable() nor f_midi_unbind() cancels midi-\u003ework.\nf_midi_disable() only disables the endpoints and drains the in_req_fifo;\nit does not synchronize the work item, and the sound card is released\nasynchronously to the final free of the midi object.\n\nThe midi object is reference-counted (midi-\u003efree_ref) and is freed in\nf_midi_free() only once both the usb_function reference and the rawmidi\nprivate_data reference have been dropped. In f_midi_unbind(),\nf_midi_disable() runs before the sound card is released, so while the\nUSB endpoints are already disabled the rawmidi device is still usable by\nan open substream. A concurrent userspace write on such a substream can\nreach f_midi_in_trigger() and queue midi-\u003ework again after\nf_midi_disable() has returned. A work item armed this way may still be\npending when the last reference drops and f_midi_free() proceeds to\nkfree(midi), letting f_midi_in_work() dereference the struct after it\nhas been freed, a use-after-free.\n\nFor this reason cancelling midi-\u003ework in f_midi_disable() would not be\nsufficient: the ALSA trigger path can rearm the work after disable()\nreturns. Cancelling at the refcount-zero free site is the boundary\nafter which neither arming source can survive, because by then both\nreferences that keep the midi object alive have been dropped: the USB\nendpoints are already disabled and the rawmidi device has been released.\n\nFix this by calling cancel_work_sync(\u0026midi-\u003ework) in the refcount-zero\nblock of f_midi_free(), before the embedded work_struct is freed along\nwith the rest of the structure. opts-\u003elock is a sleeping mutex, so\ncalling cancel_work_sync() under it is permitted, and the handler takes\nmidi-\u003etransmit_lock rather than opts-\u003elock, so no self-deadlock can\noccur while it waits for a running instance of the work to finish.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is reached by local configfs UDC clear or function unlink (unregister_gadget \u2192 f_midi_unbind/disable) plus ALSA rawmidi write/close on /dev/snd/midi*; no USB host traffic or cable access is required, and dummy_hcd suffices, matching other gadget teardown UAFs scored AV:L.\nAC:L - The attacker controls both sides of the race: opening/writing the rawmidi substream to queue midi-\u003ework via f_midi_in_trigger after disable, and forcing unbind plus dropping the last free_ref via configfs unlink/close, so the window is freely repeatable.\nPR:L - Exploitation needs access to the gadget configfs tree and/or the ALSA MIDI node; both are routinely delegated to non-root system/audio accounts on Android and embedded MIDI gadgets, with no capability check on the rawmidi write or UDC store path itself.\nUI:N - The attacker performs the full sequence\u2014configfs unbind/unlink, rawmidi write to rearm work, and close to free the midi object\u2014without any action by another user or administrator.\nS:U - The use-after-free corrupts kernel heap within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - f_midi_in_work() container_of()s the freed embedded work_struct and then reads midi-\u003ein_ep, fifo, and port/substream fields; reclaiming the freed f_midi slab yields a classic UAF read/disclosure primitive.\nI:H - Post-free f_midi_transmit()/f_midi_drop_out_substreams() write through the reclaimed object (port state, kfifo, snd_rawmidi_drop_output), giving a heap write-after-free primitive suitable for control-flow hijack.\nA:H - Dereferencing the freed f_midi from system_highpri_wq reliably produces KASAN reports, oops, or kernel panic even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:12.890Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f3c6f2c38062703d3dc7f86958bb0790c6959add"
},
{
"url": "https://git.kernel.org/stable/c/df18150126f66817e4d3f79f309e9c92d6ff384e"
},
{
"url": "https://git.kernel.org/stable/c/620955b222c47332297d6bf38f78541aa699238a"
},
{
"url": "https://git.kernel.org/stable/c/380b4bef46c2eb260c7a9c6bb2c5be33ce5a38f9"
},
{
"url": "https://git.kernel.org/stable/c/87bc316dd6fc90072297c635e10b9aa6075ecda1"
},
{
"url": "https://git.kernel.org/stable/c/f45089eaad0a083d71d84ff175741d7e157d9b69"
},
{
"url": "https://git.kernel.org/stable/c/ac9a51d910bb7465c554c45320cb6c09f3d0b49d"
},
{
"url": "https://git.kernel.org/stable/c/5650c18d93a1db7e27cb5a40b394747eb4686d5b"
}
],
"title": "usb: gadget: f_midi: cancel pending IN work before freeing the midi object",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64584",
"datePublished": "2026-08-06T07:06:25.953Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:12.890Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72502 (GCVE-0-2026-72502)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
When MTU is large, ip6_default_advmss() can return IPV6_MAXPLEN (65535).
This is interpreted by TCP as mss_clamp, allowing the MSS to reach 65535.
However, 0xFFFF is also used as a magic value GSO_BY_FRAGS in the kernel.
If a TCP packet with gso_size=0xFFFF is passed to skb_segment(), it will
be mistakenly treated as GSO_BY_FRAGS, leading to a NULL pointer
dereference because local TCP packets do not use frag_list.
Fix this by returning min(IPV6_MAXPLEN, GSO_BY_FRAGS - 1) (65534) from
ip6_default_advmss() when MTU is large.
Also update the stale comment in ip6_default_advmss() which suggested
that IPV6_MAXPLEN is returned to mean "any MSS".
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3953c46c3ac7eef31a9935427371c6f54a22f1ba Version: 3953c46c3ac7eef31a9935427371c6f54a22f1ba Version: 3953c46c3ac7eef31a9935427371c6f54a22f1ba Version: 3953c46c3ac7eef31a9935427371c6f54a22f1ba Version: 3953c46c3ac7eef31a9935427371c6f54a22f1ba Version: 3953c46c3ac7eef31a9935427371c6f54a22f1ba Version: 3953c46c3ac7eef31a9935427371c6f54a22f1ba Version: 3953c46c3ac7eef31a9935427371c6f54a22f1ba |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "560b33b434e922ef97f9ff23aa2e909ef7aacd5c",
"status": "affected",
"version": "3953c46c3ac7eef31a9935427371c6f54a22f1ba",
"versionType": "git"
},
{
"lessThan": "21f69ac1879bb970588d5e7c12a96e6542f7c1a7",
"status": "affected",
"version": "3953c46c3ac7eef31a9935427371c6f54a22f1ba",
"versionType": "git"
},
{
"lessThan": "c0db3dc2ac323b6c4b76adede3b355a9daa6dea8",
"status": "affected",
"version": "3953c46c3ac7eef31a9935427371c6f54a22f1ba",
"versionType": "git"
},
{
"lessThan": "572fff10819dfc359298d1f774839e76a4d96f93",
"status": "affected",
"version": "3953c46c3ac7eef31a9935427371c6f54a22f1ba",
"versionType": "git"
},
{
"lessThan": "8e6214a530c03e341dc1b0a846c8f2b716b3551a",
"status": "affected",
"version": "3953c46c3ac7eef31a9935427371c6f54a22f1ba",
"versionType": "git"
},
{
"lessThan": "d774cdbda6634a78d0f2baf201ee5a8c57f3bc0e",
"status": "affected",
"version": "3953c46c3ac7eef31a9935427371c6f54a22f1ba",
"versionType": "git"
},
{
"lessThan": "a210791f33345aa87187f7d7a9f3b9b7f4a28e6d",
"status": "affected",
"version": "3953c46c3ac7eef31a9935427371c6f54a22f1ba",
"versionType": "git"
},
{
"lessThan": "2bf43d0e2e6a27d52a7d624e2d6b9116972e8a22",
"status": "affected",
"version": "3953c46c3ac7eef31a9935427371c6f54a22f1ba",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)\n\nWhen MTU is large, ip6_default_advmss() can return IPV6_MAXPLEN (65535).\nThis is interpreted by TCP as mss_clamp, allowing the MSS to reach 65535.\n\nHowever, 0xFFFF is also used as a magic value GSO_BY_FRAGS in the kernel.\nIf a TCP packet with gso_size=0xFFFF is passed to skb_segment(), it will\nbe mistakenly treated as GSO_BY_FRAGS, leading to a NULL pointer\ndereference because local TCP packets do not use frag_list.\n\nFix this by returning min(IPV6_MAXPLEN, GSO_BY_FRAGS - 1) (65534) from\nip6_default_advmss() when MTU is large.\n\nAlso update the stale comment in ip6_default_advmss() which suggested\nthat IPV6_MAXPLEN is returned to mean \"any MSS\"."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Reachable from the network via IPv6 TCP: a remote peer sends a crafted SYN (MSS=65535) or connects over a large-MTU IPv6 route, causing outbound TCP GSO skbs with gso_size=0xFFFF to be software-segmented in skb_segment() during normal packet transmit.\nAC:L - The attacker controls the TCP handshake MSS option and can induce \u003e64KB outbound segments; syzbot reproduced this reliably, and software GSO paths (loopback, veth, NETIF_F_GSO_SOFTWARE) are common in cloud/container deployments where skb_segment() is invoked.\nPR:N - No privileges are required; exploitation occurs on the pre-authentication passive-open path where the kernel accepts a remote TCP SYN and MSS option before any application-level authentication.\nUI:N - No victim user interaction is needed beyond the target system normally accepting IPv6 TCP connections and transmitting response data to the attacker-controlled peer.\nS:U - The vulnerability causes a kernel crash on the attacked host itself; it does not cross a security boundary such as a VM escape, container sandbox breakout, or IOMMU/DMA isolation bypass.\nC:N - Impact is a NULL pointer dereference in skb_segment() when gso_size equals GSO_BY_FRAGS; there is no out-of-bounds read, use-after-free, or other memory disclosure primitive.\nI:N - The bug does not corrupt or modify attacker-controlled memory; it dereferences a NULL frag_list pointer during segmentation, yielding a crash rather than a write or code-execution primitive.\nA:H - The NULL pointer dereference in skb_segment() triggers a kernel oops/panic, causing complete loss of availability for the affected system when the malicious IPv6 TCP traffic path is exercised."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:45:02.121Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/560b33b434e922ef97f9ff23aa2e909ef7aacd5c"
},
{
"url": "https://git.kernel.org/stable/c/21f69ac1879bb970588d5e7c12a96e6542f7c1a7"
},
{
"url": "https://git.kernel.org/stable/c/c0db3dc2ac323b6c4b76adede3b355a9daa6dea8"
},
{
"url": "https://git.kernel.org/stable/c/572fff10819dfc359298d1f774839e76a4d96f93"
},
{
"url": "https://git.kernel.org/stable/c/8e6214a530c03e341dc1b0a846c8f2b716b3551a"
},
{
"url": "https://git.kernel.org/stable/c/d774cdbda6634a78d0f2baf201ee5a8c57f3bc0e"
},
{
"url": "https://git.kernel.org/stable/c/a210791f33345aa87187f7d7a9f3b9b7f4a28e6d"
},
{
"url": "https://git.kernel.org/stable/c/2bf43d0e2e6a27d52a7d624e2d6b9116972e8a22"
}
],
"title": "tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72502",
"datePublished": "2026-08-15T05:57:33.647Z",
"dateReserved": "2026-08-09T03:40:39.938Z",
"dateUpdated": "2026-08-17T05:45:02.121Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43213 (GCVE-0-2026-43213)
Vulnerability from cvelistv5
Published
2026-05-06 11:28
Modified
2026-08-05 12:26
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw89: pci: validate sequence number of TX release report
Hardware rarely reports abnormal sequence number in TX release report,
which will access out-of-bounds of wd_ring->pages array, causing NULL
pointer dereference.
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 1085 Comm: irq/129-rtw89_p Tainted: G S U
6.1.145-17510-g2f3369c91536 #1 (HASH:69e8 1)
Call Trace:
<IRQ>
rtw89_pci_release_tx+0x18f/0x300 [rtw89_pci (HASH:4c83 2)]
rtw89_pci_napi_poll+0xc2/0x190 [rtw89_pci (HASH:4c83 2)]
net_rx_action+0xfc/0x460 net/core/dev.c:6578 net/core/dev.c:6645 net/core/dev.c:6759
handle_softirqs+0xbe/0x290 kernel/softirq.c:601
? rtw89_pci_interrupt_threadfn+0xc5/0x350 [rtw89_pci (HASH:4c83 2)]
__local_bh_enable_ip+0xeb/0x120 kernel/softirq.c:499 kernel/softirq.c:423
</IRQ>
<TASK>
rtw89_pci_interrupt_threadfn+0xf8/0x350 [rtw89_pci (HASH:4c83 2)]
? irq_thread+0xa7/0x340 kernel/irq/manage.c:0
irq_thread+0x177/0x340 kernel/irq/manage.c:1205 kernel/irq/manage.c:1314
? thaw_kernel_threads+0xb0/0xb0 kernel/irq/manage.c:1202
? irq_forced_thread_fn+0x80/0x80 kernel/irq/manage.c:1220
kthread+0xea/0x110 kernel/kthread.c:376
? synchronize_irq+0x1a0/0x1a0 kernel/irq/manage.c:1287
? kthread_associate_blkcg+0x80/0x80 kernel/kthread.c:331
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295
</TASK>
To prevent crash, validate rpp_info.seq before using.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/realtek/rtw89/pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ef7fa19809b2d892d45da53f90ac698d13c367fd",
"status": "affected",
"version": "e3ec7017f6a20d12ddd9fe23d345ebb7b8c104dd",
"versionType": "git"
},
{
"lessThan": "b342dd13aedccb0dd27365f6cc63a262f42394ce",
"status": "affected",
"version": "e3ec7017f6a20d12ddd9fe23d345ebb7b8c104dd",
"versionType": "git"
},
{
"lessThan": "957eda596c7665f2966970fd1dcc35fe299b38e8",
"status": "affected",
"version": "e3ec7017f6a20d12ddd9fe23d345ebb7b8c104dd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/realtek/rtw89/pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: pci: validate sequence number of TX release report\n\nHardware rarely reports abnormal sequence number in TX release report,\nwhich will access out-of-bounds of wd_ring-\u003epages array, causing NULL\npointer dereference.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 1 PID: 1085 Comm: irq/129-rtw89_p Tainted: G S U\n 6.1.145-17510-g2f3369c91536 #1 (HASH:69e8 1)\n Call Trace:\n \u003cIRQ\u003e\n rtw89_pci_release_tx+0x18f/0x300 [rtw89_pci (HASH:4c83 2)]\n rtw89_pci_napi_poll+0xc2/0x190 [rtw89_pci (HASH:4c83 2)]\n net_rx_action+0xfc/0x460 net/core/dev.c:6578 net/core/dev.c:6645 net/core/dev.c:6759\n handle_softirqs+0xbe/0x290 kernel/softirq.c:601\n ? rtw89_pci_interrupt_threadfn+0xc5/0x350 [rtw89_pci (HASH:4c83 2)]\n __local_bh_enable_ip+0xeb/0x120 kernel/softirq.c:499 kernel/softirq.c:423\n \u003c/IRQ\u003e\n \u003cTASK\u003e\n rtw89_pci_interrupt_threadfn+0xf8/0x350 [rtw89_pci (HASH:4c83 2)]\n ? irq_thread+0xa7/0x340 kernel/irq/manage.c:0\n irq_thread+0x177/0x340 kernel/irq/manage.c:1205 kernel/irq/manage.c:1314\n ? thaw_kernel_threads+0xb0/0xb0 kernel/irq/manage.c:1202\n ? irq_forced_thread_fn+0x80/0x80 kernel/irq/manage.c:1220\n kthread+0xea/0x110 kernel/kthread.c:376\n ? synchronize_irq+0x1a0/0x1a0 kernel/irq/manage.c:1287\n ? kthread_associate_blkcg+0x80/0x80 kernel/kthread.c:331\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295\n \u003c/TASK\u003e\n\nTo prevent crash, validate rpp_info.seq before using."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable path is the rtw89 PCI WiFi TX release-report path reached from the device RPQ interrupt/NAPI handler after wireless transmissions. In AP or client deployments, an unauthenticated radio-range attacker can plausibly induce repeated TX completions by injecting or eliciting WiFi traffic.\nAC:H - The code path is deterministic once a malformed release report with an out-of-range sequence number is produced. However, the malformed sequence is described as a rare hardware/firmware report and is not directly chosen by the attacker.\nPR:N - In the adjacent WiFi attack scenario, the attacker does not need local accounts, capabilities, or authenticated access to the target host. Radio proximity is sufficient to stimulate the vulnerable TX completion path.\nUI:N - No victim action is required once the affected WiFi interface is active. The vulnerable processing occurs asynchronously in interrupt/NAPI context.\nS:U - The impact remains within the kernel and the affected host. There is no VM escape, IOMMU bypass, or cross-authority boundary change.\nC:H - The invalid 15-bit sequence number indexes past the 512-entry wd_ring-\u003epages array and causes adjacent kernel memory to be interpreted as TX descriptor/list/queue state. Conservatively, this out-of-bounds kernel memory access can expose sensitive kernel memory even though the observed failure is a NULL dereference.\nI:H - The out-of-bounds pseudo-TX descriptor can drive list, skb queue, DMA-unmap, status, and enqueue operations using invalid pointer fields. Conservatively, this kernel memory corruption can permit high-integrity impact.\nA:H - The fix commit documents a kernel NULL pointer dereference and oops in rtw89_pci_release_tx from this bug. A kernel crash or panic is a high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:26:38.601Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ef7fa19809b2d892d45da53f90ac698d13c367fd"
},
{
"url": "https://git.kernel.org/stable/c/b342dd13aedccb0dd27365f6cc63a262f42394ce"
},
{
"url": "https://git.kernel.org/stable/c/957eda596c7665f2966970fd1dcc35fe299b38e8"
}
],
"title": "wifi: rtw89: pci: validate sequence number of TX release report",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43213",
"datePublished": "2026-05-06T11:28:15.998Z",
"dateReserved": "2026-05-01T14:12:55.993Z",
"dateUpdated": "2026-08-05T12:26:38.601Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68217 (GCVE-0-2026-68217)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: pwc: Drain fill_buf on start_streaming() failure
pwc_isoc_init() submits its isochronous URBs with
usb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is
submitted, its completion handler pwc_isoc_handler() can run on another
CPU before the loop finishes:
start_streaming()
pwc_isoc_init()
usb_submit_urb(urbs[0], GFP_KERNEL)
pwc_isoc_handler(urbs[0])
pdev->fill_buf =
pwc_get_next_fill_buf(pdev)
usb_submit_urb(urbs[i>0], ..) -> fails
pwc_isoc_cleanup(pdev) /* kills URBs */
return ret;
pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)
pwc_get_next_fill_buf() detaches a buffer from pdev->queued_bufs and
stores it in pdev->fill_buf. The error path in start_streaming() only
drains pdev->queued_bufs, so the buffer parked in pdev->fill_buf is
leaked. vb2_start_streaming() then triggers
WARN_ON(owned_by_drv_count).
stop_streaming() already handles this since commit 80b0963e1698
("[media] pwc: fix WARN_ON"), which added the fill_buf drain in the
teardown path but not in the start_streaming() error path. Mirror that
handling on failure so start_streaming() returns with no buffer owned
by the driver.
Issue identified by automated review of the INV-003 series at
https://sashiko.dev/
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97f3c15957ec7e6d249f05407ad947c0644df24d",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "a4afffd148991a826e8995362fb10cf8705c1130",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "eabe9a59640698137d7382d5b549e95dc37f7565",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "a56e7641e09bd80b976e944ae759109b86fd5b38",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "acc789b2173070638cad89c2b61d33ed338be0dd",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "9afd605dcd96c7a45f338eded1de16679b30e1df",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "5d4812668b03f823b5044789d6aa77fe56b42587",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "906e410dcffbbd99fb4081abab817a830033aa28",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"lessThan": "3.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pwc: Drain fill_buf on start_streaming() failure\n\npwc_isoc_init() submits its isochronous URBs with\nusb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is\nsubmitted, its completion handler pwc_isoc_handler() can run on another\nCPU before the loop finishes:\n\n start_streaming()\n pwc_isoc_init()\n usb_submit_urb(urbs[0], GFP_KERNEL)\n pwc_isoc_handler(urbs[0])\n pdev-\u003efill_buf =\n pwc_get_next_fill_buf(pdev)\n usb_submit_urb(urbs[i\u003e0], ..) -\u003e fails\n pwc_isoc_cleanup(pdev) /* kills URBs */\n return ret;\n pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)\n\npwc_get_next_fill_buf() detaches a buffer from pdev-\u003equeued_bufs and\nstores it in pdev-\u003efill_buf. The error path in start_streaming() only\ndrains pdev-\u003equeued_bufs, so the buffer parked in pdev-\u003efill_buf is\nleaked. vb2_start_streaming() then triggers\nWARN_ON(owned_by_drv_count).\n\nstop_streaming() already handles this since commit 80b0963e1698\n(\"[media] pwc: fix WARN_ON\"), which added the fill_buf drain in the\nteardown path but not in the start_streaming() error path. Mirror that\nhandling on failure so start_streaming() returns with no buffer owned\nby the driver.\n\nIssue identified by automated review of the INV-003 series at\nhttps://sashiko.dev/"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:48.858Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97f3c15957ec7e6d249f05407ad947c0644df24d"
},
{
"url": "https://git.kernel.org/stable/c/a4afffd148991a826e8995362fb10cf8705c1130"
},
{
"url": "https://git.kernel.org/stable/c/eabe9a59640698137d7382d5b549e95dc37f7565"
},
{
"url": "https://git.kernel.org/stable/c/a56e7641e09bd80b976e944ae759109b86fd5b38"
},
{
"url": "https://git.kernel.org/stable/c/acc789b2173070638cad89c2b61d33ed338be0dd"
},
{
"url": "https://git.kernel.org/stable/c/9afd605dcd96c7a45f338eded1de16679b30e1df"
},
{
"url": "https://git.kernel.org/stable/c/5d4812668b03f823b5044789d6aa77fe56b42587"
},
{
"url": "https://git.kernel.org/stable/c/906e410dcffbbd99fb4081abab817a830033aa28"
}
],
"title": "media: pwc: Drain fill_buf on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68217",
"datePublished": "2026-08-10T12:00:36.773Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:48.858Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64247 (GCVE-0-2026-64247)
Vulnerability from cvelistv5
Published
2026-07-24 15:31
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: hyper-v: Bound the bank index when querying sparse banks
When checking if a VP ID is included in a sparse bank set, explicitly check
that the ID can actually be contained in a sparse bank (the TLFS allows for
a maximum of 64 banks of 64 vCPUs each). When handling a paravirtual TLB
flush for L2, the VP ID is copied verbatim from the enlightened VMCS,
without any bounds check, i.e. isn't guaranteed to be under the limit of
4096.
Failure to check the bounds of the VP ID leads to an out-of-bounds read
when testing the sparse bank, and super strictly speaking could lead to KVM
performing an unnecessary TLB flush for an L2 vCPU.
==================================================================
BUG: KASAN: use-after-free in hv_is_vp_in_sparse_set+0x85/0x100 [kvm]
Read of size 8 at addr ffff88811ba5f598 by task hyperv_evmcs/2802
CPU: 12 UID: 1000 PID: 2802 Comm: hyperv_evmcs Not tainted 7.1.0-rc2 #7 PREEMPT
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
Call Trace:
<TASK>
dump_stack_lvl+0x51/0x60
print_report+0xcb/0x5d0
kasan_report+0xb4/0xe0
kasan_check_range+0x35/0x1b0
hv_is_vp_in_sparse_set+0x85/0x100 [kvm]
kvm_hv_flush_tlb+0xe9e/0x16c0 [kvm]
kvm_hv_hypercall+0xe6b/0x1e60 [kvm]
vmx_handle_exit+0x485/0x1b60 [kvm_intel]
kvm_arch_vcpu_ioctl_run+0x22e3/0x5070 [kvm]
kvm_vcpu_ioctl+0x5d0/0x10c0 [kvm]
__x64_sys_ioctl+0x129/0x1a0
do_syscall_64+0xb9/0xcf0
entry_SYSCALL_64_after_hwframe+0x4b/0x53
RIP: 0033:0x7f0e62d1a9bf
</TASK>
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffffffffffffffff pfn:0x11ba5f
flags: 0x4000000000000000(zone=1)
raw: 4000000000000000 0000000000000000 00000000ffffffff 0000000000000000
raw: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
Memory state around the buggy address:
ffff88811ba5f480: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88811ba5f500: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff88811ba5f580: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
^
ffff88811ba5f600: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
ffff88811ba5f680: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================
Disabling lock debugging due to kernel taint
Opportunistically add a compile time assertion to ensure the maximum number
of sparse banks exactly matches the number of possible bits in the passed
in mask.
[sean: add KASAN splat, drop comment, add assert, massage changelog]
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/hyperv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d18756b12aab30d07794446445c93112e5c69a2e",
"status": "affected",
"version": "c58a318f6090efe06e6702b8882e2026f44f620e",
"versionType": "git"
},
{
"lessThan": "83c2f52c6a78b1590034e955cff3fe0b052fe4ae",
"status": "affected",
"version": "c58a318f6090efe06e6702b8882e2026f44f620e",
"versionType": "git"
},
{
"lessThan": "e36095d8d922bb26ce860231aacf0cd14edea07c",
"status": "affected",
"version": "c58a318f6090efe06e6702b8882e2026f44f620e",
"versionType": "git"
},
{
"lessThan": "f636cf6a1e7b7f40d48d8d08bd5f152aa61dd130",
"status": "affected",
"version": "c58a318f6090efe06e6702b8882e2026f44f620e",
"versionType": "git"
},
{
"lessThan": "4721f8160f17554b003e8928bb61e6c9b2fe92a3",
"status": "affected",
"version": "c58a318f6090efe06e6702b8882e2026f44f620e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/hyperv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: hyper-v: Bound the bank index when querying sparse banks\n\nWhen checking if a VP ID is included in a sparse bank set, explicitly check\nthat the ID can actually be contained in a sparse bank (the TLFS allows for\na maximum of 64 banks of 64 vCPUs each). When handling a paravirtual TLB\nflush for L2, the VP ID is copied verbatim from the enlightened VMCS,\nwithout any bounds check, i.e. isn\u0027t guaranteed to be under the limit of\n4096.\n\nFailure to check the bounds of the VP ID leads to an out-of-bounds read\nwhen testing the sparse bank, and super strictly speaking could lead to KVM\nperforming an unnecessary TLB flush for an L2 vCPU.\n\n ==================================================================\n BUG: KASAN: use-after-free in hv_is_vp_in_sparse_set+0x85/0x100 [kvm]\n Read of size 8 at addr ffff88811ba5f598 by task hyperv_evmcs/2802\n\n CPU: 12 UID: 1000 PID: 2802 Comm: hyperv_evmcs Not tainted 7.1.0-rc2 #7 PREEMPT\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x51/0x60\n print_report+0xcb/0x5d0\n kasan_report+0xb4/0xe0\n kasan_check_range+0x35/0x1b0\n hv_is_vp_in_sparse_set+0x85/0x100 [kvm]\n kvm_hv_flush_tlb+0xe9e/0x16c0 [kvm]\n kvm_hv_hypercall+0xe6b/0x1e60 [kvm]\n vmx_handle_exit+0x485/0x1b60 [kvm_intel]\n kvm_arch_vcpu_ioctl_run+0x22e3/0x5070 [kvm]\n kvm_vcpu_ioctl+0x5d0/0x10c0 [kvm]\n __x64_sys_ioctl+0x129/0x1a0\n do_syscall_64+0xb9/0xcf0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n RIP: 0033:0x7f0e62d1a9bf\n \u003c/TASK\u003e\n\n The buggy address belongs to the physical page:\n page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffffffffffffffff pfn:0x11ba5f\n flags: 0x4000000000000000(zone=1)\n raw: 4000000000000000 0000000000000000 00000000ffffffff 0000000000000000\n raw: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff88811ba5f480: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n ffff88811ba5f500: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n \u003effff88811ba5f580: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n ^\n ffff88811ba5f600: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n ffff88811ba5f680: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n ==================================================================\n Disabling lock debugging due to kernel taint\n\nOpportunistically add a compile time assertion to ensure the maximum number\nof sparse banks exactly matches the number of possible bits in the passed\nin mask.\n\n[sean: add KASAN splat, drop comment, add assert, massage changelog]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggering requires a Hyper-V TLB-flush hypercall from an L2 vCPU under KVM, ultimately reached through the local KVM_RUN ioctl; no network path reaches it.\nAC:L - A malicious nested-virtualization tenant controls both the unchecked enlightened-VMCS/VMCB VP ID and the sparse-bank hypercall data, with no uncontrollable race required.\nPR:L - The attacker needs control of a KVM guest with nested virtualization, or ordinary /dev/kvm access to create one, but requires neither host root nor an init-namespace capability.\nUI:N - Once the crafted nested guest executes, no action by another user is required.\nS:C - The out-of-bounds access occurs in the host kernel from attacker-controlled guest state, crossing the KVM guest-to-host isolation boundary.\nC:H - The attacker-selected VP ID makes test_bit() query selectable bits far beyond the stack-resident 64-bit mask, and the resulting TLB-flush decision can provide an oracle for host kernel memory.\nI:N - The primitive performs reads only; a set result merely selects a legitimate L2 vCPU for an extra TLB flush, with no out-of-bounds write or unsafe mapping change.\nA:H - The selectable access can reach a VMAP_STACK guard or another unmapped page and oops the host; KASAN already detects the access as an eight-byte invalid read, which can become a host-wide denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:58.515Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d18756b12aab30d07794446445c93112e5c69a2e"
},
{
"url": "https://git.kernel.org/stable/c/83c2f52c6a78b1590034e955cff3fe0b052fe4ae"
},
{
"url": "https://git.kernel.org/stable/c/e36095d8d922bb26ce860231aacf0cd14edea07c"
},
{
"url": "https://git.kernel.org/stable/c/f636cf6a1e7b7f40d48d8d08bd5f152aa61dd130"
},
{
"url": "https://git.kernel.org/stable/c/4721f8160f17554b003e8928bb61e6c9b2fe92a3"
}
],
"title": "KVM: x86: hyper-v: Bound the bank index when querying sparse banks",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64247",
"datePublished": "2026-07-24T15:31:15.304Z",
"dateReserved": "2026-07-19T15:36:31.772Z",
"dateUpdated": "2026-08-17T04:51:58.515Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53154 (GCVE-0-2026-53154)
Vulnerability from cvelistv5
Published
2026-06-25 08:38
Modified
2026-06-25 08:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: restore reservation on error in hugetlb folio copy paths
Two sites in mm/hugetlb.c allocate a hugetlb folio via
alloc_hugetlb_folio() (consuming a VMA reservation) and then call
copy_user_large_folio(), which became int-returning in commit 1cb9dc4b475c
("mm: hwpoison: support recovery from HugePage copy-on-write faults") and
can now fail (e.g. -EHWPOISON on a hwpoisoned source page). On the
failure path, folio_put() restores the global hugetlb pool count through
free_huge_folio(), but the per-VMA reservation map entry is left marked
consumed:
- hugetlb_mfill_atomic_pte() resubmission path (UFFDIO_COPY)
- copy_hugetlb_page_range() fork-time CoW path when
hugetlb_try_dup_anon_rmap() fails (rare: pinned hugetlb anon
folio under fork)
User-visible effect: on UFFDIO_COPY into a private hugetlb VMA where the
resubmission copy fails, the reservation for that address is leaked from
the VMA's reserve map. A subsequent fault at the same address takes the
no-reservation path, and under hugetlb pool pressure the task is SIGBUSed
at an address it had previously reserved. The fork-time CoW path leaks
the same way in the child VMA's reserve map, though it requires the much
rarer combination of pinned hugetlb anon page + hwpoisoned source.
Add the missing restore_reserve_on_error() call before folio_put() on both
error paths.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/hugetlb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8d6e1dd3ad1340cd8b6d554b7aa93d8f0a1c6d38",
"status": "affected",
"version": "1cb9dc4b475c7418f925ab0c97b6750007d9f52e",
"versionType": "git"
},
{
"lessThan": "e47bf16af3c45470ea32f2241fa69aefe0dd61bd",
"status": "affected",
"version": "1cb9dc4b475c7418f925ab0c97b6750007d9f52e",
"versionType": "git"
},
{
"lessThan": "c72469ac0f274bde3f0df60a4584e14a123d0aa6",
"status": "affected",
"version": "1cb9dc4b475c7418f925ab0c97b6750007d9f52e",
"versionType": "git"
},
{
"lessThan": "45e33d43243d71d089af42f5077b8213cee6610f",
"status": "affected",
"version": "1cb9dc4b475c7418f925ab0c97b6750007d9f52e",
"versionType": "git"
},
{
"lessThan": "40c81856e622a9dc59294a90d169ac07ea25b0b0",
"status": "affected",
"version": "1cb9dc4b475c7418f925ab0c97b6750007d9f52e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/hugetlb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: restore reservation on error in hugetlb folio copy paths\n\nTwo sites in mm/hugetlb.c allocate a hugetlb folio via\nalloc_hugetlb_folio() (consuming a VMA reservation) and then call\ncopy_user_large_folio(), which became int-returning in commit 1cb9dc4b475c\n(\"mm: hwpoison: support recovery from HugePage copy-on-write faults\") and\ncan now fail (e.g. -EHWPOISON on a hwpoisoned source page). On the\nfailure path, folio_put() restores the global hugetlb pool count through\nfree_huge_folio(), but the per-VMA reservation map entry is left marked\nconsumed:\n\n - hugetlb_mfill_atomic_pte() resubmission path (UFFDIO_COPY)\n - copy_hugetlb_page_range() fork-time CoW path when\n hugetlb_try_dup_anon_rmap() fails (rare: pinned hugetlb anon\n folio under fork)\n\nUser-visible effect: on UFFDIO_COPY into a private hugetlb VMA where the\nresubmission copy fails, the reservation for that address is leaked from\nthe VMA\u0027s reserve map. A subsequent fault at the same address takes the\nno-reservation path, and under hugetlb pool pressure the task is SIGBUSed\nat an address it had previously reserved. The fork-time CoW path leaks\nthe same way in the child VMA\u0027s reserve map, though it requires the much\nrarer combination of pinned hugetlb anon page + hwpoisoned source.\n\nAdd the missing restore_reserve_on_error() call before folio_put() on both\nerror paths."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-25T08:38:38.168Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8d6e1dd3ad1340cd8b6d554b7aa93d8f0a1c6d38"
},
{
"url": "https://git.kernel.org/stable/c/e47bf16af3c45470ea32f2241fa69aefe0dd61bd"
},
{
"url": "https://git.kernel.org/stable/c/c72469ac0f274bde3f0df60a4584e14a123d0aa6"
},
{
"url": "https://git.kernel.org/stable/c/45e33d43243d71d089af42f5077b8213cee6610f"
},
{
"url": "https://git.kernel.org/stable/c/40c81856e622a9dc59294a90d169ac07ea25b0b0"
}
],
"title": "mm/hugetlb: restore reservation on error in hugetlb folio copy paths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53154",
"datePublished": "2026-06-25T08:38:38.168Z",
"dateReserved": "2026-06-09T07:44:35.388Z",
"dateUpdated": "2026-06-25T08:38:38.168Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68422 (GCVE-0-2026-68422)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
If we have an unexpected reloc_root for our root, we jump to the out label
but never drop the reference we obtained for root, resulting in a leak.
Add a missing btrfs_put_root() call.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f89df93e8aefa4c1c813f835559f2ac727f79766",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "3f586b4c92e4272fcd01bf0db0590b63acf3e85b",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "b3d39b03799600c76c33486e2d29b73a771023db",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "72f673d1c1deb819554d3e7e154f6d84301eb735",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "60a23d4ea169e27403f3bb023bb98036797c0206",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "7591d1727067d6063247901ad25c4bdc4e5695c4",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "ce6050bafb4e33377dc17fcc357736bfc351180c",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()\n\nIf we have an unexpected reloc_root for our root, we jump to the out label\nbut never drop the reference we obtained for root, resulting in a leak.\nAdd a missing btrfs_put_root() call."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:17.540Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f89df93e8aefa4c1c813f835559f2ac727f79766"
},
{
"url": "https://git.kernel.org/stable/c/3f586b4c92e4272fcd01bf0db0590b63acf3e85b"
},
{
"url": "https://git.kernel.org/stable/c/b3d39b03799600c76c33486e2d29b73a771023db"
},
{
"url": "https://git.kernel.org/stable/c/72f673d1c1deb819554d3e7e154f6d84301eb735"
},
{
"url": "https://git.kernel.org/stable/c/60a23d4ea169e27403f3bb023bb98036797c0206"
},
{
"url": "https://git.kernel.org/stable/c/7591d1727067d6063247901ad25c4bdc4e5695c4"
},
{
"url": "https://git.kernel.org/stable/c/ce6050bafb4e33377dc17fcc357736bfc351180c"
}
],
"title": "btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68422",
"datePublished": "2026-08-10T12:04:42.949Z",
"dateReserved": "2026-07-30T09:28:09.392Z",
"dateUpdated": "2026-08-19T16:35:17.540Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-44981 (GCVE-0-2024-44981)
Vulnerability from cvelistv5
Published
2024-09-04 19:54
Modified
2026-05-11 20:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
workqueue: Fix UBSAN 'subtraction overflow' error in shift_and_mask()
UBSAN reports the following 'subtraction overflow' error when booting
in a virtual machine on Android:
| Internal error: UBSAN: integer subtraction overflow: 00000000f2005515 [#1] PREEMPT SMP
| Modules linked in:
| CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.10.0-00006-g3cbe9e5abd46-dirty #4
| Hardware name: linux,dummy-virt (DT)
| pstate: 600000c5 (nZCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
| pc : cancel_delayed_work+0x34/0x44
| lr : cancel_delayed_work+0x2c/0x44
| sp : ffff80008002ba60
| x29: ffff80008002ba60 x28: 0000000000000000 x27: 0000000000000000
| x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000
| x23: 0000000000000000 x22: 0000000000000000 x21: ffff1f65014cd3c0
| x20: ffffc0e84c9d0da0 x19: ffffc0e84cab3558 x18: ffff800080009058
| x17: 00000000247ee1f8 x16: 00000000247ee1f8 x15: 00000000bdcb279d
| x14: 0000000000000001 x13: 0000000000000075 x12: 00000a0000000000
| x11: ffff1f6501499018 x10: 00984901651fffff x9 : ffff5e7cc35af000
| x8 : 0000000000000001 x7 : 3d4d455453595342 x6 : 000000004e514553
| x5 : ffff1f6501499265 x4 : ffff1f650ff60b10 x3 : 0000000000000620
| x2 : ffff80008002ba78 x1 : 0000000000000000 x0 : 0000000000000000
| Call trace:
| cancel_delayed_work+0x34/0x44
| deferred_probe_extend_timeout+0x20/0x70
| driver_register+0xa8/0x110
| __platform_driver_register+0x28/0x3c
| syscon_init+0x24/0x38
| do_one_initcall+0xe4/0x338
| do_initcall_level+0xac/0x178
| do_initcalls+0x5c/0xa0
| do_basic_setup+0x20/0x30
| kernel_init_freeable+0x8c/0xf8
| kernel_init+0x28/0x1b4
| ret_from_fork+0x10/0x20
| Code: f9000fbf 97fffa2f 39400268 37100048 (d42aa2a0)
| ---[ end trace 0000000000000000 ]---
| Kernel panic - not syncing: UBSAN: integer subtraction overflow: Fatal exception
This is due to shift_and_mask() using a signed immediate to construct
the mask and being called with a shift of 31 (WORK_OFFQ_POOL_SHIFT) so
that it ends up decrementing from INT_MIN.
Use an unsigned constant '1U' to generate the mask in shift_and_mask().
References
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-44981",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-10T15:18:14.996929Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-12T17:33:17.087Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/workqueue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "90a6a844b2d9927d192758438a4ada33d8cd9de5",
"status": "affected",
"version": "1211f3b21c2aa0d22d8d7f050e3a5930a91cd0e4",
"versionType": "git"
},
{
"lessThan": "38f7e14519d39cf524ddc02d4caee9b337dad703",
"status": "affected",
"version": "1211f3b21c2aa0d22d8d7f050e3a5930a91cd0e4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/workqueue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"lessThan": "6.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.10.*",
"status": "unaffected",
"version": "6.10.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.11",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.10.7",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.11",
"versionStartIncluding": "6.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nworkqueue: Fix UBSAN \u0027subtraction overflow\u0027 error in shift_and_mask()\n\nUBSAN reports the following \u0027subtraction overflow\u0027 error when booting\nin a virtual machine on Android:\n\n | Internal error: UBSAN: integer subtraction overflow: 00000000f2005515 [#1] PREEMPT SMP\n | Modules linked in:\n | CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.10.0-00006-g3cbe9e5abd46-dirty #4\n | Hardware name: linux,dummy-virt (DT)\n | pstate: 600000c5 (nZCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n | pc : cancel_delayed_work+0x34/0x44\n | lr : cancel_delayed_work+0x2c/0x44\n | sp : ffff80008002ba60\n | x29: ffff80008002ba60 x28: 0000000000000000 x27: 0000000000000000\n | x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000\n | x23: 0000000000000000 x22: 0000000000000000 x21: ffff1f65014cd3c0\n | x20: ffffc0e84c9d0da0 x19: ffffc0e84cab3558 x18: ffff800080009058\n | x17: 00000000247ee1f8 x16: 00000000247ee1f8 x15: 00000000bdcb279d\n | x14: 0000000000000001 x13: 0000000000000075 x12: 00000a0000000000\n | x11: ffff1f6501499018 x10: 00984901651fffff x9 : ffff5e7cc35af000\n | x8 : 0000000000000001 x7 : 3d4d455453595342 x6 : 000000004e514553\n | x5 : ffff1f6501499265 x4 : ffff1f650ff60b10 x3 : 0000000000000620\n | x2 : ffff80008002ba78 x1 : 0000000000000000 x0 : 0000000000000000\n | Call trace:\n | cancel_delayed_work+0x34/0x44\n | deferred_probe_extend_timeout+0x20/0x70\n | driver_register+0xa8/0x110\n | __platform_driver_register+0x28/0x3c\n | syscon_init+0x24/0x38\n | do_one_initcall+0xe4/0x338\n | do_initcall_level+0xac/0x178\n | do_initcalls+0x5c/0xa0\n | do_basic_setup+0x20/0x30\n | kernel_init_freeable+0x8c/0xf8\n | kernel_init+0x28/0x1b4\n | ret_from_fork+0x10/0x20\n | Code: f9000fbf 97fffa2f 39400268 37100048 (d42aa2a0)\n | ---[ end trace 0000000000000000 ]---\n | Kernel panic - not syncing: UBSAN: integer subtraction overflow: Fatal exception\n\nThis is due to shift_and_mask() using a signed immediate to construct\nthe mask and being called with a shift of 31 (WORK_OFFQ_POOL_SHIFT) so\nthat it ends up decrementing from INT_MIN.\n\nUse an unsigned constant \u00271U\u0027 to generate the mask in shift_and_mask()."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T20:33:09.567Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/90a6a844b2d9927d192758438a4ada33d8cd9de5"
},
{
"url": "https://git.kernel.org/stable/c/38f7e14519d39cf524ddc02d4caee9b337dad703"
}
],
"title": "workqueue: Fix UBSAN \u0027subtraction overflow\u0027 error in shift_and_mask()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2024-44981",
"datePublished": "2024-09-04T19:54:31.505Z",
"dateReserved": "2024-08-21T05:34:56.670Z",
"dateUpdated": "2026-05-11T20:33:09.567Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68222 (GCVE-0-2026-68222)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: msi2500: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
msi2500_start_streaming() had five error paths that all hit this trap
and were further tangled by ret-overwriting between calls:
- -ENODEV when the USB device was already disconnected
- -ERESTARTSYS when mutex_lock_interruptible() was interrupted
- msi2500_set_usb_adc() failure: ret was silently overwritten by
the next call (msi2500_isoc_init), so the error was lost entirely
- msi2500_isoc_init() failure: cleanup_queued_bufs was called, but
the function then fell through to msi2500_ctrl_msg() and again
masked the original error by overwriting ret
- msi2500_ctrl_msg(CMD_START_STREAMING) failure: no cleanup at all,
leaving isoc URBs submitted with no way for the driver to consume
them
Consolidate the error paths into a small goto chain. Every failure
now stops the function, drains the queued-buffer list, and returns
the real error code. The ctrl_msg failure path also rolls back the
preceding msi2500_isoc_init() via msi2500_isoc_cleanup() before
unlocking and draining.
The cleanup helper takes a vb2_buffer_state argument so that the
start_streaming error paths can pass VB2_BUF_STATE_QUEUED (as
expected by userspace on start_streaming failure) while stop_streaming
keeps its existing VB2_BUF_STATE_ERROR semantics.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/msi2500/msi2500.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c74b680704baecea4620c0774de473069e0bc4e8",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "2d10eedb786a13f91d76e11320fabb0bf712519f",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "2de14ddb4fea04ca616403a6ba81c5e8099e9b9e",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "1d58229b330b7f67fbfa07e0f2a8a51fbeafaa9a",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "bab9d5a67d4db96ae8c187b92b37979911302a10",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "264b5380c4f8aa92dbc2983ecd2b627f1d5e0061",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "3673cb0a5711e910074d69201da9e1535c03f97a",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "7201c17786a498497bca57752883b90914d405ac",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/msi2500/msi2500.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"lessThan": "3.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: msi2500: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nmsi2500_start_streaming() had five error paths that all hit this trap\nand were further tangled by ret-overwriting between calls:\n\n - -ENODEV when the USB device was already disconnected\n - -ERESTARTSYS when mutex_lock_interruptible() was interrupted\n - msi2500_set_usb_adc() failure: ret was silently overwritten by\n the next call (msi2500_isoc_init), so the error was lost entirely\n - msi2500_isoc_init() failure: cleanup_queued_bufs was called, but\n the function then fell through to msi2500_ctrl_msg() and again\n masked the original error by overwriting ret\n - msi2500_ctrl_msg(CMD_START_STREAMING) failure: no cleanup at all,\n leaving isoc URBs submitted with no way for the driver to consume\n them\n\nConsolidate the error paths into a small goto chain. Every failure\nnow stops the function, drains the queued-buffer list, and returns\nthe real error code. The ctrl_msg failure path also rolls back the\npreceding msi2500_isoc_init() via msi2500_isoc_cleanup() before\nunlocking and draining.\n\nThe cleanup helper takes a vb2_buffer_state argument so that the\nstart_streaming error paths can pass VB2_BUF_STATE_QUEUED (as\nexpected by userspace on start_streaming failure) while stop_streaming\nkeeps its existing VB2_BUF_STATE_ERROR semantics.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through a local VIDIOC_STREAMON ioctl on the msi2500 SDR character device /dev/swradioN; no network or remote input is involved, and the failure paths are driven from a local process\u0027s syscalls.\nAC:L - The attacker controls both sides of the trigger: hold dev-\u003ev4l2_lock from a second thread and send a signal to the STREAMON thread so mutex_lock_interruptible() returns -ERESTARTSYS, hitting the leaking error path deterministically and repeatably.\nPR:L - Only an unprivileged local user with access to the V4L2/SDR device node is needed; on desktop, Android and embedded systems these nodes are granted to the logged-in seat or a device group, and no capability check guards STREAMON.\nUI:N - The whole sequence (REQBUFS, QBUF, STREAMON, signal, repeat) is performed by the attacker\u0027s own process; no victim action such as plugging in hardware or opening a file is required.\nS:U - The corruption is confined to kernel memory managed by the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Buffers left on dev-\u003equeued_bufs after the vb2 core reclaims and later frees them become dangling pointers reused by cleanup_queued_bufs()/get_next_fill_buf(), giving a use-after-free that can be groomed to read reclaimed kernel heap contents back into userspace buffers.\nI:H - The stale list entries permit list_add_tail() on an already-linked node (list corruption) and vb2_buffer_done()/isoc-handler writes into freed objects, yielding attacker-influenced kernel heap writes exploitable for control-flow hijacking.\nA:H - At minimum the missing buffer return trips WARN_ON(owned_by_drv_count) (fatal with panic_on_warn) and leaks buffers; the resulting list corruption and use-after-free reliably oops or hang the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:51.745Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c74b680704baecea4620c0774de473069e0bc4e8"
},
{
"url": "https://git.kernel.org/stable/c/2d10eedb786a13f91d76e11320fabb0bf712519f"
},
{
"url": "https://git.kernel.org/stable/c/2de14ddb4fea04ca616403a6ba81c5e8099e9b9e"
},
{
"url": "https://git.kernel.org/stable/c/1d58229b330b7f67fbfa07e0f2a8a51fbeafaa9a"
},
{
"url": "https://git.kernel.org/stable/c/bab9d5a67d4db96ae8c187b92b37979911302a10"
},
{
"url": "https://git.kernel.org/stable/c/264b5380c4f8aa92dbc2983ecd2b627f1d5e0061"
},
{
"url": "https://git.kernel.org/stable/c/3673cb0a5711e910074d69201da9e1535c03f97a"
},
{
"url": "https://git.kernel.org/stable/c/7201c17786a498497bca57752883b90914d405ac"
}
],
"title": "media: msi2500: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68222",
"datePublished": "2026-08-10T12:00:42.687Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:51.745Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68244 (GCVE-0-2026-68244)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Do not leak siblings[] on proto context error
After a successful BALANCE/PARALLEL_SUBMIT extension on context
creation, error during processing of next user extension leaks
the siblings[] array. Fix that.
Discovered using AI-assisted static analysis confirmed by
Intel Product Security.
(cherry picked from commit aa65e0a4b51b3b54b53e4142aaa2d997aa1061ff)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "60b7d701ffae0c3a69e838f984cc80d8ca929f5d",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "e600672f11a1d9215f5432ca58f0b9823917a292",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "f014702fbd48d06a3d7a06e4bb4075d406376cf0",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "8431a4d7ff95c7f9c6fb1dbbbc9cdadf29d4f6d5",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "37951ce1567ccf8c86c7a1b8fb7d55a32c821b87",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "6cdbef8f60f313684e641628d64aa85960080d3f",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "eed3de2acf6aa5154d49098b026710b646db67ee",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Do not leak siblings[] on proto context error\n\nAfter a successful BALANCE/PARALLEL_SUBMIT extension on context\ncreation, error during processing of next user extension leaks\nthe siblings[] array. Fix that.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit aa65e0a4b51b3b54b53e4142aaa2d997aa1061ff)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:11.063Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/60b7d701ffae0c3a69e838f984cc80d8ca929f5d"
},
{
"url": "https://git.kernel.org/stable/c/e600672f11a1d9215f5432ca58f0b9823917a292"
},
{
"url": "https://git.kernel.org/stable/c/f014702fbd48d06a3d7a06e4bb4075d406376cf0"
},
{
"url": "https://git.kernel.org/stable/c/8431a4d7ff95c7f9c6fb1dbbbc9cdadf29d4f6d5"
},
{
"url": "https://git.kernel.org/stable/c/37951ce1567ccf8c86c7a1b8fb7d55a32c821b87"
},
{
"url": "https://git.kernel.org/stable/c/6cdbef8f60f313684e641628d64aa85960080d3f"
},
{
"url": "https://git.kernel.org/stable/c/eed3de2acf6aa5154d49098b026710b646db67ee"
}
],
"title": "drm/i915/gem: Do not leak siblings[] on proto context error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68244",
"datePublished": "2026-08-10T12:01:10.469Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:11.063Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64536 (GCVE-0-2026-64536)
Vulnerability from cvelistv5
Published
2026-07-27 06:36
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop
The loop in is_ap_in_tkip() iterates over IEs without verifying that
enough bytes remain before dereferencing the IE header or its payload:
- pIE->element_id and pIE->length are read without checking that
i + sizeof(*pIE) <= ie_length, so a truncated IE at the end of the
buffer causes an OOB read.
- For WLAN_EID_VENDOR_SPECIFIC the code compares pIE->data + 12,
which requires pIE->length >= 16. For WLAN_EID_RSN it compares
pIE->data + 8, requiring pIE->length >= 12. Neither requirement
is checked.
Add the missing IE header and payload bounds checks and guard each
data access with an explicit pIE->length minimum, matching the
pattern established in update_beacon_info().
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_wlan_util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ea3809f7e20bdff282b8cc1e94937d5fb9fb32c7",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "d2055332297e24c63fffda943ef7a5eefc0a6019",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "6f26cc55affd9d7f88ae2f5d12db4ecf9072c209",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "204b22c8df115370037248859bf0fa62db73a396",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "a6105ea8ca6ebbc04beaf3bcbf7dbb5985f5d395",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "4380b3860d887a13555ff024a58dfc05b490dfd6",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "3bf39f711ff27c64be8680a8938bcc5001982e81",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_wlan_util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop\n\nThe loop in is_ap_in_tkip() iterates over IEs without verifying that\nenough bytes remain before dereferencing the IE header or its payload:\n\n- pIE-\u003eelement_id and pIE-\u003elength are read without checking that\n i + sizeof(*pIE) \u003c= ie_length, so a truncated IE at the end of the\n buffer causes an OOB read.\n\n- For WLAN_EID_VENDOR_SPECIFIC the code compares pIE-\u003edata + 12,\n which requires pIE-\u003elength \u003e= 16. For WLAN_EID_RSN it compares\n pIE-\u003edata + 8, requiring pIE-\u003elength \u003e= 12. Neither requirement\n is checked.\n\nAdd the missing IE header and payload bounds checks and guard each\ndata access with an explicit pIE-\u003elength minimum, matching the\npattern established in update_beacon_info()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - A nearby malicious WiFi access point can supply crafted beacon or probe-response IEs that reach the vulnerable association path over the air.\nAC:L - The attacker directly controls the malformed IE lengths and contents, and exploitation requires neither a race nor conditions outside the attacker\u0027s control.\nPR:N - The vulnerable code executes before WPA credentials are verified; transmitting management frames as a malicious or spoofed AP requires no privileges on the target.\nUI:N - An attacker impersonating a configured AP can trigger the path during automatic connection or reconnection without contemporaneous user action.\nS:U - The vulnerable driver and affected kernel resources belong to the same host security authority, with no demonstrated VM, sandbox, or IOMMU boundary crossing.\nC:H - The unchecked IE-header and fixed-offset comparisons read beyond attacker-declared buffer boundaries into adjacent kernel memory; under the required conservative OOB-read rule, confidentiality impact is high.\nI:N - The flaw performs reads and comparisons only, with no memory write or demonstrated data-modification primitive.\nA:H - Malformed IEs can cause kernel out-of-bounds accesses during association and potentially fault or oops the kernel; a nearby attacker can repeat the exchange."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:12.274Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ea3809f7e20bdff282b8cc1e94937d5fb9fb32c7"
},
{
"url": "https://git.kernel.org/stable/c/d2055332297e24c63fffda943ef7a5eefc0a6019"
},
{
"url": "https://git.kernel.org/stable/c/6f26cc55affd9d7f88ae2f5d12db4ecf9072c209"
},
{
"url": "https://git.kernel.org/stable/c/204b22c8df115370037248859bf0fa62db73a396"
},
{
"url": "https://git.kernel.org/stable/c/a6105ea8ca6ebbc04beaf3bcbf7dbb5985f5d395"
},
{
"url": "https://git.kernel.org/stable/c/4380b3860d887a13555ff024a58dfc05b490dfd6"
},
{
"url": "https://git.kernel.org/stable/c/3bf39f711ff27c64be8680a8938bcc5001982e81"
}
],
"title": "staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64536",
"datePublished": "2026-07-27T06:36:04.736Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:12.274Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63937 (GCVE-0-2026-63937)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer
Use READ_ONCE() when reading entries/indices from the guest-accessible
Page State Change buffer to defend against TOCTOU bugs.
Don't bother with READ_ONCE()/WRITE_ONCE() for cases where KVM is writing
(and not consuming the result!), as the guest isn't supposed to touch the
buffer while it's being processed. I.e. using READ_ONCE() is all about
protecting against misbehaving guests.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/sev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bd232801ef1d1fd985d2d4ca3cd1d888303ca86f",
"status": "affected",
"version": "9b54e248d2644be71cb394eb85f31ad99e023a05",
"versionType": "git"
},
{
"lessThan": "b1dfaa6f7a957726a6800135be3659fbe4bbf2a4",
"status": "affected",
"version": "9b54e248d2644be71cb394eb85f31ad99e023a05",
"versionType": "git"
},
{
"lessThan": "edbbe88f83b524434974e84808d3093199d67c24",
"status": "affected",
"version": "9b54e248d2644be71cb394eb85f31ad99e023a05",
"versionType": "git"
},
{
"lessThan": "c8cc238093ca6c99267032f6cfe78f59389f3157",
"status": "affected",
"version": "9b54e248d2644be71cb394eb85f31ad99e023a05",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/sev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer\n\nUse READ_ONCE() when reading entries/indices from the guest-accessible\nPage State Change buffer to defend against TOCTOU bugs.\n\nDon\u0027t bother with READ_ONCE()/WRITE_ONCE() for cases where KVM is writing\n(and not consuming the result!), as the guest isn\u0027t supposed to touch the\nbuffer while it\u0027s being processed. I.e. using READ_ONCE() is all about\nprotecting against misbehaving guests."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires code execution inside an SEV-SNP guest that issues VMGEXIT PSC events into the host KVM hypervisor; this is local access to the host kernel via a guest-controlled hypercall path, not a remote network protocol.\nAC:L - The attacker fully controls the guest-accessible PSC buffer and can trigger concurrent VMGEXITs or use multiple vCPUs to modify indices/entries between KVM\u0027s validation read and later use, reliably winning the TOCTOU race without depending on uncontrollable host conditions.\nPR:L - The attacker only needs the ability to run code in an SEV-SNP guest on a KVM host (e.g., a cloud confidential-computing tenant), not real root or capabilities in the host\u0027s init namespace.\nUI:N - No victim interaction is required beyond the attacker operating their own malicious guest workload; PSC VMGEXITs are triggered programmatically from guest code.\nS:C - The vulnerable code runs in the host hypervisor but is reached from an untrusted guest; successful exploitation crosses the VM security boundary and can alter host-managed SEV-SNP page-state (RMP) for guest physical addresses.\nC:H - TOCTOU manipulation of PSC entries/indices can bypass validation and drive KVM_HC_MAP_GPA_RANGE on unvalidated GPA ranges, potentially flipping pages between private and shared and disclosing encrypted guest (or host-visible) memory beyond what was checked.\nI:H - The same TOCTOU allows inflating combined page ranges and operations passed to userspace, enabling unauthorized modification of page encryption attributes and corrupting hypervisor-managed memory state via misdirected MAP_GPA_RANGE processing.\nA:H - Incorrect indices and out-of-sync buffer state can cause invalid hypervisor processing, kernel warnings/panics, or repeated disruption of the host\u0027s KVM/SEV-SNP path; memory-corruption-class TOCTOU bugs are scored at full availability impact when exploitability is uncertain."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:24.499Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bd232801ef1d1fd985d2d4ca3cd1d888303ca86f"
},
{
"url": "https://git.kernel.org/stable/c/b1dfaa6f7a957726a6800135be3659fbe4bbf2a4"
},
{
"url": "https://git.kernel.org/stable/c/edbbe88f83b524434974e84808d3093199d67c24"
},
{
"url": "https://git.kernel.org/stable/c/c8cc238093ca6c99267032f6cfe78f59389f3157"
}
],
"title": "KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63937",
"datePublished": "2026-07-19T14:55:34.554Z",
"dateReserved": "2026-07-19T07:54:57.022Z",
"dateUpdated": "2026-08-05T12:37:24.499Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68253 (GCVE-0-2026-68253)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/hdcp: check streams[] bounds before overflow
The data->streams[] overflow check is done after the buffer overflow has
already happened. Move the overflow check before the write.
Side note, emitting a warning splat with a backtrace might be overkill
here, but prefer not changing the behaviour other than not doing the
overrun.
Discovered using AI-assisted static analysis confirmed by Intel Product
Security.
(cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_hdcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "336cf6d80d41457442b659e7ba7a7badc0ffe79d",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "389079bf04e6f0c6f10f5b879f6d7a9cf80f0567",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "84351f12390349ba010920fc247e1a0b12e41eb3",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "2106fb490b2c6003e23ad6ff36ce823a2170e138",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "3d2ef8d389495e7889c6062d8bddc46d2a5fbdef",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "984085c5b53572e2e03fd5fc4817e86ef1effc6e",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "bbb15a6b042d02e5508a02b4847e02d2579ee7bc",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_hdcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hdcp: check streams[] bounds before overflow\n\nThe data-\u003estreams[] overflow check is done after the buffer overflow has\nalready happened. Move the overflow check before the write.\n\nSide note, emitting a warning splat with a backtrace might be overkill\nhere, but prefer not changing the behaviour other than not doing the\noverrun.\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\n(cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The overflow is reached through a local DRM atomic modeset ioctl on /dev/dri/cardN that sets the \"Content Protection\" connector property, driving intel_hdcp_enable() -\u003e intel_hdcp_prepare_streams(); no network or remote path exists to the i915 display HDCP code.\nAC:L - Any DP MST topology with more connected MST connectors on one digital port than the device has pipes (a common dock/hub/daisy-chain setup, and easily arranged by anyone with access to the machine\u0027s display outputs) makes every HDCP enable request overflow the buffer deterministically, with no race or memory-layout condition to win.\nPR:L - The attacker only needs access to the DRM device node as DRM master, which an ordinary user in a local graphical session (video/render group, logind seat) has; no CAP_SYS_ADMIN or root is required to request HDCP content protection on an MST connector.\nUI:N - The attacker performs the atomic commit that requests content protection themselves; no action by another user is needed, and on a system already running a compositor with HDCP desired the overflow occurs automatically on the modeset.\nS:U - The corruption is confined to kernel heap memory within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The out-of-bounds write corrupts adjacent objects in a small kmalloc slab, and such heap corruption is a standard primitive for pivoting to arbitrary kernel memory disclosure by overwriting neighbouring pointers or length fields.\nI:H - This is a heap out-of-bounds write past a kzalloc\u0027d streams[] buffer sized to INTEL_NUM_PIPES, with attacker-influenced VCPI values and an attacker-controlled overflow length determined by the MST topology, giving corruption of adjacent slab objects that can be leveraged for control-flow hijack.\nA:H - Overwriting adjacent slab allocations reliably produces slab corruption, oops, or panic, and the path can be re-triggered on every HDCP enable/modeset, so the system can be crashed repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:11.002Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/336cf6d80d41457442b659e7ba7a7badc0ffe79d"
},
{
"url": "https://git.kernel.org/stable/c/389079bf04e6f0c6f10f5b879f6d7a9cf80f0567"
},
{
"url": "https://git.kernel.org/stable/c/84351f12390349ba010920fc247e1a0b12e41eb3"
},
{
"url": "https://git.kernel.org/stable/c/2106fb490b2c6003e23ad6ff36ce823a2170e138"
},
{
"url": "https://git.kernel.org/stable/c/3d2ef8d389495e7889c6062d8bddc46d2a5fbdef"
},
{
"url": "https://git.kernel.org/stable/c/984085c5b53572e2e03fd5fc4817e86ef1effc6e"
},
{
"url": "https://git.kernel.org/stable/c/bbb15a6b042d02e5508a02b4847e02d2579ee7bc"
}
],
"title": "drm/i915/hdcp: check streams[] bounds before overflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68253",
"datePublished": "2026-08-10T12:01:19.402Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-23T12:46:11.002Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68195 (GCVE-0-2026-68195)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and
mt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free() on every bus.
mt7615_mac_tx_free() cleans the DMA tx queues with
mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the
mmio queue ops implement that callback; on the mt7663 USB and SDIO
buses it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX
worker. Same defect as the mt7921 and mt7925 patches in this series.
Drop the event on non-mmio buses via mt76_is_mmio(), as in
commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for
non-mmio devices").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7615/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "664f8bbc61e45e062679da512bf12f8f6fb26a1b",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "1a099d630b8667fa622662b85e35a0ef659fb343",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "a0b3e8d8726c3830102a18946c766c94c953c7f2",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "88c98ef247a3126fea9bbbda953a18a2f36c3ea7",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "ab4d213393e846baa6437497f94dda7553cbeda7",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "b2ab73b8123ce6cf2bc32634bfee4928676ffa66",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "39afc46c0243d10b7795e6e6cf4ae91f41732120",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7615/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses\n\nPKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and\nmt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free() on every bus.\nmt7615_mac_tx_free() cleans the DMA tx queues with\nmt76_queue_tx_cleanup(), which calls queue_ops-\u003etx_cleanup(). Only the\nmmio queue ops implement that callback; on the mt7663 USB and SDIO\nbuses it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX\nworker. Same defect as the mt7921 and mt7925 patches in this series.\n\nDrop the event on non-mmio buses via mt76_is_mmio(), as in\ncommit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for\nnon-mmio devices\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:11.475Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/664f8bbc61e45e062679da512bf12f8f6fb26a1b"
},
{
"url": "https://git.kernel.org/stable/c/1a099d630b8667fa622662b85e35a0ef659fb343"
},
{
"url": "https://git.kernel.org/stable/c/a0b3e8d8726c3830102a18946c766c94c953c7f2"
},
{
"url": "https://git.kernel.org/stable/c/f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5"
},
{
"url": "https://git.kernel.org/stable/c/88c98ef247a3126fea9bbbda953a18a2f36c3ea7"
},
{
"url": "https://git.kernel.org/stable/c/ab4d213393e846baa6437497f94dda7553cbeda7"
},
{
"url": "https://git.kernel.org/stable/c/b2ab73b8123ce6cf2bc32634bfee4928676ffa66"
},
{
"url": "https://git.kernel.org/stable/c/39afc46c0243d10b7795e6e6cf4ae91f41732120"
}
],
"title": "wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68195",
"datePublished": "2026-08-10T12:00:13.627Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:11.475Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-23137 (GCVE-0-2025-23137)
Vulnerability from cvelistv5
Published
2025-04-16 14:13
Modified
2026-05-11 21:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update
Check if policy is NULL before dereferencing it in amd_pstate_update.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/cpufreq/amd-pstate.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "82b6dfff0d6000b14b271f74e43d672d81fb390e",
"status": "affected",
"version": "e8f555daacd3377bf691fdda2490c0b164e00085",
"versionType": "git"
},
{
"lessThan": "b99c1c63d88c75a4dc5487c3696cda38697b8d35",
"status": "affected",
"version": "e8f555daacd3377bf691fdda2490c0b164e00085",
"versionType": "git"
},
{
"lessThan": "426db24d4db2e4f0d6720aeb7795eafcb9e82640",
"status": "affected",
"version": "e8f555daacd3377bf691fdda2490c0b164e00085",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/cpufreq/amd-pstate.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.14.*",
"status": "unaffected",
"version": "6.14.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.15",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.35",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.14.2",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update\n\nCheck if policy is NULL before dereferencing it in amd_pstate_update."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T21:13:40.994Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/82b6dfff0d6000b14b271f74e43d672d81fb390e"
},
{
"url": "https://git.kernel.org/stable/c/b99c1c63d88c75a4dc5487c3696cda38697b8d35"
},
{
"url": "https://git.kernel.org/stable/c/426db24d4db2e4f0d6720aeb7795eafcb9e82640"
}
],
"title": "cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-23137",
"datePublished": "2025-04-16T14:13:17.061Z",
"dateReserved": "2025-01-11T14:28:41.511Z",
"dateUpdated": "2026-05-11T21:13:40.994Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53365 (GCVE-0-2026-53365)
Vulnerability from cvelistv5
Published
2026-07-13 17:33
Modified
2026-08-18 13:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: fix zerocopy completion for multi-skb sends
When a large message is fragmented into multiple skbs, the zerocopy
uarg is only allocated and attached to the last skb in the loop.
Non-final skbs carry pinned user pages with no completion tracking,
so the kernel has no way to notify userspace when those pages are safe
to reuse. If the loop breaks early the uarg is never allocated at all,
leaking pinned pages with no completion notification.
Fix this by following the approach used by TCP: allocate the zerocopy
uarg (if not provided by the caller) before the send loop and attach
it to every skb via skb_zcopy_set(), which takes a reference per skb.
Each skb's completion properly decrements the refcount, and the
notification only fires after the last skb is freed.
On failure, if no data was sent, the uarg is cleanly aborted via
net_zcopy_put_abort().
This issue was initially discovered by sashiko while reviewing commit
1cb36e252211 ("vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting")
but was pre-existing.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-53365",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T03:55:24.397803Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "CWE-404 Improper Resource Shutdown or Release",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T13:29:37.454Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/MaherAzzouzi/vsockdrop"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/virtio_transport_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "293fe8f2d1b5ac464ca16a8eba09571bbbb34ba9",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
},
{
"lessThan": "76b995bc57bd90cb6e954e1966fbd8786da47f0d",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
},
{
"lessThan": "b3155f2b78db21e99256bcf7eb902f24ff6d5338",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
},
{
"lessThan": "ae38d9179190a956e2a87a69ef1dd6f451b51c4d",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/virtio_transport_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: fix zerocopy completion for multi-skb sends\n\nWhen a large message is fragmented into multiple skbs, the zerocopy\nuarg is only allocated and attached to the last skb in the loop.\nNon-final skbs carry pinned user pages with no completion tracking,\nso the kernel has no way to notify userspace when those pages are safe\nto reuse. If the loop breaks early the uarg is never allocated at all,\nleaking pinned pages with no completion notification.\n\nFix this by following the approach used by TCP: allocate the zerocopy\nuarg (if not provided by the caller) before the send loop and attach\nit to every skb via skb_zcopy_set(), which takes a reference per skb.\nEach skb\u0027s completion properly decrements the refcount, and the\nnotification only fires after the last skb is freed.\nOn failure, if no data was sent, the uarg is cleanly aborted via\nnet_zcopy_put_abort().\n\nThis issue was initially discovered by sashiko while reviewing commit\n1cb36e252211 (\"vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting\")\nbut was pre-existing."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-24T14:33:53.406Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/293fe8f2d1b5ac464ca16a8eba09571bbbb34ba9"
},
{
"url": "https://git.kernel.org/stable/c/76b995bc57bd90cb6e954e1966fbd8786da47f0d"
},
{
"url": "https://git.kernel.org/stable/c/b3155f2b78db21e99256bcf7eb902f24ff6d5338"
},
{
"url": "https://git.kernel.org/stable/c/ae38d9179190a956e2a87a69ef1dd6f451b51c4d"
}
],
"title": "vsock/virtio: fix zerocopy completion for multi-skb sends",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53365",
"datePublished": "2026-07-13T17:33:52.863Z",
"dateReserved": "2026-06-09T07:44:35.400Z",
"dateUpdated": "2026-08-18T13:29:37.454Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63972 (GCVE-0-2026-63972)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Skip redundant detach on already-detached port
When mana_per_port_queue_reset_work_handler() runs after a previous
detach succeeded but attach failed, the port is left in a detached
state with apc->tx_qp and apc->rxqs already freed. Calling
mana_detach() again unconditionally leads to NULL pointer dereferences
during queue teardown.
Add an early exit in mana_detach() when the port is already in
detached state (!netif_device_present) for non-close callers, making
it safe to call idempotently. This allows the queue reset handler and
other recovery paths to simply retry mana_attach() without redundant
teardown.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/mana_en.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c4152b4e28b3e550ec99351bf900e2c24c2608cc",
"status": "affected",
"version": "fb9f98e1041a30dd5766620a2a64cb472b54caa9",
"versionType": "git"
},
{
"lessThan": "7ae590797f9b5c240aaea5773f5f00977a42a846",
"status": "affected",
"version": "3b194343c25084a8d2fa0c0f2c9e80f3080fd732",
"versionType": "git"
},
{
"lessThan": "5b05aa36ee24297d7296ca58dfd8c448d0e4cda3",
"status": "affected",
"version": "3b194343c25084a8d2fa0c0f2c9e80f3080fd732",
"versionType": "git"
},
{
"lessThan": "6.18.35",
"status": "affected",
"version": "6.18.33",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/mana_en.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.0"
},
{
"lessThan": "7.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.18.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Skip redundant detach on already-detached port\n\nWhen mana_per_port_queue_reset_work_handler() runs after a previous\ndetach succeeded but attach failed, the port is left in a detached\nstate with apc-\u003etx_qp and apc-\u003erxqs already freed. Calling\nmana_detach() again unconditionally leads to NULL pointer dereferences\nduring queue teardown.\n\nAdd an early exit in mana_detach() when the port is already in\ndetached state (!netif_device_present) for non-close callers, making\nit safe to call idempotently. This allows the queue reset handler and\nother recovery paths to simply retry mana_attach() without redundant\nteardown."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The primary path is mana_tx_timeout() on Azure MANA NICs, triggered by the netdev TX watchdog when queues stall; remote peers on internet-facing VMs can induce TX stalls that schedule the vulnerable mana_detach() recovery workqueue.\nAC:L - An attacker can repeatedly provoke TX watchdog timeouts and control retry timing; while attach failure between cycles may need memory pressure, remote connection floods can contribute and the attacker controls both sides of the reset race.\nPR:N - The TX-timeout recovery path requires no local VM privileges\u2014only network reachability to influence the victim\u0027s MANA interface TX queue behavior and trigger automated driver recovery.\nUI:N - Exploitation is fully automated through the kernel netdev watchdog timer and workqueue handler with no victim user interaction required.\nS:U - Impact is a kernel panic within the same Azure VM guest; the MANA driver runs in guest context and does not cross a VM/host security boundary.\nC:N - The bug is a NULL pointer dereference during redundant queue teardown on already-freed pointers, causing a crash with no information disclosure primitive.\nI:N - There is no data modification or exploitable write primitive; the failure mode is dereferencing NULL tx_qp/rxqs pointers during teardown.\nA:H - The NULL pointer dereference in mana_detach()/mana_dealloc_queues() causes a kernel oops/panic, fully disrupting VM availability on affected Azure instances."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:43.858Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c4152b4e28b3e550ec99351bf900e2c24c2608cc"
},
{
"url": "https://git.kernel.org/stable/c/7ae590797f9b5c240aaea5773f5f00977a42a846"
},
{
"url": "https://git.kernel.org/stable/c/5b05aa36ee24297d7296ca58dfd8c448d0e4cda3"
}
],
"title": "net: mana: Skip redundant detach on already-detached port",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63972",
"datePublished": "2026-07-19T14:55:58.503Z",
"dateReserved": "2026-07-19T07:54:57.024Z",
"dateUpdated": "2026-08-05T12:37:43.858Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72496 (GCVE-0-2026-72496)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Proper rollback if the ioremap fails
bnxt_qplib_alloc_dpi returns success even if ioremap fails.
Add the proper rollback when the ioremap fails and return
-ENOMEM status.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/qplib_res.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "303f6fef95df5e5316970746d861cf6daeeca77f",
"status": "affected",
"version": "0ac20faf5d837b59fb4c041ea320932ed47fd67f",
"versionType": "git"
},
{
"lessThan": "87267803a8c824616eb147c5dad7030a5db6f878",
"status": "affected",
"version": "0ac20faf5d837b59fb4c041ea320932ed47fd67f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/qplib_res.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Proper rollback if the ioremap fails\n\nbnxt_qplib_alloc_dpi returns success even if ioremap fails.\nAdd the proper rollback when the ioremap fails and return\n-ENOMEM status."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only through local RDMA uverbs ioctl/write on /dev/infiniband/uverbs* (ibv_alloc_pd and BNXT_RE_ALLOC_WC_PAGE call bnxt_qplib_alloc_dpi); remote RoCE packet handling and in-kernel RDMA target/server paths never invoke this DPI setup routine.\nAC:L - An attacker can induce vmalloc/ioremap failure with local memory pressure, then repeatedly invoke alloc_pd or WC-page allocation; each call deterministically leaves a consumed DPI with NULL dbr, and subsequent create_cq/QP/SRQ doorbell rings fault without races or uncontrollable layout.\nPR:N - ib_uverbs creates per-device character nodes as mode 0666, so any local process can open uverbs, allocate a context, and call alloc_pd or alloc_page without CAP_SYS_ADMIN, init-namespace root, or other elevated capabilities on typical HPC/cloud RDMA hosts.\nUI:N - Exploitation requires only the attacker\u0027s own RDMA verbs sequence (alloc_context, alloc_pd or alloc_page, then create_cq/QP/SRQ and I/O); no cooperative action by another user, administrator, or victim mounting devices or opening files is needed.\nS:C - On Kubernetes/HPC hosts exposing bnxt_re to tenant containers or unprivileged RDMA workloads, triggering host-kernel NULL doorbell writes or exhausting finite DPI indices from a workload crosses the container/tenant security boundary to the hypervisor/host authority.\nC:L - Returning success after failed ioremap leaves DPI metadata and a mmapable BAR doorbell offset active while kernel dpi-\u003edbr stays NULL, disclosing doorbell-index/BAR layout to the caller and enabling follow-on corruption when doorbells are later rung.\nI:H - With dpi-\u003edbr left NULL, bnxt_qplib_ring_db and ring_prod_db issue writeq() to NULL during CQ, SQ, RQ, and SRQ doorbell updates on subsequent verbs activity, providing a kernel write primitive and control-flow disruption beyond a benign error return.\nA:H - NULL doorbell writeq faults oops or panic the kernel when CQ/QP/SRQ objects are used after the bogus allocation, and each successful-but-broken DPI allocation permanently consumes a finite doorbell index, enabling repeated denial of RDMA service to other tenants."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:44:57.739Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/303f6fef95df5e5316970746d861cf6daeeca77f"
},
{
"url": "https://git.kernel.org/stable/c/87267803a8c824616eb147c5dad7030a5db6f878"
}
],
"title": "RDMA/bnxt_re: Proper rollback if the ioremap fails",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72496",
"datePublished": "2026-08-15T05:57:29.723Z",
"dateReserved": "2026-08-09T03:40:39.937Z",
"dateUpdated": "2026-08-17T05:44:57.739Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64346 (GCVE-0-2026-64346)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: udc: Fix use-after-free in gadget_match_driver
The udc structure acts as the management structure for the gadget,
but their lifecycles are decoupled. A race condition exists where
usb_del_gadget() frees the udc memory (e.g., via mode-switch work)
while gadget_match_driver() concurrently accesses the freed udc memory
(e.g., via configfs), causing a Use-After-Free (UAF) that triggers a
NULL pointer dereference when the freed memory is zeroed:
[39430.908615][ T1171] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
[39430.911397][ T1171] pc : __pi_strcmp+0x20/0x140
[39430.911441][ T1171] lr : gadget_match_driver+0x34/0x60
...
[39430.911890][ T1171] usb_gadget_register_driver_owner+0x50/0xf8
[39430.911910][ T1171] gadget_dev_desc_UDC_store+0xf4/0x140
[39430.931308][ T1171] configfs_write_iter+0xec/0x134
[39430.957058][ T1171] Workqueue: events_freezable __dwc3_set_mode
[39430.957287][ T1171] dwc3_gadget_exit+0x34/0x8c
[39430.957304][ T1171] __dwc3_set_mode+0xc0/0x664
Fix this by ensuring the udc structure remains allocated until the
gadget is released. To achieve this, introduce a new
usb_gadget_release() routine to the core. When the gadget is added,
usb_add_gadget() stores the gadget's release routine in the udc
structure and takes a reference to the udc. When the gadget is
released, usb_gadget_release() drops the reference to the udc and
then calls the gadget's release routine.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fc274c1e997314bf47f6a62c79b5d7e554ed59c4 Version: fc274c1e997314bf47f6a62c79b5d7e554ed59c4 Version: fc274c1e997314bf47f6a62c79b5d7e554ed59c4 Version: fc274c1e997314bf47f6a62c79b5d7e554ed59c4 Version: fc274c1e997314bf47f6a62c79b5d7e554ed59c4 Version: fc274c1e997314bf47f6a62c79b5d7e554ed59c4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "50eeb8e8a4f389efc91b93cff14a683e714ec194",
"status": "affected",
"version": "fc274c1e997314bf47f6a62c79b5d7e554ed59c4",
"versionType": "git"
},
{
"lessThan": "7a5214dae906d9f58e07bc4995e8181ee74439f4",
"status": "affected",
"version": "fc274c1e997314bf47f6a62c79b5d7e554ed59c4",
"versionType": "git"
},
{
"lessThan": "d026f71df141c9b064ff32a78af5391a31ef75c2",
"status": "affected",
"version": "fc274c1e997314bf47f6a62c79b5d7e554ed59c4",
"versionType": "git"
},
{
"lessThan": "b52476a83d9e12df00765359d728a875b128bef1",
"status": "affected",
"version": "fc274c1e997314bf47f6a62c79b5d7e554ed59c4",
"versionType": "git"
},
{
"lessThan": "54fa390aae393eb130f307a85562e3001cc39a52",
"status": "affected",
"version": "fc274c1e997314bf47f6a62c79b5d7e554ed59c4",
"versionType": "git"
},
{
"lessThan": "67e511d2989eb1c8c588b599ce2fcc6bb8e6f7ea",
"status": "affected",
"version": "fc274c1e997314bf47f6a62c79b5d7e554ed59c4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: udc: Fix use-after-free in gadget_match_driver\n\nThe udc structure acts as the management structure for the gadget,\nbut their lifecycles are decoupled. A race condition exists where\nusb_del_gadget() frees the udc memory (e.g., via mode-switch work)\nwhile gadget_match_driver() concurrently accesses the freed udc memory\n(e.g., via configfs), causing a Use-After-Free (UAF) that triggers a\nNULL pointer dereference when the freed memory is zeroed:\n\n[39430.908615][ T1171] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[39430.911397][ T1171] pc : __pi_strcmp+0x20/0x140\n[39430.911441][ T1171] lr : gadget_match_driver+0x34/0x60\n...\n[39430.911890][ T1171] usb_gadget_register_driver_owner+0x50/0xf8\n[39430.911910][ T1171] gadget_dev_desc_UDC_store+0xf4/0x140\n[39430.931308][ T1171] configfs_write_iter+0xec/0x134\n\n[39430.957058][ T1171] Workqueue: events_freezable __dwc3_set_mode\n[39430.957287][ T1171] dwc3_gadget_exit+0x34/0x8c\n[39430.957304][ T1171] __dwc3_set_mode+0xc0/0x664\n\nFix this by ensuring the udc structure remains allocated until the\ngadget is released. To achieve this, introduce a new\nusb_gadget_release() routine to the core. When the gadget is added,\nusb_add_gadget() stores the gadget\u0027s release routine in the udc\nstructure and takes a reference to the udc. When the gadget is\nreleased, usb_gadget_release() drops the reference to the udc and\nthen calls the gadget\u0027s release routine."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:51.249Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/50eeb8e8a4f389efc91b93cff14a683e714ec194"
},
{
"url": "https://git.kernel.org/stable/c/7a5214dae906d9f58e07bc4995e8181ee74439f4"
},
{
"url": "https://git.kernel.org/stable/c/d026f71df141c9b064ff32a78af5391a31ef75c2"
},
{
"url": "https://git.kernel.org/stable/c/b52476a83d9e12df00765359d728a875b128bef1"
},
{
"url": "https://git.kernel.org/stable/c/54fa390aae393eb130f307a85562e3001cc39a52"
},
{
"url": "https://git.kernel.org/stable/c/67e511d2989eb1c8c588b599ce2fcc6bb8e6f7ea"
}
],
"title": "usb: gadget: udc: Fix use-after-free in gadget_match_driver",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64346",
"datePublished": "2026-07-25T08:50:07.680Z",
"dateReserved": "2026-07-19T15:36:31.782Z",
"dateUpdated": "2026-08-17T04:53:51.249Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53180 (GCVE-0-2026-53180)
Vulnerability from cvelistv5
Published
2026-06-25 08:38
Modified
2026-08-05 12:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
timers/migration: Fix livelock in tmigr_handle_remote_up()
tmigr_handle_remote_cpu() skips timer_expire_remote() when cpu ==
smp_processor_id(), assuming the local softirq path already handled this
CPU's timers.
This assumption is wrong because jiffies can advance after the handling of
the CPU's global timers in run_timer_base(BASE_GLOBAL) and before
tmigr_handle_remote() evaluates the expiry times.
As a consequence a timer which expires after the CPU local timer wheel
advanced and becomes expired in the remote handling is ignored and the
callback is never invoked and removed from the timer wheel.
What's worse is that fetch_next_timer_interrupt_remote() keeps reporting it
as expired, and the event is re-queued with expires == now on each
iteration. The goto-again loop spins indefinitely.
Fix this by calling timer_expire_remote() unconditionally. That's minimal
overhead for the common case as __run_timer_base() returns immediately if
there is nothing to expire in the local wheel.
[ tglx: Amend change log and add a comment ]
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/time/timer_migration.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "07b3b83587fb3012619f4439389b64a955fc7836",
"status": "affected",
"version": "7ee988770326fca440472200c3eb58935fe712f6",
"versionType": "git"
},
{
"lessThan": "1d6c2062b77be09ec15d6bf637b2e2221c4482fc",
"status": "affected",
"version": "7ee988770326fca440472200c3eb58935fe712f6",
"versionType": "git"
},
{
"lessThan": "d338e61ea94052a786aac9f58e9f0d8520afa0fd",
"status": "affected",
"version": "7ee988770326fca440472200c3eb58935fe712f6",
"versionType": "git"
},
{
"lessThan": "d486b4934a8e504376b85cdb3766f306d57aff5b",
"status": "affected",
"version": "7ee988770326fca440472200c3eb58935fe712f6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/time/timer_migration.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntimers/migration: Fix livelock in tmigr_handle_remote_up()\n\ntmigr_handle_remote_cpu() skips timer_expire_remote() when cpu ==\nsmp_processor_id(), assuming the local softirq path already handled this\nCPU\u0027s timers.\n\nThis assumption is wrong because jiffies can advance after the handling of\nthe CPU\u0027s global timers in run_timer_base(BASE_GLOBAL) and before\ntmigr_handle_remote() evaluates the expiry times.\n\nAs a consequence a timer which expires after the CPU local timer wheel\nadvanced and becomes expired in the remote handling is ignored and the\ncallback is never invoked and removed from the timer wheel.\n\nWhat\u0027s worse is that fetch_next_timer_interrupt_remote() keeps reporting it\nas expired, and the event is re-queued with expires == now on each\niteration. The goto-again loop spins indefinitely.\n\nFix this by calling timer_expire_remote() unconditionally. That\u0027s minimal\noverhead for the common case as __run_timer_base() returns immediately if\nthere is nothing to expire in the local wheel.\n\n[ tglx: Amend change log and add a comment ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Unauthenticated remote packets can create non-pinned global kernel timers, for example incomplete IPv4/IPv6 fragment reassembly queues whose timers are armed from packet receive paths. Those timers are handled by the affected timer migration code, making a network trigger reasonable on exposed Linux hosts.\nAC:L - The bug requires a timing window where jiffies advances between local global timer processing and migration handling, but an attacker can repeatedly create many expiring global timers to exercise it. Under the required rule, this uncertainty is scored as low complexity.\nPR:N - The remote fragmented-packet path requires no local account, capabilities, or protocol authentication. It can be reached before any application-level authorization.\nUI:N - No victim user action is required once the host receives the triggering traffic. Timer expiry and softirq processing happen autonomously in the kernel.\nS:U - The impact remains within the same kernel security authority. There is no VM, IOMMU, container-boundary, or sandbox escape scope change.\nC:N - The defect is a timer migration logic livelock, not a memory disclosure or memory corruption issue. No kernel memory read primitive is indicated.\nI:N - The skipped timer callback and repeated requeue do not provide data modification, arbitrary write, or control-flow hijack. The observed effect is denial of service only.\nA:H - The stale expired timer causes tmigr_handle_remote_up() to spin indefinitely in the timer softirq path. An infinite kernel livelock/soft lockup is a high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:33:47.890Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/07b3b83587fb3012619f4439389b64a955fc7836"
},
{
"url": "https://git.kernel.org/stable/c/1d6c2062b77be09ec15d6bf637b2e2221c4482fc"
},
{
"url": "https://git.kernel.org/stable/c/d338e61ea94052a786aac9f58e9f0d8520afa0fd"
},
{
"url": "https://git.kernel.org/stable/c/d486b4934a8e504376b85cdb3766f306d57aff5b"
}
],
"title": "timers/migration: Fix livelock in tmigr_handle_remote_up()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53180",
"datePublished": "2026-06-25T08:38:55.332Z",
"dateReserved": "2026-06-09T07:44:35.390Z",
"dateUpdated": "2026-08-05T12:33:47.890Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64335 (GCVE-0-2026-64335)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: digi_acceleport: fix broken rx after throttle
If the port is closed while throttled, the read urb is never resubmitted
and the port will not receive any further data until the device is
reconnected (or the driver is rebound).
Clear the throttle flags and submit the urb if needed when opening the
port.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/digi_acceleport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4f3f6f44db71e469933a7c36c5d57d937ba0a21b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d5d2660caef78d4c996d34d123574c8e86f5b5ac",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "61954033326fc7e637ed2aeeb4b52021e0ee4657",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "8d50a910194f66566a5eb252b33283855c8d5203",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "abacd67e6f689c62d8a13e3da25f4272bc9ad4af",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "eab394781e9321c0c7e97a24fd092387cb262f40",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "92fa3e1a49848509ea3f7995751963fc65095998",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "83a3dfc018943b05b6daf3a6f891833e1aabfa1f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/digi_acceleport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: digi_acceleport: fix broken rx after throttle\n\nIf the port is closed while throttled, the read urb is never resubmitted\nand the port will not receive any further data until the device is\nreconnected (or the driver is rebound).\n\nClear the throttle flags and submit the urb if needed when opening the\nport."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:38.295Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4f3f6f44db71e469933a7c36c5d57d937ba0a21b"
},
{
"url": "https://git.kernel.org/stable/c/d5d2660caef78d4c996d34d123574c8e86f5b5ac"
},
{
"url": "https://git.kernel.org/stable/c/61954033326fc7e637ed2aeeb4b52021e0ee4657"
},
{
"url": "https://git.kernel.org/stable/c/8d50a910194f66566a5eb252b33283855c8d5203"
},
{
"url": "https://git.kernel.org/stable/c/abacd67e6f689c62d8a13e3da25f4272bc9ad4af"
},
{
"url": "https://git.kernel.org/stable/c/eab394781e9321c0c7e97a24fd092387cb262f40"
},
{
"url": "https://git.kernel.org/stable/c/92fa3e1a49848509ea3f7995751963fc65095998"
},
{
"url": "https://git.kernel.org/stable/c/83a3dfc018943b05b6daf3a6f891833e1aabfa1f"
}
],
"title": "USB: serial: digi_acceleport: fix broken rx after throttle",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64335",
"datePublished": "2026-07-25T08:50:00.835Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:38.295Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52935 (GCVE-0-2026-52935)
Vulnerability from cvelistv5
Published
2026-06-24 07:14
Modified
2026-08-05 12:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: espintcp: do not reuse an in-progress partial send
espintcp keeps a single in-flight transmit in ctx->partial.
Before building a new sk_msg, espintcp_sendmsg() first tries to flush
that state through espintcp_push_msgs().
For blocking callers, espintcp_push_msgs() may return success even when
the previous partial send is still pending. espintcp_sendmsg() would
then reinitialize emsg->skmsg and reuse ctx->partial while the old
transfer still owns that state.
Do not rebuild the send message when ctx->partial is still in progress.
If espintcp_push_msgs() returns with emsg->len still set, fail the new
send instead of overwriting the live partial state.
This is a memory-safety fix: reusing the live partial-send state can
leave a stale offset attached to a new sk_msg and lead to an out-of-
bounds read in the send path.
tcp_sendmsg_locked() already handles waiting for send buffer memory, so
the fix here is just to preserve espintcp's one-message-at-a-time
transmit state.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/espintcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6564e9c7af7e1dc7bfe7f3093b728abe484d7630",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "1777ceac4bea5e568a5ad44b7f9bb219c1db21b6",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "8c6c691bf062dc0753a139a4ab8cb92a70fcf8f3",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "aa82a078f70f7ff88ba7d1017134e79d1ac140f2",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "ba21439302db9a82fe4edbed1e38a97271529421",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "f9b38a8fbfa07f1deaf7ee1eb38fa8b21ea13990",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "37487d55bf3300e3d2c1368da5c2bd3e3834ea4f",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "c381039ade2e161ab08c0eda73c4f8b9a7115928",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/espintcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: espintcp: do not reuse an in-progress partial send\n\nespintcp keeps a single in-flight transmit in ctx-\u003epartial.\nBefore building a new sk_msg, espintcp_sendmsg() first tries to flush\nthat state through espintcp_push_msgs().\n\nFor blocking callers, espintcp_push_msgs() may return success even when\nthe previous partial send is still pending. espintcp_sendmsg() would\nthen reinitialize emsg-\u003eskmsg and reuse ctx-\u003epartial while the old\ntransfer still owns that state.\n\nDo not rebuild the send message when ctx-\u003epartial is still in progress.\nIf espintcp_push_msgs() returns with emsg-\u003elen still set, fail the new\nsend instead of overwriting the live partial state.\n\nThis is a memory-safety fix: reusing the live partial-send state can\nleave a stale offset attached to a new sk_msg and lead to an out-of-\nbounds read in the send path.\n\ntcp_sendmsg_locked() already handles waiting for send buffer memory, so\nthe fix here is just to preserve espintcp\u0027s one-message-at-a-time\ntransmit state."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached through local socket syscalls: an attacker creates/uses a TCP socket, sets `TCP_ULP` to `espintcp`, and calls send/sendmsg. It is not directly triggerable by unauthenticated network packets alone.\nAC:L - The attacker can create the needed partial-send condition by controlling the TCP peer or receiver behavior and filling the send buffer, then issuing another send. No race or condition outside attacker control is required.\nPR:L - Setting an already-registered TCP ULP does not require CAP_NET_ADMIN, and ordinary local users can create TCP sockets and call setsockopt/sendmsg. XFRM administration is privileged, but it is not required for this lowest-privilege path to `espintcp_sendmsg`.\nUI:N - Exploitation does not require any victim user action after the attacker has local code execution. The attacker directly drives the socket operations.\nS:U - The impact remains within the kernel and its managed resources on the same host. This is not a VM escape, IOMMU bypass, or cross-authority boundary violation.\nC:H - The stale partial-send offset can produce an out-of-bounds read in the TCP send path, potentially exposing kernel memory through transmitted data. Because the read is not strictly bounded to a small fixed disclosure, high confidentiality impact is appropriate.\nI:H - The corrupted espintcp/sk_msg state can build invalid bvec/socket-buffer references and disturb page or send-buffer accounting, which is a plausible kernel memory integrity primitive. Under the required higher-severity rule for uncertainty, this is scored as high integrity impact.\nA:H - The invalid scatterlist/bvec state can lead to kernel warnings, invalid page references, refcount/accounting corruption, or crashes in the send/cleanup path. A local attacker can repeat the trigger, so availability impact is high."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:31:53.368Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6564e9c7af7e1dc7bfe7f3093b728abe484d7630"
},
{
"url": "https://git.kernel.org/stable/c/1777ceac4bea5e568a5ad44b7f9bb219c1db21b6"
},
{
"url": "https://git.kernel.org/stable/c/8c6c691bf062dc0753a139a4ab8cb92a70fcf8f3"
},
{
"url": "https://git.kernel.org/stable/c/aa82a078f70f7ff88ba7d1017134e79d1ac140f2"
},
{
"url": "https://git.kernel.org/stable/c/ba21439302db9a82fe4edbed1e38a97271529421"
},
{
"url": "https://git.kernel.org/stable/c/f9b38a8fbfa07f1deaf7ee1eb38fa8b21ea13990"
},
{
"url": "https://git.kernel.org/stable/c/37487d55bf3300e3d2c1368da5c2bd3e3834ea4f"
},
{
"url": "https://git.kernel.org/stable/c/c381039ade2e161ab08c0eda73c4f8b9a7115928"
}
],
"title": "xfrm: espintcp: do not reuse an in-progress partial send",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52935",
"datePublished": "2026-06-24T07:14:25.988Z",
"dateReserved": "2026-06-09T07:44:35.369Z",
"dateUpdated": "2026-08-05T12:31:53.368Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53182 (GCVE-0-2026-53182)
Vulnerability from cvelistv5
Published
2026-06-25 08:38
Modified
2026-08-05 12:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: nl80211: reject oversized EMA RNR lists
nl80211_parse_rnr_elems() stores the parsed element count in a
u8-backed cfg80211_rnr_elems::cnt field and uses that count to size
the flexible array allocation.
Reject nested NL80211_ATTR_EMA_RNR_ELEMS input once the count reaches
255, before incrementing it again. This keeps the parser aligned with
the data structure it fills and matches the existing bound check used
by nl80211_parse_mbssid_elems().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 56189d7bc30531def6b999f27940ee43c6ff2569 Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: 6.1.160 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fc0ec2fc02dfe52c5821f36fbccf6a45df43f508",
"status": "affected",
"version": "56189d7bc30531def6b999f27940ee43c6ff2569",
"versionType": "git"
},
{
"lessThan": "688fcac7054abc680c0eef753f2bb772cfaf8cf7",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "30c3fa80f423613efdda3deca4af52ff7d20e4e2",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "265c07c09c837621730d35f02975207a1224bf05",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "ecbf3c45add30a0857414e156bdb9c79906f0ff6",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "4cd92957e8f8cc4ebfe8a5d4203c14c592fde6b1",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "6.1.176",
"status": "affected",
"version": "6.1.160",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "6.1.160",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: reject oversized EMA RNR lists\n\nnl80211_parse_rnr_elems() stores the parsed element count in a\nu8-backed cfg80211_rnr_elems::cnt field and uses that count to size\nthe flexible array allocation.\n\nReject nested NL80211_ATTR_EMA_RNR_ELEMS input once the count reaches\n255, before incrementing it again. This keeps the parser aligned with\nthe data structure it fills and matches the existing bound check used\nby nl80211_parse_mbssid_elems()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable parser is reached through local nl80211 generic-netlink commands that configure AP beacon data, not by received WiFi frames or remote network traffic.\nAC:L - An attacker who can send the command can deterministically provide 256 or more nested EMA RNR elements; there is no race or condition outside the attacker\u0027s control beyond targeting an affected AP-capable configuration.\nPR:L - The commands require CAP_NET_ADMIN via GENL_UNS_ADMIN_PERM, which is checked in the relevant network namespace; under kernel scoring guidance this is low privilege because CAP_NET_ADMIN may be available through user namespaces.\nUI:N - No victim action is required after the attacker sends the crafted nl80211 request.\nS:U - The corruption occurs inside the kernel and impacts the same kernel security authority; it is not a VM escape or other cross-scope boundary violation.\nC:H - The u8 count wrap causes an undersized flexible-array allocation followed by attacker-influenced out-of-bounds heap writes, which is memory corruption plausibly usable for kernel memory disclosure.\nI:H - The bug is a kernel heap out-of-bounds write of RNR element metadata past the allocation, making arbitrary corruption or control-flow compromise defensible.\nA:H - The same heap corruption can readily crash or panic the kernel even if not weaponized for code execution."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:33:48.954Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fc0ec2fc02dfe52c5821f36fbccf6a45df43f508"
},
{
"url": "https://git.kernel.org/stable/c/688fcac7054abc680c0eef753f2bb772cfaf8cf7"
},
{
"url": "https://git.kernel.org/stable/c/30c3fa80f423613efdda3deca4af52ff7d20e4e2"
},
{
"url": "https://git.kernel.org/stable/c/265c07c09c837621730d35f02975207a1224bf05"
},
{
"url": "https://git.kernel.org/stable/c/ecbf3c45add30a0857414e156bdb9c79906f0ff6"
},
{
"url": "https://git.kernel.org/stable/c/4cd92957e8f8cc4ebfe8a5d4203c14c592fde6b1"
}
],
"title": "wifi: nl80211: reject oversized EMA RNR lists",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53182",
"datePublished": "2026-06-25T08:38:56.654Z",
"dateReserved": "2026-06-09T07:44:35.390Z",
"dateUpdated": "2026-08-05T12:33:48.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68207 (GCVE-0-2026-68207)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: ti: vpe: unwind v4l2 device registration on probe error
If the vpe_top resource is missing, vpe_probe() returns -ENODEV after
v4l2_device_register() has succeeded. Probe failures do not call the
driver's remove callback, so the v4l2 device remains registered on that
error path.
Route that failure through the existing v4l2_device_unregister() unwind
label, matching the other errors after v4l2_device_register().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/ti/vpe/vpe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f0a60c000876bcd808a70d602c758c2e64c77d8",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "4ecf0cc0cf59032a89bcdf36fbbb03bff5455fd9",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "7d383357905de975e1dbde639e5fa7477075d104",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "7e6521dd747eca3cb3d4cd3ddcf20f266494f63d",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "fcbbaf9cb9722a82f0221c56114037fc537f4ada",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "e0f1c9a90ef665f2587c274a8fed59f2dfc575a6",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/ti/vpe/vpe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ti: vpe: unwind v4l2 device registration on probe error\n\nIf the vpe_top resource is missing, vpe_probe() returns -ENODEV after\nv4l2_device_register() has succeeded. Probe failures do not call the\ndriver\u0027s remove callback, so the v4l2 device remains registered on that\nerror path.\n\nRoute that failure through the existing v4l2_device_unregister() unwind\nlabel, matching the other errors after v4l2_device_register()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:29.282Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f0a60c000876bcd808a70d602c758c2e64c77d8"
},
{
"url": "https://git.kernel.org/stable/c/4ecf0cc0cf59032a89bcdf36fbbb03bff5455fd9"
},
{
"url": "https://git.kernel.org/stable/c/7d383357905de975e1dbde639e5fa7477075d104"
},
{
"url": "https://git.kernel.org/stable/c/7e6521dd747eca3cb3d4cd3ddcf20f266494f63d"
},
{
"url": "https://git.kernel.org/stable/c/fcbbaf9cb9722a82f0221c56114037fc537f4ada"
},
{
"url": "https://git.kernel.org/stable/c/e0f1c9a90ef665f2587c274a8fed59f2dfc575a6"
}
],
"title": "media: ti: vpe: unwind v4l2 device registration on probe error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68207",
"datePublished": "2026-08-10T12:00:26.322Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:29.282Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68432 (GCVE-0-2026-68432)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: require CAP_NET_ADMIN in the device netns for changelink
A tunnel changelink() operates on at most two netns, dev_net(dev) and
the sticky underlay netns vxlan->net. They differ once the device is
created in or moved to a netns other than the one the request runs in.
The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),
so a caller privileged there but not in vxlan->net can rewrite a vxlan
device whose underlay lives in vxlan->net.
vxlan_changelink() validates and applies the new configuration against
vxlan->net (vxlan_config_validate(vxlan->net, ...)) and can reopen the
underlay socket in that netns, so the same reasoning as the tunnel
changelink series applies here.
Gate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of
the op before any attribute is parsed, matching ipgre_changelink() and
the rest of the "require CAP_NET_ADMIN in the device netns for
changelink" series.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b95a8743e58f7efed5ddc4cb73829b66f17feab0",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "7465ade989ba84adc2bfa58bad3ca25d249f0f7a",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "0aa580a8bbbed2507b4582a1f0ef581d480d06ed",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "b3793d7dccb192ffff29894d11824db6251acdd5",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "730c7e5fea7f06e0cdf21c547222ec93234fd1d6",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "e8ad0d311e225939a9a6c745d6cc384c7364ec87",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: require CAP_NET_ADMIN in the device netns for changelink\n\nA tunnel changelink() operates on at most two netns, dev_net(dev) and\nthe sticky underlay netns vxlan-\u003enet. They differ once the device is\ncreated in or moved to a netns other than the one the request runs in.\nThe rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),\nso a caller privileged there but not in vxlan-\u003enet can rewrite a vxlan\ndevice whose underlay lives in vxlan-\u003enet.\n\nvxlan_changelink() validates and applies the new configuration against\nvxlan-\u003enet (vxlan_config_validate(vxlan-\u003enet, ...)) and can reopen the\nunderlay socket in that netns, so the same reasoning as the tunnel\nchangelink series applies here.\n\nGate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of\nthe op before any attribute is parsed, matching ipgre_changelink() and\nthe rest of the \"require CAP_NET_ADMIN in the device netns for\nchangelink\" series.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires issuing an RTM_NEWLINK changelink request over an rtnetlink socket on the local system, matching the kernel guidance that netlink configuration paths are Local.\nAC:L - Once a cross-namespace vxlan device is present in the caller\u0027s netns, the missing check is bypassed by a single deterministic netlink changelink call with no race, timing, or memory-layout dependency.\nPR:L - The rtnl entry path only requires CAP_NET_ADMIN in dev_net(dev), which an unprivileged user obtains inside a user namespace via unshare --user --map-root-user --net; no privilege in the underlay netns vxlan-\u003enet is needed.\nUI:N - The attack is fully programmatic through netlink from the attacker\u0027s own process; no victim action such as mounting, opening a file, or clicking is required.\nS:C - Authorization is evaluated against dev_net(dev) while the configuration is validated and applied against vxlan-\u003enet, so the impact crosses from the attacker\u0027s net/user namespace into another tenant\u0027s or the host\u0027s network namespace.\nC:H - The attacker can rewrite IFLA_VXLAN_GROUP/LOCAL and the underlay IFLA_VXLAN_LINK so encapsulated overlay traffic in the victim netns is sent to an attacker-controlled endpoint, exposing tunneled payloads.\nI:H - Unauthorized changelink mutates live tunnel state in the victim underlay netns (remote/local addresses, lower device, TOS/TTL/label, learning and proxy/RSC flags, default-remote FDB entries), enabling redirection and injection of overlay traffic.\nA:H - Rewriting the remote group, source address, or lower device tears down and re-establishes multicast group membership and forwarding state, causing sustained loss of connectivity for every service riding the affected VXLAN overlay."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:30.743Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b95a8743e58f7efed5ddc4cb73829b66f17feab0"
},
{
"url": "https://git.kernel.org/stable/c/7465ade989ba84adc2bfa58bad3ca25d249f0f7a"
},
{
"url": "https://git.kernel.org/stable/c/0aa580a8bbbed2507b4582a1f0ef581d480d06ed"
},
{
"url": "https://git.kernel.org/stable/c/b3793d7dccb192ffff29894d11824db6251acdd5"
},
{
"url": "https://git.kernel.org/stable/c/32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f"
},
{
"url": "https://git.kernel.org/stable/c/730c7e5fea7f06e0cdf21c547222ec93234fd1d6"
},
{
"url": "https://git.kernel.org/stable/c/e8ad0d311e225939a9a6c745d6cc384c7364ec87"
},
{
"url": "https://git.kernel.org/stable/c/3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e"
}
],
"title": "vxlan: require CAP_NET_ADMIN in the device netns for changelink",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68432",
"datePublished": "2026-08-12T00:07:18.806Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:30.743Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43015 (GCVE-0-2026-43015)
Vulnerability from cvelistv5
Published
2026-05-01 14:15
Modified
2026-05-23 16:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: macb: fix clk handling on PCI glue driver removal
platform_device_unregister() may still want to use the registered clks
during runtime resume callback.
Note that there is a commit d82d5303c4c5 ("net: macb: fix use after free
on rmmod") that addressed the similar problem of clk vs platform device
unregistration but just moved the bug to another place.
Save the pointers to clks into local variables for reuse after platform
device is unregistered.
BUG: KASAN: use-after-free in clk_prepare+0x5a/0x60
Read of size 8 at addr ffff888104f85e00 by task modprobe/597
CPU: 2 PID: 597 Comm: modprobe Not tainted 6.1.164+ #114
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0x8d/0xba
print_report+0x17f/0x496
kasan_report+0xd9/0x180
clk_prepare+0x5a/0x60
macb_runtime_resume+0x13d/0x410 [macb]
pm_generic_runtime_resume+0x97/0xd0
__rpm_callback+0xc8/0x4d0
rpm_callback+0xf6/0x230
rpm_resume+0xeeb/0x1a70
__pm_runtime_resume+0xb4/0x170
bus_remove_device+0x2e3/0x4b0
device_del+0x5b3/0xdc0
platform_device_del+0x4e/0x280
platform_device_unregister+0x11/0x50
pci_device_remove+0xae/0x210
device_remove+0xcb/0x180
device_release_driver_internal+0x529/0x770
driver_detach+0xd4/0x1a0
bus_remove_driver+0x135/0x260
driver_unregister+0x72/0xb0
pci_unregister_driver+0x26/0x220
__do_sys_delete_module+0x32e/0x550
do_syscall_64+0x35/0x80
entry_SYSCALL_64_after_hwframe+0x6e/0xd8
</TASK>
Allocated by task 519:
kasan_save_stack+0x2c/0x50
kasan_set_track+0x21/0x30
__kasan_kmalloc+0x8e/0x90
__clk_register+0x458/0x2890
clk_hw_register+0x1a/0x60
__clk_hw_register_fixed_rate+0x255/0x410
clk_register_fixed_rate+0x3c/0xa0
macb_probe+0x1d8/0x42e [macb_pci]
local_pci_probe+0xd7/0x190
pci_device_probe+0x252/0x600
really_probe+0x255/0x7f0
__driver_probe_device+0x1ee/0x330
driver_probe_device+0x4c/0x1f0
__driver_attach+0x1df/0x4e0
bus_for_each_dev+0x15d/0x1f0
bus_add_driver+0x486/0x5e0
driver_register+0x23a/0x3d0
do_one_initcall+0xfd/0x4d0
do_init_module+0x18b/0x5a0
load_module+0x5663/0x7950
__do_sys_finit_module+0x101/0x180
do_syscall_64+0x35/0x80
entry_SYSCALL_64_after_hwframe+0x6e/0xd8
Freed by task 597:
kasan_save_stack+0x2c/0x50
kasan_set_track+0x21/0x30
kasan_save_free_info+0x2a/0x50
__kasan_slab_free+0x106/0x180
__kmem_cache_free+0xbc/0x320
clk_unregister+0x6de/0x8d0
macb_remove+0x73/0xc0 [macb_pci]
pci_device_remove+0xae/0x210
device_remove+0xcb/0x180
device_release_driver_internal+0x529/0x770
driver_detach+0xd4/0x1a0
bus_remove_driver+0x135/0x260
driver_unregister+0x72/0xb0
pci_unregister_driver+0x26/0x220
__do_sys_delete_module+0x32e/0x550
do_syscall_64+0x35/0x80
entry_SYSCALL_64_after_hwframe+0x6e/0xd8
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7721221e87d25c9840d9ca6b986dbdc410d5ce2b Version: d82d5303c4c539db86588ffb5dc5b26c3f1513e8 Version: d82d5303c4c539db86588ffb5dc5b26c3f1513e8 Version: d82d5303c4c539db86588ffb5dc5b26c3f1513e8 Version: d82d5303c4c539db86588ffb5dc5b26c3f1513e8 Version: d82d5303c4c539db86588ffb5dc5b26c3f1513e8 Version: d82d5303c4c539db86588ffb5dc5b26c3f1513e8 Version: d82d5303c4c539db86588ffb5dc5b26c3f1513e8 Version: a7d521cc726f30b8e679a6f36d04b18a8ab3c536 Version: 46670fb832ee80943715df618632ca13c2e96f2b Version: 1da750d1e2140ef43d64d17f301ff6f41b45541e Version: 4ad6f2d23b0f6ac0d3e5f3102a4256d1c86c90f5 Version: 5.10.70 ≤ Version: 4.14.249 ≤ Version: 4.19.209 ≤ Version: 5.4.150 ≤ Version: 5.14.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cadence/macb_pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bf64cae913cdd4821f13d5d1d68900c0891bef69",
"status": "affected",
"version": "7721221e87d25c9840d9ca6b986dbdc410d5ce2b",
"versionType": "git"
},
{
"lessThan": "67f70841a175fa3469119f52d77a3662c07507a2",
"status": "affected",
"version": "d82d5303c4c539db86588ffb5dc5b26c3f1513e8",
"versionType": "git"
},
{
"lessThan": "2d96204e4184d6f7dd2f93c6f218fd0c1f55e9ae",
"status": "affected",
"version": "d82d5303c4c539db86588ffb5dc5b26c3f1513e8",
"versionType": "git"
},
{
"lessThan": "b3f799cdf830df1782ae463cf15ace35015be99e",
"status": "affected",
"version": "d82d5303c4c539db86588ffb5dc5b26c3f1513e8",
"versionType": "git"
},
{
"lessThan": "f310a836da90d0f0321b14d446c071af63f9ee4c",
"status": "affected",
"version": "d82d5303c4c539db86588ffb5dc5b26c3f1513e8",
"versionType": "git"
},
{
"lessThan": "16ab4c0e2b15df5d33bfcb9ea8e4441b85dd4a57",
"status": "affected",
"version": "d82d5303c4c539db86588ffb5dc5b26c3f1513e8",
"versionType": "git"
},
{
"lessThan": "3496fb9e66f79d4def3bb7ec7563e3eaa33a688f",
"status": "affected",
"version": "d82d5303c4c539db86588ffb5dc5b26c3f1513e8",
"versionType": "git"
},
{
"lessThan": "ce8fe5287b87e24e225c342f3b0ec04f0b3680fe",
"status": "affected",
"version": "d82d5303c4c539db86588ffb5dc5b26c3f1513e8",
"versionType": "git"
},
{
"status": "affected",
"version": "a7d521cc726f30b8e679a6f36d04b18a8ab3c536",
"versionType": "git"
},
{
"status": "affected",
"version": "46670fb832ee80943715df618632ca13c2e96f2b",
"versionType": "git"
},
{
"status": "affected",
"version": "1da750d1e2140ef43d64d17f301ff6f41b45541e",
"versionType": "git"
},
{
"status": "affected",
"version": "4ad6f2d23b0f6ac0d3e5f3102a4256d1c86c90f5",
"versionType": "git"
},
{
"lessThan": "5.10.253",
"status": "affected",
"version": "5.10.70",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.249",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.209",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.150",
"versionType": "semver"
},
{
"lessThan": "5.15",
"status": "affected",
"version": "5.14.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cadence/macb_pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.253",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.168",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.134",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.81",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.22",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.253",
"versionStartIncluding": "5.10.70",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.168",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.134",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.81",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.22",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.12",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.249",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.209",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.150",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.14.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: fix clk handling on PCI glue driver removal\n\nplatform_device_unregister() may still want to use the registered clks\nduring runtime resume callback.\n\nNote that there is a commit d82d5303c4c5 (\"net: macb: fix use after free\non rmmod\") that addressed the similar problem of clk vs platform device\nunregistration but just moved the bug to another place.\n\nSave the pointers to clks into local variables for reuse after platform\ndevice is unregistered.\n\nBUG: KASAN: use-after-free in clk_prepare+0x5a/0x60\nRead of size 8 at addr ffff888104f85e00 by task modprobe/597\n\nCPU: 2 PID: 597 Comm: modprobe Not tainted 6.1.164+ #114\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x8d/0xba\n print_report+0x17f/0x496\n kasan_report+0xd9/0x180\n clk_prepare+0x5a/0x60\n macb_runtime_resume+0x13d/0x410 [macb]\n pm_generic_runtime_resume+0x97/0xd0\n __rpm_callback+0xc8/0x4d0\n rpm_callback+0xf6/0x230\n rpm_resume+0xeeb/0x1a70\n __pm_runtime_resume+0xb4/0x170\n bus_remove_device+0x2e3/0x4b0\n device_del+0x5b3/0xdc0\n platform_device_del+0x4e/0x280\n platform_device_unregister+0x11/0x50\n pci_device_remove+0xae/0x210\n device_remove+0xcb/0x180\n device_release_driver_internal+0x529/0x770\n driver_detach+0xd4/0x1a0\n bus_remove_driver+0x135/0x260\n driver_unregister+0x72/0xb0\n pci_unregister_driver+0x26/0x220\n __do_sys_delete_module+0x32e/0x550\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n \u003c/TASK\u003e\n\nAllocated by task 519:\n kasan_save_stack+0x2c/0x50\n kasan_set_track+0x21/0x30\n __kasan_kmalloc+0x8e/0x90\n __clk_register+0x458/0x2890\n clk_hw_register+0x1a/0x60\n __clk_hw_register_fixed_rate+0x255/0x410\n clk_register_fixed_rate+0x3c/0xa0\n macb_probe+0x1d8/0x42e [macb_pci]\n local_pci_probe+0xd7/0x190\n pci_device_probe+0x252/0x600\n really_probe+0x255/0x7f0\n __driver_probe_device+0x1ee/0x330\n driver_probe_device+0x4c/0x1f0\n __driver_attach+0x1df/0x4e0\n bus_for_each_dev+0x15d/0x1f0\n bus_add_driver+0x486/0x5e0\n driver_register+0x23a/0x3d0\n do_one_initcall+0xfd/0x4d0\n do_init_module+0x18b/0x5a0\n load_module+0x5663/0x7950\n __do_sys_finit_module+0x101/0x180\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nFreed by task 597:\n kasan_save_stack+0x2c/0x50\n kasan_set_track+0x21/0x30\n kasan_save_free_info+0x2a/0x50\n __kasan_slab_free+0x106/0x180\n __kmem_cache_free+0xbc/0x320\n clk_unregister+0x6de/0x8d0\n macb_remove+0x73/0xc0 [macb_pci]\n pci_device_remove+0xae/0x210\n device_remove+0xcb/0x180\n device_release_driver_internal+0x529/0x770\n driver_detach+0xd4/0x1a0\n bus_remove_driver+0x135/0x260\n driver_unregister+0x72/0xb0\n pci_unregister_driver+0x26/0x220\n __do_sys_delete_module+0x32e/0x550\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8"
}
],
"providerMetadata": {
"dateUpdated": "2026-05-23T16:05:58.376Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bf64cae913cdd4821f13d5d1d68900c0891bef69"
},
{
"url": "https://git.kernel.org/stable/c/67f70841a175fa3469119f52d77a3662c07507a2"
},
{
"url": "https://git.kernel.org/stable/c/2d96204e4184d6f7dd2f93c6f218fd0c1f55e9ae"
},
{
"url": "https://git.kernel.org/stable/c/b3f799cdf830df1782ae463cf15ace35015be99e"
},
{
"url": "https://git.kernel.org/stable/c/f310a836da90d0f0321b14d446c071af63f9ee4c"
},
{
"url": "https://git.kernel.org/stable/c/16ab4c0e2b15df5d33bfcb9ea8e4441b85dd4a57"
},
{
"url": "https://git.kernel.org/stable/c/3496fb9e66f79d4def3bb7ec7563e3eaa33a688f"
},
{
"url": "https://git.kernel.org/stable/c/ce8fe5287b87e24e225c342f3b0ec04f0b3680fe"
}
],
"title": "net: macb: fix clk handling on PCI glue driver removal",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43015",
"datePublished": "2026-05-01T14:15:20.242Z",
"dateReserved": "2026-05-01T14:12:55.974Z",
"dateUpdated": "2026-05-23T16:05:58.376Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64214 (GCVE-0-2026-64214)
Vulnerability from cvelistv5
Published
2026-07-24 15:23
Modified
2026-07-24 15:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()
A kernel panic is observed when handling machine check exceptions from
real mode.
BUG: Unable to handle kernel data access on read at 0xc00000006be21300
Oops: Kernel access of bad area, sig: 11 [#1]
MSR: 8000000000001003 <SF,ME,RI,LE> CR: 88222248 XER: 00000005
CFAR: c00000000003ffc4 DAR: c00000006be21300 DSISR: 40000000 IRQMASK: 0
NIP [c000000000029e40] arch_irq_work_raise+0x10/0x70
LR [c00000000003ffc8] machine_check_queue_event+0xa8/0x150
Call Trace:
[c0000000179d3c70] [c00000000003ff64] machine_check_queue_event+0x44/0x150
[c0000000179d3d30] [c0000000000084e0] machine_check_early_common+0x1f0/0x2c0
The crash occurs because arch_irq_work_raise() calls preempt_disable()
from machine check exception (MCE) handlers running in real mode. In
this context, accessing the preempt_count can fault, leading to the panic.
The preempt_disable()/preempt_enable() pair in arch_irq_work_raise()
was originally added by commit 0fe1ac48bef0 ("powerpc/perf_event: Fix
oops due to perf_event_do_pending call") to avoid races while raising
irq work from exception context.
Later, commit 471ba0e686cb ("irq_work: Do not raise an IPI when
queueing work on the local CPU") added preemption protection in
irq_work_queue() path, while commit 20b876918c06 ("irq_work: Use per
cpu atomics instead of regular atomics") added equivalent
protection in irq_work_queue_on() before reaching arch_irq_work_raise():
irq_work_queue() / irq_work_queue_on()
-> preempt_disable()
-> __irq_work_queue_local()
-> irq_work_raise()
-> arch_irq_work_raise()
As a result, callers other than mce_irq_work_raise() already execute
with preemption disabled, making the additional
preempt_disable()/preempt_enable() pair in arch_irq_work_raise()
redundant.
The arch_irq_work_raise() function executes in NMI context when called
from MCE handler. Hence we will not be preempted or scheduled out since
we are in NMI context with MSR[EE]=0. Therefore, it is safe to remove
the preempt_disable()/preempt_enable() calls from here.
Remove it to avoid accessing preempt_count from real mode context.
[Maddy: Fixed the commit title]
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cc15ff3275694fedc33cd3d53212a43eec7aa0bc Version: cc15ff3275694fedc33cd3d53212a43eec7aa0bc Version: cc15ff3275694fedc33cd3d53212a43eec7aa0bc Version: cc15ff3275694fedc33cd3d53212a43eec7aa0bc Version: cc15ff3275694fedc33cd3d53212a43eec7aa0bc Version: cc15ff3275694fedc33cd3d53212a43eec7aa0bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/powerpc/kernel/time.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "51860e423592893cd7bfa7287d99a3aff4dc3a9d",
"status": "affected",
"version": "cc15ff3275694fedc33cd3d53212a43eec7aa0bc",
"versionType": "git"
},
{
"lessThan": "a09d07ac45e283c9861a9ceea06f56d0ba851d22",
"status": "affected",
"version": "cc15ff3275694fedc33cd3d53212a43eec7aa0bc",
"versionType": "git"
},
{
"lessThan": "72d8d1c36452a4d3ee134b1da48de7518c1329f9",
"status": "affected",
"version": "cc15ff3275694fedc33cd3d53212a43eec7aa0bc",
"versionType": "git"
},
{
"lessThan": "6dcd072a5ae3aed336e4a67a7d4cc5205b240065",
"status": "affected",
"version": "cc15ff3275694fedc33cd3d53212a43eec7aa0bc",
"versionType": "git"
},
{
"lessThan": "8079acc5ee5235a627e4586d4f42082a9000ea64",
"status": "affected",
"version": "cc15ff3275694fedc33cd3d53212a43eec7aa0bc",
"versionType": "git"
},
{
"lessThan": "31467b23823ffec1f6fff407f8e3ca9af8b7491a",
"status": "affected",
"version": "cc15ff3275694fedc33cd3d53212a43eec7aa0bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/powerpc/kernel/time.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()\n\nA kernel panic is observed when handling machine check exceptions from\nreal mode.\n\n BUG: Unable to handle kernel data access on read at 0xc00000006be21300\n Oops: Kernel access of bad area, sig: 11 [#1]\n MSR: 8000000000001003 \u003cSF,ME,RI,LE\u003e CR: 88222248 XER: 00000005\n CFAR: c00000000003ffc4 DAR: c00000006be21300 DSISR: 40000000 IRQMASK: 0\n NIP [c000000000029e40] arch_irq_work_raise+0x10/0x70\n LR [c00000000003ffc8] machine_check_queue_event+0xa8/0x150\n Call Trace:\n [c0000000179d3c70] [c00000000003ff64] machine_check_queue_event+0x44/0x150\n [c0000000179d3d30] [c0000000000084e0] machine_check_early_common+0x1f0/0x2c0\n\nThe crash occurs because arch_irq_work_raise() calls preempt_disable()\nfrom machine check exception (MCE) handlers running in real mode. In\nthis context, accessing the preempt_count can fault, leading to the panic.\n\nThe preempt_disable()/preempt_enable() pair in arch_irq_work_raise()\nwas originally added by commit 0fe1ac48bef0 (\"powerpc/perf_event: Fix\noops due to perf_event_do_pending call\") to avoid races while raising\nirq work from exception context.\n\nLater, commit 471ba0e686cb (\"irq_work: Do not raise an IPI when\nqueueing work on the local CPU\") added preemption protection in\nirq_work_queue() path, while commit 20b876918c06 (\"irq_work: Use per\ncpu atomics instead of regular atomics\") added equivalent\nprotection in irq_work_queue_on() before reaching arch_irq_work_raise():\n\n irq_work_queue() / irq_work_queue_on()\n -\u003e preempt_disable()\n -\u003e __irq_work_queue_local()\n -\u003e irq_work_raise()\n -\u003e arch_irq_work_raise()\n\nAs a result, callers other than mce_irq_work_raise() already execute\nwith preemption disabled, making the additional\npreempt_disable()/preempt_enable() pair in arch_irq_work_raise()\nredundant.\n\nThe arch_irq_work_raise() function executes in NMI context when called\nfrom MCE handler. Hence we will not be preempted or scheduled out since\nwe are in NMI context with MSR[EE]=0. Therefore, it is safe to remove\nthe preempt_disable()/preempt_enable() calls from here.\n\nRemove it to avoid accessing preempt_count from real mode context.\n\n[Maddy: Fixed the commit title]"
}
],
"providerMetadata": {
"dateUpdated": "2026-07-24T15:23:03.529Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/51860e423592893cd7bfa7287d99a3aff4dc3a9d"
},
{
"url": "https://git.kernel.org/stable/c/a09d07ac45e283c9861a9ceea06f56d0ba851d22"
},
{
"url": "https://git.kernel.org/stable/c/72d8d1c36452a4d3ee134b1da48de7518c1329f9"
},
{
"url": "https://git.kernel.org/stable/c/6dcd072a5ae3aed336e4a67a7d4cc5205b240065"
},
{
"url": "https://git.kernel.org/stable/c/8079acc5ee5235a627e4586d4f42082a9000ea64"
},
{
"url": "https://git.kernel.org/stable/c/31467b23823ffec1f6fff407f8e3ca9af8b7491a"
}
],
"title": "powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64214",
"datePublished": "2026-07-24T15:23:03.529Z",
"dateReserved": "2026-07-19T15:36:31.770Z",
"dateUpdated": "2026-07-24T15:23:03.529Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68398 (GCVE-0-2026-68398)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
pppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:
l2tp_udp_encap_recv() -> l2tp_recv_common() -> pppol2tp_recv()
-> ppp_input(&po->chan)
It runs under rcu_read_lock() holding only an l2tp_session reference and
takes NO reference on the internal PPP channel (struct channel,
chan->ppp) that ppp_input() dereferences.
The pppox socket is SOCK_RCU_FREE, so 'po' and the embedded ppp_channel
are RCU-safe. But the internal struct channel is a separate allocation
that ppp_release_channel() frees with a plain kfree():
close(data socket) -> pppol2tp_release() -> pppox_unbind_sock()
-> ppp_unregister_channel() -> ppp_release_channel() -> kfree(pch)
For a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit
(no PPPIOCCONNECT, pch->ppp == NULL) and not bridged, teardown skips
both ppp_disconnect_channel()'s synchronize_net() and
ppp_unbridge_channels()'s synchronize_rcu(), so the kfree() has no grace
period. rcu_read_lock() in pppol2tp_recv() does not protect against a
plain kfree(), so an in-flight ppp_input() on one CPU can dereference
the channel just freed by close() on another CPU.
The bug is reachable by an unprivileged user.
Defer the channel free to an RCU callback via call_rcu() so the grace
period fences any in-flight ppp_input(). The disconnect and unbridge
teardown paths already fence with synchronize_net()/synchronize_rcu();
call_rcu() does the same here without stalling the close() path.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: d36e5ba7bbed5d7bd26e8609ffed503c2def401b Version: 9bcc0508576b2d50efd958f2ea1c5906749c2c89 Version: c2984681fe15cfb803a9132aaaf1140ab20a72c1 Version: 5803ecd7f6ac6f747582e775caa62ac9d0489261 Version: 26f8819ddd10141ebe7bbce700fbab36bfa5f478 Version: 3.2.99 ≤ Version: 3.16.54 ≤ Version: 4.4.225 ≤ Version: 4.9.225 ≤ Version: 4.14.182 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/ppp_generic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4e47f1ac188ece11d6fdabe44166a2776cc5bd4e",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "110b765744b147c63882f5e9cb12931c5dc8d85f",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "4bb84e964ff0fe0a171c965362de72f9820dbce9",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "3ab32218d7182705dae5c86f13925f458072da2c",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "c9574b8a8edeb4edd3ac6472c27ef7184bdb2baa",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "06213c85d8c0994f786c093b8b2a517987943ca6",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "ec4215683e47424c9c4762fd3c60f552a3119142",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"status": "affected",
"version": "d36e5ba7bbed5d7bd26e8609ffed503c2def401b",
"versionType": "git"
},
{
"status": "affected",
"version": "9bcc0508576b2d50efd958f2ea1c5906749c2c89",
"versionType": "git"
},
{
"status": "affected",
"version": "c2984681fe15cfb803a9132aaaf1140ab20a72c1",
"versionType": "git"
},
{
"status": "affected",
"version": "5803ecd7f6ac6f747582e775caa62ac9d0489261",
"versionType": "git"
},
{
"status": "affected",
"version": "26f8819ddd10141ebe7bbce700fbab36bfa5f478",
"versionType": "git"
},
{
"lessThan": "3.3",
"status": "affected",
"version": "3.2.99",
"versionType": "semver"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.54",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.225",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.225",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.182",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/ppp_generic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.2.99",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.54",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.225",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.225",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.182",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF\n\npppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:\n\n l2tp_udp_encap_recv() -\u003e l2tp_recv_common() -\u003e pppol2tp_recv()\n -\u003e ppp_input(\u0026po-\u003echan)\n\nIt runs under rcu_read_lock() holding only an l2tp_session reference and\ntakes NO reference on the internal PPP channel (struct channel,\nchan-\u003eppp) that ppp_input() dereferences.\n\nThe pppox socket is SOCK_RCU_FREE, so \u0027po\u0027 and the embedded ppp_channel\nare RCU-safe. But the internal struct channel is a separate allocation\nthat ppp_release_channel() frees with a plain kfree():\n\n close(data socket) -\u003e pppol2tp_release() -\u003e pppox_unbind_sock()\n -\u003e ppp_unregister_channel() -\u003e ppp_release_channel() -\u003e kfree(pch)\n\nFor a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit\n(no PPPIOCCONNECT, pch-\u003eppp == NULL) and not bridged, teardown skips\nboth ppp_disconnect_channel()\u0027s synchronize_net() and\nppp_unbridge_channels()\u0027s synchronize_rcu(), so the kfree() has no grace\nperiod. rcu_read_lock() in pppol2tp_recv() does not protect against a\nplain kfree(), so an in-flight ppp_input() on one CPU can dereference\nthe channel just freed by close() on another CPU.\n\nThe bug is reachable by an unprivileged user.\n\nDefer the channel free to an RCU callback via call_rcu() so the grace\nperiod fences any in-flight ppp_input(). The disconnect and unbridge\nteardown paths already fence with synchronize_net()/synchronize_rcu();\ncall_rcu() does the same here without stalling the close() path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The free side of the race is a local close() of the pppol2tp socket, which no remote peer can invoke; the full attack (create tunnel/session via AF_PPPOX socket, drive RX with loopback UDP datagrams, close concurrently) is performed entirely through local syscalls.\nAC:L - The attacker controls both sides of the race, feeding the UDP-encap RX softirq from one thread while closing the pppox socket on another, and can retry the loop indefinitely until the window is hit.\nPR:L - No capability check exists on this path: pppox_create()/pppol2tp_connect() and ppp_register_net_channel() need no CAP_NET_ADMIN, and PPPIOCGCHAN is handled by pppox_ioctl() on the socket itself, so /dev/ppp access is not required; the fix commit states the bug is reachable by an unprivileged user.\nUI:N - The attacker performs every step \u2014 socket creation, session setup, packet injection and close() \u2014 with no action by any other user or administrator.\nS:U - The use-after-free corrupts kernel slab memory within the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - After the channel is freed and its slab object reallocated, ppp_input() reads pch-\u003ebridge and pch-\u003eppp from attacker-groomed memory and can route received frames to an arbitrary attacker-chosen structure, giving a path to disclosing kernel memory.\nI:H - skb_queue_tail(\u0026pch-\u003efile.rq, skb) writes a linked-list insertion into the freed object and wake_up_interruptible(\u0026pch-\u003efile.rwait) traverses a freed waitqueue, so heap grooming yields controlled writes and function-pointer traversal usable for privilege escalation.\nA:H - Dereferencing and writing to the kfree()d struct channel from softirq context reliably corrupts the slab and panics or oopses the kernel, and the race can be re-triggered at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:49.839Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4e47f1ac188ece11d6fdabe44166a2776cc5bd4e"
},
{
"url": "https://git.kernel.org/stable/c/110b765744b147c63882f5e9cb12931c5dc8d85f"
},
{
"url": "https://git.kernel.org/stable/c/4bb84e964ff0fe0a171c965362de72f9820dbce9"
},
{
"url": "https://git.kernel.org/stable/c/3ab32218d7182705dae5c86f13925f458072da2c"
},
{
"url": "https://git.kernel.org/stable/c/c9574b8a8edeb4edd3ac6472c27ef7184bdb2baa"
},
{
"url": "https://git.kernel.org/stable/c/06213c85d8c0994f786c093b8b2a517987943ca6"
},
{
"url": "https://git.kernel.org/stable/c/ec4215683e47424c9c4762fd3c60f552a3119142"
}
],
"title": "ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68398",
"datePublished": "2026-08-10T12:04:17.771Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:49.839Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68166 (GCVE-0-2026-68166)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
userfaultfd: prevent registration of special VMAs
Vova Tokarev says:
userfaultfd allows registration on shadow stack VMAs. With userfaultfd
access, you can register on the shadow stack, discard a page ... and
inject a page with chosen return addresses via UFFDIO_COPY.
Update vma_can_userfault() to reject VM_SHADOW_STACK.
While on it, also reject VM_SPECIAL so that if a driver would implement
vm_uffd_ops, it wouldn't be possible to register special VMAs with
userfaultfd.
Since VM_SPECIAL includes VM_DONTEXPAND which is set but hugetlb, exclude
hugetlb VMAs from the check for VM_SPECIAL.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/userfaultfd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d974b4b786214883bd8e56bda10b454c80fd6205",
"status": "affected",
"version": "54007f818206dc27309ca423df4c87dd160a7208",
"versionType": "git"
},
{
"lessThan": "495a28d5a100be1b232633f4c2dcc42ba10b3796",
"status": "affected",
"version": "54007f818206dc27309ca423df4c87dd160a7208",
"versionType": "git"
},
{
"lessThan": "165613191ad9d034bf17c00e3a142f9561597ec5",
"status": "affected",
"version": "54007f818206dc27309ca423df4c87dd160a7208",
"versionType": "git"
},
{
"lessThan": "0c26202b157f1efc3cd2f26f5c30f59b508a6a5d",
"status": "affected",
"version": "54007f818206dc27309ca423df4c87dd160a7208",
"versionType": "git"
},
{
"lessThan": "3c58f641e813c3c71039f8fd4d4e2a3aab713288",
"status": "affected",
"version": "54007f818206dc27309ca423df4c87dd160a7208",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/userfaultfd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: prevent registration of special VMAs\n\nVova Tokarev says:\n\n userfaultfd allows registration on shadow stack VMAs. With userfaultfd\n access, you can register on the shadow stack, discard a page ... and\n inject a page with chosen return addresses via UFFDIO_COPY.\n\nUpdate vma_can_userfault() to reject VM_SHADOW_STACK.\n\nWhile on it, also reject VM_SPECIAL so that if a driver would implement\nvm_uffd_ops, it wouldn\u0027t be possible to register special VMAs with\nuserfaultfd.\n\nSince VM_SPECIAL includes VM_DONTEXPAND which is set but hugetlb, exclude\nhugetlb VMAs from the check for VM_SPECIAL."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:02.309Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d974b4b786214883bd8e56bda10b454c80fd6205"
},
{
"url": "https://git.kernel.org/stable/c/495a28d5a100be1b232633f4c2dcc42ba10b3796"
},
{
"url": "https://git.kernel.org/stable/c/165613191ad9d034bf17c00e3a142f9561597ec5"
},
{
"url": "https://git.kernel.org/stable/c/0c26202b157f1efc3cd2f26f5c30f59b508a6a5d"
},
{
"url": "https://git.kernel.org/stable/c/3c58f641e813c3c71039f8fd4d4e2a3aab713288"
}
],
"title": "userfaultfd: prevent registration of special VMAs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68166",
"datePublished": "2026-08-10T11:59:34.576Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-23T12:46:02.309Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63944 (GCVE-0-2026-63944)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
hci_le_create_cis_sync() dereferences conn->conn_timeout after releasing
both rcu_read_lock() and hci_dev_lock(hdev). The conn pointer was
obtained from an RCU-protected iteration over hdev->conn_hash.list and
is not valid once these locks are dropped. A concurrent disconnect can
free the hci_conn between the unlock and the dereference, causing a
use-after-free read.
The cancellation mechanism in hci_conn_del() cannot prevent this because
hci_le_create_cis_pending() queues hci_create_cis_sync with data=NULL:
hci_cmd_sync_queue(hdev, hci_create_cis_sync, NULL, NULL);
While hci_conn_del() dequeues with data=conn:
hci_cmd_sync_dequeue(hdev, NULL, conn, NULL);
Since NULL != conn, the lookup in _hci_cmd_sync_lookup_entry() never
matches, and the pending work item is not cancelled.
Fix this by saving conn->conn_timeout into a local variable while the
locks are still held, so the stale conn pointer is never dereferenced
after unlock.
This is the same class of bug as the one fixed by commit 035c25007c9e
("Bluetooth: hci_sync: Fix UAF on le_read_features_complete") which
addressed the identical pattern in a different function.
This vulnerability was identified using 0sec.ai, an open-source
automated security auditing platform (https://github.com/0sec-labs).
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a55618c0f4cead9e59c63f5ee030d393fd70d861",
"status": "affected",
"version": "c09b80be6ffc338634b2f5f8cfa12b6843410834",
"versionType": "git"
},
{
"lessThan": "a921957d39290143629eb38c4f74b9bef8035d0a",
"status": "affected",
"version": "c09b80be6ffc338634b2f5f8cfa12b6843410834",
"versionType": "git"
},
{
"lessThan": "d9019210c8c30d40eb20094274cc647e352f48f7",
"status": "affected",
"version": "c09b80be6ffc338634b2f5f8cfa12b6843410834",
"versionType": "git"
},
{
"lessThan": "380e67b1794a9a281a0cb592b4e62077fbd0c8ca",
"status": "affected",
"version": "c09b80be6ffc338634b2f5f8cfa12b6843410834",
"versionType": "git"
},
{
"lessThan": "bfea6091e0fffb270c20e74384b660910277eb6c",
"status": "affected",
"version": "c09b80be6ffc338634b2f5f8cfa12b6843410834",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: fix UAF in hci_le_create_cis_sync\n\nhci_le_create_cis_sync() dereferences conn-\u003econn_timeout after releasing\nboth rcu_read_lock() and hci_dev_lock(hdev). The conn pointer was\nobtained from an RCU-protected iteration over hdev-\u003econn_hash.list and\nis not valid once these locks are dropped. A concurrent disconnect can\nfree the hci_conn between the unlock and the dereference, causing a\nuse-after-free read.\n\nThe cancellation mechanism in hci_conn_del() cannot prevent this because\nhci_le_create_cis_pending() queues hci_create_cis_sync with data=NULL:\n\n hci_cmd_sync_queue(hdev, hci_create_cis_sync, NULL, NULL);\n\nWhile hci_conn_del() dequeues with data=conn:\n\n hci_cmd_sync_dequeue(hdev, NULL, conn, NULL);\n\nSince NULL != conn, the lookup in _hci_cmd_sync_lookup_entry() never\nmatches, and the pending work item is not cancelled.\n\nFix this by saving conn-\u003econn_timeout into a local variable while the\nlocks are still held, so the stale conn pointer is never dereferenced\nafter unlock.\n\nThis is the same class of bug as the one fixed by commit 035c25007c9e\n(\"Bluetooth: hci_sync: Fix UAF on le_read_features_complete\") which\naddressed the identical pattern in a different function.\n\nThis vulnerability was identified using 0sec.ai, an open-source\nautomated security auditing platform (https://github.com/0sec-labs)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is in the Bluetooth HCI ISO/CIS path (`hci_le_create_cis_sync`), reachable only via the Bluetooth radio interface. Per kernel CVSS guidance, Bluetooth vulnerabilities are scored as Adjacent, including on phones and LE Audio devices in public spaces.\nAC:L - The UAF is a race between `hci_le_create_cis_sync` dropping locks and a concurrent `hci_conn_del`. An attacker who controls one side of the CIS setup (local ISO socket threads or a remote peer timing ACL/CIS teardown) can repeatedly trigger the race; success does not depend on uncontrollable conditions like kernel memory layout.\nPR:N - No local Unix privileges are required for the highest-impact scenario: a remote Bluetooth peer in range can provoke CIS teardown/disconnect events while the victim host is performing normal LE Audio CIS establishment (e.g., phone connecting to earbuds). Local exploitation via ISO sockets also requires no special capabilities at the kernel level.\nUI:N - Both sides of the race run inside the kernel\u0027s own HCI event handling: hci_le_create_cis_pending() queues the vulnerable work from hci_le_cis_established_evt(), hci_cs_le_create_cis(), hci_unbound_cis_failed() and iso_connect_cfm(), all driven by controller events and remote peer traffic, while the freeing side is a peer-initiated disconnect reaching hci_conn_del(). On an LE Audio host the CIS establishment happens by itself when the earbuds connect and the attacker supplies the disconnect, so nothing is asked of the person holding the device; the existing pairing is a precondition of the deployment, not an in-attack user step.\nS:U - Impact is confined to kernel memory corruption within the Bluetooth subsystem on the host; this is standard kernel compromise, not a cross-boundary escape (KVM guest-to-host, IOMMU bypass, or sandbox breakout).\nC:H - This is a slab use-after-free read of `conn-\u003econn_timeout` on a freed `hci_conn` (kmalloc-8k object). UAF reads against attacker-influencable freed objects can disclose kernel heap contents and are scored as High per kernel CVSS guidance.\nI:H - Although the immediate bug is a post-unlock dereference of a freed `hci_conn`, UAF on large `hci_conn` kmalloc objects enables heap grooming and control of freed memory contents, which can be chained into arbitrary kernel writes or code execution; UAF class bugs are scored I:H.\nA:H - Use-after-free access to a freed connection object can cause kernel oops/panic (as demonstrated by the same bug class in the related `le_read_features_complete` fix found by syzkaller). Even without full exploitation, triggering the UAF reliably causes High availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:30.950Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a55618c0f4cead9e59c63f5ee030d393fd70d861"
},
{
"url": "https://git.kernel.org/stable/c/a921957d39290143629eb38c4f74b9bef8035d0a"
},
{
"url": "https://git.kernel.org/stable/c/d9019210c8c30d40eb20094274cc647e352f48f7"
},
{
"url": "https://git.kernel.org/stable/c/380e67b1794a9a281a0cb592b4e62077fbd0c8ca"
},
{
"url": "https://git.kernel.org/stable/c/bfea6091e0fffb270c20e74384b660910277eb6c"
}
],
"title": "Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63944",
"datePublished": "2026-07-19T14:55:39.105Z",
"dateReserved": "2026-07-19T07:54:57.022Z",
"dateUpdated": "2026-08-05T12:37:30.950Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64005 (GCVE-0-2026-64005)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/smc: Do not re-initialize smc hashtables
INIT_HLIST_HEAD(&smc_v*_hashinfo.ht) are called after smc_nl_init(),
proto_register() and sock_register(). This can lead to smc_v*_hashinfo.ht
being reset even though hash entries already exist and are being used,
possibly resulting in a corrupted list.
Remove unnecessary and dangerous re-initialisation of smc_v*_hashinfo.ht in
smc_init(); it is implicitly initialised to zero anyhow. Add
HLIST_HEAD_INIT to the definitions for clarity.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f16a7dd5cf27eeda187425c9c7d96802a549f9c4 Version: f16a7dd5cf27eeda187425c9c7d96802a549f9c4 Version: f16a7dd5cf27eeda187425c9c7d96802a549f9c4 Version: f16a7dd5cf27eeda187425c9c7d96802a549f9c4 Version: f16a7dd5cf27eeda187425c9c7d96802a549f9c4 Version: f16a7dd5cf27eeda187425c9c7d96802a549f9c4 Version: f16a7dd5cf27eeda187425c9c7d96802a549f9c4 Version: f16a7dd5cf27eeda187425c9c7d96802a549f9c4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/af_smc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cdc79c05cc375f68ae87b0c74fdaac1a5c93155a",
"status": "affected",
"version": "f16a7dd5cf27eeda187425c9c7d96802a549f9c4",
"versionType": "git"
},
{
"lessThan": "2006605006e5a4a11d93e1ebdbbe95764d24276f",
"status": "affected",
"version": "f16a7dd5cf27eeda187425c9c7d96802a549f9c4",
"versionType": "git"
},
{
"lessThan": "64c96e497d5ada0b90e99bf58f893aa2b73dcfbc",
"status": "affected",
"version": "f16a7dd5cf27eeda187425c9c7d96802a549f9c4",
"versionType": "git"
},
{
"lessThan": "ed7a758313011885347b854e97cb95903ef3c3f7",
"status": "affected",
"version": "f16a7dd5cf27eeda187425c9c7d96802a549f9c4",
"versionType": "git"
},
{
"lessThan": "0cc9d0ac22d02f1ba1884de5d6de9eaf8b45d82d",
"status": "affected",
"version": "f16a7dd5cf27eeda187425c9c7d96802a549f9c4",
"versionType": "git"
},
{
"lessThan": "55cba6b883b41e5922c00ba9d4e3262131f46f1b",
"status": "affected",
"version": "f16a7dd5cf27eeda187425c9c7d96802a549f9c4",
"versionType": "git"
},
{
"lessThan": "5ec939367e700722ffbb1b7cacccbb1a3cf0ebd1",
"status": "affected",
"version": "f16a7dd5cf27eeda187425c9c7d96802a549f9c4",
"versionType": "git"
},
{
"lessThan": "9e4389b0038781f19f97895186ed941ff8ac1678",
"status": "affected",
"version": "f16a7dd5cf27eeda187425c9c7d96802a549f9c4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/af_smc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: Do not re-initialize smc hashtables\n\nINIT_HLIST_HEAD(\u0026smc_v*_hashinfo.ht) are called after smc_nl_init(),\nproto_register() and sock_register(). This can lead to smc_v*_hashinfo.ht\nbeing reset even though hash entries already exist and are being used,\npossibly resulting in a corrupted list.\n\nRemove unnecessary and dangerous re-initialisation of smc_v*_hashinfo.ht in\nsmc_init(); it is implicitly initialised to zero anyhow. Add\nHLIST_HEAD_INIT to the definitions for clarity."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires winning a race during SMC module initialization by concurrently calling socket(PF_SMC)/socket(AF_INET, SOCK_STREAM, IPPROTO_SMC) syscalls. The bug is not reachable from remote network packet handling; SMC network upgrade paths operate only after initialization completes.\nAC:L - An attacker controls both sides of the race by spawning concurrent threads that hammer socket creation while another thread triggers SMC module autoload via request_module(\"net-pf-43\") during sock_register(). The vulnerable window between sock_register() and INIT_HLIST_HEAD() is narrow but attacker-driven and repeatable on each module load/reload.\nPR:L - Creating PF_SMC or IPPROTO_SMC sockets requires only an unprivileged local user account; no CAP_NET_ADMIN, CAP_SYS_MODULE, or real root in the initial namespace is needed to participate in the race when module autoload is enabled. Triggering module load may require admin action on hardened systems, but the corrupting socket operations themselves need only basic local privileges.\nUI:N - No victim interaction is required beyond the attacker\u0027s own concurrent socket creation during module initialization; no mount, file open, or other user action is needed.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same kernel security boundary; this is not a VM escape, IOMMU bypass, or cross-authority sandbox escape.\nC:H - Resetting smc_v4/v6_hashinfo.ht after sockets are hashed orphans live sk_node entries; subsequent hlist traversal in smc_diag_dump_proto() or corrupted pointer chasing can read arbitrary kernel memory adjacent to socket structures.\nI:H - Orphaned hlist nodes cause __hlist_del() in smc_unhash_sk() to write through stale pprev/next pointers when corrupted sockets are closed, enabling exploitable kernel heap/list corruption and potential control-flow hijacking.\nA:H - List corruption reliably causes kernel oops or panic when orphaned sockets are unhashed (__hlist_del with NULL next) or when the corrupted hashtable is walked, resulting in complete loss of kernel availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:05.933Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cdc79c05cc375f68ae87b0c74fdaac1a5c93155a"
},
{
"url": "https://git.kernel.org/stable/c/2006605006e5a4a11d93e1ebdbbe95764d24276f"
},
{
"url": "https://git.kernel.org/stable/c/64c96e497d5ada0b90e99bf58f893aa2b73dcfbc"
},
{
"url": "https://git.kernel.org/stable/c/ed7a758313011885347b854e97cb95903ef3c3f7"
},
{
"url": "https://git.kernel.org/stable/c/0cc9d0ac22d02f1ba1884de5d6de9eaf8b45d82d"
},
{
"url": "https://git.kernel.org/stable/c/55cba6b883b41e5922c00ba9d4e3262131f46f1b"
},
{
"url": "https://git.kernel.org/stable/c/5ec939367e700722ffbb1b7cacccbb1a3cf0ebd1"
},
{
"url": "https://git.kernel.org/stable/c/9e4389b0038781f19f97895186ed941ff8ac1678"
}
],
"title": "net/smc: Do not re-initialize smc hashtables",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64005",
"datePublished": "2026-07-19T14:56:21.608Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-08-05T12:38:05.933Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72296 (GCVE-0-2026-72296)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-17 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: ife: require ETH_HLEN to be pullable in ife_decode()
ife decode may return after making only the outer IFE header and
metadata pullable. The caller then passes the decapsulated packet to
eth_type_trans(), which expects the inner Ethernet header to be
accessible from the linear data area.
With a malformed IFE frame, the inner Ethernet header may still be
shorter than ETH_HLEN in the linear area, which can lead to a crash in
the original code.
Fix this by extending the pull check in ife_decode() so that the inner
Ethernet header is also guaranteed to be pullable before returning.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ef6980b6becb1afd9d82a4f043749a10ae81bf14 Version: ef6980b6becb1afd9d82a4f043749a10ae81bf14 Version: ef6980b6becb1afd9d82a4f043749a10ae81bf14 Version: ef6980b6becb1afd9d82a4f043749a10ae81bf14 Version: ef6980b6becb1afd9d82a4f043749a10ae81bf14 Version: ef6980b6becb1afd9d82a4f043749a10ae81bf14 Version: ef6980b6becb1afd9d82a4f043749a10ae81bf14 Version: ef6980b6becb1afd9d82a4f043749a10ae81bf14 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ife/ife.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "70013f9163bef7fbd9fa62f81cf91b2a7ba66163",
"status": "affected",
"version": "ef6980b6becb1afd9d82a4f043749a10ae81bf14",
"versionType": "git"
},
{
"lessThan": "be272e159dfe1207b67332ad6e17adcf59b4ea4b",
"status": "affected",
"version": "ef6980b6becb1afd9d82a4f043749a10ae81bf14",
"versionType": "git"
},
{
"lessThan": "8c8818e52fddb247ff3214622401a4de6ff8482e",
"status": "affected",
"version": "ef6980b6becb1afd9d82a4f043749a10ae81bf14",
"versionType": "git"
},
{
"lessThan": "9433578bff9c100c466a6354574892e55293cb8f",
"status": "affected",
"version": "ef6980b6becb1afd9d82a4f043749a10ae81bf14",
"versionType": "git"
},
{
"lessThan": "1cb42ec10294a55380e52e674b3df2b962648242",
"status": "affected",
"version": "ef6980b6becb1afd9d82a4f043749a10ae81bf14",
"versionType": "git"
},
{
"lessThan": "5526d1997aea6c9bd865ca4d4894b52e799d735c",
"status": "affected",
"version": "ef6980b6becb1afd9d82a4f043749a10ae81bf14",
"versionType": "git"
},
{
"lessThan": "b69ad768cd4a2ef4e07c18492ae85438ed17c7cb",
"status": "affected",
"version": "ef6980b6becb1afd9d82a4f043749a10ae81bf14",
"versionType": "git"
},
{
"lessThan": "9406f6012b7343661efb516a11c62d4db2b62f75",
"status": "affected",
"version": "ef6980b6becb1afd9d82a4f043749a10ae81bf14",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ife/ife.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ife: require ETH_HLEN to be pullable in ife_decode()\n\nife decode may return after making only the outer IFE header and\nmetadata pullable. The caller then passes the decapsulated packet to\neth_type_trans(), which expects the inner Ethernet header to be\naccessible from the linear data area.\n\nWith a malformed IFE frame, the inner Ethernet header may still be\nshorter than ETH_HLEN in the linear area, which can lead to a crash in\nthe original code.\n\nFix this by extending the pull check in ife_decode() so that the inner\nEthernet header is also guaranteed to be pullable before returning."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is hit on the ingress packet receive path (__netif_receive_skb_core\u2192sch_handle_ingress\u2192tc_run\u2192tcf_ife_act\u2192ife_decode) when a remote peer sends a malformed IFE-encapsulated Ethernet frame to a netdev with clsact/ingress IFE decode, as in SDN/NFV/ForCES edge nodes.\nAC:L - Once ingress IFE decode is present, the attacker fully controls the crafted frame (metalen, metadata size, and skb layout) to leave the inner Ethernet header non-linear or shorter than ETH_HLEN, deterministically reaching eth_type_trans() without races or uncontrollable memory layout.\nPR:N - Remote exploitation needs no credentials or capabilities on the victim\u2014only delivery of a malformed frame to an interface already configured with IFE decode; CAP_NET_ADMIN is an operator deployment prerequisite, not attacker privilege (same model as pre-configured nftables offload bugs).\nUI:N - No victim user action is required beyond normal network delivery of attacker-crafted IFE traffic; exploitation does not depend on mounting, opening files, or administrator interaction at attack time.\nS:U - Impact is confined to kernel packet-processing memory within the same kernel security authority; this is not a VM escape, IOMMU bypass, or cross-namespace scope change.\nC:H - eth_type_trans() reads the inner struct ethhdr (h_dest/h_proto) via eth_skb_pull_mac()/eth_skb_pkt_type() without ensuring ETH_HLEN bytes are linear, causing an out-of-bounds kernel read that can disclose adjacent skb/page memory beyond a few bytes.\nI:N - The defect is a missing pskb_may_pull() bounds check leading to out-of-bounds reads and crash; there is no write, UAF, or demonstrated arbitrary modification or control-flow hijack primitive.\nA:H - The fix commit states malformed IFE frames can crash the kernel; accessing a non-linear or undersized inner Ethernet header in eth_type_trans() can trigger KASAN faults, oops, or panic on the softirq receive path."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:42:29.172Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/70013f9163bef7fbd9fa62f81cf91b2a7ba66163"
},
{
"url": "https://git.kernel.org/stable/c/be272e159dfe1207b67332ad6e17adcf59b4ea4b"
},
{
"url": "https://git.kernel.org/stable/c/8c8818e52fddb247ff3214622401a4de6ff8482e"
},
{
"url": "https://git.kernel.org/stable/c/9433578bff9c100c466a6354574892e55293cb8f"
},
{
"url": "https://git.kernel.org/stable/c/1cb42ec10294a55380e52e674b3df2b962648242"
},
{
"url": "https://git.kernel.org/stable/c/5526d1997aea6c9bd865ca4d4894b52e799d735c"
},
{
"url": "https://git.kernel.org/stable/c/b69ad768cd4a2ef4e07c18492ae85438ed17c7cb"
},
{
"url": "https://git.kernel.org/stable/c/9406f6012b7343661efb516a11c62d4db2b62f75"
}
],
"title": "net: ife: require ETH_HLEN to be pullable in ife_decode()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72296",
"datePublished": "2026-08-15T05:55:17.250Z",
"dateReserved": "2026-08-09T03:40:39.917Z",
"dateUpdated": "2026-08-17T05:42:29.172Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64180 (GCVE-0-2026-64180)
Vulnerability from cvelistv5
Published
2026-07-19 15:41
Modified
2026-07-19 15:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/memory_hotplug: fix memory block reference leak on remove
Patch series "mm: Fix memory block leaks and locking", v2.
This series fixes two memory block device reference leaks and one locking
issue around the per-memory_block hwpoison counter.
This patch (of 2):
remove_memory_blocks_and_altmaps() looks up each memory block with
find_memory_block(), which acquires a reference to the memory block
device.
That reference is never dropped on this path, resulting in a leaked device
reference when removing memory blocks and their altmaps. Drop the
reference after retrieving mem->altmap and clearing mem->altmap, before
removing the memory block device.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/memory_hotplug.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b8ab30c79fc00147125b9c39f928561d9dd13d06",
"status": "affected",
"version": "6b8f0798b85aa529011570369db985a788f3003f",
"versionType": "git"
},
{
"lessThan": "09ce923071e7852ece60d7368e05249bf32c7967",
"status": "affected",
"version": "6b8f0798b85aa529011570369db985a788f3003f",
"versionType": "git"
},
{
"lessThan": "df64c0d21c3f85f844b2f656333e43d97e6ffa74",
"status": "affected",
"version": "6b8f0798b85aa529011570369db985a788f3003f",
"versionType": "git"
},
{
"lessThan": "93866f55f7e292fe3d47d36c9efe5ee10213a06b",
"status": "affected",
"version": "6b8f0798b85aa529011570369db985a788f3003f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/memory_hotplug.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/memory_hotplug: fix memory block reference leak on remove\n\nPatch series \"mm: Fix memory block leaks and locking\", v2.\n\nThis series fixes two memory block device reference leaks and one locking\nissue around the per-memory_block hwpoison counter.\n\n\nThis patch (of 2):\n\nremove_memory_blocks_and_altmaps() looks up each memory block with\nfind_memory_block(), which acquires a reference to the memory block\ndevice.\n\nThat reference is never dropped on this path, resulting in a leaked device\nreference when removing memory blocks and their altmaps. Drop the\nreference after retrieving mem-\u003ealtmap and clearing mem-\u003ealtmap, before\nremoving the memory block device."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:41:03.751Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b8ab30c79fc00147125b9c39f928561d9dd13d06"
},
{
"url": "https://git.kernel.org/stable/c/09ce923071e7852ece60d7368e05249bf32c7967"
},
{
"url": "https://git.kernel.org/stable/c/df64c0d21c3f85f844b2f656333e43d97e6ffa74"
},
{
"url": "https://git.kernel.org/stable/c/93866f55f7e292fe3d47d36c9efe5ee10213a06b"
}
],
"title": "mm/memory_hotplug: fix memory block reference leak on remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64180",
"datePublished": "2026-07-19T15:41:03.751Z",
"dateReserved": "2026-07-19T07:54:57.039Z",
"dateUpdated": "2026-07-19T15:41:03.751Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53096 (GCVE-0-2026-53096)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-08-05 12:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
The DEVMAP_HASH branch in dev_map_redirect_multi() uses
hlist_for_each_entry_safe() to iterate hash buckets, but this function
runs under RCU protection (called from xdp_do_generic_redirect_map()
in softirq context). Concurrent writers (__dev_map_hash_update_elem,
dev_map_hash_delete_elem) modify the list using RCU primitives
(hlist_add_head_rcu, hlist_del_rcu).
hlist_for_each_entry_safe() performs plain pointer dereferences without
rcu_dereference(), missing the acquire barrier needed to pair with
writers' rcu_assign_pointer(). On weakly-ordered architectures (ARM64,
POWER), a reader can observe a partially-constructed node. It also
defeats CONFIG_PROVE_RCU lockdep validation and KCSAN data-race
detection.
Replace with hlist_for_each_entry_rcu() using rcu_read_lock_bh_held()
as the lockdep condition, consistent with the rcu_dereference_check()
used in the DEVMAP (non-hash) branch of the same functions. Also fix
the same incorrect lockdep_is_held(&dtab->index_lock) condition in
dev_map_enqueue_multi(), where the lock is not held either.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/bpf/devmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4a3d0fe30b907ff324b1b49756f7e713d67f3645",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "b089aa6e94d7a08e74d076a0fe274842dc9feccc",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "571a05ea1baaccc0dc1e0d227b2cbc978b96d392",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "cb2c1f3cf65b855548e1b8d55a08bfbaa5a0901a",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "d4c4bd231ebad70e6f30db429e9640bf378b2f52",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "7027e705062482a8cea43a1c13ede3c35653966f",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "8ed82f807bb09d2c8455aaa665f2c6cb17bc6a19",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/bpf/devmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path\n\nThe DEVMAP_HASH branch in dev_map_redirect_multi() uses\nhlist_for_each_entry_safe() to iterate hash buckets, but this function\nruns under RCU protection (called from xdp_do_generic_redirect_map()\nin softirq context). Concurrent writers (__dev_map_hash_update_elem,\ndev_map_hash_delete_elem) modify the list using RCU primitives\n(hlist_add_head_rcu, hlist_del_rcu).\n\nhlist_for_each_entry_safe() performs plain pointer dereferences without\nrcu_dereference(), missing the acquire barrier needed to pair with\nwriters\u0027 rcu_assign_pointer(). On weakly-ordered architectures (ARM64,\nPOWER), a reader can observe a partially-constructed node. It also\ndefeats CONFIG_PROVE_RCU lockdep validation and KCSAN data-race\ndetection.\n\nReplace with hlist_for_each_entry_rcu() using rcu_read_lock_bh_held()\nas the lockdep condition, consistent with the rcu_dereference_check()\nused in the DEVMAP (non-hash) branch of the same functions. Also fix\nthe same incorrect lockdep_is_held(\u0026dtab-\u003eindex_lock) condition in\ndev_map_enqueue_multi(), where the lock is not held either."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path requires local BPF/netlink setup of an XDP program using a DEVMAP_HASH broadcast redirect and concurrent map update/delete operations. Network packets can trigger the packet-side reader after setup, but the exploit control path is local.\nAC:L - The attacker can control both sides of the race by driving packets through the attached XDP program while another local thread updates or deletes devmap-hash entries. Weakly ordered architectures such as ARM64/POWER are common reasonable deployments, so this is not a rare external condition.\nPR:L - The path requires BPF/CAP_NET_ADMIN-style privileges to create/update the map and load/attach XDP, but these can be available to a low-privileged local attacker through namespace/delegated BPF-token scenarios. It is not reachable by an unauthenticated remote attacker.\nUI:N - No victim action is needed once the attacker has the local privileges and can run the racing BPF/map operations. Packet delivery and map syscalls are attacker-driven.\nS:U - The impact remains within the kernel and the network namespace/security authority being attacked. This is standard kernel memory-safety exposure, not a VM escape or separate-scope boundary bypass.\nC:H - The unsafe non-RCU traversal can observe partially constructed or inconsistent bpf_dtab_netdev objects and dereference attacker-influenced stale kernel pointers. Given the kernel pointer misuse and heap-shaping potential, high confidentiality impact is defensible.\nI:H - The same stale or partially initialized dev/xdp_prog pointers can be used in redirect and BPF program execution paths, making control-flow or object-confusion style corruption plausible. Under the required overestimate rule, this supports high integrity impact.\nA:H - At minimum, dereferencing inconsistent devmap entries can crash or oops the kernel in the packet redirect path. The race is repeatable by the local attacker, so availability impact is high."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:33:21.982Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4a3d0fe30b907ff324b1b49756f7e713d67f3645"
},
{
"url": "https://git.kernel.org/stable/c/b089aa6e94d7a08e74d076a0fe274842dc9feccc"
},
{
"url": "https://git.kernel.org/stable/c/571a05ea1baaccc0dc1e0d227b2cbc978b96d392"
},
{
"url": "https://git.kernel.org/stable/c/cb2c1f3cf65b855548e1b8d55a08bfbaa5a0901a"
},
{
"url": "https://git.kernel.org/stable/c/d4c4bd231ebad70e6f30db429e9640bf378b2f52"
},
{
"url": "https://git.kernel.org/stable/c/7027e705062482a8cea43a1c13ede3c35653966f"
},
{
"url": "https://git.kernel.org/stable/c/8ed82f807bb09d2c8455aaa665f2c6cb17bc6a19"
}
],
"title": "bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53096",
"datePublished": "2026-06-24T16:30:34.477Z",
"dateReserved": "2026-06-09T07:44:35.384Z",
"dateUpdated": "2026-08-05T12:33:21.982Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64271 (GCVE-0-2026-64271)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: touchwin - reset the packet index on every complete packet
tw_interrupt() accumulates each non-zero serial byte into a fixed
three-byte buffer with a running index that is only reset once a full
packet has been received *and* the device's two Y bytes agree:
tw->data[tw->idx++] = data;
if (tw->idx == TW_LENGTH && tw->data[1] == tw->data[2]) {
...
tw->idx = 0;
}
The reset is gated on tw->data[1] == tw->data[2], a value the device
controls. A malicious, malfunctioning or counterfeit Touchwindow
peripheral can stream non-zero bytes whose 2nd and 3rd bytes differ: the
index reaches TW_LENGTH without the equality holding, is never reset, and
keeps growing, so tw->data[tw->idx++] walks off the end of the three-byte
array and the rest of the heap-allocated struct tw, one attacker-chosen
byte at a time -- an unbounded, device-driven heap out-of-bounds write.
Reset the index on every completed packet and report an event only when
the two Y bytes match, like the other serio touchscreen drivers do.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 11ea3173d5f2de71d037ef58ac43395795fed2bc Version: 11ea3173d5f2de71d037ef58ac43395795fed2bc Version: 11ea3173d5f2de71d037ef58ac43395795fed2bc Version: 11ea3173d5f2de71d037ef58ac43395795fed2bc Version: 11ea3173d5f2de71d037ef58ac43395795fed2bc Version: 11ea3173d5f2de71d037ef58ac43395795fed2bc Version: 11ea3173d5f2de71d037ef58ac43395795fed2bc Version: 11ea3173d5f2de71d037ef58ac43395795fed2bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/touchwin.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ed9b66905407eb3d02df1aaeed82eb7a7f0eb508",
"status": "affected",
"version": "11ea3173d5f2de71d037ef58ac43395795fed2bc",
"versionType": "git"
},
{
"lessThan": "044167cba2384bcd783547ad5e30ecd292b30919",
"status": "affected",
"version": "11ea3173d5f2de71d037ef58ac43395795fed2bc",
"versionType": "git"
},
{
"lessThan": "6c9f29f128dd4057404838259af4c645318487e1",
"status": "affected",
"version": "11ea3173d5f2de71d037ef58ac43395795fed2bc",
"versionType": "git"
},
{
"lessThan": "431ad239f2924dff337c3fccb9246597c1b63185",
"status": "affected",
"version": "11ea3173d5f2de71d037ef58ac43395795fed2bc",
"versionType": "git"
},
{
"lessThan": "70e4248793762df9832fd4fc2fc6ac7924572c36",
"status": "affected",
"version": "11ea3173d5f2de71d037ef58ac43395795fed2bc",
"versionType": "git"
},
{
"lessThan": "3e6f007b43e2fc6546e21fa74ee62c38984a6672",
"status": "affected",
"version": "11ea3173d5f2de71d037ef58ac43395795fed2bc",
"versionType": "git"
},
{
"lessThan": "a8d87184576c889759e3aab899799a482f1e1a5b",
"status": "affected",
"version": "11ea3173d5f2de71d037ef58ac43395795fed2bc",
"versionType": "git"
},
{
"lessThan": "478cdd736f2ce3114f90e775d7358136d3977b94",
"status": "affected",
"version": "11ea3173d5f2de71d037ef58ac43395795fed2bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/touchwin.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.19"
},
{
"lessThan": "2.6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: touchwin - reset the packet index on every complete packet\n\ntw_interrupt() accumulates each non-zero serial byte into a fixed\nthree-byte buffer with a running index that is only reset once a full\npacket has been received *and* the device\u0027s two Y bytes agree:\n\n\ttw-\u003edata[tw-\u003eidx++] = data;\n\tif (tw-\u003eidx == TW_LENGTH \u0026\u0026 tw-\u003edata[1] == tw-\u003edata[2]) {\n\t\t...\n\t\ttw-\u003eidx = 0;\n\t}\n\nThe reset is gated on tw-\u003edata[1] == tw-\u003edata[2], a value the device\ncontrols. A malicious, malfunctioning or counterfeit Touchwindow\nperipheral can stream non-zero bytes whose 2nd and 3rd bytes differ: the\nindex reaches TW_LENGTH without the equality holding, is never reset, and\nkeeps growing, so tw-\u003edata[tw-\u003eidx++] walks off the end of the three-byte\narray and the rest of the heap-allocated struct tw, one attacker-chosen\nbyte at a time -- an unbounded, device-driven heap out-of-bounds write.\n\nReset the index on every completed packet and report an event only when\nthe two Y bytes match, like the other serio touchscreen drivers do."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:25.592Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ed9b66905407eb3d02df1aaeed82eb7a7f0eb508"
},
{
"url": "https://git.kernel.org/stable/c/044167cba2384bcd783547ad5e30ecd292b30919"
},
{
"url": "https://git.kernel.org/stable/c/6c9f29f128dd4057404838259af4c645318487e1"
},
{
"url": "https://git.kernel.org/stable/c/431ad239f2924dff337c3fccb9246597c1b63185"
},
{
"url": "https://git.kernel.org/stable/c/70e4248793762df9832fd4fc2fc6ac7924572c36"
},
{
"url": "https://git.kernel.org/stable/c/3e6f007b43e2fc6546e21fa74ee62c38984a6672"
},
{
"url": "https://git.kernel.org/stable/c/a8d87184576c889759e3aab899799a482f1e1a5b"
},
{
"url": "https://git.kernel.org/stable/c/478cdd736f2ce3114f90e775d7358136d3977b94"
}
],
"title": "Input: touchwin - reset the packet index on every complete packet",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64271",
"datePublished": "2026-07-25T08:49:18.160Z",
"dateReserved": "2026-07-19T15:36:31.775Z",
"dateUpdated": "2026-08-17T04:52:25.592Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53077 (GCVE-0-2026-53077)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-08-05 12:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/rds: Restrict use of RDS/IB to the initial network namespace
Prevent using RDS/IB in network namespaces other than the initial one.
The existing RDS/IB code will not work properly in non-initial network
namespaces.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638 Version: d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638 Version: d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638 Version: d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638 Version: d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638 Version: d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638 Version: d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638 Version: d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rds/af_rds.c",
"net/rds/ib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3e7f14cd5a51533404e1ae4809caab46073fb5c7",
"status": "affected",
"version": "d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638",
"versionType": "git"
},
{
"lessThan": "3174fc703d081d2ca538b22fba734e3ad5b52322",
"status": "affected",
"version": "d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638",
"versionType": "git"
},
{
"lessThan": "c244b79adffad89a5173cf8bfaa06a6b40bbd09b",
"status": "affected",
"version": "d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638",
"versionType": "git"
},
{
"lessThan": "07035306bf722f4676a1aee35cbeb3732c76194e",
"status": "affected",
"version": "d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638",
"versionType": "git"
},
{
"lessThan": "fb407343c0c16e94584707b2dfdd350a5f81b000",
"status": "affected",
"version": "d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638",
"versionType": "git"
},
{
"lessThan": "a7494479757d60d2413bfaa087f8431a26eea032",
"status": "affected",
"version": "d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638",
"versionType": "git"
},
{
"lessThan": "b6a54f5e9ce9b97ae641855378d71c5154a085c0",
"status": "affected",
"version": "d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638",
"versionType": "git"
},
{
"lessThan": "ebf71dd4aff46e8e421d455db3e231ba43d2fa8a",
"status": "affected",
"version": "d5a8ac28a7ff2f250d1bedbb6008dd2f6f6f1638",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rds/af_rds.c",
"net/rds/ib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.3"
},
{
"lessThan": "4.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/rds: Restrict use of RDS/IB to the initial network namespace\n\nPrevent using RDS/IB in network namespaces other than the initial one.\nThe existing RDS/IB code will not work properly in non-initial network\nnamespaces."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reachability is through local syscalls: unshare a user/network namespace, create an AF_RDS socket, select RDS/IB with setsockopt, then bind/send and tear down the namespace. A remote peer alone cannot create the stale non-init namespace RDS/IB connection.\nAC:L - The attacker controls the namespace lifetime and socket operations needed to leave an RDS/IB connection with a stale net pointer, and syzbot reproduced the UAF. No hard-to-win race or victim state outside attacker control is required.\nPR:L - AF_RDS socket creation and SO_RDS_TRANSPORT do not require real init-namespace root, and the issue is reachable by an unprivileged local user via user namespaces. This is not an unauthenticated remote path, so low local privileges are required.\nUI:N - No victim action is needed after the attacker runs the local namespace and socket sequence. The later RDMA/RDS workqueue access occurs asynchronously in kernel context.\nS:U - The vulnerability corrupts/accesses kernel resources within the same kernel security authority. It is not a VM escape, IOMMU bypass, or other cross-authority boundary break.\nC:H - The bug is a slab use-after-free read of a freed net_namespace from RDS/IB asynchronous connection handling. Under the required kernel scoring guidance, UAFs are scored as high confidentiality impact because freed object reuse can expose kernel memory.\nI:H - Although the observed report is a UAF read, use-after-free bugs can generally be shaped through heap reuse into stronger memory corruption primitives. Per the required guidance and uncertainty rule, this warrants high integrity impact.\nA:H - Syzbot reports a KASAN slab-use-after-free in rds_conn_path_drop, and the same stale pointer access can trigger kernel oops/panic or destabilize RDS/RDMA workqueues. Kernel crash availability impact is high."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:33:10.122Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3e7f14cd5a51533404e1ae4809caab46073fb5c7"
},
{
"url": "https://git.kernel.org/stable/c/3174fc703d081d2ca538b22fba734e3ad5b52322"
},
{
"url": "https://git.kernel.org/stable/c/c244b79adffad89a5173cf8bfaa06a6b40bbd09b"
},
{
"url": "https://git.kernel.org/stable/c/07035306bf722f4676a1aee35cbeb3732c76194e"
},
{
"url": "https://git.kernel.org/stable/c/fb407343c0c16e94584707b2dfdd350a5f81b000"
},
{
"url": "https://git.kernel.org/stable/c/a7494479757d60d2413bfaa087f8431a26eea032"
},
{
"url": "https://git.kernel.org/stable/c/b6a54f5e9ce9b97ae641855378d71c5154a085c0"
},
{
"url": "https://git.kernel.org/stable/c/ebf71dd4aff46e8e421d455db3e231ba43d2fa8a"
}
],
"title": "net/rds: Restrict use of RDS/IB to the initial network namespace",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53077",
"datePublished": "2026-06-24T16:30:17.972Z",
"dateReserved": "2026-06-09T07:44:35.383Z",
"dateUpdated": "2026-08-05T12:33:10.122Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64316 (GCVE-0-2026-64316)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: caam - use print_hex_dump_devel to guard key hex dumps
Use print_hex_dump_devel() for dumping sensitive key material in
*_setkey() and gen_split_key() to avoid leaking secrets at runtime when
CONFIG_DYNAMIC_DEBUG is enabled.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6e005503199b9bf1b385949c05897fd6567b5af4 Version: 6e005503199b9bf1b385949c05897fd6567b5af4 Version: 6e005503199b9bf1b385949c05897fd6567b5af4 Version: 6e005503199b9bf1b385949c05897fd6567b5af4 Version: 6e005503199b9bf1b385949c05897fd6567b5af4 Version: 6e005503199b9bf1b385949c05897fd6567b5af4 Version: 6e005503199b9bf1b385949c05897fd6567b5af4 Version: 6e005503199b9bf1b385949c05897fd6567b5af4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/crypto/caam/caamalg.c",
"drivers/crypto/caam/caamalg_qi.c",
"drivers/crypto/caam/caamhash.c",
"drivers/crypto/caam/key_gen.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45c0e3615e5bca5f1fc93357af8d19975c092d4f",
"status": "affected",
"version": "6e005503199b9bf1b385949c05897fd6567b5af4",
"versionType": "git"
},
{
"lessThan": "8b56ba10105ca34a4b75f7e33d41d96a63815591",
"status": "affected",
"version": "6e005503199b9bf1b385949c05897fd6567b5af4",
"versionType": "git"
},
{
"lessThan": "9a53dc0a0ae0486e164e5af3de5f99ab42c5a23e",
"status": "affected",
"version": "6e005503199b9bf1b385949c05897fd6567b5af4",
"versionType": "git"
},
{
"lessThan": "ebd37eef6e4f435e18829c0c0c9ba3a6618cb2dd",
"status": "affected",
"version": "6e005503199b9bf1b385949c05897fd6567b5af4",
"versionType": "git"
},
{
"lessThan": "cea7302d5d05df74cfb4107897b1ca34163c06b9",
"status": "affected",
"version": "6e005503199b9bf1b385949c05897fd6567b5af4",
"versionType": "git"
},
{
"lessThan": "6f7b8e0321f3a8fbbd267d2ac15c671ab59e919e",
"status": "affected",
"version": "6e005503199b9bf1b385949c05897fd6567b5af4",
"versionType": "git"
},
{
"lessThan": "8cf5fb0503129e53052fe29302379cf83891d0fb",
"status": "affected",
"version": "6e005503199b9bf1b385949c05897fd6567b5af4",
"versionType": "git"
},
{
"lessThan": "3f57657b6ea23f933371f2c2846322f441773cee",
"status": "affected",
"version": "6e005503199b9bf1b385949c05897fd6567b5af4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/crypto/caam/caamalg.c",
"drivers/crypto/caam/caamalg_qi.c",
"drivers/crypto/caam/caamhash.c",
"drivers/crypto/caam/key_gen.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: caam - use print_hex_dump_devel to guard key hex dumps\n\nUse print_hex_dump_devel() for dumping sensitive key material in\n*_setkey() and gen_split_key() to avoid leaking secrets at runtime when\nCONFIG_DYNAMIC_DEBUG is enabled."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:16.580Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45c0e3615e5bca5f1fc93357af8d19975c092d4f"
},
{
"url": "https://git.kernel.org/stable/c/8b56ba10105ca34a4b75f7e33d41d96a63815591"
},
{
"url": "https://git.kernel.org/stable/c/9a53dc0a0ae0486e164e5af3de5f99ab42c5a23e"
},
{
"url": "https://git.kernel.org/stable/c/ebd37eef6e4f435e18829c0c0c9ba3a6618cb2dd"
},
{
"url": "https://git.kernel.org/stable/c/cea7302d5d05df74cfb4107897b1ca34163c06b9"
},
{
"url": "https://git.kernel.org/stable/c/6f7b8e0321f3a8fbbd267d2ac15c671ab59e919e"
},
{
"url": "https://git.kernel.org/stable/c/8cf5fb0503129e53052fe29302379cf83891d0fb"
},
{
"url": "https://git.kernel.org/stable/c/3f57657b6ea23f933371f2c2846322f441773cee"
}
],
"title": "crypto: caam - use print_hex_dump_devel to guard key hex dumps",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64316",
"datePublished": "2026-07-25T08:49:46.415Z",
"dateReserved": "2026-07-19T15:36:31.779Z",
"dateUpdated": "2026-08-17T04:53:16.580Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64085 (GCVE-0-2026-64085)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-07-19 15:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer
adm1266_pmbus_block_xfer() copies the device-supplied block payload
into the caller-provided buffer using the device-supplied length:
memcpy(data_r, &msgs[1].buf[1], msgs[1].buf[0]);
The helper does not know how large data_r is and trusts the device to
return at most one record's worth of bytes. adm1266_nvmem_read_blackbox()
violates that contract: it advances read_buff inside data->dev_mem in
ADM1266_BLACKBOX_SIZE (64-byte) strides while the helper is willing to
write up to ADM1266_PMBUS_BLOCK_MAX (255) bytes. A device that returns
more than 64 bytes on the trailing record (read_buff offset 1984 in
the 2048-byte dev_mem allocation) overflows dev_mem by up to 191 bytes
before the post-call
if (ret != ADM1266_BLACKBOX_SIZE)
return -EIO;
can reject the response.
Contain the fix in the caller without changing the helper signature:
read each record into a 255-byte local bounce buffer that matches the
helper's maximum output, validate the returned length, and only then
copy exactly ADM1266_BLACKBOX_SIZE bytes into the dev_mem slot.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7896d87cbb05e097efc113243d4e38f9f8cea16c",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "9d5309500b4607b7198e19f0a3fa13eb864cd5fb",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "6098634cfa711f11a8d65368dc51ec8f7c8241ba",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "60c4b9fe1a3dd012014b1f561a6928a0b5db1126",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "83e039f0a43e0708515b0479cb7690fb93faaaa0",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "97a9cf2a8217ca1cdaf48cb9ab26e471632c7e7f",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "dd47b8c4a0a8ced442da3f008db28fbbd31feaf0",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "43cae21424ff8e33894a0f86c6b80b840c049fd7",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer\n\nadm1266_pmbus_block_xfer() copies the device-supplied block payload\ninto the caller-provided buffer using the device-supplied length:\n\n\tmemcpy(data_r, \u0026msgs[1].buf[1], msgs[1].buf[0]);\n\nThe helper does not know how large data_r is and trusts the device to\nreturn at most one record\u0027s worth of bytes. adm1266_nvmem_read_blackbox()\nviolates that contract: it advances read_buff inside data-\u003edev_mem in\nADM1266_BLACKBOX_SIZE (64-byte) strides while the helper is willing to\nwrite up to ADM1266_PMBUS_BLOCK_MAX (255) bytes. A device that returns\nmore than 64 bytes on the trailing record (read_buff offset 1984 in\nthe 2048-byte dev_mem allocation) overflows dev_mem by up to 191 bytes\nbefore the post-call\n\n\tif (ret != ADM1266_BLACKBOX_SIZE)\n\t\treturn -EIO;\n\ncan reject the response.\n\nContain the fix in the caller without changing the helper signature:\nread each record into a 255-byte local bounce buffer that matches the\nhelper\u0027s maximum output, validate the returned length, and only then\ncopy exactly ADM1266_BLACKBOX_SIZE bytes into the dev_mem slot."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:39:56.067Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7896d87cbb05e097efc113243d4e38f9f8cea16c"
},
{
"url": "https://git.kernel.org/stable/c/9d5309500b4607b7198e19f0a3fa13eb864cd5fb"
},
{
"url": "https://git.kernel.org/stable/c/6098634cfa711f11a8d65368dc51ec8f7c8241ba"
},
{
"url": "https://git.kernel.org/stable/c/60c4b9fe1a3dd012014b1f561a6928a0b5db1126"
},
{
"url": "https://git.kernel.org/stable/c/83e039f0a43e0708515b0479cb7690fb93faaaa0"
},
{
"url": "https://git.kernel.org/stable/c/97a9cf2a8217ca1cdaf48cb9ab26e471632c7e7f"
},
{
"url": "https://git.kernel.org/stable/c/dd47b8c4a0a8ced442da3f008db28fbbd31feaf0"
},
{
"url": "https://git.kernel.org/stable/c/43cae21424ff8e33894a0f86c6b80b840c049fd7"
}
],
"title": "hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64085",
"datePublished": "2026-07-19T15:39:56.067Z",
"dateReserved": "2026-07-19T07:54:57.032Z",
"dateUpdated": "2026-07-19T15:39:56.067Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46274 (GCVE-0-2026-46274)
Vulnerability from cvelistv5
Published
2026-06-08 14:30
Modified
2026-08-05 12:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
io-wq: check that the predecessor is hashed in io_wq_remove_pending()
io_wq_remove_pending() needs to fix up wq->hash_tail[] if the cancelled
work was the tail of its hash bucket. When doing this, it checks whether
the preceding entry in acct->work_list has the same hash value, but
never checks that the predecessor is hashed at all. io_get_work_hash()
is simply atomic_read(&work->flags) >> IO_WQ_HASH_SHIFT, and the hash
bits are never set for non-hashed work, so it returns 0. Thus, when a
hashed bucket-0 work is cancelled while a non-hashed work is its list
predecessor, the check spuriously passes and a pointer to the non-hashed
io_kiocb is stored in wq->hash_tail[0].
Because non-hashed work is dequeued via the fast path in
io_get_next_work(), which never touches hash_tail[], the stale pointer
is never cleared. Therefore, after the non-hashed io_kiocb completes and
is freed back to req_cachep, wq->hash_tail[0] is a dangling pointer. The
io_wq is per-task (tctx->io_wq) and survives ring open/close, so the
dangling pointer persists for the lifetime of the task; the next hashed
bucket-0 enqueue dereferences it in io_wq_insert_work() and
wq_list_add_after() writes through freed memory.
Add the missing io_wq_is_hashed() check so a non-hashed predecessor
never inherits a hash_tail[] slot.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 204361a77f4018627addd4a06877448f088ddfc0 Version: 204361a77f4018627addd4a06877448f088ddfc0 Version: 204361a77f4018627addd4a06877448f088ddfc0 Version: 204361a77f4018627addd4a06877448f088ddfc0 Version: 204361a77f4018627addd4a06877448f088ddfc0 Version: 13f35a2c0fd5c6a4fcd8903542b053bcc914fcf5 Version: 5.8.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"io_uring/io-wq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d6bda9df0c0a3080804181464d5c0f4d78a4e769",
"status": "affected",
"version": "204361a77f4018627addd4a06877448f088ddfc0",
"versionType": "git"
},
{
"lessThan": "5a20ebf0c81b61f5ea3b1b529c100cad69b9f603",
"status": "affected",
"version": "204361a77f4018627addd4a06877448f088ddfc0",
"versionType": "git"
},
{
"lessThan": "252c5051dba9c709b6a72f2866f93e5e618b3f06",
"status": "affected",
"version": "204361a77f4018627addd4a06877448f088ddfc0",
"versionType": "git"
},
{
"lessThan": "d376c131af7c7739a87ff037ed2fdb67c2542c8a",
"status": "affected",
"version": "204361a77f4018627addd4a06877448f088ddfc0",
"versionType": "git"
},
{
"lessThan": "d6a2d7b04b5a093021a7a0e2e69e9d5237dfa8cc",
"status": "affected",
"version": "204361a77f4018627addd4a06877448f088ddfc0",
"versionType": "git"
},
{
"status": "affected",
"version": "13f35a2c0fd5c6a4fcd8903542b053bcc914fcf5",
"versionType": "git"
},
{
"lessThan": "5.9",
"status": "affected",
"version": "5.8.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"io_uring/io-wq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.8.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nio-wq: check that the predecessor is hashed in io_wq_remove_pending()\n\nio_wq_remove_pending() needs to fix up wq-\u003ehash_tail[] if the cancelled\nwork was the tail of its hash bucket. When doing this, it checks whether\nthe preceding entry in acct-\u003ework_list has the same hash value, but\nnever checks that the predecessor is hashed at all. io_get_work_hash()\nis simply atomic_read(\u0026work-\u003eflags) \u003e\u003e IO_WQ_HASH_SHIFT, and the hash\nbits are never set for non-hashed work, so it returns 0. Thus, when a\nhashed bucket-0 work is cancelled while a non-hashed work is its list\npredecessor, the check spuriously passes and a pointer to the non-hashed\nio_kiocb is stored in wq-\u003ehash_tail[0].\n\nBecause non-hashed work is dequeued via the fast path in\nio_get_next_work(), which never touches hash_tail[], the stale pointer\nis never cleared. Therefore, after the non-hashed io_kiocb completes and\nis freed back to req_cachep, wq-\u003ehash_tail[0] is a dangling pointer. The\nio_wq is per-task (tctx-\u003eio_wq) and survives ring open/close, so the\ndangling pointer persists for the lifetime of the task; the next hashed\nbucket-0 enqueue dereferences it in io_wq_insert_work() and\nwq_list_add_after() writes through freed memory.\n\nAdd the missing io_wq_is_hashed() check so a non-hashed predecessor\nnever inherits a hash_tail[] slot."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through io_uring syscalls (io_uring_setup/io_uring_enter) that enqueue and cancel async io-wq work; there is no network, adjacent-radio, or physical-device entry path to io_wq_remove_pending().\nAC:L - An attacker fully controls the trigger sequence\u2014queue a non-hashed async request, queue a hashed bucket-0 request behind it, cancel the hashed pending work, let the non-hashed work complete, then enqueue another hashed bucket-0 request\u2014with no dependence on uncontrollable timing or rare kernel configuration.\nPR:L - Any unprivileged local user who can invoke io_uring (default when kernel.io_uring_disabled=0) can drive the cancel/enqueue sequence; no real-root or special capability beyond normal local process access is required.\nUI:N - Exploitation requires only the attacker\u0027s own io_uring submissions and cancellations; no victim user action such as opening files or mounting filesystems is needed beyond what the attacker initiates.\nS:U - The flaw corrupts kernel heap memory within the same kernel security domain to escalate from local user to kernel privileges; it does not inherently cross a VM/host or IOMMU boundary on its own.\nC:H - The stale hash_tail pointer is a use-after-free of a freed io_kiocb slab object; subsequent dereferences in io_wq_insert_work() read freed memory and UAF heap corruption is routinely weaponizable for arbitrary kernel memory disclosure.\nI:H - io_wq_insert_work() calls wq_list_add_after(), which writes attacker-influenced list pointers through the freed io_kiocb\u0027s list.next field, providing a controlled heap write primitive suitable for further memory corruption or code execution.\nA:H - Dereferencing and writing through the dangling hash_tail pointer can cause kernel oops/panic from invalid slab access, and successful heap corruption can crash or hang the system even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:30:57.842Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d6bda9df0c0a3080804181464d5c0f4d78a4e769"
},
{
"url": "https://git.kernel.org/stable/c/5a20ebf0c81b61f5ea3b1b529c100cad69b9f603"
},
{
"url": "https://git.kernel.org/stable/c/252c5051dba9c709b6a72f2866f93e5e618b3f06"
},
{
"url": "https://git.kernel.org/stable/c/d376c131af7c7739a87ff037ed2fdb67c2542c8a"
},
{
"url": "https://git.kernel.org/stable/c/d6a2d7b04b5a093021a7a0e2e69e9d5237dfa8cc"
}
],
"title": "io-wq: check that the predecessor is hashed in io_wq_remove_pending()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46274",
"datePublished": "2026-06-08T14:30:53.323Z",
"dateReserved": "2026-05-13T15:03:33.109Z",
"dateUpdated": "2026-08-05T12:30:57.842Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64084 (GCVE-0-2026-64084)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
adm1266_gpio_get_multiple() iterates the PDIO portion of the
caller-supplied mask using
for_each_set_bit_from(gpio_nr, mask,
ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) {
...
}
where ADM1266_PDIO_STATUS is the PMBus command code (0xE9, i.e. 233),
not the number of PDIO pins. The intended upper bound is
ADM1266_GPIO_NR + ADM1266_PDIO_NR = 25.
gpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip),
so the iteration walks find_next_bit() up to 242, reading up to 217
extra bits (a handful of unsigned-long words: four on 64-bit, seven
on 32-bit) of whatever lives past the end of the mask in the
caller's stack. Any incidental set bit in that range then drives a
set_bit(gpio_nr, bits) call that writes past the end of the
caller-supplied bits array too -- both out-of-bounds.
Substitute ADM1266_PDIO_NR for the constant so the scan stops at the
last real PDIO bit.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 Version: d98dfad35c38c037b37c4adc99df01da571031a5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d0593e15fdeb56048a72c5c6e720f702759d0ccd",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "17cee2f59029039416e8f6303050038eb59ba149",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "299efd14c2eda7e5fd40025e54addd4151a01081",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "4d1da9a6be5a8156c532d571c2ed237169f99244",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "b96c7f0bc0713dc6403912f6527d4ff9168d6fe6",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
},
{
"lessThan": "d7834d92251baade796812876e95555e2066fa9f",
"status": "affected",
"version": "d98dfad35c38c037b37c4adc99df01da571031a5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR\n\nadm1266_gpio_get_multiple() iterates the PDIO portion of the\ncaller-supplied mask using\n\n\tfor_each_set_bit_from(gpio_nr, mask,\n\t\t\t ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) {\n\t\t...\n\t}\n\nwhere ADM1266_PDIO_STATUS is the PMBus command code (0xE9, i.e. 233),\nnot the number of PDIO pins. The intended upper bound is\nADM1266_GPIO_NR + ADM1266_PDIO_NR = 25.\n\ngpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip),\nso the iteration walks find_next_bit() up to 242, reading up to 217\nextra bits (a handful of unsigned-long words: four on 64-bit, seven\non 32-bit) of whatever lives past the end of the mask in the\ncaller\u0027s stack. Any incidental set bit in that range then drives a\nset_bit(gpio_nr, bits) call that writes past the end of the\ncaller-supplied bits array too -- both out-of-bounds.\n\nSubstitute ADM1266_PDIO_NR for the constant so the scan stops at the\nlast real PDIO bit."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is only reachable through the GPIO character-device ioctl path (gpiolib \u2192 adm1266_gpio_get_multiple), which requires local access to /dev/gpiochip* on a system with an ADM1266 present on I2C; it is not triggered by network packets or physical bus access.\nAC:L - Any caller who can request ADM1266 PDIO lines and issue a multi-line GET_VALUES ioctl reliably enters the flawed loop; no race or victim state beyond attacker-controlled ioctl parameters is required.\nPR:L - Exploitation requires only a local account that can open the GPIO char device and request lines (e.g. root, gpio group membership, or a BMC service account with device access), not full init-namespace CAP_SYS_ADMIN; this is plausible on embedded/BMC deployments where ADM1266 is used.\nUI:N - Once the attacker has GPIO char-device access, triggering the bug is a single ioctl with no additional victim interaction.\nS:U - Impact is kernel stack memory corruption and potential privilege escalation within the same kernel security domain; it does not cross a VM, IOMMU, or sandbox boundary.\nC:H - The flawed loop performs out-of-bounds reads of up to ~217 bits beyond the 25-bit mask into adjacent kernel stack memory, constituting kernel memory disclosure per OOB-read guidance.\nI:H - Incidental set bits found during the out-of-bounds mask scan drive set_bit() writes past the end of the caller-supplied bits array, causing out-of-bounds kernel stack writes that could be leveraged for control-flow hijacking.\nA:H - Stack corruption from the out-of-bounds writes can cause kernel oops, panic, or hang, satisfying the kernel guidance that memory-corruption bugs warrant High availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:02.926Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d0593e15fdeb56048a72c5c6e720f702759d0ccd"
},
{
"url": "https://git.kernel.org/stable/c/17cee2f59029039416e8f6303050038eb59ba149"
},
{
"url": "https://git.kernel.org/stable/c/299efd14c2eda7e5fd40025e54addd4151a01081"
},
{
"url": "https://git.kernel.org/stable/c/4d1da9a6be5a8156c532d571c2ed237169f99244"
},
{
"url": "https://git.kernel.org/stable/c/b96c7f0bc0713dc6403912f6527d4ff9168d6fe6"
},
{
"url": "https://git.kernel.org/stable/c/fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec"
},
{
"url": "https://git.kernel.org/stable/c/2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17"
},
{
"url": "https://git.kernel.org/stable/c/d7834d92251baade796812876e95555e2066fa9f"
}
],
"title": "hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64084",
"datePublished": "2026-07-19T15:39:55.417Z",
"dateReserved": "2026-07-19T07:54:57.031Z",
"dateUpdated": "2026-08-05T12:39:02.926Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72501 (GCVE-0-2026-72501)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:15
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Initialize dpi variable to zero
dpi is initialized only for BNXT_RE_ALLOC_WC_PAGE, but copied
for all the cases. So initialize the dpi to 0.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/uapi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b87cbd4d198ae377be4815d8102fa9dfefb91dcc",
"status": "affected",
"version": "360da60d6c6edb9740de7a8e6d8969d62ceff956",
"versionType": "git"
},
{
"lessThan": "3d00b375853fbbf4157ad092884b4ed9a49429c1",
"status": "affected",
"version": "360da60d6c6edb9740de7a8e6d8969d62ceff956",
"versionType": "git"
},
{
"lessThan": "978b27d6ce538bb832ccd69e45802824e4301c4b",
"status": "affected",
"version": "360da60d6c6edb9740de7a8e6d8969d62ceff956",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/uapi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Initialize dpi variable to zero\n\ndpi is initialized only for BNXT_RE_ALLOC_WC_PAGE, but copied\nfor all the cases. So initialize the dpi to 0."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:15:54.658Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b87cbd4d198ae377be4815d8102fa9dfefb91dcc"
},
{
"url": "https://git.kernel.org/stable/c/3d00b375853fbbf4157ad092884b4ed9a49429c1"
},
{
"url": "https://git.kernel.org/stable/c/978b27d6ce538bb832ccd69e45802824e4301c4b"
}
],
"title": "RDMA/bnxt_re: Initialize dpi variable to zero",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72501",
"datePublished": "2026-08-15T05:57:32.990Z",
"dateReserved": "2026-08-09T03:40:39.938Z",
"dateUpdated": "2026-08-17T05:15:54.658Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53336 (GCVE-0-2026-53336)
Vulnerability from cvelistv5
Published
2026-07-01 13:32
Modified
2026-07-01 13:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvmem: layouts: onie-tlv: fix hang on unknown types
The EEPROM on my board has a vendor specific entry of type 0x41. When
stumbling upon that, this driver hangs in an endless loop.
Fix it by keep incrementing the offset on unknown entries, so the loop
will eventually stop.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nvmem/layouts/onie-tlv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "033d498b0f473c6456be5f885be172024ad84972",
"status": "affected",
"version": "d3c0d12f6474216bf386101e2449cc73e5c5b61d",
"versionType": "git"
},
{
"lessThan": "fd47edeabadfaa75422009dc5894e92c4c697517",
"status": "affected",
"version": "d3c0d12f6474216bf386101e2449cc73e5c5b61d",
"versionType": "git"
},
{
"lessThan": "4a4d21f531ccf5bb333d99b620e0d66551f3652c",
"status": "affected",
"version": "d3c0d12f6474216bf386101e2449cc73e5c5b61d",
"versionType": "git"
},
{
"lessThan": "4f27eb01619c36cc8e3ce9a2a9af97f145f5d1c6",
"status": "affected",
"version": "d3c0d12f6474216bf386101e2449cc73e5c5b61d",
"versionType": "git"
},
{
"lessThan": "ea41020b9018e31c2ea7e9d89021e3e6d7470883",
"status": "affected",
"version": "d3c0d12f6474216bf386101e2449cc73e5c5b61d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nvmem/layouts/onie-tlv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmem: layouts: onie-tlv: fix hang on unknown types\n\nThe EEPROM on my board has a vendor specific entry of type 0x41. When\nstumbling upon that, this driver hangs in an endless loop.\n\nFix it by keep incrementing the offset on unknown entries, so the loop\nwill eventually stop."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-01T13:32:18.489Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/033d498b0f473c6456be5f885be172024ad84972"
},
{
"url": "https://git.kernel.org/stable/c/fd47edeabadfaa75422009dc5894e92c4c697517"
},
{
"url": "https://git.kernel.org/stable/c/4a4d21f531ccf5bb333d99b620e0d66551f3652c"
},
{
"url": "https://git.kernel.org/stable/c/4f27eb01619c36cc8e3ce9a2a9af97f145f5d1c6"
},
{
"url": "https://git.kernel.org/stable/c/ea41020b9018e31c2ea7e9d89021e3e6d7470883"
}
],
"title": "nvmem: layouts: onie-tlv: fix hang on unknown types",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53336",
"datePublished": "2026-07-01T13:32:18.489Z",
"dateReserved": "2026-06-09T07:44:35.399Z",
"dateUpdated": "2026-07-01T13:32:18.489Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64073 (GCVE-0-2026-64073)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT
On PREEMPT_RT, non-HARD irq_work runs in per-CPU kthreads via
run_irq_workd(), so irq_work_sync() uses rcuwait() to wait for BUSY==0.
After irq_work_single() clears BUSY via atomic_cmpxchg(), it still
dereferences @work for irq_work_is_hard() and rcuwait_wake_up().
An irq_work_sync() caller on another CPU that enters after BUSY is cleared
can observe BUSY==0 immediately, return, and free the work before those
accesses complete — causing a use-after-free.
Fix this by wrapping run_irq_workd() in guard(rcu)() so that the entire
irq_work_single() execution is within an RCU read-side critical
section. Then add synchronize_rcu() in irq_work_sync() after
rcuwait_wait_event() to ensure the caller waits for the RCU grace period
before returning, preventing premature frees.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 810979682ccc98dbd83f341c18a2e556c30a7164 Version: 810979682ccc98dbd83f341c18a2e556c30a7164 Version: 810979682ccc98dbd83f341c18a2e556c30a7164 Version: 810979682ccc98dbd83f341c18a2e556c30a7164 Version: 810979682ccc98dbd83f341c18a2e556c30a7164 Version: 810979682ccc98dbd83f341c18a2e556c30a7164 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/irq_work.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2dc79362302922cb18f35e262712b5e58de65442",
"status": "affected",
"version": "810979682ccc98dbd83f341c18a2e556c30a7164",
"versionType": "git"
},
{
"lessThan": "eef4f71b46a9929ac33e968538c9dd5d96a02460",
"status": "affected",
"version": "810979682ccc98dbd83f341c18a2e556c30a7164",
"versionType": "git"
},
{
"lessThan": "684a78183c54c23e70d1cba320f7fc184604210b",
"status": "affected",
"version": "810979682ccc98dbd83f341c18a2e556c30a7164",
"versionType": "git"
},
{
"lessThan": "18c0456ea2615b1a743a6db739c74411c3b42bc6",
"status": "affected",
"version": "810979682ccc98dbd83f341c18a2e556c30a7164",
"versionType": "git"
},
{
"lessThan": "81b582784518196eff1050212a046bc29d3a05dd",
"status": "affected",
"version": "810979682ccc98dbd83f341c18a2e556c30a7164",
"versionType": "git"
},
{
"lessThan": "91840be8f710370607f949a627e070896faeddb8",
"status": "affected",
"version": "810979682ccc98dbd83f341c18a2e556c30a7164",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/irq_work.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nirq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT\n\nOn PREEMPT_RT, non-HARD irq_work runs in per-CPU kthreads via\nrun_irq_workd(), so irq_work_sync() uses rcuwait() to wait for BUSY==0.\n\nAfter irq_work_single() clears BUSY via atomic_cmpxchg(), it still\ndereferences @work for irq_work_is_hard() and rcuwait_wake_up().\n\nAn irq_work_sync() caller on another CPU that enters after BUSY is cleared\ncan observe BUSY==0 immediately, return, and free the work before those\naccesses complete \u2014 causing a use-after-free.\n\nFix this by wrapping run_irq_workd() in guard(rcu)() so that the entire\nirq_work_single() execution is within an RCU read-side critical\nsection. Then add synchronize_rcu() in irq_work_sync() after\nrcuwait_wait_event() to ensure the caller waits for the RCU grace period\nbefore returning, preventing premature frees."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires reaching irq_work_sync() teardown paths via local syscalls (e.g. perf_event_open/close, bpf map teardown) that queue non-HARD irq_work on PREEMPT_RT; there is no direct network packet or remote-protocol entry point into irq_work.c.\nAC:L - The bug is a cross-CPU race where irq_work_sync() returns after BUSY is cleared while irq_work_single() still dereferences the work; an attacker can control both sides by concurrently closing/freeing a subsystem object and driving irq_work_queue() from another thread/CPU (e.g. perf fasync wakeup vs. close).\nPR:L - Unprivileged local users can reach vulnerable teardown via perf_event_open/close on per-task events (exclude_kernel=1, default paranoid=2) and via bpf() ringbuf/map cleanup when CAP_BPF is available in a user namespace; no init-namespace root is required for the highest-impact paths.\nUI:N - Exploitation is driven entirely by the attacker\u0027s own syscalls and threading; no victim interaction such as opening files or mounting filesystems is needed.\nS:U - Successful exploitation corrupts or reads kernel memory and can yield local privilege escalation within the same kernel security authority; it does not inherently cross a VM/host, IOMMU, or container boundary by itself.\nC:H - This is a kernel heap use-after-free: irq_work_single() dereferences a freed irq_work embedded in structures like perf_event or bpf_ringbuf, enabling arbitrary kernel memory disclosure through heap reuse and controlled reads of stale object fields.\nI:H - The UAF permits attacker-controlled reallocation of the freed irq_work container object, providing a standard kernel heap corruption primitive that can be developed into arbitrary write or control-flow hijack, not merely a bounded modification.\nA:H - Use-after-free in irq_work_single() can immediately fault or panic the kernel during post-BUSY dereferences, and repeated triggering via perf/BPF open-close races can cause persistent denial of service on PREEMPT_RT systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:54.369Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2dc79362302922cb18f35e262712b5e58de65442"
},
{
"url": "https://git.kernel.org/stable/c/eef4f71b46a9929ac33e968538c9dd5d96a02460"
},
{
"url": "https://git.kernel.org/stable/c/684a78183c54c23e70d1cba320f7fc184604210b"
},
{
"url": "https://git.kernel.org/stable/c/18c0456ea2615b1a743a6db739c74411c3b42bc6"
},
{
"url": "https://git.kernel.org/stable/c/81b582784518196eff1050212a046bc29d3a05dd"
},
{
"url": "https://git.kernel.org/stable/c/91840be8f710370607f949a627e070896faeddb8"
}
],
"title": "irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64073",
"datePublished": "2026-07-19T15:39:48.463Z",
"dateReserved": "2026-07-19T07:54:57.031Z",
"dateUpdated": "2026-08-05T12:38:54.369Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68205 (GCVE-0-2026-68205)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()
The v4l2 helper v4l2_async_register_subdev_sensor() calls
v4l2_async_register_subdev(), which is a macro that expands to
__v4l2_async_register_subdev(sd,THIS_MODULE). Since the macro is expanded
inside v4l2-fwnode.c, THIS_MODULE resolves to the v4l2-fwnode module
rather than the sensor driver module that originally set sd->owner. When
v4l2-fwnode is built-in, THIS_MODULE evaluates to NULL, which then
overwrites the sensor driver's owner with NULL.
This causes the problem that the sensor module's reference count is never
incremented during async registration, so the module can be removed while
the subdevice is still in use by a notifier (e.g., a CSI-2 receiver
bridge driver).
Fix this by renaming v4l2_async_register_subdev_sensor() to
__v4l2_async_register_subdev_sensor() with an added explicit module
argument and introducing a wrapper macro:
#define v4l2_async_register_subdev_sensor(sd) \
__v4l2_async_register_subdev_sensor(sd, THIS_MODULE)
This ensures the sensor driver module is properly referenced even when
the sensor driver does not init the owner field before calling
v4l2_async_register_subdev_sensor() and prevents premature module removal.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-fwnode.c",
"include/media/v4l2-async.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f35e85a9d919d7954d9a7752e4644c0b403ad025",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "c5e47cf9a6cffef73a1ed40b3648e6097aac165a",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "47ef04cd13d38010b580056a9d8840aaab944841",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "caea6bc68c925d63ca33d21b2255f47181943d61",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "cf9732fd6c4f2f803ccfc46d89489b6635590270",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "067887ff93fddbb3a3fb84c900bc654ecfe5ba61",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "06cb687a5132fcffe624c0070576ab852ac6b568",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-fwnode.c",
"include/media/v4l2-async.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()\n\nThe v4l2 helper v4l2_async_register_subdev_sensor() calls\nv4l2_async_register_subdev(), which is a macro that expands to\n__v4l2_async_register_subdev(sd,THIS_MODULE). Since the macro is expanded\ninside v4l2-fwnode.c, THIS_MODULE resolves to the v4l2-fwnode module\nrather than the sensor driver module that originally set sd-\u003eowner. When\nv4l2-fwnode is built-in, THIS_MODULE evaluates to NULL, which then\noverwrites the sensor driver\u0027s owner with NULL.\n\nThis causes the problem that the sensor module\u0027s reference count is never\nincremented during async registration, so the module can be removed while\nthe subdevice is still in use by a notifier (e.g., a CSI-2 receiver\nbridge driver).\n\nFix this by renaming v4l2_async_register_subdev_sensor() to\n__v4l2_async_register_subdev_sensor() with an added explicit module\nargument and introducing a wrapper macro:\n #define v4l2_async_register_subdev_sensor(sd) \\\n __v4l2_async_register_subdev_sensor(sd, THIS_MODULE)\n\nThis ensures the sensor driver module is properly referenced even when\nthe sensor driver does not init the owner field before calling\nv4l2_async_register_subdev_sensor() and prevents premature module removal."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:09.673Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f35e85a9d919d7954d9a7752e4644c0b403ad025"
},
{
"url": "https://git.kernel.org/stable/c/c5e47cf9a6cffef73a1ed40b3648e6097aac165a"
},
{
"url": "https://git.kernel.org/stable/c/47ef04cd13d38010b580056a9d8840aaab944841"
},
{
"url": "https://git.kernel.org/stable/c/caea6bc68c925d63ca33d21b2255f47181943d61"
},
{
"url": "https://git.kernel.org/stable/c/cf9732fd6c4f2f803ccfc46d89489b6635590270"
},
{
"url": "https://git.kernel.org/stable/c/067887ff93fddbb3a3fb84c900bc654ecfe5ba61"
},
{
"url": "https://git.kernel.org/stable/c/06cb687a5132fcffe624c0070576ab852ac6b568"
}
],
"title": "media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68205",
"datePublished": "2026-08-10T12:00:24.265Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-23T12:46:09.673Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64348 (GCVE-0-2026-64348)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: free iso schedules on failed submit
EHCI and FOTG210 isochronous submits build an ehci_iso_sched before
linking the URB to the endpoint queue, and keep the staged schedule in
urb->hcpriv until iso_stream_schedule() and the link helpers consume it.
If the controller is no longer accessible, or usb_hcd_link_urb_to_ep()
fails, submit jumps to done_not_linked before that handoff happens and
leaks the staged schedule still attached to urb->hcpriv.
Free the staged schedule from done_not_linked when submit fails before
the URB is linked and clear urb->hcpriv after the free.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.
An x86_64 allyesconfig build showed no new warnings. As we do not have an
EHCI host controller with a USB isochronous device to test with, no
runtime testing was able to be performed.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8de98402652c01839ae321be6cb3054cf5735d83 Version: 8de98402652c01839ae321be6cb3054cf5735d83 Version: 8de98402652c01839ae321be6cb3054cf5735d83 Version: 8de98402652c01839ae321be6cb3054cf5735d83 Version: 8de98402652c01839ae321be6cb3054cf5735d83 Version: 8de98402652c01839ae321be6cb3054cf5735d83 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/fotg210/fotg210-hcd.c",
"drivers/usb/host/ehci-sched.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b0d00d077f9738d215af9b50c74dffab7a1de19f",
"status": "affected",
"version": "8de98402652c01839ae321be6cb3054cf5735d83",
"versionType": "git"
},
{
"lessThan": "be5004395dfd0b6ec310db359f887fa396fd0dd2",
"status": "affected",
"version": "8de98402652c01839ae321be6cb3054cf5735d83",
"versionType": "git"
},
{
"lessThan": "8890699eea19027ef6e4f9cbcf27cba5e789793f",
"status": "affected",
"version": "8de98402652c01839ae321be6cb3054cf5735d83",
"versionType": "git"
},
{
"lessThan": "6bc17a78a05671d303820224fb37ca339c1dc2cb",
"status": "affected",
"version": "8de98402652c01839ae321be6cb3054cf5735d83",
"versionType": "git"
},
{
"lessThan": "4bb88aee6b868cbf73bf453f62497802f5fe4769",
"status": "affected",
"version": "8de98402652c01839ae321be6cb3054cf5735d83",
"versionType": "git"
},
{
"lessThan": "b9399d25fbb34a05bbe76eeedd730f62ff2670e9",
"status": "affected",
"version": "8de98402652c01839ae321be6cb3054cf5735d83",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/fotg210/fotg210-hcd.c",
"drivers/usb/host/ehci-sched.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.15"
},
{
"lessThan": "2.6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: free iso schedules on failed submit\n\nEHCI and FOTG210 isochronous submits build an ehci_iso_sched before\nlinking the URB to the endpoint queue, and keep the staged schedule in\nurb-\u003ehcpriv until iso_stream_schedule() and the link helpers consume it.\nIf the controller is no longer accessible, or usb_hcd_link_urb_to_ep()\nfails, submit jumps to done_not_linked before that handoff happens and\nleaks the staged schedule still attached to urb-\u003ehcpriv.\n\nFree the staged schedule from done_not_linked when submit fails before\nthe URB is linked and clear urb-\u003ehcpriv after the free.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have an\nEHCI host controller with a USB isochronous device to test with, no\nruntime testing was able to be performed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:53.432Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b0d00d077f9738d215af9b50c74dffab7a1de19f"
},
{
"url": "https://git.kernel.org/stable/c/be5004395dfd0b6ec310db359f887fa396fd0dd2"
},
{
"url": "https://git.kernel.org/stable/c/8890699eea19027ef6e4f9cbcf27cba5e789793f"
},
{
"url": "https://git.kernel.org/stable/c/6bc17a78a05671d303820224fb37ca339c1dc2cb"
},
{
"url": "https://git.kernel.org/stable/c/4bb88aee6b868cbf73bf453f62497802f5fe4769"
},
{
"url": "https://git.kernel.org/stable/c/b9399d25fbb34a05bbe76eeedd730f62ff2670e9"
}
],
"title": "usb: free iso schedules on failed submit",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64348",
"datePublished": "2026-07-25T08:50:08.983Z",
"dateReserved": "2026-07-19T15:36:31.782Z",
"dateUpdated": "2026-08-17T04:53:53.432Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64436 (GCVE-0-2026-64436)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: af_key: initialize alg_key_len for IPComp states
pfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by
allocating x->calg and copying only the algorithm name:
x->calg = kmalloc_obj(*x->calg);
if (!x->calg) {
err = -ENOMEM;
goto out;
}
strcpy(x->calg->alg_name, a->name);
x->props.calgo = sa->sadb_sa_encrypt;
Unlike the authentication (x->aalg) and encryption (x->ealg) branches of
the same function, the compression branch never initializes
calg->alg_key_len. IPComp carries no key and the allocation only
reserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field
is left containing uninitialized slab data.
calg->alg_key_len is later used as a length by xfrm_algo_clone() when an
IPComp state is cloned during XFRM_MSG_MIGRATE:
xfrm_state_migrate()
xfrm_state_clone_and_setup()
x->calg = xfrm_algo_clone(orig->calg);
kmemdup(orig, xfrm_alg_len(orig));
where xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8. With
a non-zero garbage alg_key_len, kmemdup() reads past the end of the
68-byte calg object. Adding an IPComp SA via PF_KEY and then migrating
it triggers (net-next, KASAN, init_on_alloc=0):
BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x44/0x60
Read of size 4164 at addr ff11000025a74980 by task diag2/9287
CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1
Call Trace:
<TASK>
dump_stack_lvl+0x10e/0x1f0
print_report+0xf7/0x600
kasan_report+0xe4/0x120
kasan_check_range+0x105/0x1b0
__asan_memcpy+0x23/0x60
kmemdup_noprof+0x44/0x60
xfrm_state_migrate+0x70a/0x1da0
xfrm_migrate+0x753/0x18a0
xfrm_do_migrate+0xb47/0xf10
xfrm_user_rcv_msg+0x411/0xb50
netlink_rcv_skb+0x158/0x420
xfrm_netlink_rcv+0x71/0x90
netlink_unicast+0x584/0x850
netlink_sendmsg+0x8b0/0xdc0
____sys_sendmsg+0x9f7/0xb90
___sys_sendmsg+0x134/0x1d0
__sys_sendmsg+0x16d/0x220
do_syscall_64+0x116/0x7d0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
Allocated by task 9287:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
__kasan_kmalloc+0xaa/0xb0
pfkey_add+0x2652/0x2ea0
pfkey_process+0x6d0/0x830
pfkey_sendmsg+0x42c/0x850
__sys_sendto+0x461/0x4b0
__x64_sys_sendto+0xe0/0x1c0
do_syscall_64+0x116/0x7d0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
The buggy address belongs to the object at ff11000025a74980
which belongs to the cache kmalloc-96 of size 96
The buggy address is located 0 bytes inside of
allocated 68-byte region [ff11000025a74980, ff11000025a749c4)
Depending on the uninitialized value the same field can instead request
an oversized kmemdup() allocation and make the migration clone fail.
The XFRM netlink path is not affected: verify_one_alg() rejects an
XFRMA_ALG_COMP attribute shorter than xfrm_alg_len(), so a calg added via
XFRM_MSG_NEWSA is always self-consistent.
Initialize calg->alg_key_len to 0, matching the aalg/ealg branches.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 80c9abaabf4283f7cf4a0b3597cd302506635b7f Version: 80c9abaabf4283f7cf4a0b3597cd302506635b7f Version: 80c9abaabf4283f7cf4a0b3597cd302506635b7f Version: 80c9abaabf4283f7cf4a0b3597cd302506635b7f Version: 80c9abaabf4283f7cf4a0b3597cd302506635b7f Version: 80c9abaabf4283f7cf4a0b3597cd302506635b7f Version: 80c9abaabf4283f7cf4a0b3597cd302506635b7f Version: 80c9abaabf4283f7cf4a0b3597cd302506635b7f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/key/af_key.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "58e82fc3dedb57b1432292504415b224fd2d6acb",
"status": "affected",
"version": "80c9abaabf4283f7cf4a0b3597cd302506635b7f",
"versionType": "git"
},
{
"lessThan": "01b9115b55018123ef2449ac4951f89147a8428e",
"status": "affected",
"version": "80c9abaabf4283f7cf4a0b3597cd302506635b7f",
"versionType": "git"
},
{
"lessThan": "3f63d1752d90c0e28be931a48ab5d89bc97d637d",
"status": "affected",
"version": "80c9abaabf4283f7cf4a0b3597cd302506635b7f",
"versionType": "git"
},
{
"lessThan": "273c06b81d2e902b21acc801ae18c8276c8a9b69",
"status": "affected",
"version": "80c9abaabf4283f7cf4a0b3597cd302506635b7f",
"versionType": "git"
},
{
"lessThan": "6de2a650917bedaaefd65b17cede83c5e2c1dedd",
"status": "affected",
"version": "80c9abaabf4283f7cf4a0b3597cd302506635b7f",
"versionType": "git"
},
{
"lessThan": "e8417353cbd078d10531ba3928e609c84ab09e6b",
"status": "affected",
"version": "80c9abaabf4283f7cf4a0b3597cd302506635b7f",
"versionType": "git"
},
{
"lessThan": "cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e",
"status": "affected",
"version": "80c9abaabf4283f7cf4a0b3597cd302506635b7f",
"versionType": "git"
},
{
"lessThan": "d129c3177d7b1138fd5066fcc63a698b3ba415b0",
"status": "affected",
"version": "80c9abaabf4283f7cf4a0b3597cd302506635b7f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/key/af_key.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.21"
},
{
"lessThan": "2.6.21",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.21",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: initialize alg_key_len for IPComp states\n\npfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by\nallocating x-\u003ecalg and copying only the algorithm name:\n\n\tx-\u003ecalg = kmalloc_obj(*x-\u003ecalg);\n\tif (!x-\u003ecalg) {\n\t\terr = -ENOMEM;\n\t\tgoto out;\n\t}\n\tstrcpy(x-\u003ecalg-\u003ealg_name, a-\u003ename);\n\tx-\u003eprops.calgo = sa-\u003esadb_sa_encrypt;\n\nUnlike the authentication (x-\u003eaalg) and encryption (x-\u003eealg) branches of\nthe same function, the compression branch never initializes\ncalg-\u003ealg_key_len. IPComp carries no key and the allocation only\nreserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field\nis left containing uninitialized slab data.\n\ncalg-\u003ealg_key_len is later used as a length by xfrm_algo_clone() when an\nIPComp state is cloned during XFRM_MSG_MIGRATE:\n\n\txfrm_state_migrate()\n\t xfrm_state_clone_and_setup()\n\t x-\u003ecalg = xfrm_algo_clone(orig-\u003ecalg);\n\t kmemdup(orig, xfrm_alg_len(orig));\n\nwhere xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8. With\na non-zero garbage alg_key_len, kmemdup() reads past the end of the\n68-byte calg object. Adding an IPComp SA via PF_KEY and then migrating\nit triggers (net-next, KASAN, init_on_alloc=0):\n\n BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x44/0x60\n Read of size 4164 at addr ff11000025a74980 by task diag2/9287\n CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x10e/0x1f0\n print_report+0xf7/0x600\n kasan_report+0xe4/0x120\n kasan_check_range+0x105/0x1b0\n __asan_memcpy+0x23/0x60\n kmemdup_noprof+0x44/0x60\n xfrm_state_migrate+0x70a/0x1da0\n xfrm_migrate+0x753/0x18a0\n xfrm_do_migrate+0xb47/0xf10\n xfrm_user_rcv_msg+0x411/0xb50\n netlink_rcv_skb+0x158/0x420\n xfrm_netlink_rcv+0x71/0x90\n netlink_unicast+0x584/0x850\n netlink_sendmsg+0x8b0/0xdc0\n ____sys_sendmsg+0x9f7/0xb90\n ___sys_sendmsg+0x134/0x1d0\n __sys_sendmsg+0x16d/0x220\n do_syscall_64+0x116/0x7d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n \u003c/TASK\u003e\n\n Allocated by task 9287:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n pfkey_add+0x2652/0x2ea0\n pfkey_process+0x6d0/0x830\n pfkey_sendmsg+0x42c/0x850\n __sys_sendto+0x461/0x4b0\n __x64_sys_sendto+0xe0/0x1c0\n do_syscall_64+0x116/0x7d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n The buggy address belongs to the object at ff11000025a74980\n which belongs to the cache kmalloc-96 of size 96\n The buggy address is located 0 bytes inside of\n allocated 68-byte region [ff11000025a74980, ff11000025a749c4)\n\nDepending on the uninitialized value the same field can instead request\nan oversized kmemdup() allocation and make the migration clone fail.\n\nThe XFRM netlink path is not affected: verify_one_alg() rejects an\nXFRMA_ALG_COMP attribute shorter than xfrm_alg_len(), so a calg added via\nXFRM_MSG_NEWSA is always self-consistent.\n\nInitialize calg-\u003ealg_key_len to 0, matching the aalg/ealg branches."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local PF_KEY and XFRM netlink messages; received IPComp network packets cannot create or migrate the vulnerable state.\nAC:L - The attacker can deterministically prime the same kmalloc-96 cache and control the stale length before triggering migration. No race or victim-controlled condition is required.\nPR:L - Both paths require CAP_NET_ADMIN relative to the network namespace\u0027s owning user namespace. An unprivileged user can obtain this capability in a newly created user and network namespace.\nUI:N - No victim action is required after the attacker gains local execution and submits the crafted state and migration messages.\nS:U - The vulnerability affects the host kernel within its existing security authority and does not cross a VM, IOMMU, or equivalent scope boundary.\nC:H - The controlled length causes a potentially large out-of-bounds read across adjacent kernel heap objects, which can capture sensitive kernel memory and is not tightly bounded.\nI:N - kmemdup allocates a destination matching the computed length, and the vulnerable operation only over-reads the source. No out-of-bounds write or control-flow modification path was identified.\nA:H - The over-read can trigger a kernel fault or panic under memory-safety enforcement. Controlled oversized clone allocations can also be repeated across states to exhaust kernel memory."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:37.549Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/58e82fc3dedb57b1432292504415b224fd2d6acb"
},
{
"url": "https://git.kernel.org/stable/c/01b9115b55018123ef2449ac4951f89147a8428e"
},
{
"url": "https://git.kernel.org/stable/c/3f63d1752d90c0e28be931a48ab5d89bc97d637d"
},
{
"url": "https://git.kernel.org/stable/c/273c06b81d2e902b21acc801ae18c8276c8a9b69"
},
{
"url": "https://git.kernel.org/stable/c/6de2a650917bedaaefd65b17cede83c5e2c1dedd"
},
{
"url": "https://git.kernel.org/stable/c/e8417353cbd078d10531ba3928e609c84ab09e6b"
},
{
"url": "https://git.kernel.org/stable/c/cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e"
},
{
"url": "https://git.kernel.org/stable/c/d129c3177d7b1138fd5066fcc63a698b3ba415b0"
}
],
"title": "net: af_key: initialize alg_key_len for IPComp states",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64436",
"datePublished": "2026-07-25T08:51:10.370Z",
"dateReserved": "2026-07-19T15:36:31.787Z",
"dateUpdated": "2026-08-17T04:55:37.549Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63925 (GCVE-0-2026-63925)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
macsec: fix replay protection at XPN lower-PN wrap
In macsec_post_decrypt(), when pn is U32_MAX, pn + 1 overflows u32 to 0
and the first branch never fires. If next_pn_halves.lower is also in the
upper half, pn_same_half(pn, lower) is true and the XPN else-if does not
fire either, leaving next_pn_halves unchanged. An attacker that captures
the legitimate frame carrying pn == 0xFFFFFFFF on an XPN association
can then replay it indefinitely, since lowest_pn never rises above
the captured pn and macsec_decrypt() reconstructs the same IV.
Extend the XPN else-if to also fire when pn + 1 wraps to 0, so receipt
of pn == U32_MAX advances next_pn_halves to (upper + 1, 0).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a21ecf0e033807b976967286e6c392f48ee2049f Version: a21ecf0e033807b976967286e6c392f48ee2049f Version: a21ecf0e033807b976967286e6c392f48ee2049f Version: a21ecf0e033807b976967286e6c392f48ee2049f Version: a21ecf0e033807b976967286e6c392f48ee2049f Version: a21ecf0e033807b976967286e6c392f48ee2049f Version: a21ecf0e033807b976967286e6c392f48ee2049f Version: a21ecf0e033807b976967286e6c392f48ee2049f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/macsec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dd7306779c6ce1238f4cdc34f3c1f2246b854457",
"status": "affected",
"version": "a21ecf0e033807b976967286e6c392f48ee2049f",
"versionType": "git"
},
{
"lessThan": "d15130461df388136b62a7b0ce9f66e7e2fa9ff1",
"status": "affected",
"version": "a21ecf0e033807b976967286e6c392f48ee2049f",
"versionType": "git"
},
{
"lessThan": "23c0e230eab397d7f68be2538790ac41d3bb91fd",
"status": "affected",
"version": "a21ecf0e033807b976967286e6c392f48ee2049f",
"versionType": "git"
},
{
"lessThan": "679e13a65e68a67c8b3c0467c02ee89157ec6f0f",
"status": "affected",
"version": "a21ecf0e033807b976967286e6c392f48ee2049f",
"versionType": "git"
},
{
"lessThan": "79495a1b0944fe31ffd54b54b00211b493590d62",
"status": "affected",
"version": "a21ecf0e033807b976967286e6c392f48ee2049f",
"versionType": "git"
},
{
"lessThan": "6d00f5c7e5ff7ec4795b7f5f8ed88bd346641652",
"status": "affected",
"version": "a21ecf0e033807b976967286e6c392f48ee2049f",
"versionType": "git"
},
{
"lessThan": "d55acbe577db892b60547b6ef1c020b359331a6d",
"status": "affected",
"version": "a21ecf0e033807b976967286e6c392f48ee2049f",
"versionType": "git"
},
{
"lessThan": "e68842b3356471ba56c882209f324613dac47f64",
"status": "affected",
"version": "a21ecf0e033807b976967286e6c392f48ee2049f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/macsec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmacsec: fix replay protection at XPN lower-PN wrap\n\nIn macsec_post_decrypt(), when pn is U32_MAX, pn + 1 overflows u32 to 0\nand the first branch never fires. If next_pn_halves.lower is also in the\nupper half, pn_same_half(pn, lower) is true and the XPN else-if does not\nfire either, leaving next_pn_halves unchanged. An attacker that captures\nthe legitimate frame carrying pn == 0xFFFFFFFF on an XPN association\ncan then replay it indefinitely, since lowest_pn never rises above\nthe captured pn and macsec_decrypt() reconstructs the same IV.\n\nExtend the XPN else-if to also fire when pn + 1 wraps to 0, so receipt\nof pn == U32_MAX advances next_pn_halves to (upper + 1, 0)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - MACsec processes attacker-supplied Ethernet frames via netdev rx_handler on the underlying link; exploitation requires L2 adjacency on the same broadcast domain or point-to-point MACsec link, not remote Internet reachability.\nAC:L - Once XPN with replay protection is deployed, an on-link attacker can passively capture the single legitimate frame at PN 0xFFFFFFFF and then replay it reliably and indefinitely without races or conditions outside their control.\nPR:N - Exploitation requires only the ability to send or replay Ethernet frames on the MACsec link; no local privileges, capabilities, or authentication on the victim Linux host are needed.\nUI:N - Replay injection is fully attacker-driven after capturing the target frame; no victim user or administrator action is required during exploitation.\nS:U - The flaw bypasses MACsec replay protection within the kernel network stack and does not cross a security boundary such as a VM, container, or IOMMU isolation domain.\nC:N - This is a replay-protection logic flaw, not a memory corruption or decryption weakness; the attacker replays already-captured ciphertext and gains no new confidentiality beyond what passive capture already provided.\nI:H - Bypassing replay protection allows unlimited re-injection of previously authenticated payloads into the controlled port, defeating MACsec\u0027s integrity guarantees and enabling repeated delivery of captured control or data traffic on automotive, industrial, and datacenter MACsec links.\nA:H - The commit confirms captured frames can be replayed indefinitely, enabling sustained injection of decrypted traffic that can overwhelm the receiver and deny service to legitimate peers on the protected link."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:20.197Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dd7306779c6ce1238f4cdc34f3c1f2246b854457"
},
{
"url": "https://git.kernel.org/stable/c/d15130461df388136b62a7b0ce9f66e7e2fa9ff1"
},
{
"url": "https://git.kernel.org/stable/c/23c0e230eab397d7f68be2538790ac41d3bb91fd"
},
{
"url": "https://git.kernel.org/stable/c/679e13a65e68a67c8b3c0467c02ee89157ec6f0f"
},
{
"url": "https://git.kernel.org/stable/c/79495a1b0944fe31ffd54b54b00211b493590d62"
},
{
"url": "https://git.kernel.org/stable/c/6d00f5c7e5ff7ec4795b7f5f8ed88bd346641652"
},
{
"url": "https://git.kernel.org/stable/c/d55acbe577db892b60547b6ef1c020b359331a6d"
},
{
"url": "https://git.kernel.org/stable/c/e68842b3356471ba56c882209f324613dac47f64"
}
],
"title": "macsec: fix replay protection at XPN lower-PN wrap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63925",
"datePublished": "2026-07-19T14:55:26.442Z",
"dateReserved": "2026-07-19T07:54:57.021Z",
"dateUpdated": "2026-08-05T12:37:20.197Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63928 (GCVE-0-2026-63928)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-07-19 14:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: omninet: fix memory corruption with small endpoint
Make sure that the bulk-out buffers are at least as large as the
hardcoded transfer size to avoid user-controlled slab corruption should
a malicious device report a smaller endpoint max packet size than
expected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/omninet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "180996f0ca774001944e4afa452d569ba2f6455c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b496e25ead5976bce2891dacaed09beb53a54f9f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "4e7d32189d6219beb7db37cd0ea36b6bac7dfedb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9a3860454bdfb765f936965e975c594352602ffc",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0bda1893e4cc4ad2b7dcdbaca246f2af688c6c2a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0fee0ccac29e088d4bfab7e2d075725dcecd803d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f34cf2928387fba01a78381f3258c7e1428897d9",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "60df93d30f9bdd27db17c4d80ed80ef718d7226b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/omninet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: omninet: fix memory corruption with small endpoint\n\nMake sure that the bulk-out buffers are at least as large as the\nhardcoded transfer size to avoid user-controlled slab corruption should\na malicious device report a smaller endpoint max packet size than\nexpected."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:55:28.593Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/180996f0ca774001944e4afa452d569ba2f6455c"
},
{
"url": "https://git.kernel.org/stable/c/b496e25ead5976bce2891dacaed09beb53a54f9f"
},
{
"url": "https://git.kernel.org/stable/c/4e7d32189d6219beb7db37cd0ea36b6bac7dfedb"
},
{
"url": "https://git.kernel.org/stable/c/9a3860454bdfb765f936965e975c594352602ffc"
},
{
"url": "https://git.kernel.org/stable/c/0bda1893e4cc4ad2b7dcdbaca246f2af688c6c2a"
},
{
"url": "https://git.kernel.org/stable/c/0fee0ccac29e088d4bfab7e2d075725dcecd803d"
},
{
"url": "https://git.kernel.org/stable/c/f34cf2928387fba01a78381f3258c7e1428897d9"
},
{
"url": "https://git.kernel.org/stable/c/60df93d30f9bdd27db17c4d80ed80ef718d7226b"
}
],
"title": "USB: serial: omninet: fix memory corruption with small endpoint",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63928",
"datePublished": "2026-07-19T14:55:28.593Z",
"dateReserved": "2026-07-19T07:54:57.021Z",
"dateUpdated": "2026-07-19T14:55:28.593Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74610 (GCVE-0-2026-74610)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tls: don't leave a full plaintext sk_msg ring unpushed
When the copy path in tls_sw_sendmsg_locked() adds the fragment that fills
the plaintext sk_msg ring, it does not set full_record, so the record is
left full and unpushed. A later splice() then adds to an already full
ring: sk_msg_page_add() has no fullness check of its own, so sg.end wraps
onto sg.start and the ring appears empty. Fragments added after that
overwrite live entries, and sg.size no longer matches what is reachable
between sg.start and sg.end, so pushing the record runs the scatterwalk off
the end of the scatterlist.
An unprivileged user can trigger this on a loopback TCP socket with the
"tls" ULP attached:
BUG: kernel NULL pointer dereference, address: 0000000000000008
RIP: 0010:memcpy_from_scatterwalk+0x32/0xc0
Call Trace:
skcipher_walk_next+0x1d1/0x2c0
gcm_encrypt_aesni_avx+0x1e9/0x220
bpf_exec_tx_verdict+0x3bb/0x860
tls_sw_sendmsg+0xa1a/0xca0
__sys_sendto+0x1da/0x1f0
Set full_record in the copy path when the ring becomes full, and push a
record that is already full on entry to the sendmsg loop.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "aa8b14647721b5a4958712b35cf43e3125d47753",
"status": "affected",
"version": "fe1e81d4f73b6cbaed4fcc476960d26770642842",
"versionType": "git"
},
{
"lessThan": "f634289a0b557a197c5f37284b623cefedfe73d5",
"status": "affected",
"version": "fe1e81d4f73b6cbaed4fcc476960d26770642842",
"versionType": "git"
},
{
"lessThan": "3fc5044796dd87b8d68be4207046f5ce2748174c",
"status": "affected",
"version": "fe1e81d4f73b6cbaed4fcc476960d26770642842",
"versionType": "git"
},
{
"lessThan": "3c5f8f2aa57c647b83add4896aab64aac5fdedad",
"status": "affected",
"version": "fe1e81d4f73b6cbaed4fcc476960d26770642842",
"versionType": "git"
},
{
"lessThan": "7bca91d63341274e857f4aeaad54d229405e93dc",
"status": "affected",
"version": "fe1e81d4f73b6cbaed4fcc476960d26770642842",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: don\u0027t leave a full plaintext sk_msg ring unpushed\n\nWhen the copy path in tls_sw_sendmsg_locked() adds the fragment that fills\nthe plaintext sk_msg ring, it does not set full_record, so the record is\nleft full and unpushed. A later splice() then adds to an already full\nring: sk_msg_page_add() has no fullness check of its own, so sg.end wraps\nonto sg.start and the ring appears empty. Fragments added after that\noverwrite live entries, and sg.size no longer matches what is reachable\nbetween sg.start and sg.end, so pushing the record runs the scatterwalk off\nthe end of the scatterlist.\n\nAn unprivileged user can trigger this on a loopback TCP socket with the\n\"tls\" ULP attached:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000008\n RIP: 0010:memcpy_from_scatterwalk+0x32/0xc0\n Call Trace:\n skcipher_walk_next+0x1d1/0x2c0\n gcm_encrypt_aesni_avx+0x1e9/0x220\n bpf_exec_tx_verdict+0x3bb/0x860\n tls_sw_sendmsg+0xa1a/0xca0\n __sys_sendto+0x1da/0x1f0\n\nSet full_record in the copy path when the ring becomes full, and push a\nrecord that is already full on entry to the sendmsg loop."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached from tls_sw_sendmsg() via local sendmsg/sendto/splice syscalls on a TCP socket with the tls ULP; the copy-then-splice sequence is driven by the sending process (commit repro: unprivileged user on loopback), not by remote TLS ciphertext on RX.\nAC:L - An attacker fully controls the vulnerable send path by crafting alternating copy and MSG_SPLICE_PAGES splice sequences on their kTLS socket until the plaintext sk_msg ring fills without full_record then wraps; no privileged races or special memory layout are required.\nPR:L - Any unprivileged local user can create a TCP socket, attach the tls ULP with TCP_ULP and SOL_TLS setsockopt (no capability checks in net/tls), and trigger the bug with sendmsg/splice as demonstrated on loopback.\nUI:N - Exploitation requires only the attacker\u0027s own socket I/O to sequence copy and splice operations; no action by another user or administrator is needed.\nS:U - Memory corruption occurs within kernel TLS/sk_msg state of the attacking process\u0027s connection context; there is no crossing of VM, container, or IOMMU security boundaries beyond ordinary kernel compromise.\nC:H - Corrupting a full sk_msg ring overwrites live scatterlist entries and desynchronizes sg.size from reachable fragments, so tls_push_record/AEAD scatterwalk can read past the scatterlist end; this class of kernel heap corruption is exploitable for arbitrary memory disclosure beyond the observed NULL deref.\nI:H - The wrap corrupts scatterlist metadata and drives out-of-bounds scatterwalk during GCM encryption, giving attacker-influenced overwrite primitives on kernel heap objects adjacent to sk_msg data, enabling control-flow hijack beyond the demonstrated crash.\nA:H - Pushing a corrupted record runs the AEAD scatterwalk off the scatterlist end, producing a kernel NULL pointer dereference in memcpy_from_scatterwalk during gcm_encrypt and crashing the host (commit oops trace)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:36.026Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/aa8b14647721b5a4958712b35cf43e3125d47753"
},
{
"url": "https://git.kernel.org/stable/c/f634289a0b557a197c5f37284b623cefedfe73d5"
},
{
"url": "https://git.kernel.org/stable/c/3fc5044796dd87b8d68be4207046f5ce2748174c"
},
{
"url": "https://git.kernel.org/stable/c/3c5f8f2aa57c647b83add4896aab64aac5fdedad"
},
{
"url": "https://git.kernel.org/stable/c/7bca91d63341274e857f4aeaad54d229405e93dc"
}
],
"title": "tls: don\u0027t leave a full plaintext sk_msg ring unpushed",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74610",
"datePublished": "2026-08-22T15:31:56.813Z",
"dateReserved": "2026-08-15T05:44:03.920Z",
"dateUpdated": "2026-08-25T05:40:36.026Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64166 (GCVE-0-2026-64166)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_ffa: Check for NULL FF-A ID table while driver registration
The bus match callback assumes that every FF-A driver provides an
id_table and dereferences it unconditionally. Enforce that contract at
registration time so a buggy client driver cannot crash the bus during
match.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 92743071464fca5acbbe812d9a0d88de3eaaad36 Version: 92743071464fca5acbbe812d9a0d88de3eaaad36 Version: 92743071464fca5acbbe812d9a0d88de3eaaad36 Version: 92743071464fca5acbbe812d9a0d88de3eaaad36 Version: 92743071464fca5acbbe812d9a0d88de3eaaad36 Version: 92743071464fca5acbbe812d9a0d88de3eaaad36 Version: 92743071464fca5acbbe812d9a0d88de3eaaad36 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/firmware/arm_ffa/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f98f131256beaddd51ad468e95d90d857fef12bf",
"status": "affected",
"version": "92743071464fca5acbbe812d9a0d88de3eaaad36",
"versionType": "git"
},
{
"lessThan": "bc499d1acddbb75b5b4bce05f5296dd8ef9611fd",
"status": "affected",
"version": "92743071464fca5acbbe812d9a0d88de3eaaad36",
"versionType": "git"
},
{
"lessThan": "adfff93d08a2e12ecf2a1eba272d18bc749f13c0",
"status": "affected",
"version": "92743071464fca5acbbe812d9a0d88de3eaaad36",
"versionType": "git"
},
{
"lessThan": "34f59211984f66788390e7469f3e99d3796db4a8",
"status": "affected",
"version": "92743071464fca5acbbe812d9a0d88de3eaaad36",
"versionType": "git"
},
{
"lessThan": "820245d86ce58898fb48b4fefc77d0cafc02801d",
"status": "affected",
"version": "92743071464fca5acbbe812d9a0d88de3eaaad36",
"versionType": "git"
},
{
"lessThan": "198f6c86d508ed562f07dc00276cac6dbb5dd3bf",
"status": "affected",
"version": "92743071464fca5acbbe812d9a0d88de3eaaad36",
"versionType": "git"
},
{
"lessThan": "0a5e695095c557d2380131b613dea4e8d90371be",
"status": "affected",
"version": "92743071464fca5acbbe812d9a0d88de3eaaad36",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/firmware/arm_ffa/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Check for NULL FF-A ID table while driver registration\n\nThe bus match callback assumes that every FF-A driver provides an\nid_table and dereferences it unconditionally. Enforce that contract at\nregistration time so a buggy client driver cannot crash the bus during\nmatch."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:51.305Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f98f131256beaddd51ad468e95d90d857fef12bf"
},
{
"url": "https://git.kernel.org/stable/c/bc499d1acddbb75b5b4bce05f5296dd8ef9611fd"
},
{
"url": "https://git.kernel.org/stable/c/adfff93d08a2e12ecf2a1eba272d18bc749f13c0"
},
{
"url": "https://git.kernel.org/stable/c/34f59211984f66788390e7469f3e99d3796db4a8"
},
{
"url": "https://git.kernel.org/stable/c/820245d86ce58898fb48b4fefc77d0cafc02801d"
},
{
"url": "https://git.kernel.org/stable/c/198f6c86d508ed562f07dc00276cac6dbb5dd3bf"
},
{
"url": "https://git.kernel.org/stable/c/0a5e695095c557d2380131b613dea4e8d90371be"
}
],
"title": "firmware: arm_ffa: Check for NULL FF-A ID table while driver registration",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64166",
"datePublished": "2026-07-19T15:40:51.305Z",
"dateReserved": "2026-07-19T07:54:57.038Z",
"dateUpdated": "2026-07-19T15:40:51.305Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68111 (GCVE-0-2026-68111)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit b71604f8685b0eba07866f4e8dc30f93e1931054)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "67965f576f9337e387dc8efaf9a46cb6b7ea12cb",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "9b5e4fa18fea1e7f6017e1af02fa10276628d9a0",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "6978b10861850b93292fcd6b22a5495d69fce276",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "6c8b9c1f03c7169c9577098b0c3035617606f8d4",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "d74a6351d3f64e1f8a0fba28b369c0eeecf517f1",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "042c047e8bc9c9ada7574028a8e4592102e2e1fd",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "43768ad42b8f1a91652b86e0731ac14d6853cebb",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "6302be10b521f5106ce01eb5a724b9e7945a5061",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit b71604f8685b0eba07866f4e8dc30f93e1931054)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:24.565Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/67965f576f9337e387dc8efaf9a46cb6b7ea12cb"
},
{
"url": "https://git.kernel.org/stable/c/9b5e4fa18fea1e7f6017e1af02fa10276628d9a0"
},
{
"url": "https://git.kernel.org/stable/c/6978b10861850b93292fcd6b22a5495d69fce276"
},
{
"url": "https://git.kernel.org/stable/c/6c8b9c1f03c7169c9577098b0c3035617606f8d4"
},
{
"url": "https://git.kernel.org/stable/c/d74a6351d3f64e1f8a0fba28b369c0eeecf517f1"
},
{
"url": "https://git.kernel.org/stable/c/042c047e8bc9c9ada7574028a8e4592102e2e1fd"
},
{
"url": "https://git.kernel.org/stable/c/43768ad42b8f1a91652b86e0731ac14d6853cebb"
},
{
"url": "https://git.kernel.org/stable/c/6302be10b521f5106ce01eb5a724b9e7945a5061"
}
],
"title": "drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68111",
"datePublished": "2026-08-10T11:58:28.489Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:24.565Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63808 (GCVE-0-2026-63808)
Vulnerability from cvelistv5
Published
2026-07-19 12:02
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
exfat: fix potential use-after-free in exfat_find_dir_entry()
In exfat_find_dir_entry(), the buffer_head obtained from
exfat_get_dentry() is released with brelse(bh) before the fall-through
TYPE_EXTEND branch reads the directory entry through ep (which points
into bh->b_data):
brelse(bh);
if (entry_type == TYPE_EXTEND) {
...
len = exfat_extract_uni_name(ep, entry_uniname);
...
}
After brelse() drops our reference, nothing guarantees that the
underlying page backing bh->b_data remains valid for the subsequent
exfat_extract_uni_name() read. This is the same pattern fixed in
commit fc961522ddbd ("exfat: Fix potential use after free in
exfat_load_upcase_table()").
Move brelse(bh) so it runs after ep is no longer dereferenced on
each branch.
Confirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y
+ CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image
(long filename with same-hash collisions forcing the TYPE_EXTEND path).
With a debug-only invalidate_bdev() inserted between brelse(bh) and
the ep read to make the stale-deref window deterministic, the
unpatched kernel faults:
BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0
BUG: unable to handle page fault for address: ffff88801a5fa0c2
Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI
RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0
With this patch applied, the same instrumented harness completes
cleanly under the same sanitizer stack. I have not reproduced a
crash on an uninstrumented kernel under ordinary reclaim; the
instrumented A/B establishes the lifetime violation and that the
patch closes it, not an unaided triggerability claim.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/exfat/dir.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e6f1a11cfb808441a43ffae9b476cc135732cd27",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "e48f413c2815787b8cade2795e194e3c4cd782ef",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "06c4e1e9967d332ac33ba38b7819851089ff9359",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "8e0abc17fbd7e305802e84fe98b4950d50f9c433",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "4d101016d5e587f820b3ae2d5bb6770d86342649",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "adfacfbaeae2cb760f492357cc36b41f84ef7f86",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "708b97e792945d3e4653939fd3405d71a61ad065",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "3f5f8ee9917cc2b9076ac533492d8a200edcabb8",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/exfat/dir.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.260",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.260",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix potential use-after-free in exfat_find_dir_entry()\n\nIn exfat_find_dir_entry(), the buffer_head obtained from\nexfat_get_dentry() is released with brelse(bh) before the fall-through\nTYPE_EXTEND branch reads the directory entry through ep (which points\ninto bh-\u003eb_data):\n\n\tbrelse(bh);\n\tif (entry_type == TYPE_EXTEND) {\n\t\t...\n\t\tlen = exfat_extract_uni_name(ep, entry_uniname);\n\t\t...\n\t}\n\nAfter brelse() drops our reference, nothing guarantees that the\nunderlying page backing bh-\u003eb_data remains valid for the subsequent\nexfat_extract_uni_name() read. This is the same pattern fixed in\ncommit fc961522ddbd (\"exfat: Fix potential use after free in\nexfat_load_upcase_table()\").\n\nMove brelse(bh) so it runs after ep is no longer dereferenced on\neach branch.\n\nConfirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y\n+ CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image\n(long filename with same-hash collisions forcing the TYPE_EXTEND path).\nWith a debug-only invalidate_bdev() inserted between brelse(bh) and\nthe ep read to make the stale-deref window deterministic, the\nunpatched kernel faults:\n\n BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0\n BUG: unable to handle page fault for address: ffff88801a5fa0c2\n Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI\n RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0\n\nWith this patch applied, the same instrumented harness completes\ncleanly under the same sanitizer stack. I have not reproduced a\ncrash on an uninstrumented kernel under ordinary reclaim; the\ninstrumented A/B establishes the lifetime violation and that the\npatch closes it, not an unaided triggerability claim."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - exfat_find_dir_entry() is invoked during VFS directory lookups on mounted exFAT volumes, reachable remotely when that volume is exported via ksmbd or nfsd (common on NAS/router USB shares). A network client resolving paths on the share triggers server-side exfat_lookup without local shell access.\nAC:L - The attacker fully controls the crafted exFAT image to force the TYPE_EXTEND code path and can repeatedly trigger lookups (including concurrent SMB/NFS requests and memory pressure) to win the post-brelse buffer reclaim window. UAF lifetime violations are treated as low complexity per kernel guidance.\nPR:N - Exploitation requires only access to the mounted exFAT filesystem, not real root; guest/anonymous SMB shares on consumer NAS devices and auto-mounted removable media grant unprivileged attackers filesystem access without elevated kernel credentials.\nUI:N - Once a crafted exFAT image is present on a shared or auto-mounted volume, triggering the bug requires only automated path lookups (SMB OPEN/LOOKUP, openat, statx) with no additional victim interaction beyond normal filesystem access.\nS:U - Successful exploitation compromises kernel memory within the same security authority; this is a standard kernel memory corruption issue, not a cross-boundary escape such as VM guest-to-host breakout.\nC:H - The UAF reads freed buffer_head page cache memory through exfat_extract_uni_name(), enabling out-of-bounds kernel heap reads and information disclosure from attacker-influenced reclaimed data.\nI:H - Use-after-free on buffer_head data provides a foundation for heap grooming and arbitrary memory corruption primitives that can be leveraged for kernel code execution and integrity compromise.\nA:H - The bug is a confirmed kernel use-after-free that produced a KASAN fault and page fault oops; even without full exploitation it can cause kernel crashes and denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:14.402Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e6f1a11cfb808441a43ffae9b476cc135732cd27"
},
{
"url": "https://git.kernel.org/stable/c/e48f413c2815787b8cade2795e194e3c4cd782ef"
},
{
"url": "https://git.kernel.org/stable/c/06c4e1e9967d332ac33ba38b7819851089ff9359"
},
{
"url": "https://git.kernel.org/stable/c/8e0abc17fbd7e305802e84fe98b4950d50f9c433"
},
{
"url": "https://git.kernel.org/stable/c/4d101016d5e587f820b3ae2d5bb6770d86342649"
},
{
"url": "https://git.kernel.org/stable/c/adfacfbaeae2cb760f492357cc36b41f84ef7f86"
},
{
"url": "https://git.kernel.org/stable/c/708b97e792945d3e4653939fd3405d71a61ad065"
},
{
"url": "https://git.kernel.org/stable/c/3f5f8ee9917cc2b9076ac533492d8a200edcabb8"
}
],
"title": "exfat: fix potential use-after-free in exfat_find_dir_entry()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63808",
"datePublished": "2026-07-19T12:02:11.323Z",
"dateReserved": "2026-07-19T07:54:57.013Z",
"dateUpdated": "2026-08-17T04:51:14.402Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64569 (GCVE-0-2026-64569)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
On CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed
attribute table itself instead of calling ip_valid_fib_dump_req(). The
RTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is
present, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no
RTA_OIF hits a NULL dereference.
RTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without
CAP_NET_ADMIN, so an unprivileged user can trigger it.
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)
Call Trace:
mpls_dump_routes (net/mpls/af_mpls.c:2236)
netlink_dump (net/netlink/af_netlink.c:2331)
__netlink_dump_start (net/netlink/af_netlink.c:2446)
rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)
netlink_rcv_skb (net/netlink/af_netlink.c:2556)
netlink_unicast (net/netlink/af_netlink.c:1345)
netlink_sendmsg (net/netlink/af_netlink.c:1900)
__sock_sendmsg (net/socket.c:790)
____sys_sendmsg (net/socket.c:2684)
___sys_sendmsg (net/socket.c:2738)
__sys_sendmsg (net/socket.c:2770)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Skip unset attributes, as ip_valid_fib_dump_req() does.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mpls/af_mpls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bfc1cb5d6a8308e493e307f1c823d2107abc0a47",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "03b5a2c29afc8e634924c75d6ee94140e70de88d",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "e796ce9ef4356dc7cbbaa8373843f77852f2814d",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "d6eee7cd078aaf9dd75efc801f6c9b608a37cd71",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "5f6e7b32bd1fbde10fd31a4143260735ea535b8a",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "06db79411a280707c7e4bf4b221ff4e664b51502",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "56d96fededd61192cd7cc8d2b0f36adfd59036c3",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mpls/af_mpls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n\n\nOn CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed\nattribute table itself instead of calling ip_valid_fib_dump_req(). The\nRTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is\npresent, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no\nRTA_OIF hits a NULL dereference.\n\nRTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without\nCAP_NET_ADMIN, so an unprivileged user can trigger it.\n\n Oops: general protection fault, probably for non-canonical address\n 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)\n Call Trace:\n mpls_dump_routes (net/mpls/af_mpls.c:2236)\n netlink_dump (net/netlink/af_netlink.c:2331)\n __netlink_dump_start (net/netlink/af_netlink.c:2446)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)\n netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n netlink_unicast (net/netlink/af_netlink.c:1345)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n __sock_sendmsg (net/socket.c:790)\n ____sys_sendmsg (net/socket.c:2684)\n ___sys_sendmsg (net/socket.c:2738)\n __sys_sendmsg (net/socket.c:2770)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nSkip unset attributes, as ip_valid_fib_dump_req() does."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:44.216Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bfc1cb5d6a8308e493e307f1c823d2107abc0a47"
},
{
"url": "https://git.kernel.org/stable/c/03b5a2c29afc8e634924c75d6ee94140e70de88d"
},
{
"url": "https://git.kernel.org/stable/c/e796ce9ef4356dc7cbbaa8373843f77852f2814d"
},
{
"url": "https://git.kernel.org/stable/c/d6eee7cd078aaf9dd75efc801f6c9b608a37cd71"
},
{
"url": "https://git.kernel.org/stable/c/ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce"
},
{
"url": "https://git.kernel.org/stable/c/5f6e7b32bd1fbde10fd31a4143260735ea535b8a"
},
{
"url": "https://git.kernel.org/stable/c/06db79411a280707c7e4bf4b221ff4e664b51502"
},
{
"url": "https://git.kernel.org/stable/c/56d96fededd61192cd7cc8d2b0f36adfd59036c3"
}
],
"title": "mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64569",
"datePublished": "2026-08-05T08:08:07.233Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:44.216Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64332 (GCVE-0-2026-64332)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: ulpi: fix memory leak on registration failure
The allocated device name is never freed on early ULPI device
registration failures.
Fix this by initialising the device structure earlier and releasing the
initial reference whenever registration fails.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f Version: 289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/common/ulpi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d5b32f36c50894ac2df8fa184e6f35f3a6665ecd",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "691e61e5d4cfc5a1b061e937f8cbf2126bfc19a0",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "88187a43135c79d0e43573b4d8f880bbb919eceb",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "5c098f20f15db7f9126129686d1c6da2ce8bbeb0",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "624c57147df1977e0d3da53f1da7117861b9cf19",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "1967a7f0cd5c08eb479196daa5aaa4b7b7a7bd04",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "e5493c9a98ffe083acf13ac064828ae598ba3c16",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
},
{
"lessThan": "8af6812795869a66e9b26044f455b13deecdb69c",
"status": "affected",
"version": "289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/common/ulpi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: ulpi: fix memory leak on registration failure\n\nThe allocated device name is never freed on early ULPI device\nregistration failures.\n\nFix this by initialising the device structure earlier and releasing the\ninitial reference whenever registration fails."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:35.002Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d5b32f36c50894ac2df8fa184e6f35f3a6665ecd"
},
{
"url": "https://git.kernel.org/stable/c/691e61e5d4cfc5a1b061e937f8cbf2126bfc19a0"
},
{
"url": "https://git.kernel.org/stable/c/88187a43135c79d0e43573b4d8f880bbb919eceb"
},
{
"url": "https://git.kernel.org/stable/c/5c098f20f15db7f9126129686d1c6da2ce8bbeb0"
},
{
"url": "https://git.kernel.org/stable/c/624c57147df1977e0d3da53f1da7117861b9cf19"
},
{
"url": "https://git.kernel.org/stable/c/1967a7f0cd5c08eb479196daa5aaa4b7b7a7bd04"
},
{
"url": "https://git.kernel.org/stable/c/e5493c9a98ffe083acf13ac064828ae598ba3c16"
},
{
"url": "https://git.kernel.org/stable/c/8af6812795869a66e9b26044f455b13deecdb69c"
}
],
"title": "USB: ulpi: fix memory leak on registration failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64332",
"datePublished": "2026-07-25T08:49:59.005Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:35.002Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64052 (GCVE-0-2026-64052)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-07-19 15:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()
pin_user_pages_fast() can partially succeed and return the number of
pages that were actually pinned. However, the bio_integrity_map_user()
does not handle this partial pinning. This leads to a general protection
fault since bvec_from_pages() dereferences an unpinned page address,
which is 0.
To fix this, add a check to verify that all requested memory is pinned.
If partial pinning occurs, unpin the memory and return -EFAULT.
Kernel Oops:
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
CPU: 0 UID: 0 PID: 1061 Comm: nvme-passthroug Not tainted 7.0.0-11783-g90957f9314e8-dirty #16 PREEMPT(lazy)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014
RIP: 0010:bio_integrity_map_user.cold+0x1b0/0x9d6
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"block/bio-integrity.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "77c059f41e9395793917d067476f549a911d77d3",
"status": "affected",
"version": "492c5d455969fc2e829f26ed4c83487b068f0dd7",
"versionType": "git"
},
{
"lessThan": "76410790f1491c8e06a451045ae223a61c652455",
"status": "affected",
"version": "492c5d455969fc2e829f26ed4c83487b068f0dd7",
"versionType": "git"
},
{
"lessThan": "8fa244738641d95ea4d70e6f9a62778bba42a5b7",
"status": "affected",
"version": "492c5d455969fc2e829f26ed4c83487b068f0dd7",
"versionType": "git"
},
{
"lessThan": "8582792cf23b3d94674d4d838f7cde9a28d0fcaf",
"status": "affected",
"version": "492c5d455969fc2e829f26ed4c83487b068f0dd7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"block/bio-integrity.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()\n\npin_user_pages_fast() can partially succeed and return the number of\npages that were actually pinned. However, the bio_integrity_map_user()\ndoes not handle this partial pinning. This leads to a general protection\nfault since bvec_from_pages() dereferences an unpinned page address,\nwhich is 0.\n\nTo fix this, add a check to verify that all requested memory is pinned.\nIf partial pinning occurs, unpin the memory and return -EFAULT.\n\nKernel Oops:\n\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 0 UID: 0 PID: 1061 Comm: nvme-passthroug Not tainted 7.0.0-11783-g90957f9314e8-dirty #16 PREEMPT(lazy)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\nRIP: 0010:bio_integrity_map_user.cold+0x1b0/0x9d6"
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:39:35.223Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/77c059f41e9395793917d067476f549a911d77d3"
},
{
"url": "https://git.kernel.org/stable/c/76410790f1491c8e06a451045ae223a61c652455"
},
{
"url": "https://git.kernel.org/stable/c/8fa244738641d95ea4d70e6f9a62778bba42a5b7"
},
{
"url": "https://git.kernel.org/stable/c/8582792cf23b3d94674d4d838f7cde9a28d0fcaf"
}
],
"title": "block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64052",
"datePublished": "2026-07-19T15:39:35.223Z",
"dateReserved": "2026-07-19T07:54:57.029Z",
"dateUpdated": "2026-07-19T15:39:35.223Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64337 (GCVE-0-2026-64337)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: mtu3: unmap request DMA on queue failure
mtu3_gadget_queue() maps the request before checking whether
the QMU GPD ring can accept another transfer. the request is
returned with -EAGAIN before it is linked on the endpoint
request list if mtu3_prepare_transfer() fails.
Normal completion and dequeue paths unmap requests from
mtu3_req_complete(), but this error path never reaches that
helper, so the DMA mapping is left active. Unmap the request
before returning from the failed queue path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: df2069acb00569a6299d6e11aa1865eeba463848 Version: df2069acb00569a6299d6e11aa1865eeba463848 Version: df2069acb00569a6299d6e11aa1865eeba463848 Version: df2069acb00569a6299d6e11aa1865eeba463848 Version: df2069acb00569a6299d6e11aa1865eeba463848 Version: df2069acb00569a6299d6e11aa1865eeba463848 Version: df2069acb00569a6299d6e11aa1865eeba463848 Version: df2069acb00569a6299d6e11aa1865eeba463848 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/mtu3/mtu3_gadget.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3cee30f1138281a1d247bb053a1ad4f7c5b04e98",
"status": "affected",
"version": "df2069acb00569a6299d6e11aa1865eeba463848",
"versionType": "git"
},
{
"lessThan": "f3c4026524d3660c73ef2838b99776d37631e039",
"status": "affected",
"version": "df2069acb00569a6299d6e11aa1865eeba463848",
"versionType": "git"
},
{
"lessThan": "e8f739a3860d043dcc135371637e82f53132efe5",
"status": "affected",
"version": "df2069acb00569a6299d6e11aa1865eeba463848",
"versionType": "git"
},
{
"lessThan": "4183874b7925f4a98b400cf857bea26ee87da236",
"status": "affected",
"version": "df2069acb00569a6299d6e11aa1865eeba463848",
"versionType": "git"
},
{
"lessThan": "00c3fef4c2dc2c7cbd8281f8fda09d1913420f09",
"status": "affected",
"version": "df2069acb00569a6299d6e11aa1865eeba463848",
"versionType": "git"
},
{
"lessThan": "8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1",
"status": "affected",
"version": "df2069acb00569a6299d6e11aa1865eeba463848",
"versionType": "git"
},
{
"lessThan": "835b0596d4c9bdef93f842d8f826978fb4956b74",
"status": "affected",
"version": "df2069acb00569a6299d6e11aa1865eeba463848",
"versionType": "git"
},
{
"lessThan": "0bddda5a11665c210339de76d27ebbd1a2e0b43c",
"status": "affected",
"version": "df2069acb00569a6299d6e11aa1865eeba463848",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/mtu3/mtu3_gadget.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: mtu3: unmap request DMA on queue failure\n\nmtu3_gadget_queue() maps the request before checking whether\nthe QMU GPD ring can accept another transfer. the request is\nreturned with -EAGAIN before it is linked on the endpoint\nrequest list if mtu3_prepare_transfer() fails.\n\nNormal completion and dequeue paths unmap requests from\nmtu3_req_complete(), but this error path never reaches that\nhelper, so the DMA mapping is left active. Unmap the request\nbefore returning from the failed queue path."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:40.517Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3cee30f1138281a1d247bb053a1ad4f7c5b04e98"
},
{
"url": "https://git.kernel.org/stable/c/f3c4026524d3660c73ef2838b99776d37631e039"
},
{
"url": "https://git.kernel.org/stable/c/e8f739a3860d043dcc135371637e82f53132efe5"
},
{
"url": "https://git.kernel.org/stable/c/4183874b7925f4a98b400cf857bea26ee87da236"
},
{
"url": "https://git.kernel.org/stable/c/00c3fef4c2dc2c7cbd8281f8fda09d1913420f09"
},
{
"url": "https://git.kernel.org/stable/c/8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1"
},
{
"url": "https://git.kernel.org/stable/c/835b0596d4c9bdef93f842d8f826978fb4956b74"
},
{
"url": "https://git.kernel.org/stable/c/0bddda5a11665c210339de76d27ebbd1a2e0b43c"
}
],
"title": "usb: mtu3: unmap request DMA on queue failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64337",
"datePublished": "2026-07-25T08:50:02.066Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:40.517Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53059 (GCVE-0-2026-53059)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-09-04 12:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dm log: fix out-of-bounds write due to region_count overflow
The local variable region_count in create_log_context() is declared as
unsigned int (32-bit), but dm_sector_div_up() returns sector_t (64-bit).
When a device-mapper target has a sufficiently large ti->len with a small
region_size, the division result can exceed UINT_MAX. The truncated
value is then used to calculate bitset_size, causing clean_bits,
sync_bits, and recovering_bits to be allocated far smaller than needed
for the actual number of regions.
Subsequent log operations (log_set_bit, log_clear_bit, log_test_bit) use
region indices derived from the full untruncated region space, causing
out-of-bounds writes to kernel heap memory allocated by vmalloc.
This can be reproduced by creating a mirror target whose region_count
overflows 32 bits:
dmsetup create bigzero --table '0 8589934594 zero'
dmsetup create mymirror --table '0 8589934594 mirror \
core 2 2 nosync 2 /dev/mapper/bigzero 0 \
/dev/mapper/bigzero 0'
The status output confirms the truncation (sync_count=1 instead of
4294967297, because 0x100000001 was truncated to 1):
$ dmsetup status mymirror
0 8589934594 mirror 2 254:1 254:1 1/4294967297 ...
This leads to a kernel crash in core_in_sync:
BUG: scheduling while atomic: (udev-worker)/9150/0x00000000
RIP: 0010:core_in_sync+0x14/0x30 [dm_log]
CR2: 0000000000000008
Fixing recursive fault but reboot is needed!
Fix by widening the local region_count to sector_t and adding an
explicit overflow check before the value is assigned to lc->region_count.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10.2"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:6.12.0-211.39.1.el10_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux_eus:10.0"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:6.12.0-55.98.1.el10_0",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_extras_rt_els:7"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:3.10.0-1160.159.1.rt56.1311.el7",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_els:7"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:3.10.0-1160.159.1.el7",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:8::nfv"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.147.1.rt7.488.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.147.1.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_aus:8.4"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-305.200.1.el8_4",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_eus_long_life:8.4"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-305.200.1.el8_4",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_aus:8.6"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-372.206.1.el8_6",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_eus_long_life:8.6"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-372.206.1.el8_6",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_tus:8.8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-477.158.1.el8_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_e4s:8.8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-477.158.1.el8_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:9",
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-687.30.1.el9_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_e4s:9.2"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-284.188.1.el9_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_e4s:9.2::nfv"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-284.188.1.rt14.473.el9_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_eus:9.6"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.6 Extended Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-570.135.1.el9_6",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unknown",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-06-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel\u0027s device-mapper log (dm log) component. A local attacker could exploit an integer overflow vulnerability where a 64-bit value is truncated to 32 bits, leading to undersized memory allocations. This allows for out-of-bounds writes to kernel memory during log operations. Successful exploitation of this flaw can cause a kernel crash, resulting in a Denial of Service (DoS) for the affected system."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Moderate"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-190",
"description": "Integer Overflow or Wraparound",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T12:04:41.314Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-53059"
},
{
"name": "RHBZ#2492277",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492277"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53059.json"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:61692"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:63189"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:55445"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:45114"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:59662"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:56574"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:45192"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:45115"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:47248"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:53989"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:52649"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:45116"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:59663"
}
],
"solutions": [
{
"lang": "en",
"value": "RHSA-2026:61692: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS)"
},
{
"lang": "en",
"value": "RHSA-2026:63189: Red Hat Enterprise Linux for Real Time (v. 7 ELS)"
},
{
"lang": "en",
"value": "RHSA-2026:55445: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0), Red Hat Enterprise Linux Real Time EUS (v. 10.0), Red Hat Enterprise Linux Real Time for NFV EUS (v. 10.0)"
},
{
"lang": "en",
"value": "RHSA-2026:45114: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10)"
},
{
"lang": "en",
"value": "RHSA-2026:59662: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2)"
},
{
"lang": "en",
"value": "RHSA-2026:56574: Red Hat CodeReady Linux Builder EUS (v.9.6), Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux BaseOS EUS (v.9.6), Red Hat Enterprise Linux Real Time EUS (v.9.6), Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6)"
},
{
"lang": "en",
"value": "RHSA-2026:45192: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9)"
},
{
"lang": "en",
"value": "RHSA-2026:45115: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:47248: Red Hat Enterprise Linux BaseOS AUS (v.8.4), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)"
},
{
"lang": "en",
"value": "RHSA-2026:53989: Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)"
},
{
"lang": "en",
"value": "RHSA-2026:52649: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8)"
},
{
"lang": "en",
"value": "RHSA-2026:45116: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:59663: Red Hat Enterprise Linux Real Time E4S (v.9.2), Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: dm log: fix out-of-bounds write due to region_count overflow",
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/dm-log.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "44ab8875ae4a2842bde2d756bed195d375e0debb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "defe483e47173768c227532694dc78cb65db5f09",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3ec74da927b4e171a6fc0e77b1188ba4d019af51",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d4ac87567f86a55c3c92e9a5144dcd943a9772a1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "12bd5b88e91a02785244ff1d20fb157e96e9cdc8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b455903eed4558982be0811f5b7f44f6bbc4ff57",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "4ec8323b9f0764a14d532b1ae9b87f8a9fecb867",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c20e36b7631d83e7535877f08af8b0af72c44b1a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/dm-log.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm log: fix out-of-bounds write due to region_count overflow\n\nThe local variable region_count in create_log_context() is declared as\nunsigned int (32-bit), but dm_sector_div_up() returns sector_t (64-bit).\nWhen a device-mapper target has a sufficiently large ti-\u003elen with a small\nregion_size, the division result can exceed UINT_MAX. The truncated\nvalue is then used to calculate bitset_size, causing clean_bits,\nsync_bits, and recovering_bits to be allocated far smaller than needed\nfor the actual number of regions.\n\nSubsequent log operations (log_set_bit, log_clear_bit, log_test_bit) use\nregion indices derived from the full untruncated region space, causing\nout-of-bounds writes to kernel heap memory allocated by vmalloc.\n\nThis can be reproduced by creating a mirror target whose region_count\noverflows 32 bits:\n\n dmsetup create bigzero --table \u00270 8589934594 zero\u0027\n dmsetup create mymirror --table \u00270 8589934594 mirror \\\n core 2 2 nosync 2 /dev/mapper/bigzero 0 \\\n /dev/mapper/bigzero 0\u0027\n\nThe status output confirms the truncation (sync_count=1 instead of\n4294967297, because 0x100000001 was truncated to 1):\n\n $ dmsetup status mymirror\n 0 8589934594 mirror 2 254:1 254:1 1/4294967297 ...\n\nThis leads to a kernel crash in core_in_sync:\n\n BUG: scheduling while atomic: (udev-worker)/9150/0x00000000\n RIP: 0010:core_in_sync+0x14/0x30 [dm_log]\n CR2: 0000000000000008\n Fixing recursive fault but reboot is needed!\n\nFix by widening the local region_count to sector_t and adding an\nexplicit overflow check before the value is assigned to lc-\u003eregion_count."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-24T16:30:04.210Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/44ab8875ae4a2842bde2d756bed195d375e0debb"
},
{
"url": "https://git.kernel.org/stable/c/defe483e47173768c227532694dc78cb65db5f09"
},
{
"url": "https://git.kernel.org/stable/c/3ec74da927b4e171a6fc0e77b1188ba4d019af51"
},
{
"url": "https://git.kernel.org/stable/c/d4ac87567f86a55c3c92e9a5144dcd943a9772a1"
},
{
"url": "https://git.kernel.org/stable/c/12bd5b88e91a02785244ff1d20fb157e96e9cdc8"
},
{
"url": "https://git.kernel.org/stable/c/b455903eed4558982be0811f5b7f44f6bbc4ff57"
},
{
"url": "https://git.kernel.org/stable/c/4ec8323b9f0764a14d532b1ae9b87f8a9fecb867"
},
{
"url": "https://git.kernel.org/stable/c/c20e36b7631d83e7535877f08af8b0af72c44b1a"
}
],
"title": "dm log: fix out-of-bounds write due to region_count overflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53059",
"datePublished": "2026-06-24T16:30:04.210Z",
"dateReserved": "2026-06-09T07:44:35.382Z",
"dateUpdated": "2026-09-04T12:04:41.314Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53089 (GCVE-0-2026-53089)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix use-after-free in offloaded map/prog info fill
When querying info for an offloaded BPF map or program,
bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns()
obtain the network namespace with get_net(dev_net(offmap->netdev)).
However, the associated netdev's netns may be racing with teardown
during netns destruction. If the netns refcount has already reached 0,
get_net() performs a refcount_t increment on 0, triggering:
refcount_t: addition on 0; use-after-free.
Although rtnl_lock and bpf_devs_lock ensure the netdev pointer remains
valid, they cannot prevent the netns refcount from reaching zero.
Fix this by using maybe_get_net() instead of get_net(). maybe_get_net()
uses refcount_inc_not_zero() and returns NULL if the refcount is already
zero, which causes ns_get_path_cb() to fail and the caller to return
-ENOENT -- the correct behavior when the netns is being destroyed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/bpf/offload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "43d6848a2a6c92ccfd614d9f0bb6fd85b95dfa9d",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "642943ae5bdacabc8109dc4a5e0ebb4a6b99ef3e",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "fea55b034328feaafef75aee252f305e6f85a991",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "5662dac41a3442aa378d7c405164903eb109fc05",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "1a2dc103e16448d022a77ad5fc3234641436c4b7",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "85dc711f742b192eb97c0e00b521312f5a7a415e",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "a51e7fbe94a87e236631a83973d4f558310b2cd2",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "a0c584fc18056709c8e047a82a6045d6c209f4ce",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/bpf/offload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.16"
},
{
"lessThan": "4.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix use-after-free in offloaded map/prog info fill\n\nWhen querying info for an offloaded BPF map or program,\nbpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns()\nobtain the network namespace with get_net(dev_net(offmap-\u003enetdev)).\nHowever, the associated netdev\u0027s netns may be racing with teardown\nduring netns destruction. If the netns refcount has already reached 0,\nget_net() performs a refcount_t increment on 0, triggering:\n\n refcount_t: addition on 0; use-after-free.\n\nAlthough rtnl_lock and bpf_devs_lock ensure the netdev pointer remains\nvalid, they cannot prevent the netns refcount from reaching zero.\n\nFix this by using maybe_get_net() instead of get_net(). maybe_get_net()\nuses refcount_inc_not_zero() and returns NULL if the refcount is already\nzero, which causes ns_get_path_cb() to fail and the caller to return\n-ENOENT -- the correct behavior when the netns is being destroyed."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:34.606Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/43d6848a2a6c92ccfd614d9f0bb6fd85b95dfa9d"
},
{
"url": "https://git.kernel.org/stable/c/642943ae5bdacabc8109dc4a5e0ebb4a6b99ef3e"
},
{
"url": "https://git.kernel.org/stable/c/fea55b034328feaafef75aee252f305e6f85a991"
},
{
"url": "https://git.kernel.org/stable/c/5662dac41a3442aa378d7c405164903eb109fc05"
},
{
"url": "https://git.kernel.org/stable/c/1a2dc103e16448d022a77ad5fc3234641436c4b7"
},
{
"url": "https://git.kernel.org/stable/c/85dc711f742b192eb97c0e00b521312f5a7a415e"
},
{
"url": "https://git.kernel.org/stable/c/a51e7fbe94a87e236631a83973d4f558310b2cd2"
},
{
"url": "https://git.kernel.org/stable/c/a0c584fc18056709c8e047a82a6045d6c209f4ce"
}
],
"title": "bpf: Fix use-after-free in offloaded map/prog info fill",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53089",
"datePublished": "2026-06-24T16:30:28.531Z",
"dateReserved": "2026-06-09T07:44:35.384Z",
"dateUpdated": "2026-09-02T12:49:34.606Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68135 (GCVE-0-2026-68135)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: hip04: fix RX buffer leak on build_skb failure
When build_skb() fails in hip04_rx_poll(), the driver jumps to the
refill path without releasing the current RX buffer and its DMA mapping.
Installing a replacement buffer then overwrites the slot references and
leaks both resources.
Keep the current slot intact and return budget so NAPI retries the same
buffer. Also free a newly allocated RX fragment when dma_map_single()
fails.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/hisilicon/hip04_eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "690ecc13a4032e5cae1dc6659512f32b033533b0",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "2b19fe277645fd1aeb18fd4ecdcf31966080dee7",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "bcd43ee1f25b682151df213c06a99b2e1c1cf2e5",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "e054dcd990d8180cde529ea28ce0838e76a5ad5e",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "67a7614bde310da006ab259f4f163d3fb0f9e253",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "80d977f280b4eccd4ac5369871d0ecb2b9c9a49d",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "a0f247d63489a107bbc3b712a77b302af2a2a173",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "14fa65d10f5696b063a7d8d26e8291ea84a2c6ed",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/hisilicon/hip04_eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hip04: fix RX buffer leak on build_skb failure\n\nWhen build_skb() fails in hip04_rx_poll(), the driver jumps to the\nrefill path without releasing the current RX buffer and its DMA mapping.\nInstalling a replacement buffer then overwrites the slot references and\nleaks both resources.\n\nKeep the current slot intact and return budget so NAPI retries the same\nbuffer. Also free a newly allocated RX fragment when dma_map_single()\nfails.\n\nThis issue was found by an in-house static analysis tool."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:52.114Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/690ecc13a4032e5cae1dc6659512f32b033533b0"
},
{
"url": "https://git.kernel.org/stable/c/2b19fe277645fd1aeb18fd4ecdcf31966080dee7"
},
{
"url": "https://git.kernel.org/stable/c/bcd43ee1f25b682151df213c06a99b2e1c1cf2e5"
},
{
"url": "https://git.kernel.org/stable/c/e054dcd990d8180cde529ea28ce0838e76a5ad5e"
},
{
"url": "https://git.kernel.org/stable/c/67a7614bde310da006ab259f4f163d3fb0f9e253"
},
{
"url": "https://git.kernel.org/stable/c/80d977f280b4eccd4ac5369871d0ecb2b9c9a49d"
},
{
"url": "https://git.kernel.org/stable/c/a0f247d63489a107bbc3b712a77b302af2a2a173"
},
{
"url": "https://git.kernel.org/stable/c/14fa65d10f5696b063a7d8d26e8291ea84a2c6ed"
}
],
"title": "net: hip04: fix RX buffer leak on build_skb failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68135",
"datePublished": "2026-08-10T11:58:58.463Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:52.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72464 (GCVE-0-2026-72464)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xprtrdma: Repost Receive buffers for malformed replies
rpcrdma_wc_receive() decrements the transport's Receive count for
every completion before it dispatches a successful Receive to
rpcrdma_reply_handler(). The handler must post a replacement
Receive WR before returning unless ownership of the rep has moved
elsewhere, as on the backchannel path.
Commit 2ae50ad68cd7 ("xprtrdma: Close window between waking RPC
senders and posting Receives") moved the Receive refill out of
rpcrdma_wc_receive(), where it had run ahead of every reply, into
rpcrdma_reply_handler() so that the responder's credit grant could
be parsed before reposting. The bad-version and short-reply exits
never reach that refill: they recycle the rep and return without
calling rpcrdma_post_recvs().
A remote peer can therefore drain the client's posted Receive
queue by sending a sustained stream of replies that are shorter
than the fixed transport header or that carry an unrecognized
RPC/RDMA version. Each such reply consumes one posted Receive
without replacing it. Once the queue empties, the peer's next
Send finds no posted Receive and the transport stalls until
reconnect.
Route both malformed-reply exits through the shared repost tail
after recycling the rep, refilling against buf->rb_credits, the
most recent accepted credit grant. Neither exit updates the
congestion window, so RPCs admitted under the previous grant
remain in flight awaiting replies. A smaller refill target would
let a stream of malformed replies ratchet the posted Receive count
down to the batch floor while the congestion window still admits
rb_credits RPCs; a burst of valid replies to those RPCs could then
overrun the posted Receives, and because the client connects with
rnr_retry_count of zero, a single RNR NAK terminates the
connection. Refilling against rb_credits also restores the target
that applied to malformed replies before commit 2ae50ad68cd7
("xprtrdma: Close window between waking RPC senders and posting
Receives") when rpcrdma_post_recvs() computed it from rb_credits
internally. rb_credits is at least one from connection
establishment onward, so the repost path always keeps Receives
posted.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2ae50ad68cd79224198b525f7bd645c9da98b6ff Version: 2ae50ad68cd79224198b525f7bd645c9da98b6ff Version: 2ae50ad68cd79224198b525f7bd645c9da98b6ff Version: 2ae50ad68cd79224198b525f7bd645c9da98b6ff Version: 2ae50ad68cd79224198b525f7bd645c9da98b6ff Version: 2ae50ad68cd79224198b525f7bd645c9da98b6ff Version: 3791c5982ba1eebf2900ee7ca7b9a89619c26d54 Version: 5.4.13 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sunrpc/xprtrdma/rpc_rdma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ef6fb8a5c521f1a07f85202d13e8f2898f247362",
"status": "affected",
"version": "2ae50ad68cd79224198b525f7bd645c9da98b6ff",
"versionType": "git"
},
{
"lessThan": "4322fd9645ee769ad29ce5caea74a1cd9b17269d",
"status": "affected",
"version": "2ae50ad68cd79224198b525f7bd645c9da98b6ff",
"versionType": "git"
},
{
"lessThan": "19fae02b272ee4bcdfb5db57f402d28f1697167a",
"status": "affected",
"version": "2ae50ad68cd79224198b525f7bd645c9da98b6ff",
"versionType": "git"
},
{
"lessThan": "007b4da2f38dcc16a13265416f4ca9f179bab610",
"status": "affected",
"version": "2ae50ad68cd79224198b525f7bd645c9da98b6ff",
"versionType": "git"
},
{
"lessThan": "d7c531ab477ae94fd03771d707fd29c787408039",
"status": "affected",
"version": "2ae50ad68cd79224198b525f7bd645c9da98b6ff",
"versionType": "git"
},
{
"lessThan": "abc011ddaf1617e3e82d8a1e87daa7ddbfb9bac5",
"status": "affected",
"version": "2ae50ad68cd79224198b525f7bd645c9da98b6ff",
"versionType": "git"
},
{
"status": "affected",
"version": "3791c5982ba1eebf2900ee7ca7b9a89619c26d54",
"versionType": "git"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.13",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sunrpc/xprtrdma/rpc_rdma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Repost Receive buffers for malformed replies\n\nrpcrdma_wc_receive() decrements the transport\u0027s Receive count for\nevery completion before it dispatches a successful Receive to\nrpcrdma_reply_handler(). The handler must post a replacement\nReceive WR before returning unless ownership of the rep has moved\nelsewhere, as on the backchannel path.\n\nCommit 2ae50ad68cd7 (\"xprtrdma: Close window between waking RPC\nsenders and posting Receives\") moved the Receive refill out of\nrpcrdma_wc_receive(), where it had run ahead of every reply, into\nrpcrdma_reply_handler() so that the responder\u0027s credit grant could\nbe parsed before reposting. The bad-version and short-reply exits\nnever reach that refill: they recycle the rep and return without\ncalling rpcrdma_post_recvs().\n\nA remote peer can therefore drain the client\u0027s posted Receive\nqueue by sending a sustained stream of replies that are shorter\nthan the fixed transport header or that carry an unrecognized\nRPC/RDMA version. Each such reply consumes one posted Receive\nwithout replacing it. Once the queue empties, the peer\u0027s next\nSend finds no posted Receive and the transport stalls until\nreconnect.\n\nRoute both malformed-reply exits through the shared repost tail\nafter recycling the rep, refilling against buf-\u003erb_credits, the\nmost recent accepted credit grant. Neither exit updates the\ncongestion window, so RPCs admitted under the previous grant\nremain in flight awaiting replies. A smaller refill target would\nlet a stream of malformed replies ratchet the posted Receive count\ndown to the batch floor while the congestion window still admits\nrb_credits RPCs; a burst of valid replies to those RPCs could then\noverrun the posted Receives, and because the client connects with\nrnr_retry_count of zero, a single RNR NAK terminates the\nconnection. Refilling against rb_credits also restores the target\nthat applied to malformed replies before commit 2ae50ad68cd7\n(\"xprtrdma: Close window between waking RPC senders and posting\nReceives\") when rpcrdma_post_recvs() computed it from rb_credits\ninternally. rb_credits is at least one from connection\nestablishment onward, so the repost path always keeps Receives\nposted."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Malicious or compromised NFS/RDMA server sends malformed RPC reply messages over an established RDMA connection; the kernel client processes them in rpcrdma_wc_receive()/rpcrdma_reply_handler() without any local access.\nAC:L - Remote server reliably triggers the bug by streaming replies shorter than the fixed RPC/RDMA header or carrying an unrecognized version; each consumes a posted Receive without reposting a replacement.\nPR:N - Attacker needs no credentials on the victim host, only the ability to act as the connected RDMA peer (e.g., a malicious or compromised NFS server the client has mounted).\nUI:N - Exploitation requires only an active NFS-over-RDMA client session; no additional victim action is needed beyond an existing mount/connection used for normal I/O.\nS:U - Impact is confined to SunRPC/RDMA transport availability on the NFS client; it does not cross VM, container, or kernel/user security boundaries.\nC:N - No memory corruption or out-of-bounds access occurs; short or bad-version replies are detected during header decode and the buffer is recycled without disclosing kernel data.\nI:N - The flaw only fails to repost Receive buffers after malformed replies; it does not corrupt memory, alter RPC payloads, or enable arbitrary kernel writes.\nA:H - Sustained malformed replies drain all posted Receives, stalling the transport until reconnect; a burst of valid replies can trigger RNR NAK and disconnect (rnr_retry_count=0), denying NFS/RDMA service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:44:30.706Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ef6fb8a5c521f1a07f85202d13e8f2898f247362"
},
{
"url": "https://git.kernel.org/stable/c/4322fd9645ee769ad29ce5caea74a1cd9b17269d"
},
{
"url": "https://git.kernel.org/stable/c/19fae02b272ee4bcdfb5db57f402d28f1697167a"
},
{
"url": "https://git.kernel.org/stable/c/007b4da2f38dcc16a13265416f4ca9f179bab610"
},
{
"url": "https://git.kernel.org/stable/c/d7c531ab477ae94fd03771d707fd29c787408039"
},
{
"url": "https://git.kernel.org/stable/c/abc011ddaf1617e3e82d8a1e87daa7ddbfb9bac5"
}
],
"title": "xprtrdma: Repost Receive buffers for malformed replies",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72464",
"datePublished": "2026-08-15T05:57:08.080Z",
"dateReserved": "2026-08-09T03:40:39.933Z",
"dateUpdated": "2026-08-17T05:44:30.706Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74566 (GCVE-0-2026-74566)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
keys: make keyring key-chunk byte order agree with keyring_diff_objects()
keyring_get_key_chunk() loads description bytes into the index chunk low
address first, while keyring_diff_objects() numbers the first differing
bit from the low end and folds the absolute byte index into the level
without removing the inline-prefix offset the level already carries.
The two disagree on byte order and bit position, so the array can be
told two keys first differ at a bit that does not differ in the chunk
the walker uses, letting crafted descriptions collide into one node.
Load the chunk in the order keyring_diff_objects() assumes and drop the
inline-prefix length when folding the byte index into the level. This
only changes the in-memory ordering used to place keys within a keyring;
add, search and read of non-colliding keys are unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/keys/keyring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "414bcf37d81ce9b3823aabc06b04c97fdcbe489b",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "abe43c661efb753d5ee35ad8ace4bbb16fa9afd0",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "f81920917074e3c4ad4fba06fe8c56738d010606",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "bd0f976ef89dce6db458bf75bc2cf51127becc41",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "7269df3e7fcfa308e6a456305162f7788747bdbd",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "3d9f16c0b643ceac305526b2e2fe25c2c6166926",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "7e5397a3fed0dee7779bd084bec3c0584db3c930",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "58565eef0f8d861aae92abfb7658458d661cee17",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/keys/keyring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: make keyring key-chunk byte order agree with keyring_diff_objects()\n\nkeyring_get_key_chunk() loads description bytes into the index chunk low\naddress first, while keyring_diff_objects() numbers the first differing\nbit from the low end and folds the absolute byte index into the level\nwithout removing the inline-prefix offset the level already carries.\nThe two disagree on byte order and bit position, so the array can be\ntold two keys first differ at a bit that does not differ in the chunk\nthe walker uses, letting crafted descriptions collide into one node.\n\nLoad the chunk in the order keyring_diff_objects() assumes and drop the\ninline-prefix length when folding the byte index into the level. This\nonly changes the in-memory ordering used to place keys within a keyring;\nadd, search and read of non-colliding keys are unaffected."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:39:06.890Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/414bcf37d81ce9b3823aabc06b04c97fdcbe489b"
},
{
"url": "https://git.kernel.org/stable/c/abe43c661efb753d5ee35ad8ace4bbb16fa9afd0"
},
{
"url": "https://git.kernel.org/stable/c/f81920917074e3c4ad4fba06fe8c56738d010606"
},
{
"url": "https://git.kernel.org/stable/c/bd0f976ef89dce6db458bf75bc2cf51127becc41"
},
{
"url": "https://git.kernel.org/stable/c/7269df3e7fcfa308e6a456305162f7788747bdbd"
},
{
"url": "https://git.kernel.org/stable/c/3d9f16c0b643ceac305526b2e2fe25c2c6166926"
},
{
"url": "https://git.kernel.org/stable/c/7e5397a3fed0dee7779bd084bec3c0584db3c930"
},
{
"url": "https://git.kernel.org/stable/c/58565eef0f8d861aae92abfb7658458d661cee17"
}
],
"title": "keys: make keyring key-chunk byte order agree with keyring_diff_objects()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74566",
"datePublished": "2026-08-15T12:28:07.628Z",
"dateReserved": "2026-08-15T05:44:03.917Z",
"dateUpdated": "2026-08-19T16:39:06.890Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53260 (GCVE-0-2026-53260)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-08-05 12:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().
syzbot reported a weird reqsk->rsk_refcnt underflow in
__inet_csk_reqsk_queue_drop().
The captured reqsk_put() in __inet_csk_reqsk_queue_drop()
is called only when it successfully removes reqsk from ehash.
Moreover, reqsk_timer_handler() calls another reqsk_put()
after that.
This indicates that the reqsk was missing both refcnts for
ehash and the timer itself.
Since all the syzbot reports had PREEMPT_RT enabled, the only
possible scenario is that reqsk_queue_hash_req() is preempted
after mod_timer() and before refcount_set(), and then the timer
triggered after 1s aborts the reqsk due to its listener's close().
Let's wrap mod_timer() and refcount_set() with
preempt_disable_nested() and preempt_enable_nested().
Note that inet_ehash_insert() holds the normal spin_lock()
(mutex in PREEMPT_RT), so it must be called outside of
preempt_disable_nested(), but this is fine.
The lookup path just ignores 0 sk_refcnt entries in ehash
and tries to create another reqsk, but this will fail at
inet_ehash_insert().
[0]:
refcount_t: underflow; use-after-free.
WARNING: lib/refcount.c:28 at refcount_warn_saturate+0xb2/0x110 lib/refcount.c:28, CPU#0: ktimers/0/16
Modules linked in:
CPU: 0 UID: 0 PID: 16 Comm: ktimers/0 Tainted: G L syzkaller #0 PREEMPT_{RT,(full)}
Tainted: [L]=SOFTLOCKUP
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026
RIP: 0010:refcount_warn_saturate+0xb2/0x110 lib/refcount.c:28
Code: e4 7d d1 0a 67 48 0f b9 3a eb 4a e8 38 3d 23 fd 48 8d 3d e1 7d d1 0a 67 48 0f b9 3a eb 37 e8 25 3d 23 fd 48 8d 3d de 7d d1 0a <67> 48 0f b9 3a eb 24 e8 12 3d 23 fd 48 8d 3d db 7d d1 0a 67 48 0f
RSP: 0000:ffffc90000157948 EFLAGS: 00010246
RAX: ffffffff84a1301b RBX: 0000000000000003 RCX: ffff88801ca98000
RDX: 0000000000000100 RSI: 0000000000000000 RDI: ffffffff8f72ae00
RBP: ffffffff99ae3b01 R08: ffff88801ca98000 R09: 0000000000000005
R10: 0000000000000100 R11: 0000000000000004 R12: ffff8880425ef568
R13: ffff8880425ef4f8 R14: ffff8880425ef578 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888126386000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f7b46710e9c CR3: 000000000dbb6000 CR4: 00000000003526f0
Call Trace:
<TASK>
__refcount_sub_and_test include/linux/refcount.h:400 [inline]
__refcount_dec_and_test include/linux/refcount.h:432 [inline]
refcount_dec_and_test include/linux/refcount.h:450 [inline]
reqsk_put include/net/request_sock.h:136 [inline]
__inet_csk_reqsk_queue_drop+0x3ce/0x440 net/ipv4/inet_connection_sock.c:1007
reqsk_timer_handler+0x651/0xdf0 net/ipv4/inet_connection_sock.c:1137
call_timer_fn+0x192/0x5e0 kernel/time/timer.c:1748
expire_timers kernel/time/timer.c:1799 [inline]
__run_timers kernel/time/timer.c:2374 [inline]
__run_timer_base+0x6a3/0x9f0 kernel/time/timer.c:2386
run_timer_base kernel/time/timer.c:2395 [inline]
run_timer_softirq+0x67/0x170 kernel/time/timer.c:2403
handle_softirqs+0x1de/0x6d0 kernel/softirq.c:622
__do_softirq kernel/softirq.c:656 [inline]
run_ktimerd+0x69/0x100 kernel/softirq.c:1151
smpboot_thread_fn+0x541/0xa50 kernel/smpboot.c:160
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/inet_connection_sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "889fc99967007e2493833515a645cb2d800f6742",
"status": "affected",
"version": "d2d6422f8bd17c6bb205133e290625a564194496",
"versionType": "git"
},
{
"lessThan": "de5a46f3b2c8d3cd20afa158bd3a725e3e3d6fd3",
"status": "affected",
"version": "d2d6422f8bd17c6bb205133e290625a564194496",
"versionType": "git"
},
{
"lessThan": "b183215ff714efb747d9d5a429322ba6404b5401",
"status": "affected",
"version": "d2d6422f8bd17c6bb205133e290625a564194496",
"versionType": "git"
},
{
"lessThan": "e10902df24488ca722303133acfc82490f7d59ad",
"status": "affected",
"version": "d2d6422f8bd17c6bb205133e290625a564194496",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/inet_connection_sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().\n\nsyzbot reported a weird reqsk-\u003ersk_refcnt underflow in\n__inet_csk_reqsk_queue_drop().\n\nThe captured reqsk_put() in __inet_csk_reqsk_queue_drop()\nis called only when it successfully removes reqsk from ehash.\n\nMoreover, reqsk_timer_handler() calls another reqsk_put()\nafter that.\n\nThis indicates that the reqsk was missing both refcnts for\nehash and the timer itself.\n\nSince all the syzbot reports had PREEMPT_RT enabled, the only\npossible scenario is that reqsk_queue_hash_req() is preempted\nafter mod_timer() and before refcount_set(), and then the timer\ntriggered after 1s aborts the reqsk due to its listener\u0027s close().\n\nLet\u0027s wrap mod_timer() and refcount_set() with\npreempt_disable_nested() and preempt_enable_nested().\n\nNote that inet_ehash_insert() holds the normal spin_lock()\n(mutex in PREEMPT_RT), so it must be called outside of\npreempt_disable_nested(), but this is fine.\n\nThe lookup path just ignores 0 sk_refcnt entries in ehash\nand tries to create another reqsk, but this will fail at\ninet_ehash_insert().\n\n[0]:\nrefcount_t: underflow; use-after-free.\nWARNING: lib/refcount.c:28 at refcount_warn_saturate+0xb2/0x110 lib/refcount.c:28, CPU#0: ktimers/0/16\nModules linked in:\nCPU: 0 UID: 0 PID: 16 Comm: ktimers/0 Tainted: G L syzkaller #0 PREEMPT_{RT,(full)}\nTainted: [L]=SOFTLOCKUP\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026\nRIP: 0010:refcount_warn_saturate+0xb2/0x110 lib/refcount.c:28\nCode: e4 7d d1 0a 67 48 0f b9 3a eb 4a e8 38 3d 23 fd 48 8d 3d e1 7d d1 0a 67 48 0f b9 3a eb 37 e8 25 3d 23 fd 48 8d 3d de 7d d1 0a \u003c67\u003e 48 0f b9 3a eb 24 e8 12 3d 23 fd 48 8d 3d db 7d d1 0a 67 48 0f\nRSP: 0000:ffffc90000157948 EFLAGS: 00010246\nRAX: ffffffff84a1301b RBX: 0000000000000003 RCX: ffff88801ca98000\nRDX: 0000000000000100 RSI: 0000000000000000 RDI: ffffffff8f72ae00\nRBP: ffffffff99ae3b01 R08: ffff88801ca98000 R09: 0000000000000005\nR10: 0000000000000100 R11: 0000000000000004 R12: ffff8880425ef568\nR13: ffff8880425ef4f8 R14: ffff8880425ef578 R15: 0000000000000000\nFS: 0000000000000000(0000) GS:ffff888126386000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f7b46710e9c CR3: 000000000dbb6000 CR4: 00000000003526f0\nCall Trace:\n \u003cTASK\u003e\n __refcount_sub_and_test include/linux/refcount.h:400 [inline]\n __refcount_dec_and_test include/linux/refcount.h:432 [inline]\n refcount_dec_and_test include/linux/refcount.h:450 [inline]\n reqsk_put include/net/request_sock.h:136 [inline]\n __inet_csk_reqsk_queue_drop+0x3ce/0x440 net/ipv4/inet_connection_sock.c:1007\n reqsk_timer_handler+0x651/0xdf0 net/ipv4/inet_connection_sock.c:1137\n call_timer_fn+0x192/0x5e0 kernel/time/timer.c:1748\n expire_timers kernel/time/timer.c:1799 [inline]\n __run_timers kernel/time/timer.c:2374 [inline]\n __run_timer_base+0x6a3/0x9f0 kernel/time/timer.c:2386\n run_timer_base kernel/time/timer.c:2395 [inline]\n run_timer_softirq+0x67/0x170 kernel/time/timer.c:2403\n handle_softirqs+0x1de/0x6d0 kernel/softirq.c:622\n __do_softirq kernel/softirq.c:656 [inline]\n run_ktimerd+0x69/0x100 kernel/softirq.c:1151\n smpboot_thread_fn+0x541/0xa50 kernel/smpboot.c:160\n kthread+0x388/0x470 kernel/kthread.c:436\n ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n \u003c/TASK\u003e"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable TCP request-socket path is reached by unauthenticated IPv4 or IPv6 SYN packets delivered to a listening socket over the network. This occurs before any application-level authentication.\nAC:L - Although the bug is a PREEMPT_RT timing race, an attacker can repeatedly create request sockets and timer/drop races by driving TCP connection attempts; under the required higher-severity rule this is treated as attacker-controllable rather than an uncontrollable environmental condition.\nPR:N - No credentials, capabilities, or prior authentication are required to send SYN packets to an exposed TCP listener and reach `tcp_conn_request()` and `reqsk_queue_hash_req()`. The path is in the generic TCP receive stack.\nUI:N - Exploitation does not require a victim user to open a file, mount anything, or perform an interactive action. Network traffic alone can exercise the vulnerable path on an affected listening service.\nS:U - The impact is within the kernel/network stack security authority on the same host. There is no VM escape, IOMMU bypass, or cross-authority boundary change.\nC:H - The failure is explicitly reported as a refcount underflow/use-after-free in a kernel heap object. Per the required guidance, UAF-class lifetime corruption is scored as high confidentiality impact because it can potentially be shaped into memory disclosure.\nI:H - The corrupted request-socket lifetime can leave stale kernel objects reachable through ehash/timer paths. Per the required guidance, UAF-class kernel memory corruption is scored as high integrity impact because it may be exploitable for write or control-flow manipulation.\nA:H - The observed failure triggers a kernel refcount warning with use-after-free semantics in timer context and can destabilize networking or the kernel. Kernel warnings/oopses, hangs, or UAF-triggered crashes are high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:34:39.011Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/889fc99967007e2493833515a645cb2d800f6742"
},
{
"url": "https://git.kernel.org/stable/c/de5a46f3b2c8d3cd20afa158bd3a725e3e3d6fd3"
},
{
"url": "https://git.kernel.org/stable/c/b183215ff714efb747d9d5a429322ba6404b5401"
},
{
"url": "https://git.kernel.org/stable/c/e10902df24488ca722303133acfc82490f7d59ad"
}
],
"title": "tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53260",
"datePublished": "2026-06-25T08:39:49.229Z",
"dateReserved": "2026-06-09T07:44:35.394Z",
"dateUpdated": "2026-08-05T12:34:39.011Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64033 (GCVE-0-2026-64033)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rtrs: Fix use-after-free in path file creation cleanup
In the error path of rtrs_srv_create_path_files(), the sysfs root folders
may already have been created and srv_path->kobj may already have been
initialized. If a later step fails, the cleanup currently calls
kobject_put(&srv_path->kobj) before
rtrs_srv_destroy_once_sysfs_root_folders(srv_path).
kobject_put() may drop the last reference to srv_path->kobj and invoke the
release callback, rtrs_srv_release(), which frees srv_path. The following
call to rtrs_srv_destroy_once_sysfs_root_folders(srv_path) then
dereferences srv_path internally to access srv_path->srv, resulting in a
use-after-free.
This failure path is reached before rtrs_srv_create_path_files() returns
success, so the successful-path lifetime handling is not involved.
Fix this by destroying the sysfs root folders before calling
kobject_put(&srv_path->kobj), so srv_path is still valid while the helper
accesses it.
This issue was found by a static analysis tool I am developing.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bab17b761c8974a869b04462be5d4dd9aad366b4 Version: ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 Version: ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 Version: ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 Version: ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 Version: ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 Version: ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 Version: 5.15.61 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/ulp/rtrs/rtrs-srv-sysfs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "01e42aabaf7632beb4bf235c7238b96c746d4144",
"status": "affected",
"version": "bab17b761c8974a869b04462be5d4dd9aad366b4",
"versionType": "git"
},
{
"lessThan": "548f3956e53a7f7bde912d8129010b8986d5e602",
"status": "affected",
"version": "ae4c81644e9105d9f7f713bb0d444737bb6a0cf1",
"versionType": "git"
},
{
"lessThan": "00904a73272b9f3ef3952fe69a833909dccad1ef",
"status": "affected",
"version": "ae4c81644e9105d9f7f713bb0d444737bb6a0cf1",
"versionType": "git"
},
{
"lessThan": "92060ab1c5115674cf319175550f85f68405121f",
"status": "affected",
"version": "ae4c81644e9105d9f7f713bb0d444737bb6a0cf1",
"versionType": "git"
},
{
"lessThan": "eae62c5451e67e8b033c1681fd3b85d7e9a9a28f",
"status": "affected",
"version": "ae4c81644e9105d9f7f713bb0d444737bb6a0cf1",
"versionType": "git"
},
{
"lessThan": "b0e9706fb2859064bb6c677554c4d20c713aa8e0",
"status": "affected",
"version": "ae4c81644e9105d9f7f713bb0d444737bb6a0cf1",
"versionType": "git"
},
{
"lessThan": "5b74373390113fba798a76b483837029ab010fef",
"status": "affected",
"version": "ae4c81644e9105d9f7f713bb0d444737bb6a0cf1",
"versionType": "git"
},
{
"lessThan": "5.15.209",
"status": "affected",
"version": "5.15.61",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/ulp/rtrs/rtrs-srv-sysfs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.15.61",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs: Fix use-after-free in path file creation cleanup\n\nIn the error path of rtrs_srv_create_path_files(), the sysfs root folders\nmay already have been created and srv_path-\u003ekobj may already have been\ninitialized. If a later step fails, the cleanup currently calls\nkobject_put(\u0026srv_path-\u003ekobj) before\nrtrs_srv_destroy_once_sysfs_root_folders(srv_path).\n\nkobject_put() may drop the last reference to srv_path-\u003ekobj and invoke the\nrelease callback, rtrs_srv_release(), which frees srv_path. The following\ncall to rtrs_srv_destroy_once_sysfs_root_folders(srv_path) then\ndereferences srv_path internally to access srv_path-\u003esrv, resulting in a\nuse-after-free.\n\nThis failure path is reached before rtrs_srv_create_path_files() returns\nsuccess, so the successful-path lifetime handling is not involved.\n\nFix this by destroying the sysfs root folders before calling\nkobject_put(\u0026srv_path-\u003ekobj), so srv_path is still valid while the helper\naccesses it.\n\nThis issue was found by a static analysis tool I am developing."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code runs in the RTRS server RDMA CM handler when a remote peer completes connection setup and sends RTRS_MSG_INFO_REQ; the server listens on network addresses via rdma_listen() on IPv6 and IB port spaces (default port 1234, used by rnbd-server).\nAC:L - This is a deterministic cleanup-order UAF, not a race; once the attacker drives sysfs creation into an error path (e.g., via parallel connection attempts causing allocation failures), the bug triggers reliably on every failed setup.\nPR:N - No Linux credentials are required; any remote RTRS/RNBD client that can reach the server\u0027s RDMA listener can complete the pre-authentication connection and info-request handshake that calls rtrs_srv_create_path_files().\nUI:N - Exploitation is fully automated through the RTRS wire protocol and requires no action from a local user or administrator on the target host.\nS:U - Impact is confined to kernel memory corruption and privilege escalation on the RTRS server host; it does not cross a VM, container, or IOMMU security boundary by itself.\nC:H - The use-after-free dereferences freed srv_path memory (including srv_path-\u003esrv) during cleanup, which can leak kernel heap contents or be turned into an arbitrary read primitive through heap grooming.\nI:H - UAF on a kernel heap object enables control of freed memory contents and can be leveraged for arbitrary kernel writes or code execution via heap spraying and structure reuse.\nA:H - The UAF dereference during error cleanup can cause kernel oops/panic on the RTRS server, and successful exploitation can crash or fully compromise the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:27.449Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/01e42aabaf7632beb4bf235c7238b96c746d4144"
},
{
"url": "https://git.kernel.org/stable/c/548f3956e53a7f7bde912d8129010b8986d5e602"
},
{
"url": "https://git.kernel.org/stable/c/00904a73272b9f3ef3952fe69a833909dccad1ef"
},
{
"url": "https://git.kernel.org/stable/c/92060ab1c5115674cf319175550f85f68405121f"
},
{
"url": "https://git.kernel.org/stable/c/eae62c5451e67e8b033c1681fd3b85d7e9a9a28f"
},
{
"url": "https://git.kernel.org/stable/c/b0e9706fb2859064bb6c677554c4d20c713aa8e0"
},
{
"url": "https://git.kernel.org/stable/c/5b74373390113fba798a76b483837029ab010fef"
}
],
"title": "RDMA/rtrs: Fix use-after-free in path file creation cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64033",
"datePublished": "2026-07-19T15:39:22.872Z",
"dateReserved": "2026-07-19T07:54:57.028Z",
"dateUpdated": "2026-08-05T12:38:27.449Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64382 (GCVE-0-2026-64382)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_open() replay
A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_open_init() fails before the next send, cleanup
retains the previous buffer type and frees that response again.
Reset response bookkeeping before each attempt to prevent the stale free.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 433042a91f9373241307725b52de573933ffedbf Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 6.6.32 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "02bc2896bdc3e29362d6e40d404006944a159c25",
"status": "affected",
"version": "433042a91f9373241307725b52de573933ffedbf",
"versionType": "git"
},
{
"lessThan": "3196b5192f246df4272072f61a2f4a3e9967f55d",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "14498ff5ce0f272ce0ef988721413e06b7038972",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "ff2d30927bc3bf3c629f0768d2068096e64ef5ce",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "b55e182f2324bc6a604c21a47aa6c448f719a532",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.32",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double-free in SMB2_open() replay\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_open_init() fails before the next send, cleanup\nretains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious SMB2/SMB3 server can trigger the flaw through network-delivered CREATE error responses after a victim mounts or accesses its share.\nAC:L - The server controls the replayable status and can disconnect or refuse reconnection so the next initialization fails; it can repeat the sequence to overcome scheduling variance.\nPR:N - The attacking server needs no account or privileges on the client, because the victim supplies the mounted SMB session and initiates the request.\nUI:R - A victim must mount the malicious share or perform an operation such as statfs, ACL access, notification, or file access that causes SMB2_open() to run.\nS:U - The double-free corrupts memory within the client kernel\u0027s existing security authority and does not inherently cross a VM or IOMMU boundary.\nC:H - The double-free can produce overlapping live SMB buffers and use-after-free access, supporting kernel-memory disclosure and arbitrary-read exploitation.\nI:H - Reallocation of the freed mempool object permits attacker-controlled network data to corrupt live kernel objects or allocator metadata, enabling arbitrary writes or control-flow hijacking.\nA:H - The double-free can immediately trigger allocator diagnostics or heap corruption leading to a kernel oops or panic, and the server can repeatedly retrigger it."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:33.945Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/02bc2896bdc3e29362d6e40d404006944a159c25"
},
{
"url": "https://git.kernel.org/stable/c/3196b5192f246df4272072f61a2f4a3e9967f55d"
},
{
"url": "https://git.kernel.org/stable/c/14498ff5ce0f272ce0ef988721413e06b7038972"
},
{
"url": "https://git.kernel.org/stable/c/ff2d30927bc3bf3c629f0768d2068096e64ef5ce"
},
{
"url": "https://git.kernel.org/stable/c/b55e182f2324bc6a604c21a47aa6c448f719a532"
}
],
"title": "smb: client: fix double-free in SMB2_open() replay",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64382",
"datePublished": "2026-07-25T08:50:31.937Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-08-17T04:54:33.945Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68192 (GCVE-0-2026-68192)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: make release_scratchbuffers idempotent
brcmf_pcie_release_scratchbuffers() frees the shared.scratch and
shared.ringupd DMA buffers with dma_free_coherent() but does not clear
the pointers afterwards, unlike the sibling release_ringbuffers() which
NULLs commonrings/flowrings/idxbuf on release.
Both the bus_reset .reset callback (brcmf_pcie_reset) and
brcmf_pcie_remove() call release_scratchbuffers. When reset teardown
has run before removal, remove's own teardown would call
dma_free_coherent() a second time on the already-freed DMA allocation.
NULL the pointers after free, matching release_ringbuffers(), so a later
release observes that the allocation has already been released. This
patch makes repeated sequential release safe; the reset-work lifetime is
handled separately by the following patch.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "81c58a206d1deee01f4c29236d4154c0872f2a38",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "382ee00b2d1e31869ae576a60d3fbe7a2153512f",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "739b686aecdb14a6065300ea53401f043e51fd22",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "b7d1d8cb1bdca56aecebacd2896615da0acc126a",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "5a045c2f0fbf029873d2295178fa0785ade35af0",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "044fca8f45ba9ab6ca526163155234cf88287ff5",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "0ca80328df23f851c86866720d4977783c919ee6",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "538c51e9d124cf656f2dd0c0394a8545efc7102d",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: make release_scratchbuffers idempotent\n\nbrcmf_pcie_release_scratchbuffers() frees the shared.scratch and\nshared.ringupd DMA buffers with dma_free_coherent() but does not clear\nthe pointers afterwards, unlike the sibling release_ringbuffers() which\nNULLs commonrings/flowrings/idxbuf on release.\n\nBoth the bus_reset .reset callback (brcmf_pcie_reset) and\nbrcmf_pcie_remove() call release_scratchbuffers. When reset teardown\nhas run before removal, remove\u0027s own teardown would call\ndma_free_coherent() a second time on the already-freed DMA allocation.\n\nNULL the pointers after free, matching release_ringbuffers(), so a later\nrelease observes that the allocation has already been released. This\npatch makes repeated sequential release safe; the reset-work lifetime is\nhandled separately by the following patch.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The flaw is reached during brcmfmac PCIe bus reset/teardown after firmware halt; brcmf_fw_crashed() is invoked from the threaded IRQ handler on BRCMF_D2H_DEV_FWHALT mailbox data from the WiFi firmware, which an adjacent attacker can trigger with crafted over-the-air WiFi traffic to crash the dongle.\nAC:L - An attacker who induces firmware halt controls the reset sequence; brcmf_pcie_reset() always frees scratch buffers first and a later brcmf_pcie_remove() or failed brcmf_pcie_setup() teardown calls release_scratchbuffers() again on the same stale pointers, making the double-free deterministic without races they cannot influence.\nPR:N - No host privileges are required because crashing Broadcom FullMAC firmware via adjacent WiFi frames reaches brcmf_fw_crashed() without authentication, CAP_NET_ADMIN, or local access; the debugfs reset path is root-only but is not needed for the highest-impact attack scenario.\nUI:N - Exploitation only requires a victim with an active brcmfmac PCIe WiFi interface within RF range; no victim click, file open, driver unload, or other explicit user action is needed beyond normal always-on WiFi operation on laptops and embedded hosts using Broadcom PCIe FullMAC chips.\nS:U - The vulnerability corrupts kernel DMA/page-allocator state and enables host kernel privilege escalation within the same security authority; it does not cross VM, container, or IOMMU boundaries, so scope remains unchanged.\nC:H - Calling dma_free_coherent() twice on the same scratch and ringupd DMA allocations is a double-free of kernel coherent memory; this allocator-metadata corruption can be leveraged for arbitrary kernel memory disclosure even when full exploitation is not attempted, per kernel CVSS guidance for memory corruption.\nI:H - Double-free of dma_alloc_coherent buffers corrupts the kernel DMA/page heap freelist, enabling attacker-controlled reallocation and arbitrary kernel writes or control-flow hijack on systems with BRCMFMAC_PCIE enabled and a reachable Broadcom PCIe FullMAC wireless device.\nA:H - Re-freeing already released DMA-coherent allocations during driver reset or removal typically causes immediate kernel BUG/oops/panic or fatal allocator corruption during teardown, guaranteeing severe host availability loss on affected Broadcom PCIe WiFi systems even when code execution is not achieved."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:06.873Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/81c58a206d1deee01f4c29236d4154c0872f2a38"
},
{
"url": "https://git.kernel.org/stable/c/382ee00b2d1e31869ae576a60d3fbe7a2153512f"
},
{
"url": "https://git.kernel.org/stable/c/739b686aecdb14a6065300ea53401f043e51fd22"
},
{
"url": "https://git.kernel.org/stable/c/b7d1d8cb1bdca56aecebacd2896615da0acc126a"
},
{
"url": "https://git.kernel.org/stable/c/5a045c2f0fbf029873d2295178fa0785ade35af0"
},
{
"url": "https://git.kernel.org/stable/c/044fca8f45ba9ab6ca526163155234cf88287ff5"
},
{
"url": "https://git.kernel.org/stable/c/0ca80328df23f851c86866720d4977783c919ee6"
},
{
"url": "https://git.kernel.org/stable/c/538c51e9d124cf656f2dd0c0394a8545efc7102d"
}
],
"title": "wifi: brcmfmac: make release_scratchbuffers idempotent",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68192",
"datePublished": "2026-08-10T12:00:10.041Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:31:06.873Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68369 (GCVE-0-2026-68369)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: printer: fix infinite loop in printer_read()
printer_read() uses the same variable for the requested copy size and
the number of bytes actually copied to user space. copy_to_user()
returns the number of bytes not copied, so when it fails to copy
anything, the computed copied length becomes zero.
In that case len, buf, current_rx_bytes and current_rx_buf are left
unchanged. If RX data is available and the user buffer remains
unwritable, the read loop can repeat indefinitely.
Track the copied length separately and return -EFAULT, or the number of
bytes already copied, if an iteration makes no progress.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_printer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3f81197364b57e5318620c75f3bd63f405f60552",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "e225e2998e5a9b83c838dbbe4511fb0d63f88daf",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "3081b0e187065c3b9577e393ad664b12854aeaf3",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "994afccfdcceb73be33f69a8a8ea71e260c9eca5",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "e03597ad9494b500344076589aeaa6c6d2d381d3",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "4cde0b38cc0cb8b7dc17295801015148de37d1d2",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "e41bbbbb1740ce4d7270ab1cdeca13892d6a8d2e",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "c2e819be6a5c7f34344926b4bd7e3dfca58cf48a",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_printer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: printer: fix infinite loop in printer_read()\n\nprinter_read() uses the same variable for the requested copy size and\nthe number of bytes actually copied to user space. copy_to_user()\nreturns the number of bytes not copied, so when it fails to copy\nanything, the computed copied length becomes zero.\n\nIn that case len, buf, current_rx_bytes and current_rx_buf are left\nunchanged. If RX data is available and the user buffer remains\nunwritable, the read loop can repeat indefinitely.\n\nTrack the copied length separately and return -EFAULT, or the number of\nbytes already copied, if an iteration makes no progress."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:28.812Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3f81197364b57e5318620c75f3bd63f405f60552"
},
{
"url": "https://git.kernel.org/stable/c/e225e2998e5a9b83c838dbbe4511fb0d63f88daf"
},
{
"url": "https://git.kernel.org/stable/c/3081b0e187065c3b9577e393ad664b12854aeaf3"
},
{
"url": "https://git.kernel.org/stable/c/994afccfdcceb73be33f69a8a8ea71e260c9eca5"
},
{
"url": "https://git.kernel.org/stable/c/e03597ad9494b500344076589aeaa6c6d2d381d3"
},
{
"url": "https://git.kernel.org/stable/c/4cde0b38cc0cb8b7dc17295801015148de37d1d2"
},
{
"url": "https://git.kernel.org/stable/c/e41bbbbb1740ce4d7270ab1cdeca13892d6a8d2e"
},
{
"url": "https://git.kernel.org/stable/c/c2e819be6a5c7f34344926b4bd7e3dfca58cf48a"
}
],
"title": "usb: gadget: printer: fix infinite loop in printer_read()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68369",
"datePublished": "2026-08-10T12:03:46.845Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:28.812Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64429 (GCVE-0-2026-64429)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpio: eic-sprd: use raw_spinlock_t in the irq startup path
sprd_eic_irq_unmask() enables the GPIO IRQ and then updates controller
state through sprd_eic_update(), which takes sprd_eic->lock with
spin_lock_irqsave(). The callback can be reached from irq_startup()
while setting up a requested IRQ. That path is not sleepable, but on
PREEMPT_RT a regular spinlock_t becomes a sleeping lock.
This issue was found by our static analysis tool and then manually
reviewed against the current tree.
The grounded PoC kept the request_threaded_irq() -> __setup_irq() ->
irq_startup() -> sprd_eic_irq_unmask() -> sprd_eic_update() carrier and
used the original spin_lock_irqsave(&sprd_eic->lock) edge. Lockdep
BUG: sleeping function called from invalid context
hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv]
sprd_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv]
sprd_eic_update.constprop.0+0x48/0x90 [vuln_msv]
sprd_eic_irq_unmask.constprop.0+0x35/0x50 [vuln_msv]
__setup_irq.constprop.0+0xd/0x30 [vuln_msv]
Convert the Spreadtrum EIC controller lock to raw_spinlock_t. The
locked section only serializes MMIO register updates and does not contain
sleepable operations, so keeping it non-sleeping is appropriate for the
irqchip callbacks.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 25518e024e3a6e5715d672f1daa91e1d100f7436 Version: 25518e024e3a6e5715d672f1daa91e1d100f7436 Version: 25518e024e3a6e5715d672f1daa91e1d100f7436 Version: 25518e024e3a6e5715d672f1daa91e1d100f7436 Version: 25518e024e3a6e5715d672f1daa91e1d100f7436 Version: 25518e024e3a6e5715d672f1daa91e1d100f7436 Version: 25518e024e3a6e5715d672f1daa91e1d100f7436 Version: 25518e024e3a6e5715d672f1daa91e1d100f7436 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-eic-sprd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "96612bf2712cd961dbd9b52f3a9b4ab668f57628",
"status": "affected",
"version": "25518e024e3a6e5715d672f1daa91e1d100f7436",
"versionType": "git"
},
{
"lessThan": "581ac2ad001ff1128931191f249a7f2074672b7a",
"status": "affected",
"version": "25518e024e3a6e5715d672f1daa91e1d100f7436",
"versionType": "git"
},
{
"lessThan": "e244cd8b51001ba480f274c44dba9002813a4739",
"status": "affected",
"version": "25518e024e3a6e5715d672f1daa91e1d100f7436",
"versionType": "git"
},
{
"lessThan": "19d63fd528719ce7d06d9aeb88d25b7d6478198a",
"status": "affected",
"version": "25518e024e3a6e5715d672f1daa91e1d100f7436",
"versionType": "git"
},
{
"lessThan": "6112fba4150039ccd90e29f2d1b788c73ad7b3dd",
"status": "affected",
"version": "25518e024e3a6e5715d672f1daa91e1d100f7436",
"versionType": "git"
},
{
"lessThan": "4750909a40da9016185e0ac991510a278cecb1e7",
"status": "affected",
"version": "25518e024e3a6e5715d672f1daa91e1d100f7436",
"versionType": "git"
},
{
"lessThan": "5c3c9ec1172a4c3384b8b800b3a8896cc2c1b20e",
"status": "affected",
"version": "25518e024e3a6e5715d672f1daa91e1d100f7436",
"versionType": "git"
},
{
"lessThan": "90f0109019e6817eb40a486671b7722d1544ae29",
"status": "affected",
"version": "25518e024e3a6e5715d672f1daa91e1d100f7436",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-eic-sprd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: eic-sprd: use raw_spinlock_t in the irq startup path\n\nsprd_eic_irq_unmask() enables the GPIO IRQ and then updates controller\nstate through sprd_eic_update(), which takes sprd_eic-\u003elock with\nspin_lock_irqsave(). The callback can be reached from irq_startup()\nwhile setting up a requested IRQ. That path is not sleepable, but on\nPREEMPT_RT a regular spinlock_t becomes a sleeping lock.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the request_threaded_irq() -\u003e __setup_irq() -\u003e\nirq_startup() -\u003e sprd_eic_irq_unmask() -\u003e sprd_eic_update() carrier and\nused the original spin_lock_irqsave(\u0026sprd_eic-\u003elock) edge. Lockdep\n\n BUG: sleeping function called from invalid context\n hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv]\n sprd_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv]\n sprd_eic_update.constprop.0+0x48/0x90 [vuln_msv]\n sprd_eic_irq_unmask.constprop.0+0x35/0x50 [vuln_msv]\n __setup_irq.constprop.0+0xd/0x30 [vuln_msv]\n\nConvert the Spreadtrum EIC controller lock to raw_spinlock_t. The\nlocked section only serializes MMIO register updates and does not contain\nsleepable operations, so keeping it non-sleeping is appropriate for the\nirqchip callbacks."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:29.849Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/96612bf2712cd961dbd9b52f3a9b4ab668f57628"
},
{
"url": "https://git.kernel.org/stable/c/581ac2ad001ff1128931191f249a7f2074672b7a"
},
{
"url": "https://git.kernel.org/stable/c/e244cd8b51001ba480f274c44dba9002813a4739"
},
{
"url": "https://git.kernel.org/stable/c/19d63fd528719ce7d06d9aeb88d25b7d6478198a"
},
{
"url": "https://git.kernel.org/stable/c/6112fba4150039ccd90e29f2d1b788c73ad7b3dd"
},
{
"url": "https://git.kernel.org/stable/c/4750909a40da9016185e0ac991510a278cecb1e7"
},
{
"url": "https://git.kernel.org/stable/c/5c3c9ec1172a4c3384b8b800b3a8896cc2c1b20e"
},
{
"url": "https://git.kernel.org/stable/c/90f0109019e6817eb40a486671b7722d1544ae29"
}
],
"title": "gpio: eic-sprd: use raw_spinlock_t in the irq startup path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64429",
"datePublished": "2026-07-25T08:51:06.016Z",
"dateReserved": "2026-07-19T15:36:31.787Z",
"dateUpdated": "2026-08-17T04:55:29.849Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63842 (GCVE-0-2026-63842)
Vulnerability from cvelistv5
Published
2026-07-19 14:04
Modified
2026-08-05 12:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring
JPEG rings do not support 64-bit user fence writes, reject CS
submissions with user fences.
(cherry picked from commit 0f43893d3cd478fa57836697525b338817c9c23d)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/jpeg_v5_0_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3a55ff19a6ff5e046d6a4a18e36deec5d95d9a2e",
"status": "affected",
"version": "dfad65c65728401587142577dd283476491bac83",
"versionType": "git"
},
{
"lessThan": "a7e63bb93a7fde3c8920984c3deee9acfe461562",
"status": "affected",
"version": "dfad65c65728401587142577dd283476491bac83",
"versionType": "git"
},
{
"lessThan": "69ab75c7c5f378eb46f4c918aa848bb5c5603924",
"status": "affected",
"version": "dfad65c65728401587142577dd283476491bac83",
"versionType": "git"
},
{
"lessThan": "ea7c61c5f895e8f9ea0ffffa180498ef9c740152",
"status": "affected",
"version": "dfad65c65728401587142577dd283476491bac83",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/jpeg_v5_0_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 0f43893d3cd478fa57836697525b338817c9c23d)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires submitting AMDGPU command buffers via DRM_IOCTL_AMDGPU_CS on a local /dev/dri/renderD* device; the JPEG ring is not reachable over the network.\nAC:L - An attacker with render-node access can deterministically submit a CS with an AMDGPU_CHUNK_ID_FENCE chunk and a JPEG-ring IB (AMDGPU_HW_IP_VCN_JPEG); no race or external timing is required.\nPR:L - The amdgpu_cs_ioctl path is gated by DRM_AUTH|DRM_RENDER_ALLOW, reachable by unprivileged local users with standard render-node access (render group membership), not root.\nUI:N - No victim interaction is required; the attacker triggers the malformed user-fence write through their own ioctl submission.\nS:U - Impact is confined to GPU memory writes within the attacker\u0027s amdgpu VM context; this is standard local privilege/resource abuse, not a VM escape or cross-authority boundary crossing.\nC:H - The JPEG engine performs an unsupported 64-bit fence memory write (via jpeg_v4_0_3_dec_ring_emit_fence with AMDGPU_FENCE_FLAG_64BIT), causing GPU memory corruption that can be leveraged for arbitrary read primitives within the attacker\u0027s GPU address space.\nI:H - The malformed hardware fence write can corrupt arbitrary GPU-mapped buffers in the submitter\u0027s VM, providing a write primitive that could be developed into GPU code execution or further kernel compromise.\nA:H - Incorrect fence handling can hang or reset the GPU (affecting all users of the device) and may trigger kernel GPU driver recovery paths, causing denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:36:19.801Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3a55ff19a6ff5e046d6a4a18e36deec5d95d9a2e"
},
{
"url": "https://git.kernel.org/stable/c/a7e63bb93a7fde3c8920984c3deee9acfe461562"
},
{
"url": "https://git.kernel.org/stable/c/69ab75c7c5f378eb46f4c918aa848bb5c5603924"
},
{
"url": "https://git.kernel.org/stable/c/ea7c61c5f895e8f9ea0ffffa180498ef9c740152"
}
],
"title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63842",
"datePublished": "2026-07-19T14:04:37.212Z",
"dateReserved": "2026-07-19T07:54:57.015Z",
"dateUpdated": "2026-08-05T12:36:19.801Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-23449 (GCVE-0-2026-23449)
Vulnerability from cvelistv5
Published
2026-04-03 15:15
Modified
2026-09-08 08:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: teql: Fix double-free in teql_master_xmit
Whenever a TEQL devices has a lockless Qdisc as root, qdisc_reset should
be called using the seq_lock to avoid racing with the datapath. Failure
to do so may cause crashes like the following:
[ 238.028993][ T318] BUG: KASAN: double-free in skb_release_data (net/core/skbuff.c:1139)
[ 238.029328][ T318] Free of addr ffff88810c67ec00 by task poc_teql_uaf_ke/318
[ 238.029749][ T318]
[ 238.029900][ T318] CPU: 3 UID: 0 PID: 318 Comm: poc_teql_ke Not tainted 7.0.0-rc3-00149-ge5b31d988a41 #704 PREEMPT(full)
[ 238.029906][ T318] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 238.029910][ T318] Call Trace:
[ 238.029913][ T318] <TASK>
[ 238.029916][ T318] dump_stack_lvl (lib/dump_stack.c:122)
[ 238.029928][ T318] print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)
[ 238.029940][ T318] ? skb_release_data (net/core/skbuff.c:1139)
[ 238.029944][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221)
...
[ 238.029957][ T318] ? skb_release_data (net/core/skbuff.c:1139)
[ 238.029969][ T318] kasan_report_invalid_free (mm/kasan/report.c:221 mm/kasan/report.c:563)
[ 238.029979][ T318] ? skb_release_data (net/core/skbuff.c:1139)
[ 238.029989][ T318] check_slab_allocation (mm/kasan/common.c:231)
[ 238.029995][ T318] kmem_cache_free (mm/slub.c:2637 (discriminator 1) mm/slub.c:6168 (discriminator 1) mm/slub.c:6298 (discriminator 1))
[ 238.030004][ T318] skb_release_data (net/core/skbuff.c:1139)
...
[ 238.030025][ T318] sk_skb_reason_drop (net/core/skbuff.c:1256)
[ 238.030032][ T318] pfifo_fast_reset (./include/linux/ptr_ring.h:171 ./include/linux/ptr_ring.h:309 ./include/linux/skb_array.h:98 net/sched/sch_generic.c:827)
[ 238.030039][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221)
...
[ 238.030054][ T318] qdisc_reset (net/sched/sch_generic.c:1034)
[ 238.030062][ T318] teql_destroy (./include/linux/spinlock.h:395 net/sched/sch_teql.c:157)
[ 238.030071][ T318] __qdisc_destroy (./include/net/pkt_sched.h:328 net/sched/sch_generic.c:1077)
[ 238.030077][ T318] qdisc_graft (net/sched/sch_api.c:1062 net/sched/sch_api.c:1053 net/sched/sch_api.c:1159)
[ 238.030089][ T318] ? __pfx_qdisc_graft (net/sched/sch_api.c:1091)
[ 238.030095][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221)
[ 238.030102][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221)
[ 238.030106][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221)
[ 238.030114][ T318] tc_get_qdisc (net/sched/sch_api.c:1529 net/sched/sch_api.c:1556)
...
[ 238.072958][ T318] Allocated by task 303 on cpu 5 at 238.026275s:
[ 238.073392][ T318] kasan_save_stack (mm/kasan/common.c:58)
[ 238.073884][ T318] kasan_save_track (mm/kasan/common.c:64 (discriminator 5) mm/kasan/common.c:79 (discriminator 5))
[ 238.074230][ T318] __kasan_slab_alloc (mm/kasan/common.c:369)
[ 238.074578][ T318] kmem_cache_alloc_node_noprof (./include/linux/kasan.h:253 mm/slub.c:4542 mm/slub.c:4869 mm/slub.c:4921)
[ 238.076091][ T318] kmalloc_reserve (net/core/skbuff.c:616 (discriminator 107))
[ 238.076450][ T318] __alloc_skb (net/core/skbuff.c:713)
[ 238.076834][ T318] alloc_skb_with_frags (./include/linux/skbuff.h:1383 net/core/skbuff.c:6763)
[ 238.077178][ T318] sock_alloc_send_pskb (net/core/sock.c:2997)
[ 238.077520][ T318] packet_sendmsg (net/packet/af_packet.c:2926 net/packet/af_packet.c:3019 net/packet/af_packet.c:3108)
[ 238.081469][ T318]
[ 238.081870][ T318] Freed by task 299 on cpu 1 at 238.028496s:
[ 238.082761][ T318] kasan_save_stack (mm/kasan/common.c:58)
[ 238.083481][ T318] kasan_save_track (mm/kasan/common.c:64 (discriminator 5) mm/kasan/common.c:79 (discriminator 5))
[ 238.085348][ T318] kasan_save_free_info (mm/kasan/generic.c:587 (discriminator 1))
[ 238.085900][ T318] __kasan_slab_free (mm/
---truncated---
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 96009c7d500efdd5534e83b2e3eb2c58d4b137ae Version: 96009c7d500efdd5534e83b2e3eb2c58d4b137ae Version: 96009c7d500efdd5534e83b2e3eb2c58d4b137ae Version: 96009c7d500efdd5534e83b2e3eb2c58d4b137ae Version: 96009c7d500efdd5534e83b2e3eb2c58d4b137ae Version: 96009c7d500efdd5534e83b2e3eb2c58d4b137ae |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:46:15.709Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/sch_generic.h",
"net/sched/sch_generic.c",
"net/sched/sch_teql.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4e8ebc4c18ea8213d28e6cb867d18fcc67daca21",
"status": "affected",
"version": "96009c7d500efdd5534e83b2e3eb2c58d4b137ae",
"versionType": "git"
},
{
"lessThan": "21c89a0a8de7eadad8d385645a95b3233f23130e",
"status": "affected",
"version": "96009c7d500efdd5534e83b2e3eb2c58d4b137ae",
"versionType": "git"
},
{
"lessThan": "afbc79a7770b230a9f24bd39271209d6b3682c5f",
"status": "affected",
"version": "96009c7d500efdd5534e83b2e3eb2c58d4b137ae",
"versionType": "git"
},
{
"lessThan": "e9c66d3e7d8557b3308e55c613aa07254fe97611",
"status": "affected",
"version": "96009c7d500efdd5534e83b2e3eb2c58d4b137ae",
"versionType": "git"
},
{
"lessThan": "4a233447b941db451ea5f5a0942cffd0f7f7eaae",
"status": "affected",
"version": "96009c7d500efdd5534e83b2e3eb2c58d4b137ae",
"versionType": "git"
},
{
"lessThan": "66360460cab63c248ca5b1070a01c0c29133b960",
"status": "affected",
"version": "96009c7d500efdd5534e83b2e3eb2c58d4b137ae",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/sch_generic.h",
"net/sched/sch_generic.c",
"net/sched/sch_teql.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.20",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.167",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.20",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.10",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: teql: Fix double-free in teql_master_xmit\n\nWhenever a TEQL devices has a lockless Qdisc as root, qdisc_reset should\nbe called using the seq_lock to avoid racing with the datapath. Failure\nto do so may cause crashes like the following:\n\n[ 238.028993][ T318] BUG: KASAN: double-free in skb_release_data (net/core/skbuff.c:1139)\n[ 238.029328][ T318] Free of addr ffff88810c67ec00 by task poc_teql_uaf_ke/318\n[ 238.029749][ T318]\n[ 238.029900][ T318] CPU: 3 UID: 0 PID: 318 Comm: poc_teql_ke Not tainted 7.0.0-rc3-00149-ge5b31d988a41 #704 PREEMPT(full)\n[ 238.029906][ T318] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011\n[ 238.029910][ T318] Call Trace:\n[ 238.029913][ T318] \u003cTASK\u003e\n[ 238.029916][ T318] dump_stack_lvl (lib/dump_stack.c:122)\n[ 238.029928][ T318] print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)\n[ 238.029940][ T318] ? skb_release_data (net/core/skbuff.c:1139)\n[ 238.029944][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221)\n...\n[ 238.029957][ T318] ? skb_release_data (net/core/skbuff.c:1139)\n[ 238.029969][ T318] kasan_report_invalid_free (mm/kasan/report.c:221 mm/kasan/report.c:563)\n[ 238.029979][ T318] ? skb_release_data (net/core/skbuff.c:1139)\n[ 238.029989][ T318] check_slab_allocation (mm/kasan/common.c:231)\n[ 238.029995][ T318] kmem_cache_free (mm/slub.c:2637 (discriminator 1) mm/slub.c:6168 (discriminator 1) mm/slub.c:6298 (discriminator 1))\n[ 238.030004][ T318] skb_release_data (net/core/skbuff.c:1139)\n...\n[ 238.030025][ T318] sk_skb_reason_drop (net/core/skbuff.c:1256)\n[ 238.030032][ T318] pfifo_fast_reset (./include/linux/ptr_ring.h:171 ./include/linux/ptr_ring.h:309 ./include/linux/skb_array.h:98 net/sched/sch_generic.c:827)\n[ 238.030039][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221)\n...\n[ 238.030054][ T318] qdisc_reset (net/sched/sch_generic.c:1034)\n[ 238.030062][ T318] teql_destroy (./include/linux/spinlock.h:395 net/sched/sch_teql.c:157)\n[ 238.030071][ T318] __qdisc_destroy (./include/net/pkt_sched.h:328 net/sched/sch_generic.c:1077)\n[ 238.030077][ T318] qdisc_graft (net/sched/sch_api.c:1062 net/sched/sch_api.c:1053 net/sched/sch_api.c:1159)\n[ 238.030089][ T318] ? __pfx_qdisc_graft (net/sched/sch_api.c:1091)\n[ 238.030095][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221)\n[ 238.030102][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221)\n[ 238.030106][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221)\n[ 238.030114][ T318] tc_get_qdisc (net/sched/sch_api.c:1529 net/sched/sch_api.c:1556)\n...\n[ 238.072958][ T318] Allocated by task 303 on cpu 5 at 238.026275s:\n[ 238.073392][ T318] kasan_save_stack (mm/kasan/common.c:58)\n[ 238.073884][ T318] kasan_save_track (mm/kasan/common.c:64 (discriminator 5) mm/kasan/common.c:79 (discriminator 5))\n[ 238.074230][ T318] __kasan_slab_alloc (mm/kasan/common.c:369)\n[ 238.074578][ T318] kmem_cache_alloc_node_noprof (./include/linux/kasan.h:253 mm/slub.c:4542 mm/slub.c:4869 mm/slub.c:4921)\n[ 238.076091][ T318] kmalloc_reserve (net/core/skbuff.c:616 (discriminator 107))\n[ 238.076450][ T318] __alloc_skb (net/core/skbuff.c:713)\n[ 238.076834][ T318] alloc_skb_with_frags (./include/linux/skbuff.h:1383 net/core/skbuff.c:6763)\n[ 238.077178][ T318] sock_alloc_send_pskb (net/core/sock.c:2997)\n[ 238.077520][ T318] packet_sendmsg (net/packet/af_packet.c:2926 net/packet/af_packet.c:3019 net/packet/af_packet.c:3108)\n[ 238.081469][ T318]\n[ 238.081870][ T318] Freed by task 299 on cpu 1 at 238.028496s:\n[ 238.082761][ T318] kasan_save_stack (mm/kasan/common.c:58)\n[ 238.083481][ T318] kasan_save_track (mm/kasan/common.c:64 (discriminator 5) mm/kasan/common.c:79 (discriminator 5))\n[ 238.085348][ T318] kasan_save_free_info (mm/kasan/generic.c:587 (discriminator 1))\n[ 238.085900][ T318] __kasan_slab_free (mm/\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached through local packet transmission and RTNETLINK tc/qdisc operations against TEQL; remote packets alone cannot create/delete the qdiscs needed to trigger the race.\nAC:L - The race is between attacker-driven sender workers and attacker-driven qdisc teardown/re-add operations, so both sides are controllable and repeatable.\nPR:L - Creating/deleting tc qdiscs requires CAP_NET_ADMIN, but tc/qdisc paths are reachable with namespace-scoped capabilities via user/network namespaces in plausible deployments.\nUI:N - No victim action is required once the attacker has local access and the needed namespace/network privileges.\nS:U - The impact is within the kernel and does not cross a distinct security authority such as a VM or device isolation boundary.\nC:H - The bug is a double-free/use-after-free of attacker-influenced skb memory, which can potentially be shaped into kernel heap disclosure primitives.\nI:H - The double-free/use-after-free corrupts kernel heap state and is plausibly exploitable for arbitrary write or control-flow corruption.\nA:H - KASAN reports confirm crashes in skb freeing, and repeated triggering can panic or otherwise take down the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:21:49.802Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4e8ebc4c18ea8213d28e6cb867d18fcc67daca21"
},
{
"url": "https://git.kernel.org/stable/c/21c89a0a8de7eadad8d385645a95b3233f23130e"
},
{
"url": "https://git.kernel.org/stable/c/afbc79a7770b230a9f24bd39271209d6b3682c5f"
},
{
"url": "https://git.kernel.org/stable/c/e9c66d3e7d8557b3308e55c613aa07254fe97611"
},
{
"url": "https://git.kernel.org/stable/c/4a233447b941db451ea5f5a0942cffd0f7f7eaae"
},
{
"url": "https://git.kernel.org/stable/c/66360460cab63c248ca5b1070a01c0c29133b960"
}
],
"title": "net/sched: teql: Fix double-free in teql_master_xmit",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-23449",
"datePublished": "2026-04-03T15:15:32.150Z",
"dateReserved": "2026-01-13T15:37:46.020Z",
"dateUpdated": "2026-09-08T08:46:15.709Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68357 (GCVE-0-2026-68357)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
When a watchdog governor is unregistered, it updates existing watchdog
devices that were using this governor by falling back to `default_gov`.
If the governor being unregistered is currently set as `default_gov`,
the `default_gov` is never cleared. This leads to 2 use-after-free
issues:
1. New watchdog devices registered after this point will inherit the
dangling `default_gov`.
2. Existing watchdog devices using the unregistered governor will have
their `wdd->gov` reassigned to the dangling `default_gov`.
Fix the UAF by clearing `default_gov` if it matches the governor being
unregistered.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/watchdog/watchdog_pretimeout.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b9ae33faa96bdec6bc60e4c5f8f53786182e4207",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "472ec1e34ff0bb26379805cae808f658cce58c35",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7a2ee3ec6f208307eca1119a343c7b5d39c03708",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "2e47b91b9b4020fcc01def14d6b6556d66074cf4",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "0ca252720f0e38411cfec3431db9bb1aed0a412c",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7d1658b066de30f4b23afc14814d22416a971e6e",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7993d626983cc58fbde9607333cfd2d57725c197",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/watchdog/watchdog_pretimeout.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: pretimeout: Fix UAF in watchdog_unregister_governor()\n\nWhen a watchdog governor is unregistered, it updates existing watchdog\ndevices that were using this governor by falling back to `default_gov`.\n\nIf the governor being unregistered is currently set as `default_gov`,\nthe `default_gov` is never cleared. This leads to 2 use-after-free\nissues:\n1. New watchdog devices registered after this point will inherit the\n dangling `default_gov`.\n2. Existing watchdog devices using the unregistered governor will have\n their `wdd-\u003egov` reassigned to the dangling `default_gov`.\n\nFix the UAF by clearing `default_gov` if it matches the governor being\nunregistered."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:05.347Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b9ae33faa96bdec6bc60e4c5f8f53786182e4207"
},
{
"url": "https://git.kernel.org/stable/c/472ec1e34ff0bb26379805cae808f658cce58c35"
},
{
"url": "https://git.kernel.org/stable/c/7a2ee3ec6f208307eca1119a343c7b5d39c03708"
},
{
"url": "https://git.kernel.org/stable/c/2e47b91b9b4020fcc01def14d6b6556d66074cf4"
},
{
"url": "https://git.kernel.org/stable/c/0ca252720f0e38411cfec3431db9bb1aed0a412c"
},
{
"url": "https://git.kernel.org/stable/c/7d1658b066de30f4b23afc14814d22416a971e6e"
},
{
"url": "https://git.kernel.org/stable/c/7993d626983cc58fbde9607333cfd2d57725c197"
},
{
"url": "https://git.kernel.org/stable/c/7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661"
}
],
"title": "watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68357",
"datePublished": "2026-08-10T12:03:34.241Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:05.347Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64433 (GCVE-0-2026-64433)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
add_device_complete() runs from the hci_cmd_sync_work kworker, which
holds only hci_req_sync_lock and *not* hci_dev_lock. It calls
hci_conn_params_lookup() and then dereferences the returned object
(params->flags) without taking hci_dev_lock:
params = hci_conn_params_lookup(hdev, &cp->addr.bdaddr,
le_addr_type(cp->addr.type));
...
device_flags_changed(NULL, hdev, &cp->addr.bdaddr,
cp->addr.type, hdev->conn_flags,
params ? params->flags : 0);
hci_conn_params_lookup() walks hdev->le_conn_params and is documented to
require hdev->lock. A concurrent MGMT_OP_REMOVE_DEVICE
(remove_device()), which does run under hci_dev_lock, can call
hci_conn_params_free() to list_del() and kfree() the very object the
lookup returned, so the subsequent params->flags read touches freed
memory [0].
Hold hci_dev_lock() across the hci_conn_params_lookup() and the read of
params->flags (and the matching event emission) so the lookup result
cannot be freed by a concurrent remove_device() before it is used,
honouring the locking contract of hci_conn_params_lookup().
[0]: (trailing page/memory-state dump trimmed)
BUG: KASAN: slab-use-after-free in add_device_complete+0x358/0x3d8 net/bluetooth/mgmt.c:7671
Read of size 1 at addr ffff000017ab26c1 by task kworker/u9:8/388
CPU: 1 UID: 0 PID: 388 Comm: kworker/u9:8 Not tainted 7.0.11 #20 PREEMPT
Hardware name: linux,dummy-virt (DT)
Workqueue: hci0 hci_cmd_sync_work
Call trace:
show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:499 (C)
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0xb4/0xd4 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0x118/0x5d8 mm/kasan/report.c:482
kasan_report+0xb0/0xf4 mm/kasan/report.c:595
__asan_report_load1_noabort+0x20/0x2c mm/kasan/report_generic.c:378
add_device_complete+0x358/0x3d8 net/bluetooth/mgmt.c:7671
hci_cmd_sync_work+0x14c/0x240 net/bluetooth/hci_sync.c:334
process_one_work+0x628/0xd38 kernel/workqueue.c:3289
process_scheduled_works kernel/workqueue.c:3372 [inline]
worker_thread+0x7a8/0xac0 kernel/workqueue.c:3453
kthread+0x39c/0x444 kernel/kthread.c:436
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860
Allocated by task 3401:
kasan_save_stack+0x3c/0x64 mm/kasan/common.c:57
kasan_save_track+0x20/0x3c mm/kasan/common.c:78
kasan_save_alloc_info+0x40/0x54 mm/kasan/generic.c:570
poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
__kasan_kmalloc+0xd4/0xd8 mm/kasan/common.c:415
kasan_kmalloc include/linux/kasan.h:263 [inline]
__kmalloc_cache_noprof+0x1b0/0x458 mm/slub.c:5385
kmalloc_noprof include/linux/slab.h:950 [inline]
kzalloc_noprof include/linux/slab.h:1188 [inline]
hci_conn_params_add+0x10c/0x4b0 net/bluetooth/hci_core.c:2279
hci_conn_params_set net/bluetooth/mgmt.c:5162 [inline]
add_device+0x5b4/0xa54 net/bluetooth/mgmt.c:7755
hci_mgmt_cmd net/bluetooth/hci_sock.c:1721 [inline]
hci_sock_sendmsg+0x10b4/0x1dd0 net/bluetooth/hci_sock.c:1841
sock_sendmsg_nosec net/socket.c:727 [inline]
__sock_sendmsg+0xe0/0x128 net/socket.c:742
sock_write_iter+0x250/0x390 net/socket.c:1195
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x66c/0xab0 fs/read_write.c:688
ksys_write+0x1fc/0x24c fs/read_write.c:740
__do_sys_write fs/read_write.c:751 [inline]
__se_sys_write fs/read_write.c:748 [inline]
__arm64_sys_write+0x70/0xa4 fs/read_write.c:748
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x84/0x2a8 arch/arm64/kernel/syscall.c:49
el0_svc_common.constprop.0+0xe4/0x294 arch/arm64/kernel/syscall.c:132
do_el0_svc+0x44/0x5c arch/arm64/kernel/syscall.c:151
el0_svc+0x38/0xac arch/arm64/kernel/entry-common.c:724
el0t_64_sync_handler+0xa0/0xe4 arch/arm64/kernel/entry-common.c:743
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:596
Freed by task 3740:
kasan_save_stack+0x3c/0x64
---truncated---
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 31492b8386e5a243df26ca4a9421f6b041f414d5 Version: 28826a89fdfd49f3291980c2e68b8a7c5d55e199 Version: 1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775 Version: 1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775 Version: 1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775 Version: 7e370545b8bdb54ed7f1ae485d6d24d3b62a0b53 Version: 6.6.92 ≤ Version: 6.12.30 ≤ Version: 6.14.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "caed4a96d55757c139a899744657c032b6186665",
"status": "affected",
"version": "31492b8386e5a243df26ca4a9421f6b041f414d5",
"versionType": "git"
},
{
"lessThan": "e4369e4e970f3fa4676b76be14c1d315c87f22b6",
"status": "affected",
"version": "28826a89fdfd49f3291980c2e68b8a7c5d55e199",
"versionType": "git"
},
{
"lessThan": "b346efa825b5e4386f19bc63f81141652d496ec4",
"status": "affected",
"version": "1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775",
"versionType": "git"
},
{
"lessThan": "9531014c60c804e16099885d4a98aedcf31bce8d",
"status": "affected",
"version": "1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775",
"versionType": "git"
},
{
"lessThan": "fa85d985f614bc3feb343000f14a1072e99b0df1",
"status": "affected",
"version": "1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775",
"versionType": "git"
},
{
"status": "affected",
"version": "7e370545b8bdb54ed7f1ae485d6d24d3b62a0b53",
"versionType": "git"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.92",
"versionType": "semver"
},
{
"lessThan": "6.12.96",
"status": "affected",
"version": "6.12.30",
"versionType": "semver"
},
{
"lessThan": "6.15",
"status": "affected",
"version": "6.14.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"lessThan": "6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.92",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.12.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.14.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete\n\nadd_device_complete() runs from the hci_cmd_sync_work kworker, which\nholds only hci_req_sync_lock and *not* hci_dev_lock. It calls\nhci_conn_params_lookup() and then dereferences the returned object\n(params-\u003eflags) without taking hci_dev_lock:\n\n\tparams = hci_conn_params_lookup(hdev, \u0026cp-\u003eaddr.bdaddr,\n\t\t\t\t\tle_addr_type(cp-\u003eaddr.type));\n\t...\n\tdevice_flags_changed(NULL, hdev, \u0026cp-\u003eaddr.bdaddr,\n\t\t\t cp-\u003eaddr.type, hdev-\u003econn_flags,\n\t\t\t params ? params-\u003eflags : 0);\n\nhci_conn_params_lookup() walks hdev-\u003ele_conn_params and is documented to\nrequire hdev-\u003elock. A concurrent MGMT_OP_REMOVE_DEVICE\n(remove_device()), which does run under hci_dev_lock, can call\nhci_conn_params_free() to list_del() and kfree() the very object the\nlookup returned, so the subsequent params-\u003eflags read touches freed\nmemory [0].\n\nHold hci_dev_lock() across the hci_conn_params_lookup() and the read of\nparams-\u003eflags (and the matching event emission) so the lookup result\ncannot be freed by a concurrent remove_device() before it is used,\nhonouring the locking contract of hci_conn_params_lookup().\n\n[0]: (trailing page/memory-state dump trimmed)\nBUG: KASAN: slab-use-after-free in add_device_complete+0x358/0x3d8 net/bluetooth/mgmt.c:7671\nRead of size 1 at addr ffff000017ab26c1 by task kworker/u9:8/388\n\nCPU: 1 UID: 0 PID: 388 Comm: kworker/u9:8 Not tainted 7.0.11 #20 PREEMPT\nHardware name: linux,dummy-virt (DT)\nWorkqueue: hci0 hci_cmd_sync_work\nCall trace:\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:499 (C)\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0xb4/0xd4 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x118/0x5d8 mm/kasan/report.c:482\n kasan_report+0xb0/0xf4 mm/kasan/report.c:595\n __asan_report_load1_noabort+0x20/0x2c mm/kasan/report_generic.c:378\n add_device_complete+0x358/0x3d8 net/bluetooth/mgmt.c:7671\n hci_cmd_sync_work+0x14c/0x240 net/bluetooth/hci_sync.c:334\n process_one_work+0x628/0xd38 kernel/workqueue.c:3289\n process_scheduled_works kernel/workqueue.c:3372 [inline]\n worker_thread+0x7a8/0xac0 kernel/workqueue.c:3453\n kthread+0x39c/0x444 kernel/kthread.c:436\n ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860\n\nAllocated by task 3401:\n kasan_save_stack+0x3c/0x64 mm/kasan/common.c:57\n kasan_save_track+0x20/0x3c mm/kasan/common.c:78\n kasan_save_alloc_info+0x40/0x54 mm/kasan/generic.c:570\n poison_kmalloc_redzone mm/kasan/common.c:398 [inline]\n __kasan_kmalloc+0xd4/0xd8 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263 [inline]\n __kmalloc_cache_noprof+0x1b0/0x458 mm/slub.c:5385\n kmalloc_noprof include/linux/slab.h:950 [inline]\n kzalloc_noprof include/linux/slab.h:1188 [inline]\n hci_conn_params_add+0x10c/0x4b0 net/bluetooth/hci_core.c:2279\n hci_conn_params_set net/bluetooth/mgmt.c:5162 [inline]\n add_device+0x5b4/0xa54 net/bluetooth/mgmt.c:7755\n hci_mgmt_cmd net/bluetooth/hci_sock.c:1721 [inline]\n hci_sock_sendmsg+0x10b4/0x1dd0 net/bluetooth/hci_sock.c:1841\n sock_sendmsg_nosec net/socket.c:727 [inline]\n __sock_sendmsg+0xe0/0x128 net/socket.c:742\n sock_write_iter+0x250/0x390 net/socket.c:1195\n new_sync_write fs/read_write.c:595 [inline]\n vfs_write+0x66c/0xab0 fs/read_write.c:688\n ksys_write+0x1fc/0x24c fs/read_write.c:740\n __do_sys_write fs/read_write.c:751 [inline]\n __se_sys_write fs/read_write.c:748 [inline]\n __arm64_sys_write+0x70/0xa4 fs/read_write.c:748\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x84/0x2a8 arch/arm64/kernel/syscall.c:49\n el0_svc_common.constprop.0+0xe4/0x294 arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x44/0x5c arch/arm64/kernel/syscall.c:151\n el0_svc+0x38/0xac arch/arm64/kernel/entry-common.c:724\n el0t_64_sync_handler+0xa0/0xe4 arch/arm64/kernel/entry-common.c:743\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:596\n\nFreed by task 3740:\n kasan_save_stack+0x3c/0x64 \n---truncated---"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:34.241Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/caed4a96d55757c139a899744657c032b6186665"
},
{
"url": "https://git.kernel.org/stable/c/e4369e4e970f3fa4676b76be14c1d315c87f22b6"
},
{
"url": "https://git.kernel.org/stable/c/b346efa825b5e4386f19bc63f81141652d496ec4"
},
{
"url": "https://git.kernel.org/stable/c/9531014c60c804e16099885d4a98aedcf31bce8d"
},
{
"url": "https://git.kernel.org/stable/c/fa85d985f614bc3feb343000f14a1072e99b0df1"
}
],
"title": "Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64433",
"datePublished": "2026-07-25T08:51:08.432Z",
"dateReserved": "2026-07-19T15:36:31.787Z",
"dateUpdated": "2026-08-17T04:55:34.241Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74712 (GCVE-0-2026-74712)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vdpa/mlx5: Fix buffer length in create_direct_keys()
We have seen in our CI the following KASAN message:
BUG: KASAN: slab-out-of-bounds in cmd_exec+0x550/0xca0 [mlx5_core]
Read of size 272 at addr 0000000176795020 by task qemu-system-s39/82764
[...]
[<000011388ab3a7a0>] cmd_exec+0x550/0xca0 [mlx5_core]
[<000011388ab3b61c>] mlx5_cmd_exec_cb+0x25c/0x4f0 [mlx5_core]
[<000011388b21e82e>] mlx5_vdpa_exec_async_cmds+0x22e/0x5e0 [mlx5_vdpa]
[<000011388b21fd44>] create_direct_keys+0x954/0xef0 [mlx5_vdpa]
[...]
The buggy address is located 4128 bytes inside of
allocated 4384-byte region [0000000176794000, 0000000176795120)
So in essence we read 16 bytes beyond 4384-byte allocation.
create_direct_keys calculates the pointer and length for in and out
buffers.
The size calculation for in includes the entire structure
size (out + in + mtt[]) but the pointer passed to cmd_exec points only
to the 'in' field, skipping the 'out' field.
This causes mlx5_copy_to_msg() to read beyond the allocated buffer
by sizeof(out) bytes when copying command data.
Properly calculate the input size to match the pointer and allocation size.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/vdpa/mlx5/core/mr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ec3bb289cf19d526224117d5d450a5fd9cbd5ab2",
"status": "affected",
"version": "0071b138d44af4296bf871e6624369ce697b4b15",
"versionType": "git"
},
{
"lessThan": "cde8931a25392670dd59a0acfcab87a830ab66c5",
"status": "affected",
"version": "0071b138d44af4296bf871e6624369ce697b4b15",
"versionType": "git"
},
{
"lessThan": "6c8a9f7bc00301e533a5366384f3070a8e7f8430",
"status": "affected",
"version": "0071b138d44af4296bf871e6624369ce697b4b15",
"versionType": "git"
},
{
"lessThan": "727e1f569855df83579edbd73dcb4a0723543a12",
"status": "affected",
"version": "0071b138d44af4296bf871e6624369ce697b4b15",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/vdpa/mlx5/core/mr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa/mlx5: Fix buffer length in create_direct_keys()\n\nWe have seen in our CI the following KASAN message:\nBUG: KASAN: slab-out-of-bounds in cmd_exec+0x550/0xca0 [mlx5_core]\nRead of size 272 at addr 0000000176795020 by task qemu-system-s39/82764\n[...]\n[\u003c000011388ab3a7a0\u003e] cmd_exec+0x550/0xca0 [mlx5_core]\n[\u003c000011388ab3b61c\u003e] mlx5_cmd_exec_cb+0x25c/0x4f0 [mlx5_core]\n[\u003c000011388b21e82e\u003e] mlx5_vdpa_exec_async_cmds+0x22e/0x5e0 [mlx5_vdpa]\n[\u003c000011388b21fd44\u003e] create_direct_keys+0x954/0xef0 [mlx5_vdpa]\n[...]\nThe buggy address is located 4128 bytes inside of\nallocated 4384-byte region [0000000176794000, 0000000176795120)\n\nSo in essence we read 16 bytes beyond 4384-byte allocation.\ncreate_direct_keys calculates the pointer and length for in and out\nbuffers.\nThe size calculation for in includes the entire structure\nsize (out + in + mtt[]) but the pointer passed to cmd_exec points only\nto the \u0027in\u0027 field, skipping the \u0027out\u0027 field.\n\nThis causes mlx5_copy_to_msg() to read beyond the allocated buffer\nby sizeof(out) bytes when copying command data.\n\nProperly calculate the input size to match the pointer and allocation size."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached when host vDPA memory keys are created during IOTLB/set_map handling on /dev/vhost-vdpa (ioctl/write from QEMU/vhost), not from remote network packet processing; worst case is a co-tenant VM guest driving host QEMU virtio memory updates on the same mlx5 vDPA host.\nAC:L - Once mlx5 vDPA user MR setup runs, create_direct_keys() always passes an oversized inlen to mlx5_cmd_exec_cb(), deterministically causing mlx5_copy_to_msg() to read past the slab allocation; no race or victim state is required beyond normal virtio memory mapping.\nPR:N - In cloud mlx5 virtio-vDPA deployments a malicious VM tenant needs no host credentials\u2014normal guest virtio-net bring-up causes QEMU to issue vhost IOTLB updates that invoke mlx5_vdpa_set_map() and create_user_mr() on the host without CAP_NET_ADMIN or root in the host init namespace.\nUI:N - Exploitation requires only automated virtio driver initialization and memory table updates; no additional victim clicks, mounts, or manual actions are needed beyond provisioning a vDPA-backed VM, which is the intended operational path.\nS:C - The vulnerable mlx5 vDPA code runs in the hypervisor host kernel while the practical attacker is a guest VM tenant; successful slab out-of-bounds reads and corrupted firmware commands cross the guest/host virtualization boundary per KVM guest-to-host guidance.\nC:H - Incorrect inlen makes mlx5_copy_to_msg() perform a slab out-of-bounds read (KASAN-reported) of adjacent kernel heap memory, copying leaked bytes into CREATE_MKEY commands and enabling arbitrary kernel information disclosure, not a bounded benign leak.\nI:H - The over-read injects adjacent heap contents into firmware CREATE_MKEY command buffers, corrupting memory-key setup data sent to the mlx5 device; this is exploitable kernel memory corruption that can alter device DMA mappings and enable further control, not a read-only crash.\nA:H - The flaw triggers a KASAN slab-out-of-bounds fault in mlx5_core cmd_exec() during normal MR creation; such heap corruption commonly causes kernel oops/panic and can also destabilize vDPA networking on repeated virtio memory remaps."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:54.897Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ec3bb289cf19d526224117d5d450a5fd9cbd5ab2"
},
{
"url": "https://git.kernel.org/stable/c/cde8931a25392670dd59a0acfcab87a830ab66c5"
},
{
"url": "https://git.kernel.org/stable/c/6c8a9f7bc00301e533a5366384f3070a8e7f8430"
},
{
"url": "https://git.kernel.org/stable/c/727e1f569855df83579edbd73dcb4a0723543a12"
}
],
"title": "vdpa/mlx5: Fix buffer length in create_direct_keys()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74712",
"datePublished": "2026-08-22T15:33:08.392Z",
"dateReserved": "2026-08-15T05:44:03.928Z",
"dateUpdated": "2026-08-25T05:41:54.897Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64338 (GCVE-0-2026-64338)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: misc: uss720: unregister parport on probe failure
uss720_probe() registers a parport before reading the 1284 register used
to detect unsupported Belkin F5U002 adapters. If get_1284_register()
fails, the error path drops the driver private data and the USB device
reference, but leaves the parport device registered.
Leaving the port registered is more than a private allocation leak:
parport_register_port() has already reserved a parport number and
registered the parport bus device, while pp->private_data still points at
the private data that the common error path is about to release.
Undo the pre-announce registration in the get_1284_register() failure
branch before jumping to the common private-data cleanup path. Clear
priv->pp first, matching the disconnect path and avoiding a stale pointer
in the private data.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 04736c1bc32197f7d859e01a96ae80a16659931d Version: 4eaf2331a77996bbbaf2b824d452ac8ebda7e6e7 Version: 8fc246a8a456679993df565d3c9e3da28030ee43 Version: 10132ccf99f49b43aeb7470df50d72344a601ad6 Version: 3295f1b866bfbcabd625511968e8a5c541f9ab32 Version: 3295f1b866bfbcabd625511968e8a5c541f9ab32 Version: 3295f1b866bfbcabd625511968e8a5c541f9ab32 Version: 3295f1b866bfbcabd625511968e8a5c541f9ab32 Version: 02d13616ca30014ed96302e51a5b0e17664e58bc Version: dff3b01e91a3df93063b03d0f8dd5c40546687ec Version: 489d77fbd66375972a380d207f7eb39b00c4a67b Version: 5.10.221 ≤ Version: 5.15.162 ≤ Version: 6.1.96 ≤ Version: 6.6.36 ≤ Version: 4.19.317 ≤ Version: 5.4.279 ≤ Version: 6.9.7 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/uss720.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6bbb98bec71b577fda4f4b48f7aea5874b04a576",
"status": "affected",
"version": "04736c1bc32197f7d859e01a96ae80a16659931d",
"versionType": "git"
},
{
"lessThan": "93563243377f8e9b46cc94d9c4f06533dd31b141",
"status": "affected",
"version": "4eaf2331a77996bbbaf2b824d452ac8ebda7e6e7",
"versionType": "git"
},
{
"lessThan": "1712fd71a5aaf81e47c747f180535fa963ad7830",
"status": "affected",
"version": "8fc246a8a456679993df565d3c9e3da28030ee43",
"versionType": "git"
},
{
"lessThan": "0b3073f40cc9f95d5ff0037eb0a06f5c1725a7ea",
"status": "affected",
"version": "10132ccf99f49b43aeb7470df50d72344a601ad6",
"versionType": "git"
},
{
"lessThan": "5e62d7857fd51b908b8371062ee839739a086bbe",
"status": "affected",
"version": "3295f1b866bfbcabd625511968e8a5c541f9ab32",
"versionType": "git"
},
{
"lessThan": "729b68a5bad71220ae0914c8bdab9488ad5be6c8",
"status": "affected",
"version": "3295f1b866bfbcabd625511968e8a5c541f9ab32",
"versionType": "git"
},
{
"lessThan": "48dd0b2ec9f2e97c486eb68cd0a64b25c1c3df3e",
"status": "affected",
"version": "3295f1b866bfbcabd625511968e8a5c541f9ab32",
"versionType": "git"
},
{
"lessThan": "b4ecbdc4f8830f5586c4a5cfc384c00f20f8f8b3",
"status": "affected",
"version": "3295f1b866bfbcabd625511968e8a5c541f9ab32",
"versionType": "git"
},
{
"status": "affected",
"version": "02d13616ca30014ed96302e51a5b0e17664e58bc",
"versionType": "git"
},
{
"status": "affected",
"version": "dff3b01e91a3df93063b03d0f8dd5c40546687ec",
"versionType": "git"
},
{
"status": "affected",
"version": "489d77fbd66375972a380d207f7eb39b00c4a67b",
"versionType": "git"
},
{
"lessThan": "5.10.261",
"status": "affected",
"version": "5.10.221",
"versionType": "semver"
},
{
"lessThan": "5.15.212",
"status": "affected",
"version": "5.15.162",
"versionType": "semver"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.96",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.36",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.317",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.279",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.9.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/uss720.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"lessThan": "6.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.10.221",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.15.162",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.96",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.317",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.279",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.9.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: misc: uss720: unregister parport on probe failure\n\nuss720_probe() registers a parport before reading the 1284 register used\nto detect unsupported Belkin F5U002 adapters. If get_1284_register()\nfails, the error path drops the driver private data and the USB device\nreference, but leaves the parport device registered.\n\nLeaving the port registered is more than a private allocation leak:\nparport_register_port() has already reserved a parport number and\nregistered the parport bus device, while pp-\u003eprivate_data still points at\nthe private data that the common error path is about to release.\n\nUndo the pre-announce registration in the get_1284_register() failure\nbranch before jumping to the common private-data cleanup path. Clear\npriv-\u003epp first, matching the disconnect path and avoiding a stale pointer\nin the private data.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:41.636Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6bbb98bec71b577fda4f4b48f7aea5874b04a576"
},
{
"url": "https://git.kernel.org/stable/c/93563243377f8e9b46cc94d9c4f06533dd31b141"
},
{
"url": "https://git.kernel.org/stable/c/1712fd71a5aaf81e47c747f180535fa963ad7830"
},
{
"url": "https://git.kernel.org/stable/c/0b3073f40cc9f95d5ff0037eb0a06f5c1725a7ea"
},
{
"url": "https://git.kernel.org/stable/c/5e62d7857fd51b908b8371062ee839739a086bbe"
},
{
"url": "https://git.kernel.org/stable/c/729b68a5bad71220ae0914c8bdab9488ad5be6c8"
},
{
"url": "https://git.kernel.org/stable/c/48dd0b2ec9f2e97c486eb68cd0a64b25c1c3df3e"
},
{
"url": "https://git.kernel.org/stable/c/b4ecbdc4f8830f5586c4a5cfc384c00f20f8f8b3"
}
],
"title": "USB: misc: uss720: unregister parport on probe failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64338",
"datePublished": "2026-07-25T08:50:02.673Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:41.636Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68375 (GCVE-0-2026-68375)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Handle partially initialized auxiliary devices
bnxt_aux_devices_init() calls auxiliary_device_init() before all fields
used by bnxt_aux_dev_release() are initialized. After
auxiliary_device_init() succeeds, later errors must unwind with
auxiliary_device_uninit(), which invokes the release callback.
The release callback assumes that aux_priv->id, aux_priv->edev,
edev->net and edev->ulp_tbl are all populated. If allocation fails
after auxiliary_device_init(), the release path can otherwise dereference
or clear partially initialized state.
Allocate and attach the bnxt_en_dev and ULP table before calling
auxiliary_device_init(), so the release callback only sees a fully
initialized auxiliary private object. If auxiliary_device_init() itself
fails, free those allocations directly because device_initialize() has not
run and the release callback will not be invoked.
This issue was found by a static analysis checker and confirmed by manual
source review.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/broadcom/bnxt/bnxt_ulp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4e1caa5fdd0dea36938fe39cceb1522e9d86c937",
"status": "affected",
"version": "194fad5b27815ca80e832ac875c0026ff96fc243",
"versionType": "git"
},
{
"lessThan": "1cb8553c02e93e5a150cebd42f9ee3db0ece4707",
"status": "affected",
"version": "194fad5b27815ca80e832ac875c0026ff96fc243",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/broadcom/bnxt/bnxt_ulp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"lessThan": "6.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Handle partially initialized auxiliary devices\n\nbnxt_aux_devices_init() calls auxiliary_device_init() before all fields\nused by bnxt_aux_dev_release() are initialized. After\nauxiliary_device_init() succeeds, later errors must unwind with\nauxiliary_device_uninit(), which invokes the release callback.\n\nThe release callback assumes that aux_priv-\u003eid, aux_priv-\u003eedev,\nedev-\u003enet and edev-\u003eulp_tbl are all populated. If allocation fails\nafter auxiliary_device_init(), the release path can otherwise dereference\nor clear partially initialized state.\n\nAllocate and attach the bnxt_en_dev and ULP table before calling\nauxiliary_device_init(), so the release callback only sees a fully\ninitialized auxiliary private object. If auxiliary_device_init() itself\nfails, free those allocations directly because device_initialize() has not\nrun and the release callback will not be invoked.\n\nThis issue was found by a static analysis checker and confirmed by manual\nsource review."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:20.877Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4e1caa5fdd0dea36938fe39cceb1522e9d86c937"
},
{
"url": "https://git.kernel.org/stable/c/1cb8553c02e93e5a150cebd42f9ee3db0ece4707"
}
],
"title": "bnxt_en: Handle partially initialized auxiliary devices",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68375",
"datePublished": "2026-08-10T12:03:53.659Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-17T05:04:20.877Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68397 (GCVE-0-2026-68397)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: take a reference on the socket found in afiucv_hs_rcv()
afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,
drops the lock, and then passes the socket to the afiucv_hs_callback_*()
handlers without holding a reference. AF_IUCV sockets are not
RCU-protected and are freed synchronously by iucv_sock_kill() ->
sock_put(), so a concurrent close can free the socket in the window
between read_unlock() and the handler, which then dereferences freed
memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()).
Take a reference with sock_hold() while the socket is still on the list
and release it with sock_put() once the handler has run.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5739be5c19495d709d902a2912c9102ce78740d5",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "bc6c6e546ffff8865daaeb622ef348c2d481e80f",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "e3e0679fc950191aff8f27fa78abcfc2462cff4a",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "4dc0e63abf8bc7ba8892e617c1fb8b204361e022",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "1801cb20a5025a787d6853e19c38db138344b4b4",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "c75a950e77356e526672cba4584080c6c8b793b6",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "5595ea59cdf29182cf6a270cacc1426c57b603de",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "4fa349156043dc119721d067329714179f501749",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: take a reference on the socket found in afiucv_hs_rcv()\n\nafiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,\ndrops the lock, and then passes the socket to the afiucv_hs_callback_*()\nhandlers without holding a reference. AF_IUCV sockets are not\nRCU-protected and are freed synchronously by iucv_sock_kill() -\u003e\nsock_put(), so a concurrent close can free the socket in the window\nbetween read_unlock() and the handler, which then dereferences freed\nmemory (for example sk-\u003esk_data_ready() in afiucv_hs_callback_syn()).\n\nTake a reference with sock_hold() while the socket is still on the list\nand release it with sock_put() once the handler has run."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable handler is registered via dev_add_pack() for ethertype ETH_P_AF_IUCV (0xFBFB) on every netdevice, so any peer LPAR/guest on the same HiperSockets internal LAN or any host on an attached Ethernet segment can drive afiucv_hs_rcv() with crafted frames; the frames are raw L2 and cannot be routed across an IP hop, so the vector is adjacent rather than network.\nAC:L - The attacker controls the packet side of the race outright (flooding 0xFBFB frames) and can drive the freeing side too, since SYN frames make a listener spawn and enqueue child sockets while FIN/SYN|FIN frames push sockets to IUCV_DISCONN and wake the application into close(), so the read_unlock()-to-handler window can be retried indefinitely until won.\nPR:N - afiucv_hs_rcv() runs from the netif RX softirq and processes any matching frame with no authentication, credential check, or capability test anywhere on the path; the attacker needs no account or privilege on the target s390 system.\nUI:N - No victim action is required: the attacker\u0027s own frames both create the AF_IUCV child sockets and trigger the state changes that lead to their teardown, and the packet handler runs unconditionally in softirq context.\nS:U - The freed struct sock and the resulting corruption stay inside the kernel of the affected LPAR or z/VM guest; no hypervisor, IOMMU, or container boundary is crossed.\nC:H - This is a use-after-free on a socket allocated from a generic kmalloc cache (iucv_proto is registered without its own slab), so an attacker who reclaims the object has the kernel read attacker-influenced or stale heap contents through sk fields, sk_filter()\u0027s BPF program pointer, and the iucv backlog queues, yielding kernel memory disclosure.\nI:H - After the free the handlers perform indirect calls through the freed object (sk-\u003esk_data_ready(), sk-\u003esk_state_change(), sk_filter()) and writes into it (sk_state, atomic_sub on iucv-\u003emsg_sent, skb_queue_tail() list-pointer updates), giving control-flow hijack and write primitives once the slab object is reclaimed with attacker-controlled data.\nA:H - Dereferencing the freed socket from softirq context reliably produces an oops or \"Fatal exception in interrupt\" panic, and the attacker can repeat the frame flood at will, causing complete loss of availability of the IBM Z LPAR or guest."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:47.433Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5739be5c19495d709d902a2912c9102ce78740d5"
},
{
"url": "https://git.kernel.org/stable/c/bc6c6e546ffff8865daaeb622ef348c2d481e80f"
},
{
"url": "https://git.kernel.org/stable/c/e3e0679fc950191aff8f27fa78abcfc2462cff4a"
},
{
"url": "https://git.kernel.org/stable/c/4dc0e63abf8bc7ba8892e617c1fb8b204361e022"
},
{
"url": "https://git.kernel.org/stable/c/1801cb20a5025a787d6853e19c38db138344b4b4"
},
{
"url": "https://git.kernel.org/stable/c/c75a950e77356e526672cba4584080c6c8b793b6"
},
{
"url": "https://git.kernel.org/stable/c/5595ea59cdf29182cf6a270cacc1426c57b603de"
},
{
"url": "https://git.kernel.org/stable/c/4fa349156043dc119721d067329714179f501749"
}
],
"title": "net/iucv: take a reference on the socket found in afiucv_hs_rcv()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68397",
"datePublished": "2026-08-10T12:04:16.772Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:47.433Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64015 (GCVE-0-2026-64015)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
security/keys: fix missed RCU read section on lookup
Nicholas Carlini reports that the keyring code calls assoc_array_find()
in find_key_to_update() without holding the RCU read lock, while the
assoc_array_gc() code really is designed around removing the node from
the tree and then freeing it after an RCU grace-period.
The regular key handling doesn't see this because holding the keyring
semaphore hides any lifetime issues, but the persistent key handling
uses a different model.
Instead of extending the keyring locking, just do the simple RCU locking
that the assoc_array was designed for.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b2a4df200d570b2c33a57e1ebfa5896e4bc81b69 Version: b2a4df200d570b2c33a57e1ebfa5896e4bc81b69 Version: b2a4df200d570b2c33a57e1ebfa5896e4bc81b69 Version: b2a4df200d570b2c33a57e1ebfa5896e4bc81b69 Version: b2a4df200d570b2c33a57e1ebfa5896e4bc81b69 Version: b2a4df200d570b2c33a57e1ebfa5896e4bc81b69 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/keys/keyring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4c5d407ba3ff7f30561ff73ba1b07ed70c864edc",
"status": "affected",
"version": "b2a4df200d570b2c33a57e1ebfa5896e4bc81b69",
"versionType": "git"
},
{
"lessThan": "cefa4265b11176c897a7d9e8e54d89e3701c5584",
"status": "affected",
"version": "b2a4df200d570b2c33a57e1ebfa5896e4bc81b69",
"versionType": "git"
},
{
"lessThan": "5659e6923cb72f8e18e8b539109ab512455fe195",
"status": "affected",
"version": "b2a4df200d570b2c33a57e1ebfa5896e4bc81b69",
"versionType": "git"
},
{
"lessThan": "50bb3435a5e627bfbdc52eb4536f49f88b3486b8",
"status": "affected",
"version": "b2a4df200d570b2c33a57e1ebfa5896e4bc81b69",
"versionType": "git"
},
{
"lessThan": "66288dcadf80974436250e9f70ed848836b835b5",
"status": "affected",
"version": "b2a4df200d570b2c33a57e1ebfa5896e4bc81b69",
"versionType": "git"
},
{
"lessThan": "43a1e3744548e6fd85873e6fb43e293eb4010694",
"status": "affected",
"version": "b2a4df200d570b2c33a57e1ebfa5896e4bc81b69",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/keys/keyring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.13"
},
{
"lessThan": "3.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsecurity/keys: fix missed RCU read section on lookup\n\nNicholas Carlini reports that the keyring code calls assoc_array_find()\nin find_key_to_update() without holding the RCU read lock, while the\nassoc_array_gc() code really is designed around removing the node from\nthe tree and then freeing it after an RCU grace-period.\n\nThe regular key handling doesn\u0027t see this because holding the keyring\nsemaphore hides any lifetime issues, but the persistent key handling\nuses a different model.\n\nInstead of extending the keyring locking, just do the simple RCU locking\nthat the assoc_array was designed for."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through find_key_to_update() on the persistent keyring register, which is invoked from keyctl_get_persistent() via the keyctl(2) syscall. There is no network, adjacent-radio, or physical-device path to this code.\nAC:L - Exploitation is a race between assoc_array_find() and assoc_array_gc() on the .persistent_register keyring; the attacker controls both sides by repeatedly calling KEYCTL_GET_PERSISTENT (including from multiple threads) while driving key expiry/GC via keyctl timeouts or natural garbage collection. Per kernel guidance, attacker-controlled races are AC:L.\nPR:L - Any unprivileged local user who can invoke keyctl() can call KEYCTL_GET_PERSISTENT for their own UID (-1) with a writable destination keyring (e.g., session keyring). No real-root or CAP_SETUID capability is required for the vulnerable lookup path; this remains PR:L even inside user namespaces.\nUI:N - Exploitation requires only the attacker\u0027s own keyctl syscalls and does not depend on any victim user action such as mounting a filesystem or opening a file.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same kernel security domain; it does not cross a VM, container, or IOMMU boundary on its own.\nC:H - assoc_array_find() is documented to require an RCU read lock, but the persistent-keyring path called it without one while assoc_array_gc() frees tree nodes via call_rcu(), yielding a use-after-free on assoc_array nodes/leaves. UAF on kernel heap objects can be turned into arbitrary kernel memory reads.\nI:H - The freed assoc_array nodes can be reallocated and corrupted through concurrent GC versus lookup, providing a standard kernel heap UAF primitive that can be developed into arbitrary write or code-execution primitives.\nA:H - Dereferencing RCU-freed assoc_array tree nodes during lookup can cause kernel oops/panic from invalid pointer access, and UAF exploitation commonly destabilizes or crashes the kernel even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:12.353Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4c5d407ba3ff7f30561ff73ba1b07ed70c864edc"
},
{
"url": "https://git.kernel.org/stable/c/cefa4265b11176c897a7d9e8e54d89e3701c5584"
},
{
"url": "https://git.kernel.org/stable/c/5659e6923cb72f8e18e8b539109ab512455fe195"
},
{
"url": "https://git.kernel.org/stable/c/50bb3435a5e627bfbdc52eb4536f49f88b3486b8"
},
{
"url": "https://git.kernel.org/stable/c/66288dcadf80974436250e9f70ed848836b835b5"
},
{
"url": "https://git.kernel.org/stable/c/43a1e3744548e6fd85873e6fb43e293eb4010694"
}
],
"title": "security/keys: fix missed RCU read section on lookup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64015",
"datePublished": "2026-07-19T15:39:10.557Z",
"dateReserved": "2026-07-19T07:54:57.027Z",
"dateUpdated": "2026-08-05T12:38:12.353Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64540 (GCVE-0-2026-64540)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
genelink_rx_fixup() splits an aggregated RX frame into its individual
packets, using a per-packet length taken from device-supplied data. That
length is only bounded by GL_MAX_PACKET_LEN (1514); it is never compared
against how many bytes were actually received.
A malicious GeneLink (GL620A) device can therefore send a short URB whose
header claims packet_count > 1 and a first packet of up to 1514 bytes.
skb_put_data(gl_skb, packet->packet_data, size);
then copies past the end of the receive buffer and hands the adjacent slab
contents up the network stack, an out-of-bounds read that leaks kernel heap.
No privilege is required: the path runs in the usbnet RX softirq as soon as
the interface is up.
BUG: KASAN: slab-out-of-bounds in genelink_rx_fixup (drivers/net/usb/gl620a.c:112)
Read of size 1514 at addr ffff888011309708 by task ksoftirqd/0/14
Call Trace:
...
__asan_memcpy (mm/kasan/shadow.c:105)
genelink_rx_fixup (include/linux/skbuff.h:2814 drivers/net/usb/gl620a.c:112)
usbnet_bh (drivers/net/usb/usbnet.c:572 drivers/net/usb/usbnet.c:1589)
process_one_work (kernel/workqueue.c:3322)
bh_worker (kernel/workqueue.c:3405)
tasklet_action (kernel/softirq.c:965)
handle_softirqs (kernel/softirq.c:622)
run_ksoftirqd (kernel/softirq.c:1076)
...
skb_pull() already verifies that the requested length fits the buffer and
returns NULL otherwise. Move it ahead of the copy and check its result, so
a packet that overruns the received data is rejected before it is read.
Well-formed frames, whose packets are fully present, are unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 47ee3051c856cc2aa95d35d577a8cb37279d540f Version: 47ee3051c856cc2aa95d35d577a8cb37279d540f Version: 47ee3051c856cc2aa95d35d577a8cb37279d540f Version: 47ee3051c856cc2aa95d35d577a8cb37279d540f Version: 47ee3051c856cc2aa95d35d577a8cb37279d540f Version: 47ee3051c856cc2aa95d35d577a8cb37279d540f Version: 47ee3051c856cc2aa95d35d577a8cb37279d540f Version: 47ee3051c856cc2aa95d35d577a8cb37279d540f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/usb/gl620a.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "255d03551f94c7bdd86c7d9181a70b21917d829f",
"status": "affected",
"version": "47ee3051c856cc2aa95d35d577a8cb37279d540f",
"versionType": "git"
},
{
"lessThan": "4359376e6238d89977a35086e47ca3b07f43e850",
"status": "affected",
"version": "47ee3051c856cc2aa95d35d577a8cb37279d540f",
"versionType": "git"
},
{
"lessThan": "8624e179fa3ce23c2fbd1a198ce30764b73f054a",
"status": "affected",
"version": "47ee3051c856cc2aa95d35d577a8cb37279d540f",
"versionType": "git"
},
{
"lessThan": "573418f7ea8f859a841417eb4b915594094fd967",
"status": "affected",
"version": "47ee3051c856cc2aa95d35d577a8cb37279d540f",
"versionType": "git"
},
{
"lessThan": "0575599e451aff3c5329922562374a2cab25fc51",
"status": "affected",
"version": "47ee3051c856cc2aa95d35d577a8cb37279d540f",
"versionType": "git"
},
{
"lessThan": "0a7d9c7c5f1f208c523abbb4db6aea7bc1fad3db",
"status": "affected",
"version": "47ee3051c856cc2aa95d35d577a8cb37279d540f",
"versionType": "git"
},
{
"lessThan": "3ef79fa3860e644c8de7834fa7300e1c58f38862",
"status": "affected",
"version": "47ee3051c856cc2aa95d35d577a8cb37279d540f",
"versionType": "git"
},
{
"lessThan": "8ff7f2a6da4fccaa5cc9be7251a24e71e29fbd1a",
"status": "affected",
"version": "47ee3051c856cc2aa95d35d577a8cb37279d540f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/usb/gl620a.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.14"
},
{
"lessThan": "2.6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()\n\ngenelink_rx_fixup() splits an aggregated RX frame into its individual\npackets, using a per-packet length taken from device-supplied data. That\nlength is only bounded by GL_MAX_PACKET_LEN (1514); it is never compared\nagainst how many bytes were actually received.\n\nA malicious GeneLink (GL620A) device can therefore send a short URB whose\nheader claims packet_count \u003e 1 and a first packet of up to 1514 bytes.\n\n\tskb_put_data(gl_skb, packet-\u003epacket_data, size);\n\nthen copies past the end of the receive buffer and hands the adjacent slab\ncontents up the network stack, an out-of-bounds read that leaks kernel heap.\nNo privilege is required: the path runs in the usbnet RX softirq as soon as\nthe interface is up.\n\n BUG: KASAN: slab-out-of-bounds in genelink_rx_fixup (drivers/net/usb/gl620a.c:112)\n Read of size 1514 at addr ffff888011309708 by task ksoftirqd/0/14\n Call Trace:\n ...\n __asan_memcpy (mm/kasan/shadow.c:105)\n genelink_rx_fixup (include/linux/skbuff.h:2814 drivers/net/usb/gl620a.c:112)\n usbnet_bh (drivers/net/usb/usbnet.c:572 drivers/net/usb/usbnet.c:1589)\n process_one_work (kernel/workqueue.c:3322)\n bh_worker (kernel/workqueue.c:3405)\n tasklet_action (kernel/softirq.c:965)\n handle_softirqs (kernel/softirq.c:622)\n run_ksoftirqd (kernel/softirq.c:1076)\n ...\n\nskb_pull() already verifies that the requested length fits the buffer and\nreturns NULL otherwise. Move it ahead of the copy and check its result, so\na packet that overruns the received data is rejected before it is read.\nWell-formed frames, whose packets are fully present, are unaffected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The gl620a driver is a FLAG_POINTTOPOINT network interface, and the malformed aggregation header is received network data generated by the peer host on the other end of the GeneLink host-to-host cable, processed in the usbnet RX softirq. The attack is confined to that directly attached link segment, making it logically adjacent rather than routable or purely physical.\nAC:L - The attacker fully controls the frame contents and only needs to send an 18-byte URB declaring packet_count \u003e 1 with a first packet_length of up to 1514; the missing bounds check is deterministic with no race, memory-layout, or timing dependency.\nPR:N - No credentials or privileges on the target are required \u2014 the parse runs unconditionally in the RX softirq for any frame received once the interface is up, with no capability or authentication check anywhere on the usbnet_bh -\u003e rx_process -\u003e rx_fixup path.\nUI:N - No victim action is needed beyond the interface being in its normal operational state, which is inherent to a host-to-host link cable in use and is done automatically by NetworkManager/systemd-networkd.\nS:U - The over-read and the leaked memory stay within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Up to ~47 KB of adjacent kernel heap is read past the valid received data and delivered up the network stack as an Ethernet frame, exfiltrating arbitrary slab contents (prior packet data, keys, pointers) to the attacker and to any local packet capture \u2014 an unbounded, repeatable kernel memory disclosure.\nI:N - The defect is strictly a read; gl_skb is allocated with alloc_skb(size) before skb_put_data() copies exactly size bytes, so no kernel memory is written out of bounds or otherwise modified.\nA:H - With rx_urb_size reduced the read runs tens of kilobytes past a small slab object and can touch unmapped memory from softirq context, and on hardened kernels the KASAN slab-out-of-bounds report (as captured in the fix commit) panics the machine; the attacker can repeat it with every frame."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:16.687Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/255d03551f94c7bdd86c7d9181a70b21917d829f"
},
{
"url": "https://git.kernel.org/stable/c/4359376e6238d89977a35086e47ca3b07f43e850"
},
{
"url": "https://git.kernel.org/stable/c/8624e179fa3ce23c2fbd1a198ce30764b73f054a"
},
{
"url": "https://git.kernel.org/stable/c/573418f7ea8f859a841417eb4b915594094fd967"
},
{
"url": "https://git.kernel.org/stable/c/0575599e451aff3c5329922562374a2cab25fc51"
},
{
"url": "https://git.kernel.org/stable/c/0a7d9c7c5f1f208c523abbb4db6aea7bc1fad3db"
},
{
"url": "https://git.kernel.org/stable/c/3ef79fa3860e644c8de7834fa7300e1c58f38862"
},
{
"url": "https://git.kernel.org/stable/c/8ff7f2a6da4fccaa5cc9be7251a24e71e29fbd1a"
}
],
"title": "usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64540",
"datePublished": "2026-07-27T20:10:33.905Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:16.687Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43116 (GCVE-0-2026-43116)
Vulnerability from cvelistv5
Published
2026-05-06 07:40
Modified
2026-09-08 08:48
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ctnetlink: ensure safe access to master conntrack
Holding reference on the expectation is not sufficient, the master
conntrack object can just go away, making exp->master invalid.
To access exp->master safely:
- Grab the nf_conntrack_expect_lock, this gets serialized with
clean_from_lists() which also holds this lock when the master
conntrack goes away.
- Hold reference on master conntrack via nf_conntrack_find_get().
Not so easy since the master tuple to look up for the master conntrack
is not available in the existing problematic paths.
This patch goes for extending the nf_conntrack_expect_lock section
to address this issue for simplicity, in the cases that are described
below this is just slightly extending the lock section.
The add expectation command already holds a reference to the master
conntrack from ctnetlink_create_expect().
However, the delete expectation command needs to grab the spinlock
before looking up for the expectation. Expand the existing spinlock
section to address this to cover the expectation lookup. Note that,
the nf_ct_expect_iterate_net() calls already grabs the spinlock while
iterating over the expectation table, which is correct.
The get expectation command needs to grab the spinlock to ensure master
conntrack does not go away. This also expands the existing spinlock
section to cover the expectation lookup too. I needed to move the
netlink skb allocation out of the spinlock to keep it GFP_KERNEL.
For the expectation events, the IPEXP_DESTROY event is already delivered
under the spinlock, just move the delivery of IPEXP_NEW under the
spinlock too because the master conntrack event cache is reached through
exp->master.
While at it, add lockdep notations to help identify what codepaths need
to grab the spinlock.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c1d10adb4a521de5760112853f42aaeefcec96eb Version: c1d10adb4a521de5760112853f42aaeefcec96eb Version: c1d10adb4a521de5760112853f42aaeefcec96eb Version: c1d10adb4a521de5760112853f42aaeefcec96eb Version: c1d10adb4a521de5760112853f42aaeefcec96eb Version: c1d10adb4a521de5760112853f42aaeefcec96eb |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:48:49.019Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/netfilter/nf_conntrack_core.h",
"net/netfilter/nf_conntrack_ecache.c",
"net/netfilter/nf_conntrack_expect.c",
"net/netfilter/nf_conntrack_netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9e1196d27ef496f404c76f7a9d03761142d991c4",
"status": "affected",
"version": "c1d10adb4a521de5760112853f42aaeefcec96eb",
"versionType": "git"
},
{
"lessThan": "5e1c1d22268ae710c238342c8030c21daf298168",
"status": "affected",
"version": "c1d10adb4a521de5760112853f42aaeefcec96eb",
"versionType": "git"
},
{
"lessThan": "d52fa1fa7440676b8c238037a050ab008c22737f",
"status": "affected",
"version": "c1d10adb4a521de5760112853f42aaeefcec96eb",
"versionType": "git"
},
{
"lessThan": "f338ced0473849c9f6ed0b77ca99f1aab5826787",
"status": "affected",
"version": "c1d10adb4a521de5760112853f42aaeefcec96eb",
"versionType": "git"
},
{
"lessThan": "497f99b26fffdc5635706d1b4811f1ed8ee21a5b",
"status": "affected",
"version": "c1d10adb4a521de5760112853f42aaeefcec96eb",
"versionType": "git"
},
{
"lessThan": "bffcaad9afdfe45d7fc777397d3b83c1e3ebffe5",
"status": "affected",
"version": "c1d10adb4a521de5760112853f42aaeefcec96eb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/netfilter/nf_conntrack_core.h",
"net/netfilter/nf_conntrack_ecache.c",
"net/netfilter/nf_conntrack_expect.c",
"net/netfilter/nf_conntrack_netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.16"
},
{
"lessThan": "2.6.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.24",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.24",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.14",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "2.6.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: ensure safe access to master conntrack\n\nHolding reference on the expectation is not sufficient, the master\nconntrack object can just go away, making exp-\u003emaster invalid.\n\nTo access exp-\u003emaster safely:\n\n- Grab the nf_conntrack_expect_lock, this gets serialized with\n clean_from_lists() which also holds this lock when the master\n conntrack goes away.\n\n- Hold reference on master conntrack via nf_conntrack_find_get().\n Not so easy since the master tuple to look up for the master conntrack\n is not available in the existing problematic paths.\n\nThis patch goes for extending the nf_conntrack_expect_lock section\nto address this issue for simplicity, in the cases that are described\nbelow this is just slightly extending the lock section.\n\nThe add expectation command already holds a reference to the master\nconntrack from ctnetlink_create_expect().\n\nHowever, the delete expectation command needs to grab the spinlock\nbefore looking up for the expectation. Expand the existing spinlock\nsection to address this to cover the expectation lookup. Note that,\nthe nf_ct_expect_iterate_net() calls already grabs the spinlock while\niterating over the expectation table, which is correct.\n\nThe get expectation command needs to grab the spinlock to ensure master\nconntrack does not go away. This also expands the existing spinlock\nsection to cover the expectation lookup too. I needed to move the\nnetlink skb allocation out of the spinlock to keep it GFP_KERNEL.\n\nFor the expectation events, the IPEXP_DESTROY event is already delivered\nunder the spinlock, just move the delivery of IPEXP_NEW under the\nspinlock too because the master conntrack event cache is reached through\nexp-\u003emaster.\n\nWhile at it, add lockdep notations to help identify what codepaths need\nto grab the spinlock."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable ctnetlink expectation operations are reached through NETLINK_NETFILTER messages from local userspace, not directly by remote packets.\nAC:L - The race is between attacker-driven ctnetlink expectation lookup/dump/delete and attacker-driven master conntrack deletion or timeout, so the attacker can create and retry both sides.\nPR:L - nfnetlink requires CAP_NET_ADMIN in the target network namespace, and an unprivileged local user can reasonably obtain that via a user plus network namespace on affected deployments.\nUI:N - No victim action is required after the attacker can send the netlink requests.\nS:U - This is a kernel memory safety issue within the same host security authority and does not cross a VM, IOMMU, or similar scope boundary.\nC:H - The bug is a use-after-free of the master struct nf_conn reachable from a retained expectation, and kernel UAFs can be leveraged for disclosure of sensitive kernel memory.\nI:H - The stale master pointer is kernel heap memory corruption/use-after-free, which is defensibly exploitable for control-flow or data modification with heap grooming.\nA:H - Even without full exploitation, dereferencing the freed master conntrack can trigger a kernel oops or panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:26:02.836Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9e1196d27ef496f404c76f7a9d03761142d991c4"
},
{
"url": "https://git.kernel.org/stable/c/5e1c1d22268ae710c238342c8030c21daf298168"
},
{
"url": "https://git.kernel.org/stable/c/d52fa1fa7440676b8c238037a050ab008c22737f"
},
{
"url": "https://git.kernel.org/stable/c/f338ced0473849c9f6ed0b77ca99f1aab5826787"
},
{
"url": "https://git.kernel.org/stable/c/497f99b26fffdc5635706d1b4811f1ed8ee21a5b"
},
{
"url": "https://git.kernel.org/stable/c/bffcaad9afdfe45d7fc777397d3b83c1e3ebffe5"
}
],
"title": "netfilter: ctnetlink: ensure safe access to master conntrack",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43116",
"datePublished": "2026-05-06T07:40:41.185Z",
"dateReserved": "2026-05-01T14:12:55.986Z",
"dateUpdated": "2026-09-08T08:48:49.019Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68365 (GCVE-0-2026-68365)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: io_edgeport: cap received transmit credits
The interrupt-status packet reports transmit credits returned by the
device. edge_interrupt_callback() adds the 16-bit value to txCredits
without checking maxTxCredits.
edge_write() uses txCredits minus the software FIFO count as the amount
of data that fits. Since the FIFO is allocated with maxTxCredits bytes,
txCredits exceeding maxTxCredits can cause OOB write in ring buffer.
Cap accumulated credits at maxTxCredits. Conforming devices should never
hit the cap.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/io_edgeport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d9dd87bc1d7e8476d29d68883542ec6198d385c6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5b39d3da15344b87ef54a0a04f65b52622747e99",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "63c4e55d0741cfaf00515e807cad9293445cd348",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ee57992c053a6d395e98ced2d4c9cc3b42d8c27a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "64b687f9694777754285d489abbefa3784bc78da",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "cbe00048b69d67c8a78293cb7681b4c9963b26c7",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1e47d8228b8767c8ac722aedb388f70adeeda43d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "faaddd811c5099f11a5f52e68a6b31a5898cda4f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/io_edgeport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: io_edgeport: cap received transmit credits\n\nThe interrupt-status packet reports transmit credits returned by the\ndevice. edge_interrupt_callback() adds the 16-bit value to txCredits\nwithout checking maxTxCredits.\n\nedge_write() uses txCredits minus the software FIFO count as the amount\nof data that fits. Since the FIFO is allocated with maxTxCredits bytes,\ntxCredits exceeding maxTxCredits can cause OOB write in ring buffer.\n\nCap accumulated credits at maxTxCredits. Conforming devices should never\nhit the cap."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:21.018Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d9dd87bc1d7e8476d29d68883542ec6198d385c6"
},
{
"url": "https://git.kernel.org/stable/c/5b39d3da15344b87ef54a0a04f65b52622747e99"
},
{
"url": "https://git.kernel.org/stable/c/63c4e55d0741cfaf00515e807cad9293445cd348"
},
{
"url": "https://git.kernel.org/stable/c/ee57992c053a6d395e98ced2d4c9cc3b42d8c27a"
},
{
"url": "https://git.kernel.org/stable/c/64b687f9694777754285d489abbefa3784bc78da"
},
{
"url": "https://git.kernel.org/stable/c/cbe00048b69d67c8a78293cb7681b4c9963b26c7"
},
{
"url": "https://git.kernel.org/stable/c/1e47d8228b8767c8ac722aedb388f70adeeda43d"
},
{
"url": "https://git.kernel.org/stable/c/faaddd811c5099f11a5f52e68a6b31a5898cda4f"
}
],
"title": "USB: serial: io_edgeport: cap received transmit credits",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68365",
"datePublished": "2026-08-10T12:03:42.358Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:21.018Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68212 (GCVE-0-2026-68212)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: saa7134: Fix a possible memory leak in saa7134_video_init1
In saa7134_video_init1(), the return value of the first
saa7134_pgtable_alloc() is not checked. If it fails, the function
continues as if successful, leaving the driver with an invalid page
table. Additionally, if vb2_queue_init() for the VBI queue fails after
the video queue page table has been allocated, the allocated memory is
not freed before returning. The second saa7134_pgtable_alloc() also
lacks a return value check. Errors occur during device probing before
the device is fully registered, the normal cleanup path in
saa7134_finidev() is not executed, leading to memory leaks and
potential use of uninitialized DMA resources.
Check the return value of both saa7134_pgtable_alloc() calls and
propagate errors. On failure of any later step, free allocated page
tables to avoid memory leaks. Ensure control handlers are also
released on error to prevent further resource leakage.
Found by code review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/saa7134/saa7134-video.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e773b1d4bd191e7520bf9e02cb676d62c1b20556",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "44e16e3e022bf4a26adf03bc05a6dd5ffc34ef6d",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "34082a48376fd225a5c3d971c8962eb1320a54e0",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "134c979dd721e22f196d71026432ee37d1f5cc38",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "e1ef361ee31d1dba5dcae2cdd50f9c1352df0c23",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "b7936e8cbec1b96b126058eeb005e5b9111df38e",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "1731dd61b6c0b7435c139951d2b7eada6c9667a8",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "f86ed548386e3050e5f8f25b450d09dc009d9a88",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/saa7134/saa7134-video.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: saa7134: Fix a possible memory leak in saa7134_video_init1\n\nIn saa7134_video_init1(), the return value of the first\nsaa7134_pgtable_alloc() is not checked. If it fails, the function\ncontinues as if successful, leaving the driver with an invalid page\ntable. Additionally, if vb2_queue_init() for the VBI queue fails after\nthe video queue page table has been allocated, the allocated memory is\nnot freed before returning. The second saa7134_pgtable_alloc() also\nlacks a return value check. Errors occur during device probing before\nthe device is fully registered, the normal cleanup path in\nsaa7134_finidev() is not executed, leading to memory leaks and\npotential use of uninitialized DMA resources.\n\nCheck the return value of both saa7134_pgtable_alloc() calls and\npropagate errors. On failure of any later step, free allocated page\ntables to avoid memory leaks. Ensure control handlers are also\nreleased on error to prevent further resource leakage.\n\nFound by code review."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:37.074Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e773b1d4bd191e7520bf9e02cb676d62c1b20556"
},
{
"url": "https://git.kernel.org/stable/c/44e16e3e022bf4a26adf03bc05a6dd5ffc34ef6d"
},
{
"url": "https://git.kernel.org/stable/c/34082a48376fd225a5c3d971c8962eb1320a54e0"
},
{
"url": "https://git.kernel.org/stable/c/134c979dd721e22f196d71026432ee37d1f5cc38"
},
{
"url": "https://git.kernel.org/stable/c/e1ef361ee31d1dba5dcae2cdd50f9c1352df0c23"
},
{
"url": "https://git.kernel.org/stable/c/b7936e8cbec1b96b126058eeb005e5b9111df38e"
},
{
"url": "https://git.kernel.org/stable/c/1731dd61b6c0b7435c139951d2b7eada6c9667a8"
},
{
"url": "https://git.kernel.org/stable/c/f86ed548386e3050e5f8f25b450d09dc009d9a88"
}
],
"title": "media: saa7134: Fix a possible memory leak in saa7134_video_init1",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68212",
"datePublished": "2026-08-10T12:00:31.498Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:37.074Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68112 (GCVE-0-2026-68112)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit 5676593d08998d7a6d9e2d51d6b54b3820e3755c)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v9_4_3.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c59b57c2e0c8cced4350ff7792361ba2a79ee85c",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "cfb02825277526bd216b56be555a97a9e8612682",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "05aea3344c422fe95299bb1b21a04de30c7ea198",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "ac89ea915e8b848c7cbe97b1aad2dc4f5770c6d7",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "00f4050f7c367d7bdce347ca279ce467c434cf15",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v9_4_3.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit 5676593d08998d7a6d9e2d51d6b54b3820e3755c)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:36.971Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c59b57c2e0c8cced4350ff7792361ba2a79ee85c"
},
{
"url": "https://git.kernel.org/stable/c/cfb02825277526bd216b56be555a97a9e8612682"
},
{
"url": "https://git.kernel.org/stable/c/05aea3344c422fe95299bb1b21a04de30c7ea198"
},
{
"url": "https://git.kernel.org/stable/c/ac89ea915e8b848c7cbe97b1aad2dc4f5770c6d7"
},
{
"url": "https://git.kernel.org/stable/c/00f4050f7c367d7bdce347ca279ce467c434cf15"
}
],
"title": "drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68112",
"datePublished": "2026-08-10T11:58:29.670Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-18T06:55:36.971Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68213 (GCVE-0-2026-68213)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: rtl2832_sdr: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
rtl2832_sdr_start_streaming() had multiple error paths that hit this
trap: two direct early returns (-ENODEV, -ERESTARTSYS), plus six
`goto err` paths covering subdev s_power, tuner setup, ADC setup,
stream-buffer allocation, urb allocation, and urb submission failures.
None of them returned the queued buffers.
The original function had no distinct success exit and fell straight
through into the err label, which previously only did mutex_unlock and
"return ret". Adding queued-buffer cleanup at err must therefore be
paired with an explicit success return; otherwise every successful
start would also drain the buffer queue and kill streaming. Add that
success return, then add rtl2832_sdr_cleanup_queued_bufs() at the err
label and before each early return.
The cleanup helper takes a vb2_buffer_state argument so that the
start_streaming error paths can pass VB2_BUF_STATE_QUEUED (as
expected by userspace on start_streaming failure) while stop_streaming
keeps its existing VB2_BUF_STATE_ERROR semantics.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
The err label still does not roll back power_ctrl(), frontend_ctrl(),
the POWER_ON flag, or stream/URB allocations that may have happened
before the failing step. Those are pre-existing leaks of a different
class and are not addressed here.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832_sdr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fd1e11fc3849169285e48b2d4ec441614ad2ea74",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "772f2550fe32357557d3b2f88e02f7cf477f0789",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "a248273f8af6e630a03e823274385725974009b5",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "465dc8e71d2db2ed603e749fa71392bcdccf07eb",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "0b08c0403cf672a121ace4eff647a9b240bd4e1b",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "894e83509c66910112b9eaeaa8cd66cd9806db91",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "fc0b18782aab4e35078efe72863df8eab46560a8",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "33ca0aab6f4bd90921fc1395478f38f72c4d19af",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832_sdr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.15"
},
{
"lessThan": "3.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rtl2832_sdr: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nrtl2832_sdr_start_streaming() had multiple error paths that hit this\ntrap: two direct early returns (-ENODEV, -ERESTARTSYS), plus six\n`goto err` paths covering subdev s_power, tuner setup, ADC setup,\nstream-buffer allocation, urb allocation, and urb submission failures.\nNone of them returned the queued buffers.\n\nThe original function had no distinct success exit and fell straight\nthrough into the err label, which previously only did mutex_unlock and\n\"return ret\". Adding queued-buffer cleanup at err must therefore be\npaired with an explicit success return; otherwise every successful\nstart would also drain the buffer queue and kill streaming. Add that\nsuccess return, then add rtl2832_sdr_cleanup_queued_bufs() at the err\nlabel and before each early return.\n\nThe cleanup helper takes a vb2_buffer_state argument so that the\nstart_streaming error paths can pass VB2_BUF_STATE_QUEUED (as\nexpected by userspace on start_streaming failure) while stop_streaming\nkeeps its existing VB2_BUF_STATE_ERROR semantics.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\").\n\nThe err label still does not roll back power_ctrl(), frontend_ctrl(),\nthe POWER_ON flag, or stream/URB allocations that may have happened\nbefore the failing step. Those are pre-existing leaks of a different\nclass and are not addressed here."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered entirely through ioctls on the V4L2 SDR device node /dev/swradio0 (VIDIOC_REQBUFS/QBUF/STREAMON); no network or physical interaction is required, since the failure path is reached via lock contention and signal delivery from local threads.\nAC:L - The attacker controls both sides: one thread holds dev-\u003ev4l2_lock via slow USB-backed ioctls while another calls STREAMON and a third signals it, forcing the -ERESTARTSYS path deterministically and retryably; no condition lies outside attacker influence.\nPR:L - Requires only an unprivileged local account with access to the SDR video node, which is customarily group-video readable/writable on desktop, embedded and Android-style deployments; no CAP_SYS_ADMIN or root is needed.\nUI:N - The full sequence (REQBUFS, QBUF, STREAMON, close, reopen) is performed by the attacker\u0027s own process; no victim action or cooperation is involved at any point.\nS:U - The corruption is confined to kernel heap objects owned by the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - The stale dev-\u003equeued_bufs entries point at freed vb2 buffer objects that the attacker can reclaim via heap spraying, and the URB completion handler dereferences them, yielding a use-after-free read primitive over kernel memory.\nI:H - A later buf_queue() performs list_add_tail() through the dangling list head, writing kernel pointers into freed, attacker-reclaimed memory, and vb2_buffer_done() operates on a forged buffer \u2014 a classic UAF write primitive usable for control-flow hijack.\nA:H - The immediate effect is WARN_ON(owned_by_drv_count) in vb2_start_streaming() (a panic under panic_on_warn) plus list corruption; the resulting use-after-free reliably oopses the kernel and can be repeated at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:39.730Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fd1e11fc3849169285e48b2d4ec441614ad2ea74"
},
{
"url": "https://git.kernel.org/stable/c/772f2550fe32357557d3b2f88e02f7cf477f0789"
},
{
"url": "https://git.kernel.org/stable/c/a248273f8af6e630a03e823274385725974009b5"
},
{
"url": "https://git.kernel.org/stable/c/465dc8e71d2db2ed603e749fa71392bcdccf07eb"
},
{
"url": "https://git.kernel.org/stable/c/0b08c0403cf672a121ace4eff647a9b240bd4e1b"
},
{
"url": "https://git.kernel.org/stable/c/894e83509c66910112b9eaeaa8cd66cd9806db91"
},
{
"url": "https://git.kernel.org/stable/c/fc0b18782aab4e35078efe72863df8eab46560a8"
},
{
"url": "https://git.kernel.org/stable/c/33ca0aab6f4bd90921fc1395478f38f72c4d19af"
}
],
"title": "media: rtl2832_sdr: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68213",
"datePublished": "2026-08-10T12:00:32.514Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:39.730Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64450 (GCVE-0-2026-64450)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix out-of-bounds read in broadcast Gap ACK blocks
A broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its
data area. tipc_get_gap_ack_blks() only verifies that the record's len
field is self-consistent with its ugack_cnt/bgack_cnt counts
(sz == struct_size(p, gacks, ugack_cnt + bgack_cnt)); it does not check
that the record actually fits in the message data area, msg_data_sz().
The unicast caller tipc_link_proto_rcv() bounds it ("if (glen > dlen)
break;"), but the broadcast caller tipc_bcast_sync_rcv() discards the
returned size, so tipc_link_advance_transmq() copies the record off the
receive skb with an attacker-controlled count:
this_ga = kmemdup(ga, struct_size(ga, gacks, ga->bgack_cnt),
GFP_ATOMIC);
A TIPC neighbour that negotiated TIPC_GAP_ACK_BLOCK triggers it with one
ordinary broadcast STATE_MSG (msg_bc_ack_invalid() clear), sized so its
data area is short, carrying a Gap ACK record with len = 0x400,
bgack_cnt = 0xff and ugack_cnt = 0. len then equals
struct_size(p, gacks, 255), so the consistency check passes and ga is
non-NULL; kmemdup() reads struct_size(ga, gacks, 255) = 1024 bytes out
of the much smaller skb:
BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x48/0x60
Read of size 1024 at addr ffff0000c7030d38 by task poc864/69
Call trace:
kmemdup_noprof+0x48/0x60
tipc_link_advance_transmq+0x86c/0xb80
tipc_link_bc_ack_rcv+0x19c/0x1e0
tipc_bcast_sync_rcv+0x1c4/0x2c4
tipc_rcv+0x85c/0x1340
tipc_l2_rcv_msg+0xac/0x104
The buggy address belongs to the object at ffff0000c7030d00
which belongs to the cache skbuff_small_head of size 704
The buggy address is located 56 bytes inside of
allocated 704-byte region [ffff0000c7030d00, ffff0000c7030fc0)
The copied-out bytes are subsequently consumed as gap/ack values, but
the read is already out of bounds at the kmemdup() regardless of how
they are used.
The unicast STATE path drops such a message: "if (glen > dlen) break;"
skips the rest of STATE_MSG handling and the skb is freed. Make the
broadcast path drop it too. tipc_bcast_sync_rcv() now bounds the record
against msg_data_sz() and, when it does not fit, reports it back through
tipc_node_bc_sync_rcv() to tipc_rcv() so the skb is discarded rather than
processed. ga is not cleared on this path: ga == NULL already means
"legacy peer without Selective ACK", a distinct legitimate state.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d7626b5acff9227e2a65da636a53e09bdafdc0aa Version: d7626b5acff9227e2a65da636a53e09bdafdc0aa Version: d7626b5acff9227e2a65da636a53e09bdafdc0aa Version: d7626b5acff9227e2a65da636a53e09bdafdc0aa Version: d7626b5acff9227e2a65da636a53e09bdafdc0aa Version: d7626b5acff9227e2a65da636a53e09bdafdc0aa Version: d7626b5acff9227e2a65da636a53e09bdafdc0aa Version: d7626b5acff9227e2a65da636a53e09bdafdc0aa |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/bcast.c",
"net/tipc/bcast.h",
"net/tipc/node.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "055663d21dc4336f67933ab26bef3c5934be6324",
"status": "affected",
"version": "d7626b5acff9227e2a65da636a53e09bdafdc0aa",
"versionType": "git"
},
{
"lessThan": "016f5995c37a5a2c45198308f830f244517d70b7",
"status": "affected",
"version": "d7626b5acff9227e2a65da636a53e09bdafdc0aa",
"versionType": "git"
},
{
"lessThan": "74b45af86a767594ba52330cd440ea84e24d700d",
"status": "affected",
"version": "d7626b5acff9227e2a65da636a53e09bdafdc0aa",
"versionType": "git"
},
{
"lessThan": "9a51115fcdc78687c8852bf93a1db3951dbb223b",
"status": "affected",
"version": "d7626b5acff9227e2a65da636a53e09bdafdc0aa",
"versionType": "git"
},
{
"lessThan": "a21ed5064217cc33726da6c7ef1a520eba43aea1",
"status": "affected",
"version": "d7626b5acff9227e2a65da636a53e09bdafdc0aa",
"versionType": "git"
},
{
"lessThan": "2de42e268174766cb2e2b90721afdfdff70e0d8d",
"status": "affected",
"version": "d7626b5acff9227e2a65da636a53e09bdafdc0aa",
"versionType": "git"
},
{
"lessThan": "f333b6851bdf326fd2134133272dbbed0c94d921",
"status": "affected",
"version": "d7626b5acff9227e2a65da636a53e09bdafdc0aa",
"versionType": "git"
},
{
"lessThan": "2b66974a1b6134a4bbc3bfed181f7418f688eb54",
"status": "affected",
"version": "d7626b5acff9227e2a65da636a53e09bdafdc0aa",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/bcast.c",
"net/tipc/bcast.h",
"net/tipc/node.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix out-of-bounds read in broadcast Gap ACK blocks\n\nA broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its\ndata area. tipc_get_gap_ack_blks() only verifies that the record\u0027s len\nfield is self-consistent with its ugack_cnt/bgack_cnt counts\n(sz == struct_size(p, gacks, ugack_cnt + bgack_cnt)); it does not check\nthat the record actually fits in the message data area, msg_data_sz().\n\nThe unicast caller tipc_link_proto_rcv() bounds it (\"if (glen \u003e dlen)\nbreak;\"), but the broadcast caller tipc_bcast_sync_rcv() discards the\nreturned size, so tipc_link_advance_transmq() copies the record off the\nreceive skb with an attacker-controlled count:\n\n\tthis_ga = kmemdup(ga, struct_size(ga, gacks, ga-\u003ebgack_cnt),\n\t\t\t GFP_ATOMIC);\n\nA TIPC neighbour that negotiated TIPC_GAP_ACK_BLOCK triggers it with one\nordinary broadcast STATE_MSG (msg_bc_ack_invalid() clear), sized so its\ndata area is short, carrying a Gap ACK record with len = 0x400,\nbgack_cnt = 0xff and ugack_cnt = 0. len then equals\nstruct_size(p, gacks, 255), so the consistency check passes and ga is\nnon-NULL; kmemdup() reads struct_size(ga, gacks, 255) = 1024 bytes out\nof the much smaller skb:\n\n BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x48/0x60\n Read of size 1024 at addr ffff0000c7030d38 by task poc864/69\n Call trace:\n kmemdup_noprof+0x48/0x60\n tipc_link_advance_transmq+0x86c/0xb80\n tipc_link_bc_ack_rcv+0x19c/0x1e0\n tipc_bcast_sync_rcv+0x1c4/0x2c4\n tipc_rcv+0x85c/0x1340\n tipc_l2_rcv_msg+0xac/0x104\n The buggy address belongs to the object at ffff0000c7030d00\n which belongs to the cache skbuff_small_head of size 704\n The buggy address is located 56 bytes inside of\n allocated 704-byte region [ffff0000c7030d00, ffff0000c7030fc0)\n\nThe copied-out bytes are subsequently consumed as gap/ack values, but\nthe read is already out of bounds at the kmemdup() regardless of how\nthey are used.\n\nThe unicast STATE path drops such a message: \"if (glen \u003e dlen) break;\"\nskips the rest of STATE_MSG handling and the skb is freed. Make the\nbroadcast path drop it too. tipc_bcast_sync_rcv() now bounds the record\nagainst msg_data_sz() and, when it does not fit, reports it back through\ntipc_node_bc_sync_rcv() to tipc_rcv() so the skb is discarded rather than\nprocessed. ga is not cleared on this path: ga == NULL already means\n\"legacy peer without Selective ACK\", a distinct legitimate state."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - TIPC packets can arrive through an IP/UDP bearer from a routable remote source, and the receive callback does not restrict packets to configured remote addresses. An attacker can also establish or spoof the required TIPC neighbour state without credentials.\nAC:L - The attacker controls capability advertisement, link establishment, broadcast synchronization, and the malformed STATE message; one packet then reliably performs the out-of-bounds copy without a race or uncontrollable condition.\nPR:N - The packet-receive path performs no capability or user-credential check, and TIPC discovery and link negotiation are unauthenticated when optional cryptographic keys are not configured. The vulnerable broadcast processing also precedes normal STATE-session validation.\nUI:N - No victim action is required after the TIPC bearer is active; receipt of the crafted STATE message directly invokes the vulnerable code.\nS:U - The vulnerability compromises availability and potentially confidentiality within the receiving kernel\u0027s existing security authority, without crossing a VM, IOMMU, or comparable scope boundary.\nC:H - The attacker-controlled count makes the kernel copy up to 1,024 bytes from a much smaller skb, incorporating substantial adjacent slab contents rather than a strictly bounded few-byte read.\nI:N - The defect performs an out-of-bounds read into a correctly sized new allocation; investigation found no out-of-bounds write, arbitrary-write primitive, or control-flow corruption.\nA:H - The demonstrated 1,024-byte slab-out-of-bounds access produces a KASAN BUG and can panic or fault hardened kernels, and an unauthenticated attacker can trigger it repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:54.043Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/055663d21dc4336f67933ab26bef3c5934be6324"
},
{
"url": "https://git.kernel.org/stable/c/016f5995c37a5a2c45198308f830f244517d70b7"
},
{
"url": "https://git.kernel.org/stable/c/74b45af86a767594ba52330cd440ea84e24d700d"
},
{
"url": "https://git.kernel.org/stable/c/9a51115fcdc78687c8852bf93a1db3951dbb223b"
},
{
"url": "https://git.kernel.org/stable/c/a21ed5064217cc33726da6c7ef1a520eba43aea1"
},
{
"url": "https://git.kernel.org/stable/c/2de42e268174766cb2e2b90721afdfdff70e0d8d"
},
{
"url": "https://git.kernel.org/stable/c/f333b6851bdf326fd2134133272dbbed0c94d921"
},
{
"url": "https://git.kernel.org/stable/c/2b66974a1b6134a4bbc3bfed181f7418f688eb54"
}
],
"title": "tipc: fix out-of-bounds read in broadcast Gap ACK blocks",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64450",
"datePublished": "2026-07-25T08:51:20.319Z",
"dateReserved": "2026-07-19T15:36:31.788Z",
"dateUpdated": "2026-08-17T04:55:54.043Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68410 (GCVE-0-2026-68410)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: libertas: fix memory leak in helper_firmware_cb()
helper_firmware_cb() neglects to free the single-stage firmware image
after a successful async load, leading to a memory leak in the USB
firmware-download path.
Fix this memory leak by calling release_firmware() immediately after
lbs_fw_loaded() returns.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still present in
the current wireless tree.
An x86_64 allyesconfig build showed no new warnings. As we do not have
compatible Libertas USB hardware for exercising this firmware-download
path, no runtime testing was able to be performed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/libertas/firmware.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6c1f54a04813676c5a2150d99331c8d21f199374",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "7f28722b3e4e0c8d49c859fea4a9b1fa13b5ae06",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "ce829286f4935f1eb6b5dcb64da02910ce149c76",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "d497b7566e74920acfe283dd6b2cbf1682890796",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "eaeb1d74a47fc4864f2c754c0b9d654a9b7dc55c",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "6cda91bbb8dc3d22ef0323008a12dcf73a5129da",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "644640cde2fb216e6567de5eee780a38dbc95928",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "63c2391deefb31e1b801b7f32bd502ca4808639b",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/libertas/firmware.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.13"
},
{
"lessThan": "3.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas: fix memory leak in helper_firmware_cb()\n\nhelper_firmware_cb() neglects to free the single-stage firmware image\nafter a successful async load, leading to a memory leak in the USB\nfirmware-download path.\n\nFix this memory leak by calling release_firmware() immediately after\nlbs_fw_loaded() returns.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still present in\nthe current wireless tree.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have\ncompatible Libertas USB hardware for exercising this firmware-download\npath, no runtime testing was able to be performed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:04.634Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6c1f54a04813676c5a2150d99331c8d21f199374"
},
{
"url": "https://git.kernel.org/stable/c/7f28722b3e4e0c8d49c859fea4a9b1fa13b5ae06"
},
{
"url": "https://git.kernel.org/stable/c/ce829286f4935f1eb6b5dcb64da02910ce149c76"
},
{
"url": "https://git.kernel.org/stable/c/d497b7566e74920acfe283dd6b2cbf1682890796"
},
{
"url": "https://git.kernel.org/stable/c/eaeb1d74a47fc4864f2c754c0b9d654a9b7dc55c"
},
{
"url": "https://git.kernel.org/stable/c/6cda91bbb8dc3d22ef0323008a12dcf73a5129da"
},
{
"url": "https://git.kernel.org/stable/c/644640cde2fb216e6567de5eee780a38dbc95928"
},
{
"url": "https://git.kernel.org/stable/c/63c2391deefb31e1b801b7f32bd502ca4808639b"
}
],
"title": "wifi: libertas: fix memory leak in helper_firmware_cb()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68410",
"datePublished": "2026-08-10T12:04:30.194Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:35:04.634Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68286 (GCVE-0-2026-68286)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drop_monitor: perform u64_stats updates under IRQ-disabled section
In net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(),
u64_stats_update_begin() / u64_stats_inc() / u64_stats_update_end() were
called after spin_unlock_irqrestore(&...drop_queue.lock, flags), when local
IRQs had already been re-enabled.
Tracepoint probes can execute in IRQ or softirq context. On 32-bit
architectures, u64_stats_update_begin() disables preemption but not interrupts,
relying on seqcount writes. If a nested interrupt occurs on the same CPU during
the 64-bit stats update, the reentrant seqcount update can corrupt the
seqcount state or stats value.
Fix this by performing the 64-bit per-CPU stats update before releasing
drop_queue.lock via spin_unlock_irqrestore(), ensuring local interrupts remain
disabled during the u64_stats update.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/drop_monitor.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d5e2cd2bc8ae36617346b3a54ee9da61d866bf92",
"status": "affected",
"version": "e9feb58020f952f7d9de785ede9a7d54ab1eda5c",
"versionType": "git"
},
{
"lessThan": "fd098a23bf8fda7eae48db9b06e7c34fc4d228fa",
"status": "affected",
"version": "e9feb58020f952f7d9de785ede9a7d54ab1eda5c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/drop_monitor.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrop_monitor: perform u64_stats updates under IRQ-disabled section\n\nIn net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(),\nu64_stats_update_begin() / u64_stats_inc() / u64_stats_update_end() were\ncalled after spin_unlock_irqrestore(\u0026...drop_queue.lock, flags), when local\nIRQs had already been re-enabled.\n\nTracepoint probes can execute in IRQ or softirq context. On 32-bit\narchitectures, u64_stats_update_begin() disables preemption but not interrupts,\nrelying on seqcount writes. If a nested interrupt occurs on the same CPU during\nthe 64-bit stats update, the reentrant seqcount update can corrupt the\nseqcount state or stats value.\n\nFix this by performing the 64-bit per-CPU stats update before releasing\ndrop_queue.lock via spin_unlock_irqrestore(), ensuring local interrupts remain\ndisabled during the u64_stats update."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:21.413Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d5e2cd2bc8ae36617346b3a54ee9da61d866bf92"
},
{
"url": "https://git.kernel.org/stable/c/fd098a23bf8fda7eae48db9b06e7c34fc4d228fa"
}
],
"title": "drop_monitor: perform u64_stats updates under IRQ-disabled section",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68286",
"datePublished": "2026-08-10T12:02:19.077Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-17T05:02:21.413Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52923 (GCVE-0-2026-52923)
Vulnerability from cvelistv5
Published
2026-06-24 07:14
Modified
2026-09-04 12:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipc: limit next_id allocation to the valid ID range
The checkpoint/restore sysctl path can request the next SysV IPC id
through ids->next_id. ipc_idr_alloc() currently forwards that request to
idr_alloc() with an open-ended upper bound.
If the valid tail of the SysV IPC id space is full, the allocation can
spill beyond ipc_mni. The returned SysV IPC id still uses the normal
index encoding, so later lookup and removal can target the wrong slot.
This leaves the real IDR entry behind and breaks the IDR state for the
object.
The bug is in ipc_idr_alloc() in the checkpoint/restore path.
1. ids->next_id is passed to:
idr_alloc(&ids->ipcs_idr, new, ipcid_to_idx(next_id), 0, ...)
2. The zero upper bound makes the allocation effectively open-ended.
Once the valid SysV IPC tail is occupied, idr_alloc() can spill past
ipc_mni and allocate an entry beyond the valid IPC id range.
3. The new object id is still encoded with the narrower SysV IPC index
width:
new->id = (new->seq << ipcmni_seq_shift()) + idx
4. Later removal goes through ipc_rmid(), which uses:
ipcid_to_idx(ipcp->id)
That truncates the real IDR index. An object actually stored at a
high index can then be removed as if it lived at a low in-range
index.
5. For shared memory, shm_destroy() frees the current object anyway, but
the real high IDR slot is left behind as a dangling pointer.
6. A subsequent walk of /proc/sysvipc/shm reaches the stale IDR entry
and dereferences freed memory.
Prevent this by bounding the requested allocation to ipc_mni so the
checkpoint/restore path fails once the valid range is exhausted.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 03f595668017f1a1fb971c02fc37140bc6e7bb1c Version: 03f595668017f1a1fb971c02fc37140bc6e7bb1c Version: 03f595668017f1a1fb971c02fc37140bc6e7bb1c Version: 03f595668017f1a1fb971c02fc37140bc6e7bb1c Version: 03f595668017f1a1fb971c02fc37140bc6e7bb1c Version: 03f595668017f1a1fb971c02fc37140bc6e7bb1c Version: 03f595668017f1a1fb971c02fc37140bc6e7bb1c Version: 03f595668017f1a1fb971c02fc37140bc6e7bb1c |
||
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10.2"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:6.12.0-211.46.1.el10_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux_eus:10.0"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:6.12.0-55.95.1.el10_0",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_extras_rt_els:7"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:3.10.0-1160.159.1.rt56.1311.el7",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_els:7"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:3.10.0-1160.159.1.el7",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:8::nfv"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.151.1.rt7.492.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.151.1.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_aus:8.4"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-305.200.1.el8_4",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_eus_long_life:8.4"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-305.200.1.el8_4",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_tus:8.8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-477.158.1.el8_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_e4s:8.8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-477.158.1.el8_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:9",
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-687.33.1.el9_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_e4s:9.2"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-284.186.1.el9_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_e4s:9.2::nfv"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-284.186.1.rt14.471.el9_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_e4s:9.4"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-427.141.1.el9_4",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_eus:9.6"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.6 Extended Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-570.131.1.el9_6",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unknown",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-06-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel. The `ipc_idr_alloc()` function, used in the checkpoint/restore path for SysV Inter-Process Communication (IPC) ID allocation, does not properly limit ID allocation to the valid range. This can result in the system attempting to dereference freed memory, leading to a use-after-free vulnerability. This issue could potentially cause system instability or information disclosure."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Important"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-825",
"description": "Expired Pointer Dereference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T12:04:44.570Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-52923"
},
{
"name": "RHBZ#2492094",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492094"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52923.json"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:61692"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:63189"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:52764"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:53330"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:51603"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:48386"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:49031"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:49212"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:49857"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:47248"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:52649"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:49851"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:51604"
}
],
"solutions": [
{
"lang": "en",
"value": "RHSA-2026:61692: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS)"
},
{
"lang": "en",
"value": "RHSA-2026:63189: Red Hat Enterprise Linux for Real Time (v. 7 ELS)"
},
{
"lang": "en",
"value": "RHSA-2026:52764: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0), Red Hat Enterprise Linux Real Time EUS (v. 10.0), Red Hat Enterprise Linux Real Time for NFV EUS (v. 10.0)"
},
{
"lang": "en",
"value": "RHSA-2026:53330: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10)"
},
{
"lang": "en",
"value": "RHSA-2026:51603: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2)"
},
{
"lang": "en",
"value": "RHSA-2026:48386: Red Hat Enterprise Linux AppStream E4S (v.9.4), Red Hat Enterprise Linux BaseOS E4S (v.9.4), Red Hat Enterprise Linux Real Time E4S (v.9.4), Red Hat Enterprise Linux Real Time for NFV E4S (v.9.4)"
},
{
"lang": "en",
"value": "RHSA-2026:49031: Red Hat CodeReady Linux Builder EUS (v.9.6), Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux BaseOS EUS (v.9.6), Red Hat Enterprise Linux Real Time EUS (v.9.6), Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6)"
},
{
"lang": "en",
"value": "RHSA-2026:49212: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9)"
},
{
"lang": "en",
"value": "RHSA-2026:49857: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:47248: Red Hat Enterprise Linux BaseOS AUS (v.8.4), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)"
},
{
"lang": "en",
"value": "RHSA-2026:52649: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8)"
},
{
"lang": "en",
"value": "RHSA-2026:49851: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:51604: Red Hat Enterprise Linux Real Time E4S (v.9.2), Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: ipc: limit next_id allocation to the valid ID range",
"workarounds": [
{
"lang": "en",
"value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."
}
],
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"ipc/util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3bbe2bb9111ce6967a951bfac79af142d816fae5",
"status": "affected",
"version": "03f595668017f1a1fb971c02fc37140bc6e7bb1c",
"versionType": "git"
},
{
"lessThan": "8c58a92849175f5e2ab7bc2734b3b89afe79f6ef",
"status": "affected",
"version": "03f595668017f1a1fb971c02fc37140bc6e7bb1c",
"versionType": "git"
},
{
"lessThan": "af24e202b543ded8a34f1d5d3db54eb916173f04",
"status": "affected",
"version": "03f595668017f1a1fb971c02fc37140bc6e7bb1c",
"versionType": "git"
},
{
"lessThan": "157ce2c6836ce0ff19108a819f38df061345425f",
"status": "affected",
"version": "03f595668017f1a1fb971c02fc37140bc6e7bb1c",
"versionType": "git"
},
{
"lessThan": "41058d4c3f63ab64901560a704882e0565f4e456",
"status": "affected",
"version": "03f595668017f1a1fb971c02fc37140bc6e7bb1c",
"versionType": "git"
},
{
"lessThan": "a3cc795129e5ec0f8948653a3bf471e7d8852f5e",
"status": "affected",
"version": "03f595668017f1a1fb971c02fc37140bc6e7bb1c",
"versionType": "git"
},
{
"lessThan": "bd4be70669af55b974860d13680348cfdf50bbed",
"status": "affected",
"version": "03f595668017f1a1fb971c02fc37140bc6e7bb1c",
"versionType": "git"
},
{
"lessThan": "fa0b9b2b7ae3539908d69c2b9ac0d144d9bc5139",
"status": "affected",
"version": "03f595668017f1a1fb971c02fc37140bc6e7bb1c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"ipc/util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"lessThan": "3.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipc: limit next_id allocation to the valid ID range\n\nThe checkpoint/restore sysctl path can request the next SysV IPC id\nthrough ids-\u003enext_id. ipc_idr_alloc() currently forwards that request to\nidr_alloc() with an open-ended upper bound.\n\nIf the valid tail of the SysV IPC id space is full, the allocation can\nspill beyond ipc_mni. The returned SysV IPC id still uses the normal\nindex encoding, so later lookup and removal can target the wrong slot. \nThis leaves the real IDR entry behind and breaks the IDR state for the\nobject.\n\nThe bug is in ipc_idr_alloc() in the checkpoint/restore path.\n\n1. ids-\u003enext_id is passed to:\n\n idr_alloc(\u0026ids-\u003eipcs_idr, new, ipcid_to_idx(next_id), 0, ...)\n\n2. The zero upper bound makes the allocation effectively open-ended.\n Once the valid SysV IPC tail is occupied, idr_alloc() can spill past\n ipc_mni and allocate an entry beyond the valid IPC id range.\n\n3. The new object id is still encoded with the narrower SysV IPC index\n width:\n\n new-\u003eid = (new-\u003eseq \u003c\u003c ipcmni_seq_shift()) + idx\n\n4. Later removal goes through ipc_rmid(), which uses:\n\n ipcid_to_idx(ipcp-\u003eid)\n\n That truncates the real IDR index. An object actually stored at a\n high index can then be removed as if it lived at a low in-range\n index.\n\n5. For shared memory, shm_destroy() frees the current object anyway, but\n the real high IDR slot is left behind as a dangling pointer.\n\n6. A subsequent walk of /proc/sysvipc/shm reaches the stale IDR entry\n and dereferences freed memory.\n\nPrevent this by bounding the requested allocation to ipc_mni so the\ncheckpoint/restore path fails once the valid range is exhausted."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached through local SysV IPC syscalls plus writes to `/proc/sys/kernel/*_next_id`, not through network or physical input.\nAC:L - The attacker controls the sysctl value, IPC allocation pattern, removal, and proc/syscall enumeration needed to trigger the stale IDR pointer; filling the valid ID tail is resource-intensive but deterministic.\nPR:L - A basic local user can reasonably reach this via unprivileged user namespaces by creating a user/IPC namespace and gaining the namespace capabilities needed for the checkpoint/restore sysctls.\nUI:N - No victim action is required after the local attacker runs the sysctl and SysV IPC operations.\nS:U - This is a standard kernel memory corruption/local privilege escalation class issue within the same kernel security authority.\nC:H - The bug leaves a freed SysV IPC object reachable through the IDR, producing a kernel use-after-free; UAFs are scored as high confidentiality impact because reclaimed kernel heap contents can be exposed or used for read primitives.\nI:H - The stale pointer/use-after-free can plausibly be exploited through heap reuse for kernel memory corruption and control-flow or object manipulation, so integrity impact is high.\nA:H - Even without full exploitation, walking `/proc/sysvipc/shm` or related enumeration can dereference freed memory and crash or hang the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:31:44.559Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3bbe2bb9111ce6967a951bfac79af142d816fae5"
},
{
"url": "https://git.kernel.org/stable/c/8c58a92849175f5e2ab7bc2734b3b89afe79f6ef"
},
{
"url": "https://git.kernel.org/stable/c/af24e202b543ded8a34f1d5d3db54eb916173f04"
},
{
"url": "https://git.kernel.org/stable/c/157ce2c6836ce0ff19108a819f38df061345425f"
},
{
"url": "https://git.kernel.org/stable/c/41058d4c3f63ab64901560a704882e0565f4e456"
},
{
"url": "https://git.kernel.org/stable/c/a3cc795129e5ec0f8948653a3bf471e7d8852f5e"
},
{
"url": "https://git.kernel.org/stable/c/bd4be70669af55b974860d13680348cfdf50bbed"
},
{
"url": "https://git.kernel.org/stable/c/fa0b9b2b7ae3539908d69c2b9ac0d144d9bc5139"
}
],
"title": "ipc: limit next_id allocation to the valid ID range",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52923",
"datePublished": "2026-06-24T07:14:17.849Z",
"dateReserved": "2026-06-09T07:44:35.367Z",
"dateUpdated": "2026-09-04T12:04:44.570Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68373 (GCVE-0-2026-68373)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
at76_guess_freq() checks only that the received frame is at least a bare
802.11 header (24 bytes) before subtracting the fixed management-body
offset:
len -= el_off;
For both beacon and probe response frames, el_off is 36. If the frame is
shorter than el_off, subtracting it causes the calculated IE length to
wrap. The length is eventually passed to cfg80211_find_elem_match() as a
very large unsigned value, so the element walk runs beyond the RX skb.
This path is reached from at76_rx_tasklet() while scanning. If the device
delivers a truncated beacon or probe response, the oversized IE length
causes an out-of-bounds read during scanning.
Skip the IE lookup if the frame does not reach the variable elements,
before subtracting el_off.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/atmel/at76c50x-usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cb831aff2f850f72bc5ff5ad77d0a70bb5a84061",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "4875680d1703f56afa6257ba30244f2fb44ed205",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "b406f33d234f98c8b310fdab5cbb492d85e98e49",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "e165a1d295e7e814e13b0f92c86e5d48309509ce",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "bcde7249d45f52f994a9872bedf45994472ade77",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "fb1b50ab699211e777dca5ccfb648788b6a6e519",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "f742d9c98b5c504fc9e6744eef13a721c2aea486",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "61a799ffd1e5a4fd3702d547828b7ff3d161468e",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/atmel/at76c50x-usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.30"
},
{
"lessThan": "2.6.30",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.30",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: at76c50x-usb: avoid length underflow in at76_guess_freq()\n\nat76_guess_freq() checks only that the received frame is at least a bare\n802.11 header (24 bytes) before subtracting the fixed management-body\noffset:\n\n\tlen -= el_off;\n\nFor both beacon and probe response frames, el_off is 36. If the frame is\nshorter than el_off, subtracting it causes the calculated IE length to\nwrap. The length is eventually passed to cfg80211_find_elem_match() as a\nvery large unsigned value, so the element walk runs beyond the RX skb.\n\nThis path is reached from at76_rx_tasklet() while scanning. If the device\ndelivers a truncated beacon or probe response, the oversized IE length\ncauses an out-of-bounds read during scanning.\n\nSkip the IE lookup if the frame does not reach the variable elements,\nbefore subtracting el_off."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The malformed frame is an over-the-air 802.11 beacon or probe response received by the at76c50x USB WLAN dongle and parsed in at76_rx_tasklet(); an attacker only needs to be within radio range of the victim, which is the adjacent-network (WiFi frame injection) case.\nAC:L - The attacker simply transmits a beacon/probe response whose body is shorter than the 36-byte fixed management offset with a valid FCS, and can repeat it continuously or answer the victim\u0027s probe requests during the routine scans that set priv-\u003escanning, so triggering is reliable and fully attacker-timed.\nPR:N - No authentication, association, or any local privilege is required; the frame is parsed during scanning before any association or key exchange, so an entirely unauthenticated radio-range attacker reaches the bug.\nUI:N - Background and periodic scans are issued automatically by wpa_supplicant/NetworkManager without any user action, so no victim interaction is needed for the vulnerable path to run.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The underflowed length becomes ~4GB when widened to unsigned int, so the element walk reads far past the ~2.5KB RX skb slab object, and the out-of-bounds byte taken as el[2] is turned into rx_status.freq that userspace observes in scan results, allowing repeated frames to leak adjacent kernel heap contents.\nI:N - The defect is purely a read overrun; nothing outside the skb is written and the only attacker-influenced value is the reported channel/frequency, giving no memory-corruption or control-flow primitive.\nA:H - The unbounded element walk runs off the slab and can dereference unmapped memory while executing in tasklet/softirq context, producing a kernel oops or panic that the attacker can trigger repeatedly with injected frames."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:33.308Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cb831aff2f850f72bc5ff5ad77d0a70bb5a84061"
},
{
"url": "https://git.kernel.org/stable/c/4875680d1703f56afa6257ba30244f2fb44ed205"
},
{
"url": "https://git.kernel.org/stable/c/b406f33d234f98c8b310fdab5cbb492d85e98e49"
},
{
"url": "https://git.kernel.org/stable/c/e165a1d295e7e814e13b0f92c86e5d48309509ce"
},
{
"url": "https://git.kernel.org/stable/c/bcde7249d45f52f994a9872bedf45994472ade77"
},
{
"url": "https://git.kernel.org/stable/c/fb1b50ab699211e777dca5ccfb648788b6a6e519"
},
{
"url": "https://git.kernel.org/stable/c/f742d9c98b5c504fc9e6744eef13a721c2aea486"
},
{
"url": "https://git.kernel.org/stable/c/61a799ffd1e5a4fd3702d547828b7ff3d161468e"
}
],
"title": "wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68373",
"datePublished": "2026-08-10T12:03:51.663Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:33.308Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72084 (GCVE-0-2026-72084)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: Bound PR-OUT TransportID parsing to the received buffer
core_scsi3_decode_spec_i_port() and core_scsi3_emulate_register_and_move()
hand the raw PERSISTENT RESERVE OUT parameter buffer to
target_parse_pr_out_transport_id() without telling it how many bytes are
valid. For an iSCSI TransportID (FORMAT CODE 01b),
iscsi_parse_pr_out_transport_id() locates the ",i,0x" ISID separator with
an unbounded strstr() (and on the error path prints the name with a further
unbounded "%s"). An initiator can submit a TransportID whose iSCSI name
contains neither a ",i,0x" substring nor a NUL terminator, filling the
parameter list to its end, so the scan runs off the end of the buffer.
When the parameter list spans more than one page the buffer is a multi-page
vmap (transport_kmap_data_sg()), so the over-read walks into the trailing
vmalloc guard page and oopses (KASAN: vmalloc-out-of-bounds in strstr). It
is reachable by any fabric that delivers a PR OUT to a device exported
through an iSCSI TPG, including a guest via vhost-scsi.
Pass the number of received bytes down to the parser and validate the iSCSI
TransportID's own self-described length (ADDITIONAL LENGTH + 4) once, up
front: reject it if it is below the spc4r17 minimum or larger than the
received buffer, then bound the separator search, the ISID walk and the
name copy by that length. This is the length check the callers already
perform after the parse (core_scsi3_decode_spec_i_port() compares tid_len
against tpdl, core_scsi3_emulate_register_and_move() validates it against
data_length), moved ahead of the scan. Also drop the unbounded "%s" of the
unterminated name.
Add per-format explicit name-length checks before copying into i_str,
rather than silently truncating with min_t: for FORMAT CODE 00b reject if
the descriptor body (tid_len - 4 bytes) cannot fit in
i_str[TRANSPORT_IQN_LEN]; for FORMAT CODE 01b reject if the name portion
(from &buf[4] up to the separator) cannot fit. Both checks make the bounds
intent explicit at each format branch.
While here, also reject a FORMAT CODE 01b TransportID whose ",i,0x"
separator sits at the very end of the descriptor: that leaves an empty ISID
and points the returned port nexus pointer at buf + tid_len, one past the
descriptor, which the registration code (__core_scsi3_locate_pr_reg(),
__core_scsi3_alloc_registration()) then dereferences as the ISID string --
the same over-read of the parameter buffer for a malformed descriptor.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/target/target_core_fabric_lib.c",
"drivers/target/target_core_internal.h",
"drivers/target/target_core_pr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "88c67c3de914e19172e1d878a7625c5b06c20ec5",
"status": "affected",
"version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
"versionType": "git"
},
{
"lessThan": "842248047ef28dbf3b3f7f49a0ec315054d4dab8",
"status": "affected",
"version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
"versionType": "git"
},
{
"lessThan": "03fbc7de8d5e85fc8420e57e8304c855efd453ab",
"status": "affected",
"version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
"versionType": "git"
},
{
"lessThan": "6ca5de8782e67573a61a6736b6dc0ffe58dcdf59",
"status": "affected",
"version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
"versionType": "git"
},
{
"lessThan": "9298078a8f7d8181a04614a34ab655ccdf038204",
"status": "affected",
"version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
"versionType": "git"
},
{
"lessThan": "004ccd2d3b4ac36a300e05e01df152e5c02a5a82",
"status": "affected",
"version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
"versionType": "git"
},
{
"lessThan": "555a89846ed888d7401b3f7200934c0fbedcbb46",
"status": "affected",
"version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
"versionType": "git"
},
{
"lessThan": "d04a179085c262c9ed577d0a4cbc6482ff1fd9a3",
"status": "affected",
"version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/target/target_core_fabric_lib.c",
"drivers/target/target_core_internal.h",
"drivers/target/target_core_pr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.38"
},
{
"lessThan": "2.6.38",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.38",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: Bound PR-OUT TransportID parsing to the received buffer\n\ncore_scsi3_decode_spec_i_port() and core_scsi3_emulate_register_and_move()\nhand the raw PERSISTENT RESERVE OUT parameter buffer to\ntarget_parse_pr_out_transport_id() without telling it how many bytes are\nvalid. For an iSCSI TransportID (FORMAT CODE 01b),\niscsi_parse_pr_out_transport_id() locates the \",i,0x\" ISID separator with\nan unbounded strstr() (and on the error path prints the name with a further\nunbounded \"%s\"). An initiator can submit a TransportID whose iSCSI name\ncontains neither a \",i,0x\" substring nor a NUL terminator, filling the\nparameter list to its end, so the scan runs off the end of the buffer.\n\nWhen the parameter list spans more than one page the buffer is a multi-page\nvmap (transport_kmap_data_sg()), so the over-read walks into the trailing\nvmalloc guard page and oopses (KASAN: vmalloc-out-of-bounds in strstr). It\nis reachable by any fabric that delivers a PR OUT to a device exported\nthrough an iSCSI TPG, including a guest via vhost-scsi.\n\nPass the number of received bytes down to the parser and validate the iSCSI\nTransportID\u0027s own self-described length (ADDITIONAL LENGTH + 4) once, up\nfront: reject it if it is below the spc4r17 minimum or larger than the\nreceived buffer, then bound the separator search, the ISID walk and the\nname copy by that length. This is the length check the callers already\nperform after the parse (core_scsi3_decode_spec_i_port() compares tid_len\nagainst tpdl, core_scsi3_emulate_register_and_move() validates it against\ndata_length), moved ahead of the scan. Also drop the unbounded \"%s\" of the\nunterminated name.\n\nAdd per-format explicit name-length checks before copying into i_str,\nrather than silently truncating with min_t: for FORMAT CODE 00b reject if\nthe descriptor body (tid_len - 4 bytes) cannot fit in\ni_str[TRANSPORT_IQN_LEN]; for FORMAT CODE 01b reject if the name portion\n(from \u0026buf[4] up to the separator) cannot fit. Both checks make the bounds\nintent explicit at each format branch.\n\nWhile here, also reject a FORMAT CODE 01b TransportID whose \",i,0x\"\nseparator sits at the very end of the descriptor: that leaves an empty ISID\nand points the returned port nexus pointer at buf + tid_len, one past the\ndescriptor, which the registration code (__core_scsi3_locate_pr_reg(),\n__core_scsi3_alloc_registration()) then dereferences as the ISID string --\nthe same over-read of the parameter buffer for a malformed descriptor."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is triggered by a PERSISTENT RESERVE OUT SCSI command delivered over the LIO iSCSI target fabric (TCP/3260); remote initiators reach `iscsi_parse_pr_out_transport_id()` after login and normal SCSI command processing, and the fix commit notes the same path via vhost-scsi-backed exports.\nAC:L - An attacker fully controls the PR-OUT parameter list and can reliably supply a FORMAT CODE 01b iSCSI TransportID without a \",i,0x\" separator or NUL terminator and size it past one page so `strstr()` over-reads into the vmalloc guard page; no races or victim-specific memory layout are required.\nPR:N - Exploitation requires only completing iSCSI login to an exported LUN as any initiator client, not host administrator privileges; LIO demo mode auto-provisions initiator ACLs and many storage appliances expose iSCSI targets to the network without mapping this to elevated OS credentials.\nUI:N - No end-user or administrator action beyond normal automated iSCSI target operation is needed; a remote initiator can send the malicious PR OUT command directly once a session to the LUN exists.\nS:U - The flaw corrupts or reads kernel memory and crashes the target host kernel within the same kernel security boundary; it does not by itself cross a VM, container, or IOMMU isolation boundary to another authority.\nC:H - Unbounded `strstr()` and an unbounded `%s` on the error path perform out-of-bounds reads past the received PR-OUT buffer, potentially disclosing adjacent kernel memory before the fault, matching CVSS guidance for out-of-bounds reads beyond a few bytes.\nI:H - A malformed TransportID can leave the ISID pointer one byte past the descriptor so subsequent registration code dereferences out of bounds, and the ISID normalization loop can write with `tolower()` beyond the buffer, giving a memory-corruption primitive in kernel context.\nA:H - The over-read into a multi-page vmalloc mapping hits the guard page and triggers a KASAN vmalloc-out-of-bounds fault and kernel oops, remotely denying service to the host and all consumers of the iSCSI target."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:46.221Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/88c67c3de914e19172e1d878a7625c5b06c20ec5"
},
{
"url": "https://git.kernel.org/stable/c/842248047ef28dbf3b3f7f49a0ec315054d4dab8"
},
{
"url": "https://git.kernel.org/stable/c/03fbc7de8d5e85fc8420e57e8304c855efd453ab"
},
{
"url": "https://git.kernel.org/stable/c/6ca5de8782e67573a61a6736b6dc0ffe58dcdf59"
},
{
"url": "https://git.kernel.org/stable/c/9298078a8f7d8181a04614a34ab655ccdf038204"
},
{
"url": "https://git.kernel.org/stable/c/004ccd2d3b4ac36a300e05e01df152e5c02a5a82"
},
{
"url": "https://git.kernel.org/stable/c/555a89846ed888d7401b3f7200934c0fbedcbb46"
},
{
"url": "https://git.kernel.org/stable/c/d04a179085c262c9ed577d0a4cbc6482ff1fd9a3"
}
],
"title": "scsi: target: Bound PR-OUT TransportID parsing to the received buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72084",
"datePublished": "2026-08-15T05:52:32.789Z",
"dateReserved": "2026-08-09T03:40:39.904Z",
"dateUpdated": "2026-08-23T12:46:46.221Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52939 (GCVE-0-2026-52939)
Vulnerability from cvelistv5
Published
2026-06-24 07:14
Modified
2026-06-24 07:14
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
rds_ib_xmit_atomic() always programs a masked atomic opcode
(IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD)
for every RDS atomic cmsg. But the completion-side switch in
rds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked
atomic completion falls through to default and returns rm == NULL while
send->s_op is left set. rds_ib_send_cqe_handler() then dereferences the
NULL rm via rm->m_final_op, oopsing in softirq context. An unprivileged
AF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection
triggers it; on hardware that natively accepts masked atomics (mlx4,
mlx5) no extra setup is needed.
RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR!
Oops: general protection fault [#1] SMP KASAN
KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197]
RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282)
Call Trace:
<IRQ>
rds_ib_send_cqe_handler (net/rds/ib_send.c:282)
poll_scq (net/rds/ib_cm.c:274)
rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294)
tasklet_action_common (kernel/softirq.c:943)
handle_softirqs (kernel/softirq.c:573)
run_ksoftirqd (kernel/softirq.c:479)
</IRQ>
Kernel panic - not syncing: Fatal exception in interrupt
Handle the masked atomic opcodes in the same case as the non-masked
ones: they map to the same struct rds_message.atomic union member, so
the existing container_of()/rds_ib_send_unmap_atomic() body is correct
for them.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 20c72bd5f5f902e5a8745d51573699605bf8d21c Version: 20c72bd5f5f902e5a8745d51573699605bf8d21c Version: 20c72bd5f5f902e5a8745d51573699605bf8d21c Version: 20c72bd5f5f902e5a8745d51573699605bf8d21c Version: 20c72bd5f5f902e5a8745d51573699605bf8d21c Version: 20c72bd5f5f902e5a8745d51573699605bf8d21c Version: 20c72bd5f5f902e5a8745d51573699605bf8d21c Version: 20c72bd5f5f902e5a8745d51573699605bf8d21c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rds/ib_send.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a0148342badd8c9b2e46551766a27cb76c82e715",
"status": "affected",
"version": "20c72bd5f5f902e5a8745d51573699605bf8d21c",
"versionType": "git"
},
{
"lessThan": "4dd262f875e87653df50b138de1390ab0628e6b7",
"status": "affected",
"version": "20c72bd5f5f902e5a8745d51573699605bf8d21c",
"versionType": "git"
},
{
"lessThan": "6e4615164d185a26badb2f376a2449f4d174a5f0",
"status": "affected",
"version": "20c72bd5f5f902e5a8745d51573699605bf8d21c",
"versionType": "git"
},
{
"lessThan": "0f22412a2f4fbbe0251c132abee045d15a90e5b6",
"status": "affected",
"version": "20c72bd5f5f902e5a8745d51573699605bf8d21c",
"versionType": "git"
},
{
"lessThan": "0f7baa82a24813cdad0b06a6f8f07e4824af5ed5",
"status": "affected",
"version": "20c72bd5f5f902e5a8745d51573699605bf8d21c",
"versionType": "git"
},
{
"lessThan": "dcf458120add64c96a6ef5cf719340453f6e6abf",
"status": "affected",
"version": "20c72bd5f5f902e5a8745d51573699605bf8d21c",
"versionType": "git"
},
{
"lessThan": "4fd34669558085bcb589aa2078a13b0ca79e360d",
"status": "affected",
"version": "20c72bd5f5f902e5a8745d51573699605bf8d21c",
"versionType": "git"
},
{
"lessThan": "34080db3e70ddf94c38512ad2331e3c3afca6cc1",
"status": "affected",
"version": "20c72bd5f5f902e5a8745d51573699605bf8d21c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rds/ib_send.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion\n\nrds_ib_xmit_atomic() always programs a masked atomic opcode\n(IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD)\nfor every RDS atomic cmsg. But the completion-side switch in\nrds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked\natomic completion falls through to default and returns rm == NULL while\nsend-\u003es_op is left set. rds_ib_send_cqe_handler() then dereferences the\nNULL rm via rm-\u003em_final_op, oopsing in softirq context. An unprivileged\nAF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection\ntriggers it; on hardware that natively accepts masked atomics (mlx4,\nmlx5) no extra setup is needed.\n\n RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR!\n Oops: general protection fault [#1] SMP KASAN\n KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197]\n RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282)\n Call Trace:\n \u003cIRQ\u003e\n rds_ib_send_cqe_handler (net/rds/ib_send.c:282)\n poll_scq (net/rds/ib_cm.c:274)\n rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294)\n tasklet_action_common (kernel/softirq.c:943)\n handle_softirqs (kernel/softirq.c:573)\n run_ksoftirqd (kernel/softirq.c:479)\n \u003c/IRQ\u003e\n Kernel panic - not syncing: Fatal exception in interrupt\n\nHandle the masked atomic opcodes in the same case as the non-masked\nones: they map to the same struct rds_message.atomic union member, so\nthe existing container_of()/rds_ib_send_unmap_atomic() body is correct\nfor them."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-24T07:14:28.622Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a0148342badd8c9b2e46551766a27cb76c82e715"
},
{
"url": "https://git.kernel.org/stable/c/4dd262f875e87653df50b138de1390ab0628e6b7"
},
{
"url": "https://git.kernel.org/stable/c/6e4615164d185a26badb2f376a2449f4d174a5f0"
},
{
"url": "https://git.kernel.org/stable/c/0f22412a2f4fbbe0251c132abee045d15a90e5b6"
},
{
"url": "https://git.kernel.org/stable/c/0f7baa82a24813cdad0b06a6f8f07e4824af5ed5"
},
{
"url": "https://git.kernel.org/stable/c/dcf458120add64c96a6ef5cf719340453f6e6abf"
},
{
"url": "https://git.kernel.org/stable/c/4fd34669558085bcb589aa2078a13b0ca79e360d"
},
{
"url": "https://git.kernel.org/stable/c/34080db3e70ddf94c38512ad2331e3c3afca6cc1"
}
],
"title": "net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52939",
"datePublished": "2026-06-24T07:14:28.622Z",
"dateReserved": "2026-06-09T07:44:35.370Z",
"dateUpdated": "2026-06-24T07:14:28.622Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64401 (GCVE-0-2026-64401)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: resolve SWN tcon from live registrations
cifs_swn_notify() looks up a witness registration by id under
cifs_swnreg_idr_mutex, drops the mutex, and then uses the registration's
cached tcon pointer. That pointer is not a lifetime reference, and it is
not a stable representative once cifs_get_swn_reg() lets multiple tcons
for the same net/share name share one registration id.
A same-share second mount can keep the cifs_swn_reg alive after the first
tcon unregisters and is freed. The registration then still points at the
freed first tcon, so taking tc_lock or incrementing tc_count through
swnreg->tcon only moves the use-after-free earlier. Taking tc_lock while
holding cifs_swnreg_idr_mutex also violates the documented CIFS lock
order.
Fix this by making the registration store only the stable witness
identity: id, net name, share name, and notify flags. When a notify
arrives, copy that identity under cifs_swnreg_idr_mutex, drop the mutex,
then find and pin a live witness tcon that currently matches the net/share
pair under the normal cifs_tcp_ses_lock -> tc_lock order. The notification
path uses that pinned tcon directly and drops the reference when done.
Registration and unregister messages now use the live tcon passed by the
caller instead of a cached tcon in the registration. The final unregister
send is folded into cifs_swn_unregister() while the registration is still
protected by cifs_swnreg_idr_mutex. This removes the previous
find/drop/reacquire raw-pointer window. The release path only removes the
idr entry and frees the stable identity strings.
This preserves the intended one-registration/many-tcon behavior: a
registration id represents a net/share pair, and notify handling acts on a
live representative selected at use time. It also preserves CLIENT_MOVE
ordering for the representative tcon because the old-IP unregister is sent
before cifs_swn_register() sends the new-IP register.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 Version: fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/cifs_swn.c",
"fs/smb/client/trace.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "51d18db392e5386a7bb9e816d611f14e600cca3c",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "aa3c0cab4b28c5007ec570c63e1d6ad6943ed0fd",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "945b4a4a54497db1dcb2f20ef801a84e884dac21",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "91b8a58c6ac15c7db6518f696389933282f88da7",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "0700f946659d0ab2352ec8a9b1c6fc74b13a27d7",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
},
{
"lessThan": "ec457f9afe5ae9538bdcd58fd4cb442b9787e183",
"status": "affected",
"version": "fed979a7e082bd9f25f9002c3c4f8740dacd0bc8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/cifs_swn.c",
"fs/smb/client/trace.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: resolve SWN tcon from live registrations\n\ncifs_swn_notify() looks up a witness registration by id under\ncifs_swnreg_idr_mutex, drops the mutex, and then uses the registration\u0027s\ncached tcon pointer. That pointer is not a lifetime reference, and it is\nnot a stable representative once cifs_get_swn_reg() lets multiple tcons\nfor the same net/share name share one registration id.\n\nA same-share second mount can keep the cifs_swn_reg alive after the first\ntcon unregisters and is freed. The registration then still points at the\nfreed first tcon, so taking tc_lock or incrementing tc_count through\nswnreg-\u003etcon only moves the use-after-free earlier. Taking tc_lock while\nholding cifs_swnreg_idr_mutex also violates the documented CIFS lock\norder.\n\nFix this by making the registration store only the stable witness\nidentity: id, net name, share name, and notify flags. When a notify\narrives, copy that identity under cifs_swnreg_idr_mutex, drop the mutex,\nthen find and pin a live witness tcon that currently matches the net/share\npair under the normal cifs_tcp_ses_lock -\u003e tc_lock order. The notification\npath uses that pinned tcon directly and drops the reference when done.\n\nRegistration and unregister messages now use the live tcon passed by the\ncaller instead of a cached tcon in the registration. The final unregister\nsend is folded into cifs_swn_unregister() while the registration is still\nprotected by cifs_swnreg_idr_mutex. This removes the previous\nfind/drop/reacquire raw-pointer window. The release path only removes the\nidr entry and frees the stable identity strings.\n\nThis preserves the intended one-registration/many-tcon behavior: a\nregistration id represents a net/share pair, and notify handling acts on a\nlive representative selected at use time. It also preserves CLIENT_MOVE\nordering for the representative tcon because the old-IP unregister is sent\nbefore cifs_swn_register() sends the new-IP register."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is locally reachable through the world-readable /proc/fs/cifs/DebugData path and, on earlier affected kernels, unrestricted SWN generic-netlink notifications.\nAC:L - A same-share second mount deterministically preserves the registration after the first tcon is freed; repeated proc reads or notifications then dereference the stale pointer without requiring an uncontrollable race.\nPR:L - An unprivileged local user can read /proc/fs/cifs/DebugData, and affected kernels predating the companion netlink authorization fix also allowed unprivileged SWN_NOTIFY messages. User namespaces do not grant CIFS mount authority, but no mount privilege is needed once normal mount turnover creates the stale registration.\nUI:N - Once a witness-enabled registration exists, exploitation requires no further victim action; the attacker can invoke the local trigger directly.\nS:U - Successful exploitation compromises the host kernel within the same security authority and does not inherently cross a VM, IOMMU, or other scope boundary.\nC:H - The heap UAF involves attacker-reclaimable cifs_tcon and cifs_swn_reg objects whose pointer chains reach session credentials and arbitrary kernel memory, enabling high-impact disclosure primitives.\nI:H - Reclaiming the freed objects can redirect client-move and reconnect operations through attacker-influenced pointers, providing arbitrary-write and control-flow-hijacking potential.\nA:H - Dereferencing the freed tcon or registration can cause an immediate kernel oops or panic, and the periodic echo worker can repeatedly exercise the stale pointer."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:59.017Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/51d18db392e5386a7bb9e816d611f14e600cca3c"
},
{
"url": "https://git.kernel.org/stable/c/aa3c0cab4b28c5007ec570c63e1d6ad6943ed0fd"
},
{
"url": "https://git.kernel.org/stable/c/945b4a4a54497db1dcb2f20ef801a84e884dac21"
},
{
"url": "https://git.kernel.org/stable/c/91b8a58c6ac15c7db6518f696389933282f88da7"
},
{
"url": "https://git.kernel.org/stable/c/0700f946659d0ab2352ec8a9b1c6fc74b13a27d7"
},
{
"url": "https://git.kernel.org/stable/c/ec457f9afe5ae9538bdcd58fd4cb442b9787e183"
}
],
"title": "smb: client: resolve SWN tcon from live registrations",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64401",
"datePublished": "2026-07-25T08:50:44.361Z",
"dateReserved": "2026-07-19T15:36:31.785Z",
"dateUpdated": "2026-08-17T04:54:59.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64376 (GCVE-0-2026-64376)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
firmware_loader: fix device reference leak in firmware_upload_register()
firmware_upload_register()
-> fw_create_instance()
-> device_initialize()
After fw_create_instance() succeeds, the lifetime of the embedded struct
device is expected to be managed through the device core reference
counting, since fw_create_instance() has already called
device_initialize().
In firmware_upload_register(), if alloc_lookup_fw_priv() fails after
fw_create_instance() succeeds, the code reaches free_fw_sysfs and frees
fw_sysfs directly instead of releasing the device reference with
put_device(). This may leave the reference count of the embedded struct
device unbalanced, resulting in a refcount leak.
The issue was identified by a static analysis tool I developed and
confirmed by manual review. Fix this by using put_device(fw_dev) in the
failure path and letting fw_dev_release() handle the final cleanup,
instead of freeing the instance directly from the error path.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 97730bbb242cde22b7140acd202ffd88823886c9 Version: 97730bbb242cde22b7140acd202ffd88823886c9 Version: 97730bbb242cde22b7140acd202ffd88823886c9 Version: 97730bbb242cde22b7140acd202ffd88823886c9 Version: 97730bbb242cde22b7140acd202ffd88823886c9 Version: 97730bbb242cde22b7140acd202ffd88823886c9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/base/firmware_loader/sysfs_upload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "517676ec7dfca064e08f94007a4abd21969de0a0",
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"versionType": "git"
},
{
"lessThan": "46d403da376a8b7c1187193294953816e1a8d7fe",
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"versionType": "git"
},
{
"lessThan": "2619b47a0c8114eef980a56ade7e3ef4b58eb384",
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"versionType": "git"
},
{
"lessThan": "92f41769e5fd16bcd9ba97500d0517332e0a5b45",
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"versionType": "git"
},
{
"lessThan": "15432f19562fdb9199cce6d9fc24db12c71ed574",
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"versionType": "git"
},
{
"lessThan": "896df22ee57648b0c505bd76ddbc6b2341834696",
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/base/firmware_loader/sysfs_upload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: fix device reference leak in firmware_upload_register()\n\nfirmware_upload_register()\n -\u003e fw_create_instance()\n -\u003e device_initialize()\n\nAfter fw_create_instance() succeeds, the lifetime of the embedded struct\ndevice is expected to be managed through the device core reference\ncounting, since fw_create_instance() has already called\ndevice_initialize().\n\nIn firmware_upload_register(), if alloc_lookup_fw_priv() fails after\nfw_create_instance() succeeds, the code reaches free_fw_sysfs and frees\nfw_sysfs directly instead of releasing the device reference with\nput_device(). This may leave the reference count of the embedded struct\ndevice unbalanced, resulting in a refcount leak.\n\nThe issue was identified by a static analysis tool I developed and\nconfirmed by manual review. Fix this by using put_device(fw_dev) in the\nfailure path and letting fw_dev_release() handle the final cleanup,\ninstead of freeing the instance directly from the error path."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:27.297Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/517676ec7dfca064e08f94007a4abd21969de0a0"
},
{
"url": "https://git.kernel.org/stable/c/46d403da376a8b7c1187193294953816e1a8d7fe"
},
{
"url": "https://git.kernel.org/stable/c/2619b47a0c8114eef980a56ade7e3ef4b58eb384"
},
{
"url": "https://git.kernel.org/stable/c/92f41769e5fd16bcd9ba97500d0517332e0a5b45"
},
{
"url": "https://git.kernel.org/stable/c/15432f19562fdb9199cce6d9fc24db12c71ed574"
},
{
"url": "https://git.kernel.org/stable/c/896df22ee57648b0c505bd76ddbc6b2341834696"
}
],
"title": "firmware_loader: fix device reference leak in firmware_upload_register()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64376",
"datePublished": "2026-07-25T08:50:27.577Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-08-17T04:54:27.297Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64048 (GCVE-0-2026-64048)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
On the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is
reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt()
populates V2 entries starting at index 1, so when no V1 device is
selected slot 0 is left in its kzalloc()'ed state with ism_dev[0] ==
NULL and ism_chid[0] == 0.
smc_v2_determine_accepted_chid() then matches the peer's CHID against
the array starting from index 0 using the CHID alone. A malicious
peer replying to a SMC-Dv2-only proposal with d1.chid == 0 matches
the empty slot, ini->ism_selected becomes 0, and the subsequent
ism_dev[0]->lgr_lock dereference in smc_conn_create() faults at
offsetof(struct smcd_dev, lgr_lock) == 0x68:
BUG: KASAN: null-ptr-deref in _raw_spin_lock_bh+0x79/0xe0
Write of size 4 at addr 0000000000000068 by task exploit/144
Call Trace:
_raw_spin_lock_bh
smc_conn_create (net/smc/smc_core.c:1997)
__smc_connect (net/smc/af_smc.c:1447)
smc_connect (net/smc/af_smc.c:1720)
__sys_connect
__x64_sys_connect
do_syscall_64
Require ism_dev[i] to be non-NULL before accepting a CHID match.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a7c9c5f4af7f6098da68705fc5d86565d0728ef7 Version: a7c9c5f4af7f6098da68705fc5d86565d0728ef7 Version: a7c9c5f4af7f6098da68705fc5d86565d0728ef7 Version: a7c9c5f4af7f6098da68705fc5d86565d0728ef7 Version: a7c9c5f4af7f6098da68705fc5d86565d0728ef7 Version: a7c9c5f4af7f6098da68705fc5d86565d0728ef7 Version: a7c9c5f4af7f6098da68705fc5d86565d0728ef7 Version: a7c9c5f4af7f6098da68705fc5d86565d0728ef7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/af_smc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "903f7688ffeb9b323d70652c01f554bd4ba2a3d6",
"status": "affected",
"version": "a7c9c5f4af7f6098da68705fc5d86565d0728ef7",
"versionType": "git"
},
{
"lessThan": "dd2f9dd83c68abd7ba7ded7075290b016cb7ecd0",
"status": "affected",
"version": "a7c9c5f4af7f6098da68705fc5d86565d0728ef7",
"versionType": "git"
},
{
"lessThan": "6927cacf2b10d4fa80c1a2d407512ef9397c59c6",
"status": "affected",
"version": "a7c9c5f4af7f6098da68705fc5d86565d0728ef7",
"versionType": "git"
},
{
"lessThan": "d38ba387244e5c5f7db3e11ea98bc2c7beccb0c0",
"status": "affected",
"version": "a7c9c5f4af7f6098da68705fc5d86565d0728ef7",
"versionType": "git"
},
{
"lessThan": "53eb7bd09aace72fa17510d80e0caf5ca058c231",
"status": "affected",
"version": "a7c9c5f4af7f6098da68705fc5d86565d0728ef7",
"versionType": "git"
},
{
"lessThan": "afa9036b8c9963947b487c36e332df6a42c96fcb",
"status": "affected",
"version": "a7c9c5f4af7f6098da68705fc5d86565d0728ef7",
"versionType": "git"
},
{
"lessThan": "65edb3b0822cfe5041be8fbabebd57e2e5ad9f4e",
"status": "affected",
"version": "a7c9c5f4af7f6098da68705fc5d86565d0728ef7",
"versionType": "git"
},
{
"lessThan": "277740023def559a4a2ddc3e8e784ee37a0f16a9",
"status": "affected",
"version": "a7c9c5f4af7f6098da68705fc5d86565d0728ef7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/af_smc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot\n\nOn the SMC-D client, slot 0 of ini-\u003eism_dev[]/ini-\u003eism_chid[] is\nreserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt()\npopulates V2 entries starting at index 1, so when no V1 device is\nselected slot 0 is left in its kzalloc()\u0027ed state with ism_dev[0] ==\nNULL and ism_chid[0] == 0.\n\nsmc_v2_determine_accepted_chid() then matches the peer\u0027s CHID against\nthe array starting from index 0 using the CHID alone. A malicious\npeer replying to a SMC-Dv2-only proposal with d1.chid == 0 matches\nthe empty slot, ini-\u003eism_selected becomes 0, and the subsequent\nism_dev[0]-\u003elgr_lock dereference in smc_conn_create() faults at\noffsetof(struct smcd_dev, lgr_lock) == 0x68:\n\n BUG: KASAN: null-ptr-deref in _raw_spin_lock_bh+0x79/0xe0\n Write of size 4 at addr 0000000000000068 by task exploit/144\n Call Trace:\n _raw_spin_lock_bh\n smc_conn_create (net/smc/smc_core.c:1997)\n __smc_connect (net/smc/af_smc.c:1447)\n smc_connect (net/smc/af_smc.c:1720)\n __sys_connect\n __x64_sys_connect\n do_syscall_64\n\nRequire ism_dev[i] to be non-NULL before accepting a CHID match."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The fault is triggered while processing a malicious CLC ACCEPT message received from a remote TCP peer during the SMC-D handshake; the attacker controls the server response over the network.\nAC:L - Once a victim with SMC-Dv2 hardware initiates an SMC connection, a malicious peer can reliably send `d1.chid == 0` in the CLC ACCEPT to match the empty reserved slot 0 without races or special timing.\nPR:N - No local privileges are required on the victim host; an unauthenticated remote attacker operating a malicious SMC server can crash connecting clients, and unprivileged users can create SMC sockets without capability checks.\nUI:N - Exploitation requires only that a victim application initiate a normal outbound SMC connection to the attacker\u0027s server, which occurs automatically in enterprise middleware without per-connection user action.\nS:U - The vulnerability causes a kernel crash on the victim host but does not cross a security boundary such as VM escape or sandbox breakout.\nC:N - The bug is a null pointer dereference when taking `ism_dev[0]-\u003elgr_lock`; it causes an immediate kernel fault with no information disclosure.\nI:N - The attempted write at address 0x68 is a spinlock operation on a NULL `smcd_dev` pointer, not a controlled or arbitrary memory modification primitive.\nA:H - A successful trigger causes a kernel null pointer dereference (KASAN-reported oops/panic), crashing the affected system or at minimum the connecting process\u0027s kernel context."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:32.597Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/903f7688ffeb9b323d70652c01f554bd4ba2a3d6"
},
{
"url": "https://git.kernel.org/stable/c/dd2f9dd83c68abd7ba7ded7075290b016cb7ecd0"
},
{
"url": "https://git.kernel.org/stable/c/6927cacf2b10d4fa80c1a2d407512ef9397c59c6"
},
{
"url": "https://git.kernel.org/stable/c/d38ba387244e5c5f7db3e11ea98bc2c7beccb0c0"
},
{
"url": "https://git.kernel.org/stable/c/53eb7bd09aace72fa17510d80e0caf5ca058c231"
},
{
"url": "https://git.kernel.org/stable/c/afa9036b8c9963947b487c36e332df6a42c96fcb"
},
{
"url": "https://git.kernel.org/stable/c/65edb3b0822cfe5041be8fbabebd57e2e5ad9f4e"
},
{
"url": "https://git.kernel.org/stable/c/277740023def559a4a2ddc3e8e784ee37a0f16a9"
}
],
"title": "net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64048",
"datePublished": "2026-07-19T15:39:32.664Z",
"dateReserved": "2026-07-19T07:54:57.029Z",
"dateUpdated": "2026-08-23T12:45:32.597Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72499 (GCVE-0-2026-72499)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Free CQ toggle page after firmware teardown
Free the toggle page only after firmware teardown completes so that
an NQ interrupt arriving during bnxt_qplib_destroy_cq() won't write
the toggle value to an already-freed page. Move free_page() after
bnxt_qplib_destroy_cq.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/ib_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b193854675ecad43b4d69c304c1b6a90b206cc99",
"status": "affected",
"version": "e275919d96693c5ca964b20d73a33d52a7e57f04",
"versionType": "git"
},
{
"lessThan": "bb45e06f9914ca64ac95341a80a0c20bb8dd46a9",
"status": "affected",
"version": "e275919d96693c5ca964b20d73a33d52a7e57f04",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/ib_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Free CQ toggle page after firmware teardown\n\nFree the toggle page only after firmware teardown completes so that\nan NQ interrupt arriving during bnxt_qplib_destroy_cq() won\u0027t write\nthe toggle value to an already-freed page. Move free_page() after\nbnxt_qplib_destroy_cq."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is triggered by destroying a user CQ through the RDMA uverbs ioctl on /dev/infiniband/uverbs*; although RoCE peers can generate CQ/NQ events, the premature free_page() only occurs in this local destroy path, not from remote packet handling alone.\nAC:L - An attacker controls CQ teardown timing via ibv_destroy_cq and can reliably create the race by keeping QPs active and/or soliciting CQ notifications (including from a cooperating RoCE peer) while destroy_cq runs through bnxt_qplib_destroy_cq firmware teardown.\nPR:L - Exploitation requires only local RDMA verbs access to create/destroy a user CQ on a Gen P7 bnxt_re device; uverbs char devices are created world-accessible (0666) and RDMA is commonly granted to unprivileged HPC/cloud/Kubernetes workload users rather than real root.\nUI:N - No victim interaction is required beyond the attacker (or compromised local workload) invoking CQ destroy on resources it already controls; remote peers may assist timing but do not need the victim to click, mount, or open files.\nS:C - On Kubernetes/HPC hosts that expose bnxt_re to containers/pods, triggering this host-kernel UAF from an unprivileged RDMA-enabled workload can corrupt host memory and enable container-to-host sandbox escape beyond the workload security boundary.\nC:H - This is a kernel write-after-free: an NQ interrupt writes a toggle value into a page already returned to the buddy allocator, enabling corruption of subsequently reallocated kernel objects and classic UAF-based information disclosure primitives.\nI:H - The interrupt path performs a controlled 4-byte write to freed kernel memory during destroy_cq, providing a heap corruption primitive that can be developed into arbitrary kernel write or code execution rather than being limited to a benign crash.\nA:H - Writing to a freed page during interrupt handling can oops/panic the kernel immediately, and repeated CQ create/destroy cycles let an attacker reliably induce host-level denial of service on RDMA-enabled systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:44:59.920Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b193854675ecad43b4d69c304c1b6a90b206cc99"
},
{
"url": "https://git.kernel.org/stable/c/bb45e06f9914ca64ac95341a80a0c20bb8dd46a9"
}
],
"title": "RDMA/bnxt_re: Free CQ toggle page after firmware teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72499",
"datePublished": "2026-08-15T05:57:31.696Z",
"dateReserved": "2026-08-09T03:40:39.937Z",
"dateUpdated": "2026-08-17T05:44:59.920Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68110 (GCVE-0-2026-68110)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit fa4f86a148271e325e95287630a3a15a9cd35fdc)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v4_4_2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "256d6f4803a93df96579c1ffdcb56518b9304f76",
"status": "affected",
"version": "7138fc88fdc1f999a547657af8623d3a2a862fc1",
"versionType": "git"
},
{
"lessThan": "ca50e541191fab519ed628182e1472e21d60e2ce",
"status": "affected",
"version": "7138fc88fdc1f999a547657af8623d3a2a862fc1",
"versionType": "git"
},
{
"lessThan": "dc3f5da1ba8e280d31676ce15b937e4302235b03",
"status": "affected",
"version": "7138fc88fdc1f999a547657af8623d3a2a862fc1",
"versionType": "git"
},
{
"lessThan": "cbe3b293d0ee926e595f53513d7c027d1c3e5be5",
"status": "affected",
"version": "7138fc88fdc1f999a547657af8623d3a2a862fc1",
"versionType": "git"
},
{
"lessThan": "40cdbe9fa424cc6264a7aed93a04bd7d69109d9e",
"status": "affected",
"version": "7138fc88fdc1f999a547657af8623d3a2a862fc1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v4_4_2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit fa4f86a148271e325e95287630a3a15a9cd35fdc)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:59.664Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/256d6f4803a93df96579c1ffdcb56518b9304f76"
},
{
"url": "https://git.kernel.org/stable/c/ca50e541191fab519ed628182e1472e21d60e2ce"
},
{
"url": "https://git.kernel.org/stable/c/dc3f5da1ba8e280d31676ce15b937e4302235b03"
},
{
"url": "https://git.kernel.org/stable/c/cbe3b293d0ee926e595f53513d7c027d1c3e5be5"
},
{
"url": "https://git.kernel.org/stable/c/40cdbe9fa424cc6264a7aed93a04bd7d69109d9e"
}
],
"title": "drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68110",
"datePublished": "2026-08-10T11:58:27.478Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-17T04:58:59.664Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53207 (GCVE-0-2026-53207)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-06-25 08:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
Two concurrent madvise(MADV_HWPOISON) calls on the same hugetlb page can
trigger a recursive spinlock self-deadlock (AA deadlock) on hugetlb_lock
when racing with a concurrent unmap:
thread#0 thread#1
-------- --------
madvise(folio, MADV_HWPOISON)
-> poisons the folio successfully
madvise(folio, MADV_HWPOISON) unmap(folio)
try_memory_failure_hugetlb
get_huge_page_for_hwpoison
spin_lock_irq(&hugetlb_lock) <- held
__get_huge_page_for_hwpoison
hugetlb_update_hwpoison()
-> MF_HUGETLB_FOLIO_PRE_POISONED
goto out:
folio_put()
refcount: 1 -> 0
free_huge_folio()
spin_lock_irqsave(&hugetlb_lock)
-> AA DEADLOCK!
The out: path in __get_huge_page_for_hwpoison() calls folio_put() to drop
the GUP reference while the hugetlb_lock is still held by the hugetlb.c
wrapper get_huge_page_for_hwpoison(). If concurrent unmap has released
the page table mapping reference, folio_put() drops the folio refcount to
zero, triggering free_huge_folio() which attempts to re-acquire the
non-recursive hugetlb_lock.
Fix this by moving hugetlb_lock acquisition from the hugetlb.c wrapper
into get_huge_page_for_hwpoison(). Place spin_unlock_irq() before the
folio_put() at the out: label so the folio is always released outside the
lock.
[akpm@linux-foundation.org: fix race, rename label per Miaohe]
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 405ce051236cc65b30bbfe490b28ce60ae6aed85 Version: 405ce051236cc65b30bbfe490b28ce60ae6aed85 Version: 405ce051236cc65b30bbfe490b28ce60ae6aed85 Version: 405ce051236cc65b30bbfe490b28ce60ae6aed85 Version: 405ce051236cc65b30bbfe490b28ce60ae6aed85 Version: 405ce051236cc65b30bbfe490b28ce60ae6aed85 Version: 62d1655b922958826b7ec22682c3141746f75064 Version: 5.15.54 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/hugetlb.h",
"include/linux/mm.h",
"mm/hugetlb.c",
"mm/memory-failure.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fc3ff42cb0cbf947e4600ae9761c3783760050e2",
"status": "affected",
"version": "405ce051236cc65b30bbfe490b28ce60ae6aed85",
"versionType": "git"
},
{
"lessThan": "77b73b54801ae7137479c141fd0473a491c1dc48",
"status": "affected",
"version": "405ce051236cc65b30bbfe490b28ce60ae6aed85",
"versionType": "git"
},
{
"lessThan": "a33bfed648c10f5a1519981dbfad80841191edc8",
"status": "affected",
"version": "405ce051236cc65b30bbfe490b28ce60ae6aed85",
"versionType": "git"
},
{
"lessThan": "dd77a83915b07e2b0205adb284f08b39ae31dc4b",
"status": "affected",
"version": "405ce051236cc65b30bbfe490b28ce60ae6aed85",
"versionType": "git"
},
{
"lessThan": "bf7ba8f96c258c30393814491930ae4ecdc5fe5e",
"status": "affected",
"version": "405ce051236cc65b30bbfe490b28ce60ae6aed85",
"versionType": "git"
},
{
"lessThan": "3c2d42b8ee345b17a4ba56b0f6492d1ff4c1178e",
"status": "affected",
"version": "405ce051236cc65b30bbfe490b28ce60ae6aed85",
"versionType": "git"
},
{
"status": "affected",
"version": "62d1655b922958826b7ec22682c3141746f75064",
"versionType": "git"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.54",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/hugetlb.h",
"include/linux/mm.h",
"mm/hugetlb.c",
"mm/memory-failure.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.54",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison\n\nTwo concurrent madvise(MADV_HWPOISON) calls on the same hugetlb page can\ntrigger a recursive spinlock self-deadlock (AA deadlock) on hugetlb_lock\nwhen racing with a concurrent unmap:\n\n thread#0 thread#1\n -------- --------\n madvise(folio, MADV_HWPOISON)\n -\u003e poisons the folio successfully\n madvise(folio, MADV_HWPOISON) unmap(folio)\n try_memory_failure_hugetlb\n get_huge_page_for_hwpoison\n spin_lock_irq(\u0026hugetlb_lock) \u003c- held\n __get_huge_page_for_hwpoison\n hugetlb_update_hwpoison()\n -\u003e MF_HUGETLB_FOLIO_PRE_POISONED\n goto out:\n folio_put()\n refcount: 1 -\u003e 0\n free_huge_folio()\n spin_lock_irqsave(\u0026hugetlb_lock)\n -\u003e AA DEADLOCK!\n\nThe out: path in __get_huge_page_for_hwpoison() calls folio_put() to drop\nthe GUP reference while the hugetlb_lock is still held by the hugetlb.c\nwrapper get_huge_page_for_hwpoison(). If concurrent unmap has released\nthe page table mapping reference, folio_put() drops the folio refcount to\nzero, triggering free_huge_folio() which attempts to re-acquire the\nnon-recursive hugetlb_lock.\n\nFix this by moving hugetlb_lock acquisition from the hugetlb.c wrapper\ninto get_huge_page_for_hwpoison(). Place spin_unlock_irq() before the\nfolio_put() at the out: label so the folio is always released outside the\nlock.\n\n[akpm@linux-foundation.org: fix race, rename label per Miaohe]"
}
],
"providerMetadata": {
"dateUpdated": "2026-06-25T08:39:13.592Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fc3ff42cb0cbf947e4600ae9761c3783760050e2"
},
{
"url": "https://git.kernel.org/stable/c/77b73b54801ae7137479c141fd0473a491c1dc48"
},
{
"url": "https://git.kernel.org/stable/c/a33bfed648c10f5a1519981dbfad80841191edc8"
},
{
"url": "https://git.kernel.org/stable/c/dd77a83915b07e2b0205adb284f08b39ae31dc4b"
},
{
"url": "https://git.kernel.org/stable/c/bf7ba8f96c258c30393814491930ae4ecdc5fe5e"
},
{
"url": "https://git.kernel.org/stable/c/3c2d42b8ee345b17a4ba56b0f6492d1ff4c1178e"
}
],
"title": "mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53207",
"datePublished": "2026-06-25T08:39:13.592Z",
"dateReserved": "2026-06-09T07:44:35.391Z",
"dateUpdated": "2026-06-25T08:39:13.592Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72497 (GCVE-0-2026-72497)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Add a max slot check for SQ
The variable WQE mode must be validated against
the maximum slots supported by HW. The max supported
value is 64K. Adding a max and min check and fail if user
supplied value is more than the max supported and zero.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/ib_verbs.c",
"drivers/infiniband/hw/bnxt_re/qplib_sp.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a59d815cbe667929b693b5fa6716a074e6a31c5b",
"status": "affected",
"version": "d8ea645d6984c84a87032063a0941f15a323831f",
"versionType": "git"
},
{
"lessThan": "dc95931b7e1326dacae547874bf38c092e5960d8",
"status": "affected",
"version": "d8ea645d6984c84a87032063a0941f15a323831f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/ib_verbs.c",
"drivers/infiniband/hw/bnxt_re/qplib_sp.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Add a max slot check for SQ\n\nThe variable WQE mode must be validated against\nthe maximum slots supported by HW. The max supported\nvalue is 64K. Adding a max and min check and fail if user\nsupplied value is more than the max supported and zero."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only via local RDMA uverbs ioctl/write on /dev/infiniband/uverbs* (IB_USER_VERBS_CMD_CREATE_QP \u2192 bnxt_re_create_qp \u2192 bnxt_re_init_qp_attr); remote RoCE peers cannot supply the bnxt_re_qp_req.sq_slots field.\nAC:L - On bnxt_re hardware with variable WQE enabled, an attacker deterministically sets sq_slots to 0 or any value above 65536 in create_qp driver udata; no race, timing window, or uncontrollable memory layout is required beyond opening uverbs and issuing the ioctl.\nPR:L - Exploitation requires only local access to the world-accessible (mode 0666) uverbs character device to alloc a VAR_WQE ucontext and create a QP; no CAP_SYS_ADMIN, init-namespace root, or other elevated capability is needed on typical HPC/cloud RDMA hosts.\nUI:N - The attacker triggers the bug entirely through their own alloc_context/create_qp sequence with crafted sq_slots; no cooperative action by another user, administrator, or victim is required.\nS:C - On Kubernetes/HPC hosts that expose bnxt_re to unprivileged RDMA workloads or containers, corrupting host-kernel memory or NIC DMA state from a tenant create_qp escapes the workload security boundary to the hypervisor/host authority.\nC:H - Unvalidated sq_slots drives integer overflow in SQ/PSN byte sizing and can register undersized ib_umem while programming firmware with a far larger sq_size, enabling out-of-bounds DMA reads and kernel memory disclosure beyond the mapped queue buffer.\nI:H - Oversized sq_slots values program hardware queue depth beyond the registered user buffer and corrupt queue/PSN metadata sizing, yielding out-of-bounds writes and exploitable memory corruption rather than a benign error return.\nA:H - Invalid zero or \u003e64K slot counts can kernel-oops during QP setup (e.g., inconsistent HWQ/PSN allocation) and misprogrammed queue depths can panic or hang the host when the adapter accesses nonexistent queue memory."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:44:58.837Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a59d815cbe667929b693b5fa6716a074e6a31c5b"
},
{
"url": "https://git.kernel.org/stable/c/dc95931b7e1326dacae547874bf38c092e5960d8"
}
],
"title": "RDMA/bnxt_re: Add a max slot check for SQ",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72497",
"datePublished": "2026-08-15T05:57:30.386Z",
"dateReserved": "2026-08-09T03:40:39.937Z",
"dateUpdated": "2026-08-17T05:44:58.837Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64342 (GCVE-0-2026-64342)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: iowarrior: fix use-after-free on disconnect
Submitted write URBs are not stopped on close() and therefore need to be
stopped unconditionally on disconnect() to avoid use-after-free in the
completion handler.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 946b960d13c15f050a3b848987aaca79f6a459b7 Version: 946b960d13c15f050a3b848987aaca79f6a459b7 Version: 946b960d13c15f050a3b848987aaca79f6a459b7 Version: 946b960d13c15f050a3b848987aaca79f6a459b7 Version: 946b960d13c15f050a3b848987aaca79f6a459b7 Version: 946b960d13c15f050a3b848987aaca79f6a459b7 Version: 946b960d13c15f050a3b848987aaca79f6a459b7 Version: 946b960d13c15f050a3b848987aaca79f6a459b7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/iowarrior.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d058d377291567b72aea33b017215cbfb383b0ad",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
},
{
"lessThan": "a7bbe946ca3a6eeb6f364d5e84b05e02c7c0d595",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
},
{
"lessThan": "97ad9337127be04ca0b027c2b01e69302353f404",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
},
{
"lessThan": "164398601a7f160bc3df1efa454f983302cef03f",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
},
{
"lessThan": "f328b0e9a0dbd162f5db1b83026b689f2fea2241",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
},
{
"lessThan": "b748f97aff339e7f08dca9cf38a05b980fb66fea",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
},
{
"lessThan": "e4596816984efc537e7c04c1af0c639394f967f7",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
},
{
"lessThan": "bc0e4f16c44e50daa0b1ea729934baa3b4815dee",
"status": "affected",
"version": "946b960d13c15f050a3b848987aaca79f6a459b7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/iowarrior.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.21"
},
{
"lessThan": "2.6.21",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.21",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: iowarrior: fix use-after-free on disconnect\n\nSubmitted write URBs are not stopped on close() and therefore need to be\nstopped unconditionally on disconnect() to avoid use-after-free in the\ncompletion handler."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:46.066Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d058d377291567b72aea33b017215cbfb383b0ad"
},
{
"url": "https://git.kernel.org/stable/c/a7bbe946ca3a6eeb6f364d5e84b05e02c7c0d595"
},
{
"url": "https://git.kernel.org/stable/c/97ad9337127be04ca0b027c2b01e69302353f404"
},
{
"url": "https://git.kernel.org/stable/c/164398601a7f160bc3df1efa454f983302cef03f"
},
{
"url": "https://git.kernel.org/stable/c/f328b0e9a0dbd162f5db1b83026b689f2fea2241"
},
{
"url": "https://git.kernel.org/stable/c/b748f97aff339e7f08dca9cf38a05b980fb66fea"
},
{
"url": "https://git.kernel.org/stable/c/e4596816984efc537e7c04c1af0c639394f967f7"
},
{
"url": "https://git.kernel.org/stable/c/bc0e4f16c44e50daa0b1ea729934baa3b4815dee"
}
],
"title": "USB: iowarrior: fix use-after-free on disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64342",
"datePublished": "2026-07-25T08:50:05.169Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:46.066Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68413 (GCVE-0-2026-68413)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
The memory allocated in the ipw2100_alloc_device() function is not freed
in some of the error paths in ipw2100_pci_init_one(). Fix that by
converting the direct return into a goto to the error path return.
The error path when pci_enable_device() fails cannot jump to fail, since
at this point priv is not set, so perform error handling inline.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intel/ipw2x00/ipw2100.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "71614326ab43e8b8f392ba865aeb6d7e327dff7d",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "9b080198a22fd809c4e7f6793eafab53ac2643fd",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "768a701362a8f77b62c14f8202ad559b7ecbb0c6",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "f75b9a2a9d8334ae0f9c5e47df7b31f7aeb1fdbe",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "836a19c654dcb1b01878a70090af016fbd0fd7e5",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "f442e581a88937671a22ceb3806c186265ef6254",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "7cbda50eebcd9aa00b0de382f776287cf7a36cf8",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "0d388f62031dbabcba0f44bb91b59f10e88cac17",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intel/ipw2x00/ipw2100.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.14"
},
{
"lessThan": "2.6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()\n\nThe memory allocated in the ipw2100_alloc_device() function is not freed\nin some of the error paths in ipw2100_pci_init_one(). Fix that by\nconverting the direct return into a goto to the error path return.\n\nThe error path when pci_enable_device() fails cannot jump to fail, since\nat this point priv is not set, so perform error handling inline."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:10.167Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/71614326ab43e8b8f392ba865aeb6d7e327dff7d"
},
{
"url": "https://git.kernel.org/stable/c/9b080198a22fd809c4e7f6793eafab53ac2643fd"
},
{
"url": "https://git.kernel.org/stable/c/768a701362a8f77b62c14f8202ad559b7ecbb0c6"
},
{
"url": "https://git.kernel.org/stable/c/f75b9a2a9d8334ae0f9c5e47df7b31f7aeb1fdbe"
},
{
"url": "https://git.kernel.org/stable/c/836a19c654dcb1b01878a70090af016fbd0fd7e5"
},
{
"url": "https://git.kernel.org/stable/c/f442e581a88937671a22ceb3806c186265ef6254"
},
{
"url": "https://git.kernel.org/stable/c/7cbda50eebcd9aa00b0de382f776287cf7a36cf8"
},
{
"url": "https://git.kernel.org/stable/c/0d388f62031dbabcba0f44bb91b59f10e88cac17"
}
],
"title": "wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68413",
"datePublished": "2026-08-10T12:04:33.525Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:10.167Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64039 (GCVE-0-2026-64039)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/msm/snapshot: fix dumping of the unaligned regions
The snapshotting code internally aligns data segment to 16 bytes. This
works fine for DPU code (where most of the regions are aligned), but
fails for snapshotting of the DSI data (because DSI data region is
shifted by 4 bytes). Fix the code by removing length alignment and by
accurately printing last registers in the region. While reworking the
code also fix the 16x memory overallocation in
msm_disp_state_dump_regs().
Patchwork: https://patchwork.freedesktop.org/patch/725449/
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 98659487b845c05b6bed85d881713545db674c7c Version: 98659487b845c05b6bed85d881713545db674c7c Version: 98659487b845c05b6bed85d881713545db674c7c Version: 98659487b845c05b6bed85d881713545db674c7c Version: 98659487b845c05b6bed85d881713545db674c7c Version: 98659487b845c05b6bed85d881713545db674c7c Version: 98659487b845c05b6bed85d881713545db674c7c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8fb070cf95847b29ef6cb15ec2c0de2bf4704676",
"status": "affected",
"version": "98659487b845c05b6bed85d881713545db674c7c",
"versionType": "git"
},
{
"lessThan": "cecd34e046121d788a70b5c8b4f8a88916637953",
"status": "affected",
"version": "98659487b845c05b6bed85d881713545db674c7c",
"versionType": "git"
},
{
"lessThan": "070e40acc59ef7bedba0314f59971ba87fcc8ab0",
"status": "affected",
"version": "98659487b845c05b6bed85d881713545db674c7c",
"versionType": "git"
},
{
"lessThan": "1ef79be774706dddcfcace0331fa7ff32a73c73e",
"status": "affected",
"version": "98659487b845c05b6bed85d881713545db674c7c",
"versionType": "git"
},
{
"lessThan": "cdd1aaf0ee962f50810b9aef7928f2313989d55f",
"status": "affected",
"version": "98659487b845c05b6bed85d881713545db674c7c",
"versionType": "git"
},
{
"lessThan": "0c90ececfad3fc5c4c43a75ece0e2d736ab3def1",
"status": "affected",
"version": "98659487b845c05b6bed85d881713545db674c7c",
"versionType": "git"
},
{
"lessThan": "76824d2467feb1828b745d6add2541918d7be3da",
"status": "affected",
"version": "98659487b845c05b6bed85d881713545db674c7c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/snapshot: fix dumping of the unaligned regions\n\nThe snapshotting code internally aligns data segment to 16 bytes. This\nworks fine for DPU code (where most of the regions are aligned), but\nfails for snapshotting of the DSI data (because DSI data region is\nshifted by 4 bytes). Fix the code by removing length alignment and by\naccurately printing last registers in the region. While reworking the\ncode also fix the 16x memory overallocation in\nmsm_disp_state_dump_regs().\n\nPatchwork: https://patchwork.freedesktop.org/patch/725449/"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only from kernel-local display debug/snapshot paths (error handlers, debugfs, devcoredump) in the MSM DRM/KMS driver, not from any network protocol.\nAC:L - On affected Qualcomm DSI 6G hardware the 4-byte register offset makes region sizes non-16-byte-aligned predictably, so once a display snapshot is triggered the out-of-bounds MMIO read and 16\u00d7 over-allocation occur reliably without attacker-dependent race or layout conditions.\nPR:N - Snapshot capture is invoked automatically on display error IRQ/workqueue paths that can be induced by an unprivileged local app stressing the GPU/display pipeline on Android/embedded MSM devices, without root, capabilities, or debugfs access.\nUI:N - Exploitation requires no victim interaction beyond normal device use; display-error snapshots fire from kernel error handlers without the user opening files or mounting filesystems.\nS:U - Impact is confined to kernel/driver state on the local host (crash, MMIO OOB read, memory pressure); it does not cross a VM, container, or IOMMU security boundary.\nC:H - The bug performs out-of-bounds MMIO reads past the mapped DSI register window (up to the alignment padding per block), storing returned hardware register values into the kernel snapshot buffer that is later exposed via devcoredump.\nI:N - The flaw is an out-of-bounds read and erroneous allocation sizing only; it does not corrupt kernel memory or provide a write primitive.\nA:H - Out-of-bounds MMIO accesses can provoke synchronous external aborts/kernel oops on ARM platforms, and the 16\u00d7 per-block over-allocation during error snapshots can exhaust kernel memory and crash or hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:32.825Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8fb070cf95847b29ef6cb15ec2c0de2bf4704676"
},
{
"url": "https://git.kernel.org/stable/c/cecd34e046121d788a70b5c8b4f8a88916637953"
},
{
"url": "https://git.kernel.org/stable/c/070e40acc59ef7bedba0314f59971ba87fcc8ab0"
},
{
"url": "https://git.kernel.org/stable/c/1ef79be774706dddcfcace0331fa7ff32a73c73e"
},
{
"url": "https://git.kernel.org/stable/c/cdd1aaf0ee962f50810b9aef7928f2313989d55f"
},
{
"url": "https://git.kernel.org/stable/c/0c90ececfad3fc5c4c43a75ece0e2d736ab3def1"
},
{
"url": "https://git.kernel.org/stable/c/76824d2467feb1828b745d6add2541918d7be3da"
}
],
"title": "drm/msm/snapshot: fix dumping of the unaligned regions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64039",
"datePublished": "2026-07-19T15:39:26.695Z",
"dateReserved": "2026-07-19T07:54:57.028Z",
"dateUpdated": "2026-08-05T12:38:32.825Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64305 (GCVE-0-2026-64305)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: qat - protect service table iterations with service_lock
The service_table list is protected by service_lock when entries are
added or removed (in adf_service_add() and adf_service_remove()), but
several functions iterate over the list without holding this lock.
A concurrent adf_service_register() or adf_service_unregister() call
could modify the list during traversal, leading to list corruption or
a use-after-free.
Fix this by holding service_lock across all list_for_each_entry()
iterations of service_table in adf_dev_init(), adf_dev_start(),
adf_dev_stop(), adf_dev_shutdown(), adf_dev_restarting_notify(),
adf_dev_restarted_notify(), and adf_error_notifier().
The lock ordering is safe: callers of the static helpers (adf_dev_up()
and adf_dev_down()) acquire state_lock before service_lock, and no
event_hld callback or service_lock holder ever acquires state_lock in
the reverse order.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/crypto/intel/qat/qat_common/adf_init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "222fa7b453b612f4407f260146d89a2ce2bc831d",
"status": "affected",
"version": "d8cba25d2c68992a6e7c1d329b690a9ebe01167d",
"versionType": "git"
},
{
"lessThan": "c3c5925791cff3b84d313293fd60f384d877d793",
"status": "affected",
"version": "d8cba25d2c68992a6e7c1d329b690a9ebe01167d",
"versionType": "git"
},
{
"lessThan": "0dbcecea740d943002c1cbdafa39bdfc108e32a5",
"status": "affected",
"version": "d8cba25d2c68992a6e7c1d329b690a9ebe01167d",
"versionType": "git"
},
{
"lessThan": "5c6f845e77ec35f9b7b047cc8f9789bf397cdd3e",
"status": "affected",
"version": "d8cba25d2c68992a6e7c1d329b690a9ebe01167d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/crypto/intel/qat/qat_common/adf_init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - protect service table iterations with service_lock\n\nThe service_table list is protected by service_lock when entries are\nadded or removed (in adf_service_add() and adf_service_remove()), but\nseveral functions iterate over the list without holding this lock.\n\nA concurrent adf_service_register() or adf_service_unregister() call\ncould modify the list during traversal, leading to list corruption or\na use-after-free.\n\nFix this by holding service_lock across all list_for_each_entry()\niterations of service_table in adf_dev_init(), adf_dev_start(),\nadf_dev_stop(), adf_dev_shutdown(), adf_dev_restarting_notify(),\nadf_dev_restarted_notify(), and adf_error_notifier().\n\nThe lock ordering is safe: callers of the static helpers (adf_dev_up()\nand adf_dev_down()) acquire state_lock before service_lock, and no\nevent_hld callback or service_lock holder ever acquires state_lock in\nthe reverse order."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:04.376Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/222fa7b453b612f4407f260146d89a2ce2bc831d"
},
{
"url": "https://git.kernel.org/stable/c/c3c5925791cff3b84d313293fd60f384d877d793"
},
{
"url": "https://git.kernel.org/stable/c/0dbcecea740d943002c1cbdafa39bdfc108e32a5"
},
{
"url": "https://git.kernel.org/stable/c/5c6f845e77ec35f9b7b047cc8f9789bf397cdd3e"
}
],
"title": "crypto: qat - protect service table iterations with service_lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64305",
"datePublished": "2026-07-25T08:49:39.536Z",
"dateReserved": "2026-07-19T15:36:31.779Z",
"dateUpdated": "2026-08-17T04:53:04.376Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64546 (GCVE-0-2026-64546)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/edid: fix OOB read in drm_parse_tiled_block()
drm_parse_tiled_block() casts the DisplayID block to a
struct displayid_tiled_block and reads the full fixed layout up to
tile->topology_id[7] without checking block->num_bytes. The DisplayID
iterator only validates the declared payload length, so a crafted EDID
can advertise a tiled-display block (tag DATA_BLOCK_TILED_DISPLAY, or
DATA_BLOCK_2_TILED_DISPLAY_TOPOLOGY for v2.0) with a small num_bytes at
the end of a DisplayID extension. The read then runs past the end of the
exact-sized kmemdup()'d EDID allocation, a heap out-of-bounds read.
Reject blocks shorter than the spec's 22-byte tiled payload before
reading the fixed struct, as drm_parse_vesa_mso_data() already does.
BUG: KASAN: slab-out-of-bounds in drm_edid_connector_update
Read of size 2 at addr ffff888010077700 by task exploit/147
dump_stack_lvl (lib/dump_stack.c:94 ...)
print_report (mm/kasan/report.c:378 ...)
kasan_report (mm/kasan/report.c:595)
drm_edid_connector_update (drivers/gpu/drm/drm_edid.c:7581)
bochs_connector_helper_get_modes (drivers/gpu/drm/tiny/bochs.c:574)
drm_helper_probe_single_connector_modes (drivers/gpu/drm/drm_probe_helper.c:426)
status_store (drivers/gpu/drm/drm_sysfs.c:219)
...
vfs_write (fs/read_write.c:595 fs/read_write.c:688)
ksys_write (fs/read_write.c:740)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 40d9b043a89e2301e1f97ade055a73ecc28e9afe Version: 40d9b043a89e2301e1f97ade055a73ecc28e9afe Version: 40d9b043a89e2301e1f97ade055a73ecc28e9afe Version: 40d9b043a89e2301e1f97ade055a73ecc28e9afe Version: 40d9b043a89e2301e1f97ade055a73ecc28e9afe Version: 40d9b043a89e2301e1f97ade055a73ecc28e9afe Version: 40d9b043a89e2301e1f97ade055a73ecc28e9afe Version: 40d9b043a89e2301e1f97ade055a73ecc28e9afe |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/drm_edid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c4ab04ca1bbf87eefa9fec5c80e1880450d2e7c0",
"status": "affected",
"version": "40d9b043a89e2301e1f97ade055a73ecc28e9afe",
"versionType": "git"
},
{
"lessThan": "9acd5c1ddc17ca4c5ffa0c373e3fdf480506e061",
"status": "affected",
"version": "40d9b043a89e2301e1f97ade055a73ecc28e9afe",
"versionType": "git"
},
{
"lessThan": "157727131ce8a52d8d9bc676c372ef82db6436c4",
"status": "affected",
"version": "40d9b043a89e2301e1f97ade055a73ecc28e9afe",
"versionType": "git"
},
{
"lessThan": "bfa05d89dc3ca3fb1a9099ef5185549a5ec8490d",
"status": "affected",
"version": "40d9b043a89e2301e1f97ade055a73ecc28e9afe",
"versionType": "git"
},
{
"lessThan": "4f5484d25f85ad6c989bad5f6a43450cecfcfd28",
"status": "affected",
"version": "40d9b043a89e2301e1f97ade055a73ecc28e9afe",
"versionType": "git"
},
{
"lessThan": "9cc0f8e63e8c34cf43def35cbd305ba711181a1f",
"status": "affected",
"version": "40d9b043a89e2301e1f97ade055a73ecc28e9afe",
"versionType": "git"
},
{
"lessThan": "4137e1ecec9c8cb6c4fcee28ffabbbc7409eb7fb",
"status": "affected",
"version": "40d9b043a89e2301e1f97ade055a73ecc28e9afe",
"versionType": "git"
},
{
"lessThan": "faaa1e1155833e7d4ce7e3cfaf64c0d636b190db",
"status": "affected",
"version": "40d9b043a89e2301e1f97ade055a73ecc28e9afe",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/drm_edid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/edid: fix OOB read in drm_parse_tiled_block()\n\ndrm_parse_tiled_block() casts the DisplayID block to a\nstruct displayid_tiled_block and reads the full fixed layout up to\ntile-\u003etopology_id[7] without checking block-\u003enum_bytes. The DisplayID\niterator only validates the declared payload length, so a crafted EDID\ncan advertise a tiled-display block (tag DATA_BLOCK_TILED_DISPLAY, or\nDATA_BLOCK_2_TILED_DISPLAY_TOPOLOGY for v2.0) with a small num_bytes at\nthe end of a DisplayID extension. The read then runs past the end of the\nexact-sized kmemdup()\u0027d EDID allocation, a heap out-of-bounds read.\n\nReject blocks shorter than the spec\u0027s 22-byte tiled payload before\nreading the fixed struct, as drm_parse_vesa_mso_data() already does.\n\n BUG: KASAN: slab-out-of-bounds in drm_edid_connector_update\n Read of size 2 at addr ffff888010077700 by task exploit/147\n dump_stack_lvl (lib/dump_stack.c:94 ...)\n print_report (mm/kasan/report.c:378 ...)\n kasan_report (mm/kasan/report.c:595)\n drm_edid_connector_update (drivers/gpu/drm/drm_edid.c:7581)\n bochs_connector_helper_get_modes (drivers/gpu/drm/tiny/bochs.c:574)\n drm_helper_probe_single_connector_modes (drivers/gpu/drm/drm_probe_helper.c:426)\n status_store (drivers/gpu/drm/drm_sysfs.c:219)\n ...\n vfs_write (fs/read_write.c:595 fs/read_write.c:688)\n ksys_write (fs/read_write.c:740)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The crafted EDID reaches the parser through a local device node \u2014 an unprivileged DRM client supplying a raw EDID buffer via the exynos vidi `DRM_AUTH` ioctl, or root via the connector\u0027s debugfs `edid_override` plus a sysfs re-probe. No network path exists, and local ioctl delivery is the lowest-friction vector (a physically attached malicious monitor/dock is an additional, equally automatic route).\nAC:L - The attacker fully controls the EDID bytes and only needs to place a tiled-display DisplayID block with a small `num_bytes` at the tail of the last extension block; `drm_edid_valid()` checks nothing but the header and checksums, which the attacker computes. No race and no memory-layout precondition is needed to trigger the read.\nPR:L - Handing an arbitrary EDID to `drm_edid_connector_update()` via `DRM_IOCTL_EXYNOS_VIDI_CONNECTION` requires only an authenticated DRM client (`DRM_AUTH`), i.e. an ordinary logged-in user with access to /dev/dri \u2014 no CAP_SYS_ADMIN and no root.\nUI:N - The attacker drives the connector probe itself through the ioctl, and on the hotplug path the EDID is read and parsed automatically by the kernel. No victim action is involved.\nS:U - The out-of-bounds read stays within the kernel\u0027s own heap and the impact is confined to the kernel security authority; no hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - Up to ~21 bytes of adjacent slab memory are read past the exact-size EDID allocation, and eight of those bytes are persisted into the connector\u0027s tile fields and handed back to userspace in the TILE property blob via `DRM_IOCTL_MODE_GETPROPBLOB`, giving a repeatable heap-content leak usable to defeat KASLR or recover neighbouring object data.\nI:N - The defect is purely a read; `drm_mode_create_tile_group()` copies the OOB source into a properly sized destination, so no out-of-bounds write or control-flow corruption occurs.\nA:H - The read runs past the end of the slab object and, for exact-fit allocations at a slab boundary, can touch unmapped memory; on KASAN or panic_on_warn kernels it is an immediate fatal report, and the resulting garbage tile geometry is propagated to the modesetting path."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:23.260Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c4ab04ca1bbf87eefa9fec5c80e1880450d2e7c0"
},
{
"url": "https://git.kernel.org/stable/c/9acd5c1ddc17ca4c5ffa0c373e3fdf480506e061"
},
{
"url": "https://git.kernel.org/stable/c/157727131ce8a52d8d9bc676c372ef82db6436c4"
},
{
"url": "https://git.kernel.org/stable/c/bfa05d89dc3ca3fb1a9099ef5185549a5ec8490d"
},
{
"url": "https://git.kernel.org/stable/c/4f5484d25f85ad6c989bad5f6a43450cecfcfd28"
},
{
"url": "https://git.kernel.org/stable/c/9cc0f8e63e8c34cf43def35cbd305ba711181a1f"
},
{
"url": "https://git.kernel.org/stable/c/4137e1ecec9c8cb6c4fcee28ffabbbc7409eb7fb"
},
{
"url": "https://git.kernel.org/stable/c/faaa1e1155833e7d4ce7e3cfaf64c0d636b190db"
}
],
"title": "drm/edid: fix OOB read in drm_parse_tiled_block()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64546",
"datePublished": "2026-07-27T20:10:37.217Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:23.260Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74512 (GCVE-0-2026-74512)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
audit: fix potential use-after-free in audit_del_rule()
`audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()`
before unlinking the rule from RCU-visible filter lists and waiting for a
grace period. Concurrent readers in `audit_filter()` and
`audit_filter_rules()` still dereference `e->rule.exe`, while the fsnotify
mark can be freed on an independent lifetime path. This creates a
use-after-free window during rule deletion.
Fix this by unlinking the rule from the RCU-visible lists and invoking
`synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other
rule removal helpers). This ensures that all existing RCU readers have
exited the critical section before any underlying resources are destroyed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/auditfilter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "93616c567469510b7bba55b2674e0c4523fd7e64",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "3f82927b399d7a276c0c12b6ff4424b747a0c9a7",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "8ae135a8962be9d4e8a131eb18eb06cdf02a47ce",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "45bf3df5b32e5a49953e7ceabc55f7dd85380e46",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "78bde7e9bd36eaae1b8e8cfcd47f12a34f301dbf",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "cae0dfed5d307b240bff71c3cf206652d1b6f215",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "5b8f46864f06d6dbacb7dcea52bc084dfd122638",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "246df90b5f1a8a6e6abbd2f058b029558720adec",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/auditfilter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.3"
},
{
"lessThan": "4.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix potential use-after-free in audit_del_rule()\n\n`audit_del_rule()` destroys `e-\u003erule.exe` via `audit_remove_mark_rule()`\nbefore unlinking the rule from RCU-visible filter lists and waiting for a\ngrace period. Concurrent readers in `audit_filter()` and\n`audit_filter_rules()` still dereference `e-\u003erule.exe`, while the fsnotify\nmark can be freed on an independent lifetime path. This creates a\nuse-after-free window during rule deletion.\n\nFix this by unlinking the rule from the RCU-visible lists and invoking\n`synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other\nrule removal helpers). This ensures that all existing RCU readers have\nexited the critical section before any underlying resources are destroyed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reachable only via local NETLINK_AUDIT (AUDIT_DEL_RULE) or filesystem events that autoremove AUDIT_EXE rules; concurrent UAF readers run in syscall/io_uring exit audit filtering on the local host, not from remote network input.\nAC:L - The attacker controls both sides of the race by deleting an AUDIT_EXE rule (auditctl or deleting/moving the audited executable) while driving concurrent syscall/io_uring activity to keep RCU readers in audit_filter()/audit_filter_rules().\nPR:L - Besides CAP_AUDIT_CONTROL netlink deletion, unprivileged local users can trigger audit_del_rule() via fsnotify autoremove when deleting/moving an admin-configured audited executable they can write, without init-namespace root.\nUI:N - Exploitation requires no victim interaction; the attacker schedules rule deletion and concurrent audited syscalls/io_uring exits to hit the UAF window.\nS:U - Impact is kernel heap memory corruption and local privilege escalation within the host kernel security domain, not a documented cross-VM or IOMMU boundary escape.\nC:H - Use-after-free of audit_fsnotify_mark while audit_exe_compare()/audit_mark_compare() dereference mark-\u003eino/dev enables arbitrary kernel memory reads and info disclosure primitives.\nI:H - Freed fsnotify mark objects can be reallocated and corrupted to obtain arbitrary kernel writes, control-flow hijack, and local root code execution beyond audit rule deletion.\nA:H - Concurrent dereference of a freed audit_fsnotify_mark during audit filtering can immediately oops/panic the kernel; repeated triggering yields reliable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:09.879Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/93616c567469510b7bba55b2674e0c4523fd7e64"
},
{
"url": "https://git.kernel.org/stable/c/3f82927b399d7a276c0c12b6ff4424b747a0c9a7"
},
{
"url": "https://git.kernel.org/stable/c/8ae135a8962be9d4e8a131eb18eb06cdf02a47ce"
},
{
"url": "https://git.kernel.org/stable/c/45bf3df5b32e5a49953e7ceabc55f7dd85380e46"
},
{
"url": "https://git.kernel.org/stable/c/78bde7e9bd36eaae1b8e8cfcd47f12a34f301dbf"
},
{
"url": "https://git.kernel.org/stable/c/cae0dfed5d307b240bff71c3cf206652d1b6f215"
},
{
"url": "https://git.kernel.org/stable/c/5b8f46864f06d6dbacb7dcea52bc084dfd122638"
},
{
"url": "https://git.kernel.org/stable/c/246df90b5f1a8a6e6abbd2f058b029558720adec"
}
],
"title": "audit: fix potential use-after-free in audit_del_rule()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74512",
"datePublished": "2026-08-15T12:27:33.736Z",
"dateReserved": "2026-08-15T05:44:03.909Z",
"dateUpdated": "2026-08-19T16:38:09.879Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53381 (GCVE-0-2026-53381)
Vulnerability from cvelistv5
Published
2026-07-19 11:59
Modified
2026-08-17 04:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
virtiofs: fix UAF on submount umount
iput() called from fuse_release_end() can Oops if the super block has
already been destroyed. Normally this is prevented by waiting for
num_waiting to go down to zero before commencing with super block shutdown.
This only works, however, for the last submount instance, as the wait
counter is per connection, not per superblock.
Revert to using synchronous release requests for the auto_submounts case,
which is virtiofs only at this time.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 548e1f2bac1d4df91a6138f26bb4ab00323fd948 Version: cfd1aa3e2b71f3327cb373c45a897c9028c62b35 Version: 83b375c6efef69b1066ad2d79601221e7892745a Version: bfd17b6138df0122a95989457d8e18ce0b86165e Version: b26923512dbe57ae4917bafd31396d22a9d1691a Version: 26e5c67deb2e1f42a951f022fdf5b9f7eb747b01 Version: 26e5c67deb2e1f42a951f022fdf5b9f7eb747b01 Version: 26e5c67deb2e1f42a951f022fdf5b9f7eb747b01 Version: 26e5c67deb2e1f42a951f022fdf5b9f7eb747b01 Version: f19a1390af448d9e193c08e28ea5f727bf3c3049 Version: 5.10.246 ≤ Version: 5.15.196 ≤ Version: 6.1.158 ≤ Version: 6.6.115 ≤ Version: 6.12.54 ≤ Version: 6.17.4 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/fuse/file.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "607a1d4c42f649e6197567c0448fd9ebb316cd42",
"status": "affected",
"version": "548e1f2bac1d4df91a6138f26bb4ab00323fd948",
"versionType": "git"
},
{
"lessThan": "1cc0e3a0c6499aaaa2f21a4fcbba388486afb25e",
"status": "affected",
"version": "cfd1aa3e2b71f3327cb373c45a897c9028c62b35",
"versionType": "git"
},
{
"lessThan": "0b809199ff87c44487e516a725dd4be2185712ce",
"status": "affected",
"version": "83b375c6efef69b1066ad2d79601221e7892745a",
"versionType": "git"
},
{
"lessThan": "2181a09ba980f142650fb053666350ead4471cfe",
"status": "affected",
"version": "bfd17b6138df0122a95989457d8e18ce0b86165e",
"versionType": "git"
},
{
"lessThan": "97c4691653d145dcc699eca5d3aba3219a520f1f",
"status": "affected",
"version": "b26923512dbe57ae4917bafd31396d22a9d1691a",
"versionType": "git"
},
{
"lessThan": "2abfd3ffbd9452f72535d96ff3982b3ab1f8f2f9",
"status": "affected",
"version": "26e5c67deb2e1f42a951f022fdf5b9f7eb747b01",
"versionType": "git"
},
{
"lessThan": "39a2b95e008665c14f84e50ed411d898df7cd11b",
"status": "affected",
"version": "26e5c67deb2e1f42a951f022fdf5b9f7eb747b01",
"versionType": "git"
},
{
"lessThan": "e09412a714bcd49375198427bb4aa005037a9d6f",
"status": "affected",
"version": "26e5c67deb2e1f42a951f022fdf5b9f7eb747b01",
"versionType": "git"
},
{
"lessThan": "06b41351779e9289e8785694ade9042ae85e41ea",
"status": "affected",
"version": "26e5c67deb2e1f42a951f022fdf5b9f7eb747b01",
"versionType": "git"
},
{
"status": "affected",
"version": "f19a1390af448d9e193c08e28ea5f727bf3c3049",
"versionType": "git"
},
{
"lessThan": "5.10.260",
"status": "affected",
"version": "5.10.246",
"versionType": "semver"
},
{
"lessThan": "5.15.211",
"status": "affected",
"version": "5.15.196",
"versionType": "semver"
},
{
"lessThan": "6.1.177",
"status": "affected",
"version": "6.1.158",
"versionType": "semver"
},
{
"lessThan": "6.6.144",
"status": "affected",
"version": "6.6.115",
"versionType": "semver"
},
{
"lessThan": "6.12.95",
"status": "affected",
"version": "6.12.54",
"versionType": "semver"
},
{
"lessThan": "6.18",
"status": "affected",
"version": "6.17.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/fuse/file.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"lessThan": "6.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.260",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.37",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.260",
"versionStartIncluding": "5.10.246",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "5.15.196",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "6.1.158",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.6.115",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.12.54",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.37",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.14",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.2",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.17.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtiofs: fix UAF on submount umount\n\niput() called from fuse_release_end() can Oops if the super block has\nalready been destroyed. Normally this is prevented by waiting for\nnum_waiting to go down to zero before commencing with super block shutdown.\n\nThis only works, however, for the last submount instance, as the wait\ncounter is per connection, not per superblock.\n\nRevert to using synchronous release requests for the auto_submounts case,\nwhich is virtiofs only at this time."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through local VFS operations (open/write/close) on a virtiofs mount with FUSE submounts; exploitation is in the guest FUSE client during file release and submount umount, not via remote network packets.\nAC:L - This is a use-after-free where the attacker controls file close (async FUSE RELEASE) and can drive or coincide with submount umount; Kata Containers reproduces it reliably with virtiofsd --announce-submounts (default).\nPR:L - An unprivileged local process with access to the virtiofs mount can trigger it; virtiofs defaults to allow_other and normal POSIX permissions, and no real root or init-namespace capabilities are required.\nUI:N - Exploitation needs no victim interaction beyond the attacker (or their container workload) performing normal filesystem I/O while submount teardown occurs during pod/container lifecycle.\nS:U - Impact stays within the guest kernel security boundary (crash or guest kernel compromise); it does not by itself cross a VM/host or IOMMU boundary.\nC:H - The flaw is a use-after-free in fuse_release_end() calling iput() on an inode after its superblock is destroyed, which can be turned into arbitrary kernel memory read via heap manipulation.\nI:H - Use-after-free on a struct inode in the kernel heap provides a standard path to controlled memory corruption, heap spraying, and arbitrary write or code execution in kernel context.\nA:H - Confirmed kernel general protection fault/oops in iput() from fuse_release_end during virtio_fs request completion, and UAF bugs inherently threaten kernel stability even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:50:31.586Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/607a1d4c42f649e6197567c0448fd9ebb316cd42"
},
{
"url": "https://git.kernel.org/stable/c/1cc0e3a0c6499aaaa2f21a4fcbba388486afb25e"
},
{
"url": "https://git.kernel.org/stable/c/0b809199ff87c44487e516a725dd4be2185712ce"
},
{
"url": "https://git.kernel.org/stable/c/2181a09ba980f142650fb053666350ead4471cfe"
},
{
"url": "https://git.kernel.org/stable/c/97c4691653d145dcc699eca5d3aba3219a520f1f"
},
{
"url": "https://git.kernel.org/stable/c/2abfd3ffbd9452f72535d96ff3982b3ab1f8f2f9"
},
{
"url": "https://git.kernel.org/stable/c/39a2b95e008665c14f84e50ed411d898df7cd11b"
},
{
"url": "https://git.kernel.org/stable/c/e09412a714bcd49375198427bb4aa005037a9d6f"
},
{
"url": "https://git.kernel.org/stable/c/06b41351779e9289e8785694ade9042ae85e41ea"
}
],
"title": "virtiofs: fix UAF on submount umount",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53381",
"datePublished": "2026-07-19T11:59:30.469Z",
"dateReserved": "2026-06-09T07:44:35.401Z",
"dateUpdated": "2026-08-17T04:50:31.586Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68162 (GCVE-0-2026-68162)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: avoid auth_enable sysctl UAF during netns teardown
proc_sctp_do_auth() updates the SCTP control socket after changing
net.sctp.auth_enable. The handler gets the per-net SCTP state from
ctl->data, so an already opened sysctl file can still target a network
namespace while that namespace is being torn down.
SCTP previously registered its per-net sysctls from sctp_defaults_init(),
while the control socket is created later from sctp_ctrlsock_init(). This
exposed a window during initialization where auth_enable was writable
before net->sctp.ctl_sock existed, and a teardown window where auth_enable
stayed writable after inet_ctl_sock_destroy() had released the control
socket.
Move the per-net SCTP sysctl registration into sctp_ctrlsock_init() after
sctp_ctl_sock_init() succeeds, and unregister the sysctl table before
destroying the control socket in sctp_ctrlsock_exit(). If sysctl
registration fails after the control socket was created, destroy the
control socket in the same init path.
Make sctp_sysctl_net_unregister() tolerate a missing header and clear the
saved pointer so init-error and exit paths can safely share the unregister
helper.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 10c869a52f266e40f548cc3c565d14930a5edafc Version: dc583e7e5f8515ca489c0df28e4362a70eade382 Version: bd2a2939423566c654545fa3e96a656662a0af9e Version: 1b67030d39f2b00f94ac1f0af11ba6657589e4d3 Version: 7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6 Version: c184bc621e3cef03ac9ba81a50dda2dae6a21d36 Version: 15649fd5415eda664ef35780c2013adeb5d9c695 Version: 15649fd5415eda664ef35780c2013adeb5d9c695 Version: 15649fd5415eda664ef35780c2013adeb5d9c695 Version: 5.4.290 ≤ Version: 5.10.234 ≤ Version: 5.15.177 ≤ Version: 6.1.125 ≤ Version: 6.6.72 ≤ Version: 6.12.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/protocol.c",
"net/sctp/sysctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4",
"status": "affected",
"version": "10c869a52f266e40f548cc3c565d14930a5edafc",
"versionType": "git"
},
{
"lessThan": "ceb7190b5c873d4a1267a1600c5aa52c600e929f",
"status": "affected",
"version": "dc583e7e5f8515ca489c0df28e4362a70eade382",
"versionType": "git"
},
{
"lessThan": "fd66854a22661929245f3d2b244c432bc8b1a150",
"status": "affected",
"version": "bd2a2939423566c654545fa3e96a656662a0af9e",
"versionType": "git"
},
{
"lessThan": "158f3cc332dc53f43ec20060233d7c3cecd6d912",
"status": "affected",
"version": "1b67030d39f2b00f94ac1f0af11ba6657589e4d3",
"versionType": "git"
},
{
"lessThan": "66700c0719675e0e118ae83b2d7168dacd69dd3d",
"status": "affected",
"version": "7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6",
"versionType": "git"
},
{
"lessThan": "626bda8cfe43dff19a9833ff6ba055a817b5455c",
"status": "affected",
"version": "c184bc621e3cef03ac9ba81a50dda2dae6a21d36",
"versionType": "git"
},
{
"lessThan": "be6aae9d1b91c603adb35872d37d40e83daf8758",
"status": "affected",
"version": "15649fd5415eda664ef35780c2013adeb5d9c695",
"versionType": "git"
},
{
"lessThan": "a50e73488e0bbdd262b3be3c9a1d8dd078382381",
"status": "affected",
"version": "15649fd5415eda664ef35780c2013adeb5d9c695",
"versionType": "git"
},
{
"lessThan": "f8d5e7846025f4ab15a461235f8ebae9094a361a",
"status": "affected",
"version": "15649fd5415eda664ef35780c2013adeb5d9c695",
"versionType": "git"
},
{
"lessThan": "5.4.292",
"status": "affected",
"version": "5.4.290",
"versionType": "semver"
},
{
"lessThan": "5.10.266",
"status": "affected",
"version": "5.10.234",
"versionType": "semver"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.177",
"versionType": "semver"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.125",
"versionType": "semver"
},
{
"lessThan": "6.6.151",
"status": "affected",
"version": "6.6.72",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/protocol.c",
"net/sctp/sysctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.292",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.292",
"versionStartIncluding": "5.4.290",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10.234",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.177",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.125",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.6.72",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: avoid auth_enable sysctl UAF during netns teardown\n\nproc_sctp_do_auth() updates the SCTP control socket after changing\nnet.sctp.auth_enable. The handler gets the per-net SCTP state from\nctl-\u003edata, so an already opened sysctl file can still target a network\nnamespace while that namespace is being torn down.\n\nSCTP previously registered its per-net sysctls from sctp_defaults_init(),\nwhile the control socket is created later from sctp_ctrlsock_init(). This\nexposed a window during initialization where auth_enable was writable\nbefore net-\u003esctp.ctl_sock existed, and a teardown window where auth_enable\nstayed writable after inet_ctl_sock_destroy() had released the control\nsocket.\n\nMove the per-net SCTP sysctl registration into sctp_ctrlsock_init() after\nsctp_ctl_sock_init() succeeds, and unregister the sysctl table before\ndestroying the control socket in sctp_ctrlsock_exit(). If sysctl\nregistration fails after the control socket was created, destroy the\ncontrol socket in the same init path.\n\nMake sctp_sysctl_net_unregister() tolerate a missing header and clear the\nsaved pointer so init-error and exit paths can safely share the unregister\nhelper."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is triggered only by writing the per-net sysctl net.sctp.auth_enable via /proc/sys (proc_sctp_do_auth); it is not reachable from SCTP packet receive, sockets, or other remote protocol paths.\nAC:L - An attacker can open the sysctl file, concurrently destroy the target network namespace, and repeatedly write during teardown; pernet exit destroys ctl_sock before unregistering sysctls, and the attacker controls both sides of that race.\nPR:L - Exploitation requires writing a mode 0644 sysctl in a network namespace; an unprivileged host user with CAP_NET_ADMIN via user namespaces can create a netns, become namespace root, and write net/sctp/auth_enable without init-namespace privileges.\nUI:N - No victim interaction is required beyond the attacker opening the sysctl and triggering namespace teardown in their own threads or processes.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same host/kernel security domain; it does not cross VM, container, or IOMMU boundaries by itself.\nC:H - proc_sctp_do_auth dereferences net-\u003esctp.ctl_sock after inet_ctl_sock_destroy; lock_sock and sctp_sk(sk)-\u003eep access freed socket/endpoint memory, a use-after-free that can disclose or infer heap contents.\nI:H - On a successful write, the handler sets sctp_sk(sk)-\u003eep-\u003eauth_enable on a freed endpoint object, giving a controlled heap write primitive that can be developed into arbitrary kernel modification or code execution.\nA:H - Use-after-free on the SCTP control socket/endpoint during sysctl processing can cause kernel oops/panic from lock_sock or ep access on freed memory, even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:01.222Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4"
},
{
"url": "https://git.kernel.org/stable/c/ceb7190b5c873d4a1267a1600c5aa52c600e929f"
},
{
"url": "https://git.kernel.org/stable/c/fd66854a22661929245f3d2b244c432bc8b1a150"
},
{
"url": "https://git.kernel.org/stable/c/158f3cc332dc53f43ec20060233d7c3cecd6d912"
},
{
"url": "https://git.kernel.org/stable/c/66700c0719675e0e118ae83b2d7168dacd69dd3d"
},
{
"url": "https://git.kernel.org/stable/c/626bda8cfe43dff19a9833ff6ba055a817b5455c"
},
{
"url": "https://git.kernel.org/stable/c/be6aae9d1b91c603adb35872d37d40e83daf8758"
},
{
"url": "https://git.kernel.org/stable/c/a50e73488e0bbdd262b3be3c9a1d8dd078382381"
},
{
"url": "https://git.kernel.org/stable/c/f8d5e7846025f4ab15a461235f8ebae9094a361a"
}
],
"title": "sctp: avoid auth_enable sysctl UAF during netns teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68162",
"datePublished": "2026-08-10T11:59:29.099Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-23T12:46:01.222Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64275 (GCVE-0-2026-64275)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: elan_i2c - prevent division by zero and arithmetic underflow
The Elan I2C touchpad driver queries the device for its physical
dimensions and trace counts to calculate the device resolution and width.
However, if the device firmware or device tree provides invalid zero
values for x_traces or y_traces, it results in a fatal division-by-zero
exception leading to a kernel panic during device probe.
Add checks to ensure these parameters are non-zero before performing
the division. If invalid trace values are detected, fall back to a safe
default of 1.
Additionally, prevent an arithmetic underflow in the touch reporting
logic. Previously, if the calculated or fallback width was smaller than
ETP_FWIDTH_REDUCE (90), the subtraction would underflow, resulting in a
massive unsigned integer being reported to userspace. Clamp the adjusted
width to a minimum of 0 to safely handle small physical dimensions and
fallback scenarios.
Completing the probe with safe fallback values ensures the sysfs nodes
are created, keeping the firmware update path intact so a recovery
firmware can be flashed to the device.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6696777c6506fa52b2a0282121195843ed855be6 Version: 6696777c6506fa52b2a0282121195843ed855be6 Version: 6696777c6506fa52b2a0282121195843ed855be6 Version: 6696777c6506fa52b2a0282121195843ed855be6 Version: 6696777c6506fa52b2a0282121195843ed855be6 Version: 6696777c6506fa52b2a0282121195843ed855be6 Version: 6696777c6506fa52b2a0282121195843ed855be6 Version: 6696777c6506fa52b2a0282121195843ed855be6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/mouse/elan_i2c_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "59d4cc5e7a9785e4bdc9c55273274c6b49d4b58d",
"status": "affected",
"version": "6696777c6506fa52b2a0282121195843ed855be6",
"versionType": "git"
},
{
"lessThan": "f6d10af2036d1d4a847a74fe47ebbf93bce3c84c",
"status": "affected",
"version": "6696777c6506fa52b2a0282121195843ed855be6",
"versionType": "git"
},
{
"lessThan": "2f281ff0163a38fdc4cb4061f0c241e643283a5e",
"status": "affected",
"version": "6696777c6506fa52b2a0282121195843ed855be6",
"versionType": "git"
},
{
"lessThan": "8c1db3418a419e788691746b9c47f863c2fd4890",
"status": "affected",
"version": "6696777c6506fa52b2a0282121195843ed855be6",
"versionType": "git"
},
{
"lessThan": "feb4866a42ec94764c7eb58012256f6f37664727",
"status": "affected",
"version": "6696777c6506fa52b2a0282121195843ed855be6",
"versionType": "git"
},
{
"lessThan": "01e0317c256c560d8dcce2e9825eb6142ee34611",
"status": "affected",
"version": "6696777c6506fa52b2a0282121195843ed855be6",
"versionType": "git"
},
{
"lessThan": "6bac57d8fe2a077b8a85b4140eeb7999078158eb",
"status": "affected",
"version": "6696777c6506fa52b2a0282121195843ed855be6",
"versionType": "git"
},
{
"lessThan": "df2b818fa009c10ff6ba875a1663ff001cda9558",
"status": "affected",
"version": "6696777c6506fa52b2a0282121195843ed855be6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/mouse/elan_i2c_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: elan_i2c - prevent division by zero and arithmetic underflow\n\nThe Elan I2C touchpad driver queries the device for its physical\ndimensions and trace counts to calculate the device resolution and width.\nHowever, if the device firmware or device tree provides invalid zero\nvalues for x_traces or y_traces, it results in a fatal division-by-zero\nexception leading to a kernel panic during device probe.\n\nAdd checks to ensure these parameters are non-zero before performing\nthe division. If invalid trace values are detected, fall back to a safe\ndefault of 1.\n\nAdditionally, prevent an arithmetic underflow in the touch reporting\nlogic. Previously, if the calculated or fallback width was smaller than\nETP_FWIDTH_REDUCE (90), the subtraction would underflow, resulting in a\nmassive unsigned integer being reported to userspace. Clamp the adjusted\nwidth to a minimum of 0 to safely handle small physical dimensions and\nfallback scenarios.\n\nCompleting the probe with safe fallback values ensures the sysfs nodes\nare created, keeping the firmware update path intact so a recovery\nfirmware can be flashed to the device."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:29.928Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/59d4cc5e7a9785e4bdc9c55273274c6b49d4b58d"
},
{
"url": "https://git.kernel.org/stable/c/f6d10af2036d1d4a847a74fe47ebbf93bce3c84c"
},
{
"url": "https://git.kernel.org/stable/c/2f281ff0163a38fdc4cb4061f0c241e643283a5e"
},
{
"url": "https://git.kernel.org/stable/c/8c1db3418a419e788691746b9c47f863c2fd4890"
},
{
"url": "https://git.kernel.org/stable/c/feb4866a42ec94764c7eb58012256f6f37664727"
},
{
"url": "https://git.kernel.org/stable/c/01e0317c256c560d8dcce2e9825eb6142ee34611"
},
{
"url": "https://git.kernel.org/stable/c/6bac57d8fe2a077b8a85b4140eeb7999078158eb"
},
{
"url": "https://git.kernel.org/stable/c/df2b818fa009c10ff6ba875a1663ff001cda9558"
}
],
"title": "Input: elan_i2c - prevent division by zero and arithmetic underflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64275",
"datePublished": "2026-07-25T08:49:20.669Z",
"dateReserved": "2026-07-19T15:36:31.776Z",
"dateUpdated": "2026-08-17T04:52:29.928Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64443 (GCVE-0-2026-64443)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
The IE parsing loop in update_beacon_info() advances by
(pIE->length + 2) each iteration but only guards on i < len.
When a malicious AP sends a Beacon whose last IE has only one byte
remaining in the frame (the element_id byte lands at len-1), the loop
reads pIE->length from one byte past the allocated receive buffer.
Additionally, even when the header bytes are in bounds, pIE->length
itself can extend the data window beyond len, passing a truncated IE
to the handler functions.
Add two guards at the top of the loop body:
1. Break if fewer than sizeof(*pIE) bytes remain (can't read header).
2. Break if the IE's declared data extends past len.
Also replace i += (pIE->length + 2) with i += sizeof(*pIE) + pIE->length
for consistency with the sizeof(*pIE) guards added above.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_wlan_util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5e8db4cff5b45c7c4edc8ae3f302027c3bb32b25",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "6dd5e8c3011ebabf417257d7f07901a7c4311539",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "9193c34f75fd9e1ea8a590d7cced464c3380dc29",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "bd953d52d587d42365e399b96c52dbdb13032070",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "69f174a0673b6b7a29b851adb60bc450cdc0ecc4",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "b5cc2f999927f69723ca53f1f2a3aa37dbeda907",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "ed51de4a86e173c3b0ef78e039c2e49e08b11f16",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_wlan_util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in update_beacon_info() IE loop\n\nThe IE parsing loop in update_beacon_info() advances by\n(pIE-\u003elength + 2) each iteration but only guards on i \u003c len.\nWhen a malicious AP sends a Beacon whose last IE has only one byte\nremaining in the frame (the element_id byte lands at len-1), the loop\nreads pIE-\u003elength from one byte past the allocated receive buffer.\n\nAdditionally, even when the header bytes are in bounds, pIE-\u003elength\nitself can extend the data window beyond len, passing a truncated IE\nto the handler functions.\n\nAdd two guards at the top of the loop body:\n 1. Break if fewer than sizeof(*pIE) bytes remain (can\u0027t read header).\n 2. Break if the IE\u0027s declared data extends past len.\n\nAlso replace i += (pIE-\u003elength + 2) with i += sizeof(*pIE) + pIE-\u003elength\nfor consistency with the sizeof(*pIE) guards added above."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - An attacker within WiFi radio range can inject a crafted beacon spoofing the associated AP\u0027s BSSID. WiFi management-frame injection is an adjacent attack vector.\nAC:L - The malformed IE deterministically triggers the faulty parsing, and the attacker can send repeated beacons to satisfy the every-sixteenth-packet processing condition. No race or condition outside attacker control is required.\nPR:N - Ordinary beacon frames are not authenticated, even on WPA-protected networks. The driver checks association state, addresses, and BSSID, all of which an adjacent attacker can spoof without credentials or host privileges.\nUI:N - Once the interface is associated or operating in IBSS mode, crafted beacons are processed without victim action. Continuously connected embedded and mobile deployments provide this state automatically.\nS:U - The vulnerable driver and affected kernel resources belong to the same operating-system security authority. No guest-host, sandbox, or IOMMU boundary is crossed.\nC:H - Truncated WMM or HT elements can make handlers consume roughly 22 to 24 bytes beyond the logical frame from adjacent kernel skb memory. Under conservative treatment of this nontrivial kernel out-of-bounds read, confidentiality impact is High.\nI:N - The flaw performs out-of-bounds reads but provides no out-of-bounds write or control-flow primitive. Handler copies target correctly sized driver state fields.\nA:H - Out-of-bounds accesses in the kernel receive tasklet can produce an oops or panic on hardened or unfavorable memory layouts. An unauthenticated adjacent attacker can repeatedly transmit triggering beacons."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:45.615Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5e8db4cff5b45c7c4edc8ae3f302027c3bb32b25"
},
{
"url": "https://git.kernel.org/stable/c/6dd5e8c3011ebabf417257d7f07901a7c4311539"
},
{
"url": "https://git.kernel.org/stable/c/9193c34f75fd9e1ea8a590d7cced464c3380dc29"
},
{
"url": "https://git.kernel.org/stable/c/bd953d52d587d42365e399b96c52dbdb13032070"
},
{
"url": "https://git.kernel.org/stable/c/69f174a0673b6b7a29b851adb60bc450cdc0ecc4"
},
{
"url": "https://git.kernel.org/stable/c/b5cc2f999927f69723ca53f1f2a3aa37dbeda907"
},
{
"url": "https://git.kernel.org/stable/c/ed51de4a86e173c3b0ef78e039c2e49e08b11f16"
}
],
"title": "staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64443",
"datePublished": "2026-07-25T08:51:15.234Z",
"dateReserved": "2026-07-19T15:36:31.788Z",
"dateUpdated": "2026-08-17T04:55:45.615Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53269 (GCVE-0-2026-53269)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: synproxy: add mutex to guard hook reference counting
As the synproxy infrastructure register netfilter hooks on-demand when a
user adds the first iptables target or nftables expression, if done
concurrently they can race each other.
Introduce a mutex to serialize the refcount control blocks access from
both frontends. While a per namespace mutex might be more efficient, it
is not needed for target/expression like SYNPROXY.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad49d86e07a497e834cb06f2b151dccd75f8e148 Version: ad49d86e07a497e834cb06f2b151dccd75f8e148 Version: ad49d86e07a497e834cb06f2b151dccd75f8e148 Version: ad49d86e07a497e834cb06f2b151dccd75f8e148 Version: ad49d86e07a497e834cb06f2b151dccd75f8e148 Version: ad49d86e07a497e834cb06f2b151dccd75f8e148 Version: ad49d86e07a497e834cb06f2b151dccd75f8e148 Version: ad49d86e07a497e834cb06f2b151dccd75f8e148 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:13.327Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_synproxy_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0ec9ddc1bda261a2c57636c74c8b4e53000102c9",
"status": "affected",
"version": "ad49d86e07a497e834cb06f2b151dccd75f8e148",
"versionType": "git"
},
{
"lessThan": "56ffbe3a08c01dcdb0d6adee9ce1e535bfb3b389",
"status": "affected",
"version": "ad49d86e07a497e834cb06f2b151dccd75f8e148",
"versionType": "git"
},
{
"lessThan": "debc57b83d5b323df74bf010c8d50fe26ad2ed6b",
"status": "affected",
"version": "ad49d86e07a497e834cb06f2b151dccd75f8e148",
"versionType": "git"
},
{
"lessThan": "0f8ba5e4c53d2e4a536aa68140beda9fe59b2f88",
"status": "affected",
"version": "ad49d86e07a497e834cb06f2b151dccd75f8e148",
"versionType": "git"
},
{
"lessThan": "640441348258220e78daed40528b85b8afcedab6",
"status": "affected",
"version": "ad49d86e07a497e834cb06f2b151dccd75f8e148",
"versionType": "git"
},
{
"lessThan": "aaf80701dc2f7a48fe543961e21f8ca3924d587c",
"status": "affected",
"version": "ad49d86e07a497e834cb06f2b151dccd75f8e148",
"versionType": "git"
},
{
"lessThan": "fbf0591275f50eae5733c3d7a8cd6c1e79933ffa",
"status": "affected",
"version": "ad49d86e07a497e834cb06f2b151dccd75f8e148",
"versionType": "git"
},
{
"lessThan": "2fcba19caaeb2a33017459d3430f057967bb91b6",
"status": "affected",
"version": "ad49d86e07a497e834cb06f2b151dccd75f8e148",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_synproxy_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: add mutex to guard hook reference counting\n\nAs the synproxy infrastructure register netfilter hooks on-demand when a\nuser adds the first iptables target or nftables expression, if done\nconcurrently they can race each other.\n\nIntroduce a mutex to serialize the refcount control blocks access from\nboth frontends. While a per namespace mutex might be more efficient, it\nis not needed for target/expression like SYNPROXY."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-25T08:39:55.172Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0ec9ddc1bda261a2c57636c74c8b4e53000102c9"
},
{
"url": "https://git.kernel.org/stable/c/56ffbe3a08c01dcdb0d6adee9ce1e535bfb3b389"
},
{
"url": "https://git.kernel.org/stable/c/debc57b83d5b323df74bf010c8d50fe26ad2ed6b"
},
{
"url": "https://git.kernel.org/stable/c/0f8ba5e4c53d2e4a536aa68140beda9fe59b2f88"
},
{
"url": "https://git.kernel.org/stable/c/640441348258220e78daed40528b85b8afcedab6"
},
{
"url": "https://git.kernel.org/stable/c/aaf80701dc2f7a48fe543961e21f8ca3924d587c"
},
{
"url": "https://git.kernel.org/stable/c/fbf0591275f50eae5733c3d7a8cd6c1e79933ffa"
},
{
"url": "https://git.kernel.org/stable/c/2fcba19caaeb2a33017459d3430f057967bb91b6"
}
],
"title": "netfilter: synproxy: add mutex to guard hook reference counting",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53269",
"datePublished": "2026-06-25T08:39:55.172Z",
"dateReserved": "2026-06-09T07:44:35.395Z",
"dateUpdated": "2026-09-08T08:50:13.327Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68143 (GCVE-0-2026-68143)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: slip: serialize receive against buffer reallocation
sl_realloc_bufs() replaces rbuff and updates buffsize while holding
sl->lock. slip_receive_buf() reads those fields and writes through rbuff
without holding the lock.
An MTU change can therefore race with receive processing. An MTU shrink
can expose the new smaller rbuff with the old larger bound, causing an
out-of-bounds write. A receive callback which already loaded the old
rbuff can instead continue writing after that buffer has been freed.
Serialize receive processing with sl_realloc_bufs() by holding sl->lock
while consuming each receive batch.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/slip/slip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8180daf2b66155f84ec4f9e3f95488c8a3421716",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "189a550eb7e1dc10018718ddfc46d003ffe58653",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1be09d175b627fad7f6bec7ad27b8a4a99863912",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "eb3836eab47487823f362e6985e170a1e15f20fd",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "44401f7dd9940ced7098930ef64f5a332f279fc2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5d07b178bef511d69558cfc89fe1129258dc39f8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0e37bbd6d617eb52bace49390e99eaedc1af73ce",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/slip/slip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: slip: serialize receive against buffer reallocation\n\nsl_realloc_bufs() replaces rbuff and updates buffsize while holding\nsl-\u003elock. slip_receive_buf() reads those fields and writes through rbuff\nwithout holding the lock.\n\nAn MTU change can therefore race with receive processing. An MTU shrink\ncan expose the new smaller rbuff with the old larger bound, causing an\nout-of-bounds write. A receive callback which already loaded the old\nrbuff can instead continue writing after that buffer has been freed.\n\nSerialize receive processing with sl_realloc_bufs() by holding sl-\u003elock\nwhile consuming each receive batch."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in the SLIP TTY line discipline; triggering the MTU shrink/realloc race requires SIOCSIFMTU/RTM_SETLINK (CAP_NET_ADMIN) on the host, so a single attacker must have local access even if SLIP frames arrive over a serial backhaul.\nAC:L - An attacker with CAP_NET_ADMIN can concurrently hammer MTU changes via ioctl/rtnetlink and inject SLIP frames on the bound TTY/PTY, controlling both sides of the race without depending on uncontrollable timing.\nPR:L - SIOCSIFMTU requires CAP_NET_ADMIN in the interface network namespace, obtainable by an unprivileged user via user namespaces; exploitation targets already-active SLIP links and does not repeat slip_open()\u0027s init-namespace check.\nUI:N - No end-user or administrator interaction is required during exploitation once a SLIP interface is active; the attacker drives both MTU reallocation and receive processing directly.\nS:U - Heap corruption is confined to kernel SLIP receive buffers and adjacent kmalloc objects; impact is standard kernel memory corruption and local privilege escalation, not a cross-VM or sandbox boundary escape.\nC:H - The race yields heap out-of-bounds writes and use-after-free writes on freed rbuff kmalloc objects; per kernel guidance, this class of memory corruption enables arbitrary kernel memory disclosure.\nI:H - Writing past the reallocated rbuff boundary or into a freed buffer corrupts adjacent heap metadata/objects, providing primitives for arbitrary kernel writes and control-flow hijacking.\nA:H - Out-of-bounds and use-after-free corruption of kernel heap memory reliably causes kernel oops/panic during the race even when not fully weaponized for code execution."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:04.807Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8180daf2b66155f84ec4f9e3f95488c8a3421716"
},
{
"url": "https://git.kernel.org/stable/c/189a550eb7e1dc10018718ddfc46d003ffe58653"
},
{
"url": "https://git.kernel.org/stable/c/1be09d175b627fad7f6bec7ad27b8a4a99863912"
},
{
"url": "https://git.kernel.org/stable/c/eb3836eab47487823f362e6985e170a1e15f20fd"
},
{
"url": "https://git.kernel.org/stable/c/44401f7dd9940ced7098930ef64f5a332f279fc2"
},
{
"url": "https://git.kernel.org/stable/c/5d07b178bef511d69558cfc89fe1129258dc39f8"
},
{
"url": "https://git.kernel.org/stable/c/0e37bbd6d617eb52bace49390e99eaedc1af73ce"
},
{
"url": "https://git.kernel.org/stable/c/ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d"
}
],
"title": "net: slip: serialize receive against buffer reallocation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68143",
"datePublished": "2026-08-10T11:59:07.354Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:30:04.807Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64513 (GCVE-0-2026-64513)
Vulnerability from cvelistv5
Published
2026-07-25 08:52
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Unconditionally recompute CR8 intercept on PPR update
The TPR_THRESHOLD field in the VMCS is used by VMX to induce VM exits
when the guest's virtual TPR falls under the specified threshold,
allowing KVM to inject previously masked interrupts.
KVM handles these VM exits in handle_tpr_below_threshold().
Commit eb90f3417a0c ("KVM: vmx: speed up TPR below threshold vmexits")
optimized this function by calling apic_update_ppr() instead of raising
KVM_REQ_EVENT. apic_update_ppr() then raises KVM_REQ_EVENT if there is
a pending, deliverable interrupt.
However, if there are no new interrupts pending, apic_update_ppr() does
not issue the request. Thus, kvm_lapic_update_cr8_intercept() and
vmx_update_cr8_intercept() are not called before VM entry, which results
in a high, stale TPR_THRESHOLD. This is problematic due to the following
sentence in 28.2.1.1 "VM-Execution Control Fields" in the SDM:
The following check is performed if the “use TPR shadow” VM-execution
control is 1 and the “virtualize APIC accesses” and “virtual-interrupt
delivery” VM-execution controls are both 0: the value of bits 3:0 of
the TPR threshold VM-execution control field should not be greater
than the value of bits 7:4 of VTPR.
This error condition is typically not observed when KVM runs on a bare
metal system because modern processors support APICv, which enables
virtual-interrupt delivery, and which KVM uses when possible. This
causes the processor to no longer generate TPR-below-threshold exits
and to no longer check TPR_THRESHOLD on entry. However, when running
on older platforms, or under nested virtualization on a hypervisor that
does not support virtual-interrupt delivery and enforces this check
(like Hyper-V) this can cause a VM entry failure with hardware error
0x7, as seen in [1].
Call kvm_lapic_update_cr8_intercept() if apic_update_ppr() does not
find a deliverable interrupt (and thus does not raise KVM_REQ_EVENT).
Remove calls to kvm_lapic_update_cr8_intercept() on paths that end up in
apic_update_ppr(), as they now become redundant. This ensures that any
path that updates the guest's PPR also figures out if KVM needs to wait
for a TPR change (using TPR_THRESHOLD on VMX or CR8 intercepts on SVM).
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/lapic.c",
"arch/x86/kvm/x86.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ff9c4c6428883182960cfe5c78928f0896d80ebc",
"status": "affected",
"version": "eb90f3417a0cc4880e979ccc84e41890d410ea5b",
"versionType": "git"
},
{
"lessThan": "8c8e8ac22ee17d52f9eb2bc814bca7fab90fb8df",
"status": "affected",
"version": "eb90f3417a0cc4880e979ccc84e41890d410ea5b",
"versionType": "git"
},
{
"lessThan": "bb365a506b1e6fb050c0fceaad354fe395385ef0",
"status": "affected",
"version": "eb90f3417a0cc4880e979ccc84e41890d410ea5b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/lapic.c",
"arch/x86/kvm/x86.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Unconditionally recompute CR8 intercept on PPR update\n\nThe TPR_THRESHOLD field in the VMCS is used by VMX to induce VM exits\nwhen the guest\u0027s virtual TPR falls under the specified threshold,\nallowing KVM to inject previously masked interrupts.\n\nKVM handles these VM exits in handle_tpr_below_threshold().\nCommit eb90f3417a0c (\"KVM: vmx: speed up TPR below threshold vmexits\")\noptimized this function by calling apic_update_ppr() instead of raising\nKVM_REQ_EVENT. apic_update_ppr() then raises KVM_REQ_EVENT if there is\na pending, deliverable interrupt.\n\nHowever, if there are no new interrupts pending, apic_update_ppr() does\nnot issue the request. Thus, kvm_lapic_update_cr8_intercept() and\nvmx_update_cr8_intercept() are not called before VM entry, which results\nin a high, stale TPR_THRESHOLD. This is problematic due to the following\nsentence in 28.2.1.1 \"VM-Execution Control Fields\" in the SDM:\n\n The following check is performed if the \u201cuse TPR shadow\u201d VM-execution\n control is 1 and the \u201cvirtualize APIC accesses\u201d and \u201cvirtual-interrupt\n delivery\u201d VM-execution controls are both 0: the value of bits 3:0 of\n the TPR threshold VM-execution control field should not be greater\n than the value of bits 7:4 of VTPR.\n\nThis error condition is typically not observed when KVM runs on a bare\nmetal system because modern processors support APICv, which enables\nvirtual-interrupt delivery, and which KVM uses when possible. This\ncauses the processor to no longer generate TPR-below-threshold exits\nand to no longer check TPR_THRESHOLD on entry. However, when running\non older platforms, or under nested virtualization on a hypervisor that\ndoes not support virtual-interrupt delivery and enforces this check\n(like Hyper-V) this can cause a VM entry failure with hardware error\n0x7, as seen in [1].\n\nCall kvm_lapic_update_cr8_intercept() if apic_update_ppr() does not\nfind a deliverable interrupt (and thus does not raise KVM_REQ_EVENT).\nRemove calls to kvm_lapic_update_cr8_intercept() on paths that end up in\napic_update_ppr(), as they now become redundant. This ensures that any\npath that updates the guest\u0027s PPR also figures out if KVM needs to wait\nfor a TPR change (using TPR_THRESHOLD on VMX or CR8 intercepts on SVM)."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:04.428Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ff9c4c6428883182960cfe5c78928f0896d80ebc"
},
{
"url": "https://git.kernel.org/stable/c/8c8e8ac22ee17d52f9eb2bc814bca7fab90fb8df"
},
{
"url": "https://git.kernel.org/stable/c/bb365a506b1e6fb050c0fceaad354fe395385ef0"
}
],
"title": "KVM: x86: Unconditionally recompute CR8 intercept on PPR update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64513",
"datePublished": "2026-07-25T08:52:05.119Z",
"dateReserved": "2026-07-19T15:36:31.793Z",
"dateUpdated": "2026-08-17T04:57:04.428Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68219 (GCVE-0-2026-68219)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: nxp: imx8-isi: Fix potential out-of-bounds issues
The maximum downscaling factor supported by ISI can be up to 16. Add
minimum value constraint before applying the setting to hardware.
Otherwise, the process will not respond even when Ctrl+C is executed.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nxp/imx8-isi/imx8-isi-core.h",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-m2m.c",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-pipe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "690cdda752f3dc6b7a8b2d4a243e0207b66a1f37",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "ba7e1b06cbdad3b7c3314390cca22aff42f655d4",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "28ae75dba701d7aa69a36802c398582933d3e0e6",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "75cdfaa7c908ca06d564170da9c80fb579f149a5",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "57a7ec5c9f38ce6c4d6209c4b75c8e57e1fea6cf",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nxp/imx8-isi/imx8-isi-core.h",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-m2m.c",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-pipe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: nxp: imx8-isi: Fix potential out-of-bounds issues\n\nThe maximum downscaling factor supported by ISI can be up to 16. Add\nminimum value constraint before applying the setting to hardware.\nOtherwise, the process will not respond even when Ctrl+C is executed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is reached exclusively through V4L2 ioctls (VIDIOC_S_FMT on the /dev/videoX M2M node, or VIDIOC_SUBDEV_S_SELECTION on the ISI pipe subdev), which require local access to the device node. There is no remote or adjacent-network path into the imx8-isi driver.\nAC:L - Exploitation is a deterministic ioctl sequence: set a large OUTPUT format, set a 1x1 CAPTURE format (accepted because the bound was only min() against the source size and MXC_ISI_MIN_WIDTH/HEIGHT = 1), queue buffers and stream. No race, timing window, or uncontrollable memory-layout condition is involved.\nPR:L - The attacker only needs to open the ISI video device node; no capability check exists anywhere along the path from the ioctl handler to mxc_isi_channel_set_scaling(). On the i.MX8 embedded, automotive and vision devices where this driver runs, /dev/video* is routinely accessible to ordinary unprivileged applications via the video/camera group.\nUI:N - The attacking process performs the entire sequence itself \u2014 open, S_FMT, REQBUFS, QBUF, STREAMON \u2014 with no victim action, no separate privileged process, and no administrator step required.\nS:U - The corruption and the hang stay within the kernel of the same machine; the ISI DMA write targets kernel memory adjacent to the video buffer and does not cross a VM, hypervisor or IOMMU security boundary.\nC:H - The scaler saturates at a 16x factor while the destination buffer and CHNL_OUT_BUF_PITCH are sized from the far smaller requested format, so the ISI DMA engine overruns the video buffer into adjacent kernel memory; such heap corruption in DMA-able memory is leverageable to disclose kernel memory contents, and stale buffer content is returned to userspace.\nI:H - The hardware writes an image much larger than the allocated destination buffer, producing an out-of-bounds DMA write whose contents are the attacker\u0027s own input frame in M2M mode \u2014 an attacker-controlled overwrite of kernel memory following the buffer, sufficient for control-flow-relevant corruption.\nA:H - The fix commit states the transaction never completes and \"the process will not respond even when Ctrl+C is executed\", leaving an unkillable task and a wedged ISI channel that denies the imaging pipeline to all users; the accompanying out-of-bounds DMA write can additionally panic the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:05.813Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/690cdda752f3dc6b7a8b2d4a243e0207b66a1f37"
},
{
"url": "https://git.kernel.org/stable/c/ba7e1b06cbdad3b7c3314390cca22aff42f655d4"
},
{
"url": "https://git.kernel.org/stable/c/28ae75dba701d7aa69a36802c398582933d3e0e6"
},
{
"url": "https://git.kernel.org/stable/c/75cdfaa7c908ca06d564170da9c80fb579f149a5"
},
{
"url": "https://git.kernel.org/stable/c/57a7ec5c9f38ce6c4d6209c4b75c8e57e1fea6cf"
}
],
"title": "media: nxp: imx8-isi: Fix potential out-of-bounds issues",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68219",
"datePublished": "2026-08-10T12:00:39.405Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-17T05:01:05.813Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68299 (GCVE-0-2026-68299)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the
outer header, but for a Geneve-encapsulated packet the device can set
them based on the inner header instead, signalled by the
VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the
function never skips the outer encapsulation, this mismatch triggers:
- BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP), because the outer
protocol is UDP (Geneve), not TCP.
- BUG_ON(hdr.eth->h_proto != ...), when the tunnel's outer and inner
IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).
Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the
function cannot locate the inner header it would need to parse. Also
convert the remaining BUG_ON()s in this function to return 0
defensively.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vmxnet3/vmxnet3_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2ddf51fcb6dd7d55ceef38e2e1a5ab2ab7fd47b0",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "fbab6b73cc086e32698c86e43d1b16bf17d24c36",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "28e382646417c7e2be9c9a7079eddf627ff52b90",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "667b6e52048eaf4dbcf1707ed87ffd44abb9cb38",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "4fdb0f162ccdbe9626863b10003855703253fa29",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "b28596baf87e25a078789f1c05817c8a3bf71257",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "34a71f5361fc3adb5b7138da78750b0d535a8252",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vmxnet3/vmxnet3_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets\n\nvmxnet3_get_hdr_len() assumes gdesc-\u003ercd.v4/v6/tcp always describe the\nouter header, but for a Geneve-encapsulated packet the device can set\nthem based on the inner header instead, signalled by the\nVMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the\nfunction never skips the outer encapsulation, this mismatch triggers:\n\n- BUG_ON(hdr.ipv4-\u003eprotocol != IPPROTO_TCP), because the outer\n protocol is UDP (Geneve), not TCP.\n- BUG_ON(hdr.eth-\u003eh_proto != ...), when the tunnel\u0027s outer and inner\n IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).\n\nCheck VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the\nfunction cannot locate the inner header it would need to parse. Also\nconvert the remaining BUG_ON()s in this function to return 0\ndefensively."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is triggered purely by a received Geneve-encapsulated packet processed in the vmxnet3 RX completion path (vmxnet3_rq_rx_complete -\u003e vmxnet3_get_hdr_len); any remote host that can deliver such a frame to a VMware guest\u0027s vmxnet3 interface reaches the code, with no local access required.\nAC:L - The attacker only needs to send Geneve-encapsulated TCP traffic larger than the MTU to the target; the device then sets rcd.v4/v6/tcp from the inner header and the outer UDP protocol (or an outer/inner IP version mismatch) deterministically hits the BUG_ON, with no race or memory-layout dependency.\nPR:N - Packet reception and header-length estimation occur in the driver\u0027s NAPI RX path before any socket, credential, or authentication check, so an entirely unauthenticated remote sender triggers it.\nUI:N - The panic happens during normal NAPI RX processing of an incoming packet; no action by any local user or administrator is needed.\nS:U - The BUG_ON crashes the kernel that owns the vmxnet3 interface, and impact stays entirely within that kernel\u0027s security authority with no crossing into the hypervisor or another domain.\nC:N - The header parsing is bounded by the explicit skb_headlen()/maplen checks, so no out-of-bounds read occurs and no kernel memory contents are disclosed to the attacker before the BUG_ON aborts.\nI:N - No out-of-bounds or attacker-controlled write occurs; the mismatch is caught by the BUG_ON assertion, which halts execution rather than corrupting kernel memory or control flow.\nA:H - Hitting BUG_ON() in softirq/NAPI context oopses and panics the kernel, taking down the entire guest; a remote attacker can repeat it with a single crafted Geneve packet stream for a persistent denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:48.545Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2ddf51fcb6dd7d55ceef38e2e1a5ab2ab7fd47b0"
},
{
"url": "https://git.kernel.org/stable/c/fbab6b73cc086e32698c86e43d1b16bf17d24c36"
},
{
"url": "https://git.kernel.org/stable/c/28e382646417c7e2be9c9a7079eddf627ff52b90"
},
{
"url": "https://git.kernel.org/stable/c/667b6e52048eaf4dbcf1707ed87ffd44abb9cb38"
},
{
"url": "https://git.kernel.org/stable/c/28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8"
},
{
"url": "https://git.kernel.org/stable/c/4fdb0f162ccdbe9626863b10003855703253fa29"
},
{
"url": "https://git.kernel.org/stable/c/b28596baf87e25a078789f1c05817c8a3bf71257"
},
{
"url": "https://git.kernel.org/stable/c/34a71f5361fc3adb5b7138da78750b0d535a8252"
}
],
"title": "vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68299",
"datePublished": "2026-08-10T12:02:33.213Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:48.545Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68315 (GCVE-0-2026-68315)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: validate stream count in sctp_process_strreset_inreq()
When processing a RESET_IN_REQUEST from a peer,
sctp_process_strreset_inreq() derives the stream count from the
parameter length but does not check whether the resulting
RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.
The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes
larger than the IN request header (sctp_strreset_inreq, 8 bytes).
Generally, the IP payload is bounded to 65535 bytes, so the stream
list cannot be large enough to trigger the overflow. However, on
interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a
stream list that fits within the incoming IN parameter can cause a
__u16 overflow in sctp_make_strreset_req() when computing the OUT
request size, leading to an undersized skb allocation and a kernel
BUG:
net/core/skbuff.c:207 skb_panic
net/core/skbuff.c:2625 skb_put
net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk
net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req
net/sctp/stream.c:655 sctp_process_strreset_inreq
The local setsockopt path validates the generated reset request size.
However, for an incoming-only reset, it accounts for the smaller IN
request even though the peer must generate an OUT request with the same
stream list. Such a request cannot be completed successfully by the
peer.
Reject peer IN requests whose corresponding OUT request would exceed
SCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an
IN request that would require an oversized OUT request from the peer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/stream.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "61327d8e7cfb0259d527be17202630f556213249",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "7cf7439948e3bf639119119922c88ec190874ca3",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "60c47dea5d320d2fc706e9aad1db38a04df0a056",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "6f0e39d180cd7cced647381b6fa14fd83d261047",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "1a10fe1aa9c01f41b389a31906a77d538637c9d9",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "00ae679cb21a035491fdad8d58dc6d79cc68b675",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "18ae07691d43183d270de8be9dc8e027906015d9",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/stream.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate stream count in sctp_process_strreset_inreq()\n\nWhen processing a RESET_IN_REQUEST from a peer,\nsctp_process_strreset_inreq() derives the stream count from the\nparameter length but does not check whether the resulting\nRESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.\n\nThe OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes\nlarger than the IN request header (sctp_strreset_inreq, 8 bytes).\nGenerally, the IP payload is bounded to 65535 bytes, so the stream\nlist cannot be large enough to trigger the overflow. However, on\ninterfaces with MTU \u003e 65535 (e.g., loopback with IPv6 jumbograms), a\nstream list that fits within the incoming IN parameter can cause a\n__u16 overflow in sctp_make_strreset_req() when computing the OUT\nrequest size, leading to an undersized skb allocation and a kernel\nBUG:\n\n net/core/skbuff.c:207 skb_panic\n net/core/skbuff.c:2625 skb_put\n net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk\n net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req\n net/sctp/stream.c:655 sctp_process_strreset_inreq\n\nThe local setsockopt path validates the generated reset request size.\nHowever, for an incoming-only reset, it accounts for the smaller IN\nrequest even though the peer must generate an OUT request with the same\nstream list. Such a request cannot be completed successfully by the\npeer.\n\nReject peer IN requests whose corresponding OUT request would exceed\nSCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an\nIN request that would require an oversized OUT request from the peer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerability is triggered by processing an SCTP RECONF chunk (RESET_IN_REQUEST) received from a remote/loopback peer in the in-kernel SCTP stack; per kernel guidance net-stack bugs reachable via received packets are Network.\nAC:L - The attacker fully controls the stream list length in the IN request, and the required MTU\u003e65535 is the default for loopback (65536), so the panic is reliably triggerable; stream-reset must be enabled but that is a deployment condition, not an attacker-uncontrollable one.\nPR:N - Sending the RECONF chunk only requires an established SCTP association, which any peer can set up without authentication or credentials; the bug is reached during normal association-scoped packet processing.\nUI:N - No victim interaction is needed; the attacker simply sends a crafted RECONF chunk to an established association.\nS:U - The crash occurs within the kernel\u0027s own security scope with no crossing of a security boundary such as VM or IOMMU.\nC:N - The bug is a controlled BUG()/skb_over_panic that aborts before any out-of-bounds access, disclosing no memory contents.\nI:N - The panic fires before the oversized copy executes, so no memory is written or modified out of bounds.\nA:H - The undersized skb allocation causes skb_put to invoke skb_over_panic \u2192 BUG(), producing a kernel panic (denial of service)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:08.206Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/61327d8e7cfb0259d527be17202630f556213249"
},
{
"url": "https://git.kernel.org/stable/c/7cf7439948e3bf639119119922c88ec190874ca3"
},
{
"url": "https://git.kernel.org/stable/c/60c47dea5d320d2fc706e9aad1db38a04df0a056"
},
{
"url": "https://git.kernel.org/stable/c/b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b"
},
{
"url": "https://git.kernel.org/stable/c/6f0e39d180cd7cced647381b6fa14fd83d261047"
},
{
"url": "https://git.kernel.org/stable/c/1a10fe1aa9c01f41b389a31906a77d538637c9d9"
},
{
"url": "https://git.kernel.org/stable/c/00ae679cb21a035491fdad8d58dc6d79cc68b675"
},
{
"url": "https://git.kernel.org/stable/c/18ae07691d43183d270de8be9dc8e027906015d9"
}
],
"title": "sctp: validate stream count in sctp_process_strreset_inreq()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68315",
"datePublished": "2026-08-10T12:02:50.156Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:08.206Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68136 (GCVE-0-2026-68136)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: gro: fix double aggregation of flush-marked skbs
Commit 0ab03f353d36 ("net-gro: Fix GRO flush when receiving a GSO
packet.") added a flush check to skb_gro_receive(), but
skb_gro_receive_list() lacks the same validation.
As a result, packets marked with NAPI_GRO_CB(skb)->flush may still be
re-aggregated.
This allows already-GRO'd packets with existing frag_list to be
re-aggregated into a new GRO session, corrupting the frag_list chain
structure. When skb_segment() attempts to unpack these malformed packets,
it encounters invalid state and triggers a kernel panic.
Scenario (Tethering/Device forwarding):
1. Driver: Generated aggregated packet P1 via LRO with frag_list
2. Dev A: Receives aggregated fraglist packet and flush flag set
3. Dev A: Re-enters GRO, skb_gro_receive_list() is called
4. Missing flush check allows re-aggregation despite flush flag
5. Frag_list chain becomes corrupted (loops or dangling refs)
6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list
Root cause in skb_segment():
The check at line ~4891:
if (hsize <= 0 && i >= nfrags && skb_headlen(list_skb) &&
(skb_headlen(list_skb) == len || sg)) {
When frag_list is corrupted by double aggregation, when list_skb is
a NULL pointer from skb->next, skb_headlen(list_skb) dereference
NULL/corrupted pointers occurs.
Call Trace:
skb_headlen(NULL skb)
skb_segment
tcp_gso_segment
tcp4_gso_segment
inet_gso_segment
skb_mac_gso_segment
__skb_gso_segment
skb_gso_segment
validate_xmit_skb
validate_xmit_skb_list
sch_direct_xmit
qdisc_restart
__qdisc_run
qdisc_run
net_tx_action
Fix: Add NAPI_GRO_CB(skb)->flush validation to the early-return check in
skb_gro_receive_list(), matching the defensive programming pattern of
skb_gro_receive().
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/gro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7fc7e35212cf58c134310fb47566a844297ceae9",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "d1fb23f8f794ac4683127bd49a6422bd87e0ac02",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "db3e82da616f52e2b27e25e7be3fde2f2a5e54d6",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "107e1a469f53a2a70874f3f12bf6fcd23925da1d",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "a4dfd46cc8f08a29c6183794790547d0945f3d45",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "e751256486d0ded20f5a9f9863467f1dce65142f",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/gro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: fix double aggregation of flush-marked skbs\n\nCommit 0ab03f353d36 (\"net-gro: Fix GRO flush when receiving a GSO\npacket.\") added a flush check to skb_gro_receive(), but\nskb_gro_receive_list() lacks the same validation.\n\nAs a result, packets marked with NAPI_GRO_CB(skb)-\u003eflush may still be\nre-aggregated.\n\nThis allows already-GRO\u0027d packets with existing frag_list to be\nre-aggregated into a new GRO session, corrupting the frag_list chain\nstructure. When skb_segment() attempts to unpack these malformed packets,\nit encounters invalid state and triggers a kernel panic.\n\nScenario (Tethering/Device forwarding):\n 1. Driver: Generated aggregated packet P1 via LRO with frag_list\n 2. Dev A: Receives aggregated fraglist packet and flush flag set\n 3. Dev A: Re-enters GRO, skb_gro_receive_list() is called\n 4. Missing flush check allows re-aggregation despite flush flag\n 5. Frag_list chain becomes corrupted (loops or dangling refs)\n 6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list\n\nRoot cause in skb_segment():\n The check at line ~4891:\n if (hsize \u003c= 0 \u0026\u0026 i \u003e= nfrags \u0026\u0026 skb_headlen(list_skb) \u0026\u0026\n (skb_headlen(list_skb) == len || sg)) {\n\n When frag_list is corrupted by double aggregation, when list_skb is\n a NULL pointer from skb-\u003enext, skb_headlen(list_skb) dereference\n NULL/corrupted pointers occurs.\n\nCall Trace:\n skb_headlen(NULL skb)\n skb_segment\n tcp_gso_segment\n tcp4_gso_segment\n inet_gso_segment\n skb_mac_gso_segment\n __skb_gso_segment\n skb_gso_segment\n validate_xmit_skb\n validate_xmit_skb_list\n sch_direct_xmit\n qdisc_restart\n __qdisc_run\n qdisc_run\n net_tx_action\n\nFix: Add NAPI_GRO_CB(skb)-\u003eflush validation to the early-return check in\nskb_gro_receive_list(), matching the defensive programming pattern of\nskb_gro_receive()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached from the standard NAPI GRO receive path processing remotely originated TCP/IP packets (napi_gro_receive\u2192dev_gro_receive\u2192tcp_gro_receive\u2192skb_gro_receive_list), including tethering/NAT/forwarding scenarios where packets re-enter GRO on a second netdev after driver LRO or prior GRO aggregation.\nAC:L - An attacker can reliably trigger the bug by crafting a TCP stream through a forwarding host with rx-gro-list enabled, without races or victim-specific timing; the commit documents a deterministic tethering/forwarding repro where flush-marked frag_list skbs are re-aggregated and later crash skb_segment.\nPR:N - No local privileges or authentication are required; any remote peer that can send TCP traffic through a vulnerable forwarding/tethering/NAT Linux host can reach the GRO fraglist merge path, which performs no capability or credential checks on the receive path.\nUI:N - Exploitation requires only network-delivered packets and normal kernel forwarding/GRO processing; the victim does not need to open files, mount filesystems, click links, or perform any deliberate action beyond routine network operation.\nS:U - Impact is confined to kernel memory corruption and panic within the same host kernel security domain during packet GRO aggregation and subsequent segmentation on transmit; it does not cross VM, container, or IOMMU boundaries to affect a separate security authority.\nC:H - Double aggregation corrupts the skb frag_list chain (loops, dangling references, NULL/corrupted list_skb pointers), constituting kernel heap memory corruption that can be read during skb_segment processing and is classifiable as a high-impact info-disclosure primitive beyond a simple crash.\nI:H - Re-aggregating flush-marked skbs with existing frag_list corrupts skb linked-list structure and reference relationships in kernel memory, enabling potential control of subsequent skb metadata and write/control-flow primitives during GSO segmentation, not merely integrity-preserving packet drops.\nA:H - Corrupted frag_list state causes skb_segment to dereference a NULL or invalid list_skb via skb_headlen(), producing a kernel panic/oops on the transmit path (sch_direct_xmit/qdisc_run), fully denying availability of the affected system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:54.689Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7fc7e35212cf58c134310fb47566a844297ceae9"
},
{
"url": "https://git.kernel.org/stable/c/d1fb23f8f794ac4683127bd49a6422bd87e0ac02"
},
{
"url": "https://git.kernel.org/stable/c/db3e82da616f52e2b27e25e7be3fde2f2a5e54d6"
},
{
"url": "https://git.kernel.org/stable/c/107e1a469f53a2a70874f3f12bf6fcd23925da1d"
},
{
"url": "https://git.kernel.org/stable/c/a4dfd46cc8f08a29c6183794790547d0945f3d45"
},
{
"url": "https://git.kernel.org/stable/c/fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0"
},
{
"url": "https://git.kernel.org/stable/c/e751256486d0ded20f5a9f9863467f1dce65142f"
}
],
"title": "net: gro: fix double aggregation of flush-marked skbs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68136",
"datePublished": "2026-08-10T11:58:59.450Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-23T12:45:54.689Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53330 (GCVE-0-2026-53330)
Vulnerability from cvelistv5
Published
2026-07-01 13:32
Modified
2026-07-10 11:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
[Why & How]
The aux_rd_interval array in struct dc_lttpr_caps is declared with
MAX_REPEATER_CNT - 1 (7) elements, indexed 0..6. However, the offset
parameter passed to dp_get_eq_aux_rd_interval() can be as large as
MAX_REPEATER_CNT (8) when a sink reports 8 LTTPR repeaters via DPCD.
This leads to an out-of-bounds read of aux_rd_interval[7] when offset
is 8.
Fix this by growing aux_rd_interval to MAX_REPEATER_CNT elements to
accommodate the full range of valid repeater counts defined by the DP
spec.
(cherry picked from commit a55a458a8df37a65ffda5cf721d554a8f74f6b04)
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/dc_dp_types.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "454d3b3d499c18373f8960d31aea48338a3ca9e0",
"status": "affected",
"version": "8e5100a575433cc185a2e224280fbd873b6692dd",
"versionType": "git"
},
{
"lessThan": "dc1490927d79fe9621e29f4a4f5d7b5ccb6aea3e",
"status": "affected",
"version": "8e5100a575433cc185a2e224280fbd873b6692dd",
"versionType": "git"
},
{
"lessThan": "e8b4d37eba05141ee01794fc6b7f2da808cee83b",
"status": "affected",
"version": "8e5100a575433cc185a2e224280fbd873b6692dd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/dc_dp_types.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()\n\n[Why \u0026 How]\nThe aux_rd_interval array in struct dc_lttpr_caps is declared with\nMAX_REPEATER_CNT - 1 (7) elements, indexed 0..6. However, the offset\nparameter passed to dp_get_eq_aux_rd_interval() can be as large as\nMAX_REPEATER_CNT (8) when a sink reports 8 LTTPR repeaters via DPCD.\nThis leads to an out-of-bounds read of aux_rd_interval[7] when offset\nis 8.\n\nFix this by growing aux_rd_interval to MAX_REPEATER_CNT elements to\naccommodate the full range of valid repeater counts defined by the DP\nspec.\n\n(cherry picked from commit a55a458a8df37a65ffda5cf721d554a8f74f6b04)"
}
],
"providerMetadata": {
"dateUpdated": "2026-07-10T11:53:48.960Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/454d3b3d499c18373f8960d31aea48338a3ca9e0"
},
{
"url": "https://git.kernel.org/stable/c/dc1490927d79fe9621e29f4a4f5d7b5ccb6aea3e"
},
{
"url": "https://git.kernel.org/stable/c/e8b4d37eba05141ee01794fc6b7f2da808cee83b"
}
],
"title": "drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53330",
"datePublished": "2026-07-01T13:32:15.160Z",
"dateReserved": "2026-06-09T07:44:35.398Z",
"dateUpdated": "2026-07-10T11:53:48.960Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64102 (GCVE-0-2026-64102)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Reject MPA FPDU length underflow before signed receive math
A malicious connected siw peer can send an iWARP FPDU whose MPA length
field (c_hdr->mpa_len, 16 bit big-endian, peer-controlled) is smaller
than the fixed DDP/RDMAP header for the announced opcode. Soft-iWARP
parses the full header in siw_get_hdr() based on iwarp_pktinfo[opcode]
.hdr_len, but never compares mpa_len against that header length.
siw_tcp_rx_data() then derives
srx->fpdu_part_rem = be16_to_cpu(mpa_len) - fpdu_part_rcvd
+ MPA_HDR_SIZE;
where fpdu_part_rcvd equals iwarp_pktinfo[opcode].hdr_len at this
point. For a tagged WRITE (hdr_len 16, MPA_HDR_SIZE 2) the smallest
on-wire mpa_len of 0 yields fpdu_part_rem = -14, and any mpa_len below
hdr_len - MPA_HDR_SIZE underflows to a negative int.
The signed value then flows into siw_proc_write()/siw_proc_rresp() as
bytes = min(srx->fpdu_part_rem, srx->skb_new);
is handed to siw_check_mem() as an int len (whose interval check
addr + len > mem->va + mem->len is satisfied for a valid base when
len is negative), and reaches siw_rx_data() -> siw_rx_kva() /
siw_rx_umem() -> skb_copy_bits() as a signed copy length. The header
copy branch in skb_copy_bits() promotes that to size_t, producing a
multi-gigabyte read.
KASAN under a KUnit harness that drives the real kernel TCP receive
path -- a loopback AF_INET socketpair, the malformed FPDU written via
kernel_sendmsg, sk_data_ready firing in softirq, tcp_read_sock
dispatching to siw_tcp_rx_data -- reports:
BUG: KASAN: use-after-free in skb_copy_bits+0x284/0x480
Read of size 4294967295 at addr ffff888...
Call Trace:
skb_copy_bits
siw_rx_kva
siw_rx_data
siw_check_mem
siw_proc_write
siw_tcp_rx_data
__tcp_read_sock
siw_qp_llp_data_ready
tcp_data_ready
tcp_data_queue
Add the missing invariant at the earliest point where the peer header
is fully assembled. iwarp_pktinfo[*].hdr_len - MPA_HDR_SIZE is exactly
the value the siw transmitter uses as the minimum mpa_len for each
opcode (drivers/infiniband/sw/siw/siw_qp.c:33), so this matches the
protocol contract. Out-of-range FPDUs terminate the connection with
TERM_ERROR_LAYER_LLP / LLP_ETYPE_MPA / LLP_ECODE_FPDU_START -- which
is RFC 5044 Section 8 error code 3 ("Marker and ULPDU Length fields
do not agree on the start of an FPDU"), the correct framing-error
class for this inconsistency.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 Version: 8b6a361b8c482f22ac99c3273285ff16b23fba91 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_qp_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "683f7cfbf514193d63c0efa079f3352bde84c2e0",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "4a331582011d9e8089af8aa2a61ec6b4443bb245",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "33a8b5e971e294ec2a7b74211c545e09efd8e9ac",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "14553be882d9ce91749c9d64041de66e34ad8e70",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "c7c0c0f4379dedec12d24dbb9dded5d2db7fd9f2",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "1012896f4225e8f801ff3c1648023845b66dfb11",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "775b4dc9618a99a1fa48b57554041a5dc17e1336",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
},
{
"lessThan": "0ce1bc9e46ecabe84772bb561e373c0d9876d6f2",
"status": "affected",
"version": "8b6a361b8c482f22ac99c3273285ff16b23fba91",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_qp_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Reject MPA FPDU length underflow before signed receive math\n\nA malicious connected siw peer can send an iWARP FPDU whose MPA length\nfield (c_hdr-\u003empa_len, 16 bit big-endian, peer-controlled) is smaller\nthan the fixed DDP/RDMAP header for the announced opcode. Soft-iWARP\nparses the full header in siw_get_hdr() based on iwarp_pktinfo[opcode]\n.hdr_len, but never compares mpa_len against that header length.\n\nsiw_tcp_rx_data() then derives\n\n srx-\u003efpdu_part_rem = be16_to_cpu(mpa_len) - fpdu_part_rcvd\n + MPA_HDR_SIZE;\n\nwhere fpdu_part_rcvd equals iwarp_pktinfo[opcode].hdr_len at this\npoint. For a tagged WRITE (hdr_len 16, MPA_HDR_SIZE 2) the smallest\non-wire mpa_len of 0 yields fpdu_part_rem = -14, and any mpa_len below\nhdr_len - MPA_HDR_SIZE underflows to a negative int.\n\nThe signed value then flows into siw_proc_write()/siw_proc_rresp() as\n\n bytes = min(srx-\u003efpdu_part_rem, srx-\u003eskb_new);\n\nis handed to siw_check_mem() as an int len (whose interval check\naddr + len \u003e mem-\u003eva + mem-\u003elen is satisfied for a valid base when\nlen is negative), and reaches siw_rx_data() -\u003e siw_rx_kva() /\nsiw_rx_umem() -\u003e skb_copy_bits() as a signed copy length. The header\ncopy branch in skb_copy_bits() promotes that to size_t, producing a\nmulti-gigabyte read.\n\nKASAN under a KUnit harness that drives the real kernel TCP receive\npath -- a loopback AF_INET socketpair, the malformed FPDU written via\nkernel_sendmsg, sk_data_ready firing in softirq, tcp_read_sock\ndispatching to siw_tcp_rx_data -- reports:\n\n BUG: KASAN: use-after-free in skb_copy_bits+0x284/0x480\n Read of size 4294967295 at addr ffff888...\n Call Trace:\n skb_copy_bits\n siw_rx_kva\n siw_rx_data\n siw_check_mem\n siw_proc_write\n siw_tcp_rx_data\n __tcp_read_sock\n siw_qp_llp_data_ready\n tcp_data_ready\n tcp_data_queue\n\nAdd the missing invariant at the earliest point where the peer header\nis fully assembled. iwarp_pktinfo[*].hdr_len - MPA_HDR_SIZE is exactly\nthe value the siw transmitter uses as the minimum mpa_len for each\nopcode (drivers/infiniband/sw/siw/siw_qp.c:33), so this matches the\nprotocol contract. Out-of-range FPDUs terminate the connection with\nTERM_ERROR_LAYER_LLP / LLP_ETYPE_MPA / LLP_ECODE_FPDU_START -- which\nis RFC 5044 Section 8 error code 3 (\"Marker and ULPDU Length fields\ndo not agree on the start of an FPDU\"), the correct framing-error\nclass for this inconsistency."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A remote attacker triggers this by sending a malformed iWARP FPDU over an established TCP connection; the kernel processes it in the TCP softirq receive path via siw_tcp_rx_data without any local access.\nAC:L - The attacker fully controls the peer-supplied mpa_len field and can reliably underflow fpdu_part_rem with a single crafted packet (e.g., mpa_len=0 on a tagged WRITE with hdr_len=16); no races or uncontrollable memory layout are required.\nPR:N - Exploitation requires only network reachability to a host running an iWARP listener (e.g., SMB Direct/RDMA-over-TCP on siw); completing the MPA/TCP handshake does not require any local account or elevated privileges on the victim system.\nUI:N - No victim user interaction is needed; the malformed FPDU is processed automatically when received on the connected TCP socket during normal kernel softirq handling.\nS:U - Impact is confined to kernel memory and RDMA-registered buffers on the victim host; this is standard in-kernel memory corruption without crossing a VM, container, or IOMMU security boundary.\nC:H - The negative copy length is promoted to a huge unsigned value in skb_copy_bits, producing a multi-gigabyte out-of-bounds read; KASAN confirmed use-after-free with a 4294967295-byte read, enabling arbitrary kernel memory disclosure.\nI:H - The same corrupted length drives skb_copy_bits writes into RDMA target memory (siw_rx_kva/siw_rx_umem) after siw_check_mem is bypassed by negative len, enabling out-of-bounds writes exploitable for memory corruption and potential code execution.\nA:H - KASAN reports use-after-free in skb_copy_bits during normal receive processing, and this class of kernel memory corruption reliably causes oops/panic or exploitable instability under attacker control."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:14.704Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/683f7cfbf514193d63c0efa079f3352bde84c2e0"
},
{
"url": "https://git.kernel.org/stable/c/4a331582011d9e8089af8aa2a61ec6b4443bb245"
},
{
"url": "https://git.kernel.org/stable/c/33a8b5e971e294ec2a7b74211c545e09efd8e9ac"
},
{
"url": "https://git.kernel.org/stable/c/14553be882d9ce91749c9d64041de66e34ad8e70"
},
{
"url": "https://git.kernel.org/stable/c/c7c0c0f4379dedec12d24dbb9dded5d2db7fd9f2"
},
{
"url": "https://git.kernel.org/stable/c/1012896f4225e8f801ff3c1648023845b66dfb11"
},
{
"url": "https://git.kernel.org/stable/c/775b4dc9618a99a1fa48b57554041a5dc17e1336"
},
{
"url": "https://git.kernel.org/stable/c/0ce1bc9e46ecabe84772bb561e373c0d9876d6f2"
}
],
"title": "RDMA/siw: Reject MPA FPDU length underflow before signed receive math",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64102",
"datePublished": "2026-07-19T15:40:06.776Z",
"dateReserved": "2026-07-19T07:54:57.033Z",
"dateUpdated": "2026-08-05T12:39:14.704Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68403 (GCVE-0-2026-68403)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: initialize SDIO data work before cleanup
brcmf_sdio_probe() stores the newly allocated bus in sdiodev->bus before
allocating the ordered workqueue. If that allocation fails, the function
jumps to fail and calls brcmf_sdio_remove().
brcmf_sdio_remove() unconditionally cancels bus->datawork. Initialize the
work item before the first failure path that can reach brcmf_sdio_remove(),
so the cleanup path always observes a valid work object.
This issue was found by our static analysis tool and then confirmed by
manual review of the probe error path and the remove-time work drain. The
problem pattern is an early setup failure that reaches a cleanup helper
which cancels an embedded work item before its initializer has run.
A QEMU PoC forced alloc_ordered_workqueue() to fail at the same point in
brcmf_sdio_probe(), before INIT_WORK(&bus->datawork) is reached. The
resulting fail path calls brcmf_sdio_remove(), and DEBUG_OBJECTS reports
the invalid work drain with brcmf_sdio_probe() and brcmf_sdio_remove() in
the stack.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "860887d22890417d43ef8298f0cc4865e29b54de",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "9a4be91e5bb032b34cb3c962f6d4f82e7ef09364",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "fb12c87ae855346321af72e57a93c146205f1090",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "f50a2b9e57a751e70ae9a272875d80d39eaccd6a",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "6bd21ec8549a5854dd64204a66289952917a924c",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "5c342437ea44bb829680ca9e4f683dd5b325b219",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "c73c3fc1c7ca5a927639f0884624cb244ba791e4",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "2a665946e0407a05a3f81bd56a08553c446498e0",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: initialize SDIO data work before cleanup\n\nbrcmf_sdio_probe() stores the newly allocated bus in sdiodev-\u003ebus before\nallocating the ordered workqueue. If that allocation fails, the function\njumps to fail and calls brcmf_sdio_remove().\n\nbrcmf_sdio_remove() unconditionally cancels bus-\u003edatawork. Initialize the\nwork item before the first failure path that can reach brcmf_sdio_remove(),\nso the cleanup path always observes a valid work object.\n\nThis issue was found by our static analysis tool and then confirmed by\nmanual review of the probe error path and the remove-time work drain. The\nproblem pattern is an early setup failure that reaches a cleanup helper\nwhich cancels an embedded work item before its initializer has run.\n\nA QEMU PoC forced alloc_ordered_workqueue() to fail at the same point in\nbrcmf_sdio_probe(), before INIT_WORK(\u0026bus-\u003edatawork) is reached. The\nresulting fail path calls brcmf_sdio_remove(), and DEBUG_OBJECTS reports\nthe invalid work drain with brcmf_sdio_probe() and brcmf_sdio_remove() in\nthe stack."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:54.805Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/860887d22890417d43ef8298f0cc4865e29b54de"
},
{
"url": "https://git.kernel.org/stable/c/9a4be91e5bb032b34cb3c962f6d4f82e7ef09364"
},
{
"url": "https://git.kernel.org/stable/c/fb12c87ae855346321af72e57a93c146205f1090"
},
{
"url": "https://git.kernel.org/stable/c/f50a2b9e57a751e70ae9a272875d80d39eaccd6a"
},
{
"url": "https://git.kernel.org/stable/c/6bd21ec8549a5854dd64204a66289952917a924c"
},
{
"url": "https://git.kernel.org/stable/c/5c342437ea44bb829680ca9e4f683dd5b325b219"
},
{
"url": "https://git.kernel.org/stable/c/c73c3fc1c7ca5a927639f0884624cb244ba791e4"
},
{
"url": "https://git.kernel.org/stable/c/2a665946e0407a05a3f81bd56a08553c446498e0"
}
],
"title": "wifi: brcmfmac: initialize SDIO data work before cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68403",
"datePublished": "2026-08-10T12:04:23.150Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:34:54.805Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64125 (GCVE-0-2026-64125)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: keep RBUF EEE/PM disabled
Setting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX
path on GENET hardware once MAC EEE becomes active. RX traffic stops
flowing while the link stays up and the usual descriptor/RX error
counters remain quiet. In that state the MAC still accepts frames
(rbuf_ovflow_cnt keeps climbing) but RBUF no longer forwards them to
DMA, so rx_packets is no longer incremented at the netdev level. On
some boards the corruption ends up as a paging fault in
skb_release_data via bcmgenet_rx_poll on an LPI exit.
Reproduced on Pi 4B (BCM2711 + BCM54213PE) and confirmed by Florian
Fainelli on an internal Broadcom 4908-family board with the same crash
signature. RBUF_PM_EN is not publicly documented.
This shows up more often now that phy_support_eee() enables EEE by
default, but it also affects older kernels as soon as TX LPI is
turned on via ethtool, so it is not specific to recent changes.
Always clear RBUF_EEE_EN | RBUF_PM_EN in bcmgenet_eee_enable_set so
the bits stay off across resets. UMAC and TBUF setup is left alone so
TX-side EEE keeps working.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6ef398ea60d931b97d69ed080bd0bd00fac38ec6 Version: 6ef398ea60d931b97d69ed080bd0bd00fac38ec6 Version: 6ef398ea60d931b97d69ed080bd0bd00fac38ec6 Version: 6ef398ea60d931b97d69ed080bd0bd00fac38ec6 Version: 6ef398ea60d931b97d69ed080bd0bd00fac38ec6 Version: 6ef398ea60d931b97d69ed080bd0bd00fac38ec6 Version: 6ef398ea60d931b97d69ed080bd0bd00fac38ec6 Version: 6ef398ea60d931b97d69ed080bd0bd00fac38ec6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/broadcom/genet/bcmgenet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2040eb83f6ada148fb32dd98b943a498005d79f2",
"status": "affected",
"version": "6ef398ea60d931b97d69ed080bd0bd00fac38ec6",
"versionType": "git"
},
{
"lessThan": "f2782ddac82c70df313012da5f71f1f06b5553ca",
"status": "affected",
"version": "6ef398ea60d931b97d69ed080bd0bd00fac38ec6",
"versionType": "git"
},
{
"lessThan": "b579f3a73da7a7e74213558f4cc3d865c30aaa78",
"status": "affected",
"version": "6ef398ea60d931b97d69ed080bd0bd00fac38ec6",
"versionType": "git"
},
{
"lessThan": "289499907399c5a9f2ed82cb34df49112bb8488f",
"status": "affected",
"version": "6ef398ea60d931b97d69ed080bd0bd00fac38ec6",
"versionType": "git"
},
{
"lessThan": "a212fc08f5c48a16a94092bf0a9a8b7cf4483b11",
"status": "affected",
"version": "6ef398ea60d931b97d69ed080bd0bd00fac38ec6",
"versionType": "git"
},
{
"lessThan": "3d4ef05266ab16d8ef7dd21658a557801eb78704",
"status": "affected",
"version": "6ef398ea60d931b97d69ed080bd0bd00fac38ec6",
"versionType": "git"
},
{
"lessThan": "49bdf6bbb21b9c6e3f4d0c1910bf0ef98424be95",
"status": "affected",
"version": "6ef398ea60d931b97d69ed080bd0bd00fac38ec6",
"versionType": "git"
},
{
"lessThan": "9a1730245e416d11ad5c0f2c100061d61cc43f60",
"status": "affected",
"version": "6ef398ea60d931b97d69ed080bd0bd00fac38ec6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/broadcom/genet/bcmgenet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bcmgenet: keep RBUF EEE/PM disabled\n\nSetting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX\npath on GENET hardware once MAC EEE becomes active. RX traffic stops\nflowing while the link stays up and the usual descriptor/RX error\ncounters remain quiet. In that state the MAC still accepts frames\n(rbuf_ovflow_cnt keeps climbing) but RBUF no longer forwards them to\nDMA, so rx_packets is no longer incremented at the netdev level. On\nsome boards the corruption ends up as a paging fault in\nskb_release_data via bcmgenet_rx_poll on an LPI exit.\n\nReproduced on Pi 4B (BCM2711 + BCM54213PE) and confirmed by Florian\nFainelli on an internal Broadcom 4908-family board with the same crash\nsignature. RBUF_PM_EN is not publicly documented.\n\nThis shows up more often now that phy_support_eee() enables EEE by\ndefault, but it also affects older kernels as soon as TX LPI is\nturned on via ethtool, so it is not specific to recent changes.\n\nAlways clear RBUF_EEE_EN | RBUF_PM_EN in bcmgenet_eee_enable_set so\nthe bits stay off across resets. UMAC and TBUF setup is left alone so\nTX-side EEE keeps working."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The fault is reached in `bcmgenet_rx_poll` during NAPI processing of received Ethernet frames; any remote host that can send traffic to a GENET-equipped, network-connected target (e.g., internet-exposed Raspberry Pi, Broadcom gateway, or edge IoT device) can drive RX activity and LPI exit transitions that trigger the corrupted RX path.\nAC:L - On affected GENET hardware with an EEE-capable link partner (now common and enabled by default via `phy_support_eee()`), the bug reproduces within minutes under normal RX load without attacker-influenced memory layout, and the attacker controls timing by sending sustained or bursty traffic to force LPI entry/exit cycles.\nPR:N - Exploitation does not require authentication or elevated privileges; EEE is enabled automatically at link-up through `bcmgenet_mii_setup()` \u2192 `bcmgenet_eee_enable_set()`, so a remote attacker only needs the ability to send network packets to the target interface.\nUI:N - No victim action is required beyond the device having a normal link with EEE-capable equipment; the misconfigured RBUF registers and subsequent RX stall or kernel oops occur during routine background network activity.\nS:U - Impact is confined to kernel/network availability on the same host (RX path stall, skb corruption, and kernel panic); there is no demonstrated crossing of a VM, container, or IOMMU security boundary.\nC:H - Hardware RX desynchronization from incorrectly enabled `RBUF_EEE_EN|RBUF_PM_EN` corrupts skb/DMA ring state and manifests as invalid pointers in `skb_release_data` during `bcmgenet_rx_poll`, consistent with use-after-free/double-free class corruption that can enable arbitrary kernel memory disclosure.\nI:H - The same skb pointer corruption in the RX teardown path can yield heap write primitives (double-free/incorrect free of sk_buff metadata) during LPI exit, which is the class of memory corruption typically leveraged for kernel control-flow hijacking.\nA:H - The bug reliably causes complete RX failure (silent loss of connectivity while the link remains up) and can escalate to a fatal kernel oops/panic in softirq context, constituting total loss of network availability and potential full system availability loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:31.893Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2040eb83f6ada148fb32dd98b943a498005d79f2"
},
{
"url": "https://git.kernel.org/stable/c/f2782ddac82c70df313012da5f71f1f06b5553ca"
},
{
"url": "https://git.kernel.org/stable/c/b579f3a73da7a7e74213558f4cc3d865c30aaa78"
},
{
"url": "https://git.kernel.org/stable/c/289499907399c5a9f2ed82cb34df49112bb8488f"
},
{
"url": "https://git.kernel.org/stable/c/a212fc08f5c48a16a94092bf0a9a8b7cf4483b11"
},
{
"url": "https://git.kernel.org/stable/c/3d4ef05266ab16d8ef7dd21658a557801eb78704"
},
{
"url": "https://git.kernel.org/stable/c/49bdf6bbb21b9c6e3f4d0c1910bf0ef98424be95"
},
{
"url": "https://git.kernel.org/stable/c/9a1730245e416d11ad5c0f2c100061d61cc43f60"
}
],
"title": "net: bcmgenet: keep RBUF EEE/PM disabled",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64125",
"datePublished": "2026-07-19T15:40:22.590Z",
"dateReserved": "2026-07-19T07:54:57.036Z",
"dateUpdated": "2026-08-05T12:39:31.893Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63999 (GCVE-0-2026-63999)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-07-19 14:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ethtool: rss: fix indir_table and hkey leak on get_rxfh failure
rss_prepare_get() allocates the indirection table and hash key buffer
via rss_get_data_alloc(), then calls ops->get_rxfh() to populate them.
If get_rxfh() fails, the function returns an error without freeing
the allocation.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4f038a6a02d20859a3479293cbf172b0f14cbdd6 Version: 4f038a6a02d20859a3479293cbf172b0f14cbdd6 Version: 4f038a6a02d20859a3479293cbf172b0f14cbdd6 Version: 81a5174e64ce4fb7b7a2f6499b835c904c9451ee Version: ec9faff49a4ea27731de39cb887b7e590e93157b Version: c5ed0eaddcbda56079091fc3876b140a6e70a548 Version: a065b996052656a65afc51ad82336dc55ae4c72f Version: adee9db710a6117b978a25ed4153846b7c56ec9a Version: 5eb3fdc4b6281b29e830300c866a36d90442b1f0 Version: 5.15.181 ≤ Version: 6.1.135 ≤ Version: 6.6.88 ≤ Version: 6.12.24 ≤ Version: 6.13.12 ≤ Version: 6.14.3 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ethtool/rss.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "33d05c22d6f227c5ae171c46df2f6f8bf48047ea",
"status": "affected",
"version": "4f038a6a02d20859a3479293cbf172b0f14cbdd6",
"versionType": "git"
},
{
"lessThan": "80d95d92f828cfcace955d673637d944178b435f",
"status": "affected",
"version": "4f038a6a02d20859a3479293cbf172b0f14cbdd6",
"versionType": "git"
},
{
"lessThan": "266297692f97008ca48bc311775c087c59bd7fe3",
"status": "affected",
"version": "4f038a6a02d20859a3479293cbf172b0f14cbdd6",
"versionType": "git"
},
{
"status": "affected",
"version": "81a5174e64ce4fb7b7a2f6499b835c904c9451ee",
"versionType": "git"
},
{
"status": "affected",
"version": "ec9faff49a4ea27731de39cb887b7e590e93157b",
"versionType": "git"
},
{
"status": "affected",
"version": "c5ed0eaddcbda56079091fc3876b140a6e70a548",
"versionType": "git"
},
{
"status": "affected",
"version": "a065b996052656a65afc51ad82336dc55ae4c72f",
"versionType": "git"
},
{
"status": "affected",
"version": "adee9db710a6117b978a25ed4153846b7c56ec9a",
"versionType": "git"
},
{
"status": "affected",
"version": "5eb3fdc4b6281b29e830300c866a36d90442b1f0",
"versionType": "git"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.181",
"versionType": "semver"
},
{
"lessThan": "6.2",
"status": "affected",
"version": "6.1.135",
"versionType": "semver"
},
{
"lessThan": "6.7",
"status": "affected",
"version": "6.6.88",
"versionType": "semver"
},
{
"lessThan": "6.13",
"status": "affected",
"version": "6.12.24",
"versionType": "semver"
},
{
"lessThan": "6.14",
"status": "affected",
"version": "6.13.12",
"versionType": "semver"
},
{
"lessThan": "6.15",
"status": "affected",
"version": "6.14.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ethtool/rss.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"lessThan": "6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.181",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.1.135",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.6.88",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.12.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.13.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.14.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: rss: fix indir_table and hkey leak on get_rxfh failure\n\nrss_prepare_get() allocates the indirection table and hash key buffer\nvia rss_get_data_alloc(), then calls ops-\u003eget_rxfh() to populate them.\nIf get_rxfh() fails, the function returns an error without freeing\nthe allocation."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:56:17.383Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/33d05c22d6f227c5ae171c46df2f6f8bf48047ea"
},
{
"url": "https://git.kernel.org/stable/c/80d95d92f828cfcace955d673637d944178b435f"
},
{
"url": "https://git.kernel.org/stable/c/266297692f97008ca48bc311775c087c59bd7fe3"
}
],
"title": "ethtool: rss: fix indir_table and hkey leak on get_rxfh failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63999",
"datePublished": "2026-07-19T14:56:17.383Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-07-19T14:56:17.383Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63881 (GCVE-0-2026-63881)
Vulnerability from cvelistv5
Published
2026-07-19 14:54
Modified
2026-08-05 12:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
get_queue_ids() computes array_size = num_queues * sizeof(uint32_t),
which could overflow on 32-bit size_t build. using array_size()
instead, it saturates to SIZE_MAX on overflow.
(cherry picked from commit 2d57a0475f085c08b49312dfd8edcb461845f285)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4e5f808b454167cc58d7084a407a554d8ddc694d",
"status": "affected",
"version": "a70a93fa568b4f05aba548dadb673703eccf5480",
"versionType": "git"
},
{
"lessThan": "de70a80992396ee306ee3a2810ad28aa1608ba9b",
"status": "affected",
"version": "a70a93fa568b4f05aba548dadb673703eccf5480",
"versionType": "git"
},
{
"lessThan": "5cf4a41aa0d74e4c83f82d2ce233b5189ed4b43c",
"status": "affected",
"version": "a70a93fa568b4f05aba548dadb673703eccf5480",
"versionType": "git"
},
{
"lessThan": "4f9eeedc3d3151f8a226fd676c314a813edda5a1",
"status": "affected",
"version": "a70a93fa568b4f05aba548dadb673703eccf5480",
"versionType": "git"
},
{
"lessThan": "93f5534b35a05ef8a0109c1eefa800062fee810a",
"status": "affected",
"version": "a70a93fa568b4f05aba548dadb673703eccf5480",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix a vulnerability of integer overflow in kfd debugger\n\nget_queue_ids() computes array_size = num_queues * sizeof(uint32_t),\nwhich could overflow on 32-bit size_t build. using array_size()\ninstead, it saturates to SIZE_MAX on overflow.\n\n(cherry picked from commit 2d57a0475f085c08b49312dfd8edcb461845f285)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local `ioctl()` on `/dev/kfd` via `AMDKFD_IOC_DBG_TRAP` with `KFD_IOC_DBG_TRAP_SUSPEND_QUEUES` or `KFD_IOC_DBG_TRAP_RESUME_QUEUES`; there is no network, adjacent-radio, or physical-access path to the vulnerable code.\nAC:L - On affected 32-bit `size_t` kernel builds, an attacker fully controls `num_queues` in the ioctl and can reliably force the multiply overflow (e.g. `num_queues \u003e= 0x40000001`) to trigger undersized `memdup_user()` followed by unbounded kernel heap corruption.\nPR:L - A local unprivileged user with AMDGPU/KFD device access can open `/dev/kfd`, enable the debug runtime and debug trap on their own process (no ptrace or root required), then invoke suspend/resume with a malicious `num_queues` value.\nUI:N - Exploitation is achieved entirely through attacker-initiated ioctl calls in an established KFD debug session; no victim interaction is required.\nS:U - Impact is kernel heap corruption and potential local privilege escalation within the same kernel security boundary, not a cross-boundary escape such as VM guest-to-host or IOMMU bypass.\nC:H - The integer overflow causes a heap buffer far smaller than `num_queues`, and subsequent `q_array_get_index()`/`copy_to_user()` operations perform out-of-bounds kernel reads that can disclose adjacent heap memory and be leveraged for arbitrary read primitives.\nI:H - `q_array_invalidate()` and per-queue status updates write attacker-influenced values (`KFD_DBG_QUEUE_INVALID_MASK`/`KFD_DBG_QUEUE_ERROR_MASK`) far beyond the allocated buffer, constituting an out-of-bounds heap write exploitable for control-flow hijacking and arbitrary kernel modification.\nA:H - Writing billions of 32-bit values past a 4-byte kmalloc object corrupts adjacent kernel heap metadata and objects, readily causing kernel oops/panic and complete loss of availability even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:36:51.042Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4e5f808b454167cc58d7084a407a554d8ddc694d"
},
{
"url": "https://git.kernel.org/stable/c/de70a80992396ee306ee3a2810ad28aa1608ba9b"
},
{
"url": "https://git.kernel.org/stable/c/5cf4a41aa0d74e4c83f82d2ce233b5189ed4b43c"
},
{
"url": "https://git.kernel.org/stable/c/4f9eeedc3d3151f8a226fd676c314a813edda5a1"
},
{
"url": "https://git.kernel.org/stable/c/93f5534b35a05ef8a0109c1eefa800062fee810a"
}
],
"title": "drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63881",
"datePublished": "2026-07-19T14:54:53.676Z",
"dateReserved": "2026-07-19T07:54:57.018Z",
"dateUpdated": "2026-08-05T12:36:51.042Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63823 (GCVE-0-2026-63823)
Vulnerability from cvelistv5
Published
2026-07-19 12:02
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
keys: Pin request_key_auth payload in instantiate paths
A: request_key() B: KEYCTL_INSTANTIATE_IOV
================ =========================
create auth key
store rka in auth key
wait for helper
get auth key
load rka from auth key
copy user payload
sleep on #PF
helper completed
detach and free rka
destroy auth key
wake up
use rka->target_key
**USE-AFTER-FREE**
Give request_key_auth payloads a refcount. Take a payload reference while
authkey->sem stabilizes the payload and revocation state. Hold that
reference across the instantiate and reject paths. Drop the auth key
owning reference from revoke and destroy.
[jarkko: Replaced the first two paragraphs of text with an actual
concurrency scenario.]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b5f545c880a2a47947ba2118b2509644ab7a2969 Version: b5f545c880a2a47947ba2118b2509644ab7a2969 Version: b5f545c880a2a47947ba2118b2509644ab7a2969 Version: b5f545c880a2a47947ba2118b2509644ab7a2969 Version: b5f545c880a2a47947ba2118b2509644ab7a2969 Version: b5f545c880a2a47947ba2118b2509644ab7a2969 Version: b5f545c880a2a47947ba2118b2509644ab7a2969 Version: b5f545c880a2a47947ba2118b2509644ab7a2969 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/keys/request_key_auth-type.h",
"security/keys/internal.h",
"security/keys/keyctl.c",
"security/keys/request_key_auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d8274181b0f28d450b42489723a5ba81042158d7",
"status": "affected",
"version": "b5f545c880a2a47947ba2118b2509644ab7a2969",
"versionType": "git"
},
{
"lessThan": "4982bfabce6b33b3c9eddb4fb900fe5568b7cf91",
"status": "affected",
"version": "b5f545c880a2a47947ba2118b2509644ab7a2969",
"versionType": "git"
},
{
"lessThan": "708709c65a1832a99b0eef8ae46e343ddaca3d06",
"status": "affected",
"version": "b5f545c880a2a47947ba2118b2509644ab7a2969",
"versionType": "git"
},
{
"lessThan": "35ab4db86774d82389e4b9559e26ab7f68d8e395",
"status": "affected",
"version": "b5f545c880a2a47947ba2118b2509644ab7a2969",
"versionType": "git"
},
{
"lessThan": "f9b68632ac93cc742f2e411021c4dbfe452ea0c2",
"status": "affected",
"version": "b5f545c880a2a47947ba2118b2509644ab7a2969",
"versionType": "git"
},
{
"lessThan": "7216ce8cb12fee44e309503955bb83806b106129",
"status": "affected",
"version": "b5f545c880a2a47947ba2118b2509644ab7a2969",
"versionType": "git"
},
{
"lessThan": "83c0a1cb296d955d5f4d1f0bd8a769ba8ed8c29f",
"status": "affected",
"version": "b5f545c880a2a47947ba2118b2509644ab7a2969",
"versionType": "git"
},
{
"lessThan": "fd15b457a86939c38aa12116adabd8ff686c5e51",
"status": "affected",
"version": "b5f545c880a2a47947ba2118b2509644ab7a2969",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/keys/request_key_auth-type.h",
"security/keys/internal.h",
"security/keys/keyctl.c",
"security/keys/request_key_auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.16"
},
{
"lessThan": "2.6.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.260",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.260",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: Pin request_key_auth payload in instantiate paths\n\nA: request_key() B: KEYCTL_INSTANTIATE_IOV\n================ =========================\n\ncreate auth key\nstore rka in auth key\nwait for helper\n get auth key\n load rka from auth key\n copy user payload\n sleep on #PF\n\nhelper completed\ndetach and free rka\ndestroy auth key\n wake up\n use rka-\u003etarget_key\n **USE-AFTER-FREE**\n\nGive request_key_auth payloads a refcount. Take a payload reference while\nauthkey-\u003esem stabilizes the payload and revocation state. Hold that\nreference across the instantiate and reject paths. Drop the auth key\nowning reference from revoke and destroy.\n\n[jarkko: Replaced the first two paragraphs of text with an actual\n concurrency scenario.]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local `request_key()` and `keyctl()` syscalls (`KEYCTL_ASSUME_AUTHORITY`, `KEYCTL_INSTANTIATE`, `KEYCTL_INSTANTIATE_IOV`, `KEYCTL_REJECT`); there is no network, adjacent-radio, or physical-device entry path.\nAC:L - Exploitation is a race the attacker orchestrates by calling `request_key()` and concurrently driving `KEYCTL_INSTANTIATE_IOV` with a user buffer that page-faults during `copy_from_iter_full()`, while a second helper thread or completion path revokes/frees the auth payload.\nPR:L - Any unprivileged local user can invoke `request_key()` and the affected `keyctl` instantiate/reject operations in the spawned helper context; no real-root or non-userns capability is required.\nUI:N - Exploitation does not depend on a victim performing an action beyond the attacker\u2019s own syscall activity and helper process setup.\nS:U - Impact is kernel memory corruption and local privilege escalation within the same kernel security domain, not a VM-guest-to-host or IOMMU boundary escape.\nC:H - This is a heap use-after-free of `struct request_key_auth`; after free the code dereferences `rka-\u003etarget_key` and related fields, enabling attacker-controlled reuse and arbitrary kernel memory disclosure.\nI:H - The UAF corrupts trusted kernel pointers (`target_key`, `dest_keyring`) used in `key_instantiate_and_link()`, which can be turned into arbitrary kernel writes and local privilege escalation.\nA:H - Use-after-free of kernel heap objects can cause kernel oops/panic during post-fault dereferences, and is independently severe even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:31.393Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d8274181b0f28d450b42489723a5ba81042158d7"
},
{
"url": "https://git.kernel.org/stable/c/4982bfabce6b33b3c9eddb4fb900fe5568b7cf91"
},
{
"url": "https://git.kernel.org/stable/c/708709c65a1832a99b0eef8ae46e343ddaca3d06"
},
{
"url": "https://git.kernel.org/stable/c/35ab4db86774d82389e4b9559e26ab7f68d8e395"
},
{
"url": "https://git.kernel.org/stable/c/f9b68632ac93cc742f2e411021c4dbfe452ea0c2"
},
{
"url": "https://git.kernel.org/stable/c/7216ce8cb12fee44e309503955bb83806b106129"
},
{
"url": "https://git.kernel.org/stable/c/83c0a1cb296d955d5f4d1f0bd8a769ba8ed8c29f"
},
{
"url": "https://git.kernel.org/stable/c/fd15b457a86939c38aa12116adabd8ff686c5e51"
}
],
"title": "keys: Pin request_key_auth payload in instantiate paths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63823",
"datePublished": "2026-07-19T12:02:19.847Z",
"dateReserved": "2026-07-19T07:54:57.014Z",
"dateUpdated": "2026-08-17T04:51:31.393Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68161 (GCVE-0-2026-68161)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: close UDP tunnel sockets during netns teardown
proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when
net.sctp.udp_port is set, and stops/restarts them when the sysctl value
changes. The netns exit path does not stop these sockets, so a namespace
can be torn down while its SCTP UDP tunnel sockets are still installed.
Close the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering
the per-net sysctl table. This prevents new sysctl writes from racing in
while the sockets are being released, and closes the sockets before the
control socket is destroyed.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/protocol.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c6eb2d615210b80339548ab07c0230edaab9a6c7",
"status": "affected",
"version": "046c052b475e7119b6a30e3483e2888fc606a2f8",
"versionType": "git"
},
{
"lessThan": "8ff78591d309c50a4fdab683b68dd8d512a270dd",
"status": "affected",
"version": "046c052b475e7119b6a30e3483e2888fc606a2f8",
"versionType": "git"
},
{
"lessThan": "3bf0e349cbb4f975f35eb22753acc346b89c66a0",
"status": "affected",
"version": "046c052b475e7119b6a30e3483e2888fc606a2f8",
"versionType": "git"
},
{
"lessThan": "37ff9794be48d0caa37687e04d09675f9c849121",
"status": "affected",
"version": "046c052b475e7119b6a30e3483e2888fc606a2f8",
"versionType": "git"
},
{
"lessThan": "ffb2bd7ade36ec4da32c46a6eddbf4515316d08c",
"status": "affected",
"version": "046c052b475e7119b6a30e3483e2888fc606a2f8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/protocol.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: close UDP tunnel sockets during netns teardown\n\nproc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when\nnet.sctp.udp_port is set, and stops/restarts them when the sysctl value\nchanges. The netns exit path does not stop these sockets, so a namespace\ncan be torn down while its SCTP UDP tunnel sockets are still installed.\n\nClose the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering\nthe per-net sysctl table. This prevents new sysctl writes from racing in\nwhile the sockets are being released, and closes the sockets before the\ncontrol socket is destroyed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Stale SCTP UDP tunnel sockets left installed after netns teardown still receive remote SCTP-over-UDP (RFC 6951) on the configured net.sctp.udp_port; packets enter sctp_udp_rcv\u2192sctp_rcv in softirq and touch freed per-net SCTP/UDP state.\nAC:L - An attacker can repeatedly race namespace deletion against SCTP-over-UDP traffic they send or receive, controlling both teardown timing and packet delivery; no attacker-uncontrollable memory layout or rare kernel config is required beyond SCTP being enabled.\nPR:N - On SCTP-over-UDP deployments where net.sctp.udp_port is already configured, any remote SCTP peer needs no credentials on the target; alternatively an unprivileged local user obtains CAP_NET_ADMIN via user namespaces to set udp_port and destroy the namespace.\nUI:N - Exploitation requires only attacker-driven SCTP-over-UDP traffic and namespace lifecycle events (e.g., container restart); no victim must mount a filesystem, open a file, or take any separate interactive action.\nS:U - Impact is host-kernel slab use-after-free and memory corruption within the same OS security authority; it does not cross VM, IOMMU, or sandbox boundaries to affect a separate security domain.\nC:H - Use-after-free of struct net and SCTP UDP tunnel socket state lets an attacker influence freed slab contents and obtain arbitrary kernel memory read primitives through subsequent SCTP/UDP lookups and socket processing.\nI:H - The UAF enables heap grooming and reuse of freed per-net/socket objects in SCTP/UDP handlers, supporting arbitrary kernel writes and control-flow hijack typical of slab use-after-free exploitation.\nA:H - Dereferencing SCTP/UDP tunnel sockets and per-net state after netns free causes slab use-after-free detections, kernel oops, or panic; even unexploited UAF commonly crashes or hangs the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:57.755Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c6eb2d615210b80339548ab07c0230edaab9a6c7"
},
{
"url": "https://git.kernel.org/stable/c/8ff78591d309c50a4fdab683b68dd8d512a270dd"
},
{
"url": "https://git.kernel.org/stable/c/3bf0e349cbb4f975f35eb22753acc346b89c66a0"
},
{
"url": "https://git.kernel.org/stable/c/37ff9794be48d0caa37687e04d09675f9c849121"
},
{
"url": "https://git.kernel.org/stable/c/ffb2bd7ade36ec4da32c46a6eddbf4515316d08c"
}
],
"title": "sctp: close UDP tunnel sockets during netns teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68161",
"datePublished": "2026-08-10T11:59:28.072Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-17T04:59:57.755Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68142 (GCVE-0-2026-68142)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
geneve: require CAP_NET_ADMIN in the device netns for changelink
A tunnel changelink() operates on at most two netns, dev_net(dev) and
the sticky underlay netns geneve->net. They differ once the device is
created in or moved to a netns other than the one the request runs in.
The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),
so a caller privileged there but not in geneve->net can rewrite a geneve
device whose underlay lives in geneve->net.
geneve_changelink() applies the new configuration against geneve->net:
geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair
reopen the underlay sockets in that netns (geneve_sock_add() uses
geneve->net), so the same reasoning as the tunnel changelink series
applies here.
Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of
the op before any attribute is parsed, matching ipgre_changelink() and
the rest of the "require CAP_NET_ADMIN in the device netns for
changelink" series.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/geneve.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a5522963c57f12df5f9db804ebfc472b58eef0ae",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "278c6a31ee27c931c722202c8c06cc3253923254",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "11a7d989d00160481a273eb4f7f05f64b5a6ffdf",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "2abdacc927c92fa6a9cc8341e8c9b88dcb561553",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "9de5518fc1fab583526a8f66b8e505c4864dc60a",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "f8c498585d2a08aa623748353c3e61467b7e9fd2",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "95f45e20f1b2cec13823f0f68060ab4b2261b2c1",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/geneve.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: require CAP_NET_ADMIN in the device netns for changelink\n\nA tunnel changelink() operates on at most two netns, dev_net(dev) and\nthe sticky underlay netns geneve-\u003enet. They differ once the device is\ncreated in or moved to a netns other than the one the request runs in.\nThe rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),\nso a caller privileged there but not in geneve-\u003enet can rewrite a geneve\ndevice whose underlay lives in geneve-\u003enet.\n\ngeneve_changelink() applies the new configuration against geneve-\u003enet:\ngeneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair\nreopen the underlay sockets in that netns (geneve_sock_add() uses\ngeneve-\u003enet), so the same reasoning as the tunnel changelink series\napplies here.\n\nGate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of\nthe op before any attribute is parsed, matching ipgre_changelink() and\nthe rest of the \"require CAP_NET_ADMIN in the device netns for\nchangelink\" series.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires issuing RTM_NEWLINK changelink over a local rtnetlink socket; geneve_changelink is only reachable from the rtnl configuration path, not from received GENEVE/UDP network packets.\nAC:L - Once a geneve device exists with geneve-\u003enet differing from dev_net(dev) (via IFLA_NET_NS_FD migration or IFLA_LINK_NETNSID newlink), a single deterministic netlink changelink bypasses the missing check with no race or memory-layout dependency.\nPR:L - The rtnl entry path requires CAP_NET_ADMIN in dev_net(dev), obtainable by an unprivileged local user inside a user+network namespace via unshare --user --map-root-user --net; no CAP_NET_ADMIN in the sticky underlay netns geneve-\u003enet is needed.\nUI:N - The attack is fully programmatic through netlink from the attacker\u0027s own process; no victim action such as mounting a filesystem, opening a file, or clicking is required.\nS:C - geneve_changelink applies geneve_link_config() and geneve_quiesce()/geneve_unquiesce() (reopening underlay sockets via geneve_sock_add() in geneve-\u003enet) while authorization is checked only against dev_net(dev), crossing into another tenant\u0027s or the host\u0027s network namespace.\nC:H - An attacker can set IFLA_GENEVE_REMOTE/REMOTE6 to redirect encapsulated overlay traffic to an attacker-controlled endpoint and read tunneled payloads from the victim underlay netns.\nI:H - Unauthorized changelink mutates live tunnel remote endpoint, TTL/TOS/DF/label, and MTU in geneve-\u003enet, enabling redirection and injection of overlay traffic without authorization in that namespace.\nA:H - geneve_quiesce() drops in-flight tunnel traffic and rewriting the remote endpoint or MTU breaks production GENEVE overlays (Kubernetes/OVN/cloud SDN), causing sustained loss of connectivity for dependent services."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:02.355Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a5522963c57f12df5f9db804ebfc472b58eef0ae"
},
{
"url": "https://git.kernel.org/stable/c/278c6a31ee27c931c722202c8c06cc3253923254"
},
{
"url": "https://git.kernel.org/stable/c/11a7d989d00160481a273eb4f7f05f64b5a6ffdf"
},
{
"url": "https://git.kernel.org/stable/c/2abdacc927c92fa6a9cc8341e8c9b88dcb561553"
},
{
"url": "https://git.kernel.org/stable/c/9de5518fc1fab583526a8f66b8e505c4864dc60a"
},
{
"url": "https://git.kernel.org/stable/c/f8c498585d2a08aa623748353c3e61467b7e9fd2"
},
{
"url": "https://git.kernel.org/stable/c/95f45e20f1b2cec13823f0f68060ab4b2261b2c1"
},
{
"url": "https://git.kernel.org/stable/c/8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01"
}
],
"title": "geneve: require CAP_NET_ADMIN in the device netns for changelink",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68142",
"datePublished": "2026-08-10T11:59:06.048Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:30:02.355Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64294 (GCVE-0-2026-64294)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm: do file ownership checks with the proper mount idmap
Ever since idmapped mounts were introduced, inode ownership checks (for
side-channel protection) in mincore() and madvise(MADV_PAGEOUT) were done
against the nop_mnt_idmap, which completely ignores the file's mount's
idmap. This results in odd edgecases like:
1) mount/bind-mount with an idmap userA:userB:1
2) userB runs an owner_or_capable() check on file that is owned by userA
on-disk/in-memory, but owned by userB after idmap translation
3) owner_or_capable() mysteriously fails as the correct idmap wasn't supplied
In the case of mincore/madvise MADV_PAGEOUT, this is usually benign,
because file_permission(file, MAY_WRITE) will probably succeed, as it uses
the proper idmap internally, but it does not need to be the case on e.g a
0444 file where even the owner itself doesn't have permissions to write to
it.
Since this is clearly not trivial to get right, introduce a
file_owner_or_capable() that can carry the correct semantics, and switch
the various users in mm to it.
The issue was found by manual code inspection & an off-list discussion
with Jan Kara.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/fs.h",
"mm/filemap.c",
"mm/madvise.c",
"mm/mincore.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7368bec565bac3e536cd43579dbde1e715e6ba61",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "b2f3d94ea310bea9d36d53e9d9b3f45e86c1d893",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "744b23aa430d52f5c8e4dbff7d71496d6643bed2",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "8344bdf0629457e532797b42d9d2bbf2a2900bbf",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "5c942ad7df75925ee166e7f0fb36892d8dde376b",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "04ba248d02d9eaa3d9077b00a6134caa75fa3e90",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "e187bc02f8fa4226d62814592cf064ee4557c470",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/fs.h",
"mm/filemap.c",
"mm/madvise.c",
"mm/mincore.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: do file ownership checks with the proper mount idmap\n\nEver since idmapped mounts were introduced, inode ownership checks (for\nside-channel protection) in mincore() and madvise(MADV_PAGEOUT) were done\nagainst the nop_mnt_idmap, which completely ignores the file\u0027s mount\u0027s\nidmap. This results in odd edgecases like:\n\n1) mount/bind-mount with an idmap userA:userB:1\n2) userB runs an owner_or_capable() check on file that is owned by userA\non-disk/in-memory, but owned by userB after idmap translation\n3) owner_or_capable() mysteriously fails as the correct idmap wasn\u0027t supplied\n\nIn the case of mincore/madvise MADV_PAGEOUT, this is usually benign,\nbecause file_permission(file, MAY_WRITE) will probably succeed, as it uses\nthe proper idmap internally, but it does not need to be the case on e.g a\n0444 file where even the owner itself doesn\u0027t have permissions to write to\nit.\n\nSince this is clearly not trivial to get right, introduce a\nfile_owner_or_capable() that can carry the correct semantics, and switch\nthe various users in mm to it.\n\nThe issue was found by manual code inspection \u0026 an off-list discussion\nwith Jan Kara."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:40.258Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7368bec565bac3e536cd43579dbde1e715e6ba61"
},
{
"url": "https://git.kernel.org/stable/c/b2f3d94ea310bea9d36d53e9d9b3f45e86c1d893"
},
{
"url": "https://git.kernel.org/stable/c/744b23aa430d52f5c8e4dbff7d71496d6643bed2"
},
{
"url": "https://git.kernel.org/stable/c/8344bdf0629457e532797b42d9d2bbf2a2900bbf"
},
{
"url": "https://git.kernel.org/stable/c/5c942ad7df75925ee166e7f0fb36892d8dde376b"
},
{
"url": "https://git.kernel.org/stable/c/04ba248d02d9eaa3d9077b00a6134caa75fa3e90"
},
{
"url": "https://git.kernel.org/stable/c/e187bc02f8fa4226d62814592cf064ee4557c470"
}
],
"title": "mm: do file ownership checks with the proper mount idmap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64294",
"datePublished": "2026-07-25T08:49:32.570Z",
"dateReserved": "2026-07-19T15:36:31.778Z",
"dateUpdated": "2026-08-23T12:45:40.258Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74474 (GCVE-0-2026-74474)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: use pskb_network_may_pull() for transmit path header pulls
In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was
being called to verify the availability of network layer headers (ARP, IPv6/ND,
IP/IPv6 MDB keys).
However, during transmit skb->data points to the MAC header, so skb_network_offset(skb)
is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data
rather than skb_network_offset(skb) + len, which can leave part of the network header
in non-linear frags.
Replace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly
account for the MAC header offset.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c",
"drivers/net/vxlan/vxlan_mdb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bb01c51950c3ff3c76acdd54b85ab38ccc2a8bb4",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "6146901881f09ef063eb34ad389f63231f8486f5",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "94dee751aad627b3645d424b5d0c736d394573e9",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "7076a34b6e33315dc160b4612bfea1c597495585",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "b9553558b48db54ac9273e6b98d7263ef5c1a329",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c",
"drivers/net/vxlan/vxlan_mdb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"lessThan": "3.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: use pskb_network_may_pull() for transmit path header pulls\n\nIn vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was\nbeing called to verify the availability of network layer headers (ARP, IPv6/ND,\nIP/IPv6 MDB keys).\n\nHowever, during transmit skb-\u003edata points to the MAC header, so skb_network_offset(skb)\nis ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb-\u003edata\nrather than skb_network_offset(skb) + len, which can leave part of the network header\nin non-linear frags.\n\nReplace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly\naccount for the MAC header offset."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in VXLAN transmit handling reached when overlay/bridged traffic is sent through a VXLAN netdev; remote peers on cloud/Kubernetes/OpenStack overlay networks can inject ARP, ND, or multicast frames that traverse vxlan_xmit without local shell access.\nAC:L - Once a VXLAN device has proxy or MDB enabled, an attacker can reliably craft non-linear sk_buff frames (fragmented payloads with headers split across head/frags) to pass the undersized pskb_may_pull check and trigger out-of-bounds header reads.\nPR:N - Exploitation requires only the ability to send L2/L3 traffic on an existing VXLAN overlay; no host credentials, root, or CAP_NET_ADMIN on the victim are needed because any unauthenticated remote tenant VM, pod, or overlay peer can forward triggering frames into the transmit path.\nUI:N - No victim user action is required; the kernel processes attacker-supplied network frames automatically during normal overlay bridging and VXLAN encapsulation.\nS:U - Impact is confined to the kernel network stack on the affected host; it does not cross a VM, container, or hypervisor security boundary into a different authority.\nC:H - Undersized pskb_may_pull allows direct network-header pointer access past skb_headlen into non-linear frags or adjacent kernel memory, constituting an out-of-bounds kernel read capable of disclosing sensitive heap or packet-buffer contents.\nI:H - Out-of-bounds parsed ARP, ND, and IP header fields drive proxy neighbour replies and MDB multicast forwarding decisions, letting an attacker influence overlay neighbour resolution and traffic redirection on the victim node.\nA:H - Out-of-bounds header access in the atomic VXLAN transmit path can cause kernel oops or panic, and an unauthenticated remote attacker can trigger this repeatedly for denial of service against VXLAN-enabled infrastructure nodes."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:21.225Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bb01c51950c3ff3c76acdd54b85ab38ccc2a8bb4"
},
{
"url": "https://git.kernel.org/stable/c/6146901881f09ef063eb34ad389f63231f8486f5"
},
{
"url": "https://git.kernel.org/stable/c/94dee751aad627b3645d424b5d0c736d394573e9"
},
{
"url": "https://git.kernel.org/stable/c/7076a34b6e33315dc160b4612bfea1c597495585"
},
{
"url": "https://git.kernel.org/stable/c/b9553558b48db54ac9273e6b98d7263ef5c1a329"
}
],
"title": "vxlan: use pskb_network_may_pull() for transmit path header pulls",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74474",
"datePublished": "2026-08-15T12:27:10.037Z",
"dateReserved": "2026-08-15T05:44:03.903Z",
"dateUpdated": "2026-08-23T12:47:21.225Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46107 (GCVE-0-2026-46107)
Vulnerability from cvelistv5
Published
2026-05-28 09:35
Modified
2026-08-05 12:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dm-thin: fix metadata refcount underflow
There's a bug in dm-thin in the function rebalance_children. If the
internal btree node has one entry, the code tries to copy all btree
entries from the node's child to the node itself and then decrement the
child's reference count.
If the child node is shared (it has reference count > 1), we won't free
it, so there would be two pointers to each of the grandchildren nodes.
But the reference counts of the grandchildren is not increased, thus the
reference count doesn't match the number of pointers that point to the
grandchildren. This results in "device mapper: space map common: unable
to decrement block" errors.
Fix this bug by incrementing reference counts on the grandchildren if the
btree node is shared.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 Version: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 Version: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 Version: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 Version: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 Version: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 Version: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 Version: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/persistent-data/dm-btree-remove.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b719d12cb94df345e9ad2715fd0abe9afcaeb111",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "f49b41c9eb7c6ff00df27cd49cea210abbadd8ad",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "f06f6aededd792a754cd677c02b3d3016d868c2c",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "12161e03d33afce781f68fa11cc6060538862fad",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "323d252a4a378834e4fe68298ca61cfc5dd3a460",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "85311a585a26640760cd0f3349ab9f2905691044",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "5ec0debbcfd43596e32c1239e993de06a704e04c",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "09a65adc7d8bbfce06392cb6d375468e2728ead5",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/persistent-data/dm-btree-remove.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.88",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.30",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.88",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.30",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-thin: fix metadata refcount underflow\n\nThere\u0027s a bug in dm-thin in the function rebalance_children. If the\ninternal btree node has one entry, the code tries to copy all btree\nentries from the node\u0027s child to the node itself and then decrement the\nchild\u0027s reference count.\n\nIf the child node is shared (it has reference count \u003e 1), we won\u0027t free\nit, so there would be two pointers to each of the grandchildren nodes.\nBut the reference counts of the grandchildren is not increased, thus the\nreference count doesn\u0027t match the number of pointers that point to the\ngrandchildren. This results in \"device mapper: space map common: unable\nto decrement block\" errors.\n\nFix this bug by incrementing reference counts on the grandchildren if the\nbtree node is shared."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is in the device-mapper thin-provisioning metadata layer, reached only via local block I/O (discard/TRIM) to a thin volume or local device-mapper ioctls \u2014 there is no network-facing path.\nAC:L - The bug arises during ordinary snapshot+removal workflows; an attacker controlling the operations (snapshots plus repeated removals/discards) reliably produces a single-entry internal node over a shared child, with no condition beyond their control.\nPR:L - Although pool/snapshot setup needs CAP_SYS_ADMIN, the triggering removal is reachable through discard/TRIM I/O on a snapshotted thin volume \u2014 e.g. an unprivileged user deleting files on a discard-mounted fs or a delegated volume in a multi-tenant/container deployment.\nUI:N - The attacker triggers the corruption directly through their own discard/removal operations; no action by a separate victim is required.\nS:U - The corruption stays within the kernel\u0027s storage subsystem and the affected thin pool; it does not cross into a different security authority such as a hypervisor or IOMMU boundary.\nC:H - The refcount underflow prematurely frees still-referenced blocks that get reallocated, so reads through the surviving snapshot reference can disclose whole reallocated blocks of unrelated (potentially other tenants\u0027) data.\nI:H - Double-allocated blocks and corrupted btree/space-map metadata allow modification of data belonging to other thin volumes/snapshots and corruption of pool metadata structures.\nA:H - The underflow produces \"unable to decrement block\" errors that abort the metadata transaction and force the pool read-only/fail, and corrupted metadata can crash the kernel on subsequent validation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:29:40.825Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b719d12cb94df345e9ad2715fd0abe9afcaeb111"
},
{
"url": "https://git.kernel.org/stable/c/f49b41c9eb7c6ff00df27cd49cea210abbadd8ad"
},
{
"url": "https://git.kernel.org/stable/c/f06f6aededd792a754cd677c02b3d3016d868c2c"
},
{
"url": "https://git.kernel.org/stable/c/12161e03d33afce781f68fa11cc6060538862fad"
},
{
"url": "https://git.kernel.org/stable/c/323d252a4a378834e4fe68298ca61cfc5dd3a460"
},
{
"url": "https://git.kernel.org/stable/c/85311a585a26640760cd0f3349ab9f2905691044"
},
{
"url": "https://git.kernel.org/stable/c/5ec0debbcfd43596e32c1239e993de06a704e04c"
},
{
"url": "https://git.kernel.org/stable/c/09a65adc7d8bbfce06392cb6d375468e2728ead5"
}
],
"title": "dm-thin: fix metadata refcount underflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46107",
"datePublished": "2026-05-28T09:35:13.051Z",
"dateReserved": "2026-05-13T15:03:33.098Z",
"dateUpdated": "2026-08-05T12:29:40.825Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53264 (GCVE-0-2026-53264)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-08-05 12:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_api: use RCU with deferred freeing for action lifecycle
When NEWTFILTER and DELFILTER are run concurrently it is possible to create a
race with an associated action.
Let's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:
0: mutex_lock() <-- holds the idr lock
0: rcu_read_lock()
0: p = idr_find(idr, index) <-- action p is valid (RCU protects IDR)
0: mutex_unlock() <-- releases the idr lock
1: refcount_dec_and_mutex_lock() <-- refcnt 1->0, mutex held
1: idr_remove(idr, index) <-- Action removed from IDR
1: mutex_unlock() <-- mutex released allowing us to delete the action
1: tcf_action_cleanup(p); kfree(p) <-- Kfrees p immediately, no deferral
0: refcount_inc_not_zero(&p->tcfa_refcnt) <-- ouch, UAF p points to freed memory
This patch fixes the race condition between NEWTFILTER and DELFILTER by
adding struct rcu_head to tc_action used in the deferral and introducing a
call_rcu() in the delete path to defer the final kfree().
Note: this is a revert of commit d7fb60b9cafb ("net_sched: get rid of tcfa_rcu")
but also modernization/simplification to directly use kfree_rcu().
Let's illustrate the new restored code path:
0: rcu_read_lock()
1: refcount_dec_and_mutex_lock() <-- refcnt 1->0, mutex held
1: idr_remove(idr, index)
1: mutex_unlock()
1: call_rcu(&p->tcfa_rcu, tcf_action_rcu_free) <-- defer kfree after grace period
0: p = idr_find(idr, index)
0: refcount_inc_not_zero(&p->tcfa_refcnt) <-- fails, refcnt already 0
1: rcu_read_unlock() <-- release so freeing can run after grace period
After CPU1 calls idr_remove(), the object is no longer reachable through the IDR.
CPU0's subsequent idr_find() will return NULL, and even if it still held a
stale pointer, the immediate kfree() is now deferred until after the RCU grace
period, so no UAF can occur.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da Version: d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da Version: d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da Version: d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da Version: d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da Version: d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da Version: d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da Version: d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da |
||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-53264",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-29T03:55:26.363824Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-416",
"description": "CWE-416 Use After Free",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-29T18:15:51.295Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://starlabs.sg/blog/2026/07-when-ai-makes-0-days-feel-like-n-days/"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/act_api.h",
"net/sched/act_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "98b2e40879abf0245be5a5b7af69e0f6ff524ac3",
"status": "affected",
"version": "d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da",
"versionType": "git"
},
{
"lessThan": "18af5d2ef0c4f65787fd1280c8b23286b9f2a835",
"status": "affected",
"version": "d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da",
"versionType": "git"
},
{
"lessThan": "1f1b98fea6b9ea30507d0f2fbff6750292d097e2",
"status": "affected",
"version": "d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da",
"versionType": "git"
},
{
"lessThan": "8b136f18ac4b2ace5aaad3305b3f8a5d8165a009",
"status": "affected",
"version": "d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da",
"versionType": "git"
},
{
"lessThan": "5dd51e09020c65aa53cf128e5e3517cd53b3c113",
"status": "affected",
"version": "d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da",
"versionType": "git"
},
{
"lessThan": "b60e9391142e983fab2be53497aa8f71fdd09cd5",
"status": "affected",
"version": "d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da",
"versionType": "git"
},
{
"lessThan": "91d105d2cbe002f9c7b43a6183adedc37e1da1f7",
"status": "affected",
"version": "d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da",
"versionType": "git"
},
{
"lessThan": "5057e1aca011e51ef51498c940ef96f3d3e8a305",
"status": "affected",
"version": "d7fb60b9cafb982cb2e46a267646a8dfd4f2e5da",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/act_api.h",
"net/sched/act_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_api: use RCU with deferred freeing for action lifecycle\n\nWhen NEWTFILTER and DELFILTER are run concurrently it is possible to create a\nrace with an associated action.\n\nLet\u0027s illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:\n\n 0: mutex_lock() \u003c-- holds the idr lock\n 0: rcu_read_lock()\n 0: p = idr_find(idr, index) \u003c-- action p is valid (RCU protects IDR)\n 0: mutex_unlock() \u003c-- releases the idr lock\n 1: refcount_dec_and_mutex_lock() \u003c-- refcnt 1-\u003e0, mutex held\n 1: idr_remove(idr, index) \u003c-- Action removed from IDR\n 1: mutex_unlock() \u003c-- mutex released allowing us to delete the action\n 1: tcf_action_cleanup(p); kfree(p) \u003c-- Kfrees p immediately, no deferral\n 0: refcount_inc_not_zero(\u0026p-\u003etcfa_refcnt) \u003c-- ouch, UAF p points to freed memory\n\nThis patch fixes the race condition between NEWTFILTER and DELFILTER by\nadding struct rcu_head to tc_action used in the deferral and introducing a\ncall_rcu() in the delete path to defer the final kfree().\n\nNote: this is a revert of commit d7fb60b9cafb (\"net_sched: get rid of tcfa_rcu\")\nbut also modernization/simplification to directly use kfree_rcu().\n\nLet\u0027s illustrate the new restored code path:\n\n 0: rcu_read_lock()\n 1: refcount_dec_and_mutex_lock() \u003c-- refcnt 1-\u003e0, mutex held\n 1: idr_remove(idr, index)\n 1: mutex_unlock()\n 1: call_rcu(\u0026p-\u003etcfa_rcu, tcf_action_rcu_free) \u003c-- defer kfree after grace period\n 0: p = idr_find(idr, index)\n 0: refcount_inc_not_zero(\u0026p-\u003etcfa_refcnt) \u003c-- fails, refcnt already 0\n 1: rcu_read_unlock() \u003c-- release so freeing can run after grace period\n\nAfter CPU1 calls idr_remove(), the object is no longer reachable through the IDR.\nCPU0\u0027s subsequent idr_find() will return NULL, and even if it still held a\nstale pointer, the immediate kfree() is now deferred until after the RCU grace\nperiod, so no UAF can occur."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached through local rtnetlink `RTM_NEWTFILTER`/`RTM_DELTFILTER` traffic-control netlink messages, not by remote packet input.\nAC:L - The race is attacker-controlled because the same local actor can issue concurrent filter creation and deletion operations against the same action index. No external victim timing or rare environmental condition is required.\nPR:L - The operations require `CAP_NET_ADMIN` for non-GET rtnetlink messages, but traffic control is reachable with `CAP_NET_ADMIN` inside a user-created network namespace. Under the provided kernel guidance, this is Low privileges rather than High.\nUI:N - No victim interaction is needed; exploitation consists of the attacker sending crafted concurrent rtnetlink requests.\nS:U - The impact is within the kernel security authority and is a standard local kernel memory-corruption/privilege-escalation class issue. It does not cross a VM, IOMMU, or separate authorization scope boundary.\nC:H - The bug is a use-after-free of a `tc_action` object during action lookup/refcounting. A kernel heap UAF can be shaped into disclosure primitives, so confidentiality impact is High.\nI:H - The stale freed action pointer can be reused after heap reallocation and then modified/dereferenced through refcount, bind count, ops, and action lifecycle fields. This is memory corruption that can plausibly support arbitrary write or code execution, so integrity impact is High.\nA:H - Even without full exploitation, the UAF can dereference or mutate freed/reused kernel memory and can crash or oops the kernel. Availability impact is therefore High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:34:41.215Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/98b2e40879abf0245be5a5b7af69e0f6ff524ac3"
},
{
"url": "https://git.kernel.org/stable/c/18af5d2ef0c4f65787fd1280c8b23286b9f2a835"
},
{
"url": "https://git.kernel.org/stable/c/1f1b98fea6b9ea30507d0f2fbff6750292d097e2"
},
{
"url": "https://git.kernel.org/stable/c/8b136f18ac4b2ace5aaad3305b3f8a5d8165a009"
},
{
"url": "https://git.kernel.org/stable/c/5dd51e09020c65aa53cf128e5e3517cd53b3c113"
},
{
"url": "https://git.kernel.org/stable/c/b60e9391142e983fab2be53497aa8f71fdd09cd5"
},
{
"url": "https://git.kernel.org/stable/c/91d105d2cbe002f9c7b43a6183adedc37e1da1f7"
},
{
"url": "https://git.kernel.org/stable/c/5057e1aca011e51ef51498c940ef96f3d3e8a305"
}
],
"title": "net/sched: act_api: use RCU with deferred freeing for action lifecycle",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53264",
"datePublished": "2026-06-25T08:39:51.870Z",
"dateReserved": "2026-06-09T07:44:35.395Z",
"dateUpdated": "2026-08-05T12:34:41.215Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63920 (GCVE-0-2026-63920)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: validate extension header length before copying to cmsg
ip6_datagram_recv_specific_ctl() builds IPV6_{HOPOPTS,DSTOPTS,RTHDR}
cmsgs (and their IPV6_2292* legacy counterparts) by trusting the
on-wire hdrlen byte (ptr[1]) when computing the put_cmsg() length.
The length was validated only at parse time (ipv6_parse_hopopts(),
etc.). An nftables payload-write expression can rewrite hdrlen after
parsing and before the skb reaches recvmsg; the write itself is
in-bounds but put_cmsg() then reads up to ((hdrlen+1) << 3) = 2040
bytes from an 8-byte header. nftables is reachable from an
unprivileged user namespace, so this is an unprivileged
slab-out-of-bounds read:
BUG: KASAN: slab-out-of-bounds in put_cmsg+0x3ac/0x540
put_cmsg+0x3ac/0x540
udpv6_recvmsg+0xca0/0x1250
sock_recvmsg+0xdf/0x190
____sys_recvmsg+0x1b1/0x620
Add ipv6_get_exthdr_len() which validates that at least two bytes
are accessible before reading the hdrlen field, then checks the
computed length against skb_tail_pointer(skb), returning 0 on
failure. Extension headers are kept in the linear skb area by
pskb_may_pull() during input, so skb_tail_pointer() is the correct
bound.
Use ipv6_get_exthdr_len() at all non-AH call sites: the five
standalone cmsg blocks (HbH, 2292HbH, 2292DSTOPTS x2, 2292RTHDR)
and the three standard cases in the extension-header walk loop
(DSTOPTS, ROUTING, default). AH retains an inline bounds check
because its length formula differs ((ptr[1]+2)<<2).
The walk loop also gets a pre-read bounds check at the top to
validate ptr before any case accesses ptr[0] or ptr[1].
When the walk loop detects a corrupted header, return from the
function instead of continuing to process later socket options.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/datagram.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "81394827dfb72772c50d0ae3bdfa094428a5d76d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "931b4a1f13408c2507719890f78f7227c34a0282",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "08464413e628803bd10cb1df68d0138665f2f885",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a29768d56eb3798c052ad3281b05596e695a17af",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0d330eff318c0f44d4fb0ad2c2aef38f87f24c90",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a35daeabb433686234b010ebf7b53778dbd6c9b8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "eb18a1b1644e4cad978df2131e2bb9a2e6886992",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "dd433671fef381fdaf7b530c631e6b782d66e224",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/datagram.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: validate extension header length before copying to cmsg\n\nip6_datagram_recv_specific_ctl() builds IPV6_{HOPOPTS,DSTOPTS,RTHDR}\ncmsgs (and their IPV6_2292* legacy counterparts) by trusting the\non-wire hdrlen byte (ptr[1]) when computing the put_cmsg() length.\nThe length was validated only at parse time (ipv6_parse_hopopts(),\netc.). An nftables payload-write expression can rewrite hdrlen after\nparsing and before the skb reaches recvmsg; the write itself is\nin-bounds but put_cmsg() then reads up to ((hdrlen+1) \u003c\u003c 3) = 2040\nbytes from an 8-byte header. nftables is reachable from an\nunprivileged user namespace, so this is an unprivileged\nslab-out-of-bounds read:\n\n BUG: KASAN: slab-out-of-bounds in put_cmsg+0x3ac/0x540\n put_cmsg+0x3ac/0x540\n udpv6_recvmsg+0xca0/0x1250\n sock_recvmsg+0xdf/0x190\n ____sys_recvmsg+0x1b1/0x620\n\nAdd ipv6_get_exthdr_len() which validates that at least two bytes\nare accessible before reading the hdrlen field, then checks the\ncomputed length against skb_tail_pointer(skb), returning 0 on\nfailure. Extension headers are kept in the linear skb area by\npskb_may_pull() during input, so skb_tail_pointer() is the correct\nbound.\n\nUse ipv6_get_exthdr_len() at all non-AH call sites: the five\nstandalone cmsg blocks (HbH, 2292HbH, 2292DSTOPTS x2, 2292RTHDR)\nand the three standard cases in the extension-header walk loop\n(DSTOPTS, ROUTING, default). AH retains an inline bounds check\nbecause its length formula differs ((ptr[1]+2)\u003c\u003c2).\n\nThe walk loop also gets a pre-read bounds check at the top to\nvalidate ptr before any case accesses ptr[0] or ptr[1].\n\nWhen the walk loop detects a corrupted header, return from the\nfunction instead of continuing to process later socket options."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscalls (nftables netlink to install a payload-set rule, setsockopt for IPV6_RECV* options, and recvmsg). Although the trigger packet is received over IPv6, the mandatory nftables corruption step is classified as Local per kernel guidance.\nAC:L - The attacker fully controls the nftables payload-set rule, the on-wire extension header, socket receive options, and the recvmsg call, making the slab out-of-bounds read reliably reproducible without races or external conditions.\nPR:L - An unprivileged local user can create a user+network namespace, obtain CAP_NET_ADMIN there, configure nftables, open a UDPv6/raw socket with extension-header cmsg options, and trigger the bug without real root in the initial namespace.\nUI:N - No victim interaction is required; the attacker can send the crafted IPv6 datagram and call recvmsg on their own socket to trigger the out-of-bounds read.\nS:U - Impact is confined to kernel memory disclosure and potential kernel instability within the same kernel security domain; it does not cross a VM/host or IOMMU boundary.\nC:H - put_cmsg() can copy up to 2040 bytes past the actual extension header into userspace ancillary data, leaking adjacent slab/kernel memory (confirmed by KASAN slab-out-of-bounds in put_cmsg).\nI:N - The bug is an out-of-bounds read that copies kernel data to userspace; it does not modify kernel memory, corrupt control structures, or provide a write primitive.\nA:H - The out-of-bounds slab read can provoke a KASAN fault/kernel oops during put_cmsg(), and repeated triggering can deny availability of the affected system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:14.814Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/81394827dfb72772c50d0ae3bdfa094428a5d76d"
},
{
"url": "https://git.kernel.org/stable/c/931b4a1f13408c2507719890f78f7227c34a0282"
},
{
"url": "https://git.kernel.org/stable/c/08464413e628803bd10cb1df68d0138665f2f885"
},
{
"url": "https://git.kernel.org/stable/c/a29768d56eb3798c052ad3281b05596e695a17af"
},
{
"url": "https://git.kernel.org/stable/c/0d330eff318c0f44d4fb0ad2c2aef38f87f24c90"
},
{
"url": "https://git.kernel.org/stable/c/a35daeabb433686234b010ebf7b53778dbd6c9b8"
},
{
"url": "https://git.kernel.org/stable/c/eb18a1b1644e4cad978df2131e2bb9a2e6886992"
},
{
"url": "https://git.kernel.org/stable/c/dd433671fef381fdaf7b530c631e6b782d66e224"
}
],
"title": "ipv6: validate extension header length before copying to cmsg",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63920",
"datePublished": "2026-07-19T14:55:22.813Z",
"dateReserved": "2026-07-19T07:54:57.020Z",
"dateUpdated": "2026-08-05T12:37:14.814Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64463 (GCVE-0-2026-64463)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
rt1711h_probe() registers the TCPCI port before requesting the interrupt
and enabling alert interrupts. If either of those later steps fails, the
probe function returns without unregistering the TCPCI port. The explicit
unregister currently only happens from the remove callback.
Register a devres action immediately after tcpci_register_port() succeeds,
so tcpci_unregister_port() runs on later probe failures and on driver
detach. Drop the remove callback to avoid unregistering the same port
twice.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 302c570bf36e997d55ad0d60628a2feec76954a4 Version: 302c570bf36e997d55ad0d60628a2feec76954a4 Version: 302c570bf36e997d55ad0d60628a2feec76954a4 Version: 302c570bf36e997d55ad0d60628a2feec76954a4 Version: 302c570bf36e997d55ad0d60628a2feec76954a4 Version: 4309ab96ab744703871e35d829177dd9347bf643 Version: 895ec8c86e13f85b119c71d5f95491b48867955e Version: 745dcedb896a740825160228f98dbb5725a49f85 Version: 4.19.131 ≤ Version: 5.4.50 ≤ Version: 5.7.7 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/typec/tcpm/tcpci_rt1711h.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ce2e36e8759dfbfe546723810c306f42f484866d",
"status": "affected",
"version": "302c570bf36e997d55ad0d60628a2feec76954a4",
"versionType": "git"
},
{
"lessThan": "94b1abf1af94aa5a355e9f03675e07bccfc41c4b",
"status": "affected",
"version": "302c570bf36e997d55ad0d60628a2feec76954a4",
"versionType": "git"
},
{
"lessThan": "e5406c8fb71cd2f89a46300a746f6e7972e621e8",
"status": "affected",
"version": "302c570bf36e997d55ad0d60628a2feec76954a4",
"versionType": "git"
},
{
"lessThan": "569f18a83eed0b0be4615f0c7bed40fb5c50e2e6",
"status": "affected",
"version": "302c570bf36e997d55ad0d60628a2feec76954a4",
"versionType": "git"
},
{
"lessThan": "e8da46d99d3710106e7c44db14566bf9b57386b5",
"status": "affected",
"version": "302c570bf36e997d55ad0d60628a2feec76954a4",
"versionType": "git"
},
{
"status": "affected",
"version": "4309ab96ab744703871e35d829177dd9347bf643",
"versionType": "git"
},
{
"status": "affected",
"version": "895ec8c86e13f85b119c71d5f95491b48867955e",
"versionType": "git"
},
{
"status": "affected",
"version": "745dcedb896a740825160228f98dbb5725a49f85",
"versionType": "git"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.131",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.50",
"versionType": "semver"
},
{
"lessThan": "5.8",
"status": "affected",
"version": "5.7.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/typec/tcpm/tcpci_rt1711h.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.131",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.50",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.7.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpci_rt1711h: unregister TCPCI port with devres\n\nrt1711h_probe() registers the TCPCI port before requesting the interrupt\nand enabling alert interrupts. If either of those later steps fails, the\nprobe function returns without unregistering the TCPCI port. The explicit\nunregister currently only happens from the remove callback.\n\nRegister a devres action immediately after tcpci_register_port() succeeds,\nso tcpci_unregister_port() runs on later probe failures and on driver\ndetach. Drop the remove callback to avoid unregistering the same port\ntwice.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable probe and failed-resource-unwind path is locally reachable through driver activation and locally induced resource pressure; it is not a network-facing protocol path.\nAC:L - Once a post-registration operation fails, TCPM deterministically leaves queued work and a delayed timer referencing freed memory, so exploitation does not require winning an uncontrolled race.\nPR:L - A basic local user can apply resource pressure and groom the freed kernel heap, while no capability or authentication check protects the asynchronous worker and timer paths.\nUI:N - The driver core, TCPM worker, and timer execute automatically without requiring another user to perform an action.\nS:U - The vulnerable driver and resulting kernel-memory impact remain within the host kernel security authority, with no demonstrated VM, IOMMU, or sandbox boundary crossing.\nC:H - The freed pointer-rich TCPM object can be reclaimed with attacker-influenced data, enabling kernel-memory dereferences and potentially arbitrary information disclosure.\nI:H - The freed object contains active hrtimers, work items, and TCPC operation pointers, making heap reuse potentially exploitable for arbitrary writes or control-flow hijacking.\nA:H - Queued work or timer expiry accesses the freed TCPM object and can reliably cause an oops, panic, timer corruption, or persistent system hang."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:08.330Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ce2e36e8759dfbfe546723810c306f42f484866d"
},
{
"url": "https://git.kernel.org/stable/c/94b1abf1af94aa5a355e9f03675e07bccfc41c4b"
},
{
"url": "https://git.kernel.org/stable/c/e5406c8fb71cd2f89a46300a746f6e7972e621e8"
},
{
"url": "https://git.kernel.org/stable/c/569f18a83eed0b0be4615f0c7bed40fb5c50e2e6"
},
{
"url": "https://git.kernel.org/stable/c/e8da46d99d3710106e7c44db14566bf9b57386b5"
}
],
"title": "usb: typec: tcpci_rt1711h: unregister TCPCI port with devres",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64463",
"datePublished": "2026-07-25T08:51:29.720Z",
"dateReserved": "2026-07-19T15:36:31.789Z",
"dateUpdated": "2026-08-17T04:56:08.330Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68418 (GCVE-0-2026-68418)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: Prevent user-triggered null deref on QP create
Previously, the user QP creation path would only attempt to
populate iwqp->iwpbl if the user-provided req.user_wqe_bufs
field was non-zero. The problem is that iwqp->iwpbl is
unconditionally dereferenced later on in irdma_setup_virt_qp.
While there was a check for iwqp->iwpbl != NULL, this check
would only occur if req.user_wqe_bufs was non-zero. The end
result is that a user could send a zero user_wqe_bufs value
and trigger a null ptr deref.
Fix this by unconditionally calling irdma_get_pbl and bailing
if it fails, similar to the CQ and SRQ paths.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/irdma/verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ec675b4cdfd378d8c9dd8c93126c024f2469bd79",
"status": "affected",
"version": "b48c24c2d710cf34810c555dcef883a3d35a9c08",
"versionType": "git"
},
{
"lessThan": "728211c815f6eef28dd3df2a5b6297483185aa20",
"status": "affected",
"version": "b48c24c2d710cf34810c555dcef883a3d35a9c08",
"versionType": "git"
},
{
"lessThan": "b9b0889071569d43623c260074e159cd8f26adb1",
"status": "affected",
"version": "b48c24c2d710cf34810c555dcef883a3d35a9c08",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/irdma/verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Prevent user-triggered null deref on QP create\n\nPreviously, the user QP creation path would only attempt to\npopulate iwqp-\u003eiwpbl if the user-provided req.user_wqe_bufs\nfield was non-zero. The problem is that iwqp-\u003eiwpbl is\nunconditionally dereferenced later on in irdma_setup_virt_qp.\n\nWhile there was a check for iwqp-\u003eiwpbl != NULL, this check\nwould only occur if req.user_wqe_bufs was non-zero. The end\nresult is that a user could send a zero user_wqe_bufs value\nand trigger a null ptr deref.\n\nFix this by unconditionally calling irdma_get_pbl and bailing\nif it fails, similar to the CQ and SRQ paths."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:13.218Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ec675b4cdfd378d8c9dd8c93126c024f2469bd79"
},
{
"url": "https://git.kernel.org/stable/c/728211c815f6eef28dd3df2a5b6297483185aa20"
},
{
"url": "https://git.kernel.org/stable/c/b9b0889071569d43623c260074e159cd8f26adb1"
}
],
"title": "RDMA/irdma: Prevent user-triggered null deref on QP create",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68418",
"datePublished": "2026-08-10T12:04:38.930Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-17T05:05:13.218Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68304 (GCVE-0-2026-68304)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
Based on wpa_auth as 1x_256 mode, need to set up
"use_fwsup" with BRCMF_PROFILE_FWSUP_1X.
Or it will happen trace warning when call brcmf_cfg80211_set_pmk().
[ 4481.831101] ------------[ cut here ]------------
[ 4481.831102] WARNING: CPU: 1 PID: 2997 at
drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c:7242 brcmf_cfg80211_set_pmk+0x77/0xd0 [brcmfmac]
[...]
[ 4481.831202] Call Trace:
[ 4481.831204] <TASK>
[ 4481.831205] nl80211_set_pmk+0x183/0x250 [cfg80211]
[ 4481.831233] genl_family_rcv_msg_doit+0xea/0x150
[ 4481.831237] genl_rcv_msg+0x104/0x240
[ 4481.831239] ? cfg80211_probe_status+0x2c0/0x2c0 [cfg80211]
[ 4481.831257] ? genl_family_rcv_msg_doit+0x150/0x150
[ 4481.831259] netlink_rcv_skb+0x4e/0x100
[ 4481.831261] genl_rcv+0x24/0x40
[ 4481.831262] netlink_unicast+0x236/0x380
[ 4481.831264] netlink_sendmsg+0x250/0x4b0
[ 4481.831266] sock_sendmsg+0x5c/0x70
[ 4481.831269] ____sys_sendmsg+0x236/0x2b0
[ 4481.831271] ? copy_msghdr_from_user+0x6d/0xa0
[ 4481.831272] ___sys_sendmsg+0x86/0xd0
[ 4481.831274] ? avc_has_perm+0x8c/0x1a0
[ 4481.831276] ? preempt_count_add+0x6a/0xa0
[ 4481.831279] ? sock_has_perm+0x82/0xa0
[ 4481.831280] __sys_sendmsg+0x57/0xa0
[ 4481.831282] do_syscall_64+0x38/0x90
[ 4481.831284] entry_SYSCALL_64_after_hwframe+0x63/0xcd
[ 4481.831286] RIP: 0033:0x7fd270d369b4
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fe27cc1feecde0e6a0a9a04b7ad3262ed5f99252",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "47989a233df369c2c2263ab0a5cbd8c8dad253a5",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "d0395840e3266397de94ecd3c91e1c188c7667c6",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "137e4710da626290495b174e2eb1d5e889a4b165",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "d3ac5b35ec85c41ccf8ec524d47b520e72edaca1",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "00ebbf030d8c4a1cb89cbbae15e28332373649db",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "bd4fac033bb95fcad898cf6734e869991b2561cb",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "7cb34f6c4fe8a68af621d870abe63bfca2275dd6",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: fix 802.1X-SHA256 call trace warning\n\nBased on wpa_auth as 1x_256 mode, need to set up\n\"use_fwsup\" with BRCMF_PROFILE_FWSUP_1X.\nOr it will happen trace warning when call brcmf_cfg80211_set_pmk().\n\n[ 4481.831101] ------------[ cut here ]------------\n[ 4481.831102] WARNING: CPU: 1 PID: 2997 at\ndrivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c:7242 brcmf_cfg80211_set_pmk+0x77/0xd0 [brcmfmac]\n[...]\n[ 4481.831202] Call Trace:\n[ 4481.831204] \u00a0\u003cTASK\u003e\n[ 4481.831205] \u00a0nl80211_set_pmk+0x183/0x250 [cfg80211]\n[ 4481.831233] \u00a0genl_family_rcv_msg_doit+0xea/0x150\n[ 4481.831237] \u00a0genl_rcv_msg+0x104/0x240\n[ 4481.831239] \u00a0? cfg80211_probe_status+0x2c0/0x2c0 [cfg80211]\n[ 4481.831257] \u00a0? genl_family_rcv_msg_doit+0x150/0x150\n[ 4481.831259] \u00a0netlink_rcv_skb+0x4e/0x100\n[ 4481.831261] \u00a0genl_rcv+0x24/0x40\n[ 4481.831262] \u00a0netlink_unicast+0x236/0x380\n[ 4481.831264] \u00a0netlink_sendmsg+0x250/0x4b0\n[ 4481.831266] \u00a0sock_sendmsg+0x5c/0x70\n[ 4481.831269] \u00a0____sys_sendmsg+0x236/0x2b0\n[ 4481.831271] \u00a0? copy_msghdr_from_user+0x6d/0xa0\n[ 4481.831272] \u00a0___sys_sendmsg+0x86/0xd0\n[ 4481.831274] \u00a0? avc_has_perm+0x8c/0x1a0\n[ 4481.831276] \u00a0? preempt_count_add+0x6a/0xa0\n[ 4481.831279] \u00a0? sock_has_perm+0x82/0xa0\n[ 4481.831280] \u00a0__sys_sendmsg+0x57/0xa0\n[ 4481.831282] \u00a0do_syscall_64+0x38/0x90\n[ 4481.831284] \u00a0entry_SYSCALL_64_after_hwframe+0x63/0xcd\n[ 4481.831286] RIP: 0033:0x7fd270d369b4"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:58.379Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fe27cc1feecde0e6a0a9a04b7ad3262ed5f99252"
},
{
"url": "https://git.kernel.org/stable/c/47989a233df369c2c2263ab0a5cbd8c8dad253a5"
},
{
"url": "https://git.kernel.org/stable/c/d0395840e3266397de94ecd3c91e1c188c7667c6"
},
{
"url": "https://git.kernel.org/stable/c/137e4710da626290495b174e2eb1d5e889a4b165"
},
{
"url": "https://git.kernel.org/stable/c/d3ac5b35ec85c41ccf8ec524d47b520e72edaca1"
},
{
"url": "https://git.kernel.org/stable/c/00ebbf030d8c4a1cb89cbbae15e28332373649db"
},
{
"url": "https://git.kernel.org/stable/c/bd4fac033bb95fcad898cf6734e869991b2561cb"
},
{
"url": "https://git.kernel.org/stable/c/7cb34f6c4fe8a68af621d870abe63bfca2275dd6"
}
],
"title": "wifi: brcmfmac: fix 802.1X-SHA256 call trace warning",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68304",
"datePublished": "2026-08-10T12:02:38.515Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:32:58.379Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72467 (GCVE-0-2026-72467)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:15
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xprtrdma: Check frwr_wp_create() during connect
frwr_wp_create() creates the singleton Memory Region used to encode
padding for Write chunks whose payload length is not XDR-aligned. Its
failure paths return a negative errno and leave ep->re_write_pad_mr set
to NULL.
rpcrdma_xprt_connect() currently ignores that return value. If
frwr_wp_create() fails after the rest of the connection setup succeeds,
xprt_rdma_connect_worker() treats the connection attempt as successful
and sets XPRT_CONNECTED. A later NFS/RDMA read with a non-4-byte-aligned
receive page length reaches rpcrdma_encode_write_list(), passes the NULL
write-pad MR to encode_rdma_segment(), and dereferences it.
This is locally triggerable on an NFS/RDMA client after a connect or
reconnect hits a local MR allocation, DMA-map, MR-map, or post-send
failure; a remote peer alone cannot force the local MR setup failure.
Check the return value and fail the connect as -ENOTCONN, matching the
adjacent setup failures. This keeps XPRT_CONNECTED clear and lets the
normal reconnect path retry.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 21037b8c2258ec40de3b31be9ced43ceb3b784f7 Version: 21037b8c2258ec40de3b31be9ced43ceb3b784f7 Version: 21037b8c2258ec40de3b31be9ced43ceb3b784f7 Version: 21037b8c2258ec40de3b31be9ced43ceb3b784f7 Version: 21037b8c2258ec40de3b31be9ced43ceb3b784f7 Version: 21037b8c2258ec40de3b31be9ced43ceb3b784f7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sunrpc/xprtrdma/verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3b252fe1778b2cdd68283146455929801bc2abd7",
"status": "affected",
"version": "21037b8c2258ec40de3b31be9ced43ceb3b784f7",
"versionType": "git"
},
{
"lessThan": "dd798b76a3481e392820c3ae86ed4592858c6b0f",
"status": "affected",
"version": "21037b8c2258ec40de3b31be9ced43ceb3b784f7",
"versionType": "git"
},
{
"lessThan": "6b7be4f3feae322f1c2c40a3bdc99db93574a49e",
"status": "affected",
"version": "21037b8c2258ec40de3b31be9ced43ceb3b784f7",
"versionType": "git"
},
{
"lessThan": "7471e66373a4444a57ef2192f8c4081202c54f45",
"status": "affected",
"version": "21037b8c2258ec40de3b31be9ced43ceb3b784f7",
"versionType": "git"
},
{
"lessThan": "ef3b79edf14b6bfb0d21a26ccb0463f9cf82c6a9",
"status": "affected",
"version": "21037b8c2258ec40de3b31be9ced43ceb3b784f7",
"versionType": "git"
},
{
"lessThan": "0f13fc7c7d2e0427517e63c739277a4cd338b0c5",
"status": "affected",
"version": "21037b8c2258ec40de3b31be9ced43ceb3b784f7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sunrpc/xprtrdma/verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Check frwr_wp_create() during connect\n\nfrwr_wp_create() creates the singleton Memory Region used to encode\npadding for Write chunks whose payload length is not XDR-aligned. Its\nfailure paths return a negative errno and leave ep-\u003ere_write_pad_mr set\nto NULL.\n\nrpcrdma_xprt_connect() currently ignores that return value. If\nfrwr_wp_create() fails after the rest of the connection setup succeeds,\nxprt_rdma_connect_worker() treats the connection attempt as successful\nand sets XPRT_CONNECTED. A later NFS/RDMA read with a non-4-byte-aligned\nreceive page length reaches rpcrdma_encode_write_list(), passes the NULL\nwrite-pad MR to encode_rdma_segment(), and dereferences it.\n\nThis is locally triggerable on an NFS/RDMA client after a connect or\nreconnect hits a local MR allocation, DMA-map, MR-map, or post-send\nfailure; a remote peer alone cannot force the local MR setup failure.\n\nCheck the return value and fail the connect as -ENOTCONN, matching the\nadjacent setup failures. This keeps XPRT_CONNECTED clear and lets the\nnormal reconnect path retry."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:15:12.570Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3b252fe1778b2cdd68283146455929801bc2abd7"
},
{
"url": "https://git.kernel.org/stable/c/dd798b76a3481e392820c3ae86ed4592858c6b0f"
},
{
"url": "https://git.kernel.org/stable/c/6b7be4f3feae322f1c2c40a3bdc99db93574a49e"
},
{
"url": "https://git.kernel.org/stable/c/7471e66373a4444a57ef2192f8c4081202c54f45"
},
{
"url": "https://git.kernel.org/stable/c/ef3b79edf14b6bfb0d21a26ccb0463f9cf82c6a9"
},
{
"url": "https://git.kernel.org/stable/c/0f13fc7c7d2e0427517e63c739277a4cd338b0c5"
}
],
"title": "xprtrdma: Check frwr_wp_create() during connect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72467",
"datePublished": "2026-08-15T05:57:10.499Z",
"dateReserved": "2026-08-09T03:40:39.933Z",
"dateUpdated": "2026-08-17T05:15:12.570Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64547 (GCVE-0-2026-64547)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
For an even packet_len, net1080_rx_fixup() reads the pad byte at
skb->data[packet_len] before the skb->len != packet_len check further
down, and packet_len is only bounded against NC_MAX_PACKET. A malicious
NetChip 1080 device can send a short frame advertising a large even
packet_len (e.g. 0x4000), so the pad-byte read lands past the end of the
skb:
BUG: KASAN: slab-out-of-bounds in net1080_rx_fixup
Read of size 1 at addr ffff8880106c83c6 by task ksoftirqd/0/14
...
net1080_rx_fixup (drivers/net/usb/net1080.c:384)
usbnet_bh (drivers/net/usb/usbnet.c:1589)
process_one_work (kernel/workqueue.c:3322)
bh_worker (kernel/workqueue.c:3708)
tasklet_action (kernel/softirq.c:965)
handle_softirqs (kernel/softirq.c:622)
...
Reject the frame when packet_len >= skb->len before reading.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 904813cd8a0b334189da285bb05af0b18b062502 Version: 904813cd8a0b334189da285bb05af0b18b062502 Version: 904813cd8a0b334189da285bb05af0b18b062502 Version: 904813cd8a0b334189da285bb05af0b18b062502 Version: 904813cd8a0b334189da285bb05af0b18b062502 Version: 904813cd8a0b334189da285bb05af0b18b062502 Version: 904813cd8a0b334189da285bb05af0b18b062502 Version: 904813cd8a0b334189da285bb05af0b18b062502 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/usb/net1080.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f42217fa7d535e9ec4151f7971f06f6ea65e850a",
"status": "affected",
"version": "904813cd8a0b334189da285bb05af0b18b062502",
"versionType": "git"
},
{
"lessThan": "c087749815379e9af2fdbeb08bfc33870b103958",
"status": "affected",
"version": "904813cd8a0b334189da285bb05af0b18b062502",
"versionType": "git"
},
{
"lessThan": "e4a87126c085b097d29e17e3b7647295bba8be7c",
"status": "affected",
"version": "904813cd8a0b334189da285bb05af0b18b062502",
"versionType": "git"
},
{
"lessThan": "685e92934f11d5e215dad58813e2f9955ac2f436",
"status": "affected",
"version": "904813cd8a0b334189da285bb05af0b18b062502",
"versionType": "git"
},
{
"lessThan": "4dc8484be3302d187274364820d3bef6c62bde32",
"status": "affected",
"version": "904813cd8a0b334189da285bb05af0b18b062502",
"versionType": "git"
},
{
"lessThan": "b153cfe84b1340c69a13d0957665a2bfcf21239c",
"status": "affected",
"version": "904813cd8a0b334189da285bb05af0b18b062502",
"versionType": "git"
},
{
"lessThan": "ea866cab12db1a2100b400a8b03569e5bc0ee29a",
"status": "affected",
"version": "904813cd8a0b334189da285bb05af0b18b062502",
"versionType": "git"
},
{
"lessThan": "03f384bc0cb8d4a1301d4f5b0baef2d980258383",
"status": "affected",
"version": "904813cd8a0b334189da285bb05af0b18b062502",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/usb/net1080.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.14"
},
{
"lessThan": "2.6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: net1080: validate packet_len before pad-byte access in rx_fixup\n\nFor an even packet_len, net1080_rx_fixup() reads the pad byte at\nskb-\u003edata[packet_len] before the skb-\u003elen != packet_len check further\ndown, and packet_len is only bounded against NC_MAX_PACKET. A malicious\nNetChip 1080 device can send a short frame advertising a large even\npacket_len (e.g. 0x4000), so the pad-byte read lands past the end of the\nskb:\n\n BUG: KASAN: slab-out-of-bounds in net1080_rx_fixup\n Read of size 1 at addr ffff8880106c83c6 by task ksoftirqd/0/14\n ...\n net1080_rx_fixup (drivers/net/usb/net1080.c:384)\n usbnet_bh (drivers/net/usb/usbnet.c:1589)\n process_one_work (kernel/workqueue.c:3322)\n bh_worker (kernel/workqueue.c:3708)\n tasklet_action (kernel/softirq.c:965)\n handle_softirqs (kernel/softirq.c:622)\n ...\n\nReject the frame when packet_len \u003e= skb-\u003elen before reading."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - net1080 implements a point-to-point Ethernet link over a USB host-to-host cable, so the malformed NC frame originates from the logically adjacent peer host/device on that link rather than from a local user; a compromised peer (or a gadget-mode board presenting 0525:1080, which autoloads the default-y driver) sends the frame over an already-established link with no physical interaction at attack time.\nAC:L - The attacker fully and deterministically controls packet_len and the frame length in every received frame, so the out-of-bounds read is triggered on demand with no race, no timing dependency, and no reliance on memory layout the attacker cannot influence.\nPR:N - The rx path runs in softirq/workqueue context on every received URB with no authentication, no capability check, and no local account on the target; USB/link-level peers are entirely untrusted and ungated.\nUI:N - The driver binds automatically via MODULE_DEVICE_TABLE and processes frames in usbnet_bh without any user action; on an already-connected host-to-host cable the victim does nothing at all.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority, with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - The attacker controls the read offset across a ~32 KB range past a 1523-byte slab/page-frag object, and the comparison outcome is leaked back over the wire because only the matching path reaches nc_ensure_sync()\u0027s vendor control transfer, yielding a repeatable oracle for probing kernel heap contents rather than a bounded few-byte read.\nI:N - The path performs only a one-byte read; the subsequent skb-\u003elen != packet_len check still rejects the frame, and the skb_trim calls on the underflow paths are no-ops, so no kernel memory or network data is modified.\nA:H - The read reaches roughly 31 KB beyond the allocation, which can cross into a KFENCE guard page, an unmapped hole, or a page-frag boundary and oops in softirq context, and on KASAN/panic_on_warn hardened kernels it panics the machine outright \u2014 repeatable per frame."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:24.361Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f42217fa7d535e9ec4151f7971f06f6ea65e850a"
},
{
"url": "https://git.kernel.org/stable/c/c087749815379e9af2fdbeb08bfc33870b103958"
},
{
"url": "https://git.kernel.org/stable/c/e4a87126c085b097d29e17e3b7647295bba8be7c"
},
{
"url": "https://git.kernel.org/stable/c/685e92934f11d5e215dad58813e2f9955ac2f436"
},
{
"url": "https://git.kernel.org/stable/c/4dc8484be3302d187274364820d3bef6c62bde32"
},
{
"url": "https://git.kernel.org/stable/c/b153cfe84b1340c69a13d0957665a2bfcf21239c"
},
{
"url": "https://git.kernel.org/stable/c/ea866cab12db1a2100b400a8b03569e5bc0ee29a"
},
{
"url": "https://git.kernel.org/stable/c/03f384bc0cb8d4a1301d4f5b0baef2d980258383"
}
],
"title": "net: usb: net1080: validate packet_len before pad-byte access in rx_fixup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64547",
"datePublished": "2026-07-27T20:10:37.786Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:24.361Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74581 (GCVE-0-2026-74581)
Vulnerability from cvelistv5
Published
2026-08-21 16:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: clear suppressed fib6 rule result
fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(),
but leaves res->rt6 pointing at the released rt6_info.
If no later rule supplies a replacement, fib6_rule_lookup() still sees
res.rt6 and returns that stale dst to its caller. A suppressing rule can
therefore leak a released route back to rt6_lookup(), and the next put
hits rcuref_put_slowpath() from dst_release().
Clear res->rt6 when suppressing the route so suppressed lookups fall
through to the null dst instead of reusing the released one.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 209d35ee34e25f9668c404350a1c86d914c54ffa Version: 8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: ee38eb8cf9a7323884c2b8e0adbbeb2192d31e29 Version: 5.10.84 ≤ Version: 5.15.7 ≤ Version: 5.4.164 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/fib6_rules.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "90c57310e266eb94e4a80d6b15a9ca131d2e82cb",
"status": "affected",
"version": "209d35ee34e25f9668c404350a1c86d914c54ffa",
"versionType": "git"
},
{
"lessThan": "5d29b286c9de0b309e94b9ed083aa1a2f429434f",
"status": "affected",
"version": "8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383",
"versionType": "git"
},
{
"lessThan": "354db6243eca59e9d187ffbf8b7955b044ce84dc",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"lessThan": "6d98c70fe0ba8c7708bfd5b2a5174d2086775daa",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"lessThan": "9bad152c42b37499162367fe47867411e62fffa3",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"lessThan": "dc3ab04220667f254f4348572b2a0b3febff89fb",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"lessThan": "a341c091ca0bfae377747b1b59a3bd8ebe18a937",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"lessThan": "6aea62e433fe1b586202a5fee8b5807ce635e1d7",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"status": "affected",
"version": "ee38eb8cf9a7323884c2b8e0adbbeb2192d31e29",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.84",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.7",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.164",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/fib6_rules.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.84",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.164",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: clear suppressed fib6 rule result\n\nfib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(),\nbut leaves res-\u003ert6 pointing at the released rt6_info.\n\nIf no later rule supplies a replacement, fib6_rule_lookup() still sees\nres.rt6 and returns that stale dst to its caller. A suppressing rule can\ntherefore leak a released route back to rt6_lookup(), and the next put\nhits rcuref_put_slowpath() from dst_release().\n\nClear res-\u003ert6 when suppressing the route so suppressed lookups fall\nthrough to the null dst instead of reusing the released one."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - fib6_rule_suppress() runs on every IPv6 route lookup via fib6_rule_lookup(), including ip6_route_input() for received packets and icmp6/icmpv6 redirect handlers; WireGuard/VPN servers commonly deploy suppress_prefixlength rules (wg-quick), so remote IPv6 traffic to those hosts reaches the bug.\nAC:L - Once suppress_prefixlength IPv6 policy routing rules exist, any matching packet deterministically triggers fib6_rule_suppress() to release the route while leaving a stale res-\u003ert6 pointer; no race or uncontrollable memory layout is required.\nPR:N - Remote exploitation needs only the ability to send IPv6 packets through a host whose operator already configured suppress rules (e.g., wg-quick); CAP_NET_ADMIN is an admin deployment prerequisite, not attacker privilege on the target.\nUI:N - No victim action is required beyond normal delivery of attacker-generated IPv6 traffic (or ICMPv6 redirect) to a host performing policy-route lookup.\nS:U - The stale rt6_info/dst_entry UAF corrupts kernel heap memory within the same host security boundary; it is not a VM escape or cross-authority sandbox break.\nC:H - Returning a released rt6_info leaves a dangling dst_entry in ip6_dst_cache; subsequent reads through ip6_dst_idev(), dst metrics, or error paths are classic slab UAF with attacker-influencable heap reuse via sustained IPv6 traffic.\nI:H - Double-free/imbalanced rcuref put and post-free use of rt6_info fields give heap corruption primitives; UAF on dst/route cache objects is routinely leveraged for kernel write and control-flow hijack.\nA:H - Commit explicitly reports rcuref_put_slowpath() WARN from dst_release() on the freed route; UAF and refcount corruption can oops/panic the kernel, fully denying availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:07.594Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/90c57310e266eb94e4a80d6b15a9ca131d2e82cb"
},
{
"url": "https://git.kernel.org/stable/c/5d29b286c9de0b309e94b9ed083aa1a2f429434f"
},
{
"url": "https://git.kernel.org/stable/c/354db6243eca59e9d187ffbf8b7955b044ce84dc"
},
{
"url": "https://git.kernel.org/stable/c/6d98c70fe0ba8c7708bfd5b2a5174d2086775daa"
},
{
"url": "https://git.kernel.org/stable/c/9bad152c42b37499162367fe47867411e62fffa3"
},
{
"url": "https://git.kernel.org/stable/c/dc3ab04220667f254f4348572b2a0b3febff89fb"
},
{
"url": "https://git.kernel.org/stable/c/a341c091ca0bfae377747b1b59a3bd8ebe18a937"
},
{
"url": "https://git.kernel.org/stable/c/6aea62e433fe1b586202a5fee8b5807ce635e1d7"
}
],
"title": "net: ipv6: clear suppressed fib6 rule result",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74581",
"datePublished": "2026-08-21T16:31:54.683Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-25T05:40:07.594Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64544 (GCVE-0-2026-64544)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
pefile_digest_pe_contents() computes the trailing-data hash length as
pelen - (hashed_bytes + certs_size). A crafted PE can make the addition
exceed pelen, causing the unsigned subtraction to underflow to ~4 GiB.
This is passed to crypto_shash_update() which reads out of bounds and
panics on unmapped vmalloc guard pages.
BUG: unable to handle page fault for address: ffffc900038d8000
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:sha256_blocks_generic (lib/crypto/sha256.c:152)
Call Trace:
<TASK>
__sha256_update (lib/crypto/sha256.c:208)
crypto_sha256_update (crypto/sha256.c:142)
verify_pefile_signature (crypto/asymmetric_keys/verify_pefile.c:436)
kexec_kernel_verify_pe_sig (kernel/kexec_file.c:151)
__do_sys_kexec_file_load (kernel/kexec_file.c:406)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
</TASK>
Kernel panic - not syncing: Fatal exception
Validate that the addition does not overflow and the result does not
exceed pelen before the subtraction. Return -ELIBBAD on failure.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: af316fc442ef23901bbfcec5af55e69ca6ce9563 Version: af316fc442ef23901bbfcec5af55e69ca6ce9563 Version: af316fc442ef23901bbfcec5af55e69ca6ce9563 Version: af316fc442ef23901bbfcec5af55e69ca6ce9563 Version: af316fc442ef23901bbfcec5af55e69ca6ce9563 Version: af316fc442ef23901bbfcec5af55e69ca6ce9563 Version: af316fc442ef23901bbfcec5af55e69ca6ce9563 Version: af316fc442ef23901bbfcec5af55e69ca6ce9563 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"crypto/asymmetric_keys/verify_pefile.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "89efd998470a93284b7ad5a20d4e0e3c6858ae8e",
"status": "affected",
"version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
"versionType": "git"
},
{
"lessThan": "7016377699b5b25b7ec3c0bf2ec3f983c7e95f7c",
"status": "affected",
"version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
"versionType": "git"
},
{
"lessThan": "b798ada5a5d1cb4cc4cfa72074b1b463eca6c506",
"status": "affected",
"version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
"versionType": "git"
},
{
"lessThan": "627938383761fb4334b41ebe7ef438d6b8b19d60",
"status": "affected",
"version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
"versionType": "git"
},
{
"lessThan": "e162bc386e71b5412425a38ee048e8d2185491b9",
"status": "affected",
"version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
"versionType": "git"
},
{
"lessThan": "6acd2fbd00f9c72aebefce63fc2e73e8f3d79061",
"status": "affected",
"version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
"versionType": "git"
},
{
"lessThan": "803591785d33cf13b6f73ce2796e8b9e6d5e6526",
"status": "affected",
"version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
"versionType": "git"
},
{
"lessThan": "f7dd32c5179d7755de18e21d5674b08f9e5cb180",
"status": "affected",
"version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"crypto/asymmetric_keys/verify_pefile.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents\n\npefile_digest_pe_contents() computes the trailing-data hash length as\npelen - (hashed_bytes + certs_size). A crafted PE can make the addition\nexceed pelen, causing the unsigned subtraction to underflow to ~4 GiB.\nThis is passed to crypto_shash_update() which reads out of bounds and\npanics on unmapped vmalloc guard pages.\n\n BUG: unable to handle page fault for address: ffffc900038d8000\n Oops: Oops: 0000 [#1] SMP KASAN NOPTI\n RIP: 0010:sha256_blocks_generic (lib/crypto/sha256.c:152)\n Call Trace:\n \u003cTASK\u003e\n __sha256_update (lib/crypto/sha256.c:208)\n crypto_sha256_update (crypto/sha256.c:142)\n verify_pefile_signature (crypto/asymmetric_keys/verify_pefile.c:436)\n kexec_kernel_verify_pe_sig (kernel/kexec_file.c:151)\n __do_sys_kexec_file_load (kernel/kexec_file.c:406)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n \u003c/TASK\u003e\n Kernel panic - not syncing: Fatal exception\n\nValidate that the addition does not overflow and the result does not\nexceed pelen before the subtraction. Return -ELIBBAD on failure."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:21.054Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/89efd998470a93284b7ad5a20d4e0e3c6858ae8e"
},
{
"url": "https://git.kernel.org/stable/c/7016377699b5b25b7ec3c0bf2ec3f983c7e95f7c"
},
{
"url": "https://git.kernel.org/stable/c/b798ada5a5d1cb4cc4cfa72074b1b463eca6c506"
},
{
"url": "https://git.kernel.org/stable/c/627938383761fb4334b41ebe7ef438d6b8b19d60"
},
{
"url": "https://git.kernel.org/stable/c/e162bc386e71b5412425a38ee048e8d2185491b9"
},
{
"url": "https://git.kernel.org/stable/c/6acd2fbd00f9c72aebefce63fc2e73e8f3d79061"
},
{
"url": "https://git.kernel.org/stable/c/803591785d33cf13b6f73ce2796e8b9e6d5e6526"
},
{
"url": "https://git.kernel.org/stable/c/f7dd32c5179d7755de18e21d5674b08f9e5cb180"
}
],
"title": "crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64544",
"datePublished": "2026-07-27T20:10:36.101Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:21.054Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53224 (GCVE-0-2026-53224)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-08-05 12:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: validate embedded INIT chunk and address list lengths in cookie
sctp_unpack_cookie() only checked that the embedded INIT chunk length
did not exceed the remaining cookie payload, but did not ensure that the
INIT chunk is large enough to contain a complete INIT header.
A malformed COOKIE_ECHO can therefore carry a truncated INIT chunk whose
length field is smaller than sizeof(struct sctp_init_chunk). Later,
sctp_process_init() accesses INIT parameters unconditionally, which may
lead to out-of-bounds reads.
In addition, raw_addr_list_len is not fully validated against the
remaining cookie payload. When cookie authentication is disabled, an
attacker can supply an oversized raw_addr_list_len and cause
sctp_raw_to_bind_addrs() to read beyond the end of the cookie. The
address parser also lacks sufficient bounds checks for parameter headers
and lengths, allowing malformed address parameters to trigger
out-of-bounds reads.
Fix this by:
- requiring the embedded INIT chunk length to be at least sizeof(struct
sctp_init_chunk);
- validating that the INIT chunk and raw address list together fit
within the cookie payload;
- verifying sufficient data exists for each address parameter header and
payload before parsing it.
Note that sctp_verify_init() must be called after sctp_unpack_cookie()
and before sctp_process_init() when cookie authentication is disabled.
This will be addressed in a separate patch.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/bind_addr.c",
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7560afb8cddafd829e709d7ea09230e45a825557",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "512a9bb77c04ac9927648ea58af617e472be96e6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6f4c80a2a7e6d06753b89a578b710a2499a5e62b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/bind_addr.c",
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate embedded INIT chunk and address list lengths in cookie\n\nsctp_unpack_cookie() only checked that the embedded INIT chunk length\ndid not exceed the remaining cookie payload, but did not ensure that the\nINIT chunk is large enough to contain a complete INIT header.\n\nA malformed COOKIE_ECHO can therefore carry a truncated INIT chunk whose\nlength field is smaller than sizeof(struct sctp_init_chunk). Later,\nsctp_process_init() accesses INIT parameters unconditionally, which may\nlead to out-of-bounds reads.\n\nIn addition, raw_addr_list_len is not fully validated against the\nremaining cookie payload. When cookie authentication is disabled, an\nattacker can supply an oversized raw_addr_list_len and cause\nsctp_raw_to_bind_addrs() to read beyond the end of the cookie. The\naddress parser also lacks sufficient bounds checks for parameter headers\nand lengths, allowing malformed address parameters to trigger\nout-of-bounds reads.\n\nFix this by:\n\n- requiring the embedded INIT chunk length to be at least sizeof(struct\n sctp_init_chunk);\n- validating that the INIT chunk and raw address list together fit\n within the cookie payload;\n- verifying sufficient data exists for each address parameter header and\n payload before parsing it.\n\nNote that sctp_verify_init() must be called after sctp_unpack_cookie()\nand before sctp_process_init() when cookie authentication is disabled.\nThis will be addressed in a separate patch."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - An unauthenticated remote SCTP peer can reach the vulnerable COOKIE_ECHO processing path by sending SCTP packets to a listening SCTP endpoint. In deployments with cookie HMAC disabled, the attacker can obtain and modify the state cookie over the network.\nAC:L - The bug is triggered with a malformed COOKIE_ECHO and attacker-controlled embedded INIT/address-list lengths; no race or hard-to-control timing condition is required. The no-cookie-auth deployment condition is a reasonable supported SCTP configuration.\nPR:N - No credentials or local privileges are needed to send SCTP INIT/COOKIE_ECHO traffic to a listening service. The vulnerable parsing occurs before any application authentication.\nUI:N - Exploitation only requires sending network packets to the target SCTP endpoint. No victim user action is required.\nS:U - The impact is within the kernel/network stack security authority of the target system. It does not cross a separate boundary such as guest-to-host or IOMMU isolation.\nC:H - The malformed lengths can drive out-of-bounds kernel reads beyond the COOKIE_ECHO payload, including attacker-controlled oversized address-list parsing. Because the read is not strictly bounded to a few bytes and related SCTP COOKIE_ECHO bugs demonstrate kernel memory leakage potential, confidentiality impact is High.\nI:N - The investigated fix addresses out-of-bounds reads and missing length validation, not an out-of-bounds write or direct arbitrary memory modification primitive. I did not find a defensible direct integrity impact from this bug alone.\nA:H - The attacker-controlled out-of-bounds reads can walk beyond the skb/cookie buffer and fault or trigger KASAN/oops conditions. A remotely triggerable kernel crash is High availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:34:16.814Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7560afb8cddafd829e709d7ea09230e45a825557"
},
{
"url": "https://git.kernel.org/stable/c/512a9bb77c04ac9927648ea58af617e472be96e6"
},
{
"url": "https://git.kernel.org/stable/c/6f4c80a2a7e6d06753b89a578b710a2499a5e62b"
}
],
"title": "sctp: validate embedded INIT chunk and address list lengths in cookie",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53224",
"datePublished": "2026-06-25T08:39:25.254Z",
"dateReserved": "2026-06-09T07:44:35.392Z",
"dateUpdated": "2026-08-05T12:34:16.814Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64086 (GCVE-0-2026-64086)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
adm1266_pmbus_block_xfer() sets up the read transaction with
.buf = data->read_buf,
.len = ADM1266_PMBUS_BLOCK_MAX + 2,
but read_buf in struct adm1266_data is declared as
u8 read_buf[ADM1266_PMBUS_BLOCK_MAX + 1];
For a max-length block response (length byte = 255 + up to 1 PEC
byte), the i2c controller is told to write 257 bytes into a 256-byte
buffer, putting one byte past the end of read_buf. The same response
also makes the subsequent PEC compare
if (crc != msgs[1].buf[msgs[1].buf[0] + 1])
read a byte beyond the array.
Bump the read_buf declaration to ADM1266_PMBUS_BLOCK_MAX + 2 so the
buffer can hold the length byte, up to 255 payload bytes, and the PEC
byte the i2c_msg length already accounts for.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 Version: 407dc802a9c0809ca6a48de4b4c63305eb84ef56 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "397d3f523bfff2f4e3dacf9b1339bd76dc207f78",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "472744f69d25a2d5111ad62f1d62579dce2c13c8",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "528a9f88e88502d0c2f2052a279415074cd83715",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "d94ceb16e55b6d8019ab069e357c76ac42f0ffbc",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "bd5be3fa5de6dbf61f1b3cec6b79c2c2f8065694",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "2279c342d94eca225bf9f301c8806a05a1c81619",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "a6c802145a8de0830bca803c6d415f7e9e683624",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
},
{
"lessThan": "487566cb1ccdf3756fdd7bf8d875e612ff3169bb",
"status": "affected",
"version": "407dc802a9c0809ca6a48de4b4c63305eb84ef56",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer\n\nadm1266_pmbus_block_xfer() sets up the read transaction with\n\n\t.buf = data-\u003eread_buf,\n\t.len = ADM1266_PMBUS_BLOCK_MAX + 2,\n\nbut read_buf in struct adm1266_data is declared as\n\n\tu8 read_buf[ADM1266_PMBUS_BLOCK_MAX + 1];\n\nFor a max-length block response (length byte = 255 + up to 1 PEC\nbyte), the i2c controller is told to write 257 bytes into a 256-byte\nbuffer, putting one byte past the end of read_buf. The same response\nalso makes the subsequent PEC compare\n\n\tif (crc != msgs[1].buf[msgs[1].buf[0] + 1])\n\nread a byte beyond the array.\n\nBump the read_buf declaration to ADM1266_PMBUS_BLOCK_MAX + 2 so the\nbuffer can hold the length byte, up to 255 payload bytes, and the PEC\nbyte the i2c_msg length already accounts for."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is only reached through local kernel interfaces (debugfs GPIO dump at /sys/kernel/debug/gpio and root-only nvmem blackbox reads), not through any network protocol handler. The ADM1266 sits on an on-board I2C bus on server BMC hardware.\nAC:L - An attacker who controls the I2C bus response (malicious device, compromised ADM1266 firmware, or bus interposition on the BMC) can reliably force a 255-byte block reply whenever a victim triggers the block-transfer path, causing the one-byte overflow on demand.\nPR:L - The gpio debugfs entry is world-readable (0444) if debugfs is mounted and traversable, which occurs on some embedded BMC images without strict permissions; between requiring full init-namespace root and that lower bar, the less privileged path is plausible on misconfigured systems.\nUI:N - Exploitation does not require victim interaction beyond the attacker (or a compromised daemon) programmatically reading debugfs or nvmem; no mount, click, or plug-in action by an end user is needed.\nS:U - Impact is confined to kernel memory corruption within the BMC/host kernel security boundary; this is not a VM escape, IOMMU bypass, or cross-authority sandbox breakout.\nC:H - The PEC validation performs an out-of-bounds read past read_buf, and the one-byte heap overflow can corrupt adjacent kernel objects in ways that enable further memory disclosure primitives.\nI:H - A one-byte, attacker-controlled out-of-bounds write past the end of read_buf into adjacent heap memory can corrupt slab metadata or neighboring objects and be developed into arbitrary write or code-execution primitives.\nA:H - Corrupting adjacent heap objects via the out-of-bounds write can cause kernel oops, panic, or hang on the BMC, denying management-plane availability for the managed server."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:03.986Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/397d3f523bfff2f4e3dacf9b1339bd76dc207f78"
},
{
"url": "https://git.kernel.org/stable/c/472744f69d25a2d5111ad62f1d62579dce2c13c8"
},
{
"url": "https://git.kernel.org/stable/c/528a9f88e88502d0c2f2052a279415074cd83715"
},
{
"url": "https://git.kernel.org/stable/c/d94ceb16e55b6d8019ab069e357c76ac42f0ffbc"
},
{
"url": "https://git.kernel.org/stable/c/bd5be3fa5de6dbf61f1b3cec6b79c2c2f8065694"
},
{
"url": "https://git.kernel.org/stable/c/2279c342d94eca225bf9f301c8806a05a1c81619"
},
{
"url": "https://git.kernel.org/stable/c/a6c802145a8de0830bca803c6d415f7e9e683624"
},
{
"url": "https://git.kernel.org/stable/c/487566cb1ccdf3756fdd7bf8d875e612ff3169bb"
}
],
"title": "hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64086",
"datePublished": "2026-07-19T15:39:56.749Z",
"dateReserved": "2026-07-19T07:54:57.032Z",
"dateUpdated": "2026-08-05T12:39:03.986Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68328 (GCVE-0-2026-68328)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfp: Check resource mutex allocation
nfp_cpp_resource_find() allocates a CPP mutex handle for the matching
resource-table entry and then reports success. nfp_resource_try_acquire()
immediately passes that handle to nfp_cpp_mutex_trylock().
However, nfp_cpp_mutex_alloc() returns NULL on failure. If that happens
for a matching table entry, the resource lookup still returns success and
the following trylock dereferences a NULL mutex pointer while opening the
resource.
nfp_resource_acquire() already treats failure to allocate the table mutex
as -ENOMEM. Do the same for the resource mutex and fail the lookup before
publishing the rest of the resource handle.
This issue was found by a static analysis checker and confirmed by
manual source review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "18737a48acc87e4cbe41d6fea9a3f44eae490e24",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "423523f96a681428ce6e214eaf47f0d8242319de",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "0dbd85a8cc35c14bd26e686fa5fae8c64a7958ae",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "6dbd428119cb1fd1b73cf6968c711f4ea964dc8b",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "cfa119aa781c4044dab5b4c1e5864600f53a26bc",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "a7dc30b6828c3a30252892827b12b676749f250f",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfp: Check resource mutex allocation\n\nnfp_cpp_resource_find() allocates a CPP mutex handle for the matching\nresource-table entry and then reports success. nfp_resource_try_acquire()\nimmediately passes that handle to nfp_cpp_mutex_trylock().\n\nHowever, nfp_cpp_mutex_alloc() returns NULL on failure. If that happens\nfor a matching table entry, the resource lookup still returns success and\nthe following trylock dereferences a NULL mutex pointer while opening the\nresource.\n\nnfp_resource_acquire() already treats failure to allocate the table mutex\nas -ENOMEM. Do the same for the resource mutex and fail the lookup before\npublishing the rest of the resource handle.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:25.716Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/18737a48acc87e4cbe41d6fea9a3f44eae490e24"
},
{
"url": "https://git.kernel.org/stable/c/423523f96a681428ce6e214eaf47f0d8242319de"
},
{
"url": "https://git.kernel.org/stable/c/0dbd85a8cc35c14bd26e686fa5fae8c64a7958ae"
},
{
"url": "https://git.kernel.org/stable/c/6dbd428119cb1fd1b73cf6968c711f4ea964dc8b"
},
{
"url": "https://git.kernel.org/stable/c/cfa119aa781c4044dab5b4c1e5864600f53a26bc"
},
{
"url": "https://git.kernel.org/stable/c/3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3"
},
{
"url": "https://git.kernel.org/stable/c/a7dc30b6828c3a30252892827b12b676749f250f"
},
{
"url": "https://git.kernel.org/stable/c/a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc"
}
],
"title": "nfp: Check resource mutex allocation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68328",
"datePublished": "2026-08-10T12:03:04.560Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:25.716Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68394 (GCVE-0-2026-68394)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
MGMT_OP_LOAD_CONN_PARAM queues conn_update_sync() when a single parameter
update changes an existing LE central connection. The queued work currently
stores a borrowed hci_conn_params entry from hdev->le_conn_params. A later
LOAD_CONN_PARAM request can clear disabled parameters and free that entry
before hci_cmd_sync_work() runs the queued callback.
Do not keep the borrowed hci_conn_params pointer in queued work. Queue the
hci_conn instead and hold a reference until the queued callback completes.
When the work runs, revalidate that the connection is still present, look
up the current hci_conn_params entry, and cancel the update if userspace
removed that entry while the work was pending.
Copy the interval values from the current params entry under hdev->lock,
then drop the lock and keep using hci_le_conn_update_sync() to issue the
update.
Validation reproduced this kernel report:
BUG: KASAN: slab-use-after-free in conn_update_sync+0x2a/0xf0 [bluetooth]
Read of size 1 at addr ffff88810c697126 by task kworker/u17:0/377
Workqueue: hci0 hci_cmd_sync_work [bluetooth]
Call Trace:
<TASK>
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x5f0
kasan_report+0xe0/0x110
conn_update_sync+0x2a/0xf0 [bluetooth]
hci_cmd_sync_work+0x187/0x210 [bluetooth]
process_one_work+0x4fd/0xbc0
worker_thread+0x2d8/0x570
kthread+0x1ad/0x1f0
ret_from_fork+0x3c9/0x540
ret_from_fork_asm+0x1a/0x30
Allocated by task 466:
hci_conn_params_add+0xa6/0x240 [bluetooth]
load_conn_param+0x4e1/0x850 [bluetooth]
hci_sock_sendmsg+0x96b/0xf80 [bluetooth]
Freed by task 474:
kfree+0x313/0x590
hci_conn_params_clear_disabled+0x9b/0xc0 [bluetooth]
load_conn_param+0x4bf/0x850 [bluetooth]
hci_sock_sendmsg+0x96b/0xf80 [bluetooth]
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "65ce6fe1b92112ba9064ded932c03180da3dd230",
"status": "affected",
"version": "0ece498c27d8cd2fdad6f49a6abc34b8badd8fbc",
"versionType": "git"
},
{
"lessThan": "57059ff14d81df4a970b2ea8d8f54431bb91a025",
"status": "affected",
"version": "0ece498c27d8cd2fdad6f49a6abc34b8badd8fbc",
"versionType": "git"
},
{
"lessThan": "b82802b5ab26a7c69fc2e7a0f2baa3c13a6c21aa",
"status": "affected",
"version": "0ece498c27d8cd2fdad6f49a6abc34b8badd8fbc",
"versionType": "git"
},
{
"lessThan": "2bf282f8f715f5d05d6f4c49ffb3bd241c5e667e",
"status": "affected",
"version": "0ece498c27d8cd2fdad6f49a6abc34b8badd8fbc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update\n\nMGMT_OP_LOAD_CONN_PARAM queues conn_update_sync() when a single parameter\nupdate changes an existing LE central connection. The queued work currently\nstores a borrowed hci_conn_params entry from hdev-\u003ele_conn_params. A later\nLOAD_CONN_PARAM request can clear disabled parameters and free that entry\nbefore hci_cmd_sync_work() runs the queued callback.\n\nDo not keep the borrowed hci_conn_params pointer in queued work. Queue the\nhci_conn instead and hold a reference until the queued callback completes.\nWhen the work runs, revalidate that the connection is still present, look\nup the current hci_conn_params entry, and cancel the update if userspace\nremoved that entry while the work was pending.\n\nCopy the interval values from the current params entry under hdev-\u003elock,\nthen drop the lock and keep using hci_le_conn_update_sync() to issue the\nupdate.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in conn_update_sync+0x2a/0xf0 [bluetooth]\nRead of size 1 at addr ffff88810c697126 by task kworker/u17:0/377\nWorkqueue: hci0 hci_cmd_sync_work [bluetooth]\n\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x5f0\n kasan_report+0xe0/0x110\n conn_update_sync+0x2a/0xf0 [bluetooth]\n hci_cmd_sync_work+0x187/0x210 [bluetooth]\n process_one_work+0x4fd/0xbc0\n worker_thread+0x2d8/0x570\n kthread+0x1ad/0x1f0\n ret_from_fork+0x3c9/0x540\n ret_from_fork_asm+0x1a/0x30\n\nAllocated by task 466:\n hci_conn_params_add+0xa6/0x240 [bluetooth]\n load_conn_param+0x4e1/0x850 [bluetooth]\n hci_sock_sendmsg+0x96b/0xf80 [bluetooth]\n\nFreed by task 474:\n kfree+0x313/0x590\n hci_conn_params_clear_disabled+0x9b/0xc0 [bluetooth]\n load_conn_param+0x4bf/0x850 [bluetooth]\n hci_sock_sendmsg+0x96b/0xf80 [bluetooth]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is triggered entirely through local interfaces \u2014 two MGMT_OP_LOAD_CONN_PARAM commands written to a local AF_BLUETOOTH/BTPROTO_HCI socket bound to HCI_CHANNEL_CONTROL, reaching load_conn_param() via hci_sock_sendmsg()/hci_mgmt_cmd(). No over-the-air interaction from a remote Bluetooth peer is required.\nAC:L - The attacker controls both sides of the race: it issues the LOAD_CONN_PARAM that queues conn_update_sync() and then immediately issues a second LOAD_CONN_PARAM whose hci_conn_params_clear_disabled() frees the borrowed entry before hci_cmd_sync_work() dequeues it, and it can grool the slab by repeated hci_conn_params_add() calls.\nPR:L - Reaching load_conn_param() needs a trusted MGMT socket (CAP_NET_ADMIN at bind), which is exactly the privilege held by the unprivileged Bluetooth service account on Android and desktop Linux (bluetoothd / com.android.bluetooth) \u2014 a low-privilege, externally exposed daemon, not real root, and the standard scoring for MGMT-socket flaws.\nUI:N - Exploitation requires only that the attacker send its own MGMT commands over an existing LE central connection it can itself establish; no action by any other user or victim application is needed.\nS:U - The use-after-free corrupts kernel slab memory and its impact stays within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a slab use-after-free read: conn_update_sync() reads addr/addr_type and the four interval fields from a freed hci_conn_params and places them into the HCI_OP_LE_CONN_UPDATE command, leaking reallocated heap contents; more generally a UAF gives the attacker control over freed-object contents and can be leveraged into arbitrary kernel memory disclosure.\nI:H - The attacker grooms the freed hci_conn_params slot with controlled data, so freed memory dictates which connection is looked up and what parameters are programmed into the controller; a use-after-free of this kind is a standard primitive for heap manipulation and control-flow/data corruption in the kernel.\nA:H - The bug is a confirmed KASAN slab-use-after-free (BUG: KASAN: slab-use-after-free in conn_update_sync+0x2a/0xf0) in a workqueue context, which panics on KASAN/panic_on_warn kernels and readily causes oopses or unpredictable Bluetooth-stack state otherwise."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:42.328Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/65ce6fe1b92112ba9064ded932c03180da3dd230"
},
{
"url": "https://git.kernel.org/stable/c/57059ff14d81df4a970b2ea8d8f54431bb91a025"
},
{
"url": "https://git.kernel.org/stable/c/b82802b5ab26a7c69fc2e7a0f2baa3c13a6c21aa"
},
{
"url": "https://git.kernel.org/stable/c/2bf282f8f715f5d05d6f4c49ffb3bd241c5e667e"
}
],
"title": "Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68394",
"datePublished": "2026-08-10T12:04:13.562Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-17T05:04:42.328Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-31658 (GCVE-0-2026-31658)
Vulnerability from cvelistv5
Published
2026-04-24 14:45
Modified
2026-09-08 08:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()
When dma_map_single() fails in tse_start_xmit(), the function returns
NETDEV_TX_OK without freeing the skb. Since NETDEV_TX_OK tells the
stack the packet was consumed, the skb is never freed, leaking memory
on every DMA mapping failure.
Add dev_kfree_skb_any() before returning to properly free the skb.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bbd2190ce96d8fce031f0526c1f970b68adc9d1a Version: bbd2190ce96d8fce031f0526c1f970b68adc9d1a Version: bbd2190ce96d8fce031f0526c1f970b68adc9d1a Version: bbd2190ce96d8fce031f0526c1f970b68adc9d1a Version: bbd2190ce96d8fce031f0526c1f970b68adc9d1a Version: bbd2190ce96d8fce031f0526c1f970b68adc9d1a Version: bbd2190ce96d8fce031f0526c1f970b68adc9d1a Version: bbd2190ce96d8fce031f0526c1f970b68adc9d1a |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:47:54.322Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/altera/altera_tse_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ae2cd46f57f422b51aedd406ff5d75cbff401d5d",
"status": "affected",
"version": "bbd2190ce96d8fce031f0526c1f970b68adc9d1a",
"versionType": "git"
},
{
"lessThan": "cb1d318702fdf643061350d164250198df4116f2",
"status": "affected",
"version": "bbd2190ce96d8fce031f0526c1f970b68adc9d1a",
"versionType": "git"
},
{
"lessThan": "d5ec406f0543bd6cdfd563b08015fdec8c4d5712",
"status": "affected",
"version": "bbd2190ce96d8fce031f0526c1f970b68adc9d1a",
"versionType": "git"
},
{
"lessThan": "2eb9d67704ca8f1101f7435b85f113ede471f9f2",
"status": "affected",
"version": "bbd2190ce96d8fce031f0526c1f970b68adc9d1a",
"versionType": "git"
},
{
"lessThan": "9f3ec44aeb58501d11834048d5d0dbaeacb6d4e7",
"status": "affected",
"version": "bbd2190ce96d8fce031f0526c1f970b68adc9d1a",
"versionType": "git"
},
{
"lessThan": "60f462cd2716d86bd2174f9d5e035c9278f30480",
"status": "affected",
"version": "bbd2190ce96d8fce031f0526c1f970b68adc9d1a",
"versionType": "git"
},
{
"lessThan": "3aca300e88afe56afb000cdc4c65383014fb17f9",
"status": "affected",
"version": "bbd2190ce96d8fce031f0526c1f970b68adc9d1a",
"versionType": "git"
},
{
"lessThan": "6dede3967619b5944003227a5d09fdc21ed57d10",
"status": "affected",
"version": "bbd2190ce96d8fce031f0526c1f970b68adc9d1a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/altera/altera_tse_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.15"
},
{
"lessThan": "3.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.253",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.169",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.135",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.82",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.23",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.253",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.169",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.135",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.82",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.23",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.13",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "3.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()\n\nWhen dma_map_single() fails in tse_start_xmit(), the function returns\nNETDEV_TX_OK without freeing the skb. Since NETDEV_TX_OK tells the\nstack the packet was consumed, the skb is never freed, leaking memory\non every DMA mapping failure.\n\nAdd dev_kfree_skb_any() before returning to properly free the skb."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:13:05.042Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ae2cd46f57f422b51aedd406ff5d75cbff401d5d"
},
{
"url": "https://git.kernel.org/stable/c/cb1d318702fdf643061350d164250198df4116f2"
},
{
"url": "https://git.kernel.org/stable/c/d5ec406f0543bd6cdfd563b08015fdec8c4d5712"
},
{
"url": "https://git.kernel.org/stable/c/2eb9d67704ca8f1101f7435b85f113ede471f9f2"
},
{
"url": "https://git.kernel.org/stable/c/9f3ec44aeb58501d11834048d5d0dbaeacb6d4e7"
},
{
"url": "https://git.kernel.org/stable/c/60f462cd2716d86bd2174f9d5e035c9278f30480"
},
{
"url": "https://git.kernel.org/stable/c/3aca300e88afe56afb000cdc4c65383014fb17f9"
},
{
"url": "https://git.kernel.org/stable/c/6dede3967619b5944003227a5d09fdc21ed57d10"
}
],
"title": "net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-31658",
"datePublished": "2026-04-24T14:45:09.566Z",
"dateReserved": "2026-03-09T15:48:24.129Z",
"dateUpdated": "2026-09-08T08:47:54.322Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68425 (GCVE-0-2026-68425)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
IB/mad: Drop unmatched RMPP responses before reassembly
Kernel-handled RMPP receive processing starts reassembly for active
DATA responses before the response is matched to an outstanding send.
The normal match happens later, after ib_process_rmpp_recv_wc() has
either assembled a complete message or consumed the segment.
That ordering lets an unsolicited response that routes to a kernel
RMPP agent by the high TID bits allocate or extend RMPP receive state
before the full TID and source address are checked against a real
request. A reordered burst can therefore reach the receive-side
insertion path even though the response would not match any send.
For kernel-handled RMPP DATA responses, require the existing
ib_find_send_mad() match before entering RMPP reassembly. The matcher
already checks the full TID, management class and source address/GID
against the agent wait, backlog and in-flight send lists. If there is
no match, drop the response without creating RMPP state.
This leaves the RMPP window behavior unchanged and only rejects
responses that have no corresponding request.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/mad.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45416c87ebcece1e90f3bc5bc172d106b77c6b69",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "9634fb1f4d404f36a20ffbcb8797369db69b06bb",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "bfb9e8243fd2099d1080d09222964d988f991d9b",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "dfa535c94406c03d3f0c869ef3ba5528e395737c",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "98d2d468b4faa1fdc68c0c6c238389906ee3490c",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "ad9c9ad3204f63a46f0f7de29687a8e512f05e29",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "d2e52d610b9b09694261632340b801a421e0b0c5",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/mad.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.13"
},
{
"lessThan": "2.6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mad: Drop unmatched RMPP responses before reassembly\n\nKernel-handled RMPP receive processing starts reassembly for active\nDATA responses before the response is matched to an outstanding send.\nThe normal match happens later, after ib_process_rmpp_recv_wc() has\neither assembled a complete message or consumed the segment.\n\nThat ordering lets an unsolicited response that routes to a kernel\nRMPP agent by the high TID bits allocate or extend RMPP receive state\nbefore the full TID and source address are checked against a real\nrequest. A reordered burst can therefore reach the receive-side\ninsertion path even though the response would not match any send.\n\nFor kernel-handled RMPP DATA responses, require the existing\nib_find_send_mad() match before entering RMPP reassembly. The matcher\nalready checks the full TID, management class and source address/GID\nagainst the agent wait, backlog and in-flight send lists. If there is\nno match, drop the response without creating RMPP state.\n\nThis leaves the RMPP window behavior unchanged and only rejects\nresponses that have no corresponding request."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The attacker must be a node on the same InfiniBand fabric, sending unsolicited GSI (QP1) management datagrams to the victim port; MAD/SA traffic is subnet-local, matching the CVSS \"shared physical or logical network\" definition rather than routable network reach.\nAC:L - No race or unusual precondition is needed: the attacker just sends active RMPP DATA response MADs whose high TID bits name a kernel RMPP agent, and hi_tid is a small cyclic xarray index in [0,2^24) that is trivially enumerated or brute-forced.\nPR:N - The MAD receive path accepts unsolicited datagrams from any fabric peer with no authentication; the only gate is ib_mad_enforce_security() P_Key membership, which the default partition typically grants to every node on the subnet.\nUI:N - Reassembly state is created entirely from attacker-sent packets in the completion handler; no action by a local user or administrator is needed, and the always-registered ib_sa kernel agent is the target.\nS:U - The injected RMPP state, allocations and AH objects all live inside the kernel\u0027s own IB MAD layer on the same host, so the impact stays within a single security authority.\nC:N - The flaw creates unmatched reassembly state; it provides no out-of-bounds read, no kernel memory disclosure, and the ACKs the kernel emits echo only attacker-supplied header fields.\nI:L - An unauthenticated fabric peer can insert arbitrary unsolicited entries into the kernel agent\u0027s RMPP reassembly lists and make the kernel emit ACKs, and a colliding entry (SA TIDs come from a predictable tid++ counter) diverts and drops a legitimate SA response\u0027s segments \u2014 limited, bounded modification of kernel protocol state.\nA:H - Each unmatched segment allocates a mad_rmpp_recv, an AH and a retained ~1-2 KB MAD buffer held for 40 seconds with no matching request, so a burst causes unbounded memory/resource exhaustion, while the O(N) rmpp_list walks under an IRQ-disabled spinlock stall MAD processing and break SA/path resolution for the node."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:19.996Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45416c87ebcece1e90f3bc5bc172d106b77c6b69"
},
{
"url": "https://git.kernel.org/stable/c/9634fb1f4d404f36a20ffbcb8797369db69b06bb"
},
{
"url": "https://git.kernel.org/stable/c/bfb9e8243fd2099d1080d09222964d988f991d9b"
},
{
"url": "https://git.kernel.org/stable/c/dfa535c94406c03d3f0c869ef3ba5528e395737c"
},
{
"url": "https://git.kernel.org/stable/c/6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72"
},
{
"url": "https://git.kernel.org/stable/c/98d2d468b4faa1fdc68c0c6c238389906ee3490c"
},
{
"url": "https://git.kernel.org/stable/c/ad9c9ad3204f63a46f0f7de29687a8e512f05e29"
},
{
"url": "https://git.kernel.org/stable/c/d2e52d610b9b09694261632340b801a421e0b0c5"
}
],
"title": "IB/mad: Drop unmatched RMPP responses before reassembly",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68425",
"datePublished": "2026-08-10T12:04:45.947Z",
"dateReserved": "2026-07-30T09:28:09.392Z",
"dateUpdated": "2026-08-19T16:35:19.996Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72289 (GCVE-0-2026-72289)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-17 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: vgic: Check the interrupt is still ours before migrating it
vgic_prune_ap_list() drops both ap_list_lock and irq_lock while migrating
an interrupt to another vCPU. After reacquiring the locks it only checks
that the affinity is unchanged (target_vcpu == vgic_target_oracle(irq))
before moving the interrupt, which assumes that an interrupt whose affinity
is preserved is still queued on this vCPU's ap_list.
That assumption no longer holds if the interrupt is taken off the ap_list
while the locks are dropped. vgic_flush_pending_lpis() removes the
interrupt from the list and sets irq->vcpu to NULL, but leaves
enabled/pending/target_vcpu untouched. As the interrupt is still enabled
and pending, vgic_target_oracle() returns the same target_vcpu, so the
affinity check passes and list_del() is run a second time on an entry that
has already been removed.
Also check that the interrupt is still assigned to this vCPU
(irq->vcpu == vcpu) before moving it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0919e84c0fc1fc73525fdcedefab89ea8460f697 Version: 0919e84c0fc1fc73525fdcedefab89ea8460f697 Version: 0919e84c0fc1fc73525fdcedefab89ea8460f697 Version: 0919e84c0fc1fc73525fdcedefab89ea8460f697 Version: 0919e84c0fc1fc73525fdcedefab89ea8460f697 Version: 0919e84c0fc1fc73525fdcedefab89ea8460f697 Version: 0919e84c0fc1fc73525fdcedefab89ea8460f697 Version: 0919e84c0fc1fc73525fdcedefab89ea8460f697 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/arm64/kvm/vgic/vgic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3893e1fcf6f306b327a8358dcd1cbd077989a240",
"status": "affected",
"version": "0919e84c0fc1fc73525fdcedefab89ea8460f697",
"versionType": "git"
},
{
"lessThan": "cb3efe1a354f1638726725c3ecee1ce8d1a7e2dc",
"status": "affected",
"version": "0919e84c0fc1fc73525fdcedefab89ea8460f697",
"versionType": "git"
},
{
"lessThan": "da2d249a39a1881681c303ceea33f38ba1c5bbeb",
"status": "affected",
"version": "0919e84c0fc1fc73525fdcedefab89ea8460f697",
"versionType": "git"
},
{
"lessThan": "654be81c4c637af12709d47c7efc3302cd336513",
"status": "affected",
"version": "0919e84c0fc1fc73525fdcedefab89ea8460f697",
"versionType": "git"
},
{
"lessThan": "e363c0bc0226dc5ea5046a88e9a6864b82c45399",
"status": "affected",
"version": "0919e84c0fc1fc73525fdcedefab89ea8460f697",
"versionType": "git"
},
{
"lessThan": "79fdd2aa774e44847cd9bb7edc811e73e3dc7bfe",
"status": "affected",
"version": "0919e84c0fc1fc73525fdcedefab89ea8460f697",
"versionType": "git"
},
{
"lessThan": "0658b09cba7fe866c6cd70cd2dcdfdcabe80328f",
"status": "affected",
"version": "0919e84c0fc1fc73525fdcedefab89ea8460f697",
"versionType": "git"
},
{
"lessThan": "0074b82cdfcb5fd13710a0ac308ade68ac6f6fbe",
"status": "affected",
"version": "0919e84c0fc1fc73525fdcedefab89ea8460f697",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/arm64/kvm/vgic/vgic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Check the interrupt is still ours before migrating it\n\nvgic_prune_ap_list() drops both ap_list_lock and irq_lock while migrating\nan interrupt to another vCPU. After reacquiring the locks it only checks\nthat the affinity is unchanged (target_vcpu == vgic_target_oracle(irq))\nbefore moving the interrupt, which assumes that an interrupt whose affinity\nis preserved is still queued on this vCPU\u0027s ap_list.\n\nThat assumption no longer holds if the interrupt is taken off the ap_list\nwhile the locks are dropped. vgic_flush_pending_lpis() removes the\ninterrupt from the list and sets irq-\u003evcpu to NULL, but leaves\nenabled/pending/target_vcpu untouched. As the interrupt is still enabled\nand pending, vgic_target_oracle() returns the same target_vcpu, so the\naffinity check passes and list_del() is run a second time on an entry that\nhas already been removed.\n\nAlso check that the interrupt is still assigned to this vCPU\n(irq-\u003evcpu == vcpu) before moving it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only from KVM guest execution paths\u2014GICv3 redistributor GICR_CTLR LPI-disable MMIO traps into vgic_flush_pending_lpis() and vCPU exit/sync paths into vgic_prune_ap_list()\u2014not from any remote network, adjacent-radio, or physical-device interface on the host.\nAC:L - A malicious multi-vCPU guest controls both racing sides by pinning threads, changing LPI affinity via ITS so an interrupt must migrate off one vCPU\u0027s ap_list, and concurrently disabling LPIS on that redistributor; the attacker creates the window rather than depending on uncontrollable host timing or memory layout.\nPR:N - The highest-impact scenario is a malicious cloud VM tenant on arm64 KVM who needs no host privileges beyond code already running inside the assigned guest; exploitation uses guest-kernel GIC MMIO/ITS operations, not host root, CAP_SYS_ADMIN in the init namespace, or additional /dev/kvm access beyond having a VM.\nUI:N - Exploitation is fully attacker-driven from within the guest VM through deliberate LPI setup, affinity changes, and timed GICR_CTLR writes; no victim user or administrator action on the host is required beyond normal VM operation.\nS:C - Double list_del()/list_add_tail() on host-kernel ap_list linkages corrupts KVM VGIC state from guest-controlled interrupt operations, crossing the guest-to-host virtualization security boundary with VM-escape-class impact rather than confining damage to the attacker\u0027s VM.\nC:H - Corrupting detached ap_list pointers and inserting them into another vCPU\u0027s ap_list_head enables out-of-bounds kernel linked-list traversal and disclosure of adjacent kmalloc slab memory (struct vgic_irq and neighboring objects); per kernel guidance, this list corruption is leverageable for arbitrary host memory read primitives.\nI:H - The vulnerable path performs list_del() on an already removed entry and may follow with list_add_tail() onto another vCPU\u0027s ap_list, letting a guest steer kernel list pointers and overwrite adjacent vgic_irq/host heap metadata for control-flow or data corruption on the hypervisor.\nA:H - Re-running list_del() on an entry already removed by vgic_flush_pending_lpis() dereferences poisoned list pointers and corrupts live ap_list_heads, causing immediate host kernel BUG/oops/panic or persistent interrupt-delivery failure during subsequent VGIC processing."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:42:24.760Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3893e1fcf6f306b327a8358dcd1cbd077989a240"
},
{
"url": "https://git.kernel.org/stable/c/cb3efe1a354f1638726725c3ecee1ce8d1a7e2dc"
},
{
"url": "https://git.kernel.org/stable/c/da2d249a39a1881681c303ceea33f38ba1c5bbeb"
},
{
"url": "https://git.kernel.org/stable/c/654be81c4c637af12709d47c7efc3302cd336513"
},
{
"url": "https://git.kernel.org/stable/c/e363c0bc0226dc5ea5046a88e9a6864b82c45399"
},
{
"url": "https://git.kernel.org/stable/c/79fdd2aa774e44847cd9bb7edc811e73e3dc7bfe"
},
{
"url": "https://git.kernel.org/stable/c/0658b09cba7fe866c6cd70cd2dcdfdcabe80328f"
},
{
"url": "https://git.kernel.org/stable/c/0074b82cdfcb5fd13710a0ac308ade68ac6f6fbe"
}
],
"title": "KVM: arm64: vgic: Check the interrupt is still ours before migrating it",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72289",
"datePublished": "2026-08-15T05:55:10.870Z",
"dateReserved": "2026-08-09T03:40:39.917Z",
"dateUpdated": "2026-08-17T05:42:24.760Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68220 (GCVE-0-2026-68220)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
Both mxc_isi_crossbar_init() and mxc_isi_pipe_init() call
v4l2_subdev_init_finalize() which allocates the subdev active state,
but neither mxc_isi_crossbar_cleanup() nor mxc_isi_pipe_cleanup()
calls v4l2_subdev_cleanup() to free it.
This causes a memory leak on every rmmod, reported by kmemleak:
unreferenced object 0xffff0000d06fc800 (size 192):
comm "(udev-worker)", pid 254, jiffies 4294913455
backtrace (crc 36eeae58):
kmemleak_alloc+0x34/0x40
__kvmalloc_node_noprof+0x5f8/0x7d8
__v4l2_subdev_state_alloc+0x1fc/0x30c
__v4l2_subdev_init_finalize+0x178/0x368
Add the missing v4l2_subdev_cleanup() calls before media_entity_cleanup()
in both crossbar and pipe cleanup paths.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nxp/imx8-isi/imx8-isi-crossbar.c",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-pipe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "549dd1afce2cf79a826d1f9742effb4565d52871",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "f04ec98605420e7c2c1ad6d2f6fb26692d4f218a",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "9e61258fbc3cfc053e4c2ed72254c2de76772354",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "9c5ddbabc31fda93a508d9b8f0c776a4a08e49f5",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "567418eedd25b3d86d489807682030b4b98b73d9",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nxp/imx8-isi/imx8-isi-crossbar.c",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-pipe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe\n\nBoth mxc_isi_crossbar_init() and mxc_isi_pipe_init() call\nv4l2_subdev_init_finalize() which allocates the subdev active state,\nbut neither mxc_isi_crossbar_cleanup() nor mxc_isi_pipe_cleanup()\ncalls v4l2_subdev_cleanup() to free it.\n\nThis causes a memory leak on every rmmod, reported by kmemleak:\n\n unreferenced object 0xffff0000d06fc800 (size 192):\n comm \"(udev-worker)\", pid 254, jiffies 4294913455\n backtrace (crc 36eeae58):\n kmemleak_alloc+0x34/0x40\n __kvmalloc_node_noprof+0x5f8/0x7d8\n __v4l2_subdev_state_alloc+0x1fc/0x30c\n __v4l2_subdev_init_finalize+0x178/0x368\n\nAdd the missing v4l2_subdev_cleanup() calls before media_entity_cleanup()\nin both crossbar and pipe cleanup paths."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:06.897Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/549dd1afce2cf79a826d1f9742effb4565d52871"
},
{
"url": "https://git.kernel.org/stable/c/f04ec98605420e7c2c1ad6d2f6fb26692d4f218a"
},
{
"url": "https://git.kernel.org/stable/c/9e61258fbc3cfc053e4c2ed72254c2de76772354"
},
{
"url": "https://git.kernel.org/stable/c/9c5ddbabc31fda93a508d9b8f0c776a4a08e49f5"
},
{
"url": "https://git.kernel.org/stable/c/567418eedd25b3d86d489807682030b4b98b73d9"
}
],
"title": "media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68220",
"datePublished": "2026-08-10T12:00:40.434Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-17T05:01:06.897Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64423 (GCVE-0-2026-64423)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: igmp: remove multicast group from hash table on device destruction
When a device is destroyed under RTNL, ip_mc_destroy_dev() iterates through
the multicast list and calls ip_ma_put() on each membership, scheduling
them for RCU reclamation. However, they are not unlinked from the device's
multicast hash table (mc_hash).
Since the device remains published in dev->ip_ptr until after
ip_mc_destroy_dev() completes, concurrent RCU readers traversing mc_hash
can still locate and access the multicast group after its refcount is
decremented. If the RCU callback runs and frees the group while a reader is
accessing it, a use-after-free occurs.
Fix this by unlinking the multicast group from mc_hash using
ip_mc_hash_remove() before scheduling it for reclamation.
BUG: KASAN: slab-use-after-free in ip_check_mc_rcu+0x149/0x3f0
Read of size 4 at addr ffff888009bf1408 by task mausezahn/2276
Call Trace:
<IRQ>
dump_stack_lvl+0x67/0x90
print_report+0x175/0x7c0
kasan_report+0x147/0x180
ip_check_mc_rcu+0x149/0x3f0
udp_v4_early_demux+0x36d/0x12d0
ip_rcv_finish_core+0xb8b/0x1390
ip_rcv_finish+0x54/0x120
NF_HOOK+0x213/0x2b0
__netif_receive_skb+0x126/0x340
process_backlog+0x4f2/0xf00
__napi_poll+0x92/0x2c0
net_rx_action+0x583/0xc60
handle_softirqs+0x236/0x7f0
do_softirq+0x57/0x80
</IRQ>
Allocated by task 2239:
kasan_save_track+0x3e/0x80
__kasan_kmalloc+0x72/0x90
____ip_mc_inc_group+0x31a/0xa40
__ip_mc_join_group+0x334/0x3f0
do_ip_setsockopt+0x16fa/0x2010
ip_setsockopt+0x3f/0x90
do_sock_setsockopt+0x1ad/0x300
Freed by task 0:
kasan_save_track+0x3e/0x80
kasan_save_free_info+0x40/0x50
__kasan_slab_free+0x3a/0x60
__rcu_free_sheaf_prepare+0xd4/0x220
rcu_free_sheaf+0x36/0x190
rcu_core+0x8d9/0x12f0
handle_softirqs+0x236/0x7f0
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e9897071350bd9d94a56b5b6f79c85b1a98fc7e7 Version: e9897071350bd9d94a56b5b6f79c85b1a98fc7e7 Version: e9897071350bd9d94a56b5b6f79c85b1a98fc7e7 Version: e9897071350bd9d94a56b5b6f79c85b1a98fc7e7 Version: e9897071350bd9d94a56b5b6f79c85b1a98fc7e7 Version: e9897071350bd9d94a56b5b6f79c85b1a98fc7e7 Version: e9897071350bd9d94a56b5b6f79c85b1a98fc7e7 Version: e9897071350bd9d94a56b5b6f79c85b1a98fc7e7 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:38.639Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/igmp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "412ba7def06ffe974ba9a1d862b022362c54ffa5",
"status": "affected",
"version": "e9897071350bd9d94a56b5b6f79c85b1a98fc7e7",
"versionType": "git"
},
{
"lessThan": "c6cb5f8ebe1c1a78710c19f102db9fe48b9e6ba9",
"status": "affected",
"version": "e9897071350bd9d94a56b5b6f79c85b1a98fc7e7",
"versionType": "git"
},
{
"lessThan": "5f42729d74bd6c61306d864423290d92962de4e1",
"status": "affected",
"version": "e9897071350bd9d94a56b5b6f79c85b1a98fc7e7",
"versionType": "git"
},
{
"lessThan": "76d030ac95e17f91d69a595f17ebc5979700cf9a",
"status": "affected",
"version": "e9897071350bd9d94a56b5b6f79c85b1a98fc7e7",
"versionType": "git"
},
{
"lessThan": "8820b530cb2388503d7418228d03ba074bf7a03e",
"status": "affected",
"version": "e9897071350bd9d94a56b5b6f79c85b1a98fc7e7",
"versionType": "git"
},
{
"lessThan": "2ca18df1c2611f70eb3eb487e02ae85eb703b284",
"status": "affected",
"version": "e9897071350bd9d94a56b5b6f79c85b1a98fc7e7",
"versionType": "git"
},
{
"lessThan": "f91883031e5a62877a29ce139442973cbea769f1",
"status": "affected",
"version": "e9897071350bd9d94a56b5b6f79c85b1a98fc7e7",
"versionType": "git"
},
{
"lessThan": "7993211bde166471dffac074dc965489f86531f8",
"status": "affected",
"version": "e9897071350bd9d94a56b5b6f79c85b1a98fc7e7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/igmp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.11"
},
{
"lessThan": "3.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: igmp: remove multicast group from hash table on device destruction\n\nWhen a device is destroyed under RTNL, ip_mc_destroy_dev() iterates through\nthe multicast list and calls ip_ma_put() on each membership, scheduling\nthem for RCU reclamation. However, they are not unlinked from the device\u0027s\nmulticast hash table (mc_hash).\n\nSince the device remains published in dev-\u003eip_ptr until after\nip_mc_destroy_dev() completes, concurrent RCU readers traversing mc_hash\ncan still locate and access the multicast group after its refcount is\ndecremented. If the RCU callback runs and frees the group while a reader is\naccessing it, a use-after-free occurs.\n\nFix this by unlinking the multicast group from mc_hash using\nip_mc_hash_remove() before scheduling it for reclamation.\n\nBUG: KASAN: slab-use-after-free in ip_check_mc_rcu+0x149/0x3f0\nRead of size 4 at addr ffff888009bf1408 by task mausezahn/2276\n\nCall Trace:\n \u003cIRQ\u003e\n dump_stack_lvl+0x67/0x90\n print_report+0x175/0x7c0\n kasan_report+0x147/0x180\n ip_check_mc_rcu+0x149/0x3f0\n udp_v4_early_demux+0x36d/0x12d0\n ip_rcv_finish_core+0xb8b/0x1390\n ip_rcv_finish+0x54/0x120\n NF_HOOK+0x213/0x2b0\n __netif_receive_skb+0x126/0x340\n process_backlog+0x4f2/0xf00\n __napi_poll+0x92/0x2c0\n net_rx_action+0x583/0xc60\n handle_softirqs+0x236/0x7f0\n do_softirq+0x57/0x80\n \u003c/IRQ\u003e\n\nAllocated by task 2239:\n kasan_save_track+0x3e/0x80\n __kasan_kmalloc+0x72/0x90\n ____ip_mc_inc_group+0x31a/0xa40\n __ip_mc_join_group+0x334/0x3f0\n do_ip_setsockopt+0x16fa/0x2010\n ip_setsockopt+0x3f/0x90\n do_sock_setsockopt+0x1ad/0x300\n\nFreed by task 0:\n kasan_save_track+0x3e/0x80\n kasan_save_free_info+0x40/0x50\n __kasan_slab_free+0x3a/0x60\n __rcu_free_sheaf_prepare+0xd4/0x220\n rcu_free_sheaf+0x36/0x190\n rcu_core+0x8d9/0x12f0\n handle_softirqs+0x236/0x7f0"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - An end-to-end attacker-controlled trigger requires local socket and netlink operations to create multicast memberships and concurrently destroy IPv4 device state; received multicast packets alone cannot initiate the necessary teardown. These operations are reachable inside an attacker-created user and network namespace.\nAC:L - The attacker can populate mc_hash, generate continuous multicast traffic, and repeatedly tear down IPv4 state, controlling both sides of the race. No victim-dependent timing or secret state is required.\nPR:L - Device teardown or invalid-MTU configuration requires CAP_NET_ADMIN in the target network namespace, while multicast joins and UDP sends are unprivileged. An ordinary user can obtain this namespace-scoped capability through unprivileged user and network namespaces.\nUI:N - Exploitation requires no action by another user once the attacker can execute locally and create the required namespace and traffic.\nS:U - The vulnerable code and resulting host-kernel compromise remain within the same security authority; this is conventional kernel privilege escalation rather than a guest-to-host escape.\nC:H - The stale kmalloc-256 ip_mc_list entry exposes reuse-controlled fields and pointers to kernel reads, making kernel-memory disclosure and broader read primitives plausible.\nI:H - Reallocation permits attacker-influenced object contents to drive spinlock writes and pointer traversal on freed memory, making heap corruption and control-flow hijacking defensible.\nA:H - The confirmed slab use-after-free can dereference corrupted hash pointers or operate on an invalid spinlock, causing a kernel oops, panic, general-protection fault, or hang."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:23.253Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/412ba7def06ffe974ba9a1d862b022362c54ffa5"
},
{
"url": "https://git.kernel.org/stable/c/c6cb5f8ebe1c1a78710c19f102db9fe48b9e6ba9"
},
{
"url": "https://git.kernel.org/stable/c/5f42729d74bd6c61306d864423290d92962de4e1"
},
{
"url": "https://git.kernel.org/stable/c/76d030ac95e17f91d69a595f17ebc5979700cf9a"
},
{
"url": "https://git.kernel.org/stable/c/8820b530cb2388503d7418228d03ba074bf7a03e"
},
{
"url": "https://git.kernel.org/stable/c/2ca18df1c2611f70eb3eb487e02ae85eb703b284"
},
{
"url": "https://git.kernel.org/stable/c/f91883031e5a62877a29ce139442973cbea769f1"
},
{
"url": "https://git.kernel.org/stable/c/7993211bde166471dffac074dc965489f86531f8"
}
],
"title": "ipv4: igmp: remove multicast group from hash table on device destruction",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64423",
"datePublished": "2026-07-25T08:51:01.485Z",
"dateReserved": "2026-07-19T15:36:31.787Z",
"dateUpdated": "2026-09-08T08:50:38.639Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64002 (GCVE-0-2026-64002)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()
ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports
too soon.
Only after unregister_net_sysctl_table() we can be sure no threads can possibly
use the sysctls, including /proc/sys/net/ipv4/ip_local_reserved_ports.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 122ff243f5f104194750ecbc76d5946dd1eec934 Version: 122ff243f5f104194750ecbc76d5946dd1eec934 Version: 122ff243f5f104194750ecbc76d5946dd1eec934 Version: 122ff243f5f104194750ecbc76d5946dd1eec934 Version: 122ff243f5f104194750ecbc76d5946dd1eec934 Version: 122ff243f5f104194750ecbc76d5946dd1eec934 Version: 122ff243f5f104194750ecbc76d5946dd1eec934 Version: 122ff243f5f104194750ecbc76d5946dd1eec934 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/sysctl_net_ipv4.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ecf45080a4d3f4526cacb8b14060fe3b49a6913b",
"status": "affected",
"version": "122ff243f5f104194750ecbc76d5946dd1eec934",
"versionType": "git"
},
{
"lessThan": "a0ffc6081a8b27082dd5eae5aa1e3f59bbecf06c",
"status": "affected",
"version": "122ff243f5f104194750ecbc76d5946dd1eec934",
"versionType": "git"
},
{
"lessThan": "5b23a2ff379e70b6b9ff744a972b63e1f8f4d996",
"status": "affected",
"version": "122ff243f5f104194750ecbc76d5946dd1eec934",
"versionType": "git"
},
{
"lessThan": "8e59d4d0dcde2dfb07a7ef855c849a2a0560aa57",
"status": "affected",
"version": "122ff243f5f104194750ecbc76d5946dd1eec934",
"versionType": "git"
},
{
"lessThan": "6512c57c4638ddec113bf42439361ba85a12048d",
"status": "affected",
"version": "122ff243f5f104194750ecbc76d5946dd1eec934",
"versionType": "git"
},
{
"lessThan": "a7f4eefb6e1458431eef9fa20fb363320d185f76",
"status": "affected",
"version": "122ff243f5f104194750ecbc76d5946dd1eec934",
"versionType": "git"
},
{
"lessThan": "155f90be5ee8be5b110ebc0b7da33c54c83b0208",
"status": "affected",
"version": "122ff243f5f104194750ecbc76d5946dd1eec934",
"versionType": "git"
},
{
"lessThan": "87a1e0fe7776da7ab411be332b4be58ac8840d10",
"status": "affected",
"version": "122ff243f5f104194750ecbc76d5946dd1eec934",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/sysctl_net_ipv4.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: free net-\u003eipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()\n\nipv4_sysctl_exit_net() is currently freeing net-\u003eipv4.sysctl_local_reserved_ports\ntoo soon.\n\nOnly after unregister_net_sysctl_table() we can be sure no threads can possibly\nuse the sysctls, including /proc/sys/net/ipv4/ip_local_reserved_ports."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscalls\u2014network namespace teardown via unshare/setns/put_net, sysctl access to /proc/sys/net/ipv4/ip_local_reserved_ports, and/or local socket bind/connect\u2014not remote packet delivery.\nAC:L - The attacker can control both sides of the race by concurrently tearing down a network namespace while hammering the sysctl or triggering socket port selection in that namespace.\nPR:L - An unprivileged local user can reach this via user namespaces (CAP_SYS_ADMIN within the user_ns for CLONE_NEWNET) and world-writable sysctl access (mode 0644) during namespace destruction.\nUI:N - No victim interaction is required beyond the attacker\u0027s own concurrent namespace teardown and sysctl or socket activity.\nS:U - The UAF corrupts kernel heap memory within the same kernel security domain; it is standard local kernel memory corruption, not a VM/hypervisor boundary escape.\nC:H - Freed 8 KiB bitmap memory remains reachable via sysctl reads (find_next_bit) and inet_is_local_reserved_port() (test_bit), enabling heap information disclosure through a use-after-free.\nI:H - Sysctl writes via proc_do_large_bitmap perform bitmap_copy/bitmap_or into the freed allocation, providing a heap write primitive exploitable for control-flow hijacking.\nA:H - Concurrent access to the freed bitmap can cause kernel oops/panic from invalid memory access, and UAF exploitation inherently threatens kernel availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:02.672Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ecf45080a4d3f4526cacb8b14060fe3b49a6913b"
},
{
"url": "https://git.kernel.org/stable/c/a0ffc6081a8b27082dd5eae5aa1e3f59bbecf06c"
},
{
"url": "https://git.kernel.org/stable/c/5b23a2ff379e70b6b9ff744a972b63e1f8f4d996"
},
{
"url": "https://git.kernel.org/stable/c/8e59d4d0dcde2dfb07a7ef855c849a2a0560aa57"
},
{
"url": "https://git.kernel.org/stable/c/6512c57c4638ddec113bf42439361ba85a12048d"
},
{
"url": "https://git.kernel.org/stable/c/a7f4eefb6e1458431eef9fa20fb363320d185f76"
},
{
"url": "https://git.kernel.org/stable/c/155f90be5ee8be5b110ebc0b7da33c54c83b0208"
},
{
"url": "https://git.kernel.org/stable/c/87a1e0fe7776da7ab411be332b4be58ac8840d10"
}
],
"title": "ipv4: free net-\u003eipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64002",
"datePublished": "2026-07-19T14:56:19.495Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-08-05T12:38:02.672Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64383 (GCVE-0-2026-64383)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_flush() replay
SMB2_flush() keeps its response buffer bookkeeping across replay
attempts. If a replayable flush response is received and the retry then
fails before cifs_send_recv() stores a replacement response, flush_exit
will free the stale response pointer a second time.
Reinitialize resp_buftype and rsp_iov at the top of the replay loop so
cleanup only acts on response state produced by the current attempt.
This fixes a double-free without changing replay handling for successful
requests.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 433042a91f9373241307725b52de573933ffedbf Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 6.6.32 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6e27f40b682a5e42a2daae3ce6d96f0e0e16dedb",
"status": "affected",
"version": "433042a91f9373241307725b52de573933ffedbf",
"versionType": "git"
},
{
"lessThan": "878757163eea684750107a31ea134c103863515d",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "3407240cde132a4b72d6429a2625a09a2f78adaf",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "013a9a3da46c5dabcf18f65ea6a47874ba12a15d",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "4be31c943a3a27a5a0251dbb8f5cb89059ec3d5a",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.32",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double-free in SMB2_flush() replay\n\nSMB2_flush() keeps its response buffer bookkeeping across replay\nattempts. If a replayable flush response is received and the retry then\nfails before cifs_send_recv() stores a replacement response, flush_exit\nwill free the stale response pointer a second time.\n\nReinitialize resp_buftype and rsp_iov at the top of the replay loop so\ncleanup only acts on response state produced by the current attempt.\nThis fixes a double-free without changing replay handling for successful\nrequests."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious or compromised SMB server can trigger the flaw through crafted replayable responses and connection failures over the network.\nAC:L - The server controls both the replayable error and subsequent reconnect failure, allowing repeated triggering without an uncontrollable race.\nPR:N - The attacking SMB endpoint requires no privileges on the client system once an SMB session and file handle exist.\nUI:N - An automatically mounted share and routine service-generated fsync, truncate, timestamp, or seek operations can reach SMB2_flush() without human participation.\nS:U - The memory corruption compromises resources governed by the same host kernel security authority.\nC:H - The response-buffer double-free can create overlapping CIFS slab allocations and use-after-free primitives capable of exposing arbitrary kernel memory.\nI:H - Allocator corruption and attacker-influenced overlapping network buffers can provide arbitrary-write or control-flow-hijacking primitives.\nA:H - The double-free can immediately trigger an allocator BUG, kernel oops, or panic and can be invoked repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:35.045Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6e27f40b682a5e42a2daae3ce6d96f0e0e16dedb"
},
{
"url": "https://git.kernel.org/stable/c/878757163eea684750107a31ea134c103863515d"
},
{
"url": "https://git.kernel.org/stable/c/3407240cde132a4b72d6429a2625a09a2f78adaf"
},
{
"url": "https://git.kernel.org/stable/c/013a9a3da46c5dabcf18f65ea6a47874ba12a15d"
},
{
"url": "https://git.kernel.org/stable/c/4be31c943a3a27a5a0251dbb8f5cb89059ec3d5a"
}
],
"title": "smb: client: fix double-free in SMB2_flush() replay",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64383",
"datePublished": "2026-07-25T08:50:32.634Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-08-17T04:54:35.045Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64287 (GCVE-0-2026-64287)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
flush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU
on every run. The vGIC list register save and restore use used_lrs as
their loop bound and expect it to stay within the number of implemented
list registers. While this is generally the case, flush_hyp_vcpu()
copies vgic_v3 verbatim and does not enforce this, so a value provided
by the host is used at EL2 to index vgic_lr[] and access ICH_LR<n>_EL2
(host -> EL2).
Fix by clamping used_lrs to the number of implemented list registers
after the copy, as the trusted path already does in
vgic_flush_lr_state(). The number of implemented list registers is
constant after init, so it is replicated once from
kvm_vgic_global_state.nr_lr into hyp_gicv3_nr_lr rather than read on
every entry.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/arm64/include/asm/kvm_hyp.h",
"arch/arm64/kvm/arm.c",
"arch/arm64/kvm/hyp/nvhe/hyp-main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2c5e72b9fbf83fdfa724e9f1af0f418ccf8739b8",
"status": "affected",
"version": "be66e67f175096f283c9d5614c4991fc9e7ed975",
"versionType": "git"
},
{
"lessThan": "9fa301d8298778dd799fa4dcf7a7f440715d146e",
"status": "affected",
"version": "be66e67f175096f283c9d5614c4991fc9e7ed975",
"versionType": "git"
},
{
"lessThan": "c646431865f4b1a5b14067233fa27b11e05e0d46",
"status": "affected",
"version": "be66e67f175096f283c9d5614c4991fc9e7ed975",
"versionType": "git"
},
{
"lessThan": "7fca3fcef81c713bc82a37bf741e0f28e6d04a6f",
"status": "affected",
"version": "be66e67f175096f283c9d5614c4991fc9e7ed975",
"versionType": "git"
},
{
"lessThan": "8cc8bbbfab14c22c5551d0dd19b208a44b141c76",
"status": "affected",
"version": "be66e67f175096f283c9d5614c4991fc9e7ed975",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/arm64/include/asm/kvm_hyp.h",
"arch/arm64/kvm/arm.c",
"arch/arm64/kvm/hyp/nvhe/hyp-main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU\n\nflush_hyp_vcpu() copies the host vGIC state into the hyp\u0027s private vCPU\non every run. The vGIC list register save and restore use used_lrs as\ntheir loop bound and expect it to stay within the number of implemented\nlist registers. While this is generally the case, flush_hyp_vcpu()\ncopies vgic_v3 verbatim and does not enforce this, so a value provided\nby the host is used at EL2 to index vgic_lr[] and access ICH_LR\u003cn\u003e_EL2\n(host -\u003e EL2).\n\nFix by clamping used_lrs to the number of implemented list registers\nafter the copy, as the trusted path already does in\nvgic_flush_lr_state(). The number of implemented list registers is\nconstant after init, so it is replicated once from\nkvm_vgic_global_state.nr_lr into hyp_gicv3_nr_lr rather than read on\nevery entry."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - A malicious or compromised arm64 EL1 host reaches the flaw through the local KVM vCPU-run hypercall into pKVM EL2. No network or adjacent protocol directly controls this internal field.\nAC:L - On a pKVM/GICv3 system, the host can directly select an oversized used_lrs value and deterministically trigger the unchecked loops. No race or condition outside the attacker\u0027s control is required.\nPR:H - Normal KVM paths keep used_lrs hardware-bounded, and neither an unprivileged KVM user nor a user namespace can assign it directly. Exploitation requires control of the host kernel at EL1, equivalent to real administrative privileges.\nUI:N - The malicious host can load and run a vCPU itself without any action by a protected-VM user or another victim.\nS:C - Exploitation crosses pKVM\u0027s EL1-host-to-EL2 isolation boundary and can affect hypervisor-private state and protected VMs outside the host\u0027s security authority.\nC:H - The restore and synchronization paths can read beyond vgic_lr[] and transfer hyp-private vCPU data back into host-visible memory. EL2 compromise could expose protected-VM memory and other hypervisor secrets.\nI:H - The save path writes beyond vgic_lr[] into adjacent hyp-private vCPU metadata, including pointer, lock, and list state. This memory corruption is plausibly usable for EL2 control-flow hijacking and protected-VM modification.\nA:H - Large bounds can cause extensive loops, invalid EL2 memory accesses, or corruption of critical hypervisor metadata. An nVHE hypervisor panic explicitly escalates to a host kernel panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:43.106Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2c5e72b9fbf83fdfa724e9f1af0f418ccf8739b8"
},
{
"url": "https://git.kernel.org/stable/c/9fa301d8298778dd799fa4dcf7a7f440715d146e"
},
{
"url": "https://git.kernel.org/stable/c/c646431865f4b1a5b14067233fa27b11e05e0d46"
},
{
"url": "https://git.kernel.org/stable/c/7fca3fcef81c713bc82a37bf741e0f28e6d04a6f"
},
{
"url": "https://git.kernel.org/stable/c/8cc8bbbfab14c22c5551d0dd19b208a44b141c76"
}
],
"title": "KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64287",
"datePublished": "2026-07-25T08:49:28.168Z",
"dateReserved": "2026-07-19T15:36:31.778Z",
"dateUpdated": "2026-08-17T04:52:43.106Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64572 (GCVE-0-2026-64572)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: fib: free fib_alias with kfree_rcu() on insert error path
fib_table_insert() publishes new_fa into the leaf's fa_list with
fib_insert_alias() before calling the fib entry notifiers. When a
notifier fails, the error path removes new_fa with fib_remove_alias()
(hlist_del_rcu) and frees it right away with kmem_cache_free().
fib_table_lookup() walks that list under rcu_read_lock() only, so a
concurrent lookup that already reached new_fa keeps reading it after the
free:
BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)
Read of size 1 at addr ffff88810676d4eb by task exploit/297
Call Trace:
fib_table_lookup (net/ipv4/fib_trie.c:1601)
ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)
ip_route_output_key_hash (net/ipv4/route.c:2705)
__ip4_datagram_connect (net/ipv4/datagram.c:49)
udp_connect (net/ipv4/udp.c:2144)
__sys_connect (net/socket.c:2167)
__x64_sys_connect (net/socket.c:2173)
do_syscall_64
entry_SYSCALL_64_after_hwframe
which belongs to the cache ip_fib_alias of size 56
Triggering the error path needs CAP_NET_ADMIN and a registered fib
notifier that can reject a route; a netdevsim device whose IPv4 FIB
resource is exhausted is enough.
Free new_fa with alias_free_mem_rcu(), as fib_table_delete() already
does for a fib_alias removed from the trie.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/fib_trie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9d0778571def598c31e84a38ae5a7ebc6f65e6d8",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "bb03350f974aec352b660d032a1d283eb462165a",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "6429c9cfd941e62acd7bb0bc64d631574d4c3b2a",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "8150b5365f026e72250cacc527ea00be30f40105",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "d007056868723de9c0cc3f5ffaad47a8d468b9a4",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "cb8be318b4432abd88d3172ec157330f27a5f7a7",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "b8d2ea75c76abcd0d72679c2f488271f573e32fb",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "f2f152e94a67bc746afaf05a1b2702c195553112",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/fib_trie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: free fib_alias with kfree_rcu() on insert error path\n\nfib_table_insert() publishes new_fa into the leaf\u0027s fa_list with\nfib_insert_alias() before calling the fib entry notifiers. When a\nnotifier fails, the error path removes new_fa with fib_remove_alias()\n(hlist_del_rcu) and frees it right away with kmem_cache_free().\n\nfib_table_lookup() walks that list under rcu_read_lock() only, so a\nconcurrent lookup that already reached new_fa keeps reading it after the\nfree:\n\n BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)\n Read of size 1 at addr ffff88810676d4eb by task exploit/297\n Call Trace:\n fib_table_lookup (net/ipv4/fib_trie.c:1601)\n ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)\n ip_route_output_key_hash (net/ipv4/route.c:2705)\n __ip4_datagram_connect (net/ipv4/datagram.c:49)\n udp_connect (net/ipv4/udp.c:2144)\n __sys_connect (net/socket.c:2167)\n __x64_sys_connect (net/socket.c:2173)\n do_syscall_64\n entry_SYSCALL_64_after_hwframe\n which belongs to the cache ip_fib_alias of size 56\n\nTriggering the error path needs CAP_NET_ADMIN and a registered fib\nnotifier that can reject a route; a netdevsim device whose IPv4 FIB\nresource is exhausted is enough.\n\nFree new_fa with alias_free_mem_rcu(), as fib_table_delete() already\ndoes for a fib_alias removed from the trie."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:49.541Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9d0778571def598c31e84a38ae5a7ebc6f65e6d8"
},
{
"url": "https://git.kernel.org/stable/c/bb03350f974aec352b660d032a1d283eb462165a"
},
{
"url": "https://git.kernel.org/stable/c/6429c9cfd941e62acd7bb0bc64d631574d4c3b2a"
},
{
"url": "https://git.kernel.org/stable/c/8150b5365f026e72250cacc527ea00be30f40105"
},
{
"url": "https://git.kernel.org/stable/c/d007056868723de9c0cc3f5ffaad47a8d468b9a4"
},
{
"url": "https://git.kernel.org/stable/c/cb8be318b4432abd88d3172ec157330f27a5f7a7"
},
{
"url": "https://git.kernel.org/stable/c/b8d2ea75c76abcd0d72679c2f488271f573e32fb"
},
{
"url": "https://git.kernel.org/stable/c/f2f152e94a67bc746afaf05a1b2702c195553112"
}
],
"title": "ipv4: fib: free fib_alias with kfree_rcu() on insert error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64572",
"datePublished": "2026-08-05T08:08:09.068Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:49.541Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64517 (GCVE-0-2026-64517)
Vulnerability from cvelistv5
Published
2026-07-25 09:14
Modified
2026-07-25 09:14
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/gsc: Fix double-free of managed BO in error path
The error path in xe_gsc_init_post_hwconfig() explicitly frees a BO
allocated with xe_managed_bo_create_pin_map() via
xe_bo_unpin_map_no_vm(). Since the managed BO already has a devm
cleanup action registered, this causes a double-free when devm
unwinds during probe failure.
Remove the explicit free and let devm handle it, consistent with
all other xe_managed_bo_create_pin_map() callers.
(cherry picked from commit 71d61e3e299a17139e47f980a4d6f425b2c59bf7)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/xe/xe_gsc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7cb975fcd4777e7bad688f66aa0c10c16dd8276b",
"status": "affected",
"version": "2e5d47fe7839298fa096970e184aac9bf82c3bd3",
"versionType": "git"
},
{
"lessThan": "2c890e71ae26fa32f5a96c3694b71a2c310940e7",
"status": "affected",
"version": "2e5d47fe7839298fa096970e184aac9bf82c3bd3",
"versionType": "git"
},
{
"lessThan": "889f70de2b51a877339e1979aab95111b41bed75",
"status": "affected",
"version": "2e5d47fe7839298fa096970e184aac9bf82c3bd3",
"versionType": "git"
},
{
"lessThan": "d3ded53fab90996e7d94a39049e11962dd066725",
"status": "affected",
"version": "2e5d47fe7839298fa096970e184aac9bf82c3bd3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/xe/xe_gsc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/gsc: Fix double-free of managed BO in error path\n\nThe error path in xe_gsc_init_post_hwconfig() explicitly frees a BO\nallocated with xe_managed_bo_create_pin_map() via\nxe_bo_unpin_map_no_vm(). Since the managed BO already has a devm\ncleanup action registered, this causes a double-free when devm\nunwinds during probe failure.\n\nRemove the explicit free and let devm handle it, consistent with\nall other xe_managed_bo_create_pin_map() callers.\n\n(cherry picked from commit 71d61e3e299a17139e47f980a4d6f425b2c59bf7)"
}
],
"providerMetadata": {
"dateUpdated": "2026-07-25T09:14:43.863Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7cb975fcd4777e7bad688f66aa0c10c16dd8276b"
},
{
"url": "https://git.kernel.org/stable/c/2c890e71ae26fa32f5a96c3694b71a2c310940e7"
},
{
"url": "https://git.kernel.org/stable/c/889f70de2b51a877339e1979aab95111b41bed75"
},
{
"url": "https://git.kernel.org/stable/c/d3ded53fab90996e7d94a39049e11962dd066725"
}
],
"title": "drm/xe/gsc: Fix double-free of managed BO in error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64517",
"datePublished": "2026-07-25T09:14:43.863Z",
"dateReserved": "2026-07-19T15:36:31.794Z",
"dateUpdated": "2026-07-25T09:14:43.863Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63868 (GCVE-0-2026-63868)
Vulnerability from cvelistv5
Published
2026-07-19 14:18
Modified
2026-07-19 14:18
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: garp: fix unsigned integer underflow in garp_pdu_parse_attr
The receive-side GARP attribute parser computes dlen with reversed
operands:
dlen = sizeof(*ga) - ga->len;
ga->len is the on-wire attribute length and includes the GARP attribute
header. For normal attributes with data, ga->len is larger than
sizeof(*ga), so the subtraction underflows in unsigned arithmetic.
The resulting value is later passed to garp_attr_lookup(), whose length
argument is u8. After truncation, the parsed data length usually no
longer matches the length stored for locally registered attributes, so
received Join/Leave events are ignored. This breaks the GARP receive path
for common attributes, such as GVRP VLAN registration attributes.
Compute the data length as the attribute length minus the header length.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eca9ebac651f774d8b10fce7c5d173c3c3d3394f Version: eca9ebac651f774d8b10fce7c5d173c3c3d3394f Version: eca9ebac651f774d8b10fce7c5d173c3c3d3394f Version: eca9ebac651f774d8b10fce7c5d173c3c3d3394f Version: eca9ebac651f774d8b10fce7c5d173c3c3d3394f Version: eca9ebac651f774d8b10fce7c5d173c3c3d3394f Version: eca9ebac651f774d8b10fce7c5d173c3c3d3394f Version: eca9ebac651f774d8b10fce7c5d173c3c3d3394f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/802/garp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "29f28172afb2ae7b31e9bf3e978396f20b381688",
"status": "affected",
"version": "eca9ebac651f774d8b10fce7c5d173c3c3d3394f",
"versionType": "git"
},
{
"lessThan": "973cf7c433d27f4d9556d0b7c332543be7ed7a6e",
"status": "affected",
"version": "eca9ebac651f774d8b10fce7c5d173c3c3d3394f",
"versionType": "git"
},
{
"lessThan": "d8dcd14aa886b8effd83022c550669f4f262854b",
"status": "affected",
"version": "eca9ebac651f774d8b10fce7c5d173c3c3d3394f",
"versionType": "git"
},
{
"lessThan": "74e02121be1dcc0efcd56ebdf0171d6129105659",
"status": "affected",
"version": "eca9ebac651f774d8b10fce7c5d173c3c3d3394f",
"versionType": "git"
},
{
"lessThan": "d4c86ea09ae3e63ee5aa86e941fcc38e0e39874a",
"status": "affected",
"version": "eca9ebac651f774d8b10fce7c5d173c3c3d3394f",
"versionType": "git"
},
{
"lessThan": "04e22fefac1af3e32f245e9045382348773b5d59",
"status": "affected",
"version": "eca9ebac651f774d8b10fce7c5d173c3c3d3394f",
"versionType": "git"
},
{
"lessThan": "a11f1a671b1361f0f1278dc0041374f2730df73f",
"status": "affected",
"version": "eca9ebac651f774d8b10fce7c5d173c3c3d3394f",
"versionType": "git"
},
{
"lessThan": "16e408e607a94b646fb14a2a98422c6877ae4b3c",
"status": "affected",
"version": "eca9ebac651f774d8b10fce7c5d173c3c3d3394f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/802/garp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.27"
},
{
"lessThan": "2.6.27",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.27",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: garp: fix unsigned integer underflow in garp_pdu_parse_attr\n\nThe receive-side GARP attribute parser computes dlen with reversed\noperands:\n\n dlen = sizeof(*ga) - ga-\u003elen;\n\nga-\u003elen is the on-wire attribute length and includes the GARP attribute\nheader. For normal attributes with data, ga-\u003elen is larger than\nsizeof(*ga), so the subtraction underflows in unsigned arithmetic.\n\nThe resulting value is later passed to garp_attr_lookup(), whose length\nargument is u8. After truncation, the parsed data length usually no\nlonger matches the length stored for locally registered attributes, so\nreceived Join/Leave events are ignored. This breaks the GARP receive path\nfor common attributes, such as GVRP VLAN registration attributes.\n\nCompute the data length as the attribute length minus the header length."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:18:37.823Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/29f28172afb2ae7b31e9bf3e978396f20b381688"
},
{
"url": "https://git.kernel.org/stable/c/973cf7c433d27f4d9556d0b7c332543be7ed7a6e"
},
{
"url": "https://git.kernel.org/stable/c/d8dcd14aa886b8effd83022c550669f4f262854b"
},
{
"url": "https://git.kernel.org/stable/c/74e02121be1dcc0efcd56ebdf0171d6129105659"
},
{
"url": "https://git.kernel.org/stable/c/d4c86ea09ae3e63ee5aa86e941fcc38e0e39874a"
},
{
"url": "https://git.kernel.org/stable/c/04e22fefac1af3e32f245e9045382348773b5d59"
},
{
"url": "https://git.kernel.org/stable/c/a11f1a671b1361f0f1278dc0041374f2730df73f"
},
{
"url": "https://git.kernel.org/stable/c/16e408e607a94b646fb14a2a98422c6877ae4b3c"
}
],
"title": "net: garp: fix unsigned integer underflow in garp_pdu_parse_attr",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63868",
"datePublished": "2026-07-19T14:18:37.823Z",
"dateReserved": "2026-07-19T07:54:57.017Z",
"dateUpdated": "2026-07-19T14:18:37.823Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64477 (GCVE-0-2026-64477)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled
The architecture updates the cpu_mask in a domain's header to track which
online CPUs are associated with the domain. When this mask becomes empty
the architecture initiates offline of the domain that includes calling
on resctrl fs to offline the domain. If it is a monitoring domain in
which LLC occupancy is tracked resctrl fs forces the limbo handler to
clear all busy RMID state associated with the domain.
The limbo handler always reads the current event value associated with a
busy RMID irrespective of it being checked as part of regular "is it still
busy" check or whether it will be forced released anyway. When reading an
RMID on a system with SNC enabled the "logical RMID" is converted to the
"physical RMID" and this conversion requires the NUMA node ID of the
resctrl monitoring domain that is in turn determined by querying the NUMA
node ID of any CPU belonging to the monitoring domain.
When the monitoring domain is going offline its cpu_mask is empty causing
the NUMA node ID query via cpu_to_node() to be done with "nr_cpu_ids" as
argument resulting in an out-of-bounds access.
Refactor the limbo handler to skip reading the RMID when the RMID will
just be forced to no longer be dirty in the domain anyway. Add a safety
check to the architecture's RMID reader to protect against this scenario.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kernel/cpu/resctrl/monitor.c",
"fs/resctrl/monitor.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ebc300b7ee0c669fa76a7a8858298ff32e296103",
"status": "affected",
"version": "e13db55b5a0d447dea63cde772c1078405bbbf96",
"versionType": "git"
},
{
"lessThan": "be1567992417dc92133e74126de7a6066c825ac9",
"status": "affected",
"version": "e13db55b5a0d447dea63cde772c1078405bbbf96",
"versionType": "git"
},
{
"lessThan": "58c5ec23b1a238eb75cb0aba6f69d8f9e68ef0b2",
"status": "affected",
"version": "e13db55b5a0d447dea63cde772c1078405bbbf96",
"versionType": "git"
},
{
"lessThan": "fc16126cc11d9f507130bf84ab137ee0938c900e",
"status": "affected",
"version": "e13db55b5a0d447dea63cde772c1078405bbbf96",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kernel/cpu/resctrl/monitor.c",
"fs/resctrl/monitor.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled\n\nThe architecture updates the cpu_mask in a domain\u0027s header to track which\nonline CPUs are associated with the domain. When this mask becomes empty\nthe architecture initiates offline of the domain that includes calling\non resctrl fs to offline the domain. If it is a monitoring domain in\nwhich LLC occupancy is tracked resctrl fs forces the limbo handler to\nclear all busy RMID state associated with the domain.\n\nThe limbo handler always reads the current event value associated with a\nbusy RMID irrespective of it being checked as part of regular \"is it still\nbusy\" check or whether it will be forced released anyway. When reading an\nRMID on a system with SNC enabled the \"logical RMID\" is converted to the\n\"physical RMID\" and this conversion requires the NUMA node ID of the\nresctrl monitoring domain that is in turn determined by querying the NUMA\nnode ID of any CPU belonging to the monitoring domain.\n\nWhen the monitoring domain is going offline its cpu_mask is empty causing\nthe NUMA node ID query via cpu_to_node() to be done with \"nr_cpu_ids\" as\nargument resulting in an out-of-bounds access.\n\nRefactor the limbo handler to skip reading the RMID when the RMID will\njust be forced to no longer be dirty in the domain anyway. Add a safety\ncheck to the architecture\u0027s RMID reader to protect against this scenario."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:23.686Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ebc300b7ee0c669fa76a7a8858298ff32e296103"
},
{
"url": "https://git.kernel.org/stable/c/be1567992417dc92133e74126de7a6066c825ac9"
},
{
"url": "https://git.kernel.org/stable/c/58c5ec23b1a238eb75cb0aba6f69d8f9e68ef0b2"
},
{
"url": "https://git.kernel.org/stable/c/fc16126cc11d9f507130bf84ab137ee0938c900e"
}
],
"title": "x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64477",
"datePublished": "2026-07-25T08:51:39.558Z",
"dateReserved": "2026-07-19T15:36:31.791Z",
"dateUpdated": "2026-08-17T04:56:23.686Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46091 (GCVE-0-2026-46091)
Vulnerability from cvelistv5
Published
2026-05-27 12:58
Modified
2026-06-19 11:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: rc: igorplugusb: heed coherency rules
In a control request, the USB request structure
can be subject to DMA on some HCs. Hence it must obey
the rules for DMA coherency. Allocate it separately.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b1c97193c6437a6083da67f8e97c8ee29b2f1989 Version: b1c97193c6437a6083da67f8e97c8ee29b2f1989 Version: b1c97193c6437a6083da67f8e97c8ee29b2f1989 Version: b1c97193c6437a6083da67f8e97c8ee29b2f1989 Version: b1c97193c6437a6083da67f8e97c8ee29b2f1989 Version: b1c97193c6437a6083da67f8e97c8ee29b2f1989 Version: b1c97193c6437a6083da67f8e97c8ee29b2f1989 Version: b1c97193c6437a6083da67f8e97c8ee29b2f1989 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/rc/igorplugusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bc04b8633b375af6ac8a8bb615258b80fe06cdaa",
"status": "affected",
"version": "b1c97193c6437a6083da67f8e97c8ee29b2f1989",
"versionType": "git"
},
{
"lessThan": "81f0fb813e4bf28b3ca28dc218938a32eb48f740",
"status": "affected",
"version": "b1c97193c6437a6083da67f8e97c8ee29b2f1989",
"versionType": "git"
},
{
"lessThan": "0e84aa8fc23c7578f105e3a2160f9d0aa2bed79a",
"status": "affected",
"version": "b1c97193c6437a6083da67f8e97c8ee29b2f1989",
"versionType": "git"
},
{
"lessThan": "18d6a7c9e4e63c57157e9a57dd9bf3cd38e4c45a",
"status": "affected",
"version": "b1c97193c6437a6083da67f8e97c8ee29b2f1989",
"versionType": "git"
},
{
"lessThan": "0be8fcd9005e3d3b5a61fe34b070a9663adbb4dc",
"status": "affected",
"version": "b1c97193c6437a6083da67f8e97c8ee29b2f1989",
"versionType": "git"
},
{
"lessThan": "0adac0ee2c42027d80bac02ea9b576a88f8955d3",
"status": "affected",
"version": "b1c97193c6437a6083da67f8e97c8ee29b2f1989",
"versionType": "git"
},
{
"lessThan": "a62ca67e3c72fb297dc7c86495ba8f7329d7f150",
"status": "affected",
"version": "b1c97193c6437a6083da67f8e97c8ee29b2f1989",
"versionType": "git"
},
{
"lessThan": "eac69475b01fe1e861dfe3960b57fa95671c132e",
"status": "affected",
"version": "b1c97193c6437a6083da67f8e97c8ee29b2f1989",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/rc/igorplugusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.86",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.27",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.86",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.27",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.4",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rc: igorplugusb: heed coherency rules\n\nIn a control request, the USB request structure\ncan be subject to DMA on some HCs. Hence it must obey\nthe rules for DMA coherency. Allocate it separately."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-19T11:59:27.632Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bc04b8633b375af6ac8a8bb615258b80fe06cdaa"
},
{
"url": "https://git.kernel.org/stable/c/81f0fb813e4bf28b3ca28dc218938a32eb48f740"
},
{
"url": "https://git.kernel.org/stable/c/0e84aa8fc23c7578f105e3a2160f9d0aa2bed79a"
},
{
"url": "https://git.kernel.org/stable/c/18d6a7c9e4e63c57157e9a57dd9bf3cd38e4c45a"
},
{
"url": "https://git.kernel.org/stable/c/0be8fcd9005e3d3b5a61fe34b070a9663adbb4dc"
},
{
"url": "https://git.kernel.org/stable/c/0adac0ee2c42027d80bac02ea9b576a88f8955d3"
},
{
"url": "https://git.kernel.org/stable/c/a62ca67e3c72fb297dc7c86495ba8f7329d7f150"
},
{
"url": "https://git.kernel.org/stable/c/eac69475b01fe1e861dfe3960b57fa95671c132e"
}
],
"title": "media: rc: igorplugusb: heed coherency rules",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46091",
"datePublished": "2026-05-27T12:58:35.422Z",
"dateReserved": "2026-05-13T15:03:33.097Z",
"dateUpdated": "2026-06-19T11:59:27.632Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68234 (GCVE-0-2026-68234)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
amdgpu_bo_create_reserved() only allocates a new BO when
*bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is
NULL, it simply skips creation when *bo_ptr is non-NULL.
But it unconditionally reserves, pins, gart allocates
and maps the BO afterwards.
When the same non-NULL BO pointer is passed in again,
for example firmware buffers that live in adev and are
re-loaded on every resume / cp_resume / start
under AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases
pin_count unconditionally, however the matching teardown only unpins
once, so pin_count never drops to zero, so TTM is not able
to move, swap or evict a BO, causing BO leaks.
This commit fixes this issue by only pinning the bo
once at creation, and repeated calls no longer
take additional pin references.
(cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_object.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7aea619d9f186dcf0f1289879e9edb69d2b56639",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "b572d0814c1366701ca704286589fab025802566",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "e06e0885725a16304b7723aeb478a78cca9dc96a",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "51eeef1949c11d3dcb5f422a5d9b3f09ebe8a1bc",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "2f390b4c83011452753fd84972f657d2b00a952b",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "ba7b6444097a73ccd3d3ac9e2be4ebb73d226460",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "9743f60013273987abf415dc47474683d22aaee9",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "a2f895f3c852063258d62e9f74b081de07ca95df",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_object.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix bo-\u003epin leaking in amdgpu_bo_create_reserved\n\namdgpu_bo_create_reserved() only allocates a new BO when\n*bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is\nNULL, it simply skips creation when *bo_ptr is non-NULL.\nBut it unconditionally reserves, pins, gart allocates\nand maps the BO afterwards.\n\nWhen the same non-NULL BO pointer is passed in again,\nfor example firmware buffers that live in adev and are\nre-loaded on every resume / cp_resume / start\nunder AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases\npin_count unconditionally, however the matching teardown only unpins\nonce, so pin_count never drops to zero, so TTM is not able\nto move, swap or evict a BO, causing BO leaks.\n\nThis commit fixes this issue by only pinning the bo\nonce at creation, and repeated calls no longer\ntake additional pin references.\n\n(cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:06.457Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7aea619d9f186dcf0f1289879e9edb69d2b56639"
},
{
"url": "https://git.kernel.org/stable/c/b572d0814c1366701ca704286589fab025802566"
},
{
"url": "https://git.kernel.org/stable/c/e06e0885725a16304b7723aeb478a78cca9dc96a"
},
{
"url": "https://git.kernel.org/stable/c/51eeef1949c11d3dcb5f422a5d9b3f09ebe8a1bc"
},
{
"url": "https://git.kernel.org/stable/c/2f390b4c83011452753fd84972f657d2b00a952b"
},
{
"url": "https://git.kernel.org/stable/c/ba7b6444097a73ccd3d3ac9e2be4ebb73d226460"
},
{
"url": "https://git.kernel.org/stable/c/9743f60013273987abf415dc47474683d22aaee9"
},
{
"url": "https://git.kernel.org/stable/c/a2f895f3c852063258d62e9f74b081de07ca95df"
}
],
"title": "drm/amdgpu: fix bo-\u003epin leaking in amdgpu_bo_create_reserved",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68234",
"datePublished": "2026-08-10T12:00:59.074Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:32:06.457Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64274 (GCVE-0-2026-64274)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: goodix - clamp the device-reported contact count
goodix_ts_read_input_report() copies the number of touch points reported
by the device into an on-stack buffer
u8 point_data[2 + GOODIX_MAX_CONTACT_SIZE * GOODIX_MAX_CONTACTS];
which is sized for at most GOODIX_MAX_CONTACTS (10) contacts. The only
runtime check bounds the per-interrupt count against ts->max_touch_num,
but that value is taken verbatim from a 4-bit field of the device
configuration block and is never clamped:
ts->max_touch_num = ts->config[MAX_CONTACTS_LOC] & 0x0f;
The nibble can be 0..15, so a malfunctioning, malicious or counterfeit
controller (or an attacker tampering with the I2C bus) can advertise up
to 15 contacts. goodix_ts_read_input_report() then accepts a touch_num
of up to 15 and the second goodix_i2c_read() writes
ts->contact_size * (touch_num - 1) bytes past the one-contact header into
point_data - up to 30 bytes (45 with the 9-byte report format) beyond the
92-byte buffer: a stack out-of-bounds write.
Clamp max_touch_num to GOODIX_MAX_CONTACTS, the number of contacts
point_data[] is sized for, when reading it from the configuration.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a7ac7c95d4682883d141c5d7a7544d2818f0a09f Version: a7ac7c95d4682883d141c5d7a7544d2818f0a09f Version: a7ac7c95d4682883d141c5d7a7544d2818f0a09f Version: a7ac7c95d4682883d141c5d7a7544d2818f0a09f Version: a7ac7c95d4682883d141c5d7a7544d2818f0a09f Version: a7ac7c95d4682883d141c5d7a7544d2818f0a09f Version: a7ac7c95d4682883d141c5d7a7544d2818f0a09f Version: a7ac7c95d4682883d141c5d7a7544d2818f0a09f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/goodix.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e825f352ef5271255cd08cc994b0dc25648a2f38",
"status": "affected",
"version": "a7ac7c95d4682883d141c5d7a7544d2818f0a09f",
"versionType": "git"
},
{
"lessThan": "4bfea9c3a0981c1c7fc5d1a1b27197b2de247902",
"status": "affected",
"version": "a7ac7c95d4682883d141c5d7a7544d2818f0a09f",
"versionType": "git"
},
{
"lessThan": "98b2caef249183b572c04451365246f919707845",
"status": "affected",
"version": "a7ac7c95d4682883d141c5d7a7544d2818f0a09f",
"versionType": "git"
},
{
"lessThan": "719d1a2c83a46be6bf81af905e4f6adb3d32dc28",
"status": "affected",
"version": "a7ac7c95d4682883d141c5d7a7544d2818f0a09f",
"versionType": "git"
},
{
"lessThan": "46addbd13dbf4aacb71cfbca964a5e552d0f45ae",
"status": "affected",
"version": "a7ac7c95d4682883d141c5d7a7544d2818f0a09f",
"versionType": "git"
},
{
"lessThan": "3b32303460155603d25444274856013d211d5e1f",
"status": "affected",
"version": "a7ac7c95d4682883d141c5d7a7544d2818f0a09f",
"versionType": "git"
},
{
"lessThan": "2a67668690129953e898923260a2dd1c7c196495",
"status": "affected",
"version": "a7ac7c95d4682883d141c5d7a7544d2818f0a09f",
"versionType": "git"
},
{
"lessThan": "5ed62a96e06be4e94b8296b7932afee550a70e04",
"status": "affected",
"version": "a7ac7c95d4682883d141c5d7a7544d2818f0a09f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/goodix.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: goodix - clamp the device-reported contact count\n\ngoodix_ts_read_input_report() copies the number of touch points reported\nby the device into an on-stack buffer\n\n\tu8 point_data[2 + GOODIX_MAX_CONTACT_SIZE * GOODIX_MAX_CONTACTS];\n\nwhich is sized for at most GOODIX_MAX_CONTACTS (10) contacts. The only\nruntime check bounds the per-interrupt count against ts-\u003emax_touch_num,\nbut that value is taken verbatim from a 4-bit field of the device\nconfiguration block and is never clamped:\n\n\tts-\u003emax_touch_num = ts-\u003econfig[MAX_CONTACTS_LOC] \u0026 0x0f;\n\nThe nibble can be 0..15, so a malfunctioning, malicious or counterfeit\ncontroller (or an attacker tampering with the I2C bus) can advertise up\nto 15 contacts. goodix_ts_read_input_report() then accepts a touch_num\nof up to 15 and the second goodix_i2c_read() writes\nts-\u003econtact_size * (touch_num - 1) bytes past the one-contact header into\npoint_data - up to 30 bytes (45 with the 9-byte report format) beyond the\n92-byte buffer: a stack out-of-bounds write.\n\nClamp max_touch_num to GOODIX_MAX_CONTACTS, the number of contacts\npoint_data[] is sized for, when reading it from the configuration."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:28.842Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e825f352ef5271255cd08cc994b0dc25648a2f38"
},
{
"url": "https://git.kernel.org/stable/c/4bfea9c3a0981c1c7fc5d1a1b27197b2de247902"
},
{
"url": "https://git.kernel.org/stable/c/98b2caef249183b572c04451365246f919707845"
},
{
"url": "https://git.kernel.org/stable/c/719d1a2c83a46be6bf81af905e4f6adb3d32dc28"
},
{
"url": "https://git.kernel.org/stable/c/46addbd13dbf4aacb71cfbca964a5e552d0f45ae"
},
{
"url": "https://git.kernel.org/stable/c/3b32303460155603d25444274856013d211d5e1f"
},
{
"url": "https://git.kernel.org/stable/c/2a67668690129953e898923260a2dd1c7c196495"
},
{
"url": "https://git.kernel.org/stable/c/5ed62a96e06be4e94b8296b7932afee550a70e04"
}
],
"title": "Input: goodix - clamp the device-reported contact count",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64274",
"datePublished": "2026-07-25T08:49:20.040Z",
"dateReserved": "2026-07-19T15:36:31.776Z",
"dateUpdated": "2026-08-17T04:52:28.842Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52972 (GCVE-0-2026-52972)
Vulnerability from cvelistv5
Published
2026-06-24 16:28
Modified
2026-08-17 04:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Cap AEAD AD length to 0x80000000
In order to prevent arithmetic overflows when checking the TX
buffer size, cap the associated data length to 0x80000000.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 400c40cf78da00c16e561a3a253ca272455c42ef Version: 400c40cf78da00c16e561a3a253ca272455c42ef Version: 400c40cf78da00c16e561a3a253ca272455c42ef Version: 400c40cf78da00c16e561a3a253ca272455c42ef Version: 400c40cf78da00c16e561a3a253ca272455c42ef Version: 400c40cf78da00c16e561a3a253ca272455c42ef Version: 400c40cf78da00c16e561a3a253ca272455c42ef Version: 400c40cf78da00c16e561a3a253ca272455c42ef Version: 400c40cf78da00c16e561a3a253ca272455c42ef |
||
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-06-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel\u0027s `af_alg` cryptography module. This vulnerability involves an arithmetic overflow when processing associated data lengths during the transmit buffer size check. A remote attacker could exploit this flaw by providing a specially crafted associated data length, potentially leading to a denial of service (DoS) due to system instability."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Important"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-190",
"description": "Integer Overflow or Wraparound",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-15T02:46:50.271Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-52972"
},
{
"name": "RHBZ#2492364",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492364"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52972.json"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000",
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"crypto/af_alg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f8a5203596797f394ff3f9aa4005597a92249802",
"status": "affected",
"version": "400c40cf78da00c16e561a3a253ca272455c42ef",
"versionType": "git"
},
{
"lessThan": "a9f68d9ed38dd6e5a6c6d75b03d25c1c133e321d",
"status": "affected",
"version": "400c40cf78da00c16e561a3a253ca272455c42ef",
"versionType": "git"
},
{
"lessThan": "a4fe4eb580bbc7439f649a496d4cf38415a4021c",
"status": "affected",
"version": "400c40cf78da00c16e561a3a253ca272455c42ef",
"versionType": "git"
},
{
"lessThan": "e4c4a5074532eaaa14951994a3aad0d479aa7431",
"status": "affected",
"version": "400c40cf78da00c16e561a3a253ca272455c42ef",
"versionType": "git"
},
{
"lessThan": "265ac26d1c5e17b34d497cbda1f754a1ec8552bc",
"status": "affected",
"version": "400c40cf78da00c16e561a3a253ca272455c42ef",
"versionType": "git"
},
{
"lessThan": "a1c5672faf8e93e38c2deac3979cc767ca5cf918",
"status": "affected",
"version": "400c40cf78da00c16e561a3a253ca272455c42ef",
"versionType": "git"
},
{
"lessThan": "97948906dc8e0ea84775e03e35b60a2063c70193",
"status": "affected",
"version": "400c40cf78da00c16e561a3a253ca272455c42ef",
"versionType": "git"
},
{
"lessThan": "0b3a57d218618cb1cc78ddc9ba02c07de84b46f4",
"status": "affected",
"version": "400c40cf78da00c16e561a3a253ca272455c42ef",
"versionType": "git"
},
{
"lessThan": "e4c06479d7059888adf2f22bc1ebcf053bf691a2",
"status": "affected",
"version": "400c40cf78da00c16e561a3a253ca272455c42ef",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"crypto/af_alg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Cap AEAD AD length to 0x80000000\n\nIn order to prevent arithmetic overflows when checking the TX\nbuffer size, cap the associated data length to 0x80000000."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:50:24.931Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f8a5203596797f394ff3f9aa4005597a92249802"
},
{
"url": "https://git.kernel.org/stable/c/a9f68d9ed38dd6e5a6c6d75b03d25c1c133e321d"
},
{
"url": "https://git.kernel.org/stable/c/a4fe4eb580bbc7439f649a496d4cf38415a4021c"
},
{
"url": "https://git.kernel.org/stable/c/e4c4a5074532eaaa14951994a3aad0d479aa7431"
},
{
"url": "https://git.kernel.org/stable/c/265ac26d1c5e17b34d497cbda1f754a1ec8552bc"
},
{
"url": "https://git.kernel.org/stable/c/a1c5672faf8e93e38c2deac3979cc767ca5cf918"
},
{
"url": "https://git.kernel.org/stable/c/97948906dc8e0ea84775e03e35b60a2063c70193"
},
{
"url": "https://git.kernel.org/stable/c/0b3a57d218618cb1cc78ddc9ba02c07de84b46f4"
},
{
"url": "https://git.kernel.org/stable/c/e4c06479d7059888adf2f22bc1ebcf053bf691a2"
}
],
"title": "crypto: af_alg - Cap AEAD AD length to 0x80000000",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52972",
"datePublished": "2026-06-24T16:28:50.425Z",
"dateReserved": "2026-06-09T07:44:35.375Z",
"dateUpdated": "2026-08-17T04:50:24.931Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68235 (GCVE-0-2026-68235)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: dce100: skip non-DP stream encoders for DP MST
On DCE8-class ASICs (e.g. Bonaire), the resource pool contains digital
DIG stream encoders plus one analog DAC encoder. When assigning a stream
encoder for a second DisplayPort MST stream, if the preferred digital
encoder is already acquired, dce100_find_first_free_match_stream_enc_for_link()
falls back to the first free pool entry. That entry may be the analog
encoder, whose funcs table lacks DP hooks such as dp_set_stream_attribute.
The subsequent atomic commit then dereferences NULL function pointers in
link_set_dpms_on() and crashes.
Skip encoders without dp_set_stream_attribute when the stream uses a DP
signal (including MST). Use dc_is_dp_signal(stream->signal) for the MST
fallback path instead of checking only the link connector signal.
Tested on:
- GPU: AMD Radeon R7 260X (Bonaire / DCE8)
- Board: Supermicro C9X299-PG300
- Setup: DP MST daisy chain, hotplug second monitor or have it connected on boot
- Kernel: 7.1.3 (issue observed since 6.19)
- Result: kernel oops without patch; dual monitors stable with patch
(cherry picked from commit 28ec64943e3ee4d9b8d30cea61e380f1429953a8)
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/resource/dce100/dce100_resource.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ed2d86aef9fa4c43f82da0fca91a60f7326d7d03",
"status": "affected",
"version": "5834c33fd3f6f2a26dd4d6d4bbc7b8ed1c2ac4aa",
"versionType": "git"
},
{
"lessThan": "d340cba0df4cf327c7e89c7c1a4e79d4771d7dd5",
"status": "affected",
"version": "5834c33fd3f6f2a26dd4d6d4bbc7b8ed1c2ac4aa",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/resource/dce100/dce100_resource.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"lessThan": "6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: dce100: skip non-DP stream encoders for DP MST\n\nOn DCE8-class ASICs (e.g. Bonaire), the resource pool contains digital\nDIG stream encoders plus one analog DAC encoder. When assigning a stream\nencoder for a second DisplayPort MST stream, if the preferred digital\nencoder is already acquired, dce100_find_first_free_match_stream_enc_for_link()\nfalls back to the first free pool entry. That entry may be the analog\nencoder, whose funcs table lacks DP hooks such as dp_set_stream_attribute.\nThe subsequent atomic commit then dereferences NULL function pointers in\nlink_set_dpms_on() and crashes.\n\nSkip encoders without dp_set_stream_attribute when the stream uses a DP\nsignal (including MST). Use dc_is_dp_signal(stream-\u003esignal) for the MST\nfallback path instead of checking only the link connector signal.\n\nTested on:\n- GPU: AMD Radeon R7 260X (Bonaire / DCE8)\n- Board: Supermicro C9X299-PG300\n- Setup: DP MST daisy chain, hotplug second monitor or have it connected on boot\n- Kernel: 7.1.3 (issue observed since 6.19)\n- Result: kernel oops without patch; dual monitors stable with patch\n\n(cherry picked from commit 28ec64943e3ee4d9b8d30cea61e380f1429953a8)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:45.652Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ed2d86aef9fa4c43f82da0fca91a60f7326d7d03"
},
{
"url": "https://git.kernel.org/stable/c/d340cba0df4cf327c7e89c7c1a4e79d4771d7dd5"
}
],
"title": "drm/amd/display: dce100: skip non-DP stream encoders for DP MST",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68235",
"datePublished": "2026-08-10T12:01:00.099Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-18T06:55:45.652Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72473 (GCVE-0-2026-72473)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xprtrdma: Decouple req recycling from RPC completion
rl_kref formerly served two distinct lifetimes through a single
refcount: it gated when a Reply could wake its RPC task, and it
gated when an rpcrdma_req could return to its free pool. The
marshal path took the Send-side reference only when SGEs needed
DMA-unmap (sc_unmap_count > 0), which made a Send carrying only
pre-registered buffers an exception: the Reply handler dropped
rl_kref from 1 to 0 and freed the req while the HCA might still
be DMA-reading from its send buffer.
Give rl_kref a narrower job. The RPC layer takes one reference
when slot allocation hands a req out. rpcrdma_prepare_send_sges()
takes a Send-side reference unconditionally after WR preparation
succeeds. xprt_rdma_free_slot() and xprt_rdma_bc_free_rqst() drop
the RPC-layer reference; rpcrdma_sendctx_unmap() drops the
Send-side reference. The req returns to its free pool only after
both owners have signed off.
The existing kref_init(&req->rl_kref) call in
rpcrdma_prepare_send_sges() is removed. Initialization moves to
the slot-allocation paths (xprt_rdma_alloc_slot and
rpcrdma_bc_rqst_get), and the release callback re-arms rl_kref
before the req returns to a free pool. A re-init in the marshal
path would discard the RPC-layer reference that already exists
on entry.
Three invariants follow:
- Any rpcrdma_req held by an rpc_rqst has rl_kref >= 1.
xprt_rdma_alloc_slot(), rpcrdma_bc_rqst_get(), and the
backlog-wake branch in xprt_rdma_alloc_slot() each kref_init
rl_kref before publishing the req. Without this invariant,
an RPC task that aborts between slot allocation and marshal
(gss_refresh failure or signal during call_connect, for
example) would drive xprt_release() ->
xprt_rdma_free_slot() -> kref_put against a refcount of
zero, saturating refcount_t and stranding the slot.
- The Send-side reference is taken only after WR prep
succeeds. A mapping failure in rpcrdma_prepare_send_sges()
runs rpcrdma_sendctx_cancel(), which DMA-unmaps the sendctx
and clears sc_req without touching rl_kref. The sendctx
ring walks in rpcrdma_sendctx_put_locked() and
rpcrdma_sendctxs_destroy() skip entries with sc_req == NULL,
so a burst of -EIO marshal failures cannot hold reqs off
rb_send_bufs.
- The release callback re-arms rl_kref so the next consumer
enters with the invariant satisfied.
Replies now complete the RPC directly. rpcrdma_reply_handler()
calls rpcrdma_complete_rqst() in place of kref_put on the
non-LocalInv branch. The LocalInv branch already completes the
RPC from frwr_unmap_async() and is unaffected.
Because Send-side references can now outlive RPC completion,
connection teardown drains sendctx entries whose unsignaled
Sends never had a later signaled completion to walk the ring.
rpcrdma_sendctxs_destroy() walks the active range and runs
rpcrdma_sendctx_unmap() on each entry with a non-NULL sc_req
before the request buffers are reset, and is moved ahead of
rpcrdma_reqs_reset() in rpcrdma_xprt_disconnect() so the reqs
are still in their pre-reset state when the Send-side refs are
released.
The drain creates a teardown-ordering hazard on the backchannel
path. With the new lifetime, releasing a bc_prealloc req from
rpcrdma_req_release() re-adds it to bc_pa_list. The disconnect
in xprt_rdma_destroy() runs after xprt_destroy_backchannel() has
already emptied bc_pa_list, so the drained reqs would otherwise
leak. xprt_rdma_destroy() now runs xprt_rdma_bc_destroy(xprt, 0)
a second time after the disconnect to reclaim them.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0ab115237025f5e379620bbcd56a02697d07b002 Version: 0ab115237025f5e379620bbcd56a02697d07b002 Version: 0ab115237025f5e379620bbcd56a02697d07b002 Version: 0ab115237025f5e379620bbcd56a02697d07b002 Version: 0ab115237025f5e379620bbcd56a02697d07b002 Version: 0ab115237025f5e379620bbcd56a02697d07b002 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sunrpc/xprtrdma/backchannel.c",
"net/sunrpc/xprtrdma/rpc_rdma.c",
"net/sunrpc/xprtrdma/transport.c",
"net/sunrpc/xprtrdma/verbs.c",
"net/sunrpc/xprtrdma/xprt_rdma.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "740975054a1970c0cf15f70ac39724a064f45847",
"status": "affected",
"version": "0ab115237025f5e379620bbcd56a02697d07b002",
"versionType": "git"
},
{
"lessThan": "9f3d9b68c1c6c51746e5ecdb52b2e6a2901de37e",
"status": "affected",
"version": "0ab115237025f5e379620bbcd56a02697d07b002",
"versionType": "git"
},
{
"lessThan": "e7632089523acddcdd8f090ad19e96fb3107b04d",
"status": "affected",
"version": "0ab115237025f5e379620bbcd56a02697d07b002",
"versionType": "git"
},
{
"lessThan": "53442c7d0c888e51b8bc3da196970a669cc6b294",
"status": "affected",
"version": "0ab115237025f5e379620bbcd56a02697d07b002",
"versionType": "git"
},
{
"lessThan": "8203f760a72bd39a3b66bc4eff0aa272a99fe22b",
"status": "affected",
"version": "0ab115237025f5e379620bbcd56a02697d07b002",
"versionType": "git"
},
{
"lessThan": "e786233d2e0bbff9a82e43f02ae3a46ab4b08ec3",
"status": "affected",
"version": "0ab115237025f5e379620bbcd56a02697d07b002",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sunrpc/xprtrdma/backchannel.c",
"net/sunrpc/xprtrdma/rpc_rdma.c",
"net/sunrpc/xprtrdma/transport.c",
"net/sunrpc/xprtrdma/verbs.c",
"net/sunrpc/xprtrdma/xprt_rdma.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Decouple req recycling from RPC completion\n\nrl_kref formerly served two distinct lifetimes through a single\nrefcount: it gated when a Reply could wake its RPC task, and it\ngated when an rpcrdma_req could return to its free pool. The\nmarshal path took the Send-side reference only when SGEs needed\nDMA-unmap (sc_unmap_count \u003e 0), which made a Send carrying only\npre-registered buffers an exception: the Reply handler dropped\nrl_kref from 1 to 0 and freed the req while the HCA might still\nbe DMA-reading from its send buffer.\n\nGive rl_kref a narrower job. The RPC layer takes one reference\nwhen slot allocation hands a req out. rpcrdma_prepare_send_sges()\ntakes a Send-side reference unconditionally after WR preparation\nsucceeds. xprt_rdma_free_slot() and xprt_rdma_bc_free_rqst() drop\nthe RPC-layer reference; rpcrdma_sendctx_unmap() drops the\nSend-side reference. The req returns to its free pool only after\nboth owners have signed off.\n\nThe existing kref_init(\u0026req-\u003erl_kref) call in\nrpcrdma_prepare_send_sges() is removed. Initialization moves to\nthe slot-allocation paths (xprt_rdma_alloc_slot and\nrpcrdma_bc_rqst_get), and the release callback re-arms rl_kref\nbefore the req returns to a free pool. A re-init in the marshal\npath would discard the RPC-layer reference that already exists\non entry.\n\nThree invariants follow:\n\n - Any rpcrdma_req held by an rpc_rqst has rl_kref \u003e= 1.\n xprt_rdma_alloc_slot(), rpcrdma_bc_rqst_get(), and the\n backlog-wake branch in xprt_rdma_alloc_slot() each kref_init\n rl_kref before publishing the req. Without this invariant,\n an RPC task that aborts between slot allocation and marshal\n (gss_refresh failure or signal during call_connect, for\n example) would drive xprt_release() -\u003e\n xprt_rdma_free_slot() -\u003e kref_put against a refcount of\n zero, saturating refcount_t and stranding the slot.\n\n - The Send-side reference is taken only after WR prep\n succeeds. A mapping failure in rpcrdma_prepare_send_sges()\n runs rpcrdma_sendctx_cancel(), which DMA-unmaps the sendctx\n and clears sc_req without touching rl_kref. The sendctx\n ring walks in rpcrdma_sendctx_put_locked() and\n rpcrdma_sendctxs_destroy() skip entries with sc_req == NULL,\n so a burst of -EIO marshal failures cannot hold reqs off\n rb_send_bufs.\n\n - The release callback re-arms rl_kref so the next consumer\n enters with the invariant satisfied.\n\nReplies now complete the RPC directly. rpcrdma_reply_handler()\ncalls rpcrdma_complete_rqst() in place of kref_put on the\nnon-LocalInv branch. The LocalInv branch already completes the\nRPC from frwr_unmap_async() and is unaffected.\n\nBecause Send-side references can now outlive RPC completion,\nconnection teardown drains sendctx entries whose unsignaled\nSends never had a later signaled completion to walk the ring.\nrpcrdma_sendctxs_destroy() walks the active range and runs\nrpcrdma_sendctx_unmap() on each entry with a non-NULL sc_req\nbefore the request buffers are reset, and is moved ahead of\nrpcrdma_reqs_reset() in rpcrdma_xprt_disconnect() so the reqs\nare still in their pre-reset state when the Send-side refs are\nreleased.\n\nThe drain creates a teardown-ordering hazard on the backchannel\npath. With the new lifetime, releasing a bc_prealloc req from\nrpcrdma_req_release() re-adds it to bc_pa_list. The disconnect\nin xprt_rdma_destroy() runs after xprt_destroy_backchannel() has\nalready emptied bc_pa_list, so the drained reqs would otherwise\nleak. xprt_rdma_destroy() now runs xprt_rdma_bc_destroy(xprt, 0)\na second time after the disconnect to reclaim them."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in the RPC-over-RDMA client (xprtrdma); a remote NFS/RDMA peer delivers Receive completions that invoke rpcrdma_reply_handler() over InfiniBand/RoCE/iWARP, so exploitation is via network protocol traffic from a malicious or compromised server.\nAC:L - For inline Sends using only pre-registered buffers (sc_unmap_count==0), the reply path completes the RPC and returns the req to the free pool before Send completion; a remote peer can reliably trigger this by replying immediately to normal small NFS RPCs.\nPR:N - Exploitation requires no privileges on the victim host; a remote malicious or compromised NFS/RDMA server can send crafted/fast replies over the established RDMA connection to drive the vulnerable completion path.\nUI:N - No end-user interaction is needed at exploit time; once a host uses NFS-over-RDMA, triggering the bug is automatic during ordinary client I/O against the attacker-controlled server.\nS:U - The flaw causes kernel heap UAF/DMA corruption within the NFS client\u0027s kernel context and does not by itself cross hypervisor, VM, or sandbox security boundaries.\nC:H - Recycling rpcrdma_req while the HCA may still DMA-read its send buffers is a use-after-free that can expose or leak kernel memory when the slot is reallocated and buffers are reused under active DMA.\nI:H - Premature return of rpcrdma_req to rb_send_bufs while Send WRs are in flight permits heap corruption and typical UAF exploitation paths for arbitrary kernel memory writes or control-flow hijack.\nA:H - Concurrent DMA against freed/reused request buffers can provoke kernel oops/panic or wedged RPC/RDMA transport state, giving high availability impact on NFS-over-RDMA clients."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:44:39.513Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/740975054a1970c0cf15f70ac39724a064f45847"
},
{
"url": "https://git.kernel.org/stable/c/9f3d9b68c1c6c51746e5ecdb52b2e6a2901de37e"
},
{
"url": "https://git.kernel.org/stable/c/e7632089523acddcdd8f090ad19e96fb3107b04d"
},
{
"url": "https://git.kernel.org/stable/c/53442c7d0c888e51b8bc3da196970a669cc6b294"
},
{
"url": "https://git.kernel.org/stable/c/8203f760a72bd39a3b66bc4eff0aa272a99fe22b"
},
{
"url": "https://git.kernel.org/stable/c/e786233d2e0bbff9a82e43f02ae3a46ab4b08ec3"
}
],
"title": "xprtrdma: Decouple req recycling from RPC completion",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72473",
"datePublished": "2026-08-15T05:57:14.412Z",
"dateReserved": "2026-08-09T03:40:39.934Z",
"dateUpdated": "2026-08-17T05:44:39.513Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68149 (GCVE-0-2026-68149)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
The ACL_DONT_CACHE state is meant to be a constant state for the inode
for filesystems that want to opt out of posix acl caching.
Commit facd61053cff1 ("fuse: fixes after adapting to new posix acl api")
used this facility to opt out of posix acl caching for fuse inodes with
fuse server that does not negotiate FUSE_POSIX_ACL (fc->posix_acl).
The commit also takes care to gate the forget_all_cached_acls() call in
fuse_set_acl() on fc->posix_acl because there is no need for it, but
there are other placed in fuse code which call forget_all_cached_acls()
unconditional to fc->posix_acl and those cause the loss of the
ACL_DONT_CACHE state.
This is not only a functional bug. Properly timed, a get_acl() from this
fuse filesystem can return a stale cached value, as was observed in tests,
because set_acl() does not invalidate the unintentional acl cache.
We could fix this in fuse, but it actually makes no sense for the vfs
helper forget_cached_acl() to invalidate the ACL_DONT_CACHE state, so
let it not do that to fix fuse and future users of ACL_DONT_CACHE.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/posix_acl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b98fad81f1202b0eb26aacf3ff4cc7a21ed3b5bf",
"status": "affected",
"version": "facd61053cff100973921d4d45d47cf53c747ec6",
"versionType": "git"
},
{
"lessThan": "834ddf899484a2f23129080e8773bc04f4691d07",
"status": "affected",
"version": "facd61053cff100973921d4d45d47cf53c747ec6",
"versionType": "git"
},
{
"lessThan": "a019b074903b3ad0a9726087efd0e8291452023b",
"status": "affected",
"version": "facd61053cff100973921d4d45d47cf53c747ec6",
"versionType": "git"
},
{
"lessThan": "ca03a7984a34f48085fd013e0d2cf4e6420b4acf",
"status": "affected",
"version": "facd61053cff100973921d4d45d47cf53c747ec6",
"versionType": "git"
},
{
"lessThan": "4b9a5458d02e214ef2b384124ca626e3e381d778",
"status": "affected",
"version": "facd61053cff100973921d4d45d47cf53c747ec6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/posix_acl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: preserve ACL_DONT_CACHE state in forget_cached_acl()\n\nThe ACL_DONT_CACHE state is meant to be a constant state for the inode\nfor filesystems that want to opt out of posix acl caching.\n\nCommit facd61053cff1 (\"fuse: fixes after adapting to new posix acl api\")\nused this facility to opt out of posix acl caching for fuse inodes with\nfuse server that does not negotiate FUSE_POSIX_ACL (fc-\u003eposix_acl).\n\nThe commit also takes care to gate the forget_all_cached_acls() call in\nfuse_set_acl() on fc-\u003eposix_acl because there is no need for it, but\nthere are other placed in fuse code which call forget_all_cached_acls()\nunconditional to fc-\u003eposix_acl and those cause the loss of the\nACL_DONT_CACHE state.\n\nThis is not only a functional bug. Properly timed, a get_acl() from this\nfuse filesystem can return a stale cached value, as was observed in tests,\nbecause set_acl() does not invalidate the unintentional acl cache.\n\nWe could fix this in fuse, but it actually makes no sense for the vfs\nhelper forget_cached_acl() to invalidate the ACL_DONT_CACHE state, so\nlet it not do that to fix fuse and future users of ACL_DONT_CACHE."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local VFS syscalls (getxattr, statx, open, read, write) on a FUSE-backed mount; the bug is in kernel ACL caching, not in a network protocol handler.\nAC:L - The attacker controls the full trigger sequence (stat/getattr to clear ACL_DONT_CACHE, getxattr to populate cache, ACL change, then access) and can drive timing with concurrent threads without depending on uncontrollable system state.\nPR:L - Any unprivileged local user who can mount or access a FUSE filesystem (fusermount, user namespaces, virtio-fs/SSHFS mounts with allow_other) can reach the vulnerable code paths on files within that mount.\nUI:N - Exploitation is fully attacker-driven through syscall sequences on the FUSE mount; no victim click, mount action, or other interactive cooperation is required beyond routine filesystem use.\nS:C - On virtio-fs/Kata/Firecracker shared host directories, stale kernel ACL enforcement can let a guest/container process access host-exported files beyond the permissions the host administrator intended, crossing that isolation boundary.\nC:H - Stale permissive cached ACLs cause check_acl()/posix_acl_permission() to authorize reads of files that should be denied after ACL tightening, enabling unauthorized disclosure of protected file contents on default_permissions mounts.\nI:H - The same stale ACL bypass lets an attacker obtain write permission enforced by the kernel VFS on files whose ACLs were subsequently restricted, enabling unauthorized modification of protected data.\nA:N - This is a stale-cache logic bug with no memory corruption, kernel crash, panic, or hang; observed impact is incorrect ACL enforcement and authorization bypass, not availability loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:43.618Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b98fad81f1202b0eb26aacf3ff4cc7a21ed3b5bf"
},
{
"url": "https://git.kernel.org/stable/c/834ddf899484a2f23129080e8773bc04f4691d07"
},
{
"url": "https://git.kernel.org/stable/c/a019b074903b3ad0a9726087efd0e8291452023b"
},
{
"url": "https://git.kernel.org/stable/c/ca03a7984a34f48085fd013e0d2cf4e6420b4acf"
},
{
"url": "https://git.kernel.org/stable/c/4b9a5458d02e214ef2b384124ca626e3e381d778"
}
],
"title": "fs: preserve ACL_DONT_CACHE state in forget_cached_acl()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68149",
"datePublished": "2026-08-10T11:59:14.645Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-17T04:59:43.618Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68121 (GCVE-0-2026-68121)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
pppoe: reload header pointer after dev_hard_header()
pppoe_sendmsg() saves a pointer to the PPPoE header before calling
dev_hard_header(). Device header callbacks are allowed to reallocate the
skb head, invalidating pointers into it.
This can happen when a send is blocked in copy_from_user() while the first
non-Ethernet port is added to an empty team device. The team's delegated
GRE header callback then expands the skb head. PPPoE subsequently writes
six bytes through the stale pointer into the freed head.
Reload the PPPoE header through the skb's network-header offset after
device header creation. pskb_expand_head() updates that offset when it
relocates the head.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/pppoe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7a56e7c9b08e08fd55a1bcada24cf4fe3782b722",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6eed5ae7887a93160803d2b81ff88e75eefd4a4c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ba3409369c5413cdf0dcbf3a928f76b48e8c3e6a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e6493a4d1ee17595766165fa446d45b7e0c318d0",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7e9fbd7f96bcde63a7c798fe16b38cedee7a1501",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6866abf59976d273164a6624234d96a967280223",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "bed4caecd723693f750e13adbb2c42ca1249a3fd",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e9c238f6fe42fb1b4dba3a578277de32cb487937",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/pppoe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npppoe: reload header pointer after dev_hard_header()\n\npppoe_sendmsg() saves a pointer to the PPPoE header before calling\ndev_hard_header(). Device header callbacks are allowed to reallocate the\nskb head, invalidating pointers into it.\n\nThis can happen when a send is blocked in copy_from_user() while the first\nnon-Ethernet port is added to an empty team device. The team\u0027s delegated\nGRE header callback then expands the skb head. PPPoE subsequently writes\nsix bytes through the stale pointer into the freed head.\n\nReload the PPPoE header through the skb\u0027s network-header offset after\ndevice header creation. pskb_expand_head() updates that offset when it\nrelocates the head."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in pppoe_sendmsg(), reached only via the local sendmsg() syscall on a PF_PPPOX/PPPoE socket; it is not triggered by remote packet reception or in-kernel PPP transmit paths such as __pppoe_xmit().\nAC:L - Exploitation requires a race between copy_from_user() blocking in sendmsg and changing team header_ops (e.g., adding the first non-Ethernet GRE port), which an attacker can drive with concurrent threads and retries rather than uncontrollable timing.\nPR:L - PPPoE sockets can be created without special privileges, and configuring the team/GRE topology needed to trigger dev_hard_header() head expansion is achievable with CAP_NET_ADMIN inside an unprivileged user/network namespace (unshare -Urn).\nUI:N - No victim interaction is required; exploitation is fully attacker-driven through socket I/O and netlink/rtnl configuration of the team device.\nS:U - Impact is kernel heap corruption and privilege escalation within the same kernel security authority, not a cross-boundary escape such as guest-to-host VM breakout or IOMMU bypass.\nC:H - Writing PPPoE header fields through a stale pointer after pskb_expand_head() frees the old skb head is a slab use-after-free; freed kmalloc objects can be reclaimed for sensitive data, enabling arbitrary kernel memory disclosure.\nI:H - The post-dev_hard_header() memcpy/ph-\u003elength stores up to eight attacker-influenced bytes into freed skb head memory, providing a heap corruption primitive that can be developed into arbitrary kernel writes or code execution.\nA:H - Use-after-free writes into freed slab memory commonly cause kernel oops/panic and can be triggered repeatedly via sendmsg, yielding persistent denial of service even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:31.935Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7a56e7c9b08e08fd55a1bcada24cf4fe3782b722"
},
{
"url": "https://git.kernel.org/stable/c/6eed5ae7887a93160803d2b81ff88e75eefd4a4c"
},
{
"url": "https://git.kernel.org/stable/c/ba3409369c5413cdf0dcbf3a928f76b48e8c3e6a"
},
{
"url": "https://git.kernel.org/stable/c/e6493a4d1ee17595766165fa446d45b7e0c318d0"
},
{
"url": "https://git.kernel.org/stable/c/7e9fbd7f96bcde63a7c798fe16b38cedee7a1501"
},
{
"url": "https://git.kernel.org/stable/c/6866abf59976d273164a6624234d96a967280223"
},
{
"url": "https://git.kernel.org/stable/c/bed4caecd723693f750e13adbb2c42ca1249a3fd"
},
{
"url": "https://git.kernel.org/stable/c/e9c238f6fe42fb1b4dba3a578277de32cb487937"
}
],
"title": "pppoe: reload header pointer after dev_hard_header()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68121",
"datePublished": "2026-08-10T11:58:41.489Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:31.935Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63889 (GCVE-0-2026-63889)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS
frame to an lpfc or qla2xxx Linux initiator can trigger a non-return in
the generic FC transport. This is not a local userspace or IP network
path; the attacker must be able to inject fabric traffic, for example as
a compromised switch or fabric controller, or as a same-zone N_Port on a
fabric that permits source spoofing.
The Link-Integrity and Peer-Congestion FPIN walkers used a u8 loop
counter against the 32-bit on-wire pname_count field, and did not bound
pname_count by the descriptor body already validated by the TLV walker.
A pname_count of 256 therefore wraps the counter and keeps the loop
condition true indefinitely.
Factor the shared pname_list[] walk into one helper, widen the counter
to u32, and clamp pname_count against the entries that fit in the
descriptor body before iterating.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 Version: 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 Version: 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 Version: 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 Version: 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 Version: 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 Version: 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/scsi/scsi_transport_fc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "07776b7779c9426982c1ad74aad91bd531593790",
"status": "affected",
"version": "3dcfe0de5a9752e646a61f4ce513ac059960c7c3",
"versionType": "git"
},
{
"lessThan": "29f126f09e34a425b376b3646c89aa7cc18b142c",
"status": "affected",
"version": "3dcfe0de5a9752e646a61f4ce513ac059960c7c3",
"versionType": "git"
},
{
"lessThan": "163bd704d7515c3df6c2e03bcba93d1db79edbff",
"status": "affected",
"version": "3dcfe0de5a9752e646a61f4ce513ac059960c7c3",
"versionType": "git"
},
{
"lessThan": "ee57b89e5da9fffbe0d26647e4ff0750dacb9943",
"status": "affected",
"version": "3dcfe0de5a9752e646a61f4ce513ac059960c7c3",
"versionType": "git"
},
{
"lessThan": "35461d23744175a78b6280293892cca357c22793",
"status": "affected",
"version": "3dcfe0de5a9752e646a61f4ce513ac059960c7c3",
"versionType": "git"
},
{
"lessThan": "bdff76dff6ec23d6fe35812fa33e5c4ce2cdb770",
"status": "affected",
"version": "3dcfe0de5a9752e646a61f4ce513ac059960c7c3",
"versionType": "git"
},
{
"lessThan": "a9a39233ec1fc9f97ea1340a4d09bb7ec2be5153",
"status": "affected",
"version": "3dcfe0de5a9752e646a61f4ce513ac059960c7c3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/scsi/scsi_transport_fc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_transport_fc: Widen FPIN pname walker counter to u32\n\nAn adjacent Fibre Channel fabric actor that can deliver an FPIN ELS\nframe to an lpfc or qla2xxx Linux initiator can trigger a non-return in\nthe generic FC transport. This is not a local userspace or IP network\npath; the attacker must be able to inject fabric traffic, for example as\na compromised switch or fabric controller, or as a same-zone N_Port on a\nfabric that permits source spoofing.\n\nThe Link-Integrity and Peer-Congestion FPIN walkers used a u8 loop\ncounter against the 32-bit on-wire pname_count field, and did not bound\npname_count by the descriptor body already validated by the TLV walker.\nA pname_count of 256 therefore wraps the counter and keeps the loop\ncondition true indefinitely.\n\nFactor the shared pname_list[] walk into one helper, widen the counter\nto u32, and clamp pname_count against the entries that fit in the\ndescriptor body before iterating."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Exploitation requires injecting a crafted FPIN ELS frame onto the Fibre Channel fabric from an adjacent fabric actor (compromised switch, fabric controller, or same-zone N_Port), not via IP or local syscalls.\nAC:L - Once on the fabric, an attacker can reliably trigger the bug by sending an FPIN with a Link-Integrity or Peer-Congestion descriptor containing pname_count=256 and a minimally valid TLV length; no race or special memory layout is required.\nPR:N - The attacker needs no privileges on the victim Linux host; FPIN ELS frames are processed without authentication once the HBA has completed fabric discovery.\nUI:N - No victim user action is required; the malicious FPIN is processed automatically when received by the HBA firmware and driver stack.\nS:U - Impact is confined to kernel availability and information disclosure on the affected host; it does not cross a security boundary such as VM escape or sandbox breakout.\nC:H - The unbounded loop reads pname_list[i] beyond the validated descriptor body via out-of-bounds kernel memory reads on every iteration, enabling information disclosure from adjacent kernel memory.\nI:N - The bug causes only counter increments in FPIN statistics structures on matched rports; there is no memory corruption or write primitive that could modify arbitrary data or achieve code execution.\nA:H - The infinite loop pins a CPU in kernel context (potentially from interrupt/DPC paths) and repeatedly acquires host_lock via fc_find_rport_by_wwpn(), causing soft lockup and complete loss of host availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:36:58.639Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/07776b7779c9426982c1ad74aad91bd531593790"
},
{
"url": "https://git.kernel.org/stable/c/29f126f09e34a425b376b3646c89aa7cc18b142c"
},
{
"url": "https://git.kernel.org/stable/c/163bd704d7515c3df6c2e03bcba93d1db79edbff"
},
{
"url": "https://git.kernel.org/stable/c/ee57b89e5da9fffbe0d26647e4ff0750dacb9943"
},
{
"url": "https://git.kernel.org/stable/c/35461d23744175a78b6280293892cca357c22793"
},
{
"url": "https://git.kernel.org/stable/c/bdff76dff6ec23d6fe35812fa33e5c4ce2cdb770"
},
{
"url": "https://git.kernel.org/stable/c/a9a39233ec1fc9f97ea1340a4d09bb7ec2be5153"
}
],
"title": "scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63889",
"datePublished": "2026-07-19T14:55:01.515Z",
"dateReserved": "2026-07-19T07:54:57.018Z",
"dateUpdated": "2026-08-05T12:36:58.639Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64273 (GCVE-0-2026-64273)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: iforce - bound the device-reported force-feedback effect index
iforce_process_packet() handles a status report (packet id 0x02) by
taking a force-feedback effect index straight from the device wire and
using it to address the per-effect state array:
i = data[1] & 0x7f;
if (data[1] & 0x80) {
if (!test_and_set_bit(FF_CORE_IS_PLAYED,
iforce->core_effects[i].flags))
...
} else if (test_and_clear_bit(FF_CORE_IS_PLAYED,
iforce->core_effects[i].flags)) {
...
}
The index is masked only with 0x7f, so it ranges 0..127, but
core_effects[] holds only IFORCE_EFFECTS_MAX (32) entries. For an index
of 32..127 the test_and_set_bit()/test_and_clear_bit() is an
out-of-bounds single-bit read-modify-write past the array. core_effects[]
is the second-to-last member of struct iforce, so the write lands in the
trailing members and beyond the embedding kzalloc()'d iforce_serio /
iforce_usb object.
data[1] is unvalidated device payload on both transports (the USB
interrupt endpoint and serio), and the status path is not gated on force
feedback being present, so a malicious or counterfeit device can set or
clear a bit at an attacker-chosen offset past the object.
Reject an out-of-range index instead of indexing with it. Bound against
the array dimension IFORCE_EFFECTS_MAX rather than dev->ff->max_effects so
the check guarantees memory safety regardless of how many effects the
device registered. A legitimate "effect started/stopped" status always
carries an index below IFORCE_EFFECTS_MAX, so well-formed devices are
unaffected; the neighbouring mark_core_as_ready() loop is already bounded
and is left untouched.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/joystick/iforce/iforce-packets.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b1b79e89bc33e4c682d3df7ae2aadc62b5a0c310",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d10b0507fa0f5b46764b178e3271f9012f2df677",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6c0f2901c9d325d4a0574c4237fd507810d225ff",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c21295616a8a52b9a5f18cd4ca8c73030eda3d4f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e5fa31f0550b55d80045669ae9080dd5b88abffa",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "70019779325f2bb5f5a4098e91e79c655f50fcef",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a40250f97c312e000e3616c9074022311a0efbc3",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0e9943d2e4c63496b6ca84bc66fd3c71d40558e2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/joystick/iforce/iforce-packets.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: iforce - bound the device-reported force-feedback effect index\n\niforce_process_packet() handles a status report (packet id 0x02) by\ntaking a force-feedback effect index straight from the device wire and\nusing it to address the per-effect state array:\n\n\ti = data[1] \u0026 0x7f;\n\tif (data[1] \u0026 0x80) {\n\t\tif (!test_and_set_bit(FF_CORE_IS_PLAYED,\n\t\t\t\t iforce-\u003ecore_effects[i].flags))\n\t\t\t...\n\t} else if (test_and_clear_bit(FF_CORE_IS_PLAYED,\n\t\t\t\t iforce-\u003ecore_effects[i].flags)) {\n\t\t...\n\t}\n\nThe index is masked only with 0x7f, so it ranges 0..127, but\ncore_effects[] holds only IFORCE_EFFECTS_MAX (32) entries. For an index\nof 32..127 the test_and_set_bit()/test_and_clear_bit() is an\nout-of-bounds single-bit read-modify-write past the array. core_effects[]\nis the second-to-last member of struct iforce, so the write lands in the\ntrailing members and beyond the embedding kzalloc()\u0027d iforce_serio /\niforce_usb object.\n\ndata[1] is unvalidated device payload on both transports (the USB\ninterrupt endpoint and serio), and the status path is not gated on force\nfeedback being present, so a malicious or counterfeit device can set or\nclear a bit at an attacker-chosen offset past the object.\n\nReject an out-of-range index instead of indexing with it. Bound against\nthe array dimension IFORCE_EFFECTS_MAX rather than dev-\u003eff-\u003emax_effects so\nthe check guarantees memory safety regardless of how many effects the\ndevice registered. A legitimate \"effect started/stopped\" status always\ncarries an index below IFORCE_EFFECTS_MAX, so well-formed devices are\nunaffected; the neighbouring mark_core_as_ready() loop is already bounded\nand is left untouched."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:27.750Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b1b79e89bc33e4c682d3df7ae2aadc62b5a0c310"
},
{
"url": "https://git.kernel.org/stable/c/d10b0507fa0f5b46764b178e3271f9012f2df677"
},
{
"url": "https://git.kernel.org/stable/c/6c0f2901c9d325d4a0574c4237fd507810d225ff"
},
{
"url": "https://git.kernel.org/stable/c/c21295616a8a52b9a5f18cd4ca8c73030eda3d4f"
},
{
"url": "https://git.kernel.org/stable/c/e5fa31f0550b55d80045669ae9080dd5b88abffa"
},
{
"url": "https://git.kernel.org/stable/c/70019779325f2bb5f5a4098e91e79c655f50fcef"
},
{
"url": "https://git.kernel.org/stable/c/a40250f97c312e000e3616c9074022311a0efbc3"
},
{
"url": "https://git.kernel.org/stable/c/0e9943d2e4c63496b6ca84bc66fd3c71d40558e2"
}
],
"title": "Input: iforce - bound the device-reported force-feedback effect index",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64273",
"datePublished": "2026-07-25T08:49:19.416Z",
"dateReserved": "2026-07-19T15:36:31.776Z",
"dateUpdated": "2026-08-17T04:52:27.750Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72469 (GCVE-0-2026-72469)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
rpcrdma_cm_event_handler() falls through to the disconnected: label
on RDMA_CM_EVENT_ADDR_CHANGE and calls rpcrdma_ep_put() with no
matching get when the event arrives before RDMA_CM_EVENT_ESTABLISHED.
The kref then underflows during connect teardown and
rpcrdma_xprt_disconnect() operates on a freed ep.
Reference counts across a normal connection lifecycle:
rpcrdma_ep_create() kref_init ->1
rpcrdma_xprt_connect() ep_get ->2 (before post_recvs)
RDMA_CM_EVENT_ESTABLISHED ep_get ->3
RDMA_CM_EVENT_DISCONNECTED ep_put ->2
rpcrdma_xprt_drain() ep_put ->1
rpcrdma_xprt_disconnect() tail ep_put ->0 (ep_destroy)
The connect-time get in rpcrdma_xprt_connect(), taken just before
rpcrdma_post_recvs() "while there are outstanding Receives," is
balanced by rpcrdma_xprt_drain. ADDR_CHANGE before ESTABLISHED has
no get to consume, so its put drops the count to 1 and the drain
put then frees the ep while rpcrdma_xprt_disconnect() still holds a
pointer to it.
Fix by dispatching on the prior re_connect_status via xchg(): for
prev == 0 (pre-ESTABLISHED) wake the connect waiter and return with
no put; for prev == 1 call rpcrdma_force_disconnect() and return.
The case-1 arm relies on the subsequent RDMA_CM_EVENT_DISCONNECTED
event -- reliably delivered when rdma_disconnect() is called on a
still-connected cm_id -- to balance the ESTABLISHED get;
rpcrdma_xprt_drain() continues to balance only that connect-time
get. Any other prior value means teardown is already in flight.
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2acc5cae292355f5f18ad377a2a966e7f03c8fec Version: 2acc5cae292355f5f18ad377a2a966e7f03c8fec Version: 2acc5cae292355f5f18ad377a2a966e7f03c8fec Version: 2acc5cae292355f5f18ad377a2a966e7f03c8fec Version: 2fcbf07a4f23174a45e015b62a8e42ddbc2e53ef Version: 5.7.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sunrpc/xprtrdma/verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cfd1bab66b042da7a778786685125656c695931b",
"status": "affected",
"version": "2acc5cae292355f5f18ad377a2a966e7f03c8fec",
"versionType": "git"
},
{
"lessThan": "d0479c2b12974aa188b10d221a5770126b118b6d",
"status": "affected",
"version": "2acc5cae292355f5f18ad377a2a966e7f03c8fec",
"versionType": "git"
},
{
"lessThan": "ffc07790539736a5d029f6a3c966b46c529f93a8",
"status": "affected",
"version": "2acc5cae292355f5f18ad377a2a966e7f03c8fec",
"versionType": "git"
},
{
"lessThan": "af9b65b29af341932625c4283dc7a23cdb62688a",
"status": "affected",
"version": "2acc5cae292355f5f18ad377a2a966e7f03c8fec",
"versionType": "git"
},
{
"status": "affected",
"version": "2fcbf07a4f23174a45e015b62a8e42ddbc2e53ef",
"versionType": "git"
},
{
"lessThan": "5.8",
"status": "affected",
"version": "5.7.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sunrpc/xprtrdma/verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.7.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Fix ep kref imbalance on ADDR_CHANGE\n\nrpcrdma_cm_event_handler() falls through to the disconnected: label\non RDMA_CM_EVENT_ADDR_CHANGE and calls rpcrdma_ep_put() with no\nmatching get when the event arrives before RDMA_CM_EVENT_ESTABLISHED.\nThe kref then underflows during connect teardown and\nrpcrdma_xprt_disconnect() operates on a freed ep.\n\nReference counts across a normal connection lifecycle:\n\n rpcrdma_ep_create() kref_init -\u003e1\n rpcrdma_xprt_connect() ep_get -\u003e2 (before post_recvs)\n RDMA_CM_EVENT_ESTABLISHED ep_get -\u003e3\n RDMA_CM_EVENT_DISCONNECTED ep_put -\u003e2\n rpcrdma_xprt_drain() ep_put -\u003e1\n rpcrdma_xprt_disconnect() tail ep_put -\u003e0 (ep_destroy)\n\nThe connect-time get in rpcrdma_xprt_connect(), taken just before\nrpcrdma_post_recvs() \"while there are outstanding Receives,\" is\nbalanced by rpcrdma_xprt_drain. ADDR_CHANGE before ESTABLISHED has\nno get to consume, so its put drops the count to 1 and the drain\nput then frees the ep while rpcrdma_xprt_disconnect() still holds a\npointer to it.\n\nFix by dispatching on the prior re_connect_status via xchg(): for\nprev == 0 (pre-ESTABLISHED) wake the connect waiter and return with\nno put; for prev == 1 call rpcrdma_force_disconnect() and return.\nThe case-1 arm relies on the subsequent RDMA_CM_EVENT_DISCONNECTED\nevent -- reliably delivered when rdma_disconnect() is called on a\nstill-connected cm_id -- to balance the ESTABLISHED get;\nrpcrdma_xprt_drain() continues to balance only that connect-time\nget. Any other prior value means teardown is already in flight."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is in the NFS/RPC-over-RDMA client reached during RDMA CM connect/reconnect to a remote server; ADDR_CHANGE is delivered on bonded RoCE/IB netdev failover on the storage network segment, a plausible adjacent-network trigger in HPC and cloud NFS-over-RDMA deployments.\nAC:L - Once NFS-over-RDMA is in use, an attacker can reliably drive repeated reconnect attempts and time or induce bonding failover so ADDR_CHANGE arrives pre-ESTABLISHED; the resulting kref underflow and UAF are deterministic, not a probabilistic memory-layout race.\nPR:N - Exploitation requires no privileges on the victim host\u2014only that NFS-over-RDMA is configured and reconnects occur\u2014while an adjacent attacker or malicious storage peer can provoke link failover and connection churn without authenticating to the victim system.\nUI:N - No victim user interaction is required beyond normal automated NFS-over-RDMA client reconnect activity already performed by the kernel when links fail or sessions drop.\nS:U - Impact is kernel memory corruption and potential local privilege escalation within the same kernel security domain, not a cross-boundary escape such as VM guest-to-host or IOMMU bypass.\nC:H - Premature free of rpcrdma_ep leaves dangling pointers used in rpcrdma_xprt_disconnect (rdma_disconnect, ib_drain_rq/sq), a classic kernel heap UAF that can be leveraged for arbitrary memory disclosure via controlled reuse of the freed endpoint object.\nI:H - Teardown continues to operate on the freed endpoint and associated RDMA/IB state, enabling heap corruption and potential arbitrary kernel write or control-flow hijack, not merely a benign NULL dereference crash.\nA:H - The kref imbalance causes premature endpoint destruction during disconnect teardown, which can trigger kernel oops/panic from use-after-free even when exploitation for code execution is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:44:33.996Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cfd1bab66b042da7a778786685125656c695931b"
},
{
"url": "https://git.kernel.org/stable/c/d0479c2b12974aa188b10d221a5770126b118b6d"
},
{
"url": "https://git.kernel.org/stable/c/ffc07790539736a5d029f6a3c966b46c529f93a8"
},
{
"url": "https://git.kernel.org/stable/c/af9b65b29af341932625c4283dc7a23cdb62688a"
}
],
"title": "xprtrdma: Fix ep kref imbalance on ADDR_CHANGE",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72469",
"datePublished": "2026-08-15T05:57:11.829Z",
"dateReserved": "2026-08-09T03:40:39.934Z",
"dateUpdated": "2026-08-17T05:44:33.996Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43273 (GCVE-0-2026-43273)
Vulnerability from cvelistv5
Published
2026-05-06 11:28
Modified
2026-05-11 22:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ceph: supply snapshot context in ceph_zero_partial_object()
The ceph_zero_partial_object function was missing proper snapshot
context for its OSD write operations, which could lead to data
inconsistencies in snapshots.
Reproducer:
../src/vstart.sh --new -x --localhost --bluestore
./bin/ceph auth caps client.fs_a mds 'allow rwps fsname=a' mon 'allow r fsname=a' osd 'allow rw tag cephfs data=a'
mount -t ceph fs_a@.a=/ /mnt/mycephfs/ -o conf=./ceph.conf
dd if=/dev/urandom of=/mnt/mycephfs/foo bs=64K count=1
mkdir /mnt/mycephfs/.snap/snap1
md5sum /mnt/mycephfs/.snap/snap1/foo
fallocate -p -o 0 -l 4096 /mnt/mycephfs/foo
echo 3 > /proc/sys/vm/drop/caches
md5sum /mnt/mycephfs/.snap/snap1/foo # get different md5sum!!
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad7a60de882aca31afb58721db166f7e77afcd92 Version: ad7a60de882aca31afb58721db166f7e77afcd92 Version: ad7a60de882aca31afb58721db166f7e77afcd92 Version: ad7a60de882aca31afb58721db166f7e77afcd92 Version: ad7a60de882aca31afb58721db166f7e77afcd92 Version: ad7a60de882aca31afb58721db166f7e77afcd92 Version: ad7a60de882aca31afb58721db166f7e77afcd92 Version: ad7a60de882aca31afb58721db166f7e77afcd92 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ceph/file.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "36673344b41c31fb502dd0d0113cec1aa96f581e",
"status": "affected",
"version": "ad7a60de882aca31afb58721db166f7e77afcd92",
"versionType": "git"
},
{
"lessThan": "5788b742007f53406049bef917833a71ddd43f60",
"status": "affected",
"version": "ad7a60de882aca31afb58721db166f7e77afcd92",
"versionType": "git"
},
{
"lessThan": "757873abfc8ea38592582180aed0f57f0f0cb07a",
"status": "affected",
"version": "ad7a60de882aca31afb58721db166f7e77afcd92",
"versionType": "git"
},
{
"lessThan": "9efa154609cdb658f51c7d76b30a09f7e6485250",
"status": "affected",
"version": "ad7a60de882aca31afb58721db166f7e77afcd92",
"versionType": "git"
},
{
"lessThan": "531a76c5a2e44264cee8a70121e63eb28c1ba728",
"status": "affected",
"version": "ad7a60de882aca31afb58721db166f7e77afcd92",
"versionType": "git"
},
{
"lessThan": "69e59a87bab0ea31ab2a584fc65e12dafacf8953",
"status": "affected",
"version": "ad7a60de882aca31afb58721db166f7e77afcd92",
"versionType": "git"
},
{
"lessThan": "4097e70fc543cca72982854108a32f6ae924e727",
"status": "affected",
"version": "ad7a60de882aca31afb58721db166f7e77afcd92",
"versionType": "git"
},
{
"lessThan": "f16bd3fa74a2084ee7e16a8a2be7e7399b970907",
"status": "affected",
"version": "ad7a60de882aca31afb58721db166f7e77afcd92",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ceph/file.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"lessThan": "3.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.252",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.202",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.252",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.202",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: supply snapshot context in ceph_zero_partial_object()\n\nThe ceph_zero_partial_object function was missing proper snapshot\ncontext for its OSD write operations, which could lead to data\ninconsistencies in snapshots.\n\nReproducer:\n../src/vstart.sh --new -x --localhost --bluestore\n./bin/ceph auth caps client.fs_a mds \u0027allow rwps fsname=a\u0027 mon \u0027allow r fsname=a\u0027 osd \u0027allow rw tag cephfs data=a\u0027\nmount -t ceph fs_a@.a=/ /mnt/mycephfs/ -o conf=./ceph.conf\ndd if=/dev/urandom of=/mnt/mycephfs/foo bs=64K count=1\nmkdir /mnt/mycephfs/.snap/snap1\nmd5sum /mnt/mycephfs/.snap/snap1/foo\nfallocate -p -o 0 -l 4096 /mnt/mycephfs/foo\necho 3 \u003e /proc/sys/vm/drop/caches\nmd5sum /mnt/mycephfs/.snap/snap1/foo # get different md5sum!!"
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:21:22.184Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/36673344b41c31fb502dd0d0113cec1aa96f581e"
},
{
"url": "https://git.kernel.org/stable/c/5788b742007f53406049bef917833a71ddd43f60"
},
{
"url": "https://git.kernel.org/stable/c/757873abfc8ea38592582180aed0f57f0f0cb07a"
},
{
"url": "https://git.kernel.org/stable/c/9efa154609cdb658f51c7d76b30a09f7e6485250"
},
{
"url": "https://git.kernel.org/stable/c/531a76c5a2e44264cee8a70121e63eb28c1ba728"
},
{
"url": "https://git.kernel.org/stable/c/69e59a87bab0ea31ab2a584fc65e12dafacf8953"
},
{
"url": "https://git.kernel.org/stable/c/4097e70fc543cca72982854108a32f6ae924e727"
},
{
"url": "https://git.kernel.org/stable/c/f16bd3fa74a2084ee7e16a8a2be7e7399b970907"
}
],
"title": "ceph: supply snapshot context in ceph_zero_partial_object()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43273",
"datePublished": "2026-05-06T11:28:56.851Z",
"dateReserved": "2026-05-01T14:12:55.998Z",
"dateUpdated": "2026-05-11T22:21:22.184Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64494 (GCVE-0-2026-64494)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iio: light: gp2ap002: fix runtime PM leak on read error
gp2ap002_read_raw() calls pm_runtime_get_sync() before reading the
lux value, but if gp2ap002_get_lux() fails, it returns directly. This
skips the pm_runtime_put_autosuspend() call at the "out" label,
permanently leaking a runtime PM reference and preventing the device
from autosuspending.
Replace the direct return with a "goto out" to ensure the reference
is properly dropped on the error path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 Version: f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 Version: f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 Version: f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 Version: f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 Version: f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 Version: f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 Version: f6dbf83c17cb223ceabd7c42d441414f3e0e8a86 Version: f3e84bf3f86bb3b7bd50666bb8ef7a203a656ca3 Version: 5.7.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iio/light/gp2ap002.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "62e0d74821a02f0e0c5c79b99ae64dc83a9a90f5",
"status": "affected",
"version": "f6dbf83c17cb223ceabd7c42d441414f3e0e8a86",
"versionType": "git"
},
{
"lessThan": "7110201c6b21455240c63388f30113f3baafacfc",
"status": "affected",
"version": "f6dbf83c17cb223ceabd7c42d441414f3e0e8a86",
"versionType": "git"
},
{
"lessThan": "2593f0c6ea37df168975694a3b17e7086f11453e",
"status": "affected",
"version": "f6dbf83c17cb223ceabd7c42d441414f3e0e8a86",
"versionType": "git"
},
{
"lessThan": "f350883989ced96d6da7f582f9a6f9c6ffc94e34",
"status": "affected",
"version": "f6dbf83c17cb223ceabd7c42d441414f3e0e8a86",
"versionType": "git"
},
{
"lessThan": "29137052c4485c74bc2d1b0717f69ca4de14274f",
"status": "affected",
"version": "f6dbf83c17cb223ceabd7c42d441414f3e0e8a86",
"versionType": "git"
},
{
"lessThan": "0c655d067ac69ee24e2e9d706c54179ea58a43db",
"status": "affected",
"version": "f6dbf83c17cb223ceabd7c42d441414f3e0e8a86",
"versionType": "git"
},
{
"lessThan": "2ebaea7f3089decb01a8294d89d7e0cf288146c4",
"status": "affected",
"version": "f6dbf83c17cb223ceabd7c42d441414f3e0e8a86",
"versionType": "git"
},
{
"lessThan": "38b72267b7e22768a1f26d9935de4e1752a1dc85",
"status": "affected",
"version": "f6dbf83c17cb223ceabd7c42d441414f3e0e8a86",
"versionType": "git"
},
{
"status": "affected",
"version": "f3e84bf3f86bb3b7bd50666bb8ef7a203a656ca3",
"versionType": "git"
},
{
"lessThan": "5.8",
"status": "affected",
"version": "5.7.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iio/light/gp2ap002.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.7.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: light: gp2ap002: fix runtime PM leak on read error\n\ngp2ap002_read_raw() calls pm_runtime_get_sync() before reading the\nlux value, but if gp2ap002_get_lux() fails, it returns directly. This\nskips the pm_runtime_put_autosuspend() call at the \"out\" label,\npermanently leaking a runtime PM reference and preventing the device\nfrom autosuspending.\n\nReplace the direct return with a \"goto out\" to ensure the reference\nis properly dropped on the error path."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:42.612Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/62e0d74821a02f0e0c5c79b99ae64dc83a9a90f5"
},
{
"url": "https://git.kernel.org/stable/c/7110201c6b21455240c63388f30113f3baafacfc"
},
{
"url": "https://git.kernel.org/stable/c/2593f0c6ea37df168975694a3b17e7086f11453e"
},
{
"url": "https://git.kernel.org/stable/c/f350883989ced96d6da7f582f9a6f9c6ffc94e34"
},
{
"url": "https://git.kernel.org/stable/c/29137052c4485c74bc2d1b0717f69ca4de14274f"
},
{
"url": "https://git.kernel.org/stable/c/0c655d067ac69ee24e2e9d706c54179ea58a43db"
},
{
"url": "https://git.kernel.org/stable/c/2ebaea7f3089decb01a8294d89d7e0cf288146c4"
},
{
"url": "https://git.kernel.org/stable/c/38b72267b7e22768a1f26d9935de4e1752a1dc85"
}
],
"title": "iio: light: gp2ap002: fix runtime PM leak on read error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64494",
"datePublished": "2026-07-25T08:51:51.747Z",
"dateReserved": "2026-07-19T15:36:31.792Z",
"dateUpdated": "2026-08-17T04:56:42.612Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64378 (GCVE-0-2026-64378)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
When a container exits, the following BUG_ON() is occasionally triggered:
==================================================================
VFS: Busy inodes after unmount of sdb (ext4)
------------[ cut here ]------------
kernel BUG at fs/super.c:695!
CPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1
pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
pc : generic_shutdown_super+0xf0/0x100
lr : generic_shutdown_super+0xf0/0x100
Call trace:
generic_shutdown_super+0xf0/0x100
kill_block_super+0x20/0x48
ext4_kill_sb+0x28/0x60
deactivate_locked_super+0x54/0x130
deactivate_super+0x84/0xa0
cleanup_mnt+0xa4/0x140
__cleanup_mnt+0x18/0x28
task_work_run+0x78/0xe0
do_notify_resume+0x204/0x240
==================================================================
The root cause is a race between cgroup_writeback_umount() and
inode_switch_wbs()/cleanup_offline_cgwb(). There is a window between
inode_prepare_wbs_switch() returning true and the subsequent
wb_queue_isw() call. Following is the process that triggers the issue:
CPU A (umount) | CPU B (writeback)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
inode_switch_wbs/cleanup_offline_cgwb
atomic_inc(&isw_nr_in_flight)
inode_prepare_wbs_switch
-> passes SB_ACTIVE check
__iget(inode)
generic_shutdown_super
sb->s_flags &= ~SB_ACTIVE
cgroup_writeback_umount(sb)
smp_mb()
atomic_read(&isw_nr_in_flight)
rcu_barrier()
-> no pending RCU callbacks
flush_workqueue(isw_wq)
-> nothing queued, returns
evict_inodes(sb)
-> Inode skipped as isw still holds a ref.
sop->put_super(sb)
/* destroys percpu counters */
-> VFS: Busy inodes after unmount!
wb_queue_isw()
queue_work(isw_wq, ...)
/* later in work function */
inode_switch_wbs_work_fn
process_inode_switch_wbs
iput() -> evict
percpu_counter_dec() // UAF!
Fix this by extending the RCU read-side critical section in
inode_switch_wbs() and cleanup_offline_cgwb() to cover from
inode_prepare_wbs_switch() through wb_queue_isw(). Since there is
no sleep in this window, rcu_read_lock() can be used. Then add a
synchronize_rcu() in cgroup_writeback_umount() before the existing
rcu_barrier(), so that all in-flight switchers that have passed the
SB_ACTIVE check have completed queue_work() before flush_workqueue()
is called.
The existing rcu_barrier() is intentionally retained so this fix can
be backported unchanged to stable kernels (5.10.y, 6.6.y, ...) that
still queue switches via queue_rcu_work(). It is a no-op on current
mainline (since commit e1b849cfa6b6 ("writeback: Avoid contention on
wb->list_lock when switching inodes")) and is removed in a follow-up
patch.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a1a0e23e49037c23ea84bc8cc146a03584d13577 Version: a1a0e23e49037c23ea84bc8cc146a03584d13577 Version: a1a0e23e49037c23ea84bc8cc146a03584d13577 Version: a1a0e23e49037c23ea84bc8cc146a03584d13577 Version: a1a0e23e49037c23ea84bc8cc146a03584d13577 Version: a1a0e23e49037c23ea84bc8cc146a03584d13577 Version: a1a0e23e49037c23ea84bc8cc146a03584d13577 Version: c5cbbec54fe71c4de2d34f8c0ec8fbfdd7f17339 Version: 4.4.5 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/fs-writeback.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "087d5b8b501c570f84bf655164e6698c3ce146e0",
"status": "affected",
"version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
"versionType": "git"
},
{
"lessThan": "3c9c9648f77e4d14e50676bc51c2174ba9c8d361",
"status": "affected",
"version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
"versionType": "git"
},
{
"lessThan": "5c3265f3252b2ee50707adaaa3f9bd0df3df72de",
"status": "affected",
"version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
"versionType": "git"
},
{
"lessThan": "c923cc3cb5cd8945ceaf08252754110643446593",
"status": "affected",
"version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
"versionType": "git"
},
{
"lessThan": "685fc15a410885b6d4dee64de0dce721b9428b12",
"status": "affected",
"version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
"versionType": "git"
},
{
"lessThan": "53eeaf4d63068dbc7708b0c7adb20151c812feca",
"status": "affected",
"version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
"versionType": "git"
},
{
"lessThan": "cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d",
"status": "affected",
"version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
"versionType": "git"
},
{
"status": "affected",
"version": "c5cbbec54fe71c4de2d34f8c0ec8fbfdd7f17339",
"versionType": "git"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.5",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/fs-writeback.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()\n\nWhen a container exits, the following BUG_ON() is occasionally triggered:\n\n==================================================================\n VFS: Busy inodes after unmount of sdb (ext4)\n ------------[ cut here ]------------\n kernel BUG at fs/super.c:695!\n CPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1\n pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : generic_shutdown_super+0xf0/0x100\n lr : generic_shutdown_super+0xf0/0x100\n Call trace:\n generic_shutdown_super+0xf0/0x100\n kill_block_super+0x20/0x48\n ext4_kill_sb+0x28/0x60\n deactivate_locked_super+0x54/0x130\n deactivate_super+0x84/0xa0\n cleanup_mnt+0xa4/0x140\n __cleanup_mnt+0x18/0x28\n task_work_run+0x78/0xe0\n do_notify_resume+0x204/0x240\n==================================================================\n\nThe root cause is a race between cgroup_writeback_umount() and\ninode_switch_wbs()/cleanup_offline_cgwb(). There is a window between\ninode_prepare_wbs_switch() returning true and the subsequent\nwb_queue_isw() call. Following is the process that triggers the issue:\n\n CPU A (umount) | CPU B (writeback)\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n inode_switch_wbs/cleanup_offline_cgwb\n atomic_inc(\u0026isw_nr_in_flight)\n inode_prepare_wbs_switch\n -\u003e passes SB_ACTIVE check\n __iget(inode)\n generic_shutdown_super\n sb-\u003es_flags \u0026= ~SB_ACTIVE\n cgroup_writeback_umount(sb)\n smp_mb()\n atomic_read(\u0026isw_nr_in_flight)\n rcu_barrier()\n -\u003e no pending RCU callbacks\n flush_workqueue(isw_wq)\n -\u003e nothing queued, returns\n evict_inodes(sb)\n -\u003e Inode skipped as isw still holds a ref.\n sop-\u003eput_super(sb)\n /* destroys percpu counters */\n -\u003e VFS: Busy inodes after unmount!\n wb_queue_isw()\n queue_work(isw_wq, ...)\n /* later in work function */\n inode_switch_wbs_work_fn\n process_inode_switch_wbs\n iput() -\u003e evict\n percpu_counter_dec() // UAF!\n\nFix this by extending the RCU read-side critical section in\ninode_switch_wbs() and cleanup_offline_cgwb() to cover from\ninode_prepare_wbs_switch() through wb_queue_isw(). Since there is\nno sleep in this window, rcu_read_lock() can be used. Then add a\nsynchronize_rcu() in cgroup_writeback_umount() before the existing\nrcu_barrier(), so that all in-flight switchers that have passed the\nSB_ACTIVE check have completed queue_work() before flush_workqueue()\nis called.\n\nThe existing rcu_barrier() is intentionally retained so this fix can\nbe backported unchanged to stable kernels (5.10.y, 6.6.y, ...) that\nstill queue switches via queue_rcu_work(). It is a no-op on current\nmainline (since commit e1b849cfa6b6 (\"writeback: Avoid contention on\nwb-\u003elist_lock when switching inodes\")) and is removed in a follow-up\npatch."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is reached through local filesystem writes, cgroup teardown, and mount-namespace or filesystem unmount paths; no network protocol directly reaches the race.\nAC:L - An attacker can churn cgroup writeback switches while repeatedly triggering container or mount teardown, controlling both racing activities and amplifying the timing window.\nPR:L - A basic local or container user can dirty writable files and initiate its own cgroup or namespace teardown; lifecycle infrastructure can perform the privileged final unmount automatically.\nUI:N - The attacker can generate the writeback state and trigger teardown without requiring another user to perform an action.\nS:U - The resulting corruption affects the same host kernel security authority and does not inherently cross a VM or hardware isolation boundary.\nC:H - The delayed worker can access superblock-private state after it and its per-CPU counters have been freed, creating an exploitable use-after-free capable of exposing arbitrary kernel memory.\nI:H - The freed superblock and per-CPU counter pointers are subsequently dereferenced and modified, potentially providing attacker-influenced kernel writes and control-flow hijacking.\nA:H - The race demonstrably triggers the busy-inode BUG_ON, and configurations continuing past that check encounter a use-after-free capable of causing an oops or kernel panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:29.511Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/087d5b8b501c570f84bf655164e6698c3ce146e0"
},
{
"url": "https://git.kernel.org/stable/c/3c9c9648f77e4d14e50676bc51c2174ba9c8d361"
},
{
"url": "https://git.kernel.org/stable/c/5c3265f3252b2ee50707adaaa3f9bd0df3df72de"
},
{
"url": "https://git.kernel.org/stable/c/c923cc3cb5cd8945ceaf08252754110643446593"
},
{
"url": "https://git.kernel.org/stable/c/685fc15a410885b6d4dee64de0dce721b9428b12"
},
{
"url": "https://git.kernel.org/stable/c/53eeaf4d63068dbc7708b0c7adb20151c812feca"
},
{
"url": "https://git.kernel.org/stable/c/cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d"
}
],
"title": "writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64378",
"datePublished": "2026-07-25T08:50:29.006Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-08-17T04:54:29.511Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64246 (GCVE-0-2026-64246)
Vulnerability from cvelistv5
Published
2026-07-24 15:31
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
Move of_node_put(dn) after the of_match_node() call, which still needs
the node pointer. The node reference is correctly released after use.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e2f471efe1d607a7aff38ce53ec717cebe4283d6 Version: e2f471efe1d607a7aff38ce53ec717cebe4283d6 Version: e2f471efe1d607a7aff38ce53ec717cebe4283d6 Version: e2f471efe1d607a7aff38ce53ec717cebe4283d6 Version: e2f471efe1d607a7aff38ce53ec717cebe4283d6 Version: e2f471efe1d607a7aff38ce53ec717cebe4283d6 Version: e2f471efe1d607a7aff38ce53ec717cebe4283d6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/power/reset/linkstation-poweroff.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "93c7ee139721936b6fa717572e74d3994603ae13",
"status": "affected",
"version": "e2f471efe1d607a7aff38ce53ec717cebe4283d6",
"versionType": "git"
},
{
"lessThan": "cdda7d384c05485a232ae9a849f6445accb095bf",
"status": "affected",
"version": "e2f471efe1d607a7aff38ce53ec717cebe4283d6",
"versionType": "git"
},
{
"lessThan": "c04d606f8b35ee7d3ed243f63893a607e9d6c0bc",
"status": "affected",
"version": "e2f471efe1d607a7aff38ce53ec717cebe4283d6",
"versionType": "git"
},
{
"lessThan": "3928ae803dee044b01076c478c279c0bd54164cd",
"status": "affected",
"version": "e2f471efe1d607a7aff38ce53ec717cebe4283d6",
"versionType": "git"
},
{
"lessThan": "2205275be9be981e70ff29610b0117d8853fac70",
"status": "affected",
"version": "e2f471efe1d607a7aff38ce53ec717cebe4283d6",
"versionType": "git"
},
{
"lessThan": "d109e72f3fbccb540473285d17d7519584f7f76e",
"status": "affected",
"version": "e2f471efe1d607a7aff38ce53ec717cebe4283d6",
"versionType": "git"
},
{
"lessThan": "8eec545cde69e46e9a1d2b7d915ce4f5df85b3bd",
"status": "affected",
"version": "e2f471efe1d607a7aff38ce53ec717cebe4283d6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/power/reset/linkstation-poweroff.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()\n\nMove of_node_put(dn) after the of_match_node() call, which still needs\nthe node pointer. The node reference is correctly released after use."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:57.403Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/93c7ee139721936b6fa717572e74d3994603ae13"
},
{
"url": "https://git.kernel.org/stable/c/cdda7d384c05485a232ae9a849f6445accb095bf"
},
{
"url": "https://git.kernel.org/stable/c/c04d606f8b35ee7d3ed243f63893a607e9d6c0bc"
},
{
"url": "https://git.kernel.org/stable/c/3928ae803dee044b01076c478c279c0bd54164cd"
},
{
"url": "https://git.kernel.org/stable/c/2205275be9be981e70ff29610b0117d8853fac70"
},
{
"url": "https://git.kernel.org/stable/c/d109e72f3fbccb540473285d17d7519584f7f76e"
},
{
"url": "https://git.kernel.org/stable/c/8eec545cde69e46e9a1d2b7d915ce4f5df85b3bd"
}
],
"title": "power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64246",
"datePublished": "2026-07-24T15:31:14.709Z",
"dateReserved": "2026-07-19T15:36:31.772Z",
"dateUpdated": "2026-08-17T04:51:57.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64385 (GCVE-0-2026-64385)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_ioctl() replay
A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_ioctl_init() fails before the next send, cleanup
retains the previous buffer type and frees that response again.
Reset response bookkeeping before each attempt to prevent the stale free.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 433042a91f9373241307725b52de573933ffedbf Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 6.6.32 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0be4bc64882edaefaaee8d1e27d083643eb778e6",
"status": "affected",
"version": "433042a91f9373241307725b52de573933ffedbf",
"versionType": "git"
},
{
"lessThan": "96fcfc8ae7359346156e492ca610e830d2649ad6",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "276c8efbc49f9303ac76d0d4deab7128581b0f3b",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "fc65ffb4ef1bf540da16b17c225ae51091e07d72",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "f9bbadb6c94583e3b4af1afc449bfceb1d1ddec9",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.32",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double-free in SMB2_ioctl() replay\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_ioctl_init() fails before the next send, cleanup\nretains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - An attacker-controlled SMB server can deliver crafted SMB2 IOCTL responses over TCP, including through the kernel\u0027s periodic interface-query FSCTL on an existing SMB3 mount.\nAC:L - On a hard or retrans-enabled mount, the server controls replayable statuses, response contents, disconnects, reconnects, and repeated attempts, allowing it to drive both sides of the triggering sequence.\nPR:N - The malicious SMB server needs no account or privilege on the target; victim mounting authority and client authentication do not grant or require attacker-side target privileges.\nUI:N - Once the share is mounted, kernel delayed work can automatically issue the affected FSCTL when the server advertises multichannel support, requiring no user action during exploitation.\nS:U - The memory corruption compromises resources governed by the same host-kernel security authority and does not inherently cross a VM, container, or IOMMU boundary.\nC:H - The response-buffer double-free can corrupt SLUB or mempool state and create dangling or overlapping live buffers, enabling use-after-free exploitation and kernel-memory disclosure.\nI:H - Attacker-controlled network data can overwrite aliased or freed buffers and poison allocator state, supporting arbitrary writes and control-flow hijacking.\nA:H - The duplicate free can trigger an allocator BUG or corrupt kernel heap state, causing an oops, panic, or complete system crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:37.258Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0be4bc64882edaefaaee8d1e27d083643eb778e6"
},
{
"url": "https://git.kernel.org/stable/c/96fcfc8ae7359346156e492ca610e830d2649ad6"
},
{
"url": "https://git.kernel.org/stable/c/276c8efbc49f9303ac76d0d4deab7128581b0f3b"
},
{
"url": "https://git.kernel.org/stable/c/fc65ffb4ef1bf540da16b17c225ae51091e07d72"
},
{
"url": "https://git.kernel.org/stable/c/f9bbadb6c94583e3b4af1afc449bfceb1d1ddec9"
}
],
"title": "smb: client: fix double-free in SMB2_ioctl() replay",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64385",
"datePublished": "2026-07-25T08:50:33.997Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-08-17T04:54:37.258Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64244 (GCVE-0-2026-64244)
Vulnerability from cvelistv5
Published
2026-07-24 15:29
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drivers/base/memory: set mem->altmap after successful device registration
If __add_memory_block() fails at xa_store() (under memory pressure for
example), device_unregister() is called, which eventually triggers
memory_block_release() with mem->altmap still set, causing a
WARN_ON(mem->altmap). This was triggered by modifying virtio-mem driver.
Fix this by delaying the assignment of mem->altmap until after
__add_memory_block() has succeeded.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1a8c64e110435e44e71bcd50a75663174b575f22 Version: 1a8c64e110435e44e71bcd50a75663174b575f22 Version: 1a8c64e110435e44e71bcd50a75663174b575f22 Version: 1a8c64e110435e44e71bcd50a75663174b575f22 Version: 1a8c64e110435e44e71bcd50a75663174b575f22 Version: 1a8c64e110435e44e71bcd50a75663174b575f22 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/base/memory.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "802e113cf120df7208e4c7e604950a85e87120a8",
"status": "affected",
"version": "1a8c64e110435e44e71bcd50a75663174b575f22",
"versionType": "git"
},
{
"lessThan": "22dc0d042f02ce82aa61422ea5f232628bfd9e9c",
"status": "affected",
"version": "1a8c64e110435e44e71bcd50a75663174b575f22",
"versionType": "git"
},
{
"lessThan": "6c25bf4e44a2b6a14332f952bba0974521f5b72d",
"status": "affected",
"version": "1a8c64e110435e44e71bcd50a75663174b575f22",
"versionType": "git"
},
{
"lessThan": "bc3dd82a0ffd488bb902f4c69c3d28fd4088d973",
"status": "affected",
"version": "1a8c64e110435e44e71bcd50a75663174b575f22",
"versionType": "git"
},
{
"lessThan": "059ac6252a63edf1cea79bf30bd860a8c264b62c",
"status": "affected",
"version": "1a8c64e110435e44e71bcd50a75663174b575f22",
"versionType": "git"
},
{
"lessThan": "a2b8d7827f48ee54a686cb80e4a1d0ff954ec42a",
"status": "affected",
"version": "1a8c64e110435e44e71bcd50a75663174b575f22",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/base/memory.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.37",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.37",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.14",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.2",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/base/memory: set mem-\u003ealtmap after successful device registration\n\nIf __add_memory_block() fails at xa_store() (under memory pressure for\nexample), device_unregister() is called, which eventually triggers\nmemory_block_release() with mem-\u003ealtmap still set, causing a\nWARN_ON(mem-\u003ealtmap). This was triggered by modifying virtio-mem driver.\n\nFix this by delaying the assignment of mem-\u003ealtmap until after\n__add_memory_block() has succeeded."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:55.230Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/802e113cf120df7208e4c7e604950a85e87120a8"
},
{
"url": "https://git.kernel.org/stable/c/22dc0d042f02ce82aa61422ea5f232628bfd9e9c"
},
{
"url": "https://git.kernel.org/stable/c/6c25bf4e44a2b6a14332f952bba0974521f5b72d"
},
{
"url": "https://git.kernel.org/stable/c/bc3dd82a0ffd488bb902f4c69c3d28fd4088d973"
},
{
"url": "https://git.kernel.org/stable/c/059ac6252a63edf1cea79bf30bd860a8c264b62c"
},
{
"url": "https://git.kernel.org/stable/c/a2b8d7827f48ee54a686cb80e4a1d0ff954ec42a"
}
],
"title": "drivers/base/memory: set mem-\u003ealtmap after successful device registration",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64244",
"datePublished": "2026-07-24T15:29:59.891Z",
"dateReserved": "2026-07-19T15:36:31.772Z",
"dateUpdated": "2026-08-17T04:51:55.230Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53111 (GCVE-0-2026-53111)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-06-24 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap
The bpf_lwt_xmit_push_encap helper needs to access skb_dst(skb)->dev to
calculate the needed headroom:
err = skb_cow_head(skb,
len + LL_RESERVED_SPACE(skb_dst(skb)->dev));
But skb->_skb_refdst may not be initialized when the skb is set up by
bpf_prog_test_run_skb function. Executing bpf_lwt_push_ip_encap function
in this scenario will trigger null pointer dereference, causing a kernel
crash as Yinhao reported:
[ 105.186365] BUG: kernel NULL pointer dereference, address: 0000000000000000
[ 105.186382] #PF: supervisor read access in kernel mode
[ 105.186388] #PF: error_code(0x0000) - not-present page
[ 105.186393] PGD 121d3d067 P4D 121d3d067 PUD 106c83067 PMD 0
[ 105.186404] Oops: 0000 [#1] PREEMPT SMP NOPTI
[ 105.186412] CPU: 3 PID: 3250 Comm: poc Kdump: loaded Not tainted 6.19.0-rc5 #1
[ 105.186423] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 105.186427] RIP: 0010:bpf_lwt_push_ip_encap+0x1eb/0x520
[ 105.186443] Code: 0f 84 de 01 00 00 0f b7 4a 04 66 85 c9 0f 85 47 01 00 00 31 c0 5b 5d 41 5c 41 5d 41 5e c3 cc cc cc cc 48 8b 73 58 48 83 e6 fe <48> 8b 36 0f b7 be ec 00 00 00 0f b7 b6 e6 00 00 00 01 fe 83 e6 f0
[ 105.186449] RSP: 0018:ffffbb0e0387bc50 EFLAGS: 00010246
[ 105.186455] RAX: 000000000000004e RBX: ffff94c74e036500 RCX: ffff94c74874da00
[ 105.186460] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff94c74e036500
[ 105.186463] RBP: 0000000000000001 R08: 0000000000000002 R09: 0000000000000000
[ 105.186467] R10: ffffbb0e0387bd50 R11: 0000000000000000 R12: ffffbb0e0387bc98
[ 105.186471] R13: 0000000000000014 R14: 0000000000000000 R15: 0000000000000002
[ 105.186484] FS: 00007f166aa4d680(0000) GS:ffff94c8b7780000(0000) knlGS:0000000000000000
[ 105.186490] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 105.186494] CR2: 0000000000000000 CR3: 000000015eade001 CR4: 0000000000770ee0
[ 105.186499] PKRU: 55555554
[ 105.186502] Call Trace:
[ 105.186507] <TASK>
[ 105.186513] bpf_lwt_xmit_push_encap+0x2b/0x40
[ 105.186522] bpf_prog_a75eaad51e517912+0x41/0x49
[ 105.186536] ? kvm_clock_get_cycles+0x18/0x30
[ 105.186547] ? ktime_get+0x3c/0xa0
[ 105.186554] bpf_test_run+0x195/0x320
[ 105.186563] ? bpf_test_run+0x10f/0x320
[ 105.186579] bpf_prog_test_run_skb+0x2f5/0x4f0
[ 105.186590] __sys_bpf+0x69c/0xa40
[ 105.186603] __x64_sys_bpf+0x1e/0x30
[ 105.186611] do_syscall_64+0x59/0x110
[ 105.186620] entry_SYSCALL_64_after_hwframe+0x76/0xe0
[ 105.186649] RIP: 0033:0x7f166a97455d
Temporarily add the setting of skb->_skb_refdst before bpf_test_run to resolve the issue.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 52f278774e796a553be0c869dcaaee6f259ca795 Version: 52f278774e796a553be0c869dcaaee6f259ca795 Version: 52f278774e796a553be0c869dcaaee6f259ca795 Version: 52f278774e796a553be0c869dcaaee6f259ca795 Version: 52f278774e796a553be0c869dcaaee6f259ca795 Version: 52f278774e796a553be0c869dcaaee6f259ca795 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bpf/test_run.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5c8d1f91fc4898d79f29d79c1a6f7c2b3ee66fb0",
"status": "affected",
"version": "52f278774e796a553be0c869dcaaee6f259ca795",
"versionType": "git"
},
{
"lessThan": "c7ad31fb948fdd4905263f4324160682c3fa7bc6",
"status": "affected",
"version": "52f278774e796a553be0c869dcaaee6f259ca795",
"versionType": "git"
},
{
"lessThan": "599905c3f10bb83e6e6881d5a7f5cea5df07dc23",
"status": "affected",
"version": "52f278774e796a553be0c869dcaaee6f259ca795",
"versionType": "git"
},
{
"lessThan": "5500913516e071dbe23e5a404c861dd2d82c9589",
"status": "affected",
"version": "52f278774e796a553be0c869dcaaee6f259ca795",
"versionType": "git"
},
{
"lessThan": "94f95328b9070909b5b875c647b17a11d3d85567",
"status": "affected",
"version": "52f278774e796a553be0c869dcaaee6f259ca795",
"versionType": "git"
},
{
"lessThan": "972787479ee73006fddb5e59ab5c8e733810ff42",
"status": "affected",
"version": "52f278774e796a553be0c869dcaaee6f259ca795",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bpf/test_run.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap\n\nThe bpf_lwt_xmit_push_encap helper needs to access skb_dst(skb)-\u003edev to\ncalculate the needed headroom:\n\n\terr = skb_cow_head(skb,\n\t\t\t len + LL_RESERVED_SPACE(skb_dst(skb)-\u003edev));\n\nBut skb-\u003e_skb_refdst may not be initialized when the skb is set up by\nbpf_prog_test_run_skb function. Executing bpf_lwt_push_ip_encap function\nin this scenario will trigger null pointer dereference, causing a kernel\ncrash as Yinhao reported:\n\n[ 105.186365] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 105.186382] #PF: supervisor read access in kernel mode\n[ 105.186388] #PF: error_code(0x0000) - not-present page\n[ 105.186393] PGD 121d3d067 P4D 121d3d067 PUD 106c83067 PMD 0\n[ 105.186404] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[ 105.186412] CPU: 3 PID: 3250 Comm: poc Kdump: loaded Not tainted 6.19.0-rc5 #1\n[ 105.186423] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[ 105.186427] RIP: 0010:bpf_lwt_push_ip_encap+0x1eb/0x520\n[ 105.186443] Code: 0f 84 de 01 00 00 0f b7 4a 04 66 85 c9 0f 85 47 01 00 00 31 c0 5b 5d 41 5c 41 5d 41 5e c3 cc cc cc cc 48 8b 73 58 48 83 e6 fe \u003c48\u003e 8b 36 0f b7 be ec 00 00 00 0f b7 b6 e6 00 00 00 01 fe 83 e6 f0\n[ 105.186449] RSP: 0018:ffffbb0e0387bc50 EFLAGS: 00010246\n[ 105.186455] RAX: 000000000000004e RBX: ffff94c74e036500 RCX: ffff94c74874da00\n[ 105.186460] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff94c74e036500\n[ 105.186463] RBP: 0000000000000001 R08: 0000000000000002 R09: 0000000000000000\n[ 105.186467] R10: ffffbb0e0387bd50 R11: 0000000000000000 R12: ffffbb0e0387bc98\n[ 105.186471] R13: 0000000000000014 R14: 0000000000000000 R15: 0000000000000002\n[ 105.186484] FS: 00007f166aa4d680(0000) GS:ffff94c8b7780000(0000) knlGS:0000000000000000\n[ 105.186490] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 105.186494] CR2: 0000000000000000 CR3: 000000015eade001 CR4: 0000000000770ee0\n[ 105.186499] PKRU: 55555554\n[ 105.186502] Call Trace:\n[ 105.186507] \u003cTASK\u003e\n[ 105.186513] bpf_lwt_xmit_push_encap+0x2b/0x40\n[ 105.186522] bpf_prog_a75eaad51e517912+0x41/0x49\n[ 105.186536] ? kvm_clock_get_cycles+0x18/0x30\n[ 105.186547] ? ktime_get+0x3c/0xa0\n[ 105.186554] bpf_test_run+0x195/0x320\n[ 105.186563] ? bpf_test_run+0x10f/0x320\n[ 105.186579] bpf_prog_test_run_skb+0x2f5/0x4f0\n[ 105.186590] __sys_bpf+0x69c/0xa40\n[ 105.186603] __x64_sys_bpf+0x1e/0x30\n[ 105.186611] do_syscall_64+0x59/0x110\n[ 105.186620] entry_SYSCALL_64_after_hwframe+0x76/0xe0\n[ 105.186649] RIP: 0033:0x7f166a97455d\n\nTemporarily add the setting of skb-\u003e_skb_refdst before bpf_test_run to resolve the issue."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-24T16:30:44.691Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5c8d1f91fc4898d79f29d79c1a6f7c2b3ee66fb0"
},
{
"url": "https://git.kernel.org/stable/c/c7ad31fb948fdd4905263f4324160682c3fa7bc6"
},
{
"url": "https://git.kernel.org/stable/c/599905c3f10bb83e6e6881d5a7f5cea5df07dc23"
},
{
"url": "https://git.kernel.org/stable/c/5500913516e071dbe23e5a404c861dd2d82c9589"
},
{
"url": "https://git.kernel.org/stable/c/94f95328b9070909b5b875c647b17a11d3d85567"
},
{
"url": "https://git.kernel.org/stable/c/972787479ee73006fddb5e59ab5c8e733810ff42"
}
],
"title": "bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53111",
"datePublished": "2026-06-24T16:30:44.691Z",
"dateReserved": "2026-06-09T07:44:35.385Z",
"dateUpdated": "2026-06-24T16:30:44.691Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64545 (GCVE-0-2026-64545)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net, bpf: check master for NULL in xdp_master_redirect()
xdp_master_redirect() dereferences the result of
netdev_master_upper_dev_get_rcu() without a NULL check, but that helper
returns NULL when the receiving device has no upper-master adjacency.
The reach guard only checks netif_is_bond_slave(). On bond slave release
bond_upper_dev_unlink() drops the upper-master adjacency before clearing
IFF_SLAVE, so an XDP_TX reaching xdp_master_redirect() in that window
still passes netif_is_bond_slave() while master is already NULL, and
faults on master->flags at offset 0xb0:
BUG: kernel NULL pointer dereference, address: 00000000000000b0
RIP: 0010:xdp_master_redirect (net/core/filter.c:4432)
Call Trace:
xdp_master_redirect (net/core/filter.c:4432)
bpf_prog_run_generic_xdp (include/net/xdp.h:700)
do_xdp_generic (net/core/dev.c:5608)
__netif_receive_skb_one_core (net/core/dev.c:6204)
process_backlog (net/core/dev.c:6319)
__napi_poll (net/core/dev.c:7729)
net_rx_action (net/core/dev.c:7792)
handle_softirqs (kernel/softirq.c:622)
__dev_queue_xmit (include/linux/bottom_half.h:33)
packet_sendmsg (net/packet/af_packet.c:3082)
__sys_sendto (net/socket.c:2252)
Kernel panic - not syncing: Fatal exception in interrupt
The missing check dates back to the original code; commit 1921f91298d1
("net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master")
later added the master->flags read where the fault now lands but kept the
unconditional deref. Check master for NULL before use; a NULL master is
treated the same as one that is not up.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7 Version: 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7 Version: 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7 Version: 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7 Version: 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7 Version: 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7 Version: 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:42.721Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c99ca049e910d61ddbd28cc2c47242f2bfbb4970",
"status": "affected",
"version": "879af96ffd72706c6e3278ea6b45b0b0e37ec5d7",
"versionType": "git"
},
{
"lessThan": "e2a56441233131fe18a76001de347ecda217e40c",
"status": "affected",
"version": "879af96ffd72706c6e3278ea6b45b0b0e37ec5d7",
"versionType": "git"
},
{
"lessThan": "3876318ea54e83eb70982b8280a3c5e4e32269bf",
"status": "affected",
"version": "879af96ffd72706c6e3278ea6b45b0b0e37ec5d7",
"versionType": "git"
},
{
"lessThan": "4edbcacca09f92b85d3951b6add11894b20a84bc",
"status": "affected",
"version": "879af96ffd72706c6e3278ea6b45b0b0e37ec5d7",
"versionType": "git"
},
{
"lessThan": "03b743586a2469744e96e9c1015096d07240935d",
"status": "affected",
"version": "879af96ffd72706c6e3278ea6b45b0b0e37ec5d7",
"versionType": "git"
},
{
"lessThan": "89c103d702b25ceb2d097faf854deb47b53b17ff",
"status": "affected",
"version": "879af96ffd72706c6e3278ea6b45b0b0e37ec5d7",
"versionType": "git"
},
{
"lessThan": "e82d8cc4321c373dc46e741cd2dfdaa7921fddb7",
"status": "affected",
"version": "879af96ffd72706c6e3278ea6b45b0b0e37ec5d7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet, bpf: check master for NULL in xdp_master_redirect()\n\nxdp_master_redirect() dereferences the result of\nnetdev_master_upper_dev_get_rcu() without a NULL check, but that helper\nreturns NULL when the receiving device has no upper-master adjacency.\n\nThe reach guard only checks netif_is_bond_slave(). On bond slave release\nbond_upper_dev_unlink() drops the upper-master adjacency before clearing\nIFF_SLAVE, so an XDP_TX reaching xdp_master_redirect() in that window\nstill passes netif_is_bond_slave() while master is already NULL, and\nfaults on master-\u003eflags at offset 0xb0:\n\n BUG: kernel NULL pointer dereference, address: 00000000000000b0\n RIP: 0010:xdp_master_redirect (net/core/filter.c:4432)\n Call Trace:\n xdp_master_redirect (net/core/filter.c:4432)\n bpf_prog_run_generic_xdp (include/net/xdp.h:700)\n do_xdp_generic (net/core/dev.c:5608)\n __netif_receive_skb_one_core (net/core/dev.c:6204)\n process_backlog (net/core/dev.c:6319)\n __napi_poll (net/core/dev.c:7729)\n net_rx_action (net/core/dev.c:7792)\n handle_softirqs (kernel/softirq.c:622)\n __dev_queue_xmit (include/linux/bottom_half.h:33)\n packet_sendmsg (net/packet/af_packet.c:3082)\n __sys_sendto (net/socket.c:2252)\n Kernel panic - not syncing: Fatal exception in interrupt\n\nThe missing check dates back to the original code; commit 1921f91298d1\n(\"net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master\")\nlater added the master-\u003eflags read where the fault now lands but kept the\nunconditional deref. Check master for NULL before use; a NULL master is\ntreated the same as one that is not up."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The faulting path is the XDP receive hook \u2014 packets arriving on a bond slave drive `bpf_prog_run_xdp`/`do_xdp_generic` \u2192 `xdp_master_redirect()`, so a remote attacker sending traffic to a bonded interface running an XDP_TX program (XDP load balancers/DDoS scrubbers on bonded uplinks are a mainstream deployment) supplies the triggering packets with no local access.\nAC:L - The attacker controls the packet side of the race and can sustain line-rate traffic so the multi-microsecond window between adjacency teardown and `IFF_SLAVE` clearing is hit essentially deterministically; where the attacker also holds the network configuration side (container/netns with bond and XDP control) both sides of the race are attacker-driven, which the kernel guidance classes as Low.\nPR:N - No credentials or authentication are needed to send frames to a bonded interface, and the fault occurs in softirq during receive processing before any socket, filesystem, or user-level authorization is consulted \u2014 matching the PR:N treatment of the sibling fix CVE-2026-53069 in this same function.\nUI:N - No victim action is required; the slave-release window is reached by routine and externally-induced events (bond reconfiguration, `bond_enslave` rollback, NIC hotplug/`NETDEV_UNREGISTER`), and the attacker need only keep traffic flowing.\nS:U - The NULL dereference and its consequences are confined to the kernel\u0027s own security authority; no hypervisor, IOMMU, or sandbox boundary is crossed.\nC:N - The bug is a read of `master-\u003eflags` at fixed offset 0xb0 from a NULL pointer, which faults immediately; no memory contents are returned to the attacker and no kernel addresses are disclosed.\nI:N - There is no write primitive \u2014 the defect is a read-side dereference that faults before `master-\u003enetdev_ops-\u003endo_xdp_get_xmit_slave()` is reached, so no kernel data or control flow is modified.\nA:H - The dereference happens in softirq/interrupt context, producing \"Kernel panic - not syncing: Fatal exception in interrupt\" \u2014 a complete system crash rather than a recoverable oops, and it can be re-triggered on every reboot as long as traffic and bond reconfiguration continue."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:22.161Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c99ca049e910d61ddbd28cc2c47242f2bfbb4970"
},
{
"url": "https://git.kernel.org/stable/c/e2a56441233131fe18a76001de347ecda217e40c"
},
{
"url": "https://git.kernel.org/stable/c/3876318ea54e83eb70982b8280a3c5e4e32269bf"
},
{
"url": "https://git.kernel.org/stable/c/4edbcacca09f92b85d3951b6add11894b20a84bc"
},
{
"url": "https://git.kernel.org/stable/c/03b743586a2469744e96e9c1015096d07240935d"
},
{
"url": "https://git.kernel.org/stable/c/89c103d702b25ceb2d097faf854deb47b53b17ff"
},
{
"url": "https://git.kernel.org/stable/c/e82d8cc4321c373dc46e741cd2dfdaa7921fddb7"
}
],
"title": "net, bpf: check master for NULL in xdp_master_redirect()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64545",
"datePublished": "2026-07-27T20:10:36.659Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-09-08T08:50:42.721Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46127 (GCVE-0-2026-46127)
Vulnerability from cvelistv5
Published
2026-05-28 09:35
Modified
2026-06-14 17:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()
Sashiko points out that pd->uctx isn't initialized until late in the
function so all these error flow references are NULL and will crash. Use
the uctx that isn't NULL.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fe2caefcdf5869f308c102e3d64d40683bfad711 Version: fe2caefcdf5869f308c102e3d64d40683bfad711 Version: fe2caefcdf5869f308c102e3d64d40683bfad711 Version: fe2caefcdf5869f308c102e3d64d40683bfad711 Version: fe2caefcdf5869f308c102e3d64d40683bfad711 Version: fe2caefcdf5869f308c102e3d64d40683bfad711 Version: fe2caefcdf5869f308c102e3d64d40683bfad711 Version: fe2caefcdf5869f308c102e3d64d40683bfad711 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/ocrdma/ocrdma_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b610f33c5523fe26f6dd897667fff9c7a1de5905",
"status": "affected",
"version": "fe2caefcdf5869f308c102e3d64d40683bfad711",
"versionType": "git"
},
{
"lessThan": "443c991fbc954cc9363e963c09f404b9f281f3a2",
"status": "affected",
"version": "fe2caefcdf5869f308c102e3d64d40683bfad711",
"versionType": "git"
},
{
"lessThan": "27b6eb1f27fda9bdd5cae028e396758cdf525845",
"status": "affected",
"version": "fe2caefcdf5869f308c102e3d64d40683bfad711",
"versionType": "git"
},
{
"lessThan": "e01a957561f663d3b68d2fd233a4502e3367efcd",
"status": "affected",
"version": "fe2caefcdf5869f308c102e3d64d40683bfad711",
"versionType": "git"
},
{
"lessThan": "75fc130664ae324e7b2f9ad3630e0f175e9ca6c8",
"status": "affected",
"version": "fe2caefcdf5869f308c102e3d64d40683bfad711",
"versionType": "git"
},
{
"lessThan": "8832626a483439e207734e027afff322ccdf726e",
"status": "affected",
"version": "fe2caefcdf5869f308c102e3d64d40683bfad711",
"versionType": "git"
},
{
"lessThan": "ec44c00a4fe1327efa35083f98b39c01cb535a51",
"status": "affected",
"version": "fe2caefcdf5869f308c102e3d64d40683bfad711",
"versionType": "git"
},
{
"lessThan": "34fbf48cf3b410d2a6e8c586fa952a36331ca5ba",
"status": "affected",
"version": "fe2caefcdf5869f308c102e3d64d40683bfad711",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/ocrdma/ocrdma_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.88",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.30",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.88",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.30",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ocrdma: Don\u0027t NULL deref uctx on errors in ocrdma_copy_pd_uresp()\n\nSashiko points out that pd-\u003euctx isn\u0027t initialized until late in the\nfunction so all these error flow references are NULL and will crash. Use\nthe uctx that isn\u0027t NULL."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-14T17:56:27.705Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b610f33c5523fe26f6dd897667fff9c7a1de5905"
},
{
"url": "https://git.kernel.org/stable/c/443c991fbc954cc9363e963c09f404b9f281f3a2"
},
{
"url": "https://git.kernel.org/stable/c/27b6eb1f27fda9bdd5cae028e396758cdf525845"
},
{
"url": "https://git.kernel.org/stable/c/e01a957561f663d3b68d2fd233a4502e3367efcd"
},
{
"url": "https://git.kernel.org/stable/c/75fc130664ae324e7b2f9ad3630e0f175e9ca6c8"
},
{
"url": "https://git.kernel.org/stable/c/8832626a483439e207734e027afff322ccdf726e"
},
{
"url": "https://git.kernel.org/stable/c/ec44c00a4fe1327efa35083f98b39c01cb535a51"
},
{
"url": "https://git.kernel.org/stable/c/34fbf48cf3b410d2a6e8c586fa952a36331ca5ba"
}
],
"title": "RDMA/ocrdma: Don\u0027t NULL deref uctx on errors in ocrdma_copy_pd_uresp()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46127",
"datePublished": "2026-05-28T09:35:42.368Z",
"dateReserved": "2026-05-13T15:03:33.099Z",
"dateUpdated": "2026-06-14T17:56:27.705Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68363 (GCVE-0-2026-68363)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
ath9k_hif_request_firmware() re-arms an asynchronous firmware load via
request_firmware_nowait(), passing hif_dev as the completion context, and
then still dereferences hif_dev:
dev_info(&hif_dev->udev->dev, "ath9k_htc: Firmware %s requested\n",
hif_dev->fw_name);
The re-armed callback ath9k_hif_usb_firmware_cb() runs on the "events"
workqueue and, when the firmware is missing, walks the retry chain into
ath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That
releases the wait_for_completion(&hif_dev->fw_done) in a concurrent
ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing
dev_info() in the frame that re-armed the request can therefore read freed
memory (hif_dev->udev, the first field of struct hif_device_usb):
BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware
Read of size 8 ... by task kworker/...
ath9k_hif_request_firmware
ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247
request_firmware_work_func
Allocated by ...:
ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c
Freed by ...:
ath9k_hif_usb_disconnect -> kfree drivers/net/wireless/ath/ath9k/hif_usb.c
The fw_done barrier only makes disconnect wait for the firmware chain to
*terminate*; it does not protect the outer ath9k_hif_request_firmware()
frame that re-armed the request and keeps touching hif_dev afterwards.
Drop the post-request dev_info(): it is the only use of hif_dev after the
async request is armed, and it is purely informational (the dev_err() on the
failure path runs only when request_firmware_nowait() did not arm a callback,
so hif_dev is still alive there).
This was first reported by syzbot as a single, non-reproduced crash that was
later auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,
which produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc
device whose firmware download fails). The vulnerable code is unchanged and
still present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN
once the (sub-microsecond) race window is widened.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath9k/hif_usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "47ed81aaa7f94d9808f4719e78a760c2ec1e6c86",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "48de0c6952192b0771fca468df4364d11ec74ad9",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "063497cc9f320ab71a7a937c3bc0a23e630aefe2",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "7f184ca38a90889f3f6665ff96748b95da39dbee",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "10b0ce629123a3737b4eda50188f73bb7be7b68b",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "48a69cedde7388294e4ea6fd804156cd62bc04fc",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "dad9f96945d77ecd4708f730c06ef54dcd8cc057",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath9k/hif_usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.4"
},
{
"lessThan": "4.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: hif_usb: don\u0027t dereference hif_dev after re-arming firmware request\n\nath9k_hif_request_firmware() re-arms an asynchronous firmware load via\nrequest_firmware_nowait(), passing hif_dev as the completion context, and\nthen still dereferences hif_dev:\n\n\tdev_info(\u0026hif_dev-\u003eudev-\u003edev, \"ath9k_htc: Firmware %s requested\\n\",\n\t\t hif_dev-\u003efw_name);\n\nThe re-armed callback ath9k_hif_usb_firmware_cb() runs on the \"events\"\nworkqueue and, when the firmware is missing, walks the retry chain into\nath9k_hif_usb_firmware_fail() -\u003e complete_all(\u0026hif_dev-\u003efw_done). That\nreleases the wait_for_completion(\u0026hif_dev-\u003efw_done) in a concurrent\nath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing\ndev_info() in the frame that re-armed the request can therefore read freed\nmemory (hif_dev-\u003eudev, the first field of struct hif_device_usb):\n\n BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware\n Read of size 8 ... by task kworker/...\n ath9k_hif_request_firmware\n ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247\n request_firmware_work_func\n Allocated by ...:\n ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c\n Freed by ...:\n ath9k_hif_usb_disconnect -\u003e kfree drivers/net/wireless/ath/ath9k/hif_usb.c\n\nThe fw_done barrier only makes disconnect wait for the firmware chain to\n*terminate*; it does not protect the outer ath9k_hif_request_firmware()\nframe that re-armed the request and keeps touching hif_dev afterwards.\n\nDrop the post-request dev_info(): it is the only use of hif_dev after the\nasync request is armed, and it is purely informational (the dev_err() on the\nfailure path runs only when request_firmware_nowait() did not arm a callback,\nso hif_dev is still alive there).\n\nThis was first reported by syzbot as a single, non-reproduced crash that was\nlater auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,\nwhich produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc\ndevice whose firmware download fails). The vulnerable code is unchanged and\nstill present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN\nonce the (sub-microsecond) race window is widened."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:18.694Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/47ed81aaa7f94d9808f4719e78a760c2ec1e6c86"
},
{
"url": "https://git.kernel.org/stable/c/48de0c6952192b0771fca468df4364d11ec74ad9"
},
{
"url": "https://git.kernel.org/stable/c/063497cc9f320ab71a7a937c3bc0a23e630aefe2"
},
{
"url": "https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee"
},
{
"url": "https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b"
},
{
"url": "https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc"
},
{
"url": "https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a"
},
{
"url": "https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057"
}
],
"title": "wifi: ath9k: hif_usb: don\u0027t dereference hif_dev after re-arming firmware request",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68363",
"datePublished": "2026-08-10T12:03:40.355Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:18.694Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40204 (GCVE-0-2025-40204)
Vulnerability from cvelistv5
Published
2025-11-12 21:56
Modified
2026-08-05 12:08
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: Fix MAC comparison to be constant-time
To prevent timing attacks, MACs need to be compared in constant time.
Use the appropriate helper function for this.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c",
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b93fa8dc521d00d2d44bf034fb90e0d79b036617",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0e8b8c326c2a6de4d837b1bb034ea704f4690d77",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1cd60e0d0fb8f0e62ec4499138afce6342dc9d4c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9c05d44ec24126fc283835b68f82dba3ae985209",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ed3044b9c810c5c24eb2830053fbfe5fd134c5d4",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "8019b3699289fce3f10b63f98601db97b8d105b0",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0b32ff285ff6f6f1ac1d9495787ccce8837d6405",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "dd91c79e4f58fbe2898dac84858033700e0e99fb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c",
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.301",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.246",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.195",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.157",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.113",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.54",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.301",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.246",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.195",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.157",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.113",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.54",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.4",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: Fix MAC comparison to be constant-time\n\nTo prevent timing attacks, MACs need to be compared in constant time.\nUse the appropriate helper function for this."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Both vulnerable comparisons process data from remote SCTP peers \u2014 COOKIE ECHO chunks in `sctp_sf_do_5_1D_ce()`/`sctp_unpack_cookie()` and AUTH chunks in `sctp_sf_authenticate()` \u2014 delivered over IPv4/IPv6 from any routable host. No local access or network adjacency is required.\nAC:H - Exploitation requires statistically extracting nanosecond-scale timing deltas from the early-exit `memcmp` across network jitter and target CPU load, and on 64-bit architectures with `HAVE_EFFICIENT_UNALIGNED_ACCESS` the loop leaks only 8-byte-granular prefixes \u2014 conditions the attacker cannot influence. The bad-signature path is a silent `sctp_sf_pdiscard()`, so no direct request/response oracle exists.\nPR:N - The COOKIE ECHO path is reached pre-authentication on any listening SCTP socket, with the attacker supplying both the cookie contents and the matching verification tag, so no credentials or prior association state are needed. Cookie HMAC signing is enabled by default via `CONFIG_SCTP_DEFAULT_COOKIE_HMAC_MD5`.\nUI:N - The vulnerable comparisons execute automatically in the SCTP receive path for every COOKIE ECHO or AUTH chunk that reaches a listening endpoint or established association. No action by any local user or administrator is involved.\nS:U - The forged-MAC consequences \u2014 spoofed association establishment, out-of-bounds reads, and softirq hangs \u2014 all occur inside the kernel of the targeted host. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - A forged cookie MAC yields a fully attacker-controlled `struct sctp_cookie` whose unvalidated `raw_addr_list_len` drives an unbounded walk in `sctp_raw_to_bind_addrs()`, reading far past the skb. A forged SCTP-AUTH HMAC additionally allows ASCONF Add-IP injection to redirect an established association\u0027s data stream to the attacker.\nI:H - Recovering the MAC constitutes a complete bypass of SCTP\u0027s state-cookie and SCTP-AUTH authentication, letting an off-path attacker forge cookies to establish spoofed associations and inject arbitrary authenticated chunks into existing ones. The attacker-controlled cookie is copied wholesale into the new association via `memcpy(\u0026retval-\u003ec, bear_cookie, ...)` and fed to `sctp_process_init()`.\nA:H - With the cookie MAC forged, `sctp_raw_to_bind_addrs()` at this commit has no bounds checks \u2014 a zero-length address parameter makes `addrs_len -= len` never progress, producing an infinite loop in softirq context, while an oversized length causes an OOB read that can oops the kernel. Forged AUTH chunks also permit tearing down established associations."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:08:33.114Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b93fa8dc521d00d2d44bf034fb90e0d79b036617"
},
{
"url": "https://git.kernel.org/stable/c/0e8b8c326c2a6de4d837b1bb034ea704f4690d77"
},
{
"url": "https://git.kernel.org/stable/c/1cd60e0d0fb8f0e62ec4499138afce6342dc9d4c"
},
{
"url": "https://git.kernel.org/stable/c/9c05d44ec24126fc283835b68f82dba3ae985209"
},
{
"url": "https://git.kernel.org/stable/c/ed3044b9c810c5c24eb2830053fbfe5fd134c5d4"
},
{
"url": "https://git.kernel.org/stable/c/8019b3699289fce3f10b63f98601db97b8d105b0"
},
{
"url": "https://git.kernel.org/stable/c/0b32ff285ff6f6f1ac1d9495787ccce8837d6405"
},
{
"url": "https://git.kernel.org/stable/c/dd91c79e4f58fbe2898dac84858033700e0e99fb"
}
],
"title": "sctp: Fix MAC comparison to be constant-time",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40204",
"datePublished": "2025-11-12T21:56:35.110Z",
"dateReserved": "2025-04-16T07:20:57.179Z",
"dateUpdated": "2026-08-05T12:08:33.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46195 (GCVE-0-2026-46195)
Vulnerability from cvelistv5
Published
2026-05-28 09:36
Modified
2026-09-11 12:09
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: validate dacloffset before building DACL pointers
parse_sec_desc(), build_sec_desc(), and the chown path in
id_mode_to_cifs_acl() all add the server-supplied dacloffset to pntsd
before proving a DACL header fits inside the returned security
descriptor.
On 32-bit builds a malicious server can return dacloffset near
U32_MAX, wrap the derived DACL pointer below end_of_acl, and then slip
past the later pointer-based bounds checks. build_sec_desc() and
id_mode_to_cifs_acl() can then dereference DACL fields from the wrapped
pointer in the chmod/chown rewrite paths.
Validate dacloffset numerically before building any DACL pointer and
reuse the same helper at the three DACL entry points.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 Version: bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 Version: bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 Version: bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 Version: bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 Version: bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 Version: bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:8::nfv"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.126.1.rt7.467.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.126.1.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:9",
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-687.12.1.el9_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-05-28T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel\u0027s Server Message Block (SMB) client. A malicious server can exploit this vulnerability on 32-bit systems by providing a crafted dacloffset value. This can cause a pointer wrap, leading to the dereferencing of invalid Discretionary Access Control List (DACL) fields during chmod or chown operations. This memory corruption could potentially allow the malicious server to bypass security mechanisms or cause a denial of service."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Important"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-787",
"description": "Out-of-bounds Write",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T12:09:11.879Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-46195"
},
{
"name": "RHBZ#2482606",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482606"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46195.json"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:21556"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:21706"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:21745"
}
],
"solutions": [
{
"lang": "en",
"value": "RHSA-2026:21556: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9)"
},
{
"lang": "en",
"value": "RHSA-2026:21706: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:21745: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8)"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-05-28T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-05-28T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: smb: client: validate dacloffset before building DACL pointers",
"workarounds": [
{
"lang": "en",
"value": "To mitigate this issue, avoid mounting shares from untrusted SMB servers on 32-bit Red Hat Enterprise Linux systems. If interaction with untrusted SMB servers is unavoidable, consider isolating affected systems or restricting network access to only known, trusted SMB servers."
}
],
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/cifsacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5de2665e913a10ad70aaeecf736b97276e83d995",
"status": "affected",
"version": "bc3e9dd9d104ca1b75644eab87b38ce8a924aef4",
"versionType": "git"
},
{
"lessThan": "f9dc3be8f403c1216df73e57221f44b045e7ee0b",
"status": "affected",
"version": "bc3e9dd9d104ca1b75644eab87b38ce8a924aef4",
"versionType": "git"
},
{
"lessThan": "ba7f71b6161c0943dafc367565e5843d16b7d505",
"status": "affected",
"version": "bc3e9dd9d104ca1b75644eab87b38ce8a924aef4",
"versionType": "git"
},
{
"lessThan": "3b1ddba19e77ee35241cd27f16dc3e8d14e08db7",
"status": "affected",
"version": "bc3e9dd9d104ca1b75644eab87b38ce8a924aef4",
"versionType": "git"
},
{
"lessThan": "c688f3ed73d31943334ad2139cb02ec49664322a",
"status": "affected",
"version": "bc3e9dd9d104ca1b75644eab87b38ce8a924aef4",
"versionType": "git"
},
{
"lessThan": "8bd07e417b6bda67e317920584e48cb6ee442a8a",
"status": "affected",
"version": "bc3e9dd9d104ca1b75644eab87b38ce8a924aef4",
"versionType": "git"
},
{
"lessThan": "f98b48151cc502ada59d9778f0112d21f2586ca3",
"status": "affected",
"version": "bc3e9dd9d104ca1b75644eab87b38ce8a924aef4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/cifsacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.88",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.30",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.88",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.30",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate dacloffset before building DACL pointers\n\nparse_sec_desc(), build_sec_desc(), and the chown path in\nid_mode_to_cifs_acl() all add the server-supplied dacloffset to pntsd\nbefore proving a DACL header fits inside the returned security\ndescriptor.\n\nOn 32-bit builds a malicious server can return dacloffset near\nU32_MAX, wrap the derived DACL pointer below end_of_acl, and then slip\npast the later pointer-based bounds checks. build_sec_desc() and\nid_mode_to_cifs_acl() can then dereference DACL fields from the wrapped\npointer in the chmod/chown rewrite paths.\n\nValidate dacloffset numerically before building any DACL pointer and\nreuse the same helper at the three DACL entry points."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The malicious data is the SMB server\u0027s security-descriptor response processed by the in-kernel CIFS client over TCP/445; a remote server (or MITM) supplies the crafted dacloffset, so the vulnerable code is reached purely via network protocol data.\nAC:L - On a 32-bit target the attacker fully controls dacloffset and thus the wrapped pointer target, reliably bypassing the bounds checks and reliably forcing a dereference (e.g. unmapped memory for a guaranteed crash); no condition outside attacker control is needed once the target is the affected architecture.\nPR:N - The attacker is the SMB server itself (or a MITM) and needs no account or privilege on the victim client; the client parses the malicious response automatically.\nUI:N - Under the reasonable compromised-server/MITM model the parse path fires during routine file access (stat/ls) on an already-mounted share, requiring no victim action at attack time.\nS:U - The corruption stays within the kernel\u0027s own memory and security authority; no crossing into another security scope (VM/IOMMU) occurs.\nC:H - The attacker-controlled wrapped pointer is an arbitrary-address read primitive; the read kernel memory influences file mode bits (observable) and is copied into the ACL returned to the server, providing a genuine disclosure channel.\nI:H - This is server-controlled memory corruption: OOB-read DACL/ACE data with attacker-influenced sizes/counts is copied into a fixed-size heap buffer in the chmod path, giving a plausible OOB-write primitive, consistent with treating memory corruption as high integrity impact.\nA:H - Dereferencing the attacker-positioned wrapped pointer (typically unmapped memory) reliably triggers a kernel oops/panic, a full denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:30:20.801Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5de2665e913a10ad70aaeecf736b97276e83d995"
},
{
"url": "https://git.kernel.org/stable/c/f9dc3be8f403c1216df73e57221f44b045e7ee0b"
},
{
"url": "https://git.kernel.org/stable/c/ba7f71b6161c0943dafc367565e5843d16b7d505"
},
{
"url": "https://git.kernel.org/stable/c/3b1ddba19e77ee35241cd27f16dc3e8d14e08db7"
},
{
"url": "https://git.kernel.org/stable/c/c688f3ed73d31943334ad2139cb02ec49664322a"
},
{
"url": "https://git.kernel.org/stable/c/8bd07e417b6bda67e317920584e48cb6ee442a8a"
},
{
"url": "https://git.kernel.org/stable/c/f98b48151cc502ada59d9778f0112d21f2586ca3"
}
],
"title": "smb: client: validate dacloffset before building DACL pointers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46195",
"datePublished": "2026-05-28T09:36:48.259Z",
"dateReserved": "2026-05-13T15:03:33.104Z",
"dateUpdated": "2026-09-11T12:09:11.879Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74482 (GCVE-0-2026-74482)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
__folio_split() keeps dereferencing the mapping after the split:
shmem_uncharge(mapping->host) and remap_page() while the folios are still
frozen/locked, and i_mmap_unlock_read(mapping) at the very end, after the
after-split folios have been unlocked and freed.
Nothing holds an inode reference across that. The split relies on @folio
-- which the beyond-EOF drop loop never removes, as it starts at
folio_next(folio) -- staying locked and in the page cache to hold off
eviction. But the unlock loop unlocks @folio before i_mmap_unlock_read()
runs. If the caller's @lock_at is a tail beyond EOF, as memory_failure()
passes when splitting a poisoned tail of a shmem THP that reaches past
i_size during truncation, it too is gone from the page cache; so once
@folio is unlocked no locked, in-cache folio pins the inode, and a
concurrent final iput() can evict and RCU-free it before
i_mmap_unlock_read() touches i_mmap_rwsem:
BUG: KASAN: slab-use-after-free in __up_read+0x634/0x790
i_mmap_unlock_read include/linux/fs.h:537 [inline]
__folio_split+0x732/0x1640 mm/huge_memory.c:4100
try_to_split_thp_page+0xab/0x390 mm/memory-failure.c:1675
memory_failure+0x1394/0x26e0 mm/memory-failure.c:2470
Freed by task 4601:
shmem_free_in_core_inode+0x54/0xb0 mm/shmem.c:5177
evict+0x57f/0xac0 fs/inode.c:870
Do every mapping dereference while @folio still pins the inode: drop
i_mmap_rwsem right after remap_page(), before the loop that unlocks and
frees the after-split folios, and clear @mapping so the exit path does not
unlock it again. shmem_uncharge() and remap_page() already run before
that point, so after this nothing past the unlock loop touches the inode
or the mapping.
This is now a rule the split depends on, alongside keeping @folio frozen
until the page cache is updated: no inode or mapping dereference once the
after-split folios start being unlocked.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/huge_memory.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bc2f5eabaaf60ec18da70b619a8fba1bfb7dea3a",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "f87c08060818ebb19bafed37c38244538da25097",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "6f5c272d71845a669e4c8ee5c72b376e29a0e6e5",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "be106f7855f03d3128ed0ce70ba74b484a90b473",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "e3dd774dbfd0b5bc2dbd0995221751b1234f8205",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "10065fb891651d9541e7a5a2db84c1e656ece4f9",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "d640efe94d86d3be893d4c19220362546a637e90",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "e923bd21058ea02fd0dcd3549d151d143fd036e5",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/huge_memory.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios\n\n__folio_split() keeps dereferencing the mapping after the split:\nshmem_uncharge(mapping-\u003ehost) and remap_page() while the folios are still\nfrozen/locked, and i_mmap_unlock_read(mapping) at the very end, after the\nafter-split folios have been unlocked and freed.\n\nNothing holds an inode reference across that. The split relies on @folio\n-- which the beyond-EOF drop loop never removes, as it starts at\nfolio_next(folio) -- staying locked and in the page cache to hold off\neviction. But the unlock loop unlocks @folio before i_mmap_unlock_read()\nruns. If the caller\u0027s @lock_at is a tail beyond EOF, as memory_failure()\npasses when splitting a poisoned tail of a shmem THP that reaches past\ni_size during truncation, it too is gone from the page cache; so once\n@folio is unlocked no locked, in-cache folio pins the inode, and a\nconcurrent final iput() can evict and RCU-free it before\ni_mmap_unlock_read() touches i_mmap_rwsem:\n\n BUG: KASAN: slab-use-after-free in __up_read+0x634/0x790\n i_mmap_unlock_read include/linux/fs.h:537 [inline]\n __folio_split+0x732/0x1640 mm/huge_memory.c:4100\n try_to_split_thp_page+0xab/0x390 mm/memory-failure.c:1675\n memory_failure+0x1394/0x26e0 mm/memory-failure.c:2470\n\n Freed by task 4601:\n shmem_free_in_core_inode+0x54/0xb0 mm/shmem.c:5177\n evict+0x57f/0xac0 fs/inode.c:870\n\nDo every mapping dereference while @folio still pins the inode: drop\ni_mmap_rwsem right after remap_page(), before the loop that unlocks and\nfrees the after-split folios, and clear @mapping so the exit path does not\nunlock it again. shmem_uncharge() and remap_page() already run before\nthat point, so after this nothing past the unlock loop touches the inode\nor the mapping.\n\nThis is now a rule the split depends on, alongside keeping @folio frozen\nuntil the page cache is updated: no inode or mapping dereference once the\nafter-split folios start being unlocked."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is in __folio_split() on the memory_failure()-\u003etry_to_split_thp_page() path while splitting file-backed shmem THPs; reachability is via local syscalls (memfd/mmap/madvise/ftruncate) or admin hwpoison injection, not network or physical interfaces.\nAC:L - An attacker can deterministically create a shmem THP with tail pages beyond EOF and race MADV_HWPOISON-driven memory_failure() against concurrent truncate/close(iput) using attacker-controlled threads; both sides of the race are attacker-driven.\nPR:L - Reliable exploitation uses MADV_HWPOISON to invoke memory_failure() on a chosen tail page; CAP_SYS_ADMIN is available to user-namespace/container root, and the shmem THP setup needs only ordinary local mapping and truncation privileges.\nUI:N - No separate victim action is required; the attacker creates, maps, poisons, and truncates their own memfd/shmem/tmpfs object to reach the vulnerable split path.\nS:U - Impact is a kernel slab use-after-free on inode/mapping metadata in core MM within the same kernel security domain, not a VM escape, sandbox breakout, or other cross-authority boundary violation.\nC:H - KASAN reports slab-use-after-free in i_mmap_unlock_read() after shmem_free_in_core_inode() RCU-frees the inode; this inode/mapping UAF can be heap-sprayed into an arbitrary kernel memory read primitive.\nI:H - The same UAF corrupts freed inode slab objects and i_mmap_rwsem state, enabling heap grooming for arbitrary kernel writes and potential privilege escalation via control-flow hijacking per kernel UAF guidance.\nA:H - The use-after-free provokes a KASAN BUG/oops during i_mmap_unlock_read() and corrupts core MM inode state, capable of kernel panic or hang when triggered on production shmem/tmpfs workloads."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:38.544Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bc2f5eabaaf60ec18da70b619a8fba1bfb7dea3a"
},
{
"url": "https://git.kernel.org/stable/c/f87c08060818ebb19bafed37c38244538da25097"
},
{
"url": "https://git.kernel.org/stable/c/6f5c272d71845a669e4c8ee5c72b376e29a0e6e5"
},
{
"url": "https://git.kernel.org/stable/c/be106f7855f03d3128ed0ce70ba74b484a90b473"
},
{
"url": "https://git.kernel.org/stable/c/e3dd774dbfd0b5bc2dbd0995221751b1234f8205"
},
{
"url": "https://git.kernel.org/stable/c/10065fb891651d9541e7a5a2db84c1e656ece4f9"
},
{
"url": "https://git.kernel.org/stable/c/d640efe94d86d3be893d4c19220362546a637e90"
},
{
"url": "https://git.kernel.org/stable/c/e923bd21058ea02fd0dcd3549d151d143fd036e5"
}
],
"title": "mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74482",
"datePublished": "2026-08-15T12:27:15.083Z",
"dateReserved": "2026-08-15T05:44:03.904Z",
"dateUpdated": "2026-08-19T16:37:38.544Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63997 (GCVE-0-2026-63997)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-07-19 14:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ethtool: module: avoid leaking a netdev ref on module flash errors
module_flash_fw_schedule() is missing undo for setting
the "in_progress" flag and taking the netdev reference.
Delay taking these, the device can't disappear while
we are holding rtnl_lock.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ethtool/module.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f7b4513e77f9571dc1041a798b93b5c4a4bfc191",
"status": "affected",
"version": "32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e",
"versionType": "git"
},
{
"lessThan": "61848c83b9132ab839809fe415ba7802a0aca4f6",
"status": "affected",
"version": "32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e",
"versionType": "git"
},
{
"lessThan": "956b134d917fd7e014dc7e39a9b7610c04fcc9ba",
"status": "affected",
"version": "32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e",
"versionType": "git"
},
{
"lessThan": "fb7f511d62692661846c47f199e0afe25c2982db",
"status": "affected",
"version": "32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ethtool/module.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: module: avoid leaking a netdev ref on module flash errors\n\nmodule_flash_fw_schedule() is missing undo for setting\nthe \"in_progress\" flag and taking the netdev reference.\nDelay taking these, the device can\u0027t disappear while\nwe are holding rtnl_lock."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:56:15.965Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f7b4513e77f9571dc1041a798b93b5c4a4bfc191"
},
{
"url": "https://git.kernel.org/stable/c/61848c83b9132ab839809fe415ba7802a0aca4f6"
},
{
"url": "https://git.kernel.org/stable/c/956b134d917fd7e014dc7e39a9b7610c04fcc9ba"
},
{
"url": "https://git.kernel.org/stable/c/fb7f511d62692661846c47f199e0afe25c2982db"
}
],
"title": "ethtool: module: avoid leaking a netdev ref on module flash errors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63997",
"datePublished": "2026-07-19T14:56:15.965Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-07-19T14:56:15.965Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68139 (GCVE-0-2026-68139)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Use sender devcom for MPV master-up
After PCIe DPC recovery, mlx5 reloads the affected functions and
replays multiport affiliation events. In the reported failure, the
first relevant device error was:
pcieport 0000:10:01.1: DPC: containment event
pcieport 0000:10:01.1: PCIe Bus Error: severity=Uncorrected (Fatal)
pcieport 0000:10:01.1: [ 5] SDES (First)
mlx5 recovered the PCI functions and resumed 0000:11:00.1. During
that resume, RDMA multiport binding replayed
MLX5_DRIVER_EVENT_AFFILIATION_DONE and mlx5e sent
MPV_DEVCOM_MASTER_UP. The host then panicked with:
BUG: kernel NULL pointer dereference, address: 0000000000000010
RIP: mlx5_devcom_comp_set_ready+0x5/0x40 [mlx5_core]
RDI: 0000000000000000
Call trace included:
mlx5_devcom_comp_set_ready
mlx5e_devcom_event_mpv
mlx5_devcom_send_event
mlx5_ib_bind_slave_port
mlx5r_mp_probe
mlx5_pci_resume
MPV devcom registration publishes mlx5e private data to the component
peer list before mlx5e_devcom_init_mpv() stores the returned component
device in priv->devcom. A concurrent master-up event can therefore
reach a peer whose private data is visible but whose priv->devcom
backpointer is still NULL.
MPV_DEVCOM_MASTER_UP already carries the sender/master mlx5e private
data as event_data. The ready bit is stored on the shared devcom
component, not on an individual peer. Use the sender devcom when
marking the MPV component ready.
This preserves the readiness transition while avoiding a NULL
dereference of the peer devcom pointer during affiliation replay after
PCI error recovery.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c698b2735613f1f35c55688bd2252f75f31c49ad",
"status": "affected",
"version": "bf11485f8419f90ffaa3804fd01d8468fcc56e23",
"versionType": "git"
},
{
"lessThan": "40f9a124ebbe0d60fe165fb3f87515c35b2d72f5",
"status": "affected",
"version": "bf11485f8419f90ffaa3804fd01d8468fcc56e23",
"versionType": "git"
},
{
"lessThan": "a60c81f168c9fe4f5d84302d1e32b717f5a8a933",
"status": "affected",
"version": "bf11485f8419f90ffaa3804fd01d8468fcc56e23",
"versionType": "git"
},
{
"lessThan": "e32649b4bad90a6216d8e93cd7dd050af8ac9740",
"status": "affected",
"version": "bf11485f8419f90ffaa3804fd01d8468fcc56e23",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Use sender devcom for MPV master-up\n\nAfter PCIe DPC recovery, mlx5 reloads the affected functions and\nreplays multiport affiliation events. In the reported failure, the\nfirst relevant device error was:\n\n pcieport 0000:10:01.1: DPC: containment event\n pcieport 0000:10:01.1: PCIe Bus Error: severity=Uncorrected (Fatal)\n pcieport 0000:10:01.1: [ 5] SDES (First)\n\nmlx5 recovered the PCI functions and resumed 0000:11:00.1. During\nthat resume, RDMA multiport binding replayed\nMLX5_DRIVER_EVENT_AFFILIATION_DONE and mlx5e sent\nMPV_DEVCOM_MASTER_UP. The host then panicked with:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n RIP: mlx5_devcom_comp_set_ready+0x5/0x40 [mlx5_core]\n RDI: 0000000000000000\n\nCall trace included:\n\n mlx5_devcom_comp_set_ready\n mlx5e_devcom_event_mpv\n mlx5_devcom_send_event\n mlx5_ib_bind_slave_port\n mlx5r_mp_probe\n mlx5_pci_resume\n\nMPV devcom registration publishes mlx5e private data to the component\npeer list before mlx5e_devcom_init_mpv() stores the returned component\ndevice in priv-\u003edevcom. A concurrent master-up event can therefore\nreach a peer whose private data is visible but whose priv-\u003edevcom\nbackpointer is still NULL.\n\nMPV_DEVCOM_MASTER_UP already carries the sender/master mlx5e private\ndata as event_data. The ready bit is stored on the shared devcom\ncomponent, not on an individual peer. Use the sender devcom when\nmarking the MPV component ready.\n\nThis preserves the readiness transition while avoiding a NULL\ndereference of the peer devcom pointer during affiliation replay after\nPCI error recovery."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:32.634Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c698b2735613f1f35c55688bd2252f75f31c49ad"
},
{
"url": "https://git.kernel.org/stable/c/40f9a124ebbe0d60fe165fb3f87515c35b2d72f5"
},
{
"url": "https://git.kernel.org/stable/c/a60c81f168c9fe4f5d84302d1e32b717f5a8a933"
},
{
"url": "https://git.kernel.org/stable/c/e32649b4bad90a6216d8e93cd7dd050af8ac9740"
}
],
"title": "net/mlx5e: Use sender devcom for MPV master-up",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68139",
"datePublished": "2026-08-10T11:59:02.768Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-17T04:59:32.634Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64007 (GCVE-0-2026-64007)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: synproxy: refresh tcphdr after skb_ensure_writable
synproxy_tstamp_adjust() rewrites the TCP timestamp option in place
and then patches the TCP checksum via inet_proto_csum_replace4() on
the caller-supplied tcphdr pointer. Both ipv4_synproxy_hook() and
ipv6_synproxy_hook() obtain that pointer with skb_header_pointer()
before calling in, so it may either alias skb->head directly or
point at the caller's on-stack _tcph buffer.
Between obtaining the pointer and using it, the function calls
skb_ensure_writable(skb, optend), which on a cloned or non-linear
skb invokes pskb_expand_head() and frees the old skb->head. After
that point the cached th is stale:
caller (ipv[46]_synproxy_hook)
th = skb_header_pointer(skb, ..., &_tcph)
synproxy_tstamp_adjust(skb, protoff, th, ...)
skb_ensure_writable(skb, optend)
pskb_expand_head() /* kfree(old skb->head) */
...
inet_proto_csum_replace4(&th->check, ...)
/* writes into freed head, or
into the caller's stack copy
leaving the on-wire checksum
stale */
The option bytes are written through skb->data and are fine; only
the checksum update goes through th and so lands in the wrong
place. The result is either a write into freed slab memory or a
packet leaving with a checksum that does not match its payload.
Fix by re-deriving th from skb->data + protoff immediately after
skb_ensure_writable() succeeds, so the subsequent checksum update
targets the linear, writable header.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 48b1de4c110a7afa4b85862f6c75af817db26fad Version: 48b1de4c110a7afa4b85862f6c75af817db26fad Version: 48b1de4c110a7afa4b85862f6c75af817db26fad Version: 48b1de4c110a7afa4b85862f6c75af817db26fad Version: 48b1de4c110a7afa4b85862f6c75af817db26fad Version: 48b1de4c110a7afa4b85862f6c75af817db26fad Version: 48b1de4c110a7afa4b85862f6c75af817db26fad Version: 48b1de4c110a7afa4b85862f6c75af817db26fad |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_synproxy_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9902a1058992de5d95656b64a3bd95c077f7ba2c",
"status": "affected",
"version": "48b1de4c110a7afa4b85862f6c75af817db26fad",
"versionType": "git"
},
{
"lessThan": "d3019c61799adc21811af4b521f11f3dc77f8e04",
"status": "affected",
"version": "48b1de4c110a7afa4b85862f6c75af817db26fad",
"versionType": "git"
},
{
"lessThan": "dd206819f210522579010d889d45a9530bb494bc",
"status": "affected",
"version": "48b1de4c110a7afa4b85862f6c75af817db26fad",
"versionType": "git"
},
{
"lessThan": "af2c22ccb1f621aff487ff47a040e38e058541e7",
"status": "affected",
"version": "48b1de4c110a7afa4b85862f6c75af817db26fad",
"versionType": "git"
},
{
"lessThan": "c7f945f7da097245a2f8ed7775ce48421047ee96",
"status": "affected",
"version": "48b1de4c110a7afa4b85862f6c75af817db26fad",
"versionType": "git"
},
{
"lessThan": "f0fea2b6d5453a11ad11713bbf37561b9b3a7edf",
"status": "affected",
"version": "48b1de4c110a7afa4b85862f6c75af817db26fad",
"versionType": "git"
},
{
"lessThan": "a91887a5b6ee4b98dfbf1db657ed2b879430149e",
"status": "affected",
"version": "48b1de4c110a7afa4b85862f6c75af817db26fad",
"versionType": "git"
},
{
"lessThan": "92170e6afe927ab2792a3f71902845789c8e31b1",
"status": "affected",
"version": "48b1de4c110a7afa4b85862f6c75af817db26fad",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_synproxy_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"lessThan": "3.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: refresh tcphdr after skb_ensure_writable\n\nsynproxy_tstamp_adjust() rewrites the TCP timestamp option in place\nand then patches the TCP checksum via inet_proto_csum_replace4() on\nthe caller-supplied tcphdr pointer. Both ipv4_synproxy_hook() and\nipv6_synproxy_hook() obtain that pointer with skb_header_pointer()\nbefore calling in, so it may either alias skb-\u003ehead directly or\npoint at the caller\u0027s on-stack _tcph buffer.\n\nBetween obtaining the pointer and using it, the function calls\nskb_ensure_writable(skb, optend), which on a cloned or non-linear\nskb invokes pskb_expand_head() and frees the old skb-\u003ehead. After\nthat point the cached th is stale:\n\n caller (ipv[46]_synproxy_hook)\n th = skb_header_pointer(skb, ..., \u0026_tcph)\n synproxy_tstamp_adjust(skb, protoff, th, ...)\n skb_ensure_writable(skb, optend)\n pskb_expand_head() /* kfree(old skb-\u003ehead) */\n ...\n inet_proto_csum_replace4(\u0026th-\u003echeck, ...)\n /* writes into freed head, or\n into the caller\u0027s stack copy\n leaving the on-wire checksum\n stale */\n\nThe option bytes are written through skb-\u003edata and are fine; only\nthe checksum update goes through th and so lands in the wrong\nplace. The result is either a write into freed slab memory or a\npacket leaving with a checksum that does not match its payload.\n\nFix by re-deriving th from skb-\u003edata + protoff immediately after\nskb_ensure_writable() succeeds, so the subsequent checksum update\ntargets the linear, writable header."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is triggered when remote TCP packets traverse SYNPROXY netfilter hooks (NF_INET_LOCAL_IN / NF_INET_POST_ROUTING) on a host with SYNPROXY configured, which is the standard internet-facing firewall/router deployment for this subsystem.\nAC:L - An attacker who controls a TCP session through SYNPROXY can reliably send timestamp-bearing packets to hit the vulnerable path; the stale-pointer UAF write occurs whenever skb_ensure_writable() must expand a cloned skb, which the attacker can influence by sustaining traffic on the proxied connection.\nPR:N - Exploitation requires only that the victim already runs SYNPROXY (normal for protected services); the remote attacker needs no credentials or local privileges on the target system to send the triggering TCP packets.\nUI:N - No victim user action is required beyond normal network operation; exploitation is fully automated via crafted or sustained TCP traffic through the SYNPROXY session.\nS:U - Impact is confined to kernel memory on the affected host running SYNPROXY; this is standard kernel privilege escalation/memory corruption, not a cross-VM or cross-security-boundary escape.\nC:H - The stale tcphdr pointer causes inet_proto_csum_replace4() to write into freed slab memory, a use-after-free class bug that can be leveraged for arbitrary kernel memory read via heap grooming techniques.\nI:H - The out-of-bounds write into freed slab memory via a stale tcphdr pointer is a use-after-free write primitive that can be developed into arbitrary kernel memory writes and local privilege escalation.\nA:H - Writing into freed slab memory can corrupt adjacent kernel objects and cause kernel oops, panic, or crash, and UAF conditions are inherently capable of destabilizing the system even during exploitation attempts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:06.995Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9902a1058992de5d95656b64a3bd95c077f7ba2c"
},
{
"url": "https://git.kernel.org/stable/c/d3019c61799adc21811af4b521f11f3dc77f8e04"
},
{
"url": "https://git.kernel.org/stable/c/dd206819f210522579010d889d45a9530bb494bc"
},
{
"url": "https://git.kernel.org/stable/c/af2c22ccb1f621aff487ff47a040e38e058541e7"
},
{
"url": "https://git.kernel.org/stable/c/c7f945f7da097245a2f8ed7775ce48421047ee96"
},
{
"url": "https://git.kernel.org/stable/c/f0fea2b6d5453a11ad11713bbf37561b9b3a7edf"
},
{
"url": "https://git.kernel.org/stable/c/a91887a5b6ee4b98dfbf1db657ed2b879430149e"
},
{
"url": "https://git.kernel.org/stable/c/92170e6afe927ab2792a3f71902845789c8e31b1"
}
],
"title": "netfilter: synproxy: refresh tcphdr after skb_ensure_writable",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64007",
"datePublished": "2026-07-19T14:56:23.049Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-08-05T12:38:06.995Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64313 (GCVE-0-2026-64313)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: ecc - Fix carry overflow in vli multiplication
The carry flag calculation fails when r01.m_high is saturated
(0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows.
The condition (r01.m_high < product.m_high) doesn't handle the case
where r01.m_high == product.m_high and an additional carry exists
from lower-bit overflow.
When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support")
introduced crypto/ecc.c, it split the muladd() function in the
micro-ecc library into separate mul_64_64() and add_128_128() helpers.
It seems the check got lost in translation.
Add proper handling for this boundary by accounting for the carry
from the lower addition.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3c4b23901a0c766879dff680cd6bdab47bcdbbd2 Version: 3c4b23901a0c766879dff680cd6bdab47bcdbbd2 Version: 3c4b23901a0c766879dff680cd6bdab47bcdbbd2 Version: 3c4b23901a0c766879dff680cd6bdab47bcdbbd2 Version: 3c4b23901a0c766879dff680cd6bdab47bcdbbd2 Version: 3c4b23901a0c766879dff680cd6bdab47bcdbbd2 Version: 3c4b23901a0c766879dff680cd6bdab47bcdbbd2 Version: 3c4b23901a0c766879dff680cd6bdab47bcdbbd2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"crypto/ecc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d11b2bb99bec1f5557c01cac42231e23745f49b8",
"status": "affected",
"version": "3c4b23901a0c766879dff680cd6bdab47bcdbbd2",
"versionType": "git"
},
{
"lessThan": "b709e0e768766abe29a49e1c1922a1604be602f4",
"status": "affected",
"version": "3c4b23901a0c766879dff680cd6bdab47bcdbbd2",
"versionType": "git"
},
{
"lessThan": "24a54dfa06d09813b4802a374fad3d2c0e16a884",
"status": "affected",
"version": "3c4b23901a0c766879dff680cd6bdab47bcdbbd2",
"versionType": "git"
},
{
"lessThan": "677450e5ef850c4d28b7956aa01104548c2a894e",
"status": "affected",
"version": "3c4b23901a0c766879dff680cd6bdab47bcdbbd2",
"versionType": "git"
},
{
"lessThan": "5275e0fca256d081e2e7d4ba3dd8216c6e50d44e",
"status": "affected",
"version": "3c4b23901a0c766879dff680cd6bdab47bcdbbd2",
"versionType": "git"
},
{
"lessThan": "774ddddf5eb26eeca177350413e3e2bc50930ee9",
"status": "affected",
"version": "3c4b23901a0c766879dff680cd6bdab47bcdbbd2",
"versionType": "git"
},
{
"lessThan": "ebaae7c4251cc0cdb2602f334d4f08a3e82d271e",
"status": "affected",
"version": "3c4b23901a0c766879dff680cd6bdab47bcdbbd2",
"versionType": "git"
},
{
"lessThan": "27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406",
"status": "affected",
"version": "3c4b23901a0c766879dff680cd6bdab47bcdbbd2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"crypto/ecc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ecc - Fix carry overflow in vli multiplication\n\nThe carry flag calculation fails when r01.m_high is saturated\n(0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows.\n\nThe condition (r01.m_high \u003c product.m_high) doesn\u0027t handle the case\nwhere r01.m_high == product.m_high and an additional carry exists\nfrom lower-bit overflow.\n\nWhen commit 3c4b23901a0c (\"crypto: ecdh - Add ECDH software support\")\nintroduced crypto/ecc.c, it split the muladd() function in the\nmicro-ecc library into separate mul_64_64() and add_128_128() helpers.\nIt seems the check got lost in translation.\n\nAdd proper handling for this boundary by accounting for the carry\nfrom the lower addition."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The concrete unauthenticated external path is Bluetooth LE Secure Connections, where a nearby peer\u0027s SMP Public Key message reaches the flawed ECC multiplication. Bluetooth requires proximity rather than routable network access.\nAC:L - The attacker controls the ECC operands and can repeatedly submit deliberately constructed values that trigger the carry error. No race, unpredictable memory layout, or victim-controlled state is required.\nPR:N - SMP permits a peer to negotiate Secure Connections and submit its public key before credential validation, DHKey confirmation, or bonding completes. No local account or capability is required.\nUI:N - The peer\u0027s public key is validated and the ECDH secret is computed before authentication-method completion. Headless and Just Works deployments require no human action.\nS:U - The vulnerable arithmetic and affected cryptographic consumers operate within the same kernel security authority. The vulnerability does not inherently cross a VM, IOMMU, or comparable security boundary.\nC:H - Incorrect field multiplication can undermine public-key validation and ECDH shared-secret computation. Faulty-curve or key-agreement attacks could expose secrets and all data protected by derived session keys.\nI:H - The same faulty multiplication supports ECDSA and ECRDSA verification, making false cryptographic results and signature or peer-authentication bypass defensible. This can authorize attacker-controlled content, code, or commands.\nA:H - Authentication bypass can authorize attacker-controlled code or commands capable of halting the system, while repeated crafted exchanges can prevent secure pairing. Safety-critical or headless devices dependent on the affected trust path can lose their protected function completely."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:13.285Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d11b2bb99bec1f5557c01cac42231e23745f49b8"
},
{
"url": "https://git.kernel.org/stable/c/b709e0e768766abe29a49e1c1922a1604be602f4"
},
{
"url": "https://git.kernel.org/stable/c/24a54dfa06d09813b4802a374fad3d2c0e16a884"
},
{
"url": "https://git.kernel.org/stable/c/677450e5ef850c4d28b7956aa01104548c2a894e"
},
{
"url": "https://git.kernel.org/stable/c/5275e0fca256d081e2e7d4ba3dd8216c6e50d44e"
},
{
"url": "https://git.kernel.org/stable/c/774ddddf5eb26eeca177350413e3e2bc50930ee9"
},
{
"url": "https://git.kernel.org/stable/c/ebaae7c4251cc0cdb2602f334d4f08a3e82d271e"
},
{
"url": "https://git.kernel.org/stable/c/27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406"
}
],
"title": "crypto: ecc - Fix carry overflow in vli multiplication",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64313",
"datePublished": "2026-07-25T08:49:44.546Z",
"dateReserved": "2026-07-19T15:36:31.779Z",
"dateUpdated": "2026-08-17T04:53:13.285Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68430 (GCVE-0-2026-68430)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx8: drop unecessary BUG_ON()
There's no need to crash the kernel for this case.
(cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "69004f1f769f7f6e9e34f4390d98a12aa0b4ab98",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "26ad939b402a754b0624840dfaeebd86d7ff2a22",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "0027afe3dc97a4964a9ea0fb5a3457de06d85f5b",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "ab05af6c345bc8460052c60de657ce6d4a2386f7",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "2404600dca5c0979485c6f2d9c62bd356a98870a",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "f70bd5235d9efc2ee2f70293eea51888c5f2a54d",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "db85aa861b8214fa0d1d8405c01488f604a455a0",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx8: drop unecessary BUG_ON()\n\nThere\u0027s no need to crash the kernel for this case.\n\n(cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:27.984Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/69004f1f769f7f6e9e34f4390d98a12aa0b4ab98"
},
{
"url": "https://git.kernel.org/stable/c/26ad939b402a754b0624840dfaeebd86d7ff2a22"
},
{
"url": "https://git.kernel.org/stable/c/0027afe3dc97a4964a9ea0fb5a3457de06d85f5b"
},
{
"url": "https://git.kernel.org/stable/c/ab05af6c345bc8460052c60de657ce6d4a2386f7"
},
{
"url": "https://git.kernel.org/stable/c/2404600dca5c0979485c6f2d9c62bd356a98870a"
},
{
"url": "https://git.kernel.org/stable/c/f70bd5235d9efc2ee2f70293eea51888c5f2a54d"
},
{
"url": "https://git.kernel.org/stable/c/db85aa861b8214fa0d1d8405c01488f604a455a0"
},
{
"url": "https://git.kernel.org/stable/c/84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5"
}
],
"title": "drm/amdgpu/gfx8: drop unecessary BUG_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68430",
"datePublished": "2026-08-12T00:07:15.927Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:27.984Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74394 (GCVE-0-2026-74394)
Vulnerability from cvelistv5
Published
2026-08-15 05:59
Modified
2026-08-17 05:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/srpt: fix integer overflow in immediate data length check
imm_buf->len is a user-controlled uint32_t received from the network.
Adding it to imm_data_offset without overflow checking allows a
malicious initiator to send len=0xFFFFFFFF, causing req_size to wrap
around to a small value, bypassing the bounds check, and subsequently
passing a ~4GB length to sg_init_one().
Use check_add_overflow() to detect wrapping before the comparison.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 Version: 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 Version: 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 Version: 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 Version: 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 Version: 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 Version: 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 Version: 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/ulp/srpt/ib_srpt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c82c860f8c8e4f4f454c9f14d0ad0c0466965f7d",
"status": "affected",
"version": "5dabcd0456d7ee17c2c7a17d7c2305444d2b9639",
"versionType": "git"
},
{
"lessThan": "3efa5301137140a3ca3677a9098c0a93a0acfd49",
"status": "affected",
"version": "5dabcd0456d7ee17c2c7a17d7c2305444d2b9639",
"versionType": "git"
},
{
"lessThan": "067b9556eeb007f28b7c2033b4dcde5b6d88418f",
"status": "affected",
"version": "5dabcd0456d7ee17c2c7a17d7c2305444d2b9639",
"versionType": "git"
},
{
"lessThan": "dcf7a986f377cce0749ed53f1d64195fbd5fdf91",
"status": "affected",
"version": "5dabcd0456d7ee17c2c7a17d7c2305444d2b9639",
"versionType": "git"
},
{
"lessThan": "07dec3f6dcb6c6cc891162d252b800eb0e6d5e8e",
"status": "affected",
"version": "5dabcd0456d7ee17c2c7a17d7c2305444d2b9639",
"versionType": "git"
},
{
"lessThan": "65572fbd86033ae2370125593d59b8be34253aaf",
"status": "affected",
"version": "5dabcd0456d7ee17c2c7a17d7c2305444d2b9639",
"versionType": "git"
},
{
"lessThan": "72497172a4799119a0282a5eb5e2b8ddcc821921",
"status": "affected",
"version": "5dabcd0456d7ee17c2c7a17d7c2305444d2b9639",
"versionType": "git"
},
{
"lessThan": "eb4ecdf631fe00e8020bf461503cb9b7017ed796",
"status": "affected",
"version": "5dabcd0456d7ee17c2c7a17d7c2305444d2b9639",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/ulp/srpt/ib_srpt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: fix integer overflow in immediate data length check\n\nimm_buf-\u003elen is a user-controlled uint32_t received from the network.\nAdding it to imm_data_offset without overflow checking allows a\nmalicious initiator to send len=0xFFFFFFFF, causing req_size to wrap\naround to a small value, bypassing the bounds check, and subsequently\npassing a ~4GB length to sg_init_one().\n\nUse check_add_overflow() to detect wrapping before the comparison."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - SRPT is an in-kernel SCSI RDMA target reached by remote initiators over InfiniBand/RoCE via RDMA/IB CM; malicious SRP_CMD IUs are delivered through `srpt_recv_done()` without any local syscall or physical access.\nAC:L - Once connected on an immediate-data SRPT target (use_srq=0), a malicious initiator deterministically sets `imm_buf-\u003elen=0xFFFFFFFF` to wrap `req_size` and bypass checks; no race or attacker-uncontrollable condition is required.\nPR:N - SRPT enables LIO demo mode (`srpt_check_true`), so any remote initiator that completes SRP login on an enabled target gets a dynamic ACL without target-local credentials, root, or CAP_NET_ADMIN on the victim host.\nUI:N - Exploitation requires only attacker-initiated RDMA connection, SRP login, and crafted SRP_CMD traffic; no administrator or other user must mount storage or perform any action on the target.\nS:U - The integer overflow corrupts kernel heap memory and SCSI-target processing within the host kernel\u0027s own security authority; it does not cross VM, IOMMU, or container sandbox boundaries.\nC:H - Passing a ~4GB length to `sg_init_one()` on a small receive buffer creates a massive out-of-bounds scatterlist; subsequent target-core DMA/map operations can read far beyond the buffer, enabling arbitrary kernel memory disclosure.\nI:H - The bogus scatterlist gives the block/SCSI target path an attacker-controlled ~4GB kernel memory write/read primitive over adjacent heap objects, exploitable for control-flow hijacking and privilege escalation.\nA:H - Out-of-bounds access from a ~4GB scatterlist on a kilobyte-scale receive buffer readily triggers kernel oops, KASAN faults, or panic, denying availability even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:46:39.840Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c82c860f8c8e4f4f454c9f14d0ad0c0466965f7d"
},
{
"url": "https://git.kernel.org/stable/c/3efa5301137140a3ca3677a9098c0a93a0acfd49"
},
{
"url": "https://git.kernel.org/stable/c/067b9556eeb007f28b7c2033b4dcde5b6d88418f"
},
{
"url": "https://git.kernel.org/stable/c/dcf7a986f377cce0749ed53f1d64195fbd5fdf91"
},
{
"url": "https://git.kernel.org/stable/c/07dec3f6dcb6c6cc891162d252b800eb0e6d5e8e"
},
{
"url": "https://git.kernel.org/stable/c/65572fbd86033ae2370125593d59b8be34253aaf"
},
{
"url": "https://git.kernel.org/stable/c/72497172a4799119a0282a5eb5e2b8ddcc821921"
},
{
"url": "https://git.kernel.org/stable/c/eb4ecdf631fe00e8020bf461503cb9b7017ed796"
}
],
"title": "RDMA/srpt: fix integer overflow in immediate data length check",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74394",
"datePublished": "2026-08-15T05:59:07.144Z",
"dateReserved": "2026-08-15T05:44:03.891Z",
"dateUpdated": "2026-08-17T05:46:39.840Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74692 (GCVE-0-2026-74692)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix TOCTOU race between smc_listen_out() and listener close
smc_listen_out() reads lsmc->sk.sk_state without the listener lock,
then acquires lock_sock_nested() only after the check passes. This
opens a window where smc_close_active() can transition the listener
to SMC_CLOSED, call smc_close_cleanup_listen() to drain the accept
queue, and release the lock, all between the lockless read and the
delayed lock acquisition:
smc_listen_work (smc_hs_wq) smc_close_active()
------------------------------- -------------------------
release_sock(child)
if (sk_state == SMC_LISTEN) TRUE
lock_sock(listener)
sk_state = SMC_CLOSED
smc_close_cleanup_listen()
release_sock(listener)
flush_work(tcp_listen_work)
lock_sock_nested(listener)
smc_accept_enqueue(listener, child) /* child enqueued on dead listener */
smc_close_active() flushes only tcp_listen_work. Work items already
dispatched onto smc_hs_wq for the CLC handshake continue running
unguarded. smc_accept_enqueue() takes a sock_hold() on the child that
is never released, so the child smc_sock, its clcsock, and the
reference all leak. A remote peer that opens TCP connections while the
server calls close() can exhaust kernel memory.
Move lock_sock_nested() to before the sk_state check so that the test
and the enqueue are atomic under the listener lock.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: d1d004585b40c212b338fc8a40cbaaf230ea4703 Version: 4.19.299 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/af_smc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "53c7938d8bcfde3296ec1a347ba2a9393c1fdcfa",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "feb71634bb1abab3e8fb5cde874b27001cc1282e",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "01865e1ddb126b25ac9eba5cdd7ec49e11183a64",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "00f89433777236ced4771211047fb5d4cd581cea",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "78e5ebcd1c10ed7c8bda0a99e0abd5b62da86d67",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "ff5bcd804b5bc5c64736b7d318c20e12ea9506b8",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "185a4caeecabc150106deda1da170b09f2ad803f",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"status": "affected",
"version": "d1d004585b40c212b338fc8a40cbaaf230ea4703",
"versionType": "git"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.299",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/af_smc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.299",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix TOCTOU race between smc_listen_out() and listener close\n\nsmc_listen_out() reads lsmc-\u003esk.sk_state without the listener lock,\nthen acquires lock_sock_nested() only after the check passes. This\nopens a window where smc_close_active() can transition the listener\nto SMC_CLOSED, call smc_close_cleanup_listen() to drain the accept\nqueue, and release the lock, all between the lockless read and the\ndelayed lock acquisition:\n\n smc_listen_work (smc_hs_wq) smc_close_active()\n ------------------------------- -------------------------\n release_sock(child)\n if (sk_state == SMC_LISTEN) TRUE\n lock_sock(listener)\n sk_state = SMC_CLOSED\n smc_close_cleanup_listen()\n release_sock(listener)\n flush_work(tcp_listen_work)\n lock_sock_nested(listener)\n smc_accept_enqueue(listener, child) /* child enqueued on dead listener */\n\nsmc_close_active() flushes only tcp_listen_work. Work items already\ndispatched onto smc_hs_wq for the CLC handshake continue running\nunguarded. smc_accept_enqueue() takes a sock_hold() on the child that\nis never released, so the child smc_sock, its clcsock, and the\nreference all leak. A remote peer that opens TCP connections while the\nserver calls close() can exhaust kernel memory.\n\nMove lock_sock_nested() to before the sk_state check so that the test\nand the enqueue are atomic under the listener lock."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug fires when smc_listen_work() on smc_hs_wq finishes an inbound SMC/TCP handshake queued by smc_tcp_listen_work() for each remote connection to an AF_SMC listener, so any network peer that reaches the listener port drives the full path via SYN and CLC messages.\nAC:L - The attacker controls handshake completions by flooding SMC-capable TCP connections and overlapping them with listener close(), either by timing floods against restarts or locally by running server and client together; smc_close_active() only flushes tcp_listen_work, leaving smc_hs_wq workers racing through the unlocked sk_state check.\nPR:N - SMC performs no authentication; smc_create() and smc_listen() enforce no capabilities, and smc_listen_work() processes the CLC handshake immediately after TCP accept before any credential verification, so an unauthenticated remote peer need only reach the listener port.\nUI:N - Exploitation requires only inbound network connections and kernel handshake/close processing; no end-user action such as opening a file or mounting a filesystem is needed, and listener shutdown during deployments or restarts is routine automated server behavior.\nS:U - The leak accumulates orphaned smc_sock structures and clcsock references within the kernel networking subsystem on the targeted host; it does not cross VM, container, IOMMU, or other security boundaries.\nC:N - The bug is an unreleased sock_hold() leaving child sockets on a closed listener accept queue; objects are never freed prematurely, so there is no out-of-bounds read, use-after-free dereference, or kernel data disclosure to the attacker.\nI:N - Only reference counts are incremented without matching decrements; no memory is written out of bounds, no freed object is reused, and no control-flow or integrity primitive is obtained\u2014only unreclaimable kernel allocations accumulate.\nA:H - Each successful race permanently leaks a child smc_sock, its clcsock, and sock references that smc_close_cleanup_listen() can never drain; a remote peer repeating handshakes during listener close can exhaust kernel memory and cause system-wide denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:37.608Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/53c7938d8bcfde3296ec1a347ba2a9393c1fdcfa"
},
{
"url": "https://git.kernel.org/stable/c/feb71634bb1abab3e8fb5cde874b27001cc1282e"
},
{
"url": "https://git.kernel.org/stable/c/01865e1ddb126b25ac9eba5cdd7ec49e11183a64"
},
{
"url": "https://git.kernel.org/stable/c/00f89433777236ced4771211047fb5d4cd581cea"
},
{
"url": "https://git.kernel.org/stable/c/78e5ebcd1c10ed7c8bda0a99e0abd5b62da86d67"
},
{
"url": "https://git.kernel.org/stable/c/ff5bcd804b5bc5c64736b7d318c20e12ea9506b8"
},
{
"url": "https://git.kernel.org/stable/c/185a4caeecabc150106deda1da170b09f2ad803f"
}
],
"title": "net/smc: fix TOCTOU race between smc_listen_out() and listener close",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74692",
"datePublished": "2026-08-22T15:32:55.873Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-25T05:41:37.608Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53133 (GCVE-0-2026-53133)
Vulnerability from cvelistv5
Published
2026-06-25 08:38
Modified
2026-08-05 12:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/umem: Fix truncation for block sizes >= 4G
When the iommu is used the linearization of the mapping can give a single
block that is very large split across multiple SG entries.
When __rdma_block_iter_next() reassembles the split SG entries it is
overflowing the 32 bit stack values and computed the wrong DMA addresses
for blocks after the truncation.
Use the right types to hold DMA addresses.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a808273a495c657e33281b181fd7fcc2bb28f662 Version: a808273a495c657e33281b181fd7fcc2bb28f662 Version: a808273a495c657e33281b181fd7fcc2bb28f662 Version: a808273a495c657e33281b181fd7fcc2bb28f662 Version: a808273a495c657e33281b181fd7fcc2bb28f662 Version: a808273a495c657e33281b181fd7fcc2bb28f662 Version: a808273a495c657e33281b181fd7fcc2bb28f662 Version: a808273a495c657e33281b181fd7fcc2bb28f662 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/iter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2ff4b7817e5b78070c30f5fb5e678e452a2628b3",
"status": "affected",
"version": "a808273a495c657e33281b181fd7fcc2bb28f662",
"versionType": "git"
},
{
"lessThan": "dee2a49adeeb2a5e16a3fc858fa21b841c519802",
"status": "affected",
"version": "a808273a495c657e33281b181fd7fcc2bb28f662",
"versionType": "git"
},
{
"lessThan": "cc644d5608e3b0dadc970bd6e6aa26b91ea07d0f",
"status": "affected",
"version": "a808273a495c657e33281b181fd7fcc2bb28f662",
"versionType": "git"
},
{
"lessThan": "8fe0231adebe086c8a459c790944ac026cd99c6e",
"status": "affected",
"version": "a808273a495c657e33281b181fd7fcc2bb28f662",
"versionType": "git"
},
{
"lessThan": "baf8685bcf56dc1efb44b8f6a57c42516e549068",
"status": "affected",
"version": "a808273a495c657e33281b181fd7fcc2bb28f662",
"versionType": "git"
},
{
"lessThan": "afd35fec9297195b759078745549c2671223f24f",
"status": "affected",
"version": "a808273a495c657e33281b181fd7fcc2bb28f662",
"versionType": "git"
},
{
"lessThan": "ac1aad8e1281534ce936c250f68084fc79c5469e",
"status": "affected",
"version": "a808273a495c657e33281b181fd7fcc2bb28f662",
"versionType": "git"
},
{
"lessThan": "15fe76e23615f502d051ef0768f86babaf08746c",
"status": "affected",
"version": "a808273a495c657e33281b181fd7fcc2bb28f662",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/iter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/umem: Fix truncation for block sizes \u003e= 4G\n\nWhen the iommu is used the linearization of the mapping can give a single\nblock that is very large split across multiple SG entries.\n\nWhen __rdma_block_iter_next() reassembles the split SG entries it is\noverflowing the 32 bit stack values and computed the wrong DMA addresses\nfor blocks after the truncation.\n\nUse the right types to hold DMA addresses."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Vulnerable code is reached through local RDMA uverbs operations such as opening `/dev/infiniband/uverbsX` and issuing memory-registration commands. Remote RDMA traffic may later exercise a bad MR, but the vulnerable iterator is invoked by local userspace registration, not by network packet parsing.\nAC:L - There is no race or probabilistic condition; on an affected RDMA/IOMMU deployment the attacker controls the MR address, length, and access flags needed to request large aligned mappings. Hardware/IOMMU support is an environmental prerequisite for the affected subsystem, not an exploitation step beyond attacker control.\nPR:L - The uverbs device node is created world-accessible and MR registration does not require CAP_SYS_ADMIN or CAP_NET_ADMIN, though the process must be an unprivileged local user able to use the RDMA device and pin memory under its memlock limits. No real init-namespace root privilege is required.\nUI:N - After local access to the RDMA device, the attacker can perform the open/context/PD/MR registration sequence directly. No separate victim action is required.\nS:U - The impact remains within the kernel/RDMA device memory-management security authority. This is not a guest-to-host escape, IOMMU boundary bypass by a guest, or another cross-scope boundary change.\nC:H - The truncation can program wrong DMA addresses into RDMA memory translation tables for blocks after the overflow. With RDMA read-capable access, the resulting mistranslation can expose unintended memory reachable through the device mapping, so the higher defensible confidentiality impact is High.\nI:H - The same wrong DMA translation can be used with local or remote write-capable MR permissions to direct RDMA writes to unintended mapped memory. Because this is device DMA memory corruption rather than a bounded metadata error, the higher defensible integrity impact is High.\nA:H - Incorrect DMA translations can cause IOMMU/device faults, corrupted RDMA state, or repeated failures of registered memory operations. Given the kernel/device-level DMA fault surface and the requirement to choose the higher severity when uncertain, availability impact is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:33:27.415Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2ff4b7817e5b78070c30f5fb5e678e452a2628b3"
},
{
"url": "https://git.kernel.org/stable/c/dee2a49adeeb2a5e16a3fc858fa21b841c519802"
},
{
"url": "https://git.kernel.org/stable/c/cc644d5608e3b0dadc970bd6e6aa26b91ea07d0f"
},
{
"url": "https://git.kernel.org/stable/c/8fe0231adebe086c8a459c790944ac026cd99c6e"
},
{
"url": "https://git.kernel.org/stable/c/baf8685bcf56dc1efb44b8f6a57c42516e549068"
},
{
"url": "https://git.kernel.org/stable/c/afd35fec9297195b759078745549c2671223f24f"
},
{
"url": "https://git.kernel.org/stable/c/ac1aad8e1281534ce936c250f68084fc79c5469e"
},
{
"url": "https://git.kernel.org/stable/c/15fe76e23615f502d051ef0768f86babaf08746c"
}
],
"title": "RDMA/umem: Fix truncation for block sizes \u003e= 4G",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53133",
"datePublished": "2026-06-25T08:38:22.469Z",
"dateReserved": "2026-06-09T07:44:35.386Z",
"dateUpdated": "2026-08-05T12:33:27.415Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63985 (GCVE-0-2026-63985)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ethtool: eeprom: add more safeties to EEPROM Netlink fallback
The Netlink fallback path for reading module EEPROM
(fallback_set_params()) validates that offset < eeprom_len,
but does not check that offset + length stays within eeprom_len.
The ioctl equivalent (ethtool_get_any_eeprom() in ioctl.c) has
always enforced both bounds:
if (eeprom.offset + eeprom.len > total_len)
return -EINVAL;
This could lead to surprises in both drivers and device FW.
Add the missing offset + length validation to fallback_set_params(),
mirroring the ioctl.
Similarly - ethtool core in general, and ethtool_get_any_eeprom()
in particular tries to zero-init all buffers passed to the drivers
to avoid any extra work of zeroing things out. eeprom_fallback()
uses a plain kmalloc(), change it to zalloc.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 96d971e307cc0e434f96329b42bbd98cfbca07d2 Version: 96d971e307cc0e434f96329b42bbd98cfbca07d2 Version: 96d971e307cc0e434f96329b42bbd98cfbca07d2 Version: 96d971e307cc0e434f96329b42bbd98cfbca07d2 Version: 96d971e307cc0e434f96329b42bbd98cfbca07d2 Version: 96d971e307cc0e434f96329b42bbd98cfbca07d2 Version: 96d971e307cc0e434f96329b42bbd98cfbca07d2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ethtool/eeprom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0e182689831277faf2ef683573a60474c208f690",
"status": "affected",
"version": "96d971e307cc0e434f96329b42bbd98cfbca07d2",
"versionType": "git"
},
{
"lessThan": "6ed7ebe22e9c3e3e946b6973c1ce43d3c38aeac1",
"status": "affected",
"version": "96d971e307cc0e434f96329b42bbd98cfbca07d2",
"versionType": "git"
},
{
"lessThan": "65674d2489a12b8efd2ca0effb3de1d12224b596",
"status": "affected",
"version": "96d971e307cc0e434f96329b42bbd98cfbca07d2",
"versionType": "git"
},
{
"lessThan": "d81376053a00865c70b8d8506a1cb93f2943d413",
"status": "affected",
"version": "96d971e307cc0e434f96329b42bbd98cfbca07d2",
"versionType": "git"
},
{
"lessThan": "fd0de51c54fa8474a0ddeedd71c65ad09fada390",
"status": "affected",
"version": "96d971e307cc0e434f96329b42bbd98cfbca07d2",
"versionType": "git"
},
{
"lessThan": "4fe1bc4b3603f621240d5b401742f302190db769",
"status": "affected",
"version": "96d971e307cc0e434f96329b42bbd98cfbca07d2",
"versionType": "git"
},
{
"lessThan": "67cfdd9210b99f260b3e0afeb9525e0acc7be31e",
"status": "affected",
"version": "96d971e307cc0e434f96329b42bbd98cfbca07d2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ethtool/eeprom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: eeprom: add more safeties to EEPROM Netlink fallback\n\nThe Netlink fallback path for reading module EEPROM\n(fallback_set_params()) validates that offset \u003c eeprom_len,\nbut does not check that offset + length stays within eeprom_len.\nThe ioctl equivalent (ethtool_get_any_eeprom() in ioctl.c) has\nalways enforced both bounds:\n\n if (eeprom.offset + eeprom.len \u003e total_len)\n return -EINVAL;\n\nThis could lead to surprises in both drivers and device FW.\nAdd the missing offset + length validation to fallback_set_params(),\nmirroring the ioctl.\n\nSimilarly - ethtool core in general, and ethtool_get_any_eeprom()\nin particular tries to zero-init all buffers passed to the drivers\nto avoid any extra work of zeroing things out. eeprom_fallback()\nuses a plain kmalloc(), change it to zalloc."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires sending an ETHTOOL_MSG_MODULE_EEPROM_GET Netlink request to the kernel; this is a local syscall/interface path, not remote packet processing.\nAC:L - An attacker with CAP_NET_ADMIN can deterministically craft page/offset/length values after querying module info, and only needs a netdev using the legacy fallback path (common on ice/ixgbe/i40e-class drivers without get_module_eeprom_by_page).\nPR:L - The ethtool Netlink handler is registered with GENL_UNS_ADMIN_PERM, requiring CAP_NET_ADMIN in the caller\u0027s user namespace, which is obtainable via unprivileged user namespaces (e.g., unshare -Urn).\nUI:N - No victim interaction is required; the attacker triggers the malformed EEPROM read directly via Netlink.\nS:U - Impact remains within the kernel/driver/NIC security domain on the same host; this is not a VM escape or cross-authority boundary crossing.\nC:H - The fallback path used kmalloc() instead of kzalloc(), allowing uninitialized kernel heap contents to be returned to userspace, and out-of-bounds offset+length values cause legacy drivers to read and return data from beyond the declared EEPROM region (NIC/module memory).\nI:H - The fix commit explicitly warns of \"surprises in both drivers and device FW\" from out-of-bounds EEPROM access; on datacenter/cloud NICs this can drive NIC or transceiver firmware into undefined states that alter device behavior beyond the intended read-only query.\nA:H - Invalid EEPROM parameters passed to driver and device firmware can cause kernel driver errors, NIC firmware hangs/resets, or link loss on production servers with optical modules installed."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:53.524Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0e182689831277faf2ef683573a60474c208f690"
},
{
"url": "https://git.kernel.org/stable/c/6ed7ebe22e9c3e3e946b6973c1ce43d3c38aeac1"
},
{
"url": "https://git.kernel.org/stable/c/65674d2489a12b8efd2ca0effb3de1d12224b596"
},
{
"url": "https://git.kernel.org/stable/c/d81376053a00865c70b8d8506a1cb93f2943d413"
},
{
"url": "https://git.kernel.org/stable/c/fd0de51c54fa8474a0ddeedd71c65ad09fada390"
},
{
"url": "https://git.kernel.org/stable/c/4fe1bc4b3603f621240d5b401742f302190db769"
},
{
"url": "https://git.kernel.org/stable/c/67cfdd9210b99f260b3e0afeb9525e0acc7be31e"
}
],
"title": "ethtool: eeprom: add more safeties to EEPROM Netlink fallback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63985",
"datePublished": "2026-07-19T14:56:07.527Z",
"dateReserved": "2026-07-19T07:54:57.025Z",
"dateUpdated": "2026-08-05T12:37:53.524Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-71075 (GCVE-0-2025-71075)
Vulnerability from cvelistv5
Published
2026-01-13 15:31
Modified
2026-09-08 08:43
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: aic94xx: fix use-after-free in device removal path
The asd_pci_remove() function fails to synchronize with pending tasklets
before freeing the asd_ha structure, leading to a potential
use-after-free vulnerability.
When a device removal is triggered (via hot-unplug or module unload),
race condition can occur.
The fix adds tasklet_kill() before freeing the asd_ha structure,
ensuring all scheduled tasklets complete before cleanup proceeds.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2908d778ab3e244900c310974e1fc1c69066e450 Version: 2908d778ab3e244900c310974e1fc1c69066e450 Version: 2908d778ab3e244900c310974e1fc1c69066e450 Version: 2908d778ab3e244900c310974e1fc1c69066e450 Version: 2908d778ab3e244900c310974e1fc1c69066e450 Version: 2908d778ab3e244900c310974e1fc1c69066e450 Version: 2908d778ab3e244900c310974e1fc1c69066e450 |
||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-71075",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-10T20:41:46.291525Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-11T18:44:15.965Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:43:41.884Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/scsi/aic94xx/aic94xx_init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c8f6f88cd1df35155258285c4f43268b361819df",
"status": "affected",
"version": "2908d778ab3e244900c310974e1fc1c69066e450",
"versionType": "git"
},
{
"lessThan": "278455a82245a572aeb218a6212a416a98e418de",
"status": "affected",
"version": "2908d778ab3e244900c310974e1fc1c69066e450",
"versionType": "git"
},
{
"lessThan": "b3e655e52b98a1d3df41c8e42035711e083099f8",
"status": "affected",
"version": "2908d778ab3e244900c310974e1fc1c69066e450",
"versionType": "git"
},
{
"lessThan": "e354793a7ab9bb0934ea699a9d57bcd1b48fc27b",
"status": "affected",
"version": "2908d778ab3e244900c310974e1fc1c69066e450",
"versionType": "git"
},
{
"lessThan": "a41dc180b6e1229ae49ca290ae14d82101c148c3",
"status": "affected",
"version": "2908d778ab3e244900c310974e1fc1c69066e450",
"versionType": "git"
},
{
"lessThan": "751c19635c2bfaaf2836a533caa3663633066dcf",
"status": "affected",
"version": "2908d778ab3e244900c310974e1fc1c69066e450",
"versionType": "git"
},
{
"lessThan": "f6ab594672d4cba08540919a4e6be2e202b60007",
"status": "affected",
"version": "2908d778ab3e244900c310974e1fc1c69066e450",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/scsi/aic94xx/aic94xx_init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.19"
},
{
"lessThan": "2.6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.248",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.198",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.160",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.120",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.64",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.248",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.198",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.160",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.120",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.64",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.3",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19",
"versionStartIncluding": "2.6.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: aic94xx: fix use-after-free in device removal path\n\nThe asd_pci_remove() function fails to synchronize with pending tasklets\nbefore freeing the asd_ha structure, leading to a potential\nuse-after-free vulnerability.\n\nWhen a device removal is triggered (via hot-unplug or module unload),\nrace condition can occur.\n\nThe fix adds tasklet_kill() before freeing the asd_ha structure,\nensuring all scheduled tasklets complete before cleanup proceeds."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T21:54:15.327Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c8f6f88cd1df35155258285c4f43268b361819df"
},
{
"url": "https://git.kernel.org/stable/c/278455a82245a572aeb218a6212a416a98e418de"
},
{
"url": "https://git.kernel.org/stable/c/b3e655e52b98a1d3df41c8e42035711e083099f8"
},
{
"url": "https://git.kernel.org/stable/c/e354793a7ab9bb0934ea699a9d57bcd1b48fc27b"
},
{
"url": "https://git.kernel.org/stable/c/a41dc180b6e1229ae49ca290ae14d82101c148c3"
},
{
"url": "https://git.kernel.org/stable/c/751c19635c2bfaaf2836a533caa3663633066dcf"
},
{
"url": "https://git.kernel.org/stable/c/f6ab594672d4cba08540919a4e6be2e202b60007"
}
],
"title": "scsi: aic94xx: fix use-after-free in device removal path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-71075",
"datePublished": "2026-01-13T15:31:28.075Z",
"dateReserved": "2026-01-13T15:30:19.647Z",
"dateUpdated": "2026-09-08T08:43:41.884Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64340 (GCVE-0-2026-64340)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: legousbtower: fix use-after-free on disconnect race
mutex_unlock() may access the mutex structure after releasing the lock
and therefore cannot be used to manage lifetime of objects directly
(unlike spinlocks and refcounts). [1][2]
Use a kref to release the driver data to avoid use-after-free in
mutex_unlock() when release() races with disconnect().
[1] a51749ab34d9 ("locking/mutex: Document that mutex_unlock() is
non-atomic")
[2] 2b9d9e0a9ba0 ("locking/mutex: Clarify that mutex_unlock(), and most
other sleeping locks, can still use the lock object
after it's unlocked")
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 18bcbcfe9ca2308ebffb40068b51803da9315d97 Version: 18bcbcfe9ca2308ebffb40068b51803da9315d97 Version: 18bcbcfe9ca2308ebffb40068b51803da9315d97 Version: 18bcbcfe9ca2308ebffb40068b51803da9315d97 Version: 18bcbcfe9ca2308ebffb40068b51803da9315d97 Version: 18bcbcfe9ca2308ebffb40068b51803da9315d97 Version: 18bcbcfe9ca2308ebffb40068b51803da9315d97 Version: 18bcbcfe9ca2308ebffb40068b51803da9315d97 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/legousbtower.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "11d069f85851997b4ea0adf242ed9672dc749b8f",
"status": "affected",
"version": "18bcbcfe9ca2308ebffb40068b51803da9315d97",
"versionType": "git"
},
{
"lessThan": "b4222c05066b252b451f9c8c4730b5b60824ea66",
"status": "affected",
"version": "18bcbcfe9ca2308ebffb40068b51803da9315d97",
"versionType": "git"
},
{
"lessThan": "6462de75d2e370c7e74dcfb7b4ae79eb5a6a55ee",
"status": "affected",
"version": "18bcbcfe9ca2308ebffb40068b51803da9315d97",
"versionType": "git"
},
{
"lessThan": "0b57e5ddbd89df3bc367463de3d2ca66f99a1a5e",
"status": "affected",
"version": "18bcbcfe9ca2308ebffb40068b51803da9315d97",
"versionType": "git"
},
{
"lessThan": "ab2bfd7bec4f134b377ec42f513e90c35db94160",
"status": "affected",
"version": "18bcbcfe9ca2308ebffb40068b51803da9315d97",
"versionType": "git"
},
{
"lessThan": "766738ecf2b819e54d38763c8d1c8ae6cff14b39",
"status": "affected",
"version": "18bcbcfe9ca2308ebffb40068b51803da9315d97",
"versionType": "git"
},
{
"lessThan": "9ba62966461a8e3cc593b62c56ec62eb2d80436d",
"status": "affected",
"version": "18bcbcfe9ca2308ebffb40068b51803da9315d97",
"versionType": "git"
},
{
"lessThan": "62fc8eb1b1481051f7bab4aa93d79809053dd09f",
"status": "affected",
"version": "18bcbcfe9ca2308ebffb40068b51803da9315d97",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/legousbtower.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: legousbtower: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is\n non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n other sleeping locks, can still use the lock object\n after it\u0027s unlocked\")"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:43.875Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/11d069f85851997b4ea0adf242ed9672dc749b8f"
},
{
"url": "https://git.kernel.org/stable/c/b4222c05066b252b451f9c8c4730b5b60824ea66"
},
{
"url": "https://git.kernel.org/stable/c/6462de75d2e370c7e74dcfb7b4ae79eb5a6a55ee"
},
{
"url": "https://git.kernel.org/stable/c/0b57e5ddbd89df3bc367463de3d2ca66f99a1a5e"
},
{
"url": "https://git.kernel.org/stable/c/ab2bfd7bec4f134b377ec42f513e90c35db94160"
},
{
"url": "https://git.kernel.org/stable/c/766738ecf2b819e54d38763c8d1c8ae6cff14b39"
},
{
"url": "https://git.kernel.org/stable/c/9ba62966461a8e3cc593b62c56ec62eb2d80436d"
},
{
"url": "https://git.kernel.org/stable/c/62fc8eb1b1481051f7bab4aa93d79809053dd09f"
}
],
"title": "USB: legousbtower: fix use-after-free on disconnect race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64340",
"datePublished": "2026-07-25T08:50:03.896Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:43.875Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43416 (GCVE-0-2026-43416)
Vulnerability from cvelistv5
Published
2026-05-08 14:21
Modified
2026-05-11 22:24
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
powerpc, perf: Check that current->mm is alive before getting user callchain
It may happen that mm is already released, which leads to kernel panic.
This adds the NULL check for current->mm, similarly to
commit 20afc60f892d ("x86, perf: Check that current->mm is alive before getting user callchain").
I was getting this panic when running a profiling BPF program
(profile.py from bcc-tools):
[26215.051935] Kernel attempted to read user page (588) - exploit attempt? (uid: 0)
[26215.051950] BUG: Kernel NULL pointer dereference on read at 0x00000588
[26215.051952] Faulting instruction address: 0xc00000000020fac0
[26215.051957] Oops: Kernel access of bad area, sig: 11 [#1]
[...]
[26215.052049] Call Trace:
[26215.052050] [c000000061da6d30] [c00000000020fc10] perf_callchain_user_64+0x2d0/0x490 (unreliable)
[26215.052054] [c000000061da6dc0] [c00000000020f92c] perf_callchain_user+0x1c/0x30
[26215.052057] [c000000061da6de0] [c0000000005ab2a0] get_perf_callchain+0x100/0x360
[26215.052063] [c000000061da6e70] [c000000000573bc8] bpf_get_stackid+0x88/0xf0
[26215.052067] [c000000061da6ea0] [c008000000042258] bpf_prog_16d4ab9ab662f669_do_perf_event+0xf8/0x274
[...]
In addition, move storing the top-level stack entry to generic
perf_callchain_user to make sure the top-evel entry is always captured,
even if current->mm is NULL.
[Maddy: fixed message to avoid checkpatch format style error]
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/powerpc/perf/callchain.c",
"arch/powerpc/perf/callchain_32.c",
"arch/powerpc/perf/callchain_64.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "98074e16742ae87fb82e234b419783c5ffc9baea",
"status": "affected",
"version": "20002ded4d937ca87aca6253b874920a96a763c4",
"versionType": "git"
},
{
"lessThan": "7e5f60b8cfc02a2b23a40a5f5fd2fa81d010e737",
"status": "affected",
"version": "20002ded4d937ca87aca6253b874920a96a763c4",
"versionType": "git"
},
{
"lessThan": "e9bbfb4bfa86c6b5515b868d6982ac60505d7e39",
"status": "affected",
"version": "20002ded4d937ca87aca6253b874920a96a763c4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/powerpc/perf/callchain.c",
"arch/powerpc/perf/callchain_32.c",
"arch/powerpc/perf/callchain_64.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.32"
},
{
"lessThan": "2.6.32",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.19",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.19",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.9",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "2.6.32",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc, perf: Check that current-\u003emm is alive before getting user callchain\n\nIt may happen that mm is already released, which leads to kernel panic.\nThis adds the NULL check for current-\u003emm, similarly to\ncommit 20afc60f892d (\"x86, perf: Check that current-\u003emm is alive before getting user callchain\").\n\nI was getting this panic when running a profiling BPF program\n(profile.py from bcc-tools):\n\n [26215.051935] Kernel attempted to read user page (588) - exploit attempt? (uid: 0)\n [26215.051950] BUG: Kernel NULL pointer dereference on read at 0x00000588\n [26215.051952] Faulting instruction address: 0xc00000000020fac0\n [26215.051957] Oops: Kernel access of bad area, sig: 11 [#1]\n [...]\n [26215.052049] Call Trace:\n [26215.052050] [c000000061da6d30] [c00000000020fc10] perf_callchain_user_64+0x2d0/0x490 (unreliable)\n [26215.052054] [c000000061da6dc0] [c00000000020f92c] perf_callchain_user+0x1c/0x30\n [26215.052057] [c000000061da6de0] [c0000000005ab2a0] get_perf_callchain+0x100/0x360\n [26215.052063] [c000000061da6e70] [c000000000573bc8] bpf_get_stackid+0x88/0xf0\n [26215.052067] [c000000061da6ea0] [c008000000042258] bpf_prog_16d4ab9ab662f669_do_perf_event+0xf8/0x274\n [...]\n\nIn addition, move storing the top-level stack entry to generic\nperf_callchain_user to make sure the top-evel entry is always captured,\neven if current-\u003emm is NULL.\n\n[Maddy: fixed message to avoid checkpatch format style error]"
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:24:10.050Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/98074e16742ae87fb82e234b419783c5ffc9baea"
},
{
"url": "https://git.kernel.org/stable/c/7e5f60b8cfc02a2b23a40a5f5fd2fa81d010e737"
},
{
"url": "https://git.kernel.org/stable/c/e9bbfb4bfa86c6b5515b868d6982ac60505d7e39"
}
],
"title": "powerpc, perf: Check that current-\u003emm is alive before getting user callchain",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43416",
"datePublished": "2026-05-08T14:21:52.954Z",
"dateReserved": "2026-05-01T14:12:56.008Z",
"dateUpdated": "2026-05-11T22:24:10.050Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64511 (GCVE-0-2026-64511)
Vulnerability from cvelistv5
Published
2026-07-25 08:52
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ACPI: NFIT: core: Fix possible NULL pointer dereference
After commit 9b311b7313d6 ("ACPI: NFIT: Install Notify() handler before
getting NFIT table"), acpi_nfit_probe() installs an ACPI notify handler
for the NFIT device before checking the presence of the NFIT table. If
that table is not there, 0 is returned without allocating the acpi_desc
object and setting the driver data pointer of the NFIT device. If the
platform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification
on the NFIT device at that point, acpi_nfit_uc_error_notify() will
dereference a NULL pointer.
Prevent that from occurring by adding an acpi_desc check against NULL
to acpi_nfit_uc_error_notify().
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/acpi/nfit/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a44343fe230aa48c74ef09830f3c5c90848b257e",
"status": "affected",
"version": "9b311b7313d6c104dd4a2d43ab54536dce07f960",
"versionType": "git"
},
{
"lessThan": "3c8f73b0fbdf956c98e2329d5aaea3ad09a9cfb6",
"status": "affected",
"version": "9b311b7313d6c104dd4a2d43ab54536dce07f960",
"versionType": "git"
},
{
"lessThan": "452945662fd8e9862a2d2043239c7ee1815d1ac4",
"status": "affected",
"version": "9b311b7313d6c104dd4a2d43ab54536dce07f960",
"versionType": "git"
},
{
"lessThan": "873576e585da5d0fc5debbab74eed565c0acea99",
"status": "affected",
"version": "9b311b7313d6c104dd4a2d43ab54536dce07f960",
"versionType": "git"
},
{
"lessThan": "027e128abb82788189d6d45b68e3e8e7329b67be",
"status": "affected",
"version": "9b311b7313d6c104dd4a2d43ab54536dce07f960",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/acpi/nfit/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: NFIT: core: Fix possible NULL pointer dereference\n\nAfter commit 9b311b7313d6 (\"ACPI: NFIT: Install Notify() handler before\ngetting NFIT table\"), acpi_nfit_probe() installs an ACPI notify handler\nfor the NFIT device before checking the presence of the NFIT table. If\nthat table is not there, 0 is returned without allocating the acpi_desc\nobject and setting the driver data pointer of the NFIT device. If the\nplatform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification\non the NFIT device at that point, acpi_nfit_uc_error_notify() will\ndereference a NULL pointer.\n\nPrevent that from occurring by adding an acpi_desc check against NULL\nto acpi_nfit_uc_error_notify()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:02.104Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a44343fe230aa48c74ef09830f3c5c90848b257e"
},
{
"url": "https://git.kernel.org/stable/c/3c8f73b0fbdf956c98e2329d5aaea3ad09a9cfb6"
},
{
"url": "https://git.kernel.org/stable/c/452945662fd8e9862a2d2043239c7ee1815d1ac4"
},
{
"url": "https://git.kernel.org/stable/c/873576e585da5d0fc5debbab74eed565c0acea99"
},
{
"url": "https://git.kernel.org/stable/c/027e128abb82788189d6d45b68e3e8e7329b67be"
}
],
"title": "ACPI: NFIT: core: Fix possible NULL pointer dereference",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64511",
"datePublished": "2026-07-25T08:52:03.818Z",
"dateReserved": "2026-07-19T15:36:31.793Z",
"dateUpdated": "2026-08-17T04:57:02.104Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53034 (GCVE-0-2026-53034)
Vulnerability from cvelistv5
Published
2026-06-24 16:29
Modified
2026-06-24 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix af_unix null-ptr-deref in proto update
unix_stream_connect() sets sk_state (`WRITE_ONCE(sk->sk_state,
TCP_ESTABLISHED)`) _before_ it assigns a peer (`unix_peer(sk) = newsk`).
sk_state == TCP_ESTABLISHED makes sock_map_sk_state_allowed() believe that
socket is properly set up, which would include having a defined peer. IOW,
there's a window when unix_stream_bpf_update_proto() can be called on
socket which still has unix_peer(sk) == NULL.
CPU0 bpf CPU1 connect
-------- ------------
WRITE_ONCE(sk->sk_state, TCP_ESTABLISHED)
sock_map_sk_state_allowed(sk)
...
sk_pair = unix_peer(sk)
sock_hold(sk_pair)
sock_hold(newsk)
smp_mb__after_atomic()
unix_peer(sk) = newsk
BUG: kernel NULL pointer dereference, address: 0000000000000080
RIP: 0010:unix_stream_bpf_update_proto+0xa0/0x1b0
Call Trace:
sock_map_link+0x564/0x8b0
sock_map_update_common+0x6e/0x340
sock_map_update_elem_sys+0x17d/0x240
__sys_bpf+0x26db/0x3250
__x64_sys_bpf+0x21/0x30
do_syscall_64+0x6b/0x3a0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
Initial idea was to move peer assignment _before_ the sk_state update[1],
but that involved an additional memory barrier, and changing the hot path
was rejected.
Then a NULL check during proto update in unix_stream_bpf_update_proto() was
considered[2], but the follow-up discussion[3] focused on the root cause,
i.e. sockmap update taking a wrong lock. Or, more specifically, missing
unix_state_lock()[4].
In the end it was concluded that teaching sockmap about the af_unix locking
would be unnecessarily complex[5].
Complexity aside, since BPF_PROG_TYPE_SCHED_CLS and BPF_PROG_TYPE_SCHED_ACT
are allowed to update sockmaps, sock_map_update_elem() taking the unix
lock, as it is currently implemented in unix_state_lock():
spin_lock(&unix_sk(s)->lock), would be problematic. unix_state_lock() taken
in a process context, followed by a softirq-context TC BPF program
attempting to take the same spinlock -- deadlock[6].
This way we circled back to the peer check idea[2].
[1]: https://lore.kernel.org/netdev/ba5c50aa-1df4-40c2-ab33-a72022c5a32e@rbox.co/
[2]: https://lore.kernel.org/netdev/20240610174906.32921-1-kuniyu@amazon.com/
[3]: https://lore.kernel.org/netdev/7603c0e6-cd5b-452b-b710-73b64bd9de26@linux.dev/
[4]: https://lore.kernel.org/netdev/CAAVpQUA+8GL_j63CaKb8hbxoL21izD58yr1NvhOhU=j+35+3og@mail.gmail.com/
[5]: https://lore.kernel.org/bpf/CAAVpQUAHijOMext28Gi10dSLuMzGYh+jK61Ujn+fZ-wvcODR2A@mail.gmail.com/
[6]: https://lore.kernel.org/bpf/dd043c69-4d03-46fe-8325-8f97101435cf@linux.dev/
Summary of scenarios where af_unix/stream connect() may race a sockmap
update:
1. connect() vs. bpf(BPF_MAP_UPDATE_ELEM), i.e. sock_map_update_elem_sys()
Implemented NULL check is sufficient. Once assigned, socket peer won't
be released until socket fd is released. And that's not an issue because
sock_map_update_elem_sys() bumps fd refcnf.
2. connect() vs BPF program doing update
Update restricted per verifier.c:may_update_sockmap() to
BPF_PROG_TYPE_TRACING/BPF_TRACE_ITER
BPF_PROG_TYPE_SOCK_OPS (bpf_sock_map_update() only)
BPF_PROG_TYPE_SOCKET_FILTER
BPF_PROG_TYPE_SCHED_CLS
BPF_PROG_TYPE_SCHED_ACT
BPF_PROG_TYPE_XDP
BPF_PROG_TYPE_SK_REUSEPORT
BPF_PROG_TYPE_FLOW_DISSECTOR
BPF_PROG_TYPE_SK_LOOKUP
Plus one more race to consider:
CPU0 bpf CPU1 connect
-------- ------------
WRITE_ONCE(sk->sk_state, TCP_ESTABLISHED)
sock_map_sk_state_allowed(sk)
sock_hold(newsk)
smp_mb__after_atomic()
---truncated---
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c63829182c37c2d6d0608976d15fa61ebebe9e6b Version: c63829182c37c2d6d0608976d15fa61ebebe9e6b Version: c63829182c37c2d6d0608976d15fa61ebebe9e6b Version: c63829182c37c2d6d0608976d15fa61ebebe9e6b Version: c63829182c37c2d6d0608976d15fa61ebebe9e6b Version: c63829182c37c2d6d0608976d15fa61ebebe9e6b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/unix/unix_bpf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "75b7d3b3f8bd4e59eb3af1b11a43c64c0c2db6f4",
"status": "affected",
"version": "c63829182c37c2d6d0608976d15fa61ebebe9e6b",
"versionType": "git"
},
{
"lessThan": "a94d3dd78ee8b63e6b8ad629081c952c93ee5a10",
"status": "affected",
"version": "c63829182c37c2d6d0608976d15fa61ebebe9e6b",
"versionType": "git"
},
{
"lessThan": "4913c94a3adcdbb64c552110c0c243cb1fdbb317",
"status": "affected",
"version": "c63829182c37c2d6d0608976d15fa61ebebe9e6b",
"versionType": "git"
},
{
"lessThan": "041eb6348d73ee5e15fc8161f1eac5a6e8289ca0",
"status": "affected",
"version": "c63829182c37c2d6d0608976d15fa61ebebe9e6b",
"versionType": "git"
},
{
"lessThan": "37bfcd164161b47d00b1c3bd20adc816a6977ce0",
"status": "affected",
"version": "c63829182c37c2d6d0608976d15fa61ebebe9e6b",
"versionType": "git"
},
{
"lessThan": "dca38b7734d2ea00af4818ff3ae836fab33d5d5a",
"status": "affected",
"version": "c63829182c37c2d6d0608976d15fa61ebebe9e6b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/unix/unix_bpf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix af_unix null-ptr-deref in proto update\n\nunix_stream_connect() sets sk_state (`WRITE_ONCE(sk-\u003esk_state,\nTCP_ESTABLISHED)`) _before_ it assigns a peer (`unix_peer(sk) = newsk`).\nsk_state == TCP_ESTABLISHED makes sock_map_sk_state_allowed() believe that\nsocket is properly set up, which would include having a defined peer. IOW,\nthere\u0027s a window when unix_stream_bpf_update_proto() can be called on\nsocket which still has unix_peer(sk) == NULL.\n\n CPU0 bpf CPU1 connect\n -------- ------------\n\n WRITE_ONCE(sk-\u003esk_state, TCP_ESTABLISHED)\nsock_map_sk_state_allowed(sk)\n...\nsk_pair = unix_peer(sk)\nsock_hold(sk_pair)\n sock_hold(newsk)\n smp_mb__after_atomic()\n unix_peer(sk) = newsk\n\nBUG: kernel NULL pointer dereference, address: 0000000000000080\nRIP: 0010:unix_stream_bpf_update_proto+0xa0/0x1b0\nCall Trace:\n sock_map_link+0x564/0x8b0\n sock_map_update_common+0x6e/0x340\n sock_map_update_elem_sys+0x17d/0x240\n __sys_bpf+0x26db/0x3250\n __x64_sys_bpf+0x21/0x30\n do_syscall_64+0x6b/0x3a0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nInitial idea was to move peer assignment _before_ the sk_state update[1],\nbut that involved an additional memory barrier, and changing the hot path\nwas rejected.\nThen a NULL check during proto update in unix_stream_bpf_update_proto() was\nconsidered[2], but the follow-up discussion[3] focused on the root cause,\ni.e. sockmap update taking a wrong lock. Or, more specifically, missing\nunix_state_lock()[4].\nIn the end it was concluded that teaching sockmap about the af_unix locking\nwould be unnecessarily complex[5].\nComplexity aside, since BPF_PROG_TYPE_SCHED_CLS and BPF_PROG_TYPE_SCHED_ACT\nare allowed to update sockmaps, sock_map_update_elem() taking the unix\nlock, as it is currently implemented in unix_state_lock():\nspin_lock(\u0026unix_sk(s)-\u003elock), would be problematic. unix_state_lock() taken\nin a process context, followed by a softirq-context TC BPF program\nattempting to take the same spinlock -- deadlock[6].\nThis way we circled back to the peer check idea[2].\n\n[1]: https://lore.kernel.org/netdev/ba5c50aa-1df4-40c2-ab33-a72022c5a32e@rbox.co/\n[2]: https://lore.kernel.org/netdev/20240610174906.32921-1-kuniyu@amazon.com/\n[3]: https://lore.kernel.org/netdev/7603c0e6-cd5b-452b-b710-73b64bd9de26@linux.dev/\n[4]: https://lore.kernel.org/netdev/CAAVpQUA+8GL_j63CaKb8hbxoL21izD58yr1NvhOhU=j+35+3og@mail.gmail.com/\n[5]: https://lore.kernel.org/bpf/CAAVpQUAHijOMext28Gi10dSLuMzGYh+jK61Ujn+fZ-wvcODR2A@mail.gmail.com/\n[6]: https://lore.kernel.org/bpf/dd043c69-4d03-46fe-8325-8f97101435cf@linux.dev/\n\nSummary of scenarios where af_unix/stream connect() may race a sockmap\nupdate:\n\n1. connect() vs. bpf(BPF_MAP_UPDATE_ELEM), i.e. sock_map_update_elem_sys()\n\n Implemented NULL check is sufficient. Once assigned, socket peer won\u0027t\n be released until socket fd is released. And that\u0027s not an issue because\n sock_map_update_elem_sys() bumps fd refcnf.\n\n2. connect() vs BPF program doing update\n\n Update restricted per verifier.c:may_update_sockmap() to\n\n BPF_PROG_TYPE_TRACING/BPF_TRACE_ITER\n BPF_PROG_TYPE_SOCK_OPS (bpf_sock_map_update() only)\n BPF_PROG_TYPE_SOCKET_FILTER\n BPF_PROG_TYPE_SCHED_CLS\n BPF_PROG_TYPE_SCHED_ACT\n BPF_PROG_TYPE_XDP\n BPF_PROG_TYPE_SK_REUSEPORT\n BPF_PROG_TYPE_FLOW_DISSECTOR\n BPF_PROG_TYPE_SK_LOOKUP\n\n Plus one more race to consider:\n\n CPU0 bpf CPU1 connect\n -------- ------------\n\n WRITE_ONCE(sk-\u003esk_state, TCP_ESTABLISHED)\n sock_map_sk_state_allowed(sk)\n sock_hold(newsk)\n smp_mb__after_atomic()\n \n---truncated---"
}
],
"providerMetadata": {
"dateUpdated": "2026-06-24T16:29:41.676Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/75b7d3b3f8bd4e59eb3af1b11a43c64c0c2db6f4"
},
{
"url": "https://git.kernel.org/stable/c/a94d3dd78ee8b63e6b8ad629081c952c93ee5a10"
},
{
"url": "https://git.kernel.org/stable/c/4913c94a3adcdbb64c552110c0c243cb1fdbb317"
},
{
"url": "https://git.kernel.org/stable/c/041eb6348d73ee5e15fc8161f1eac5a6e8289ca0"
},
{
"url": "https://git.kernel.org/stable/c/37bfcd164161b47d00b1c3bd20adc816a6977ce0"
},
{
"url": "https://git.kernel.org/stable/c/dca38b7734d2ea00af4818ff3ae836fab33d5d5a"
}
],
"title": "bpf, sockmap: Fix af_unix null-ptr-deref in proto update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53034",
"datePublished": "2026-06-24T16:29:41.676Z",
"dateReserved": "2026-06-09T07:44:35.380Z",
"dateUpdated": "2026-06-24T16:29:41.676Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63992 (GCVE-0-2026-63992)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
In some cases, iptunnel_pmtud_check_icmp() can be called while
skb transport header is not set.
This triggers an out-of-bound access, because
(typeof(skb->transport_header))~0U is 65535.
Access the icmp header based on IPv4 network header,
after making sure icmp->type is present in skb linear part.
Note that iptunnel_pmtud_check_icmpv6()) is fine.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4cb47a8644cc9eb8ec81190a50e79e6530d0297f Version: 4cb47a8644cc9eb8ec81190a50e79e6530d0297f Version: 4cb47a8644cc9eb8ec81190a50e79e6530d0297f Version: 4cb47a8644cc9eb8ec81190a50e79e6530d0297f Version: 4cb47a8644cc9eb8ec81190a50e79e6530d0297f Version: 4cb47a8644cc9eb8ec81190a50e79e6530d0297f Version: 4cb47a8644cc9eb8ec81190a50e79e6530d0297f Version: 4cb47a8644cc9eb8ec81190a50e79e6530d0297f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/ip_tunnel_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5a92cb45e34749865d03daf8d3500f77b5f6644c",
"status": "affected",
"version": "4cb47a8644cc9eb8ec81190a50e79e6530d0297f",
"versionType": "git"
},
{
"lessThan": "c7b7ec3e69e673c0d6b57f74d21da50c485c598e",
"status": "affected",
"version": "4cb47a8644cc9eb8ec81190a50e79e6530d0297f",
"versionType": "git"
},
{
"lessThan": "7f4f7efe7f30edd29c4988de01728bf2398217e4",
"status": "affected",
"version": "4cb47a8644cc9eb8ec81190a50e79e6530d0297f",
"versionType": "git"
},
{
"lessThan": "e917d0c69f01af2bb4fbea2b66d560a53b3ac7ec",
"status": "affected",
"version": "4cb47a8644cc9eb8ec81190a50e79e6530d0297f",
"versionType": "git"
},
{
"lessThan": "a096b6e34f602950af9a2b0856cd93a5f4c276d7",
"status": "affected",
"version": "4cb47a8644cc9eb8ec81190a50e79e6530d0297f",
"versionType": "git"
},
{
"lessThan": "43368636c663cff6e59dde93cf4b8e43ac28eb93",
"status": "affected",
"version": "4cb47a8644cc9eb8ec81190a50e79e6530d0297f",
"versionType": "git"
},
{
"lessThan": "cb549df9ce4ee15c9d5b19ddab12cf2128e4313c",
"status": "affected",
"version": "4cb47a8644cc9eb8ec81190a50e79e6530d0297f",
"versionType": "git"
},
{
"lessThan": "509323077ef79a26ba0c60bb556e45c12c398b2d",
"status": "affected",
"version": "4cb47a8644cc9eb8ec81190a50e79e6530d0297f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/ip_tunnel_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntunnels: do not assume transport header in iptunnel_pmtud_check_icmp()\n\nIn some cases, iptunnel_pmtud_check_icmp() can be called while\nskb transport header is not set.\n\nThis triggers an out-of-bound access, because\n(typeof(skb-\u003etransport_header))~0U is 65535.\n\nAccess the icmp header based on IPv4 network header,\nafter making sure icmp-\u003etype is present in skb linear part.\n\nNote that iptunnel_pmtud_check_icmpv6()) is fine."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code runs on the VXLAN/GENEVE transmit path when processing remotely received UDP-encapsulated tunnel traffic (or L2 frames forwarded through a bridge port), which is reachable by sending crafted packets over the network to the victim VTEP.\nAC:L - The attacker fully controls the inner IPv4 header fields (DF bit, length, addresses) and can reliably craft oversized packets that exceed the tunnel-adjusted PMTU on bridge-port tunnel devices without depending on race timing or uncontrollable system state.\nPR:N - Exploitation requires only the ability to send network packets to a host with VXLAN/GENEVE bridged; no local account, authentication, or capabilities on the victim are needed.\nUI:N - No victim user action is required; the kernel processes attacker-supplied packets automatically through the tunnel receive, bridge forward, and re-encapsulation path.\nS:U - The out-of-bounds read and resulting kernel oops occur within the kernel network stack on the same host; there is no crossing of a VM, container, or IOMMU security boundary beyond standard kernel memory safety failure.\nC:H - Reading through `icmp_hdr(skb)` when `transport_header` is unset causes an out-of-bounds read at `skb-\u003ehead + 65535`, potentially disclosing adjacent kernel memory beyond the skb buffer before any bounds checking occurs.\nI:N - The flaw is an out-of-bounds read of the ICMP type field; it does not directly modify or write kernel memory, though it may cause a kernel fault.\nA:H - The invalid pointer dereference at offset 65535 can trigger a kernel oops or panic when accessing unmapped memory, causing denial of service on the affected host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:55.661Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5a92cb45e34749865d03daf8d3500f77b5f6644c"
},
{
"url": "https://git.kernel.org/stable/c/c7b7ec3e69e673c0d6b57f74d21da50c485c598e"
},
{
"url": "https://git.kernel.org/stable/c/7f4f7efe7f30edd29c4988de01728bf2398217e4"
},
{
"url": "https://git.kernel.org/stable/c/e917d0c69f01af2bb4fbea2b66d560a53b3ac7ec"
},
{
"url": "https://git.kernel.org/stable/c/a096b6e34f602950af9a2b0856cd93a5f4c276d7"
},
{
"url": "https://git.kernel.org/stable/c/43368636c663cff6e59dde93cf4b8e43ac28eb93"
},
{
"url": "https://git.kernel.org/stable/c/cb549df9ce4ee15c9d5b19ddab12cf2128e4313c"
},
{
"url": "https://git.kernel.org/stable/c/509323077ef79a26ba0c60bb556e45c12c398b2d"
}
],
"title": "tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63992",
"datePublished": "2026-07-19T14:56:12.528Z",
"dateReserved": "2026-07-19T07:54:57.025Z",
"dateUpdated": "2026-08-05T12:37:55.661Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68133 (GCVE-0-2026-68133)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ice: fix PTP Call Trace during PTP release
If a PF reset occurs when the PTP state is ICE_PTP_UNINIT, then
ice_ptp_rebuild() will update the state to ICE_PTP_ERROR. This will
result in the following PTP release call trace during driver unload:
kernel BUG at lib/list_debug.c:52!
ice_ptp_release+0x332/0x3c0 [ice]
ice_deinit_features.part.0+0x10e/0x120 [ice]
ice_remove+0x100/0x220 [ice]
This was observed when passing PF1 through to a VM. ice_ptp_init()
fails because ctrl_pf is NULL and sets the state to ICE_PTP_UNINIT.
Fix by detecting the ICE_PTP_UNINIT state in ice_ptp_rebuild() and
returning without error, preventing the invalid state transition to
ICE_PTP_ERROR. The only valid path to ICE_PTP_ERROR is from
ICE_PTP_RESETTING after a failed rebuild.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/ice/ice_ptp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7d517b255f669cedd09830214d55f2f413b34481",
"status": "affected",
"version": "8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8",
"versionType": "git"
},
{
"lessThan": "e4406cbdd915f702d2ed9ee8b30683a16b06c6ac",
"status": "affected",
"version": "8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8",
"versionType": "git"
},
{
"lessThan": "14fceda28069fdbe1bb49cdb6e1774892b583348",
"status": "affected",
"version": "8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8",
"versionType": "git"
},
{
"lessThan": "f6a7e00b81e35ef1325234925f2fe1e53b466f92",
"status": "affected",
"version": "8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/ice/ice_ptp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix PTP Call Trace during PTP release\n\nIf a PF reset occurs when the PTP state is ICE_PTP_UNINIT, then\nice_ptp_rebuild() will update the state to ICE_PTP_ERROR. This will\nresult in the following PTP release call trace during driver unload:\n\n kernel BUG at lib/list_debug.c:52!\n ice_ptp_release+0x332/0x3c0 [ice]\n ice_deinit_features.part.0+0x10e/0x120 [ice]\n ice_remove+0x100/0x220 [ice]\n\nThis was observed when passing PF1 through to a VM. ice_ptp_init()\nfails because ctrl_pf is NULL and sets the state to ICE_PTP_UNINIT.\n\nFix by detecting the ICE_PTP_UNINIT state in ice_ptp_rebuild() and\nreturning without error, preventing the invalid state transition to\nICE_PTP_ERROR. The only valid path to ICE_PTP_ERROR is from\nICE_PTP_RESETTING after a failed rebuild."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:25.287Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7d517b255f669cedd09830214d55f2f413b34481"
},
{
"url": "https://git.kernel.org/stable/c/e4406cbdd915f702d2ed9ee8b30683a16b06c6ac"
},
{
"url": "https://git.kernel.org/stable/c/14fceda28069fdbe1bb49cdb6e1774892b583348"
},
{
"url": "https://git.kernel.org/stable/c/f6a7e00b81e35ef1325234925f2fe1e53b466f92"
}
],
"title": "ice: fix PTP Call Trace during PTP release",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68133",
"datePublished": "2026-08-10T11:58:56.223Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-17T04:59:25.287Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68152 (GCVE-0-2026-68152)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
amt: fix use-after-free in AMT delayed works
When an AMT device is removed, pending delayed works can still access
the freed amt_dev structure, which may result in kernel crashes or
memory corruption.
amt_dev_stop() cancels req_wq and discovery_wq with
cancel_delayed_work_sync(), but these works can be scheduled again
from event_wq after the cancellation. This allows delayed works to
access the freed amt_dev structure after the netdev has been released.
The following is a simple race scenario:
CPU0 CPU1
amt_dev_stop()
cancel_delayed_work_sync()
amt_event_work()
mod_delayed_work(req_wq)
free netdev
req_wq accesses freed amt_dev
Use disable_delayed_work_sync() in amt_dev_stop() to prevent req_wq and
discovery_wq from being queued again and wait for running work items
to complete.
The delayed works are disabled after initialization in
amt_newlink() and enabled only when the device is successfully opened.
This keeps the delayed work lifecycle synchronized with the lifetime
of the AMT device.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/amt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a46bfa01e01df0f6f6dc4b0be18db002d6d2dbd2",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "1a644db2cf59f164cdf3c75995bab5aadc097528",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "006340cf06881b6ff49767d8b6f3c4f7b892670c",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "ea20c44935d6142daecfa9b39d635033a7553e1b",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/amt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\namt: fix use-after-free in AMT delayed works\n\nWhen an AMT device is removed, pending delayed works can still access\nthe freed amt_dev structure, which may result in kernel crashes or\nmemory corruption.\n\namt_dev_stop() cancels req_wq and discovery_wq with\ncancel_delayed_work_sync(), but these works can be scheduled again\nfrom event_wq after the cancellation. This allows delayed works to\naccess the freed amt_dev structure after the netdev has been released.\n\nThe following is a simple race scenario:\n\nCPU0 CPU1\n\namt_dev_stop()\ncancel_delayed_work_sync()\n amt_event_work()\n mod_delayed_work(req_wq)\nfree netdev\n req_wq accesses freed amt_dev\n\nUse disable_delayed_work_sync() in amt_dev_stop() to prevent req_wq and\ndiscovery_wq from being queued again and wait for running work items\nto complete.\n\nThe delayed works are disabled after initialization in\namt_newlink() and enabled only when the device is successfully opened.\nThis keeps the delayed work lifecycle synchronized with the lifetime\nof the AMT device."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires triggering amt_dev_stop() via local rtnetlink (RTM_DELLINK/ip link del) or ndo_stop on an AMT gateway netdev; the UAF race in teardown is not reachable by remote UDP alone without this privileged local device-removal path.\nAC:L - The attacker controls both sides of the race by concurrently deleting/bringing down the AMT interface while flooding AMT UDP packets or letting discovery/request timers fire, reliably re-queuing req_wq/discovery_wq via amt_event_work during the cancel_work_sync window.\nPR:L - Creating, opening, and removing AMT virtual interfaces requires CAP_NET_ADMIN via rtnetlink, which unprivileged users can obtain inside a user network namespace (unshare -Urn), but not without any privileges at all.\nUI:N - No victim user interaction is required; a single attacker with namespace CAP_NET_ADMIN can create an AMT gateway, bring it up, and race interface teardown against self-generated AMT traffic or delayed-work events.\nS:U - Successful exploitation corrupts kernel heap memory and can escalate privileges within the same kernel, but does not inherently cross VM, container, or IOMMU security boundaries into a separate authority domain.\nC:H - Use-after-free of the amt_dev structure embedded in netdev private data allows accessing attacker-influenced freed heap memory, enabling arbitrary kernel memory disclosure through standard UAF exploitation techniques.\nI:H - The UAF on amt_dev delayed-work handlers can corrupt kernel heap metadata and adjacent objects, providing primitives for arbitrary kernel memory writes and potential code execution as acknowledged in the fix commit.\nA:H - Use-after-free in amt_req_work/amt_discovery_work accessing freed amt_dev during netdev teardown can cause kernel oops, panic, or hang, and the fix commit explicitly warns of kernel crashes and memory corruption."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:47.614Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a46bfa01e01df0f6f6dc4b0be18db002d6d2dbd2"
},
{
"url": "https://git.kernel.org/stable/c/1a644db2cf59f164cdf3c75995bab5aadc097528"
},
{
"url": "https://git.kernel.org/stable/c/006340cf06881b6ff49767d8b6f3c4f7b892670c"
},
{
"url": "https://git.kernel.org/stable/c/ea20c44935d6142daecfa9b39d635033a7553e1b"
}
],
"title": "amt: fix use-after-free in AMT delayed works",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68152",
"datePublished": "2026-08-10T11:59:18.270Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-17T04:59:47.614Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68354 (GCVE-0-2026-68354)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
firewire: net: Fix fragmented datagram reassembly
fwnet_frag_new() keeps a sorted list of received fragments for a partial
datagram. When a new fragment is adjacent to an existing fragment, the
code checks whether the new fragment also closes the gap to the next or
previous list entry.
Those neighbor lookups currently assume that the current fragment always
has a real next or previous fragment. At a list edge, the next or
previous entry is the list head, not a struct fwnet_fragment_info.
The gap checks also compare against the old edge of the current fragment
instead of the edge after adding the new fragment. As a result, a
fragment that bridges two existing ranges may leave two adjacent ranges
unmerged, so fwnet_pd_is_complete() can miss a complete datagram.
Check for the list head before looking up the neighboring fragment, and
compare the neighbor against the new fragment's far edge when deciding
whether to merge all three ranges.
This issue was found by a static analysis checker and confirmed by
manual source review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/firewire/net.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1aaf16031d65ccd4576451a79f7dabbec994c111",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "0a219b2a01b4fe93706717e3bcacf7f62967b26f",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "268cea3800eda5fa3ee04a49ee2973b8766a8df3",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "b7d633c7c92321be98724b1d365e8ce507f2f349",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "22e05b8ddbcf7d22c7f1598786e86635547e554d",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "0177e578d7a885037b0fb82286c12e9d0360cc10",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "d52a13adbb8ccbab99cd3bad36804e87d8b5c052",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/firewire/net.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.31"
},
{
"lessThan": "2.6.31",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.31",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: net: Fix fragmented datagram reassembly\n\nfwnet_frag_new() keeps a sorted list of received fragments for a partial\ndatagram. When a new fragment is adjacent to an existing fragment, the\ncode checks whether the new fragment also closes the gap to the next or\nprevious list entry.\n\nThose neighbor lookups currently assume that the current fragment always\nhas a real next or previous fragment. At a list edge, the next or\nprevious entry is the list head, not a struct fwnet_fragment_info.\n\nThe gap checks also compare against the old edge of the current fragment\ninstead of the edge after adding the new fragment. As a result, a\nfragment that bridges two existing ranges may leave two adjacent ranges\nunmerged, so fwnet_pd_is_complete() can miss a complete datagram.\n\nCheck for the list head before looking up the neighboring fragment, and\ncompare the neighbor against the new fragment\u0027s far edge when deciding\nwhether to merge all three ranges.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable reassembly code processes IP-over-1394 (RFC 2734) fragments arriving from another node on the shared IEEE 1394 bus via fwnet_receive_packet/fwnet_receive_broadcast -\u003e fwnet_incoming_packet -\u003e fwnet_pd_update -\u003e fwnet_frag_new, matching this CNA\u0027s Adjacent shared-physical-segment model for FireWire (CVE-2023-53432, CVE-2024-50113).\nAC:L - The attacker fully controls fg_off, dg_size and fragment ordering (12-bit fields, 0-4095) and can create unlimited fresh partial datagrams, so they can sweep every boundary offset against the aliased pd-\u003eskb bits and groom skb allocation until the type-confused compare matches; once it does, the list-head corruption and misaligned kfree are deterministic, with no attacker-uncontrollable race involved.\nPR:N - fwnet_receive_packet accepts TCODE_WRITE_BLOCK_REQUEST payloads from any bus peer and fwnet_receive_broadcast processes GASP packets automatically, with no credentials, capability check, or authentication anywhere on the path to fwnet_frag_new.\nUI:N - Fragment reassembly runs entirely in FireWire IRQ/softirq context once the firewire-net interface is up; the attacker\u0027s own node supplies the fragments and no victim action such as opening, mounting, or clicking is needed.\nS:U - The corruption is confined to kernel slab objects (fwnet_partial_datagram, sk_buff) under the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - list_entry() on the list head reads the low 32 bits of pd-\u003eskb as fragment metadata (a kernel-pointer disclosure primitive), the missed merge lets fwnet_pd_is_complete() hand up an skb whose unwritten gaps contain uninitialized heap data, and the resulting slab freelist corruption from kfree() of an interior pointer yields overlapping objects usable for arbitrary kernel memory read.\nI:H - The prepend branch performs fi2-\u003elen += fi-\u003elen + len directly into bits 16-31 of pd-\u003eskb, giving a partially attacker-influenced write to a kernel pointer that is later passed to dev_kfree_skb_any() (arbitrary free), while the append branch\u0027s kfree() of pd+16 corrupts the SLUB freelist into attacker-groomable overlapping allocations - both classic control-flow-hijack primitives.\nA:H - list_del() on the list head leaves pd-\u003efi_list poisoned, and the immediately following fwnet_pd_is_complete() dereferences LIST_POISON1 in interrupt context while holding dev-\u003elock with IRQs disabled, oopsing or hanging the machine; the misaligned kfree() also trips slab debug BUGs, and a bus peer can repeat the packet flood to crash the system at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:00.740Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1aaf16031d65ccd4576451a79f7dabbec994c111"
},
{
"url": "https://git.kernel.org/stable/c/0a219b2a01b4fe93706717e3bcacf7f62967b26f"
},
{
"url": "https://git.kernel.org/stable/c/268cea3800eda5fa3ee04a49ee2973b8766a8df3"
},
{
"url": "https://git.kernel.org/stable/c/b7d633c7c92321be98724b1d365e8ce507f2f349"
},
{
"url": "https://git.kernel.org/stable/c/22e05b8ddbcf7d22c7f1598786e86635547e554d"
},
{
"url": "https://git.kernel.org/stable/c/0177e578d7a885037b0fb82286c12e9d0360cc10"
},
{
"url": "https://git.kernel.org/stable/c/2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999"
},
{
"url": "https://git.kernel.org/stable/c/d52a13adbb8ccbab99cd3bad36804e87d8b5c052"
}
],
"title": "firewire: net: Fix fragmented datagram reassembly",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68354",
"datePublished": "2026-08-10T12:03:31.348Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:00.740Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52929 (GCVE-0-2026-52929)
Vulnerability from cvelistv5
Published
2026-06-24 07:14
Modified
2026-08-05 12:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: stream: fully roll back denied add-stream state
When ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and
then lowers outcnt. That leaves removed stream metadata behind, so a
later re-add can reuse a stale ext and hit a null-pointer dereference in
the scheduler get path.
Fix the rollback by tearing down the removed stream state the same way
other stream resizes do. Unschedule the current scheduler state, drop
the removed stream ext state with sctp_stream_outq_migrate(), and then
reschedule the remaining streams.
This keeps scheduler-private RR/FC/PRIO lists consistent while fully
rolling back denied outgoing stream additions.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 637784ade221a3c8a7ecd0f583eddd95d6276b9a Version: 637784ade221a3c8a7ecd0f583eddd95d6276b9a Version: 637784ade221a3c8a7ecd0f583eddd95d6276b9a Version: 637784ade221a3c8a7ecd0f583eddd95d6276b9a Version: 637784ade221a3c8a7ecd0f583eddd95d6276b9a Version: 637784ade221a3c8a7ecd0f583eddd95d6276b9a Version: 637784ade221a3c8a7ecd0f583eddd95d6276b9a Version: 637784ade221a3c8a7ecd0f583eddd95d6276b9a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/stream.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0cd2dc6dce8ca47212cd306ccd52eb315ef3cf85",
"status": "affected",
"version": "637784ade221a3c8a7ecd0f583eddd95d6276b9a",
"versionType": "git"
},
{
"lessThan": "a6724b7b812ac8793514a1d5938db5d9d29ae725",
"status": "affected",
"version": "637784ade221a3c8a7ecd0f583eddd95d6276b9a",
"versionType": "git"
},
{
"lessThan": "9662eb0401518f0b4681f10e7fbf688f504f24cf",
"status": "affected",
"version": "637784ade221a3c8a7ecd0f583eddd95d6276b9a",
"versionType": "git"
},
{
"lessThan": "7dd9a42b044aad2dbe037db1c1e2943582485b44",
"status": "affected",
"version": "637784ade221a3c8a7ecd0f583eddd95d6276b9a",
"versionType": "git"
},
{
"lessThan": "39dc2b0eb5371a669ebc9ec6072b9184eac95418",
"status": "affected",
"version": "637784ade221a3c8a7ecd0f583eddd95d6276b9a",
"versionType": "git"
},
{
"lessThan": "d5ea0b3e261fcb2cfff142675516165244cab1da",
"status": "affected",
"version": "637784ade221a3c8a7ecd0f583eddd95d6276b9a",
"versionType": "git"
},
{
"lessThan": "1c6773b8c081509dcd5cd2954f2b02c50c00f151",
"status": "affected",
"version": "637784ade221a3c8a7ecd0f583eddd95d6276b9a",
"versionType": "git"
},
{
"lessThan": "a5f8a90ac9f77c678a9781c0a464b635e0d63e49",
"status": "affected",
"version": "637784ade221a3c8a7ecd0f583eddd95d6276b9a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/stream.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: stream: fully roll back denied add-stream state\n\nWhen ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and\nthen lowers outcnt. That leaves removed stream metadata behind, so a\nlater re-add can reuse a stale ext and hit a null-pointer dereference in\nthe scheduler get path.\n\nFix the rollback by tearing down the removed stream state the same way\nother stream resizes do. Unschedule the current scheduler state, drop\nthe removed stream ext state with sctp_stream_outq_migrate(), and then\nreschedule the remaining streams.\n\nThis keeps scheduler-private RR/FC/PRIO lists consistent while fully\nrolling back denied outgoing stream additions."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code is reached while processing an SCTP RE-CONFIG response chunk received from a remote SCTP peer on an established association. A malicious peer can send a denied ADD_OUT_STREAMS response over the network once stream reconfiguration is negotiated.\nAC:L - The packet/state sequence is protocol-controlled and reproducible: negotiate SCTP RE-CONFIG, trigger an ADD_OUT_STREAMS request, deny it, then cause later reuse of the stale stream state. Although RE-CONFIG must be enabled by the application, there is no race or condition outside the attacker\u0027s reasonable influence in a deployment using this feature.\nPR:N - A remote SCTP peer does not need local kernel privileges or authenticated OS privileges to send the denial response. The path is gated by SCTP association state, verification tag, and matching outstanding request sequence, not by credentials.\nUI:N - No human user interaction is required once the SCTP service/association is operating with stream reconfiguration. The triggering input is network protocol traffic from the peer.\nS:U - The vulnerability affects kernel SCTP state within the same host security authority. It does not cross a VM, IOMMU, or other separate authorization boundary.\nC:N - The investigated failure mode is stale SCTP stream scheduler metadata leading to a NULL pointer dereference in scheduler value retrieval. I did not find evidence of an attacker-controlled memory read or information disclosure primitive.\nI:N - The bug leaves scheduler-private stream state inconsistent but the demonstrated impact is a NULL dereference/crash, not controlled data modification or code execution. No arbitrary write primitive was evident from the rollback path.\nA:H - The stale stream extension state can lead to a kernel NULL pointer dereference/oops in the SCTP scheduler path. A remotely reachable kernel crash is a high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:31:47.863Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0cd2dc6dce8ca47212cd306ccd52eb315ef3cf85"
},
{
"url": "https://git.kernel.org/stable/c/a6724b7b812ac8793514a1d5938db5d9d29ae725"
},
{
"url": "https://git.kernel.org/stable/c/9662eb0401518f0b4681f10e7fbf688f504f24cf"
},
{
"url": "https://git.kernel.org/stable/c/7dd9a42b044aad2dbe037db1c1e2943582485b44"
},
{
"url": "https://git.kernel.org/stable/c/39dc2b0eb5371a669ebc9ec6072b9184eac95418"
},
{
"url": "https://git.kernel.org/stable/c/d5ea0b3e261fcb2cfff142675516165244cab1da"
},
{
"url": "https://git.kernel.org/stable/c/1c6773b8c081509dcd5cd2954f2b02c50c00f151"
},
{
"url": "https://git.kernel.org/stable/c/a5f8a90ac9f77c678a9781c0a464b635e0d63e49"
}
],
"title": "sctp: stream: fully roll back denied add-stream state",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52929",
"datePublished": "2026-06-24T07:14:22.020Z",
"dateReserved": "2026-06-09T07:44:35.368Z",
"dateUpdated": "2026-08-05T12:31:47.863Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68407 (GCVE-0-2026-68407)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: nl80211: free RNR data on MBSSID mismatch
nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR
entries than MBSSID entries.
The rejected RNR allocation has not been attached to the beacon data yet,
so free it before returning the error.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 56189d7bc30531def6b999f27940ee43c6ff2569 Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: 6.1.160 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4b76fc30c80b240107a7de3c7560113c9290eafc",
"status": "affected",
"version": "56189d7bc30531def6b999f27940ee43c6ff2569",
"versionType": "git"
},
{
"lessThan": "fa9592ef7de11f8c7042315d9bc20e91a97f679e",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "312c8b9d7836ef58e552619a8c19be08b04032bb",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "fb052a6e2fa866384d8edc237746583ec94c15af",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "6f919f29e9b75793104709987131b8d910d7800a",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "07a95ec2b54774201fdf4ef7ffb0ca2ab19ed29c",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.160",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.160",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: free RNR data on MBSSID mismatch\n\nnl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR\nentries than MBSSID entries.\n\nThe rejected RNR allocation has not been attached to the beacon data yet,\nso free it before returning the error."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:02.178Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4b76fc30c80b240107a7de3c7560113c9290eafc"
},
{
"url": "https://git.kernel.org/stable/c/fa9592ef7de11f8c7042315d9bc20e91a97f679e"
},
{
"url": "https://git.kernel.org/stable/c/312c8b9d7836ef58e552619a8c19be08b04032bb"
},
{
"url": "https://git.kernel.org/stable/c/fb052a6e2fa866384d8edc237746583ec94c15af"
},
{
"url": "https://git.kernel.org/stable/c/6f919f29e9b75793104709987131b8d910d7800a"
},
{
"url": "https://git.kernel.org/stable/c/07a95ec2b54774201fdf4ef7ffb0ca2ab19ed29c"
}
],
"title": "wifi: nl80211: free RNR data on MBSSID mismatch",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68407",
"datePublished": "2026-08-10T12:04:27.252Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:35:02.178Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64604 (GCVE-0-2026-64604)
Vulnerability from cvelistv5
Published
2026-08-06 07:13
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
When updating CR8 intercepts, get vmcs12 if and only if the vCPU is in
guest mode so that a future change can have update CR8 intercepts during
vCPU creation, without running afoul of get_vmcs12()'s lockdep assertion.
------------[ cut here ]------------
debug_locks && !(lock_is_held(&(&vcpu->mutex)->dep_map) || !refcount_read(&vcpu->kvm->users_count))
WARNING: arch/x86/kvm/vmx/nested.h:61 at get_vmcs12 arch/x86/kvm/vmx/nested.h:60 [inline], CPU#0: syz.2.19/5879
WARNING: arch/x86/kvm/vmx/nested.h:61 at vmx_update_cr8_intercept+0x3de/0x4e0 arch/x86/kvm/vmx/vmx.c:6879, CPU#0: syz.2.19/5879
Modules linked in:
CPU: 0 UID: 0 PID: 5879 Comm: syz.2.19 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
RIP: 0010:get_vmcs12 arch/x86/kvm/vmx/nested.h:60 [inline]
RIP: 0010:vmx_update_cr8_intercept+0x3de/0x4e0 arch/x86/kvm/vmx/vmx.c:6879
Call Trace:
<TASK>
apic_update_ppr arch/x86/kvm/lapic.c:984 [inline]
kvm_lapic_reset+0x1c24/0x2980 arch/x86/kvm/lapic.c:3023
kvm_vcpu_reset+0x44c/0x1bf0 arch/x86/kvm/x86.c:12986
kvm_arch_vcpu_create+0x746/0x8b0 arch/x86/kvm/x86.c:12847
kvm_vm_ioctl_create_vcpu+0x428/0x930 virt/kvm/kvm_main.c:4201
kvm_vm_ioctl+0x893/0xd50 virt/kvm/kvm_main.c:5159
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:597 [inline]
__se_sys_ioctl+0xfc/0x170 fs/ioctl.c:583
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
No functional change intended.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a7c0b07d570848e50fce4d31ac01313484d6b844 Version: a7c0b07d570848e50fce4d31ac01313484d6b844 Version: a7c0b07d570848e50fce4d31ac01313484d6b844 Version: a7c0b07d570848e50fce4d31ac01313484d6b844 Version: a7c0b07d570848e50fce4d31ac01313484d6b844 Version: a7c0b07d570848e50fce4d31ac01313484d6b844 Version: a7c0b07d570848e50fce4d31ac01313484d6b844 Version: a7c0b07d570848e50fce4d31ac01313484d6b844 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/vmx/vmx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c7cd3605244c924249dea32632e1bc3e89bda543",
"status": "affected",
"version": "a7c0b07d570848e50fce4d31ac01313484d6b844",
"versionType": "git"
},
{
"lessThan": "9a21f1defd96c6301c5fb462a78eb51b191bd2dd",
"status": "affected",
"version": "a7c0b07d570848e50fce4d31ac01313484d6b844",
"versionType": "git"
},
{
"lessThan": "570af5db081b87374594a00711ac5760d2ea6844",
"status": "affected",
"version": "a7c0b07d570848e50fce4d31ac01313484d6b844",
"versionType": "git"
},
{
"lessThan": "ffaaff82336db84e9b58e7a3e81c2fd64e05ed7a",
"status": "affected",
"version": "a7c0b07d570848e50fce4d31ac01313484d6b844",
"versionType": "git"
},
{
"lessThan": "258ec63c0f281bf7b50f9de67c8e93b5b7be5ed4",
"status": "affected",
"version": "a7c0b07d570848e50fce4d31ac01313484d6b844",
"versionType": "git"
},
{
"lessThan": "3dcfb04dd43b16fa1240fc6487fff578ad57264c",
"status": "affected",
"version": "a7c0b07d570848e50fce4d31ac01313484d6b844",
"versionType": "git"
},
{
"lessThan": "db8407b9fd06d857a4a5e8bcff1d086d13007711",
"status": "affected",
"version": "a7c0b07d570848e50fce4d31ac01313484d6b844",
"versionType": "git"
},
{
"lessThan": "7ef78d71ca713d8c00f7c34ddcf276c808143f77",
"status": "affected",
"version": "a7c0b07d570848e50fce4d31ac01313484d6b844",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/vmx/vmx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"lessThan": "3.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode\n\nWhen updating CR8 intercepts, get vmcs12 if and only if the vCPU is in\nguest mode so that a future change can have update CR8 intercepts during\nvCPU creation, without running afoul of get_vmcs12()\u0027s lockdep assertion.\n\n ------------[ cut here ]------------\n debug_locks \u0026\u0026 !(lock_is_held(\u0026(\u0026vcpu-\u003emutex)-\u003edep_map) || !refcount_read(\u0026vcpu-\u003ekvm-\u003eusers_count))\n WARNING: arch/x86/kvm/vmx/nested.h:61 at get_vmcs12 arch/x86/kvm/vmx/nested.h:60 [inline], CPU#0: syz.2.19/5879\n WARNING: arch/x86/kvm/vmx/nested.h:61 at vmx_update_cr8_intercept+0x3de/0x4e0 arch/x86/kvm/vmx/vmx.c:6879, CPU#0: syz.2.19/5879\n Modules linked in:\n CPU: 0 UID: 0 PID: 5879 Comm: syz.2.19 Not tainted syzkaller #0 PREEMPT(full)\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014\n RIP: 0010:get_vmcs12 arch/x86/kvm/vmx/nested.h:60 [inline]\n RIP: 0010:vmx_update_cr8_intercept+0x3de/0x4e0 arch/x86/kvm/vmx/vmx.c:6879\n Call Trace:\n \u003cTASK\u003e\n apic_update_ppr arch/x86/kvm/lapic.c:984 [inline]\n kvm_lapic_reset+0x1c24/0x2980 arch/x86/kvm/lapic.c:3023\n kvm_vcpu_reset+0x44c/0x1bf0 arch/x86/kvm/x86.c:12986\n kvm_arch_vcpu_create+0x746/0x8b0 arch/x86/kvm/x86.c:12847\n kvm_vm_ioctl_create_vcpu+0x428/0x930 virt/kvm/kvm_main.c:4201\n kvm_vm_ioctl+0x893/0xd50 virt/kvm/kvm_main.c:5159\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:597 [inline]\n __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:583\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n \u003c/TASK\u003e\n\nNo functional change intended."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:27.506Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c7cd3605244c924249dea32632e1bc3e89bda543"
},
{
"url": "https://git.kernel.org/stable/c/9a21f1defd96c6301c5fb462a78eb51b191bd2dd"
},
{
"url": "https://git.kernel.org/stable/c/570af5db081b87374594a00711ac5760d2ea6844"
},
{
"url": "https://git.kernel.org/stable/c/ffaaff82336db84e9b58e7a3e81c2fd64e05ed7a"
},
{
"url": "https://git.kernel.org/stable/c/258ec63c0f281bf7b50f9de67c8e93b5b7be5ed4"
},
{
"url": "https://git.kernel.org/stable/c/3dcfb04dd43b16fa1240fc6487fff578ad57264c"
},
{
"url": "https://git.kernel.org/stable/c/db8407b9fd06d857a4a5e8bcff1d086d13007711"
},
{
"url": "https://git.kernel.org/stable/c/7ef78d71ca713d8c00f7c34ddcf276c808143f77"
}
],
"title": "KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64604",
"datePublished": "2026-08-06T07:13:55.718Z",
"dateReserved": "2026-07-19T15:36:31.799Z",
"dateUpdated": "2026-08-17T04:58:27.506Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64484 (GCVE-0-2026-64484)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: es1938: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails.
snd_es1938_mixer() does not check the return value before dereferencing
the pointer, which can lead to a NULL pointer dereference.
Add a NULL check after snd_ctl_new1() and return -ENOMEM if it fails.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/pci/es1938.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "96cad5bd7d0a176db3fdc06717a41271247336bd",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6c4efebaf73e217efbd08cdbda805758a7db3680",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "41759affbcfe3d51a32900da9547a1ffd744a85f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7531a37720c2545a480fd0fa464978569bf9d6a2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "af01c48e17a66fa038af210a5c49d6cdefd210bd",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9e53e99b6fa3cd82992d963cbff58dbbd1df8651",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1949163dee39e0e4a1468f37dd7302962f6af45a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1edd1f02dddd20aeb6066ded41017615766ea42f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/pci/es1938.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: es1938: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_es1938_mixer() does not check the return value before dereferencing\nthe pointer, which can lead to a NULL pointer dereference.\n\nAdd a NULL check after snd_ctl_new1() and return -ENOMEM if it fails."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:31.383Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/96cad5bd7d0a176db3fdc06717a41271247336bd"
},
{
"url": "https://git.kernel.org/stable/c/6c4efebaf73e217efbd08cdbda805758a7db3680"
},
{
"url": "https://git.kernel.org/stable/c/41759affbcfe3d51a32900da9547a1ffd744a85f"
},
{
"url": "https://git.kernel.org/stable/c/7531a37720c2545a480fd0fa464978569bf9d6a2"
},
{
"url": "https://git.kernel.org/stable/c/af01c48e17a66fa038af210a5c49d6cdefd210bd"
},
{
"url": "https://git.kernel.org/stable/c/9e53e99b6fa3cd82992d963cbff58dbbd1df8651"
},
{
"url": "https://git.kernel.org/stable/c/1949163dee39e0e4a1468f37dd7302962f6af45a"
},
{
"url": "https://git.kernel.org/stable/c/1edd1f02dddd20aeb6066ded41017615766ea42f"
}
],
"title": "ALSA: es1938: check snd_ctl_new1() return value",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64484",
"datePublished": "2026-07-25T08:51:44.591Z",
"dateReserved": "2026-07-19T15:36:31.791Z",
"dateUpdated": "2026-08-17T04:56:31.383Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64010 (GCVE-0-2026-64010)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
A race condition exists in the NFC LLCP connection state machine where
the connection acceptance packet (CC) can be processed concurrently with
socket release. This can lead to a use-after-free of the socket object.
When nfc_llcp_recv_cc() moves the socket from the connecting_sockets
list to the sockets list, it does so without holding the socket lock.
If llcp_sock_release() is executing concurrently, it might have already
unlinked the socket and dropped its references, which can result in
nfc_llcp_recv_cc() linking a freed socket into the live list.
Fix this by holding lock_sock() during the state transition and list
movement in nfc_llcp_recv_cc(). After acquiring the lock, check if
the socket is still hashed to ensure it hasn't already been unlinked
and marked for destruction by the release path. This aligns the locking
pattern with recv_hdlc() and recv_disc().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a69f32af86e389dd232b1bb2269e202c1bfcc60f Version: a69f32af86e389dd232b1bb2269e202c1bfcc60f Version: a69f32af86e389dd232b1bb2269e202c1bfcc60f Version: a69f32af86e389dd232b1bb2269e202c1bfcc60f Version: a69f32af86e389dd232b1bb2269e202c1bfcc60f Version: a69f32af86e389dd232b1bb2269e202c1bfcc60f Version: a69f32af86e389dd232b1bb2269e202c1bfcc60f Version: a69f32af86e389dd232b1bb2269e202c1bfcc60f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dce85215a6c7b0fd753f577a4c487f647119884c",
"status": "affected",
"version": "a69f32af86e389dd232b1bb2269e202c1bfcc60f",
"versionType": "git"
},
{
"lessThan": "bd08bb7443c501d2f2a71d529e4afcf11c9b07d2",
"status": "affected",
"version": "a69f32af86e389dd232b1bb2269e202c1bfcc60f",
"versionType": "git"
},
{
"lessThan": "0b45c31746e1523d5d482fda8fcf54a35ac417f1",
"status": "affected",
"version": "a69f32af86e389dd232b1bb2269e202c1bfcc60f",
"versionType": "git"
},
{
"lessThan": "ee2d1a8a1833c5e56e9a1745e64b0b4edda732c2",
"status": "affected",
"version": "a69f32af86e389dd232b1bb2269e202c1bfcc60f",
"versionType": "git"
},
{
"lessThan": "ad8a27d63cac96bac441edd002209ebd996e12fb",
"status": "affected",
"version": "a69f32af86e389dd232b1bb2269e202c1bfcc60f",
"versionType": "git"
},
{
"lessThan": "650bdd8fdfab64a09ee474150313dbc48c374795",
"status": "affected",
"version": "a69f32af86e389dd232b1bb2269e202c1bfcc60f",
"versionType": "git"
},
{
"lessThan": "b2a60f7f846faaf5c2cdad4ea6d3a33e5f863183",
"status": "affected",
"version": "a69f32af86e389dd232b1bb2269e202c1bfcc60f",
"versionType": "git"
},
{
"lessThan": "b493ea2765cc17cb8aa7e7544a4b6dcb05b6ed77",
"status": "affected",
"version": "a69f32af86e389dd232b1bb2269e202c1bfcc60f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.6"
},
{
"lessThan": "3.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()\n\nA race condition exists in the NFC LLCP connection state machine where\nthe connection acceptance packet (CC) can be processed concurrently with\nsocket release. This can lead to a use-after-free of the socket object.\n\nWhen nfc_llcp_recv_cc() moves the socket from the connecting_sockets\nlist to the sockets list, it does so without holding the socket lock.\nIf llcp_sock_release() is executing concurrently, it might have already\nunlinked the socket and dropped its references, which can result in\nnfc_llcp_recv_cc() linking a freed socket into the live list.\n\nFix this by holding lock_sock() during the state transition and list\nmovement in nfc_llcp_recv_cc(). After acquiring the lock, check if\nthe socket is still hashed to ensure it hasn\u0027t already been unlinked\nand marked for destruction by the release path. This aligns the locking\npattern with recv_hdlc() and recv_disc()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The corrupting input is an NFC LLCP Connection Complete (CC) PDU delivered over the NFC radio from a nearby peer; per kernel CNA guidance, NFC/Bluetooth-class wireless reachability maps to Adjacent rather than Local or Network.\nAC:L - The attacker can control both sides of the race by concurrently calling connect()/close() on an LLCP socket while timing CC transmission from an adjacent NFC device, making exploitation depend only on attacker-controlled timing rather than victim state.\nPR:N - An adjacent attacker needs no privileges on the victim system\u2014the kernel processes inbound NFC frames in kernel context; SOCK_STREAM LLCP sockets require no CAP_NET_RAW, so no elevated credentials are needed on either attack path.\nUI:N - Exploitation can be fully automated by a local or adjacent attacker scripting concurrent connect/close and CC injection without requiring any deliberate victim action beyond the device having NFC active and an LLCP session in progress.\nS:U - Impact is confined to kernel memory corruption and local privilege escalation within the same kernel security domain; there is no VM escape, IOMMU bypass, or other cross-authority boundary crossing.\nC:H - The use-after-free operates on a freed socket structure still referenced in kernel linked lists, enabling reads of stale heap contents and kernel pointer disclosure as part of UAF exploitation.\nI:H - The UAF re-links a freed socket into the live list and writes connection TLVs into freed memory via nfc_llcp_parse_connection_tlv(), providing a heap corruption primitive suitable for arbitrary write and code execution.\nA:H - Use-after-free of a socket object in the NFC receive path reliably causes kernel oops/panic or hang, and the freed-but-linked socket corrupts subsequent list walks causing system crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:10.194Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dce85215a6c7b0fd753f577a4c487f647119884c"
},
{
"url": "https://git.kernel.org/stable/c/bd08bb7443c501d2f2a71d529e4afcf11c9b07d2"
},
{
"url": "https://git.kernel.org/stable/c/0b45c31746e1523d5d482fda8fcf54a35ac417f1"
},
{
"url": "https://git.kernel.org/stable/c/ee2d1a8a1833c5e56e9a1745e64b0b4edda732c2"
},
{
"url": "https://git.kernel.org/stable/c/ad8a27d63cac96bac441edd002209ebd996e12fb"
},
{
"url": "https://git.kernel.org/stable/c/650bdd8fdfab64a09ee474150313dbc48c374795"
},
{
"url": "https://git.kernel.org/stable/c/b2a60f7f846faaf5c2cdad4ea6d3a33e5f863183"
},
{
"url": "https://git.kernel.org/stable/c/b493ea2765cc17cb8aa7e7544a4b6dcb05b6ed77"
}
],
"title": "nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64010",
"datePublished": "2026-07-19T14:56:25.162Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-08-05T12:38:10.194Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64135 (GCVE-0-2026-64135)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
adm1266_nvmem_read_blackbox() declares a 5-byte stack buffer and
passes it to i2c_smbus_read_block_data() to retrieve the 4-byte
BLACKBOX_INFO response. i2c_smbus_read_block_data() does not honour
caller buffer sizes -- it memcpy()s data.block[0] bytes from the
SMBus transaction (where data.block[0] is the length byte returned by
the slave device, up to I2C_SMBUS_BLOCK_MAX = 32):
memcpy(values, &data.block[1], data.block[0]);
If the device returns any block length above 5, the call overflows
the caller's 5-byte stack buffer before the post-call
if (ret != 4)
return -EIO;
check has a chance to reject the response.
Widen the local buffer to I2C_SMBUS_BLOCK_MAX so the helper has room
for any well-formed SMBus block response, matching the convention used
by the other i2c_smbus_read_block_data() callers in this driver.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 Version: 15609d1893020436e1e8ccfd9ded774a96dd17a2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "33251abb9c9dd62943be76f0427c5527ee39188f",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "ba09f4baa5bd96c5d26c942defa546a72dbbe5bf",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "6ed16a40b162e9d87d9ac8bed4d7f0e3e807700e",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "0dbf64c502443c08c2e28a77ecbfcc5479d93228",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "2b7a698d5093b548c464828d984f05ced5f3fd2a",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "ca560f7566df7e2826c2999e959e6b94eb938f76",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "7f705e581ef3e6bb308a121a89adf5237d968204",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
},
{
"lessThan": "eee213daa1e1b402eb631bcd1b8c5aa340a6b081",
"status": "affected",
"version": "15609d1893020436e1e8ccfd9ded774a96dd17a2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/pmbus/adm1266.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX\n\nadm1266_nvmem_read_blackbox() declares a 5-byte stack buffer and\npasses it to i2c_smbus_read_block_data() to retrieve the 4-byte\nBLACKBOX_INFO response. i2c_smbus_read_block_data() does not honour\ncaller buffer sizes -- it memcpy()s data.block[0] bytes from the\nSMBus transaction (where data.block[0] is the length byte returned by\nthe slave device, up to I2C_SMBUS_BLOCK_MAX = 32):\n\n\tmemcpy(values, \u0026data.block[1], data.block[0]);\n\nIf the device returns any block length above 5, the call overflows\nthe caller\u0027s 5-byte stack buffer before the post-call\n\n\tif (ret != 4)\n\t\treturn -EIO;\n\ncheck has a chance to reject the response.\n\nWiden the local buffer to I2C_SMBUS_BLOCK_MAX so the helper has room\nfor any well-formed SMBus block response, matching the convention used\nby the other i2c_smbus_read_block_data() callers in this driver."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:29.676Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/33251abb9c9dd62943be76f0427c5527ee39188f"
},
{
"url": "https://git.kernel.org/stable/c/ba09f4baa5bd96c5d26c942defa546a72dbbe5bf"
},
{
"url": "https://git.kernel.org/stable/c/6ed16a40b162e9d87d9ac8bed4d7f0e3e807700e"
},
{
"url": "https://git.kernel.org/stable/c/0dbf64c502443c08c2e28a77ecbfcc5479d93228"
},
{
"url": "https://git.kernel.org/stable/c/2b7a698d5093b548c464828d984f05ced5f3fd2a"
},
{
"url": "https://git.kernel.org/stable/c/ca560f7566df7e2826c2999e959e6b94eb938f76"
},
{
"url": "https://git.kernel.org/stable/c/7f705e581ef3e6bb308a121a89adf5237d968204"
},
{
"url": "https://git.kernel.org/stable/c/eee213daa1e1b402eb631bcd1b8c5aa340a6b081"
}
],
"title": "hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64135",
"datePublished": "2026-07-19T15:40:29.676Z",
"dateReserved": "2026-07-19T07:54:57.036Z",
"dateUpdated": "2026-07-19T15:40:29.676Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64553 (GCVE-0-2026-64553)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: psample: fix info leak in PSAMPLE_ATTR_DATA
psample open codes nla_put() presumably to avoid wiping
the data with 0s just to override it with packet data.
This open coding is missing clearing the pad, however,
each netlink attr is padded to 4B and data_len may
not be divisible by 4B.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6ae0a6286171154661b74f7f550f9441c6008424 Version: 6ae0a6286171154661b74f7f550f9441c6008424 Version: 6ae0a6286171154661b74f7f550f9441c6008424 Version: 6ae0a6286171154661b74f7f550f9441c6008424 Version: 6ae0a6286171154661b74f7f550f9441c6008424 Version: 6ae0a6286171154661b74f7f550f9441c6008424 Version: 6ae0a6286171154661b74f7f550f9441c6008424 Version: 6ae0a6286171154661b74f7f550f9441c6008424 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/psample/psample.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0d3ea2ccddda442077fc44f11d873209c97ec50b",
"status": "affected",
"version": "6ae0a6286171154661b74f7f550f9441c6008424",
"versionType": "git"
},
{
"lessThan": "7fe7e6949964aa8ee6305f09db2dc9eede977bb3",
"status": "affected",
"version": "6ae0a6286171154661b74f7f550f9441c6008424",
"versionType": "git"
},
{
"lessThan": "e2fa322782a2d7d8078f7bb20817e0aa9f7c32e9",
"status": "affected",
"version": "6ae0a6286171154661b74f7f550f9441c6008424",
"versionType": "git"
},
{
"lessThan": "befe1ebe7fc2c65c80074bc34ceeb0a721ed3cd2",
"status": "affected",
"version": "6ae0a6286171154661b74f7f550f9441c6008424",
"versionType": "git"
},
{
"lessThan": "48930f6c59fd0056c2de46ce52bfe27d9c9e5eb6",
"status": "affected",
"version": "6ae0a6286171154661b74f7f550f9441c6008424",
"versionType": "git"
},
{
"lessThan": "a6cfb924ad74efce254e99c197d2e3863de70868",
"status": "affected",
"version": "6ae0a6286171154661b74f7f550f9441c6008424",
"versionType": "git"
},
{
"lessThan": "794a0d8bdbb39e083ed42caccb86d687a9b53570",
"status": "affected",
"version": "6ae0a6286171154661b74f7f550f9441c6008424",
"versionType": "git"
},
{
"lessThan": "aedd02af1f8b0bceb7f42f5a21c41634ca9ed390",
"status": "affected",
"version": "6ae0a6286171154661b74f7f550f9441c6008424",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/psample/psample.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: psample: fix info leak in PSAMPLE_ATTR_DATA\n\npsample open codes nla_put() presumably to avoid wiping\nthe data with 0s just to override it with packet data.\nThis open coding is missing clearing the pad, however,\neach netlink attr is padded to 4B and data_len may\nnot be divisible by 4B."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:30.953Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0d3ea2ccddda442077fc44f11d873209c97ec50b"
},
{
"url": "https://git.kernel.org/stable/c/7fe7e6949964aa8ee6305f09db2dc9eede977bb3"
},
{
"url": "https://git.kernel.org/stable/c/e2fa322782a2d7d8078f7bb20817e0aa9f7c32e9"
},
{
"url": "https://git.kernel.org/stable/c/befe1ebe7fc2c65c80074bc34ceeb0a721ed3cd2"
},
{
"url": "https://git.kernel.org/stable/c/48930f6c59fd0056c2de46ce52bfe27d9c9e5eb6"
},
{
"url": "https://git.kernel.org/stable/c/a6cfb924ad74efce254e99c197d2e3863de70868"
},
{
"url": "https://git.kernel.org/stable/c/794a0d8bdbb39e083ed42caccb86d687a9b53570"
},
{
"url": "https://git.kernel.org/stable/c/aedd02af1f8b0bceb7f42f5a21c41634ca9ed390"
}
],
"title": "net: psample: fix info leak in PSAMPLE_ATTR_DATA",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64553",
"datePublished": "2026-07-27T20:10:41.159Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-08-17T04:57:30.953Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74695 (GCVE-0-2026-74695)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()
Incoming skbs passing through netfilter flowtable offload hooks (or XFRM
offload path) might already carry a ref-counted dst_entry assigned during
earlier RX or routing steps.
Calling skb_dst_set_noref() when skb already holds a ref-counted dst
overwrites skb->_skb_refdst, leaking the previous dst_entry reference
count and triggering a DEBUG_NET_WARN_ON_ONCE assertion in
skb_dst_check_unset():
WARNING: at skb_dst_check_unset include/linux/skbuff.h:1170
WARNING: at skb_dst_set_noref include/linux/skbuff.h:1234
WARNING: at nf_flow_offload_ip_hook+0xf6c/0x2b60 net/netfilter/nf_flow_table_ip.c:864
Drop any existing dst_entry reference with skb_dst_drop(skb) before
setting the non-referenced flowtable destination.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2a79fd3908acd88e6cb0e620c314d7b1fee56a02 Version: 2a79fd3908acd88e6cb0e620c314d7b1fee56a02 Version: 2a79fd3908acd88e6cb0e620c314d7b1fee56a02 Version: b4b1adf2e66ecc7125c4117e7aad9ff61e2cfd27 Version: 209dedf806d31095968f54323dbe62525b077b33 Version: 4.16.15 ≤ Version: 4.17.1 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_flow_table_ip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "12afa450a6a6c0cce2c42b7545a9958f62d8a00c",
"status": "affected",
"version": "2a79fd3908acd88e6cb0e620c314d7b1fee56a02",
"versionType": "git"
},
{
"lessThan": "538e67e8c7889cf5f93951f5309d1bcb41f86036",
"status": "affected",
"version": "2a79fd3908acd88e6cb0e620c314d7b1fee56a02",
"versionType": "git"
},
{
"lessThan": "8aecf0bbcc72605592134c917c222207d8f63ab0",
"status": "affected",
"version": "2a79fd3908acd88e6cb0e620c314d7b1fee56a02",
"versionType": "git"
},
{
"status": "affected",
"version": "b4b1adf2e66ecc7125c4117e7aad9ff61e2cfd27",
"versionType": "git"
},
{
"status": "affected",
"version": "209dedf806d31095968f54323dbe62525b077b33",
"versionType": "git"
},
{
"lessThan": "4.17",
"status": "affected",
"version": "4.16.15",
"versionType": "semver"
},
{
"lessThan": "4.18",
"status": "affected",
"version": "4.17.1",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_flow_table_ip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.16.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.17.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()\n\nIncoming skbs passing through netfilter flowtable offload hooks (or XFRM\noffload path) might already carry a ref-counted dst_entry assigned during\nearlier RX or routing steps.\n\nCalling skb_dst_set_noref() when skb already holds a ref-counted dst\noverwrites skb-\u003e_skb_refdst, leaking the previous dst_entry reference\ncount and triggering a DEBUG_NET_WARN_ON_ONCE assertion in\nskb_dst_check_unset():\n\n WARNING: at skb_dst_check_unset include/linux/skbuff.h:1170\n WARNING: at skb_dst_set_noref include/linux/skbuff.h:1234\n WARNING: at nf_flow_offload_ip_hook+0xf6c/0x2b60 net/netfilter/nf_flow_table_ip.c:864\n\nDrop any existing dst_entry reference with skb_dst_drop(skb) before\nsetting the non-referenced flowtable destination."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug fires in nf_flow_offload_ip_hook on NF_NETDEV_INGRESS when remotely sourced IPv4/IPv6 packets matching an offloaded flow are received on nftables flowtable-bound interfaces, not via netlink configuration APIs.\nAC:L - Once a flowtable ingress hook and offloaded TCP/UDP flow exist, an attacker can reliably send matching traffic that reaches FLOW_OFFLOAD_XMIT_NEIGH or the XFRM offload path with a ref-counted skb dst; syzbot reproduced this without uncontrollable races.\nPR:N - Exploitation requires only sending network traffic through an already deployed nftables flow-offload path on an ingress device; no local account, authentication, or CAP_NET_ADMIN on the victim is needed to trigger the leak.\nUI:N - No victim interaction is required beyond normal network delivery; packets are processed automatically in softirq on the netdev ingress netfilter hook without opening files or mounting filesystems.\nS:U - Impact is confined to kernel refcount imbalance and availability degradation on the affected host; this is standard in-kernel compromise territory, not a VM escape, IOMMU bypass, or other cross-authority scope change.\nC:N - The flaw leaks a dst_entry reference by overwriting skb-\u003e_skb_refdst without releasing the prior dst; it does not expose kernel memory or provide an arbitrary read primitive.\nI:N - No unauthorized data modification occurs; the skb is forwarded using the intended flowtable destination while the previous dst reference is orphaned, not corrupted into a controllable write primitive.\nA:H - Each matching packet leaks a dst_entry refcount on the flowtable fast path, enabling sustained unauthenticated remote memory exhaustion on high-volume routers; CONFIG_DEBUG_NET builds also emit WARN_ON_ONCE during the overwrite."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:38.836Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/12afa450a6a6c0cce2c42b7545a9958f62d8a00c"
},
{
"url": "https://git.kernel.org/stable/c/538e67e8c7889cf5f93951f5309d1bcb41f86036"
},
{
"url": "https://git.kernel.org/stable/c/8aecf0bbcc72605592134c917c222207d8f63ab0"
}
],
"title": "netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74695",
"datePublished": "2026-08-22T15:32:57.756Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-25T05:41:38.836Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64351 (GCVE-0-2026-64351)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
kalmia_rx_fixup() computes usb_packet_length = skb->len - (2 *
KALMIA_HEADER_LENGTH) as a u16, guarded only by a pre-loop check that
skb->len is at least KALMIA_HEADER_LENGTH, which is 6. A device can
deliver a short bulk-IN frame with skb->len in the 6 to 11 range, or
leave a short trailing remainder on a later loop iteration. Either case
underflows usb_packet_length to about 65530.
That bypasses the usb_packet_length < ether_packet_length truncation path.
The device-supplied ether_packet_length, a le16 up to 65535 read from
header_start[2], then drives a memcmp() and the following skb_trim() and
skb_pull() past the end of the rx buffer. The rx buffer is hard_mtu * 10,
which is 14000 bytes. That is an out of bounds read.
Require both the start and end framing headers to be present before
subtracting them, on every loop iteration.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d40261236e8e278cb1936cb5e934262971692b10 Version: d40261236e8e278cb1936cb5e934262971692b10 Version: d40261236e8e278cb1936cb5e934262971692b10 Version: d40261236e8e278cb1936cb5e934262971692b10 Version: d40261236e8e278cb1936cb5e934262971692b10 Version: d40261236e8e278cb1936cb5e934262971692b10 Version: d40261236e8e278cb1936cb5e934262971692b10 Version: d40261236e8e278cb1936cb5e934262971692b10 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/usb/kalmia.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "391706889a5112feafdc0c68db3ecc7ed325d09c",
"status": "affected",
"version": "d40261236e8e278cb1936cb5e934262971692b10",
"versionType": "git"
},
{
"lessThan": "aa4eef2cbb66ea3dfcfc24bdce798dd78a81b54b",
"status": "affected",
"version": "d40261236e8e278cb1936cb5e934262971692b10",
"versionType": "git"
},
{
"lessThan": "2d04c37ed4e1d0f733ad39ec35b5a5d8818b4f4a",
"status": "affected",
"version": "d40261236e8e278cb1936cb5e934262971692b10",
"versionType": "git"
},
{
"lessThan": "46ab32870d010e9a057bc5659cea22b7e728ca88",
"status": "affected",
"version": "d40261236e8e278cb1936cb5e934262971692b10",
"versionType": "git"
},
{
"lessThan": "c466097d85d52f3aa200736cb4759e66d4bbf6e3",
"status": "affected",
"version": "d40261236e8e278cb1936cb5e934262971692b10",
"versionType": "git"
},
{
"lessThan": "e24eb271061db384a3c3ef6f107fe515e68ef222",
"status": "affected",
"version": "d40261236e8e278cb1936cb5e934262971692b10",
"versionType": "git"
},
{
"lessThan": "51e65f1d78457ea4f9513d90ab22c9dccbb35110",
"status": "affected",
"version": "d40261236e8e278cb1936cb5e934262971692b10",
"versionType": "git"
},
{
"lessThan": "47b6bcef6e679593d2e86e04ee72c46a4e2f7139",
"status": "affected",
"version": "d40261236e8e278cb1936cb5e934262971692b10",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/usb/kalmia.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.0"
},
{
"lessThan": "3.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: kalmia: bound RX frame length in kalmia_rx_fixup()\n\nkalmia_rx_fixup() computes usb_packet_length = skb-\u003elen - (2 *\nKALMIA_HEADER_LENGTH) as a u16, guarded only by a pre-loop check that\nskb-\u003elen is at least KALMIA_HEADER_LENGTH, which is 6. A device can\ndeliver a short bulk-IN frame with skb-\u003elen in the 6 to 11 range, or\nleave a short trailing remainder on a later loop iteration. Either case\nunderflows usb_packet_length to about 65530.\n\nThat bypasses the usb_packet_length \u003c ether_packet_length truncation path.\nThe device-supplied ether_packet_length, a le16 up to 65535 read from\nheader_start[2], then drives a memcmp() and the following skb_trim() and\nskb_pull() past the end of the rx buffer. The rx buffer is hard_mtu * 10,\nwhich is 14000 bytes. That is an out of bounds read.\n\nRequire both the start and end framing headers to be present before\nsubtracting them, on every loop iteration."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:56.750Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/391706889a5112feafdc0c68db3ecc7ed325d09c"
},
{
"url": "https://git.kernel.org/stable/c/aa4eef2cbb66ea3dfcfc24bdce798dd78a81b54b"
},
{
"url": "https://git.kernel.org/stable/c/2d04c37ed4e1d0f733ad39ec35b5a5d8818b4f4a"
},
{
"url": "https://git.kernel.org/stable/c/46ab32870d010e9a057bc5659cea22b7e728ca88"
},
{
"url": "https://git.kernel.org/stable/c/c466097d85d52f3aa200736cb4759e66d4bbf6e3"
},
{
"url": "https://git.kernel.org/stable/c/e24eb271061db384a3c3ef6f107fe515e68ef222"
},
{
"url": "https://git.kernel.org/stable/c/51e65f1d78457ea4f9513d90ab22c9dccbb35110"
},
{
"url": "https://git.kernel.org/stable/c/47b6bcef6e679593d2e86e04ee72c46a4e2f7139"
}
],
"title": "net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64351",
"datePublished": "2026-07-25T08:50:10.882Z",
"dateReserved": "2026-07-19T15:36:31.782Z",
"dateUpdated": "2026-08-17T04:53:56.750Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68277 (GCVE-0-2026-68277)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
Three sideband reply parsers read 16-bit fields as:
val = (raw->msg[idx] << 8) | (raw->msg[idx+1]);
and check bounds only after the fact. When idx == raw->curlen,
raw->msg[idx+1] reads one byte past the received message data into
the following struct fields (curchunk_len, curchunk_idx, curlen).
Affected functions:
- drm_dp_sideband_parse_enum_path_resources_ack()
full_payload_bw_number and avail_payload_bw_number fields
- drm_dp_sideband_parse_allocate_payload_ack()
allocated_pbn field
- drm_dp_sideband_parse_query_payload_ack()
allocated_pbn field
Fix by using a single combined check (idx + 2 > curlen) before each
2-byte read. Since the check is strictly tighter than idx > curlen,
no separate step is needed.
[added fixes tag]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c1f72a13d54ffd16647d3fa540d961f5deba8790",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "192e146c2d57ad033b0d418ec64ee390f8dc074e",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "6e3107e6522109a07fc9bb0fc4ec463f1982e113",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "bdf0508b1e6785d4a8982c637e97e68d60b47d7b",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "0bcd7675c69a2462a8531fcd9e4d096e9c7ec5df",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "d5c70523cafa26ad2c7a37b612849abe2683baa8",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "68a624416d1dd481b3e5b7ea0e8a070a9b8a2c73",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "6b89ba3dba2f583626fb693e47e951ffb8bf591f",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers\n\nThree sideband reply parsers read 16-bit fields as:\n\n val = (raw-\u003emsg[idx] \u003c\u003c 8) | (raw-\u003emsg[idx+1]);\n\nand check bounds only after the fact. When idx == raw-\u003ecurlen,\nraw-\u003emsg[idx+1] reads one byte past the received message data into\nthe following struct fields (curchunk_len, curchunk_idx, curlen).\n\nAffected functions:\n - drm_dp_sideband_parse_enum_path_resources_ack()\n full_payload_bw_number and avail_payload_bw_number fields\n - drm_dp_sideband_parse_allocate_payload_ack()\n allocated_pbn field\n - drm_dp_sideband_parse_query_payload_ack()\n allocated_pbn field\n\nFix by using a single combined check (idx + 2 \u003e curlen) before each\n2-byte read. Since the check is strictly tighter than idx \u003e curlen,\nno separate step is needed.\n\n[added fixes tag]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:14.372Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c1f72a13d54ffd16647d3fa540d961f5deba8790"
},
{
"url": "https://git.kernel.org/stable/c/192e146c2d57ad033b0d418ec64ee390f8dc074e"
},
{
"url": "https://git.kernel.org/stable/c/6e3107e6522109a07fc9bb0fc4ec463f1982e113"
},
{
"url": "https://git.kernel.org/stable/c/bdf0508b1e6785d4a8982c637e97e68d60b47d7b"
},
{
"url": "https://git.kernel.org/stable/c/0bcd7675c69a2462a8531fcd9e4d096e9c7ec5df"
},
{
"url": "https://git.kernel.org/stable/c/d5c70523cafa26ad2c7a37b612849abe2683baa8"
},
{
"url": "https://git.kernel.org/stable/c/68a624416d1dd481b3e5b7ea0e8a070a9b8a2c73"
},
{
"url": "https://git.kernel.org/stable/c/6b89ba3dba2f583626fb693e47e951ffb8bf591f"
}
],
"title": "drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68277",
"datePublished": "2026-08-10T12:01:53.085Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:14.372Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68351 (GCVE-0-2026-68351)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
When the firmware sends a command response with a length mismatch,
carl9170_cmd_callback() logs the mismatch and calls carl9170_restart()
but then falls through to memcpy(ar->readbuf, buffer + 4, len - 4).
Since len comes from the firmware and can exceed ar->readlen, this
copies more data than the readbuf was allocated for.
Bound the memcpy to min(len - 4, ar->readlen) so that the response
is still completed -- avoiding repeated restarts from queued garbage --
while preventing an overread past the response buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "38e240996a6a78c94ab07d461fd66e361d55c3c4",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "2d05c321d27624c413c950278d2dc8e0f44a8950",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "525036b20ef01d814a7fcd0567d123992e4479fa",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "f74e34e66379e487a09009a4f2d42470051672bd",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "500c36649f270de05a56591fcc1aaaa36687958e",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "9aee949c68dc6dccbc54333537b109c53fe2079f",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "cb7a38810cf25738176dac32dec7a146b3f959cf",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "4cde55b2feff9504d1f993ab80e84e7ccb62791c",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: bound memcpy length in cmd callback to prevent OOB read\n\nWhen the firmware sends a command response with a length mismatch,\ncarl9170_cmd_callback() logs the mismatch and calls carl9170_restart()\nbut then falls through to memcpy(ar-\u003ereadbuf, buffer + 4, len - 4).\nSince len comes from the firmware and can exceed ar-\u003ereadlen, this\ncopies more data than the readbuf was allocated for.\n\nBound the memcpy to min(len - 4, ar-\u003ereadlen) so that the response\nis still completed -- avoiding repeated restarts from queued garbage --\nwhile preventing an overread past the response buffer."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:53.098Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/38e240996a6a78c94ab07d461fd66e361d55c3c4"
},
{
"url": "https://git.kernel.org/stable/c/2d05c321d27624c413c950278d2dc8e0f44a8950"
},
{
"url": "https://git.kernel.org/stable/c/525036b20ef01d814a7fcd0567d123992e4479fa"
},
{
"url": "https://git.kernel.org/stable/c/f74e34e66379e487a09009a4f2d42470051672bd"
},
{
"url": "https://git.kernel.org/stable/c/500c36649f270de05a56591fcc1aaaa36687958e"
},
{
"url": "https://git.kernel.org/stable/c/9aee949c68dc6dccbc54333537b109c53fe2079f"
},
{
"url": "https://git.kernel.org/stable/c/cb7a38810cf25738176dac32dec7a146b3f959cf"
},
{
"url": "https://git.kernel.org/stable/c/4cde55b2feff9504d1f993ab80e84e7ccb62791c"
}
],
"title": "wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68351",
"datePublished": "2026-08-10T12:03:28.312Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:53.098Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53219 (GCVE-0-2026-53219)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: x_tables: avoid leaking percpu counter pointers
The native and compat get-entries paths copy the fixed rule entry header
from the kernelized rule blob to userspace before overwriting the entry's
counter fields with a sanitized counter snapshot.
On SMP kernels, entry->counters.pcnt contains the percpu allocation
address used by x_tables rule counters. A caller can provide a userspace
buffer that faults during the initial fixed-header copy after pcnt has
been copied but before the later sanitized counter copy runs. The syscall
then returns -EFAULT while leaving the raw percpu pointer in userspace.
Copy only the fixed entry prefix before counters from the kernelized rule
blob, then copy the sanitized counter snapshot into the counter field.
Apply this ordering to the IPv4, IPv6, and ARP native and compat
get-entries implementations so a fault cannot expose the internal percpu
counter pointer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 71ae0dff02d756e4d2ca710b79f2ff5390029a5f Version: 71ae0dff02d756e4d2ca710b79f2ff5390029a5f Version: 71ae0dff02d756e4d2ca710b79f2ff5390029a5f Version: 71ae0dff02d756e4d2ca710b79f2ff5390029a5f Version: 71ae0dff02d756e4d2ca710b79f2ff5390029a5f Version: 71ae0dff02d756e4d2ca710b79f2ff5390029a5f Version: 71ae0dff02d756e4d2ca710b79f2ff5390029a5f Version: 71ae0dff02d756e4d2ca710b79f2ff5390029a5f |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:04.454Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/netfilter/arp_tables.c",
"net/ipv4/netfilter/ip_tables.c",
"net/ipv6/netfilter/ip6_tables.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b74ba3343eb44b2cbf7e9665918c287df1d52ebb",
"status": "affected",
"version": "71ae0dff02d756e4d2ca710b79f2ff5390029a5f",
"versionType": "git"
},
{
"lessThan": "0b35dc8527ccc16b7dc34e8a3164313e68cd4e45",
"status": "affected",
"version": "71ae0dff02d756e4d2ca710b79f2ff5390029a5f",
"versionType": "git"
},
{
"lessThan": "b28e2fcad3db7e8687b15bc20bced26b5b7c920e",
"status": "affected",
"version": "71ae0dff02d756e4d2ca710b79f2ff5390029a5f",
"versionType": "git"
},
{
"lessThan": "a0d16941adf3a501956d74aefd8d6e217906e79c",
"status": "affected",
"version": "71ae0dff02d756e4d2ca710b79f2ff5390029a5f",
"versionType": "git"
},
{
"lessThan": "8d67e42ad3b1a95a152541015a07110e06992d6c",
"status": "affected",
"version": "71ae0dff02d756e4d2ca710b79f2ff5390029a5f",
"versionType": "git"
},
{
"lessThan": "08a3e218064db11f154ad9ad5541751ea7f34ebe",
"status": "affected",
"version": "71ae0dff02d756e4d2ca710b79f2ff5390029a5f",
"versionType": "git"
},
{
"lessThan": "fb0521aff1e10e300d89725cc439d3ea74c828c5",
"status": "affected",
"version": "71ae0dff02d756e4d2ca710b79f2ff5390029a5f",
"versionType": "git"
},
{
"lessThan": "f7f2fbb0e893a0238dc464f8d8c0f5609bec584f",
"status": "affected",
"version": "71ae0dff02d756e4d2ca710b79f2ff5390029a5f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/netfilter/arp_tables.c",
"net/ipv4/netfilter/ip_tables.c",
"net/ipv6/netfilter/ip6_tables.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: avoid leaking percpu counter pointers\n\nThe native and compat get-entries paths copy the fixed rule entry header\nfrom the kernelized rule blob to userspace before overwriting the entry\u0027s\ncounter fields with a sanitized counter snapshot.\n\nOn SMP kernels, entry-\u003ecounters.pcnt contains the percpu allocation\naddress used by x_tables rule counters. A caller can provide a userspace\nbuffer that faults during the initial fixed-header copy after pcnt has\nbeen copied but before the later sanitized counter copy runs. The syscall\nthen returns -EFAULT while leaving the raw percpu pointer in userspace.\n\nCopy only the fixed entry prefix before counters from the kernelized rule\nblob, then copy the sanitized counter snapshot into the counter field.\nApply this ordering to the IPv4, IPv6, and ARP native and compat\nget-entries implementations so a fault cannot expose the internal percpu\ncounter pointer."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-25T08:39:21.730Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b74ba3343eb44b2cbf7e9665918c287df1d52ebb"
},
{
"url": "https://git.kernel.org/stable/c/0b35dc8527ccc16b7dc34e8a3164313e68cd4e45"
},
{
"url": "https://git.kernel.org/stable/c/b28e2fcad3db7e8687b15bc20bced26b5b7c920e"
},
{
"url": "https://git.kernel.org/stable/c/a0d16941adf3a501956d74aefd8d6e217906e79c"
},
{
"url": "https://git.kernel.org/stable/c/8d67e42ad3b1a95a152541015a07110e06992d6c"
},
{
"url": "https://git.kernel.org/stable/c/08a3e218064db11f154ad9ad5541751ea7f34ebe"
},
{
"url": "https://git.kernel.org/stable/c/fb0521aff1e10e300d89725cc439d3ea74c828c5"
},
{
"url": "https://git.kernel.org/stable/c/f7f2fbb0e893a0238dc464f8d8c0f5609bec584f"
}
],
"title": "netfilter: x_tables: avoid leaking percpu counter pointers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53219",
"datePublished": "2026-06-25T08:39:21.730Z",
"dateReserved": "2026-06-09T07:44:35.392Z",
"dateUpdated": "2026-09-08T08:50:04.454Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64599 (GCVE-0-2026-64599)
Vulnerability from cvelistv5
Published
2026-08-06 07:13
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: amlogic - avoid double cleanup in meson_crypto_probe()
When meson_allocate_chanlist() fails after a partial allocation, it already
unwinds the allocated chanlist state through its local error path.
meson_crypto_probe() then jump to error_flow and calls
meson_free_chanlist() again, causing the same per-flow resources to be torn
down twice. In the reproduced failure path, the second teardown
re-entered crypto_engine_exit() on an already destroyed worker and KASAN
reported a slab-use-after-free in kthread_destroy_worker().
Prevent double-free by handling partial allocation failures locally within
meson_allocate_chanlist() and skipping the outer cleanup path.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available.
The bug was reproduced in a QEMU x86_64 guest booted with KASAN on v7.1,
using the reproducer under tools/testing/meson_crypto_probe. The reproducer
forces the second dma_alloc_attrs() call in the gxl-crypto probe path to
return NULL, making meson_allocate_chanlist() fail after partial
initialization. On the unpatched kernel this reliably triggered a
slab-use-after-free. With this fix applied, the same reproducer no longer
emits any KASAN report and the probe fails cleanly with -ENOMEM.
==================================================================
BUG: KASAN: slab-use-after-free in kthread_destroy_worker+0xb2/0xd0
Read of size 8 at addr ff1100010c057a68 by task insmod/265
CPU: 1 UID: 0 PID: 265 Comm: insmod Tainted: G O 7.1.0-rc2-00376-g810af9adc907-dirty #10 PREEMPT(lazy)
Tainted: [O]=OOT_MODULE
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0x68/0xa0
print_report+0xcb/0x5e0
? __virt_addr_valid+0x21d/0x3f0
? kthread_destroy_worker+0xb2/0xd0
? kthread_destroy_worker+0xb2/0xd0
kasan_report+0xca/0x100
? kthread_destroy_worker+0xb2/0xd0
kthread_destroy_worker+0xb2/0xd0
meson_crypto_probe+0x4d0/0xc10 [amlogic_gxl_crypto]
platform_probe+0x99/0x140
really_probe+0x1c6/0x6a0
? __pfx___device_attach_driver+0x10/0x10
__driver_probe_device+0x248/0x310
? acpi_driver_match_device+0xb0/0x100
driver_probe_device+0x48/0x210
? __pfx___device_attach_driver+0x10/0x10
__device_attach_driver+0x160/0x320
bus_for_each_drv+0x104/0x190
? __pfx_bus_for_each_drv+0x10/0x10
? _raw_spin_unlock_irqrestore+0x2c/0x50
__device_attach+0x19d/0x3b0
? __pfx___device_attach+0x10/0x10
? do_raw_spin_unlock+0x53/0x220
device_initial_probe+0x78/0xa0
bus_probe_device+0x5b/0x130
device_add+0xcfd/0x1430
? __pfx_device_add+0x10/0x10
? insert_resource+0x34/0x50
? lock_release+0xc9/0x290
platform_device_add+0x24e/0x590
? __pfx_meson_crypto_probe_repro_init+0x10/0x10 [meson_crypto_probe_repro]
meson_crypto_probe_repro_init+0x330/0xff0 [meson_crypto_probe_repro]
do_one_initcall+0xc0/0x450
? __pfx_do_one_initcall+0x10/0x10
? _raw_spin_unlock_irqrestore+0x2c/0x50
? __create_object+0x59/0x80
? kasan_unpoison+0x27/0x60
do_init_module+0x27b/0x7d0
? __pfx_do_init_module+0x10/0x10
? kasan_quarantine_put+0x84/0x1d0
? kfree+0x32c/0x510
? load_module+0x561e/0x5ff0
load_module+0x54fe/0x5ff0
? __pfx_load_module+0x10/0x10
? security_file_permission+0x20/0x40
? kernel_read_file+0x23d/0x6e0
? mmap_region+0x235/0x4a0
? __pfx_kernel_read_file+0x10/0x10
? __file_has_perm+0x2c0/0x3e0
init_module_from_file+0x158/0x180
? __pfx_init_module_from_file+0x10/0x10
? __lock_acquire+0x45a/0x1ba0
? idempotent_init_module+0x315/0x610
? lock_release+0xc9/0x290
? lock
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 48fe583fe54177bfb80f348e2a5cc34c3f710095 Version: 48fe583fe54177bfb80f348e2a5cc34c3f710095 Version: 48fe583fe54177bfb80f348e2a5cc34c3f710095 Version: 48fe583fe54177bfb80f348e2a5cc34c3f710095 Version: 48fe583fe54177bfb80f348e2a5cc34c3f710095 Version: 48fe583fe54177bfb80f348e2a5cc34c3f710095 Version: 48fe583fe54177bfb80f348e2a5cc34c3f710095 Version: 48fe583fe54177bfb80f348e2a5cc34c3f710095 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/crypto/amlogic/amlogic-gxl-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c2c48aa7a6be36d4c93da75d14d4b4f2f4168c81",
"status": "affected",
"version": "48fe583fe54177bfb80f348e2a5cc34c3f710095",
"versionType": "git"
},
{
"lessThan": "c80360b4e85099fc3835378a96a59c0a2480fb07",
"status": "affected",
"version": "48fe583fe54177bfb80f348e2a5cc34c3f710095",
"versionType": "git"
},
{
"lessThan": "5b452019a4127f63c1f2147237fc287d1581f606",
"status": "affected",
"version": "48fe583fe54177bfb80f348e2a5cc34c3f710095",
"versionType": "git"
},
{
"lessThan": "f30e2b879bda14bc3e1524fba6f8ab9ec119da90",
"status": "affected",
"version": "48fe583fe54177bfb80f348e2a5cc34c3f710095",
"versionType": "git"
},
{
"lessThan": "6effdbaca3cd8354540bdf42c7f5fb84412afeb7",
"status": "affected",
"version": "48fe583fe54177bfb80f348e2a5cc34c3f710095",
"versionType": "git"
},
{
"lessThan": "84a00be9b736aa5dce902a290f62cbbbdcfab9ed",
"status": "affected",
"version": "48fe583fe54177bfb80f348e2a5cc34c3f710095",
"versionType": "git"
},
{
"lessThan": "6dda8406d8a3da2519c8b388d443d7357839cb63",
"status": "affected",
"version": "48fe583fe54177bfb80f348e2a5cc34c3f710095",
"versionType": "git"
},
{
"lessThan": "6d827ade51a24e18d81afb9f32756d339520a14c",
"status": "affected",
"version": "48fe583fe54177bfb80f348e2a5cc34c3f710095",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/crypto/amlogic/amlogic-gxl-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: amlogic - avoid double cleanup in meson_crypto_probe()\n\nWhen meson_allocate_chanlist() fails after a partial allocation, it already\nunwinds the allocated chanlist state through its local error path.\nmeson_crypto_probe() then jump to error_flow and calls\nmeson_free_chanlist() again, causing the same per-flow resources to be torn\ndown twice. In the reproduced failure path, the second teardown\nre-entered crypto_engine_exit() on an already destroyed worker and KASAN\nreported a slab-use-after-free in kthread_destroy_worker().\n\nPrevent double-free by handling partial allocation failures locally within\nmeson_allocate_chanlist() and skipping the outer cleanup path.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable.\n\nThe bug was reproduced in a QEMU x86_64 guest booted with KASAN on v7.1,\nusing the reproducer under tools/testing/meson_crypto_probe. The reproducer\nforces the second dma_alloc_attrs() call in the gxl-crypto probe path to\nreturn NULL, making meson_allocate_chanlist() fail after partial\ninitialization. On the unpatched kernel this reliably triggered a\nslab-use-after-free. With this fix applied, the same reproducer no longer\nemits any KASAN report and the probe fails cleanly with -ENOMEM.\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in kthread_destroy_worker+0xb2/0xd0\n Read of size 8 at addr ff1100010c057a68 by task insmod/265\n\n CPU: 1 UID: 0 PID: 265 Comm: insmod Tainted: G O 7.1.0-rc2-00376-g810af9adc907-dirty #10 PREEMPT(lazy)\n Tainted: [O]=OOT_MODULE\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x68/0xa0\n print_report+0xcb/0x5e0\n ? __virt_addr_valid+0x21d/0x3f0\n ? kthread_destroy_worker+0xb2/0xd0\n ? kthread_destroy_worker+0xb2/0xd0\n kasan_report+0xca/0x100\n ? kthread_destroy_worker+0xb2/0xd0\n kthread_destroy_worker+0xb2/0xd0\n meson_crypto_probe+0x4d0/0xc10 [amlogic_gxl_crypto]\n platform_probe+0x99/0x140\n really_probe+0x1c6/0x6a0\n ? __pfx___device_attach_driver+0x10/0x10\n __driver_probe_device+0x248/0x310\n ? acpi_driver_match_device+0xb0/0x100\n driver_probe_device+0x48/0x210\n ? __pfx___device_attach_driver+0x10/0x10\n __device_attach_driver+0x160/0x320\n bus_for_each_drv+0x104/0x190\n ? __pfx_bus_for_each_drv+0x10/0x10\n ? _raw_spin_unlock_irqrestore+0x2c/0x50\n __device_attach+0x19d/0x3b0\n ? __pfx___device_attach+0x10/0x10\n ? do_raw_spin_unlock+0x53/0x220\n device_initial_probe+0x78/0xa0\n bus_probe_device+0x5b/0x130\n device_add+0xcfd/0x1430\n ? __pfx_device_add+0x10/0x10\n ? insert_resource+0x34/0x50\n ? lock_release+0xc9/0x290\n platform_device_add+0x24e/0x590\n ? __pfx_meson_crypto_probe_repro_init+0x10/0x10 [meson_crypto_probe_repro]\n meson_crypto_probe_repro_init+0x330/0xff0 [meson_crypto_probe_repro]\n do_one_initcall+0xc0/0x450\n ? __pfx_do_one_initcall+0x10/0x10\n ? _raw_spin_unlock_irqrestore+0x2c/0x50\n ? __create_object+0x59/0x80\n ? kasan_unpoison+0x27/0x60\n do_init_module+0x27b/0x7d0\n ? __pfx_do_init_module+0x10/0x10\n ? kasan_quarantine_put+0x84/0x1d0\n ? kfree+0x32c/0x510\n ? load_module+0x561e/0x5ff0\n load_module+0x54fe/0x5ff0\n ? __pfx_load_module+0x10/0x10\n ? security_file_permission+0x20/0x40\n ? kernel_read_file+0x23d/0x6e0\n ? mmap_region+0x235/0x4a0\n ? __pfx_kernel_read_file+0x10/0x10\n ? __file_has_perm+0x2c0/0x3e0\n init_module_from_file+0x158/0x180\n ? __pfx_init_module_from_file+0x10/0x10\n ? __lock_acquire+0x45a/0x1ba0\n ? idempotent_init_module+0x315/0x610\n ? lock_release+0xc9/0x290\n ? lock\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only in the Amlogic GXL platform driver probe path (meson_crypto_probe \u2192 meson_allocate_chanlist error unwind), via boot/deferred probe, module bind, or local sysfs rebind\u2014not from network, adjacent, or physical I/O.\nAC:L - Once meson_allocate_chanlist() fails after partial engine/DMA setup, the outer error_flow double-calls meson_free_chanlist() deterministically; a local attacker can induce that ENOMEM with memory pressure or allocation failure, with no race beyond their control.\nPR:L - On Amlogic GXL devices the DT node is status=okay and probes automatically (including deferred retries when clocks/IRQs appear); an ordinary local user can apply memory pressure during that probe without CAP_SYS_MODULE or init-namespace root, matching the higher-severity choice over PR:H.\nUI:N - No victim action such as opening a file or mounting a filesystem is required; probe error unwinding runs entirely in kernel context once allocation failure is induced.\nS:U - The double-free/UAF corrupts host kernel heap and crypto-engine worker state within the same kernel security authority and does not cross a VM, IOMMU, or sandbox boundary by itself.\nC:H - The second teardown re-enters crypto_engine_exit()/kthread_destroy_worker() and dma_free_coherent() on already freed objects (confirmed KASAN slab-UAF), which can expose arbitrary kernel memory via attacker-controlled reuse of the freed slabs.\nI:H - Double-free of kthread_worker and DMA descriptor buffers yields overlapping live objects and classic heap corruption primitives that can be leveraged for arbitrary kernel writes or control-flow hijacking, not merely a clean crash.\nA:H - The use-after-free and double-free paths reliably cause kernel oops/panic (KASAN reported slab-UAF in kthread_destroy_worker), and NULL engine pointers on early failure also crash via crypto_engine_exit(NULL)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:21.956Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c2c48aa7a6be36d4c93da75d14d4b4f2f4168c81"
},
{
"url": "https://git.kernel.org/stable/c/c80360b4e85099fc3835378a96a59c0a2480fb07"
},
{
"url": "https://git.kernel.org/stable/c/5b452019a4127f63c1f2147237fc287d1581f606"
},
{
"url": "https://git.kernel.org/stable/c/f30e2b879bda14bc3e1524fba6f8ab9ec119da90"
},
{
"url": "https://git.kernel.org/stable/c/6effdbaca3cd8354540bdf42c7f5fb84412afeb7"
},
{
"url": "https://git.kernel.org/stable/c/84a00be9b736aa5dce902a290f62cbbbdcfab9ed"
},
{
"url": "https://git.kernel.org/stable/c/6dda8406d8a3da2519c8b388d443d7357839cb63"
},
{
"url": "https://git.kernel.org/stable/c/6d827ade51a24e18d81afb9f32756d339520a14c"
}
],
"title": "crypto: amlogic - avoid double cleanup in meson_crypto_probe()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64599",
"datePublished": "2026-08-06T07:13:53.328Z",
"dateReserved": "2026-07-19T15:36:31.799Z",
"dateUpdated": "2026-08-17T04:58:21.956Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68145 (GCVE-0-2026-68145)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iomap: fix out-of-bounds bitmap_set() with zero-length range
ifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk
as (off + len - 1) >> i_blkbits. When off is 0 and len is 0, the
unsigned subtraction underflows to SIZE_MAX, producing a huge
last_blk and nr_blks value that causes bitmap_set() to write far
beyond the ifs->state allocation.
Regarding ifs_set_range_uptodate(), it is temporarily safe because len
cannot be passed in as 0. However, for ifs_set_range_dirty() this is
reachable from __iomap_write_end(): when copy_folio_from_iter_atomic()
returns 0 (e.g. user buffer fault) and the folio is already uptodate,
the guard at the top of __iomap_write_end() does not trigger because
!folio_test_uptodate() is false, and iomap_set_range_dirty() is called
with copied == 0.
Add a !len guard to both functions before the computation, so that a
zero-length range is a no-op.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/iomap/buffered-io.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "48829622212f6b8f49155889aecc818ba28ba680",
"status": "affected",
"version": "4ce02c67972211be488408c275c8fbf19faf29b3",
"versionType": "git"
},
{
"lessThan": "fb4fad9105c88b1d82f1b3c39e3b6abea8249af6",
"status": "affected",
"version": "4ce02c67972211be488408c275c8fbf19faf29b3",
"versionType": "git"
},
{
"lessThan": "7037e7bdcd26f46c080b8ce307dee5cb471c4b7c",
"status": "affected",
"version": "4ce02c67972211be488408c275c8fbf19faf29b3",
"versionType": "git"
},
{
"lessThan": "c5b6a48a8a716a7730e39af1cad083dc4ec955ce",
"status": "affected",
"version": "4ce02c67972211be488408c275c8fbf19faf29b3",
"versionType": "git"
},
{
"lessThan": "9c7d8f7c8994c790fca501dc45ce66e7356cbe05",
"status": "affected",
"version": "4ce02c67972211be488408c275c8fbf19faf29b3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/iomap/buffered-io.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niomap: fix out-of-bounds bitmap_set() with zero-length range\n\nifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk\nas (off + len - 1) \u003e\u003e i_blkbits. When off is 0 and len is 0, the\nunsigned subtraction underflows to SIZE_MAX, producing a huge\nlast_blk and nr_blks value that causes bitmap_set() to write far\nbeyond the ifs-\u003estate allocation.\n\nRegarding ifs_set_range_uptodate(), it is temporarily safe because len\ncannot be passed in as 0. However, for ifs_set_range_dirty() this is\nreachable from __iomap_write_end(): when copy_folio_from_iter_atomic()\nreturns 0 (e.g. user buffer fault) and the folio is already uptodate,\nthe guard at the top of __iomap_write_end() does not trigger because\n!folio_test_uptodate() is false, and iomap_set_range_dirty() is called\nwith copied == 0.\n\nAdd a !len guard to both functions before the computation, so that a\nzero-length range is a no-op."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached via the buffered write() path through iomap_file_buffered_write() when copy_folio_from_iter_atomic() returns 0; NFS/ksmbd server writes use kernel bvec iterators and do not hit this user-buffer fault path.\nAC:L - An attacker can reliably trigger copied==0 by racing munmap/remap against write() on an already-uptodate folio (TOCTOU after fault_in_iov_iter_readable), controlling both sides of the race on systems where folio size exceeds filesystem block size.\nPR:L - Only standard local write permission to a file on an iomap-backed filesystem (XFS, GFS2, FUSE writeback-cache, zonefs, NTFS) is required; no CAP_SYS_ADMIN or other elevated capability is needed beyond creating/triggering writes to attacker-writable files.\nUI:N - Exploitation requires only the attacker\u0027s own write operations to a writable file; no action by another user or administrator (such as mounting a filesystem or opening a file on the victim\u0027s behalf) is needed.\nS:U - Successful exploitation corrupts host kernel heap memory and enables local privilege escalation within the same kernel security domain; it does not inherently cross VM, container, or IOMMU boundaries.\nC:H - ifs_set_range_dirty() with len==0 underflows to SIZE_MAX and bitmap_set() writes far beyond the small kzalloc_flex(ifs-\u003estate) allocation, corrupting adjacent kmalloc objects in ways that can be leveraged for arbitrary kernel memory disclosure.\nI:H - The out-of-bounds bitmap_set() is a large heap overwrite primitive adjacent to the iomap_folio_state allocation, enabling control of kernel data structures and arbitrary code execution via standard heap exploitation techniques.\nA:H - The massive out-of-bounds write can immediately corrupt critical kernel heap metadata or adjacent objects, causing kernel oops/panic or unrecoverable memory corruption even before full exploitation is attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:56.875Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/48829622212f6b8f49155889aecc818ba28ba680"
},
{
"url": "https://git.kernel.org/stable/c/fb4fad9105c88b1d82f1b3c39e3b6abea8249af6"
},
{
"url": "https://git.kernel.org/stable/c/7037e7bdcd26f46c080b8ce307dee5cb471c4b7c"
},
{
"url": "https://git.kernel.org/stable/c/c5b6a48a8a716a7730e39af1cad083dc4ec955ce"
},
{
"url": "https://git.kernel.org/stable/c/9c7d8f7c8994c790fca501dc45ce66e7356cbe05"
}
],
"title": "iomap: fix out-of-bounds bitmap_set() with zero-length range",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68145",
"datePublished": "2026-08-10T11:59:09.721Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-23T12:45:56.875Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-68179 (GCVE-0-2025-68179)
Vulnerability from cvelistv5
Published
2025-12-16 13:42
Modified
2026-08-05 12:10
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP
As reported by Luiz Capitulino enabling HVO on s390 leads to reproducible
crashes. The problem is that kernel page tables are modified without
flushing corresponding TLB entries.
Even if it looks like the empty flush_tlb_all() implementation on s390 is
the problem, it is actually a different problem: on s390 it is not allowed
to replace an active/valid page table entry with another valid page table
entry without the detour over an invalid entry. A direct replacement may
lead to random crashes and/or data corruption.
In order to invalidate an entry special instructions have to be used
(e.g. ipte or idte). Alternatively there are also special instructions
available which allow to replace a valid entry with a different valid
entry (e.g. crdte or cspg).
Given that the HVO code currently does not provide the hooks to allow for
an implementation which is compliant with the s390 architecture
requirements, disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP again, which is
basically a revert of the original patch which enabled it.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/s390/Kconfig"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7088465f10816d9425b95740b37c95f082041d76",
"status": "affected",
"version": "00a34d5a99c0631bd780b14cbe3813d0b39c3886",
"versionType": "git"
},
{
"lessThan": "5e23918e4352288323d13fb511116cdea0234b71",
"status": "affected",
"version": "00a34d5a99c0631bd780b14cbe3813d0b39c3886",
"versionType": "git"
},
{
"lessThan": "d4a8238e5729505b7394ccb007e5dc3e557aa66b",
"status": "affected",
"version": "00a34d5a99c0631bd780b14cbe3813d0b39c3886",
"versionType": "git"
},
{
"lessThan": "64e2f60f355e556337fcffe80b9bcff1b22c9c42",
"status": "affected",
"version": "00a34d5a99c0631bd780b14cbe3813d0b39c3886",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/s390/Kconfig"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.117",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.58",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.117",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.58",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.8",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP\n\nAs reported by Luiz Capitulino enabling HVO on s390 leads to reproducible\ncrashes. The problem is that kernel page tables are modified without\nflushing corresponding TLB entries.\n\nEven if it looks like the empty flush_tlb_all() implementation on s390 is\nthe problem, it is actually a different problem: on s390 it is not allowed\nto replace an active/valid page table entry with another valid page table\nentry without the detour over an invalid entry. A direct replacement may\nlead to random crashes and/or data corruption.\n\nIn order to invalidate an entry special instructions have to be used\n(e.g. ipte or idte). Alternatively there are also special instructions\navailable which allow to replace a valid entry with a different valid\nentry (e.g. crdte or cspg).\n\nGiven that the HVO code currently does not provide the hooks to allow for\nan implementation which is compliant with the s390 architecture\nrequirements, disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP again, which is\nbasically a revert of the original patch which enabled it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable HVO remap code is reached through local hugetlb pool operations \u2014 `mmap(MAP_HUGETLB)`/`munmap` driving surplus folio allocation and free, or sysfs/sysctl pool resizing \u2014 all requiring local system access. There is no network-facing path to `hugetlb_vmemmap_optimize_folio()`.\nAC:L - Every HVO optimize/restore cycle unconditionally performs the architecturally illegal valid-to-valid page table entry replacement and, in the batched path, frees vmemmap pages with zero TLB invalidation because s390\u0027s `flush_tlb_all()` is empty; the reporter confirmed reproducible crashes and an attacker can repeat the allocate/free loop indefinitely to compound the stale-TLB window.\nPR:L - On a system with HVO enabled and `nr_overcommit_hugepages` configured \u2014 the exact deployment the s390 enabling commit documents \u2014 an ordinary unprivileged user triggers `alloc_surplus_hugetlb_folio()` \u2192 `hugetlb_vmemmap_optimize_folio()` via `mmap(MAP_HUGETLB|MAP_ANONYMOUS)`, which has no capability check in `mm/mmap.c:586`. Access to a world-writable hugetlbfs mount gives the same unprivileged reach.\nUI:N - The attacker triggers the hugetlb allocation and free cycle entirely on their own; no victim action, file open, or filesystem mount by another user is needed.\nS:U - The corruption is confined to the kernel\u0027s own page tables and physical memory within a single security authority; there is no crossing of a hypervisor, IOMMU, or sandbox boundary.\nC:H - Stale writable TLB entries continue to map vmemmap virtual addresses to physical pages already returned to the buddy allocator and reallocated for arbitrary kernel or user data, giving read access to that memory; additionally, a mixed old/new translation can resolve to an arbitrary physical address, and corrupted `struct page` metadata can expose page contents across process boundaries.\nI:H - The commit explicitly states the direct entry replacement \"may lead to random crashes and/or data corruption\"; kernel writes to `struct page` through stale RW mappings land in reallocated physical pages, and the corrupted refcount/flags/mapping fields are readily leveraged into arbitrary write and control-flow hijacking primitives.\nA:H - The reporter observed reproducible kernel crashes with HVO enabled on s390, and the attacker can re-trigger the condition at will to reliably panic the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:10:03.176Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7088465f10816d9425b95740b37c95f082041d76"
},
{
"url": "https://git.kernel.org/stable/c/5e23918e4352288323d13fb511116cdea0234b71"
},
{
"url": "https://git.kernel.org/stable/c/d4a8238e5729505b7394ccb007e5dc3e557aa66b"
},
{
"url": "https://git.kernel.org/stable/c/64e2f60f355e556337fcffe80b9bcff1b22c9c42"
}
],
"title": "s390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-68179",
"datePublished": "2025-12-16T13:42:57.817Z",
"dateReserved": "2025-12-16T13:41:40.251Z",
"dateUpdated": "2026-08-05T12:10:03.176Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64552 (GCVE-0-2026-64552)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: fix len check in receive_big()
receive_big() bounds the device-announced length by
(big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose:
add_recvbuf_big() sets sg[1] to start at offset
sizeof(struct padded_vnet_hdr) into the first page, so the chain
actually carries hdr_len + (PAGE_SIZE - sizeof(padded_vnet_hdr)) +
big_packets_num_skbfrags * PAGE_SIZE bytes -- 20 bytes less than the
check allows for the common hdr_len == 12 case.
A malicious virtio backend can announce a len in that gap. page_to_skb()
then walks one frag past the page chain, storing a NULL page->private
into skb_shinfo()->frags[MAX_SKB_FRAGS], which is both an out-of-bounds
write past the static frag array and a NULL frag handed up the rx path.
Bound len by the size add_recvbuf_big() actually advertised.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 82f9028e83944a9eee5229cbc6fee9be1de8a62d Version: 946dec89c41726b94d31147ec528b96af0be1b5a Version: 82fe78065450d2d07f36a22e2b6b44955cf5ca5b Version: 0c716703965ffc5ef4311b65cb5d84a703784717 Version: 0c716703965ffc5ef4311b65cb5d84a703784717 Version: 0c716703965ffc5ef4311b65cb5d84a703784717 Version: 3e9d89f2ecd3636bd4cbdfd0b2dfdaf58f9882e2 Version: 6.1.159 ≤ Version: 6.6.117 ≤ Version: 6.12.58 ≤ Version: 6.17.8 ≤ |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:44.170Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/virtio_net.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f9451d0fd5ba635dcabb49bfe456a6db734a8986",
"status": "affected",
"version": "82f9028e83944a9eee5229cbc6fee9be1de8a62d",
"versionType": "git"
},
{
"lessThan": "38e94d63e29f4a5c6eae87ee2c02101aaa321502",
"status": "affected",
"version": "946dec89c41726b94d31147ec528b96af0be1b5a",
"versionType": "git"
},
{
"lessThan": "fbeb65154583879d556ea94cb2f15888e9470f3d",
"status": "affected",
"version": "82fe78065450d2d07f36a22e2b6b44955cf5ca5b",
"versionType": "git"
},
{
"lessThan": "c7fc9adf4e006155f7f2aeda052fbcde25cdcc49",
"status": "affected",
"version": "0c716703965ffc5ef4311b65cb5d84a703784717",
"versionType": "git"
},
{
"lessThan": "e6b8463b7d791f3886d7584259d6e9f06a69f12e",
"status": "affected",
"version": "0c716703965ffc5ef4311b65cb5d84a703784717",
"versionType": "git"
},
{
"lessThan": "9e5ad06ea826322ce8c58b4a68442a96f600c3c4",
"status": "affected",
"version": "0c716703965ffc5ef4311b65cb5d84a703784717",
"versionType": "git"
},
{
"status": "affected",
"version": "3e9d89f2ecd3636bd4cbdfd0b2dfdaf58f9882e2",
"versionType": "git"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.159",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.117",
"versionType": "semver"
},
{
"lessThan": "6.12.97",
"status": "affected",
"version": "6.12.58",
"versionType": "semver"
},
{
"lessThan": "6.18",
"status": "affected",
"version": "6.17.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/virtio_net.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"lessThan": "6.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.159",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.117",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.12.58",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.17.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-net: fix len check in receive_big()\n\nreceive_big() bounds the device-announced length by\n(big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose:\nadd_recvbuf_big() sets sg[1] to start at offset\nsizeof(struct padded_vnet_hdr) into the first page, so the chain\nactually carries hdr_len + (PAGE_SIZE - sizeof(padded_vnet_hdr)) +\nbig_packets_num_skbfrags * PAGE_SIZE bytes -- 20 bytes less than the\ncheck allows for the common hdr_len == 12 case.\n\nA malicious virtio backend can announce a len in that gap. page_to_skb()\nthen walks one frag past the page chain, storing a NULL page-\u003eprivate\ninto skb_shinfo()-\u003efrags[MAX_SKB_FRAGS], which is both an out-of-bounds\nwrite past the static frag array and a NULL frag handed up the rx path.\n\nBound len by the size add_recvbuf_big() actually advertised."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The malicious input is the buffer length announced by the virtio backend (hypervisor, vhost-user/VDUSE daemon, or virtio-net hardware device), not data from a network peer; a conforming backend can never announce a length in the vulnerable gap. This is the local device-to-driver attack surface, matching how other malicious-virtio-device bugs are scored.\nAC:L - The backend deterministically controls feature negotiation, MTU (hence big_packets_num_skbfrags), and the announced len, so it can force big-packets mode and hit the 20-byte gap on the first packet with no race or memory-layout luck.\nPR:N - The attacking backend requires no credentials or privileges inside the victim kernel \u2014 it is outside the guest\u0027s security authority and simply completes an RX descriptor. No guest-side account is needed.\nUI:N - Triggered automatically in the NAPI receive path as soon as the backend completes a receive buffer; no victim action is required.\nS:U - The corruption and crash are confined to the kernel that owns the virtio-net driver, with no crossing into a different security-managing authority such as an IOMMU or hypervisor boundary.\nC:H - A controlled 16-byte out-of-bounds write past skb_shared_info into an adjacent skb head in the NAPI page-frag cache lets the attacker corrupt neighbouring network buffer metadata, which is leverageable to disclose adjacent kernel memory; nr_frags is also left one past MAX_SKB_FRAGS so downstream code reads out-of-bounds frag state.\nI:H - This is an out-of-bounds write past the end of the static skb_shinfo()-\u003efrags[] array with attacker-influenced index and size, corrupting adjacent slab/page-frag memory \u2014 per guidance an OOB write is High and is potentially leverageable for control-flow hijack.\nA:H - After the OOB write, a NULL page is stored as a frag and immediately dereferenced via compound_head() in softirq context, producing a guaranteed kernel oops; the backend can repeat this at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:29.862Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f9451d0fd5ba635dcabb49bfe456a6db734a8986"
},
{
"url": "https://git.kernel.org/stable/c/38e94d63e29f4a5c6eae87ee2c02101aaa321502"
},
{
"url": "https://git.kernel.org/stable/c/fbeb65154583879d556ea94cb2f15888e9470f3d"
},
{
"url": "https://git.kernel.org/stable/c/c7fc9adf4e006155f7f2aeda052fbcde25cdcc49"
},
{
"url": "https://git.kernel.org/stable/c/e6b8463b7d791f3886d7584259d6e9f06a69f12e"
},
{
"url": "https://git.kernel.org/stable/c/9e5ad06ea826322ce8c58b4a68442a96f600c3c4"
}
],
"title": "virtio-net: fix len check in receive_big()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64552",
"datePublished": "2026-07-27T20:10:40.570Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-09-08T08:50:44.170Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64178 (GCVE-0-2026-64178)
Vulnerability from cvelistv5
Published
2026-07-19 15:41
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: bnep: Fix UAF read of dev->name
bnep_add_connection() needs to keep holding the bnep_session_sem while
reading dev->name (just like bnep_get_connlist() does); otherwise the
bnep_session() thread can concurrently free the net_device, which can for
example be triggered by a concurrent bnep_del_connection().
(This UAF is fairly uninteresting from a security perspective;
calling bnep_add_connection() requires passing a capable(CAP_NET_ADMIN)
check. It also requires completely tearing down a netdev during a fairly
tight race window.)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/bnep/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a75bbcb10cb21acc169b785e9804f57d97873a9c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "4907596f25b1720fa948371ac5f6c1f8da10a5bc",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "915a92182e2cda9cd7d2479020a44c6eda986f7c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "fe69f634b076ae3ca81c5a5b845d9bba527036f7",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b21805258d7e926adfd455fc820a447b90da3b82",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5506aec795135cdd4cbf4e845929155663b25055",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e7578529b97e5d4e439cf8f3e637c2303015338f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "59e932ded949fa6f0340bf7c6d7818f962fa4fd2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/bnep/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: bnep: Fix UAF read of dev-\u003ename\n\nbnep_add_connection() needs to keep holding the bnep_session_sem while\nreading dev-\u003ename (just like bnep_get_connlist() does); otherwise the\nbnep_session() thread can concurrently free the net_device, which can for\nexample be triggered by a concurrent bnep_del_connection().\n\n(This UAF is fairly uninteresting from a security perspective;\ncalling bnep_add_connection() requires passing a capable(CAP_NET_ADMIN)\ncheck. It also requires completely tearing down a netdev during a fairly\ntight race window.)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is in BNEP session setup for Bluetooth PAN; the highest-impact scenario is an adjacent Bluetooth peer on a phone or laptop whose stack calls BNEPCONNADD during PAN bridging, not a generic local syscall path.\nAC:L - The attacker controls disconnect/reconnect timing on the established L2CAP socket and can repeatedly race teardown against bnep_add_connection()\u0027s unprotected strcpy window; UAF races with attacker-controlled concurrency are AC:L.\nPR:N - Exploitation does not require attacker privileges on the victim\u2014only adjacency as the connected Bluetooth peer while the victim\u0027s privileged bluetoothd issues BNEPCONNADD; CAP_NET_ADMIN gates the ioctl on the victim side, not the attacker.\nUI:N - Once Bluetooth PAN/tethering is available, the attacker initiates and tears down the connection to drive the race without requiring additional victim action during exploitation.\nS:U - Impact is kernel memory corruption and potential privilege escalation within the host kernel, not crossing into another security authority such as a VM guest or separate sandbox domain.\nC:H - This is a use-after-free read of freed net_device memory via strcpy(dev-\u003ename); UAF reads can expose reclaimed slab contents and support further kernel memory disclosure.\nI:H - UAF on a heap-allocated net_device can be leveraged with heap grooming for control-flow or data corruption beyond the immediate bounded name copy.\nA:H - Concurrent free of the net_device during the UAF read can cause kernel oops/panic and denial of service, consistent with UAF availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:55.555Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a75bbcb10cb21acc169b785e9804f57d97873a9c"
},
{
"url": "https://git.kernel.org/stable/c/4907596f25b1720fa948371ac5f6c1f8da10a5bc"
},
{
"url": "https://git.kernel.org/stable/c/915a92182e2cda9cd7d2479020a44c6eda986f7c"
},
{
"url": "https://git.kernel.org/stable/c/fe69f634b076ae3ca81c5a5b845d9bba527036f7"
},
{
"url": "https://git.kernel.org/stable/c/b21805258d7e926adfd455fc820a447b90da3b82"
},
{
"url": "https://git.kernel.org/stable/c/5506aec795135cdd4cbf4e845929155663b25055"
},
{
"url": "https://git.kernel.org/stable/c/e7578529b97e5d4e439cf8f3e637c2303015338f"
},
{
"url": "https://git.kernel.org/stable/c/59e932ded949fa6f0340bf7c6d7818f962fa4fd2"
}
],
"title": "Bluetooth: bnep: Fix UAF read of dev-\u003ename",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64178",
"datePublished": "2026-07-19T15:41:02.293Z",
"dateReserved": "2026-07-19T07:54:57.039Z",
"dateUpdated": "2026-08-05T12:39:55.555Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64245 (GCVE-0-2026-64245)
Vulnerability from cvelistv5
Published
2026-07-24 15:31
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fbdev: modedb: fix a possible UAF in fb_find_mode()
If mode_option is NULL, it is assigned from mode_option_buf:
if (!mode_option) {
fb_get_options(NULL, &mode_option_buf);
mode_option = mode_option_buf;
}
Later, name is assigned from mode_option:
const char *name = mode_option;
However, mode_option_buf is freed before name is no longer used:
kfree(mode_option_buf);
while name is still accessed by:
if ((name_matches(db[i], name, namelen) ||
Since name aliases mode_option_buf, this may result in a
use-after-free.
Fix this by extending the lifetime of mode_option_buf until the end of the
function by using scope-based resource management for cleanup.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/video/fbdev/core/modedb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c7dc382439f7b019e207055b52e9cec051d42fa9",
"status": "affected",
"version": "089d924d03d5c17b05d02992f57671ccfba1c4f0",
"versionType": "git"
},
{
"lessThan": "f906347d75c7fc377041c6d3c535d0f08846aada",
"status": "affected",
"version": "089d924d03d5c17b05d02992f57671ccfba1c4f0",
"versionType": "git"
},
{
"lessThan": "4d418cf8daf57e454b4d855bf9b2419fd8e6a540",
"status": "affected",
"version": "089d924d03d5c17b05d02992f57671ccfba1c4f0",
"versionType": "git"
},
{
"lessThan": "13b6f0cdd5cd5e60f682ec43134ab0e2024bd356",
"status": "affected",
"version": "089d924d03d5c17b05d02992f57671ccfba1c4f0",
"versionType": "git"
},
{
"lessThan": "85b6256469cebdac395e7447147e06b2e151014f",
"status": "affected",
"version": "089d924d03d5c17b05d02992f57671ccfba1c4f0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/video/fbdev/core/modedb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: modedb: fix a possible UAF in fb_find_mode()\n\nIf mode_option is NULL, it is assigned from mode_option_buf:\n\n if (!mode_option) {\n fb_get_options(NULL, \u0026mode_option_buf);\n mode_option = mode_option_buf;\n }\n\nLater, name is assigned from mode_option:\n\n const char *name = mode_option;\n\nHowever, mode_option_buf is freed before name is no longer used:\n\n kfree(mode_option_buf);\n\nwhile name is still accessed by:\n\n if ((name_matches(db[i], name, namelen) ||\n\nSince name aliases mode_option_buf, this may result in a\nuse-after-free.\n\nFix this by extending the lifetime of mode_option_buf until the end of the\nfunction by using scope-based resource management for cleanup."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:56.311Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c7dc382439f7b019e207055b52e9cec051d42fa9"
},
{
"url": "https://git.kernel.org/stable/c/f906347d75c7fc377041c6d3c535d0f08846aada"
},
{
"url": "https://git.kernel.org/stable/c/4d418cf8daf57e454b4d855bf9b2419fd8e6a540"
},
{
"url": "https://git.kernel.org/stable/c/13b6f0cdd5cd5e60f682ec43134ab0e2024bd356"
},
{
"url": "https://git.kernel.org/stable/c/85b6256469cebdac395e7447147e06b2e151014f"
}
],
"title": "fbdev: modedb: fix a possible UAF in fb_find_mode()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64245",
"datePublished": "2026-07-24T15:31:14.142Z",
"dateReserved": "2026-07-19T15:36:31.772Z",
"dateUpdated": "2026-08-17T04:51:56.311Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72494 (GCVE-0-2026-72494)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: Replace waitqueue and flag with completion
The driver previously used a waitqueue along with an explicit
request_done flag, but without proper barriers around request_done.
An earlier patch by Gui-Dong Han <hanguidong02@gmail.com> attempted
to fix this by adding the missing memory barriers. Rather than
adding the barriers, this patch replaces the waitqueue+flag with
a completion, which is designed for this exact purpose.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/irdma/hw.c",
"drivers/infiniband/hw/irdma/main.h",
"drivers/infiniband/hw/irdma/utils.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bde37aed0724c0139dea177f3aae8d989b6babb1",
"status": "affected",
"version": "44d9e52977a1b90b0db1c7f8b197c218e9226520",
"versionType": "git"
},
{
"lessThan": "d9c8c45e6d2f438a3c8e643ae78b59454fa0fadd",
"status": "affected",
"version": "44d9e52977a1b90b0db1c7f8b197c218e9226520",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/irdma/hw.c",
"drivers/infiniband/hw/irdma/main.h",
"drivers/infiniband/hw/irdma/utils.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Replace waitqueue and flag with completion\n\nThe driver previously used a waitqueue along with an explicit\nrequest_done flag, but without proper barriers around request_done.\n\nAn earlier patch by Gui-Dong Han \u003changuidong02@gmail.com\u003e attempted\nto fix this by adding the missing memory barriers. Rather than\nadding the barriers, this patch replaces the waitqueue+flag with\na completion, which is designed for this exact purpose."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Intel irdma CQP completion/wait synchronization is exercised from remote iWARP/RoCE connection management (SYN/listener/IEQ/AEQ) and deferred-completion events, not only local ibverbs; network peers drive the completion side of the race on internet-facing RDMA/NFS/SMB-Direct servers.\nAC:L - Attacker controls both sides by flooding concurrent connections/CQP ops remotely or via concurrent RDMA verbs locally; missing release/acquire ordering on request_done vs compl_info is triggerable at high operation rates without luck-dependent layout.\nPR:N - Remote CM and packet-processing paths issue/wait on CQP before MPA/application auth; local exploitation needs only standard unprivileged /dev/infiniband/uverbs* access (0666 under typical rdma-core udev rules), not init-namespace capabilities.\nUI:N - Exploitation needs only attacker-driven network or verbs traffic against an already-bound RDMA device/listener; no additional victim user action at attack time beyond normal server role.\nS:U - Impact stays within kernel/driver security domain (CQP request objects, NIC PF reset); no VM escape or cross-authority boundary.\nC:H - Without proper barriers the waiter can observe request_done before compl_info stores, return success with stale op_ret_val/error, and recycle the cqp_request while hardware still references scratch \u2192 UAF/read primitives.\nI:H - Premature recycle/double-put of dynamic cqp_requests enables attacker-influenced heap reuse; stale callbacks on reused objects and invalid kfree paths provide kernel write/control-flow corruption primitives.\nA:H - Lost request_done causes CQP timeout \u2192 ice_rdma_request_reset PF reset; wrong completion state can leave mod_qp_waitq in uninterruptible wait; UAF/panic paths cause kernel crash/hang."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:44:55.551Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bde37aed0724c0139dea177f3aae8d989b6babb1"
},
{
"url": "https://git.kernel.org/stable/c/d9c8c45e6d2f438a3c8e643ae78b59454fa0fadd"
}
],
"title": "RDMA/irdma: Replace waitqueue and flag with completion",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72494",
"datePublished": "2026-08-15T05:57:28.280Z",
"dateReserved": "2026-08-09T03:40:39.937Z",
"dateUpdated": "2026-08-17T05:44:55.551Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64574 (GCVE-0-2026-64574)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: tear down new links on vif update error path
When ieee80211_vif_update_links() adds new links it allocates a link
container for each and calls ieee80211_link_init() (which registers the
per-link debugfs files with file->private_data pointing into the container)
and ieee80211_link_setup(). If the subsequent drv_change_vif_links() fails,
the error path restores the old pointers and jumps to 'free', which frees
the new containers but never removes their debugfs entries or stops the
links. The debugfs files survive with file->private_data dangling at the
freed container, so a later open()+read() (e.g. link-1/txpower)
dereferences freed memory in ieee80211_if_read_link(), a use-after-free.
The removal path already dismantles links correctly via
ieee80211_tear_down_links(), which removes each link's keys and debugfs
entries and calls ieee80211_link_stop(); the add path on the error branch
does not. Commit be1ba9ed221f ("wifi: mac80211: avoid weird state in error
path") hardened this same error path for the link-removal case
(new_links == 0) but left the newly-added links' teardown unaddressed.
drv_change_vif_links() can fail at runtime on MLO drivers (internal
allocation / queue / firmware command failures).
Remove the new links' debugfs entries and stop them before freeing.
BUG: KASAN: slab-use-after-free in ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)
Read of size 8 at addr ffff888011290000 by task exploit/145
Call Trace:
...
ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)
short_proxy_read (fs/debugfs/file.c:373)
vfs_read (fs/read_write.c:572)
ksys_read (fs/read_write.c:716)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
...
Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a
RIP: 0010:ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)
Kernel panic - not syncing: Fatal exception
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/link.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "329589417214d3b7221432e5b266ed2bba7ff674",
"status": "affected",
"version": "170cd6a66d9a164180eb4dc72d50afa6ce1ce566",
"versionType": "git"
},
{
"lessThan": "c57d97f381306bbfba174e8f708419e007824e0c",
"status": "affected",
"version": "170cd6a66d9a164180eb4dc72d50afa6ce1ce566",
"versionType": "git"
},
{
"lessThan": "0f7eaeb950adb77f71beb546e5ab30f90b41fe6f",
"status": "affected",
"version": "170cd6a66d9a164180eb4dc72d50afa6ce1ce566",
"versionType": "git"
},
{
"lessThan": "901a73523e093beff123b54b1ceaf3113f18acc9",
"status": "affected",
"version": "170cd6a66d9a164180eb4dc72d50afa6ce1ce566",
"versionType": "git"
},
{
"lessThan": "952c02b33f56207a160421bcd61e7ac53c9c59ae",
"status": "affected",
"version": "170cd6a66d9a164180eb4dc72d50afa6ce1ce566",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/link.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: tear down new links on vif update error path\n\nWhen ieee80211_vif_update_links() adds new links it allocates a link\ncontainer for each and calls ieee80211_link_init() (which registers the\nper-link debugfs files with file-\u003eprivate_data pointing into the container)\nand ieee80211_link_setup(). If the subsequent drv_change_vif_links() fails,\nthe error path restores the old pointers and jumps to \u0027free\u0027, which frees\nthe new containers but never removes their debugfs entries or stops the\nlinks. The debugfs files survive with file-\u003eprivate_data dangling at the\nfreed container, so a later open()+read() (e.g. link-1/txpower)\ndereferences freed memory in ieee80211_if_read_link(), a use-after-free.\n\nThe removal path already dismantles links correctly via\nieee80211_tear_down_links(), which removes each link\u0027s keys and debugfs\nentries and calls ieee80211_link_stop(); the add path on the error branch\ndoes not. Commit be1ba9ed221f (\"wifi: mac80211: avoid weird state in error\npath\") hardened this same error path for the link-removal case\n(new_links == 0) but left the newly-added links\u0027 teardown unaddressed.\n\ndrv_change_vif_links() can fail at runtime on MLO drivers (internal\nallocation / queue / firmware command failures).\n\nRemove the new links\u0027 debugfs entries and stop them before freeing.\n\n BUG: KASAN: slab-use-after-free in ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n Read of size 8 at addr ffff888011290000 by task exploit/145\n Call Trace:\n ...\n ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n short_proxy_read (fs/debugfs/file.c:373)\n vfs_read (fs/read_write.c:572)\n ksys_read (fs/read_write.c:716)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n ...\n Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a\n RIP: 0010:ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n Kernel panic - not syncing: Fatal exception"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached via local nl80211 link updates (NL80211_CMD_ADD_LINK / ieee80211_vif_set_links \u2192 ieee80211_vif_update_links) and completed by a local debugfs open/read of the dangling per-link file, not by processing over-the-air frames alone.\nAC:L - An attacker can reliably force the error path by adding an MLO AP link whose MAC duplicates an existing link so ieee80211_check_dup_link_addrs() fails after ieee80211_link_init() already registered debugfs, then read the leftover file; no attacker-independent condition is required.\nPR:L - NL80211_CMD_ADD_LINK is gated by GENL_UNS_ADMIN_PERM (CAP_NET_ADMIN in the netns user_ns), which an unprivileged user can obtain via user/net namespaces or common WiFi management paths, so privileges are Low rather than init-namespace root.\nUI:N - The attacker issues the nl80211 ADD_LINK sequence and the subsequent debugfs read themselves; no separate victim action such as mounting a filesystem or opening a hostile file is required.\nS:U - The use-after-free and resulting kernel memory corruption stay within the host mac80211/debugfs authority and do not cross a VM, IOMMU, or other separate security boundary.\nC:H - Dangling debugfs file-\u003eprivate_data points at the freed link_container; reading it (ieee80211_if_read_link) is a slab use-after-free that can be reclaimed/sprayed for arbitrary kernel memory disclosure.\nI:H - The same freed link object is the debugfs private_data for readable/writable per-link files, so UAF reclaim enables attacker-controlled structure contents and control-flow hijack consistent with kernel UAF integrity High.\nA:H - The fix commit\u2019s KASAN slab-use-after-free in ieee80211_if_read_link leads to a general protection fault and kernel panic, so availability impact is High even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:54.008Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/329589417214d3b7221432e5b266ed2bba7ff674"
},
{
"url": "https://git.kernel.org/stable/c/c57d97f381306bbfba174e8f708419e007824e0c"
},
{
"url": "https://git.kernel.org/stable/c/0f7eaeb950adb77f71beb546e5ab30f90b41fe6f"
},
{
"url": "https://git.kernel.org/stable/c/901a73523e093beff123b54b1ceaf3113f18acc9"
},
{
"url": "https://git.kernel.org/stable/c/952c02b33f56207a160421bcd61e7ac53c9c59ae"
}
],
"title": "wifi: mac80211: tear down new links on vif update error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64574",
"datePublished": "2026-08-05T08:08:10.272Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-17T04:57:54.008Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64481 (GCVE-0-2026-64481)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: hda/cs35l41: Fix firmware load work teardown
cs35l41_hda creates ALSA controls whose private data points at the
cs35l41_hda object. The firmware load control can also queue
fw_load_work.
Those controls are not removed on component unbind, and device remove
only cancels fw_load_work through cs35l41_remove_dsp(). That helper is
skipped when halo_initialized is false. With firmware_autostart
disabled, a firmware load can be requested before the DSP has been
initialized. If the component or device is removed before the queued
work runs, the worker can run after teardown and dereference driver
state that is no longer valid.
Track the created controls and remove them on unbind so no new control
callback can reach the driver data or queue more work. Then cancel
fw_load_work to drain any request that was already queued. Also cancel
the work unconditionally during device remove before runtime PM teardown.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/hda/codecs/side-codecs/cs35l41_hda.c",
"sound/hda/codecs/side-codecs/cs35l41_hda.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8947215c0136c9d905e4a46d824824f8b48a2e5b",
"status": "affected",
"version": "47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8",
"versionType": "git"
},
{
"lessThan": "ce0a903d0591e3e2c790c5b628802b08d1b287cc",
"status": "affected",
"version": "47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8",
"versionType": "git"
},
{
"lessThan": "d6a40a4d083ef74d00c8f9516cb5ff07ac70720b",
"status": "affected",
"version": "47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8",
"versionType": "git"
},
{
"lessThan": "b65020d5398f499c09498c9786dba6d67ae57664",
"status": "affected",
"version": "47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/hda/codecs/side-codecs/cs35l41_hda.c",
"sound/hda/codecs/side-codecs/cs35l41_hda.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/cs35l41: Fix firmware load work teardown\n\ncs35l41_hda creates ALSA controls whose private data points at the\ncs35l41_hda object. The firmware load control can also queue\nfw_load_work.\n\nThose controls are not removed on component unbind, and device remove\nonly cancels fw_load_work through cs35l41_remove_dsp(). That helper is\nskipped when halo_initialized is false. With firmware_autostart\ndisabled, a firmware load can be requested before the DSP has been\ninitialized. If the component or device is removed before the queued\nwork runs, the worker can run after teardown and dereference driver\nstate that is no longer valid.\n\nTrack the created controls and remove them on unbind so no new control\ncallback can reach the driver data or queue more work. Then cancel\nfw_load_work to drain any request that was already queued. Also cancel\nthe work unconditionally during device remove before runtime PM teardown."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - An attacker reaches the vulnerable callbacks through ALSA control ioctls on /dev/snd/controlC*. No network or physical protocol directly exposes this path.\nAC:L - After teardown, stale controls can repeatedly dereference the freed object or queue its embedded work item, so exploitation does not require winning a narrow race. A queued work_struct also remains directly usable after its containing allocation is freed.\nPR:L - An unprivileged user with ordinary audio-device access can invoke the control callbacks. The ioctl path contains no capability, namespace, or administrative privilege check.\nUI:N - Exploitation requires no victim to open content or perform an interactive action.\nS:U - The vulnerable driver and the affected kernel resources are governed by the same kernel security authority.\nC:H - The heap use-after-free permits attacker-influenced reuse and disclosure of freed kernel object contents, potentially supporting arbitrary kernel memory reads.\nI:H - The freed object embeds mutable workqueue list state and a function pointer that is subsequently invoked, making kernel memory corruption and control-flow hijacking defensible.\nA:H - Stale control accesses or corrupted queued work can cause a kernel oops, panic, or workqueue corruption, resulting in complete system unavailability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:28.073Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8947215c0136c9d905e4a46d824824f8b48a2e5b"
},
{
"url": "https://git.kernel.org/stable/c/ce0a903d0591e3e2c790c5b628802b08d1b287cc"
},
{
"url": "https://git.kernel.org/stable/c/d6a40a4d083ef74d00c8f9516cb5ff07ac70720b"
},
{
"url": "https://git.kernel.org/stable/c/b65020d5398f499c09498c9786dba6d67ae57664"
}
],
"title": "ALSA: hda/cs35l41: Fix firmware load work teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64481",
"datePublished": "2026-07-25T08:51:42.430Z",
"dateReserved": "2026-07-19T15:36:31.791Z",
"dateUpdated": "2026-08-17T04:56:28.073Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68180 (GCVE-0-2026-68180)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
intel_th: fix MSC output device reference leak
intel_th_output_open() looks up the output device with
bus_find_device_by_devt(), which returns the device with a reference that
must be dropped after use.
commit 95fc36a234da ("intel_th: fix device leak on output open()")
attempted to drop the reference from intel_th_output_release(). However,
a successful open replaces file->f_op with the output driver file
operations before returning, so close runs the output driver release
callback instead.
For MSC outputs, close runs intel_th_msc_release(), which only removes
the per-file iterator and does not drop the device reference taken by
intel_th_output_open(). Consequently, every successful MSC output open
leaks one device reference.
Drop the device reference from intel_th_msc_release(), which is the
release path actually used for MSC output files. Remove the now-unused
intel_th_output_release() callback from intel_th_output_fops.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: af4b9467296b9a16ebc008147238070236982b6d Version: 64015cbf06e8bb75b81ae95b997e847b55280f7f Version: b71e64ef7ff9443835d1333e3e80ab1e49e5209f Version: bf7785434b5d05d940d936b78925080950bd54dd Version: 0fca16c5591534cc1fec8b6181277ee3a3d0f26c Version: f9b059bda4276f2bb72cb98ec7875a747f042ea2 Version: 95fc36a234da24bbc5f476f8104a5a15f99ed3e3 Version: 95fc36a234da24bbc5f476f8104a5a15f99ed3e3 Version: 5.10.249 ≤ Version: 5.15.199 ≤ Version: 6.1.162 ≤ Version: 6.6.122 ≤ Version: 6.12.68 ≤ Version: 6.18.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwtracing/intel_th/core.c",
"drivers/hwtracing/intel_th/msu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "12ad4fad748e6e563ff4480f03b89134a41b5c37",
"status": "affected",
"version": "af4b9467296b9a16ebc008147238070236982b6d",
"versionType": "git"
},
{
"lessThan": "df55842fddbcdb80e6dd16680439c0f780ed592e",
"status": "affected",
"version": "64015cbf06e8bb75b81ae95b997e847b55280f7f",
"versionType": "git"
},
{
"lessThan": "141641a70ed337e54487f766ede745fc2ce44c42",
"status": "affected",
"version": "b71e64ef7ff9443835d1333e3e80ab1e49e5209f",
"versionType": "git"
},
{
"lessThan": "ddcf2064d7ec5a8c9afa7cb74442320e443502bc",
"status": "affected",
"version": "bf7785434b5d05d940d936b78925080950bd54dd",
"versionType": "git"
},
{
"lessThan": "26e27b8dcef1e4df6f30d8f25b3304a506d482b3",
"status": "affected",
"version": "0fca16c5591534cc1fec8b6181277ee3a3d0f26c",
"versionType": "git"
},
{
"lessThan": "caba30eb8bd321c465ecfc7d850ee85f5b353496",
"status": "affected",
"version": "f9b059bda4276f2bb72cb98ec7875a747f042ea2",
"versionType": "git"
},
{
"lessThan": "c3a28f9cb82425fe0835048ed3677f321e780691",
"status": "affected",
"version": "95fc36a234da24bbc5f476f8104a5a15f99ed3e3",
"versionType": "git"
},
{
"lessThan": "761b785a0cfbce43761227bc42a7f984f31f8921",
"status": "affected",
"version": "95fc36a234da24bbc5f476f8104a5a15f99ed3e3",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.249",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.199",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.162",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.122",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.68",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwtracing/intel_th/core.c",
"drivers/hwtracing/intel_th/msu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"lessThan": "6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.249",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.199",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.162",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.122",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.68",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nintel_th: fix MSC output device reference leak\n\nintel_th_output_open() looks up the output device with\nbus_find_device_by_devt(), which returns the device with a reference that\nmust be dropped after use.\n\ncommit 95fc36a234da (\"intel_th: fix device leak on output open()\")\nattempted to drop the reference from intel_th_output_release(). However,\na successful open replaces file-\u003ef_op with the output driver file\noperations before returning, so close runs the output driver release\ncallback instead.\n\nFor MSC outputs, close runs intel_th_msc_release(), which only removes\nthe per-file iterator and does not drop the device reference taken by\nintel_th_output_open(). Consequently, every successful MSC output open\nleaks one device reference.\n\nDrop the device reference from intel_th_msc_release(), which is the\nrelease path actually used for MSC output files. Remove the now-unused\nintel_th_output_release() callback from intel_th_output_fops."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:44.755Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/12ad4fad748e6e563ff4480f03b89134a41b5c37"
},
{
"url": "https://git.kernel.org/stable/c/df55842fddbcdb80e6dd16680439c0f780ed592e"
},
{
"url": "https://git.kernel.org/stable/c/141641a70ed337e54487f766ede745fc2ce44c42"
},
{
"url": "https://git.kernel.org/stable/c/ddcf2064d7ec5a8c9afa7cb74442320e443502bc"
},
{
"url": "https://git.kernel.org/stable/c/26e27b8dcef1e4df6f30d8f25b3304a506d482b3"
},
{
"url": "https://git.kernel.org/stable/c/caba30eb8bd321c465ecfc7d850ee85f5b353496"
},
{
"url": "https://git.kernel.org/stable/c/c3a28f9cb82425fe0835048ed3677f321e780691"
},
{
"url": "https://git.kernel.org/stable/c/761b785a0cfbce43761227bc42a7f984f31f8921"
}
],
"title": "intel_th: fix MSC output device reference leak",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68180",
"datePublished": "2026-08-10T11:59:51.694Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:44.755Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64304 (GCVE-0-2026-64304)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: qat - validate RSA CRT component lengths
The generic RSA key parser (rsa_helper.c) bounds each CRT component (p,
q, dp, dq, qinv) by the modulus size n_sz, but qat_rsa_setkey_crt()
allocates half-size DMA buffers (key_sz / 2) and right-aligns each
component with:
memcpy(dst + half_key_sz - len, src, len)
When a CRT component is larger than half_key_sz the subtraction
underflows and memcpy writes past the DMA buffer, causing memory
corruption.
Add a len > half_key_sz check next to the existing !len check for each
of the five CRT components so the driver falls back to the non-CRT path
instead of writing out of bounds.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 879f77e9071f029e1c9bd5a75814ecf51370f846 Version: 879f77e9071f029e1c9bd5a75814ecf51370f846 Version: 879f77e9071f029e1c9bd5a75814ecf51370f846 Version: 879f77e9071f029e1c9bd5a75814ecf51370f846 Version: 879f77e9071f029e1c9bd5a75814ecf51370f846 Version: 879f77e9071f029e1c9bd5a75814ecf51370f846 Version: 879f77e9071f029e1c9bd5a75814ecf51370f846 Version: 879f77e9071f029e1c9bd5a75814ecf51370f846 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/crypto/intel/qat/qat_common/qat_asym_algs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6d99c5fadd2df488103f64d6475b63ba6852202b",
"status": "affected",
"version": "879f77e9071f029e1c9bd5a75814ecf51370f846",
"versionType": "git"
},
{
"lessThan": "c34369473bfe92a0b46ec78d6358e30341c7f481",
"status": "affected",
"version": "879f77e9071f029e1c9bd5a75814ecf51370f846",
"versionType": "git"
},
{
"lessThan": "1002719d13072a5e4be1e993aa61dffb4a604e82",
"status": "affected",
"version": "879f77e9071f029e1c9bd5a75814ecf51370f846",
"versionType": "git"
},
{
"lessThan": "500319830d76911c120dc0b9605f8c16d7702844",
"status": "affected",
"version": "879f77e9071f029e1c9bd5a75814ecf51370f846",
"versionType": "git"
},
{
"lessThan": "3d61a214fdcda41f1ebfabbb483404032a7b4d91",
"status": "affected",
"version": "879f77e9071f029e1c9bd5a75814ecf51370f846",
"versionType": "git"
},
{
"lessThan": "6fb62b767f3e27661e8f8d2f7b85f4e098fcdb1a",
"status": "affected",
"version": "879f77e9071f029e1c9bd5a75814ecf51370f846",
"versionType": "git"
},
{
"lessThan": "ce42224487c504aee4b7ff3a7342e7b4d7e28cc9",
"status": "affected",
"version": "879f77e9071f029e1c9bd5a75814ecf51370f846",
"versionType": "git"
},
{
"lessThan": "b3ac78756588059729b9195fcc9f4b37d54057a5",
"status": "affected",
"version": "879f77e9071f029e1c9bd5a75814ecf51370f846",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/crypto/intel/qat/qat_common/qat_asym_algs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - validate RSA CRT component lengths\n\nThe generic RSA key parser (rsa_helper.c) bounds each CRT component (p,\nq, dp, dq, qinv) by the modulus size n_sz, but qat_rsa_setkey_crt()\nallocates half-size DMA buffers (key_sz / 2) and right-aligns each\ncomponent with:\n\n memcpy(dst + half_key_sz - len, src, len)\n\nWhen a CRT component is larger than half_key_sz the subtraction\nunderflows and memcpy writes past the DMA buffer, causing memory\ncorruption.\n\nAdd a len \u003e half_key_sz check next to the existing !len check for each\nof the five CRT components so the driver falls back to the non-CRT path\ninstead of writing out of bounds."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - An unprivileged local process can add a crafted PKCS#8 RSA private key to its own keyring and invoke KEYCTL_PKEY_QUERY, which selects qat-rsa and reaches the vulnerable key setup path.\nAC:L - With an active QAT asymmetric service and PKCS#8 parser, an oversized CRT integer deterministically causes unsigned offset underflow and an out-of-bounds memcpy. No race or attacker-uncontrollable condition is required.\nPR:L - An ordinary user can create, search, and use keys in a personal process, thread, or session keyring. No capability, administrator privilege, or user namespace is required.\nUI:N - The attacker directly performs the add_key and keyctl system calls without any victim action.\nS:U - The vulnerable QAT driver and the corrupted kernel resources share the same security authority. Ordinary kernel privilege escalation does not cross a CVSS scope boundary.\nC:H - The controlled kernel-memory overwrite can corrupt page tables, credentials, or control-flow objects and plausibly yield code execution with access to protected kernel memory.\nI:H - Attacker-controlled CRT bytes are written outside the coherent DMA allocation, potentially through multiple CRT components. This can provide powerful kernel-memory corruption and control-flow hijacking primitives.\nA:H - The invalid destination can cause an immediate kernel fault or corrupt unrelated kernel memory and subsequently panic or hang the system. The attack is repeatable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:03.298Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6d99c5fadd2df488103f64d6475b63ba6852202b"
},
{
"url": "https://git.kernel.org/stable/c/c34369473bfe92a0b46ec78d6358e30341c7f481"
},
{
"url": "https://git.kernel.org/stable/c/1002719d13072a5e4be1e993aa61dffb4a604e82"
},
{
"url": "https://git.kernel.org/stable/c/500319830d76911c120dc0b9605f8c16d7702844"
},
{
"url": "https://git.kernel.org/stable/c/3d61a214fdcda41f1ebfabbb483404032a7b4d91"
},
{
"url": "https://git.kernel.org/stable/c/6fb62b767f3e27661e8f8d2f7b85f4e098fcdb1a"
},
{
"url": "https://git.kernel.org/stable/c/ce42224487c504aee4b7ff3a7342e7b4d7e28cc9"
},
{
"url": "https://git.kernel.org/stable/c/b3ac78756588059729b9195fcc9f4b37d54057a5"
}
],
"title": "crypto: qat - validate RSA CRT component lengths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64304",
"datePublished": "2026-07-25T08:49:38.873Z",
"dateReserved": "2026-07-19T15:36:31.779Z",
"dateUpdated": "2026-08-17T04:53:03.298Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68154 (GCVE-0-2026-68154)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: reject zero bucket types in crush_decode
CRUSH bucket type 0 is reserved for devices. The mapper relies on
that invariant and uses type 0 to identify leaf devices.
If crush_decode() accepts a bucket with type 0, a malformed CRUSH map
can make the mapper treat a negative bucket ID as a device and pass it
to is_out(), which then indexes the OSD weight array with a negative
value.
Reject zero bucket types while decoding the CRUSH map so the invalid
state never reaches the mapper.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "952ca5dc99913d169263f59fd689f586729a13c1",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "146461f09565afe3665e65b0423d3d6b0fe806c5",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "80fc40e11cda1b5d990a3f69c6efa344fb5cd987",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "b8a9fb6bf806f9c4891e71ae1beab0c07c23a877",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "826cd1de5802fd392922785f9b64d76e65d2a100",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "3b2f1937f5fce8b7dd5432e7693e3cc8b5eece56",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "70998f91030ee083ecb336a1dff0701c20a38081",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "05f90284223381005d6bcddab3fda4a97f9c3401",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: reject zero bucket types in crush_decode\n\nCRUSH bucket type 0 is reserved for devices. The mapper relies on\nthat invariant and uses type 0 to identify leaf devices.\n\nIf crush_decode() accepts a bucket with type 0, a malformed CRUSH map\ncan make the mapper treat a negative bucket ID as a device and pass it\nto is_out(), which then indexes the OSD weight array with a negative\nvalue.\n\nReject zero bucket types while decoding the CRUSH map so the invalid\nstate never reaches the mapper."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached when the in-kernel Ceph client decodes a crafted CRUSH map inside CEPH_MSG_OSD_MAP received over TCP from a Ceph monitor or OSD, which is a standard network-delivered cluster control message on connected storage clients.\nAC:L - An attacker can reliably craft a CRUSH map with a bucket whose type field is zero and controlled hierarchy/items so crush_do_rule() later calls is_out() with a negative index, without races, victim-specific memory layout, or rare kernel build options.\nPR:N - No local privileges on the victim host are required; a remote attacker who controls, compromises, or MITMs the authenticated Ceph monitor/OSD peer can deliver the malicious OSD map over the established client cluster connection.\nUI:N - No additional victim action is needed at exploit time because poisoned OSD maps are processed automatically and CRUSH placement is recalculated during routine map updates, request rescanning, and normal Ceph client I/O.\nS:U - The vulnerability corrupts or reads kernel memory on the host running the Ceph client, affecting that kernel security domain rather than crossing a VM, container sandbox, or IOMMU boundary.\nC:H - When a type-0 bucket makes the mapper treat a negative bucket ID as a device, is_out() indexes osd_weight[] with a negative value, causing an out-of-bounds read of adjacent kernel memory beyond the OSD weight array.\nI:H - This out-of-bounds kernel heap access during CRUSH placement is memory corruption in a privileged parser/mapper path that can be leveraged for further kernel memory control and arbitrary code execution, not only information disclosure.\nA:H - The invalid negative indexing during CRUSH mapping can dereference unmapped or non-resident memory and trigger a kernel oops or panic, causing complete loss of availability on affected Ceph client hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:20.481Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/952ca5dc99913d169263f59fd689f586729a13c1"
},
{
"url": "https://git.kernel.org/stable/c/146461f09565afe3665e65b0423d3d6b0fe806c5"
},
{
"url": "https://git.kernel.org/stable/c/80fc40e11cda1b5d990a3f69c6efa344fb5cd987"
},
{
"url": "https://git.kernel.org/stable/c/b8a9fb6bf806f9c4891e71ae1beab0c07c23a877"
},
{
"url": "https://git.kernel.org/stable/c/826cd1de5802fd392922785f9b64d76e65d2a100"
},
{
"url": "https://git.kernel.org/stable/c/3b2f1937f5fce8b7dd5432e7693e3cc8b5eece56"
},
{
"url": "https://git.kernel.org/stable/c/70998f91030ee083ecb336a1dff0701c20a38081"
},
{
"url": "https://git.kernel.org/stable/c/05f90284223381005d6bcddab3fda4a97f9c3401"
}
],
"title": "libceph: reject zero bucket types in crush_decode",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68154",
"datePublished": "2026-08-10T11:59:20.250Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:20.481Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64448 (GCVE-0-2026-64448)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: restrict implied bcc[0] exemption to responses without data area
smb2_check_message() has a long-standing quirk that accepts a response
whose calculated length is one byte larger than the bytes actually
received ("server can return one byte more due to implied bcc[0]").
This was introduced to accommodate servers that omit the trailing bcc[0]
overlap byte when no data area is present.
However, the exemption is applied unconditionally, regardless of whether
the command actually carries a data area (has_smb2_data_area[]). When a
response with a data area is subject to the +1 exemption, the reported
data can extend one byte beyond the bytes actually received, yet
smb2_check_message() still accepts it. The subsequent decoder then reads
past the end of the receive buffer. This is reachable during NEGOTIATE
and SESSION_SETUP, before the session is established.
The resulting out-of-bounds reads are visible under KASAN when mounting
against a non-conforming server; both the SPNEGO/negTokenInit and the
NTLMSSP challenge decoders are affected:
BUG: KASAN: slab-out-of-bounds in asn1_ber_decoder+0x16a7/0x1b00
Read of size 1 at addr ffff8880084d67c0 by task mount.cifs/81
CPU: 1 UID: 0 PID: 81 Comm: mount.cifs Not tainted 7.1.0-rc6 #1
Call Trace:
<TASK>
dump_stack_lvl+0x4e/0x70
print_report+0x157/0x4c9
kasan_report+0xce/0x100
asn1_ber_decoder+0x16a7/0x1b00
decode_negTokenInit+0x19/0x30
SMB2_negotiate+0x31d9/0x4c90
cifs_negotiate_protocol+0x1f2/0x3f0
cifs_get_smb_ses+0x93f/0x17e0
cifs_mount_get_session+0x7f/0x3a0
cifs_mount+0xb4/0xcf0
cifs_smb3_do_mount+0x23a/0x1500
smb3_get_tree+0x3b0/0x630
vfs_get_tree+0x82/0x2d0
fc_mount+0x10/0x1b0
path_mount+0x50d/0x1de0
__x64_sys_mount+0x20b/0x270
do_syscall_64+0xee/0x590
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
Allocated by task 85:
kmem_cache_alloc_noprof+0x106/0x380
mempool_alloc_noprof+0x116/0x1e0
cifs_small_buf_get+0x31/0x80
allocate_buffers+0x10d/0x2b0
cifs_demultiplex_thread+0x1d5/0x1d50
kthread+0x2c6/0x390
ret_from_fork+0x36e/0x5a0
ret_from_fork_asm+0x1a/0x30
The buggy address is located 0 bytes to the right of
allocated 448-byte region [ffff8880084d6600, ffff8880084d67c0)
which belongs to the cache cifs_small_rq of size 448
BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x36/0x50
Read of size 329 at addr ffff88800726c678 by task mount.cifs/89
CPU: 0 UID: 0 PID: 89 Comm: mount.cifs Tainted: G B 7.1.0-rc6 #1
Call Trace:
<TASK>
dump_stack_lvl+0x4e/0x70
print_report+0x157/0x4c9
kasan_report+0xce/0x100
kasan_check_range+0x10f/0x1e0
__asan_memcpy+0x23/0x60
kmemdup_noprof+0x36/0x50
decode_ntlmssp_challenge+0x457/0x680
SMB2_sess_auth_rawntlmssp_negotiate+0x6f0/0xcb0
SMB2_sess_setup+0x219/0x4f0
cifs_setup_session+0x248/0xaf0
cifs_get_smb_ses+0xf79/0x17e0
cifs_mount_get_session+0x7f/0x3a0
cifs_mount+0xb4/0xcf0
cifs_smb3_do_mount+0x23a/0x1500
smb3_get_tree+0x3b0/0x630
vfs_get_tree+0x82/0x2d0
fc_mount+0x10/0x1b0
path_mount+0x50d/0x1de0
__x64_sys_mount+0x20b/0x270
do_syscall_64+0xee/0x590
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
Allocated by task 93:
kmem_cache_alloc_noprof+0x106/0x380
mempool_alloc_noprof+0x116/0x1e0
cifs_small_buf_get+0x31/0x80
allocate_buffers+0x10d/0x2b0
cifs_demultiplex_thread+0x1d5/0x1d50
kthread+0x2c6/0x390
ret_from_fork+0x36e/0x5a0
ret_from_fork_asm+0x1a/0x30
The buggy address is located 120 bytes inside of
allocated 448-byte region [ffff88800726c600, ffff88800726c7c0)
which belongs to the cache cifs_small_rq of size 448
Restrict the +1 exemption to responses that have no data area, so that
it still covers the bcc[0] omission it was meant for. When a data area
is present, the +1 discrepancy instead means the reported data length
overruns the
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 093b2bdad3221e3fae3c26d89387e7297a157664 Version: 093b2bdad3221e3fae3c26d89387e7297a157664 Version: 093b2bdad3221e3fae3c26d89387e7297a157664 Version: 093b2bdad3221e3fae3c26d89387e7297a157664 Version: 093b2bdad3221e3fae3c26d89387e7297a157664 Version: 093b2bdad3221e3fae3c26d89387e7297a157664 Version: 093b2bdad3221e3fae3c26d89387e7297a157664 Version: 093b2bdad3221e3fae3c26d89387e7297a157664 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8d0bbc78046d264bbf6a574ea6f9072258a43e35",
"status": "affected",
"version": "093b2bdad3221e3fae3c26d89387e7297a157664",
"versionType": "git"
},
{
"lessThan": "b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0",
"status": "affected",
"version": "093b2bdad3221e3fae3c26d89387e7297a157664",
"versionType": "git"
},
{
"lessThan": "31c6312608c60b72a1feb99a5afb680645a3e8a3",
"status": "affected",
"version": "093b2bdad3221e3fae3c26d89387e7297a157664",
"versionType": "git"
},
{
"lessThan": "573e502d14714d2947e22e7eff40ec20a6a44a42",
"status": "affected",
"version": "093b2bdad3221e3fae3c26d89387e7297a157664",
"versionType": "git"
},
{
"lessThan": "419ec1b604d7fb60c10aec2dc062371f9fcd4940",
"status": "affected",
"version": "093b2bdad3221e3fae3c26d89387e7297a157664",
"versionType": "git"
},
{
"lessThan": "ceb875a375dedbf51c9425c1d13a2d7a8435c08c",
"status": "affected",
"version": "093b2bdad3221e3fae3c26d89387e7297a157664",
"versionType": "git"
},
{
"lessThan": "6e9d10f62773b99bd927940fd9cbdfe7207e23ff",
"status": "affected",
"version": "093b2bdad3221e3fae3c26d89387e7297a157664",
"versionType": "git"
},
{
"lessThan": "53b7c271f06be4dd5cfc8c6ef552a8355c891a7f",
"status": "affected",
"version": "093b2bdad3221e3fae3c26d89387e7297a157664",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.6"
},
{
"lessThan": "3.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: restrict implied bcc[0] exemption to responses without data area\n\nsmb2_check_message() has a long-standing quirk that accepts a response\nwhose calculated length is one byte larger than the bytes actually\nreceived (\"server can return one byte more due to implied bcc[0]\").\nThis was introduced to accommodate servers that omit the trailing bcc[0]\noverlap byte when no data area is present.\n\nHowever, the exemption is applied unconditionally, regardless of whether\nthe command actually carries a data area (has_smb2_data_area[]). When a\nresponse with a data area is subject to the +1 exemption, the reported\ndata can extend one byte beyond the bytes actually received, yet\nsmb2_check_message() still accepts it. The subsequent decoder then reads\npast the end of the receive buffer. This is reachable during NEGOTIATE\nand SESSION_SETUP, before the session is established.\n\nThe resulting out-of-bounds reads are visible under KASAN when mounting\nagainst a non-conforming server; both the SPNEGO/negTokenInit and the\nNTLMSSP challenge decoders are affected:\n\n BUG: KASAN: slab-out-of-bounds in asn1_ber_decoder+0x16a7/0x1b00\n Read of size 1 at addr ffff8880084d67c0 by task mount.cifs/81\n CPU: 1 UID: 0 PID: 81 Comm: mount.cifs Not tainted 7.1.0-rc6 #1\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x4e/0x70\n print_report+0x157/0x4c9\n kasan_report+0xce/0x100\n asn1_ber_decoder+0x16a7/0x1b00\n decode_negTokenInit+0x19/0x30\n SMB2_negotiate+0x31d9/0x4c90\n cifs_negotiate_protocol+0x1f2/0x3f0\n cifs_get_smb_ses+0x93f/0x17e0\n cifs_mount_get_session+0x7f/0x3a0\n cifs_mount+0xb4/0xcf0\n cifs_smb3_do_mount+0x23a/0x1500\n smb3_get_tree+0x3b0/0x630\n vfs_get_tree+0x82/0x2d0\n fc_mount+0x10/0x1b0\n path_mount+0x50d/0x1de0\n __x64_sys_mount+0x20b/0x270\n do_syscall_64+0xee/0x590\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n \u003c/TASK\u003e\n Allocated by task 85:\n kmem_cache_alloc_noprof+0x106/0x380\n mempool_alloc_noprof+0x116/0x1e0\n cifs_small_buf_get+0x31/0x80\n allocate_buffers+0x10d/0x2b0\n cifs_demultiplex_thread+0x1d5/0x1d50\n kthread+0x2c6/0x390\n ret_from_fork+0x36e/0x5a0\n ret_from_fork_asm+0x1a/0x30\n The buggy address is located 0 bytes to the right of\n allocated 448-byte region [ffff8880084d6600, ffff8880084d67c0)\n which belongs to the cache cifs_small_rq of size 448\n\n BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x36/0x50\n Read of size 329 at addr ffff88800726c678 by task mount.cifs/89\n CPU: 0 UID: 0 PID: 89 Comm: mount.cifs Tainted: G B 7.1.0-rc6 #1\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x4e/0x70\n print_report+0x157/0x4c9\n kasan_report+0xce/0x100\n kasan_check_range+0x10f/0x1e0\n __asan_memcpy+0x23/0x60\n kmemdup_noprof+0x36/0x50\n decode_ntlmssp_challenge+0x457/0x680\n SMB2_sess_auth_rawntlmssp_negotiate+0x6f0/0xcb0\n SMB2_sess_setup+0x219/0x4f0\n cifs_setup_session+0x248/0xaf0\n cifs_get_smb_ses+0xf79/0x17e0\n cifs_mount_get_session+0x7f/0x3a0\n cifs_mount+0xb4/0xcf0\n cifs_smb3_do_mount+0x23a/0x1500\n smb3_get_tree+0x3b0/0x630\n vfs_get_tree+0x82/0x2d0\n fc_mount+0x10/0x1b0\n path_mount+0x50d/0x1de0\n __x64_sys_mount+0x20b/0x270\n do_syscall_64+0xee/0x590\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n \u003c/TASK\u003e\n Allocated by task 93:\n kmem_cache_alloc_noprof+0x106/0x380\n mempool_alloc_noprof+0x116/0x1e0\n cifs_small_buf_get+0x31/0x80\n allocate_buffers+0x10d/0x2b0\n cifs_demultiplex_thread+0x1d5/0x1d50\n kthread+0x2c6/0x390\n ret_from_fork+0x36e/0x5a0\n ret_from_fork_asm+0x1a/0x30\n The buggy address is located 120 bytes inside of\n allocated 448-byte region [ffff88800726c600, ffff88800726c7c0)\n which belongs to the cache cifs_small_rq of size 448\n\nRestrict the +1 exemption to responses that have no data area, so that\nit still covers the bcc[0] omission it was meant for. When a data area\nis present, the +1 discrepancy instead means the reported data length\noverruns the\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious or compromised SMB server can trigger the flaw through crafted TCP responses, typically over port 445.\nAC:L - The server directly controls the frame length, data offset, and declared data length, so no race or condition outside the attacker\u0027s control is required.\nPR:N - NEGOTIATE and SESSION_SETUP responses are processed before authentication and signature verification, requiring no attacker credentials or local capabilities.\nUI:N - An existing persistent SMB mount automatically renegotiates after a server-induced reconnect, allowing exploitation without contemporaneous user action.\nS:U - The vulnerable SMB decoder and resulting kernel impact remain within the host kernel\u0027s security authority.\nC:L - The discrepancy permits exactly one byte beyond the received data to be read; the NTLM path can preserve and reflect that byte in subsequent authentication data, but the disclosure is strictly bounded.\nI:N - The flaw performs an out-of-bounds read and copies data into valid allocations; it provides no out-of-bounds write or other demonstrated memory-modification primitive.\nA:H - The demonstrated slab out-of-bounds access raises a KASAN BUG and can panic hardened kernels, and a malicious peer can retrigger it during negotiation or reconnection."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:51.813Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8d0bbc78046d264bbf6a574ea6f9072258a43e35"
},
{
"url": "https://git.kernel.org/stable/c/b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0"
},
{
"url": "https://git.kernel.org/stable/c/31c6312608c60b72a1feb99a5afb680645a3e8a3"
},
{
"url": "https://git.kernel.org/stable/c/573e502d14714d2947e22e7eff40ec20a6a44a42"
},
{
"url": "https://git.kernel.org/stable/c/419ec1b604d7fb60c10aec2dc062371f9fcd4940"
},
{
"url": "https://git.kernel.org/stable/c/ceb875a375dedbf51c9425c1d13a2d7a8435c08c"
},
{
"url": "https://git.kernel.org/stable/c/6e9d10f62773b99bd927940fd9cbdfe7207e23ff"
},
{
"url": "https://git.kernel.org/stable/c/53b7c271f06be4dd5cfc8c6ef552a8355c891a7f"
}
],
"title": "smb: client: restrict implied bcc[0] exemption to responses without data area",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64448",
"datePublished": "2026-07-25T08:51:18.796Z",
"dateReserved": "2026-07-19T15:36:31.788Z",
"dateUpdated": "2026-08-17T04:55:51.813Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64570 (GCVE-0-2026-64570)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix fils_discovery double free on alloc failure
ieee80211_set_fils_discovery() calls kfree_rcu() on the old template
before allocating the replacement. If the kzalloc() then fails, it
returns -ENOMEM while link->u.ap.fils_discovery still points at the
object already queued for freeing. A later update or AP teardown
(ieee80211_stop_ap()) re-queues that same rcu_head; the second free is
caught by KASAN when the RCU sheaf is processed in softirq:
BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)
Free of addr ffff88800c065280 by task swapper/0/0
...
__rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)
rcu_free_sheaf (mm/slub.c:5850)
rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)
handle_softirqs (kernel/softirq.c:622)
The buggy address belongs to the cache kmalloc-96 of size 96
Queue the old object for kfree_rcu() only after the new one is published,
matching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/cfg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e2c55079155a953db669ca1986a985fa286bad95",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "5baaa1042f71dd4b8e418f2cdd516808702d229b",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "1981fba71797ec95e6755fb882cad88899a2a84f",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "286e52a799fa158bdbd77da1426c4d93f9a6e7ad",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/cfg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix fils_discovery double free on alloc failure\n\nieee80211_set_fils_discovery() calls kfree_rcu() on the old template\nbefore allocating the replacement. If the kzalloc() then fails, it\nreturns -ENOMEM while link-\u003eu.ap.fils_discovery still points at the\nobject already queued for freeing. A later update or AP teardown\n(ieee80211_stop_ap()) re-queues that same rcu_head; the second free is\ncaught by KASAN when the RCU sheaf is processed in softirq:\n\n BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n Free of addr ffff88800c065280 by task swapper/0/0\n ...\n __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n rcu_free_sheaf (mm/slub.c:5850)\n rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n handle_softirqs (kernel/softirq.c:622)\n The buggy address belongs to the cache kmalloc-96 of size 96\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered only via local nl80211 SoftAP config (NL80211_CMD_START_AP/SET_BEACON \u2192 ieee80211_set_fils_discovery), not by processing over-the-air WiFi frames or remote packets.\nAC:L - The attacker fully controls the SET_BEACON/STOP_AP sequence and can force the GFP_KERNEL kzalloc failure (e.g. memory pressure/memcg) with an attacker-chosen template size; no race or condition outside attacker influence is required.\nPR:L - START_AP and SET_BEACON use GENL_UNS_ADMIN_PERM (CAP_NET_ADMIN in the wiphy netns user_ns). Per CNA guidance that capability via user namespaces scores Low, not init-namespace root High.\nUI:N - The attacker issues the nl80211 commands to set FILS discovery and later tear down or update the AP; no separate victim action is required.\nS:U - Impact stays inside the host kernel mac80211 heap (local privilege-escalation class) and does not cross a VM, IOMMU, or other separate security authority.\nC:H - After the failed alloc the dangling fils_discovery pointer can be read via ieee80211_get_fils_discovery_tmpl and the object is double-freed; double-free/UAF enables heap reuse and arbitrary kernel memory disclosure.\nI:H - Double-free of the attacker-sized kmalloc FILS template (and subsequent stop_ap/update re-free) is classic heap corruption enabling spray/arbitrary-write and control-flow hijack primitives.\nA:H - The bug is a KASAN-confirmed double-free in rcu_free_sheaf softirq processing and can oops/panic the kernel, fully denying availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:49.594Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e2c55079155a953db669ca1986a985fa286bad95"
},
{
"url": "https://git.kernel.org/stable/c/5baaa1042f71dd4b8e418f2cdd516808702d229b"
},
{
"url": "https://git.kernel.org/stable/c/1981fba71797ec95e6755fb882cad88899a2a84f"
},
{
"url": "https://git.kernel.org/stable/c/286e52a799fa158bdbd77da1426c4d93f9a6e7ad"
}
],
"title": "wifi: mac80211: fix fils_discovery double free on alloc failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64570",
"datePublished": "2026-08-05T08:08:07.855Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-17T04:57:49.594Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64034 (GCVE-0-2026-64034)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
In mana_hwc_rx_event_handler(), resp->response.hwc_msg_id is read from
DMA-coherent memory and bounds-checked, then mana_hwc_handle_resp()
re-reads the same field from the same DMA buffer for test_bit() and
pointer arithmetic.
DMA-coherent memory is mapped uncacheable on x86 and is shared,
unencrypted, in Confidential VMs (SEV-SNP/TDX), so each load goes
directly to host-visible memory. A H/W can modify the value
between the check and the use, bypassing the bounds validation.
Fix this by reading hwc_msg_id exactly once using READ_ONCE() into a
stack-local variable in mana_hwc_rx_event_handler(), and passing the
validated value as a parameter to mana_hwc_handle_resp().
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/hw_channel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a201c66edf2ebc6cfdc3813a889ba20fecebfae3",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "70ad2dff8d052a85dfef15715b531f38a29108cf",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "566f42fb67a7ebfed6650e407e5b72e6b3e83bf7",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "6180a06bbc99fd9114b8db4be6c4d46e40f046ef",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "09ec063d87c2dd3fa6f3561361a017bd882e9f37",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "3c4db56ccd13dd020fbf43afabaee74a40ec75e4",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "35f0f0a2536a4d604b4dbad92c85c4a8fdebb870",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/hw_channel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer\n\nIn mana_hwc_rx_event_handler(), resp-\u003eresponse.hwc_msg_id is read from\nDMA-coherent memory and bounds-checked, then mana_hwc_handle_resp()\nre-reads the same field from the same DMA buffer for test_bit() and\npointer arithmetic.\n\nDMA-coherent memory is mapped uncacheable on x86 and is shared,\nunencrypted, in Confidential VMs (SEV-SNP/TDX), so each load goes\ndirectly to host-visible memory. A H/W can modify the value\nbetween the check and the use, bypassing the bounds validation.\n\nFix this by reading hwc_msg_id exactly once using READ_ONCE() into a\nstack-local variable in mana_hwc_rx_event_handler(), and passing the\nvalidated value as a parameter to mana_hwc_handle_resp()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a malicious hypervisor or host that can modify MANA HWC DMA-coherent response buffers between guest kernel loads; it is not reachable by sending network packets to the guest\u0027s data path.\nAC:L - The attacker controlling the hypervisor fully controls DMA buffer contents and can reliably flip hwc_msg_id between the validation read and the use in mana_hwc_handle_resp() on uncacheable coherent memory.\nPR:N - The attacking hypervisor needs no guest OS credentials or capabilities; exploitation targets the guest kernel through the virtual device DMA path while the MANA driver is active.\nUI:N - No victim user action is required beyond normal Azure VM operation with the MANA driver loaded and HWC receive buffers posted.\nS:C - The vulnerability crosses the VM/DMA security boundary by allowing a hostile hypervisor to corrupt guest kernel memory that the confidential-guest threat model assumes is protected from host tampering.\nC:H - Out-of-bounds indexing via bypassed hwc_msg_id validation enables reading adjacent kernel heap objects through misdirected caller_ctx access and test_bit() on the inflight bitmap.\nI:H - Host-controlled response data is copied with memcpy() to an out-of-bounds output_buf pointer, enabling arbitrary kernel memory corruption and potential control-flow hijacking.\nA:H - Out-of-bounds caller_ctx access and corrupted completion signaling can cause kernel oops, panic, or hang during HWC response handling."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:28.529Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a201c66edf2ebc6cfdc3813a889ba20fecebfae3"
},
{
"url": "https://git.kernel.org/stable/c/70ad2dff8d052a85dfef15715b531f38a29108cf"
},
{
"url": "https://git.kernel.org/stable/c/566f42fb67a7ebfed6650e407e5b72e6b3e83bf7"
},
{
"url": "https://git.kernel.org/stable/c/6180a06bbc99fd9114b8db4be6c4d46e40f046ef"
},
{
"url": "https://git.kernel.org/stable/c/09ec063d87c2dd3fa6f3561361a017bd882e9f37"
},
{
"url": "https://git.kernel.org/stable/c/3c4db56ccd13dd020fbf43afabaee74a40ec75e4"
},
{
"url": "https://git.kernel.org/stable/c/35f0f0a2536a4d604b4dbad92c85c4a8fdebb870"
}
],
"title": "net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64034",
"datePublished": "2026-07-19T15:39:23.470Z",
"dateReserved": "2026-07-19T07:54:57.028Z",
"dateUpdated": "2026-08-05T12:38:28.529Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80590 (GCVE-0-2026-80590)
Vulnerability from cvelistv5
Published
2026-08-28 06:35
Modified
2026-08-31 06:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
inet: frags: strip GSO state from fragments before reassembly
A virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark
an IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off.
inet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first
fragment's skb as the head of the reassembled datagram, including its
shinfo->gso_size/gso_type/gso_segs, and chain the remaining fragments
on frag_list with whatever linear/paged layout they arrived with.
After ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the
reassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and
the next software segmentation point - udp_rcv_segment() on local
delivery, validate_xmit_skb(), or the ip_finish_output_gso() slow
path - hands it to skb_segment(). skb_segment()'s frag_list walk
assumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to
a tap by an unprivileged user in its own userns are enough:
kernel BUG at net/core/skbuff.c:4899!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2
RIP: 0010:skb_segment+0x20ca/0x48b0
Call Trace:
<TASK>
__udp_gso_segment+0x29a/0x27d0
udp4_ufo_fragment+0x458/0x6c0
inet_gso_segment+0x429/0x1340
skb_mac_gso_segment+0x233/0x4f0
__skb_gso_segment+0x308/0x660
udp_queue_rcv_skb+0x440/0xad0
udp_unicast_rcv_skb+0xc7/0x2c0
udp_rcv+0x16ce/0x2260
ip_protocol_deliver_rcu+0x197/0x2d0
ip_local_deliver+0x430/0x690
ip_rcv+0x16f/0x1f0
__netif_receive_skb_one_core+0x15e/0x1c0
__netif_receive_skb+0x1e/0x110
netif_receive_skb+0xf6/0x5c0
tun_rx_batched.isra.0+0x3ab/0x790
tun_get_user+0x17c3/0x3550
tun_chr_write_iter+0xba/0x1b0
vfs_write+0x646/0x1130
</TASK>
Kernel panic - not syncing: Fatal exception in interrupt
This runs with BH disabled, so it is a panic rather than an oops. The
same is reachable with CAP_NET_RAW in a netns where a defrag point
precedes a GSO point, and from a guest whose VMM forwards
virtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by
commit 3dcbdb134f32 ("net: gso: Fix skb_segment splat when splitting
gso_size mangled skb having linear-headed frag_list") and by
commit 9e4b7a99a03a ("net: gso: fix panic on frag_list with mixed head
alloc types") do not cover it: page-backed heads skip them, and kmalloc
heads skip them when gso_size == skb_headlen(head), which the sender
controls.
An skb entering a frag queue is an IP fragment by definition and
cannot legitimately carry GSO state: GRO does not merge fragments and
the stack segments before it fragments, so only untrusted sources are
affected. This has been reachable since
commit f43798c27684 ("tun: Allow GSO using virtio_net_hdr"), the first
path that let userspace attach GSO metadata to an IP fragment. Reset
the GSO fields of every fragment as it is queued, in
inet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and
6lowpan reassembly share; then neither the head nor the frag_list
members of the reassembled skb carry them (the members matter too:
the ip_do_fragment()/ip6_fragment() fast paths send them out as they
are). The head may remain CHECKSUM_PARTIAL; that is already accepted
on receive and resolved by skb_checksum_help() in
ip_do_fragment()/ip6_fragment() on forward.
Tested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer
above, two further IPv4 frag_list geometries that reach
BUG_ON(i >= nfrags) and BUG_ON(!list_skb->head_frag), and an IPv6
fragment-header variant (udp6_ufo_fragment()) each panic the unpatched
kernel; with this patch all four datagrams are delivered intact and
nothing is logged.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/inet_fragment.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cfdbc8c2e6f9ef5d8b8e54859da03dfe682b0bee",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "29dda278a5ed272f2230ff4eaa23cf403107bba0",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "14a8f3e10fa9a5abd6cedcdaa0c0b7ea9a09f234",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "3edf721bb4b99d272c336631b44e3d8ff9a4f31b",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "dec2edb7aaf12a8878b3a03172ea8fc277b8eaad",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "c49f04e8d2b94dbb8d9fd99731dd3f00589c8ace",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "69b73b74d9eb45f5560a8fe4fa406ada580e1340",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "da857e448322a2e871ce3ecc2900027041160d43",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "d5dc1e69fd7258ea605c9952e5d5947539159ae3",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/inet_fragment.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.27"
},
{
"lessThan": "2.6.27",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.268",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.219",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.186",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.155",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.107",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.48",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.268",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.219",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.186",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.155",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.107",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.48",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.12",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.2",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.27",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ninet: frags: strip GSO state from fragments before reassembly\n\nA virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark\nan IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off.\ninet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first\nfragment\u0027s skb as the head of the reassembled datagram, including its\nshinfo-\u003egso_size/gso_type/gso_segs, and chain the remaining fragments\non frag_list with whatever linear/paged layout they arrived with.\n\nAfter ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the\nreassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and\nthe next software segmentation point - udp_rcv_segment() on local\ndelivery, validate_xmit_skb(), or the ip_finish_output_gso() slow\npath - hands it to skb_segment(). skb_segment()\u0027s frag_list walk\nassumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to\na tap by an unprivileged user in its own userns are enough:\n\n kernel BUG at net/core/skbuff.c:4899!\n Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2\n RIP: 0010:skb_segment+0x20ca/0x48b0\n Call Trace:\n \u003cTASK\u003e\n __udp_gso_segment+0x29a/0x27d0\n udp4_ufo_fragment+0x458/0x6c0\n inet_gso_segment+0x429/0x1340\n skb_mac_gso_segment+0x233/0x4f0\n __skb_gso_segment+0x308/0x660\n udp_queue_rcv_skb+0x440/0xad0\n udp_unicast_rcv_skb+0xc7/0x2c0\n udp_rcv+0x16ce/0x2260\n ip_protocol_deliver_rcu+0x197/0x2d0\n ip_local_deliver+0x430/0x690\n ip_rcv+0x16f/0x1f0\n __netif_receive_skb_one_core+0x15e/0x1c0\n __netif_receive_skb+0x1e/0x110\n netif_receive_skb+0xf6/0x5c0\n tun_rx_batched.isra.0+0x3ab/0x790\n tun_get_user+0x17c3/0x3550\n tun_chr_write_iter+0xba/0x1b0\n vfs_write+0x646/0x1130\n \u003c/TASK\u003e\n Kernel panic - not syncing: Fatal exception in interrupt\n\nThis runs with BH disabled, so it is a panic rather than an oops. The\nsame is reachable with CAP_NET_RAW in a netns where a defrag point\nprecedes a GSO point, and from a guest whose VMM forwards\nvirtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by\ncommit 3dcbdb134f32 (\"net: gso: Fix skb_segment splat when splitting\ngso_size mangled skb having linear-headed frag_list\") and by\ncommit 9e4b7a99a03a (\"net: gso: fix panic on frag_list with mixed head\nalloc types\") do not cover it: page-backed heads skip them, and kmalloc\nheads skip them when gso_size == skb_headlen(head), which the sender\ncontrols.\n\nAn skb entering a frag queue is an IP fragment by definition and\ncannot legitimately carry GSO state: GRO does not merge fragments and\nthe stack segments before it fragments, so only untrusted sources are\naffected. This has been reachable since\ncommit f43798c27684 (\"tun: Allow GSO using virtio_net_hdr\"), the first\npath that let userspace attach GSO metadata to an IP fragment. Reset\nthe GSO fields of every fragment as it is queued, in\ninet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and\n6lowpan reassembly share; then neither the head nor the frag_list\nmembers of the reassembled skb carry them (the members matter too:\nthe ip_do_fragment()/ip6_fragment() fast paths send them out as they\nare). The head may remain CHECKSUM_PARTIAL; that is already accepted\non receive and resolved by skb_checksum_help() in\nip_do_fragment()/ip6_fragment() on forward.\n\nTested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer\nabove, two further IPv4 frag_list geometries that reach\nBUG_ON(i \u003e= nfrags) and BUG_ON(!list_skb-\u003ehead_frag), and an IPv6\nfragment-header variant (udp6_ufo_fragment()) each panic the unpatched\nkernel; with this patch all four datagrams are delivered intact and\nnothing is logged."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious cloud VM guest injects virtio_net_hdr-marked IPv4/IPv6 fragments through virtio-net/vhost-tap into the host ip_rcv() path; the same inet_frag reassembly and skb_segment() crash also fires on validate_xmit_skb()/ip_finish_output_gso() when such skbs traverse forwarding.\nAC:L - The attacker fully controls virtio_net_hdr gso_type/gso_size and fragment geometry; the commit reproduces a host panic from two tap writes with no races, timing, or uncontrollable memory layout required.\nPR:N - On typical KVM/QEMU tap-backed virtio-net deployments a tenant VM needs no host account or capability; exploitation uses only the pre-provisioned virtual NIC, not init-namespace root or CAP_NET_ADMIN on the host.\nUI:N - Packet injection, ip_defrag reassembly, and GSO segmentation run automatically in softirq once crafted virtio fragments are sent; no victim mount, click, or other cooperative action is required.\nS:C - A guest VM tenant can panic the host kernel by crossing the hypervisor virtio/tap boundary, impacting resources outside the guest security authority even though the demonstrated primitive is denial of service rather than full escape.\nC:N - Impact is an intentional BUG_ON in skb_segment() frag_list handling; there is no demonstrated out-of-bounds read, use-after-free, or other information-disclosure primitive before the assertion aborts.\nI:N - The failure aborts in skb_segment() before any out-of-bounds write, page-desc conversion, or control-flow hijack; attacker-controlled metadata only reaches a defensive assertion, not a memory modification primitive.\nA:H - Triggering skb_segment() BUG_ON from tun_rx/tun_get_user runs with BH disabled and causes a fatal kernel panic, fully and repeatedly denying availability of the affected host until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T06:12:21.989Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cfdbc8c2e6f9ef5d8b8e54859da03dfe682b0bee"
},
{
"url": "https://git.kernel.org/stable/c/29dda278a5ed272f2230ff4eaa23cf403107bba0"
},
{
"url": "https://git.kernel.org/stable/c/14a8f3e10fa9a5abd6cedcdaa0c0b7ea9a09f234"
},
{
"url": "https://git.kernel.org/stable/c/3edf721bb4b99d272c336631b44e3d8ff9a4f31b"
},
{
"url": "https://git.kernel.org/stable/c/dec2edb7aaf12a8878b3a03172ea8fc277b8eaad"
},
{
"url": "https://git.kernel.org/stable/c/c49f04e8d2b94dbb8d9fd99731dd3f00589c8ace"
},
{
"url": "https://git.kernel.org/stable/c/69b73b74d9eb45f5560a8fe4fa406ada580e1340"
},
{
"url": "https://git.kernel.org/stable/c/da857e448322a2e871ce3ecc2900027041160d43"
},
{
"url": "https://git.kernel.org/stable/c/d5dc1e69fd7258ea605c9952e5d5947539159ae3"
}
],
"title": "inet: frags: strip GSO state from fragments before reassembly",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80590",
"datePublished": "2026-08-28T06:35:12.516Z",
"dateReserved": "2026-08-26T14:34:25.770Z",
"dateUpdated": "2026-08-31T06:12:21.989Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64218 (GCVE-0-2026-64218)
Vulnerability from cvelistv5
Published
2026-07-24 15:23
Modified
2026-08-05 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: bla: fix report_work leak on backbone_gw purge
batadv_bla_purge_backbone_gw() removes stale backbone gateway entries,
but fails to properly handle their associated report_work:
- If report_work is running, the purge must wait for it to finish before
freeing the backbone_gw, otherwise the worker may access freed memory
(e.g. bat_priv).
- If report_work is pending, the purge must cancel it and release the
reference held for that pending work item.
The previous implementation called hlist_for_each_entry_safe() inside a
spin_lock_bh() section, but cancel_work_sync() may sleep and therefore
cannot be called from within a spinlock-protected region.
Restructure the loop to handle one entry per spinlock critical section:
acquire the lock, find the next entry to purge, remove it from the hash
list, then release the lock before calling cancel_work_sync() and
dropping the hash_entry reference. Repeat until no more entries require
purging.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 23721387c409087fd3b97e274f34d3ddc0970b74 Version: 23721387c409087fd3b97e274f34d3ddc0970b74 Version: 23721387c409087fd3b97e274f34d3ddc0970b74 Version: 23721387c409087fd3b97e274f34d3ddc0970b74 Version: 23721387c409087fd3b97e274f34d3ddc0970b74 Version: 23721387c409087fd3b97e274f34d3ddc0970b74 Version: 23721387c409087fd3b97e274f34d3ddc0970b74 Version: 23721387c409087fd3b97e274f34d3ddc0970b74 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/batman-adv/bridge_loop_avoidance.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ce2c0ee4d76d5ee4b391fe0e31334361e25030ec",
"status": "affected",
"version": "23721387c409087fd3b97e274f34d3ddc0970b74",
"versionType": "git"
},
{
"lessThan": "3423a45e5c3d3c5129f88143a9a969787d7d5a0a",
"status": "affected",
"version": "23721387c409087fd3b97e274f34d3ddc0970b74",
"versionType": "git"
},
{
"lessThan": "f1303adb1e59582f76c22798a2e2e150e054a9e7",
"status": "affected",
"version": "23721387c409087fd3b97e274f34d3ddc0970b74",
"versionType": "git"
},
{
"lessThan": "48663158222b3b7f6ee6791a67d512ede7fc94bb",
"status": "affected",
"version": "23721387c409087fd3b97e274f34d3ddc0970b74",
"versionType": "git"
},
{
"lessThan": "eeddd7bab3d59c1e98642a204141f8c5d6194707",
"status": "affected",
"version": "23721387c409087fd3b97e274f34d3ddc0970b74",
"versionType": "git"
},
{
"lessThan": "c6de1a5a9c406e30b91f1515a6ce05cc84023baa",
"status": "affected",
"version": "23721387c409087fd3b97e274f34d3ddc0970b74",
"versionType": "git"
},
{
"lessThan": "95a7034661274cf5985708bd2f6d86ee46f88fa9",
"status": "affected",
"version": "23721387c409087fd3b97e274f34d3ddc0970b74",
"versionType": "git"
},
{
"lessThan": "0459430add32ea41f3e2ef9351610e6d33627a6b",
"status": "affected",
"version": "23721387c409087fd3b97e274f34d3ddc0970b74",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/batman-adv/bridge_loop_avoidance.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: bla: fix report_work leak on backbone_gw purge\n\nbatadv_bla_purge_backbone_gw() removes stale backbone gateway entries,\nbut fails to properly handle their associated report_work:\n\n- If report_work is running, the purge must wait for it to finish before\n freeing the backbone_gw, otherwise the worker may access freed memory\n (e.g. bat_priv).\n- If report_work is pending, the purge must cancel it and release the\n reference held for that pending work item.\n\nThe previous implementation called hlist_for_each_entry_safe() inside a\nspin_lock_bh() section, but cancel_work_sync() may sleep and therefore\ncannot be called from within a spinlock-protected region.\n\nRestructure the loop to handle one entry per spinlock critical section:\nacquire the lock, find the next entry to purge, remove it from the hash\nlist, then release the lock before calling cancel_work_sync() and\ndropping the hash_entry reference. Repeat until no more entries require\npurging."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Although mesh packets can enqueue report_work, exploitation requires purging or tearing down the mesh object, which a local attacker can perform through netlink in a controlled network namespace.\nAC:L - The attacker can observe the periodic loop-detect address, enqueue many VLAN-specific work items, and immediately delete the interface, controlling both sides of the race.\nPR:L - Mesh configuration and teardown require CAP_NET_ADMIN, but batman-adv supports network namespaces and GENL_UNS_ADMIN_PERM, making the path reachable by an otherwise unprivileged user through user namespaces.\nUI:N - The attacker can create, trigger, and tear down the affected mesh interface without action from another user.\nS:U - Exploitation compromises the host kernel within its existing security authority; this is standard kernel privilege escalation rather than a VM or hardware-boundary escape.\nC:H - The worker can dereference a freed bat_priv, net_device, and embedded kobject; controlled reallocation can turn these stale pointer chains into kernel-memory disclosure primitives.\nI:H - The use-after-free reaches kobject uevent processing and stale callback-bearing structures, making heap reuse and control-flow hijacking or arbitrary kernel modification plausible.\nA:H - The stale net_device and kobject dereferences can cause a kernel oops or panic, and an attacker can repeat the trigger through user-namespace-created mesh interfaces."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:40:06.269Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ce2c0ee4d76d5ee4b391fe0e31334361e25030ec"
},
{
"url": "https://git.kernel.org/stable/c/3423a45e5c3d3c5129f88143a9a969787d7d5a0a"
},
{
"url": "https://git.kernel.org/stable/c/f1303adb1e59582f76c22798a2e2e150e054a9e7"
},
{
"url": "https://git.kernel.org/stable/c/48663158222b3b7f6ee6791a67d512ede7fc94bb"
},
{
"url": "https://git.kernel.org/stable/c/eeddd7bab3d59c1e98642a204141f8c5d6194707"
},
{
"url": "https://git.kernel.org/stable/c/c6de1a5a9c406e30b91f1515a6ce05cc84023baa"
},
{
"url": "https://git.kernel.org/stable/c/95a7034661274cf5985708bd2f6d86ee46f88fa9"
},
{
"url": "https://git.kernel.org/stable/c/0459430add32ea41f3e2ef9351610e6d33627a6b"
}
],
"title": "batman-adv: bla: fix report_work leak on backbone_gw purge",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64218",
"datePublished": "2026-07-24T15:23:05.814Z",
"dateReserved": "2026-07-19T15:36:31.770Z",
"dateUpdated": "2026-08-05T12:40:06.269Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72083 (GCVE-0-2026-72083)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-17 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
core_scsi3_emulate_pro_register_and_move() maps the PERSISTENT RESERVE OUT
parameter list with transport_kmap_data_sg() and parses the destination
TransportID with target_parse_pr_out_transport_id(). For an iSCSI
TransportID (FORMAT CODE 01b), iscsi_parse_pr_out_transport_id() returns
the ISID in iport_ptr as a raw pointer into that mapped buffer.
The function then unmaps the buffer with transport_kunmap_data_sg() before
dereferencing iport_ptr in strcmp(), __core_scsi3_locate_pr_reg() and
core_scsi3_alloc_registration(). When the parameter list spans more than
one page (PARAMETER LIST LENGTH > 4096), transport_kmap_data_sg() uses
vmap() and transport_kunmap_data_sg() does vunmap(), so the kernel virtual
address backing iport_ptr is torn down and every subsequent dereference is
a use-after-free read of the unmapped region.
Keep the parameter list mapped until iport_ptr is no longer needed: drop
the early transport_kunmap_data_sg() and unmap once on the success path,
right before returning. The error paths already unmap through the existing
"if (buf) transport_kunmap_data_sg(cmd)" at the out: label, which now runs
on every post-map error exit because buf is no longer cleared early. Only
reads of the mapping happen while spinlocks are held; the map and unmap
calls remain outside any lock. The sibling caller
core_scsi3_decode_spec_i_port() already uses the buffer before unmapping it
and is left unchanged.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4949314c7283ea4f9ade182ca599583b89f7edd6 Version: 4949314c7283ea4f9ade182ca599583b89f7edd6 Version: 4949314c7283ea4f9ade182ca599583b89f7edd6 Version: 4949314c7283ea4f9ade182ca599583b89f7edd6 Version: 4949314c7283ea4f9ade182ca599583b89f7edd6 Version: 4949314c7283ea4f9ade182ca599583b89f7edd6 Version: 4949314c7283ea4f9ade182ca599583b89f7edd6 Version: 4949314c7283ea4f9ade182ca599583b89f7edd6 Version: d2227f84ba0e97906153ac83db13213fb2e3938d Version: 3.2.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/target/target_core_pr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7d56f5c868d92c9d504a34a3ea450bce481c7f63",
"status": "affected",
"version": "4949314c7283ea4f9ade182ca599583b89f7edd6",
"versionType": "git"
},
{
"lessThan": "59a2a5a37dc49a641ad6bc64aee34e5a61025ffd",
"status": "affected",
"version": "4949314c7283ea4f9ade182ca599583b89f7edd6",
"versionType": "git"
},
{
"lessThan": "9f8076cc73dfa6b10155978c160587e986b22169",
"status": "affected",
"version": "4949314c7283ea4f9ade182ca599583b89f7edd6",
"versionType": "git"
},
{
"lessThan": "a040004846f1fbe687f6ec76d9ccc27b4ead42e4",
"status": "affected",
"version": "4949314c7283ea4f9ade182ca599583b89f7edd6",
"versionType": "git"
},
{
"lessThan": "05b3e37433cf2eaf8867f1c16528aa347bb212ab",
"status": "affected",
"version": "4949314c7283ea4f9ade182ca599583b89f7edd6",
"versionType": "git"
},
{
"lessThan": "cb7bdae7fba404852ade34b0c1445fbaf3e54fbb",
"status": "affected",
"version": "4949314c7283ea4f9ade182ca599583b89f7edd6",
"versionType": "git"
},
{
"lessThan": "ef2ee18fec92088c7d8877baf7674e89389ccd66",
"status": "affected",
"version": "4949314c7283ea4f9ade182ca599583b89f7edd6",
"versionType": "git"
},
{
"lessThan": "fda6a1f3c3d7047b5ce5654487649c2daa738bfc",
"status": "affected",
"version": "4949314c7283ea4f9ade182ca599583b89f7edd6",
"versionType": "git"
},
{
"status": "affected",
"version": "d2227f84ba0e97906153ac83db13213fb2e3938d",
"versionType": "git"
},
{
"lessThan": "3.3",
"status": "affected",
"version": "3.2.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/target/target_core_pr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.3"
},
{
"lessThan": "3.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.2.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE\n\ncore_scsi3_emulate_pro_register_and_move() maps the PERSISTENT RESERVE OUT\nparameter list with transport_kmap_data_sg() and parses the destination\nTransportID with target_parse_pr_out_transport_id(). For an iSCSI\nTransportID (FORMAT CODE 01b), iscsi_parse_pr_out_transport_id() returns\nthe ISID in iport_ptr as a raw pointer into that mapped buffer.\n\nThe function then unmaps the buffer with transport_kunmap_data_sg() before\ndereferencing iport_ptr in strcmp(), __core_scsi3_locate_pr_reg() and\ncore_scsi3_alloc_registration(). When the parameter list spans more than\none page (PARAMETER LIST LENGTH \u003e 4096), transport_kmap_data_sg() uses\nvmap() and transport_kunmap_data_sg() does vunmap(), so the kernel virtual\naddress backing iport_ptr is torn down and every subsequent dereference is\na use-after-free read of the unmapped region.\n\nKeep the parameter list mapped until iport_ptr is no longer needed: drop\nthe early transport_kunmap_data_sg() and unmap once on the success path,\nright before returning. The error paths already unmap through the existing\n\"if (buf) transport_kunmap_data_sg(cmd)\" at the out: label, which now runs\non every post-map error exit because buf is no longer cleared early. Only\nreads of the mapping happen while spinlocks are held; the map and unmap\ncalls remain outside any lock. The sibling caller\ncore_scsi3_decode_spec_i_port() already uses the buffer before unmapping it\nand is left unchanged."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On LIO/iSCSI storage servers and appliances, a remote initiator sends PERSISTENT_RESERVE_OUT with REGISTER AND MOVE over TCP (port 3260); iscsit_process_scsi_cmd()\u2192target_execute_cmd()\u2192target_scsi3_emulate_pr_out()\u2192core_scsi3_emulate_pro_register_and_move() with no local access required.\nAC:L - The attacker fully controls the PR-OUT parameter list length (\u003e4096 to force vmap/vunmap), iSCSI TransportID format 01b with ISID, and can establish prerequisite PR registration and reservation via prior SCSI commands on the same session; no uncontrollable race or layout dependency exists.\nPR:N - Exploitation requires only the ability to act as a network SCSI/iSCSI client with LUN access to an exported target; no Linux UID, capability, or init-namespace root on the storage server is needed\u2014only standard iSCSI initiator connectivity (CHAP/ACL when configured).\nUI:N - Triggering is fully automated once an iSCSI session exists: the attacker issues scripted REGISTER, RESERVE, then REGISTER AND MOVE commands with a crafted \u003e4 KiB parameter list; no victim mount, click, or other interactive action is required.\nS:U - The UAF corrupts kernel heap state inside the target-core PR handler on the storage host; impact stays within that kernel security domain and does not inherently cross VM, container, or IOMMU boundaries (standard host compromise, not escape).\nC:H - After vunmap(), iport_ptr aliases freed kernel virtual address space and is dereferenced in strcmp(), __core_scsi3_locate_pr_reg(), and snprintf() into pr_reg_isid; per kernel CVSS guidance, UAF reads enable arbitrary kernel memory disclosure when uncertain.\nI:H - UAF reads of attacker-influenced unmapped PR-OUT data drive strcmp-based registration matching and snprintf copies into persistent kernel pr_reg structures; memory corruption/UAF is scored High for integrity because it can be leveraged for control-flow or state manipulation.\nA:H - Dereferencing iport_ptr after transport_kunmap_data_sg() vunmap() on multi-page buffers causes immediate invalid kernel virtual address accesses (oops/panic) on every qualifying REGISTER AND MOVE; UAF availability impact is High per kernel guidance even before full exploit development."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:40:05.325Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7d56f5c868d92c9d504a34a3ea450bce481c7f63"
},
{
"url": "https://git.kernel.org/stable/c/59a2a5a37dc49a641ad6bc64aee34e5a61025ffd"
},
{
"url": "https://git.kernel.org/stable/c/9f8076cc73dfa6b10155978c160587e986b22169"
},
{
"url": "https://git.kernel.org/stable/c/a040004846f1fbe687f6ec76d9ccc27b4ead42e4"
},
{
"url": "https://git.kernel.org/stable/c/05b3e37433cf2eaf8867f1c16528aa347bb212ab"
},
{
"url": "https://git.kernel.org/stable/c/cb7bdae7fba404852ade34b0c1445fbaf3e54fbb"
},
{
"url": "https://git.kernel.org/stable/c/ef2ee18fec92088c7d8877baf7674e89389ccd66"
},
{
"url": "https://git.kernel.org/stable/c/fda6a1f3c3d7047b5ce5654487649c2daa738bfc"
}
],
"title": "scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72083",
"datePublished": "2026-08-15T05:52:32.045Z",
"dateReserved": "2026-08-09T03:40:39.904Z",
"dateUpdated": "2026-08-17T05:40:05.325Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64558 (GCVE-0-2026-64558)
Vulnerability from cvelistv5
Published
2026-07-29 16:31
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/pkey: Check length in pkey_pckmo handler implementation
Explicitly check the length of the target buffer in the pkey_pckmo
implementation of the key_to_protkey() handler function. The handler
function fails, if the generated output data exceeds the length of the
provided target buffer.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/pkey_pckmo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "02028a24e26d85262ab9c8fc4344e1f3503007fc",
"status": "affected",
"version": "8fcc231ce3bea12b78bb94b280cdc03cff342435",
"versionType": "git"
},
{
"lessThan": "433e5e70cdc1edf382d28d08a885b22e2b98b7da",
"status": "affected",
"version": "8fcc231ce3bea12b78bb94b280cdc03cff342435",
"versionType": "git"
},
{
"lessThan": "614aa0491c7a190556c2345dddee0b6f5ed90989",
"status": "affected",
"version": "8fcc231ce3bea12b78bb94b280cdc03cff342435",
"versionType": "git"
},
{
"lessThan": "1ac287e2af9a9112fe271427ef45eceb26bce8b4",
"status": "affected",
"version": "8fcc231ce3bea12b78bb94b280cdc03cff342435",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/pkey_pckmo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Check length in pkey_pckmo handler implementation\n\nExplicitly check the length of the target buffer in the pkey_pckmo\nimplementation of the key_to_protkey() handler function. The handler\nfunction fails, if the generated output data exceeds the length of the\nprovided target buffer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is entered through the PKEY_KBLOB2PROTK/PKEY_KBLOB2PROTK2 ioctls on the /dev/pkey character device, or via an AF_ALG setkey on the paes skciphers. Both require local system access; no network input reaches this code.\nAC:L - A single ioctl with a hand-crafted 176-byte protected-key token (type 0x00, version TOKVER_PROTECTED_KEY, keytype PKEY_KEYTYPE_HMAC_1024, len 160) deterministically triggers the 96-byte overflow; there is no race, no memory-layout dependency, and no hardware or wrapping-key prerequisite since the non-AES branch skips pckmo_verify_protkey().\nPR:L - /dev/pkey is registered as a miscdevice with .mode = 0666 and pkey_unlocked_ioctl() contains no capability or permission check, so any unprivileged local user can reach the bug; the paes/AF_ALG setkey path likewise requires no privileges.\nUI:N - The attacker triggers the overflow entirely on their own via a single ioctl or socket option call; no victim action, mount, or file open is involved.\nS:U - The corruption is confined to the kernel\u0027s own stack within the same security authority; exploitation yields kernel privilege escalation rather than crossing a VM, IOMMU, or sandbox boundary.\nC:H - The attacker gains a fully controlled 96-byte out-of-bounds stack write that can clobber adjacent locals, saved pointers and return addresses, which is readily leveraged into arbitrary kernel memory disclosure; the copy also leaves *protkeylen inflated to 160 while the buffer is 64 bytes, feeding an oversized length back to callers.\nI:H - This is an out-of-bounds write of 96 attacker-chosen bytes past the end of a kernel stack object (the last member of struct pkey_kblob2pkey), overwriting saved registers and the return address \u2014 a classic control-flow hijack / local privilege escalation primitive.\nA:H - Smashing the kernel stack past the canary reliably produces a stack-protector panic or an oops on return, and any unprivileged user can repeat it at will to crash the machine."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:36.699Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/02028a24e26d85262ab9c8fc4344e1f3503007fc"
},
{
"url": "https://git.kernel.org/stable/c/433e5e70cdc1edf382d28d08a885b22e2b98b7da"
},
{
"url": "https://git.kernel.org/stable/c/614aa0491c7a190556c2345dddee0b6f5ed90989"
},
{
"url": "https://git.kernel.org/stable/c/1ac287e2af9a9112fe271427ef45eceb26bce8b4"
}
],
"title": "s390/pkey: Check length in pkey_pckmo handler implementation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64558",
"datePublished": "2026-07-29T16:31:21.591Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-08-17T04:57:36.699Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63865 (GCVE-0-2026-63865)
Vulnerability from cvelistv5
Published
2026-07-19 14:04
Modified
2026-08-05 12:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks
bpf_lsm_task_to_inode() is called under rcu_read_lock() and
bpf_lsm_inet_conn_established() is called from softirq context, so
neither hook can be used by sleepable LSM programs.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 423f16108c9d832bd96059d5c882c8ef6d76eb96 Version: 423f16108c9d832bd96059d5c882c8ef6d76eb96 Version: 423f16108c9d832bd96059d5c882c8ef6d76eb96 Version: 423f16108c9d832bd96059d5c882c8ef6d76eb96 Version: 423f16108c9d832bd96059d5c882c8ef6d76eb96 Version: 423f16108c9d832bd96059d5c882c8ef6d76eb96 Version: 423f16108c9d832bd96059d5c882c8ef6d76eb96 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/bpf/bpf_lsm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "452a927cddcd67478d030e646f41cb904a93156f",
"status": "affected",
"version": "423f16108c9d832bd96059d5c882c8ef6d76eb96",
"versionType": "git"
},
{
"lessThan": "f0fc2a9828171205244a28013f02889f50b71c9f",
"status": "affected",
"version": "423f16108c9d832bd96059d5c882c8ef6d76eb96",
"versionType": "git"
},
{
"lessThan": "26b380a3ca0b605fd8860995ed6a208f276dd316",
"status": "affected",
"version": "423f16108c9d832bd96059d5c882c8ef6d76eb96",
"versionType": "git"
},
{
"lessThan": "0d918263c9bfc86078edb2e2f7302a0c6ce42b7c",
"status": "affected",
"version": "423f16108c9d832bd96059d5c882c8ef6d76eb96",
"versionType": "git"
},
{
"lessThan": "281f2a214565a5cbf8b7355a65738d80bd19b8c5",
"status": "affected",
"version": "423f16108c9d832bd96059d5c882c8ef6d76eb96",
"versionType": "git"
},
{
"lessThan": "989f1b93907de1753a814996222da375f07e579b",
"status": "affected",
"version": "423f16108c9d832bd96059d5c882c8ef6d76eb96",
"versionType": "git"
},
{
"lessThan": "beaf0e96b1da74549a6cabd040f9667d83b2e97e",
"status": "affected",
"version": "423f16108c9d832bd96059d5c882c8ef6d76eb96",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/bpf/bpf_lsm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks\n\nbpf_lsm_task_to_inode() is called under rcu_read_lock() and\nbpf_lsm_inet_conn_established() is called from softirq context, so\nneither hook can be used by sleepable LSM programs."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires loading and attaching a sleepable BPF LSM program via bpf() syscalls; per kernel CNA guidance BPF subsystem issues are Local even though inet_conn_established fires during TCP receive processing.\nAC:L - Once a sleepable BPF LSM program is attached, the attacker reliably triggers the bug by making outbound TCP connections (inet_conn_established in softirq) or accessing /proc entries (task_to_inode under rcu_read_lock) without race-dependent conditions.\nPR:L - Loading BPF_PROG_TYPE_LSM programs requires CAP_BPF and CAP_PERFMON, both obtainable by an unprivileged user inside a user namespace (unshare -Ur) on typical Linux deployments with CONFIG_BPF_LSM enabled.\nUI:N - No victim user interaction is required; triggering occurs automatically from normal outbound TCP handshakes or /proc filesystem access after the sleepable BPF program is loaded.\nS:C - A container tenant with namespace CAP_BPF can load a sleepable BPF LSM on inet_conn_established or task_to_inode, and hook execution in host kernel softirq/RCU context can crash or corrupt the entire host, crossing the container-to-host security boundary.\nC:H - Executing sleepable BPF helpers (e.g. bpf_copy_from_user, GFP_KERNEL allocations) inside rcu_read_lock or softirq can corrupt kernel memory before detection, and such context violations are classifiable as exploitable memory-safety failures.\nI:H - Sleeping while holding TCP stack or RCU-protected locks can corrupt kernel data structures and potentially be leveraged for arbitrary kernel write or control-flow hijack, not merely a clean crash.\nA:H - Invoking might_sleep operations from softirq or RCU-critical sections reliably causes kernel BUG/oops/panic (\"sleeping function called from invalid context\"), producing complete host denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:36:41.333Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/452a927cddcd67478d030e646f41cb904a93156f"
},
{
"url": "https://git.kernel.org/stable/c/f0fc2a9828171205244a28013f02889f50b71c9f"
},
{
"url": "https://git.kernel.org/stable/c/26b380a3ca0b605fd8860995ed6a208f276dd316"
},
{
"url": "https://git.kernel.org/stable/c/0d918263c9bfc86078edb2e2f7302a0c6ce42b7c"
},
{
"url": "https://git.kernel.org/stable/c/281f2a214565a5cbf8b7355a65738d80bd19b8c5"
},
{
"url": "https://git.kernel.org/stable/c/989f1b93907de1753a814996222da375f07e579b"
},
{
"url": "https://git.kernel.org/stable/c/beaf0e96b1da74549a6cabd040f9667d83b2e97e"
}
],
"title": "bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63865",
"datePublished": "2026-07-19T14:04:51.215Z",
"dateReserved": "2026-07-19T07:54:57.017Z",
"dateUpdated": "2026-08-05T12:36:41.333Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68361 (GCVE-0-2026-68361)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
corsairpsu_probe(). If the probe operation fails after "io start" has
been initiated, this race condition will result in a uaf vulnerability
[1].
CPU0 CPU1
==== ====
corsairpsu_probe()
hid_device_io_start()
... unlock driver_input_lock
hid_hw_stop()
kfree(hidraw) __hid_input_report()
... acquire driver_input_lock
hid_report_raw_event()
hidraw_report_event()
... access hidraw's list_lock // trigger uaf
Consequently, when corsairpsu_probe() fails and hid_hw_stop() needs to
be executed, the io_started flag is first cleared while holding the
driver_input_lock to prevent potential race conditions involving input
reports.
[1]
BUG: KASAN: slab-use-after-free in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56
Call Trace:
hidraw_report_event+0x5d/0x3a0 drivers/hid/hidraw.c:577
hid_report_raw_event+0x311/0x1730 drivers/hid/hid-core.c:2076
__hid_input_report drivers/hid/hid-core.c:2152 [inline]
hid_input_report+0x44e/0x580 drivers/hid/hid-core.c:2174
hid_irq_in+0x47e/0x6d0 drivers/hid/usbhid/hid-core.c:286
__usb_hcd_giveback_urb+0x3b3/0x5e0 drivers/usb/core/hcd.c:1657
dummy_timer+0x8a9/0x47d0 drivers/usb/gadget/udc/dummy_hcd.c:2005
Allocated by task 10:
hidraw_connect+0x57/0x430 drivers/hid/hidraw.c:606
hid_connect+0x5bf/0x19d0 drivers/hid/hid-core.c:2277
hid_hw_start+0xa8/0x120 drivers/hid/hid-core.c:2387
corsairpsu_probe+0xd9/0x3c0 drivers/hwmon/corsair-psu.c:782
Freed by task 10:
hidraw_disconnect+0x4f/0x60 drivers/hid/hidraw.c:662
hid_disconnect drivers/hid/hid-core.c:2362 [inline]
hid_hw_stop+0x101/0x1e0 drivers/hid/hid-core.c:2407
corsairpsu_probe+0x327/0x3c0 drivers/hwmon/corsair-psu.c:826
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
[groeck: Updated subject and description;
call hid_device_io_stop() only if IO has been started]
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-psu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45dcd8a63069197f64dbda30509b9e224b74c0d8",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "c80ed058f31bb0251a748034d69feb376741dcb2",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "e6e1e0f3050d1a1a3ea1c9d6253363e87fdad67a",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "c0aae8d24f5e52d6910f97d59bc624e131f3ae1a",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "ec477af3a7e8d3964e62fd24ef01cdebb96b8e4e",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "bb25bd980f2d9bd34558e1b1d16636e4945baf14",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "9ab8656548cd737b98d0b19c4253aff8d68e97f4",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-psu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (corsair-psu) Stop device IO before calling hid_hw_stop\n\nhid_hw_stop() does not stop the device IO.\n\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\ncorsairpsu_probe(). If the probe operation fails after \"io start\" has\nbeen initiated, this race condition will result in a uaf vulnerability\n[1].\n\nCPU0\t\t\t\tCPU1\n====\t\t\t\t====\ncorsairpsu_probe()\n hid_device_io_start()\n ... unlock driver_input_lock\n hid_hw_stop()\n kfree(hidraw)\t\t\t__hid_input_report()\n\t\t\t\t ... acquire driver_input_lock\n\t\t\t\t hid_report_raw_event()\n\t\t\t\t hidraw_report_event()\n\t\t\t\t ... access hidraw\u0027s list_lock // trigger uaf\n\nConsequently, when corsairpsu_probe() fails and hid_hw_stop() needs to\nbe executed, the io_started flag is first cleared while holding the\ndriver_input_lock to prevent potential race conditions involving input\nreports.\n\n[1]\nBUG: KASAN: slab-use-after-free in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56\nCall Trace:\n hidraw_report_event+0x5d/0x3a0 drivers/hid/hidraw.c:577\n hid_report_raw_event+0x311/0x1730 drivers/hid/hid-core.c:2076\n __hid_input_report drivers/hid/hid-core.c:2152 [inline]\n hid_input_report+0x44e/0x580 drivers/hid/hid-core.c:2174\n hid_irq_in+0x47e/0x6d0 drivers/hid/usbhid/hid-core.c:286\n __usb_hcd_giveback_urb+0x3b3/0x5e0 drivers/usb/core/hcd.c:1657\n dummy_timer+0x8a9/0x47d0 drivers/usb/gadget/udc/dummy_hcd.c:2005\n\nAllocated by task 10:\n hidraw_connect+0x57/0x430 drivers/hid/hidraw.c:606\n hid_connect+0x5bf/0x19d0 drivers/hid/hid-core.c:2277\n hid_hw_start+0xa8/0x120 drivers/hid/hid-core.c:2387\n corsairpsu_probe+0xd9/0x3c0 drivers/hwmon/corsair-psu.c:782\n\nFreed by task 10:\n hidraw_disconnect+0x4f/0x60 drivers/hid/hidraw.c:662\n hid_disconnect drivers/hid/hid-core.c:2362 [inline]\n hid_hw_stop+0x101/0x1e0 drivers/hid/hid-core.c:2407\n corsairpsu_probe+0x327/0x3c0 drivers/hwmon/corsair-psu.c:826\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop().\n\n[groeck: Updated subject and description;\n call hid_device_io_stop() only if IO has been started]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:13.231Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45dcd8a63069197f64dbda30509b9e224b74c0d8"
},
{
"url": "https://git.kernel.org/stable/c/c80ed058f31bb0251a748034d69feb376741dcb2"
},
{
"url": "https://git.kernel.org/stable/c/e6e1e0f3050d1a1a3ea1c9d6253363e87fdad67a"
},
{
"url": "https://git.kernel.org/stable/c/c0aae8d24f5e52d6910f97d59bc624e131f3ae1a"
},
{
"url": "https://git.kernel.org/stable/c/ec477af3a7e8d3964e62fd24ef01cdebb96b8e4e"
},
{
"url": "https://git.kernel.org/stable/c/bb25bd980f2d9bd34558e1b1d16636e4945baf14"
},
{
"url": "https://git.kernel.org/stable/c/9ab8656548cd737b98d0b19c4253aff8d68e97f4"
}
],
"title": "hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68361",
"datePublished": "2026-08-10T12:03:38.332Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:13.231Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68107 (GCVE-0-2026-68107)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vcn4: avoid rereading IB param length
Reuse the parameter length returned by
vcn_v4_0_enc_find_ib_param() instead of rereading it from
the IB.
This avoids a potential TOCTOU issue if the IB contents
change between reads.
(cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cfdde9197ecd957281507be99af172671a57755c Version: 6dc4eddeb7e6cca7e1ab32cafbda79d06e652d84 Version: 2b10cb58d7a3fd621ec9b2ba765a092e562ef998 Version: 2b10cb58d7a3fd621ec9b2ba765a092e562ef998 Version: 2b10cb58d7a3fd621ec9b2ba765a092e562ef998 Version: b1dc92f55b22a80ded8f0263c9ef4ba902303895 Version: 6.6.107 ≤ Version: 6.12.48 ≤ Version: 6.16.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bbbe6a2a8d8dc87243438d3ffea2083b52d882d9",
"status": "affected",
"version": "cfdde9197ecd957281507be99af172671a57755c",
"versionType": "git"
},
{
"lessThan": "ff6aa542d91d76a185f69bd1997b94a560ff5f6b",
"status": "affected",
"version": "6dc4eddeb7e6cca7e1ab32cafbda79d06e652d84",
"versionType": "git"
},
{
"lessThan": "bd868c077f67589ed2a714307ceaade5f246e302",
"status": "affected",
"version": "2b10cb58d7a3fd621ec9b2ba765a092e562ef998",
"versionType": "git"
},
{
"lessThan": "c309626bf91fa0a0b583575654e6e14e81f818a3",
"status": "affected",
"version": "2b10cb58d7a3fd621ec9b2ba765a092e562ef998",
"versionType": "git"
},
{
"lessThan": "3b4082fabc67c9780b06eb959e59dd92fa79c0f0",
"status": "affected",
"version": "2b10cb58d7a3fd621ec9b2ba765a092e562ef998",
"versionType": "git"
},
{
"status": "affected",
"version": "b1dc92f55b22a80ded8f0263c9ef4ba902303895",
"versionType": "git"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.107",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.48",
"versionType": "semver"
},
{
"lessThan": "6.17",
"status": "affected",
"version": "6.16.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"lessThan": "6.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.107",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.48",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.16.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn4: avoid rereading IB param length\n\nReuse the parameter length returned by\nvcn_v4_0_enc_find_ib_param() instead of rereading it from\nthe IB.\n\nThis avoids a potential TOCTOU issue if the IB contents\nchange between reads.\n\n(cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is only reachable through the local AMDGPU_CS DRM ioctl on /dev/dri/renderD* (amdgpu_cs_ioctl \u2192 amdgpu_cs_patch_jobs \u2192 amdgpu_cs_patch_ibs), which kmaps the user IB and calls vcn_v4_0_ring_patch_cs_in_place(); no network or physical-device path exists.\nAC:L - patch_cs_in_place reads IB contents directly from attacker-mapped GEM memory without copying; a concurrent thread can change the param-length dword between vcn_v4_0_enc_find_ib_param()\u0027s initial read and the later idx+=amdgpu_ib_get_value(ib,idx)/4, so the attacker controls both sides of the TOCTOU race.\nPR:L - AMDGPU_CS is registered with DRM_AUTH|DRM_RENDER_ALLOW, so any local user who can open the AMDGPU render node (typical render/video group on desktops, gaming handhelds, and GPU cloud instances) can submit VCN4 command buffers without root or init-namespace capabilities.\nUI:N - Exploitation requires only the attacker submitting crafted VCN encode IBs through their own DRM context; no separate victim action such as opening a file, mounting a filesystem, or interacting with malicious content is needed.\nS:C - On VFIO GPU-passthrough and cloud ML hosts, a malicious VM guest submits VCN command streams through the assigned AMD GPU to corrupt host amdgpu kernel state, crossing the guest-to-hypervisor security boundary analogous to a device-model escape.\nC:H - Racing the length dword smaller under-advances IB iteration so nested RADEON_VCN_ENGINE_INFO entries inside a parent package are reached; vcn_v4_0_dec_msg() then reads user-mapped message buffers without snapshotting, enabling TOCTOU check/use mismatches on length/offset fields and out-of-bounds kernel reads past validated bounds.\nI:H - The same nested-entry bypass plus unsnapshotted dec_msg parsing lets userspace rewrite offset/size after kernel validation, driving out-of-bounds accesses in the message loop; skipping vcn_v4_0_limit_sched() via mis-iteration also leaves scheduler/BO state inconsistently modified in attacker-influenceable ways.\nA:H - Racing the length field to zero on re-read makes idx+=0 and re-enters the same ENGINE_INFO entry indefinitely, soft-locking the CS ioctl path; vcn_v4_0_limit_sched() may also block in dma_fence_wait(), yielding repeatable kernel denial-of-service on shared GPU hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:56.350Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bbbe6a2a8d8dc87243438d3ffea2083b52d882d9"
},
{
"url": "https://git.kernel.org/stable/c/ff6aa542d91d76a185f69bd1997b94a560ff5f6b"
},
{
"url": "https://git.kernel.org/stable/c/bd868c077f67589ed2a714307ceaade5f246e302"
},
{
"url": "https://git.kernel.org/stable/c/c309626bf91fa0a0b583575654e6e14e81f818a3"
},
{
"url": "https://git.kernel.org/stable/c/3b4082fabc67c9780b06eb959e59dd92fa79c0f0"
}
],
"title": "drm/amdgpu/vcn4: avoid rereading IB param length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68107",
"datePublished": "2026-08-10T11:58:24.135Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-17T04:58:56.350Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68248 (GCVE-0-2026-68248)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915: Return NULL on error in active_instance
Avoid returning &node->base when node is NULL due to OOM
during GFP_ATOMIC allocation.
Discovered using AI-assisted static analysis confirmed by
Intel Product Security.
(cherry picked from commit 6029bc064f0b1bac184203a50fbaaf070fa18832)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/i915_active.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a727a004d14580b2fc9bec9e1a9ea60a9016cfcf",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "2bc7c50ffca43e1824cf29738d0572f1eb21f261",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "32c1a2afa90dd07df931f0b12578de1dbb751f0c",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "b238d86e7f43afde8e830ef5b8d89ffedbbc7613",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "cbec6a57959ab503e3ad4ad6edd51efb585dce92",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "58b7e63ca0cd964190957ddd169c899256acaee9",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "1e33f0de5fdcd09e51fdec1e5822448970b6420f",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/i915_active.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Return NULL on error in active_instance\n\nAvoid returning \u0026node-\u003ebase when node is NULL due to OOM\nduring GFP_ATOMIC allocation.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit 6029bc064f0b1bac184203a50fbaaf070fa18832)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:15.977Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a727a004d14580b2fc9bec9e1a9ea60a9016cfcf"
},
{
"url": "https://git.kernel.org/stable/c/2bc7c50ffca43e1824cf29738d0572f1eb21f261"
},
{
"url": "https://git.kernel.org/stable/c/32c1a2afa90dd07df931f0b12578de1dbb751f0c"
},
{
"url": "https://git.kernel.org/stable/c/b238d86e7f43afde8e830ef5b8d89ffedbbc7613"
},
{
"url": "https://git.kernel.org/stable/c/cbec6a57959ab503e3ad4ad6edd51efb585dce92"
},
{
"url": "https://git.kernel.org/stable/c/58b7e63ca0cd964190957ddd169c899256acaee9"
},
{
"url": "https://git.kernel.org/stable/c/1e33f0de5fdcd09e51fdec1e5822448970b6420f"
}
],
"title": "drm/i915: Return NULL on error in active_instance",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68248",
"datePublished": "2026-08-10T12:01:14.485Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:15.977Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63995 (GCVE-0-2026-63995)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ethtool: cmis: validate start_cmd_payload_size from module
The CMIS firmware update code reads start_cmd_payload_size from
the module's FW Management Features CDB reply and uses it directly
as the byte count for memcpy. The destination buffer is 112 bytes
(ETHTOOL_CMIS_CDB_LPL_MAX_PL_LENGTH - 8). So a malicious
module (or corrupted response) can cause a OOB write later on in
cmis_fw_update_start_download().
Let's error out. If modules that expect longer LPL writes actually
exist we should revisit.
struct cmis_cdb_start_fw_download_pl's definition has to move,
no change there.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ethtool/cmis_fw_update.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "63112b4515469d00008452d9cfe3fb3bf1aa2df3",
"status": "affected",
"version": "c4f78134d45c9619339c96b4bea380b1d0699788",
"versionType": "git"
},
{
"lessThan": "0696709e951be54c699664adf546d16e28974d53",
"status": "affected",
"version": "c4f78134d45c9619339c96b4bea380b1d0699788",
"versionType": "git"
},
{
"lessThan": "a46340da00385be7fb16c62425ebc20006f2d5d8",
"status": "affected",
"version": "c4f78134d45c9619339c96b4bea380b1d0699788",
"versionType": "git"
},
{
"lessThan": "12c2496a71f82f63617971ca9b730dffa05cf58b",
"status": "affected",
"version": "c4f78134d45c9619339c96b4bea380b1d0699788",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ethtool/cmis_fw_update.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: cmis: validate start_cmd_payload_size from module\n\nThe CMIS firmware update code reads start_cmd_payload_size from\nthe module\u0027s FW Management Features CDB reply and uses it directly\nas the byte count for memcpy. The destination buffer is 112 bytes\n(ETHTOOL_CMIS_CDB_LPL_MAX_PL_LENGTH - 8). So a malicious\nmodule (or corrupted response) can cause a OOB write later on in\ncmis_fw_update_start_download().\n\nLet\u0027s error out. If modules that expect longer LPL writes actually\nexist we should revisit.\n\nstruct cmis_cdb_start_fw_download_pl\u0027s definition has to move,\nno change there."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through the ethtool genetlink MODULE_FW_FLASH_ACT handler, not from remote network packet processing. Triggering the bug requires a local privileged process to initiate CMIS firmware flashing on a netdev.\nAC:L - An attacker with CAP_NET_ADMIN who inserts or controls a malicious CMIS module can reliably trigger the overflow by starting a firmware flash while the interface is down. No race or uncontrollable memory-layout conditions are required beyond attacker-controlled module metadata and firmware image content.\nPR:L - The MODULE_FW_FLASH_ACT operation requires CAP_NET_ADMIN enforced via GENL_UNS_ADMIN_PERM with netnsok enabled, which is obtainable by unprivileged users through user namespaces (unshare -Urn). Real init-namespace root is not strictly required.\nUI:N - Exploitation does not depend on a separate victim performing an action; the same privileged attacker who initiates the ethtool firmware-flash command controls the trigger. No end-user interaction beyond the attacker\u0027s own administrative operation is needed.\nS:U - The stack buffer overflow corrupts kernel memory within the same kernel security authority. Impact is kernel memory corruption and potential privilege escalation, not a cross-boundary escape such as VM-to-host or IOMMU bypass.\nC:H - The unchecked memcpy performs an out-of-bounds stack write of up to 143 bytes past a 112-byte vendor_data buffer with attacker-controlled firmware content. Stack corruption adjacent to other locals (including ethtool_cmis_cdb_cmd_args) can be leveraged for arbitrary kernel memory read primitives.\nI:H - The out-of-bounds write corrupts the kernel stack with fully attacker-controlled data from the firmware image, enabling control of adjacent structures and potential control-flow hijacking or arbitrary kernel write primitives.\nA:H - Stack corruption in kernel context during firmware update can cause immediate kernel oops or panic. Even without full exploitation, the memory corruption reliably threatens system availability on affected datacenter and cloud NIC deployments using CMIS pluggable optics."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:59.454Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/63112b4515469d00008452d9cfe3fb3bf1aa2df3"
},
{
"url": "https://git.kernel.org/stable/c/0696709e951be54c699664adf546d16e28974d53"
},
{
"url": "https://git.kernel.org/stable/c/a46340da00385be7fb16c62425ebc20006f2d5d8"
},
{
"url": "https://git.kernel.org/stable/c/12c2496a71f82f63617971ca9b730dffa05cf58b"
}
],
"title": "ethtool: cmis: validate start_cmd_payload_size from module",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63995",
"datePublished": "2026-07-19T14:56:14.580Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-08-05T12:37:59.454Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68105 (GCVE-0-2026-68105)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix kernel panic during driver load failure
Avoid kernel panic if MES init fails during driver load. The KIQ ring is
falsely marked as ready as ASICs that use MES, KIQ is owned by MES.
BUG: kernel NULL pointer dereference, address: 0000000000000000
RIP: 0010:gfx_v12_1_wait_reg_mem+0x5a/0x1f0 [amdgpu]
Call Trace:
gfx_v12_1_ring_emit_reg_write_reg_wait+0x1f/0x30 [amdgpu]
amdgpu_gmc_fw_reg_write_reg_wait+0xb2/0x190 [amdgpu]
amdgpu_gmc_flush_gpu_tlb+0x1cc/0x230 [amdgpu]
amdgpu_gart_invalidate_tlb+0x81/0xa0 [amdgpu]
amdgpu_gart_unbind+0x72/0x90 [amdgpu]
amdgpu_ttm_backend_unbind+0xa4/0xb0 [amdgpu]
amdgpu_ttm_tt_unpopulate+0x13/0xd0 [amdgpu]
amdttm_tt_unpopulate+0x29/0x70 [amdttm]
ttm_bo_put+0x1eb/0x360 [amdttm]
amdgpu_bo_free_kernel+0xf9/0x1f0 [amdgpu]
amdgpu_ih_ring_fini+0x5a/0x90 [amdgpu]
amdgpu_irq_fini_hw+0x58/0x80 [amdgpu]
amdgpu_device_fini_hw+0x4e0/0x5b0 [amdgpu]
amdgpu_driver_load_kms+0x60/0xa0 [amdgpu]
amdgpu_pci_probe+0x28e/0x6d0 [amdgpu]
pci_device_probe+0x19f/0x220
really_probe+0x1ed/0x340
driver_probe_device+0x1e/0x80
__driver_attach+0xd3/0x1a0
bus_for_each_dev+0x68/0xa0
bus_add_driver+0x19f/0x270
driver_register+0x5d/0xf0
do_one_initcall+0xac/0x200
do_init_module+0x1ec/0x280
__se_sys_finit_module+0x2de/0x310
do_syscall_64+0x6a/0x250
entry_SYSCALL_64_after_hwframe+0x4b/0x53
(cherry picked from commit 4623b958dd6da0f4c3026afdf330626a09ecb0f0)
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c",
"drivers/gpu/drm/amd/amdgpu/gfx_v12_1.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5bc93f907bad7e076d814664dfab8fc230efca3d",
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"versionType": "git"
},
{
"lessThan": "a279bd143b3c184358b658e43a057e31ee8c4de5",
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c",
"drivers/gpu/drm/amd/amdgpu/gfx_v12_1.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix kernel panic during driver load failure\n\nAvoid kernel panic if MES init fails during driver load. The KIQ ring is\nfalsely marked as ready as ASICs that use MES, KIQ is owned by MES.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nRIP: 0010:gfx_v12_1_wait_reg_mem+0x5a/0x1f0 [amdgpu]\nCall Trace:\n gfx_v12_1_ring_emit_reg_write_reg_wait+0x1f/0x30 [amdgpu]\n amdgpu_gmc_fw_reg_write_reg_wait+0xb2/0x190 [amdgpu]\n amdgpu_gmc_flush_gpu_tlb+0x1cc/0x230 [amdgpu]\n amdgpu_gart_invalidate_tlb+0x81/0xa0 [amdgpu]\n amdgpu_gart_unbind+0x72/0x90 [amdgpu]\n amdgpu_ttm_backend_unbind+0xa4/0xb0 [amdgpu]\n amdgpu_ttm_tt_unpopulate+0x13/0xd0 [amdgpu]\n amdttm_tt_unpopulate+0x29/0x70 [amdttm]\n ttm_bo_put+0x1eb/0x360 [amdttm]\n amdgpu_bo_free_kernel+0xf9/0x1f0 [amdgpu]\n amdgpu_ih_ring_fini+0x5a/0x90 [amdgpu]\n amdgpu_irq_fini_hw+0x58/0x80 [amdgpu]\n amdgpu_device_fini_hw+0x4e0/0x5b0 [amdgpu]\n amdgpu_driver_load_kms+0x60/0xa0 [amdgpu]\n amdgpu_pci_probe+0x28e/0x6d0 [amdgpu]\n pci_device_probe+0x19f/0x220\n really_probe+0x1ed/0x340\n driver_probe_device+0x1e/0x80\n __driver_attach+0xd3/0x1a0\n bus_for_each_dev+0x68/0xa0\n bus_add_driver+0x19f/0x270\n driver_register+0x5d/0xf0\n do_one_initcall+0xac/0x200\n do_init_module+0x1ec/0x280\n __se_sys_finit_module+0x2de/0x310\n do_syscall_64+0x6a/0x250\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n(cherry picked from commit 4623b958dd6da0f4c3026afdf330626a09ecb0f0)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:54.131Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5bc93f907bad7e076d814664dfab8fc230efca3d"
},
{
"url": "https://git.kernel.org/stable/c/a279bd143b3c184358b658e43a057e31ee8c4de5"
}
],
"title": "drm/amdgpu: Fix kernel panic during driver load failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68105",
"datePublished": "2026-08-10T11:58:22.101Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-17T04:58:54.131Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68159 (GCVE-0-2026-68159)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
__decode_pg_temp() decodes an user-controlled length but only rejects
values large enough to overflow the allocation; it does not bound it to
CEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and
apply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size
on-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends
an OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack
out-of-bounds write.
An OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer
entries at decode time. The bound is well below the old overflow threshold, so
it also covers the allocation-size overflow the previous check guarded against.
BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds
Write of size 4 ... by task exploit
kasan_report (mm/kasan/report.c:595)
ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833)
calc_target (net/ceph/osd_client.c:1638)
__submit_request (net/ceph/osd_client.c:2394)
ceph_osdc_start_request (net/ceph/osd_client.c:2490)
ceph_osdc_call (net/ceph/osd_client.c:5164)
rbd_dev_image_probe (drivers/block/rbd.c:6899)
do_rbd_add (drivers/block/rbd.c:7138)
...
kernel BUG at net/ceph/osdmap.c:2670!
[ idryomov: do the same in __decode_pg_upmap_items() ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "66eec4af1e080b695229c9a20635648a6d12fedf",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "4daf06456677177f2a6044729abac59c1b49e87b",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "d5650ddbd4d42c1a916c8fe1a4c4cb573ef810a1",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "42bc06c67d94d5f2a6b33294b0c4b07d8a47c515",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "ebdf4b4f3b1474079980a2e5cd79ad65fb54db57",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "590b07ceea138d49c9b64f65d263aa902d3b4730",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "e36663145abd7024f0281dfb22fdef65f185845b",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "9f00f9cf2be293efe899db67dc5272e3a9c62717",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE\n\n__decode_pg_temp() decodes an user-controlled length but only rejects\nvalues large enough to overflow the allocation; it does not bound it to\nCEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and\napply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size\non-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends\nan OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack\nout-of-bounds write.\n\nAn OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer\nentries at decode time. The bound is well below the old overflow threshold, so\nit also covers the allocation-size overflow the previous check guarded against.\n\n BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds\n Write of size 4 ... by task exploit\n kasan_report (mm/kasan/report.c:595)\n ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833)\n calc_target (net/ceph/osd_client.c:1638)\n __submit_request (net/ceph/osd_client.c:2394)\n ceph_osdc_start_request (net/ceph/osd_client.c:2490)\n ceph_osdc_call (net/ceph/osd_client.c:5164)\n rbd_dev_image_probe (drivers/block/rbd.c:6899)\n do_rbd_add (drivers/block/rbd.c:7138)\n ...\n kernel BUG at net/ceph/osdmap.c:2670!\n\n[ idryomov: do the same in __decode_pg_upmap_items() ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Malicious pg_temp/pg_upmap data arrives in CEPH_MSG_OSD_MAP from a Ceph monitor or OSD over TCP, is decoded in libceph, and later triggers stack corruption in ceph_pg_to_up_acting_osds during RBD/CephFS/libceph client I/O.\nAC:L - A compromised or attacker-controlled monitor can publish osdmap entries with length \u003e32 for chosen PGs; once the client subscribes, kernel I/O paths such as RBD mount/probe via calc_target deterministically invoke apply_upmap/get_temp_osds and overflow the stack buffer.\nPR:N - Exploitation requires no privileges on the victim host; any machine acting as a Ceph client that receives a forged osdmap from a cluster peer over the network can be attacked without local user capabilities or namespace tricks.\nUI:N - No victim user action is needed during exploitation beyond the host already being a Ceph client; forged osdmaps are applied automatically and the overflow fires on subsequent kernel client operations without interactive steps.\nS:U - Impact is confined to kernel memory on the Ceph client host (privilege escalation or crash); it does not cross VM, IOMMU, or sandbox boundaries to other security authorities.\nC:H - KASAN-confirmed stack out-of-bounds write in ceph_pg_to_up_acting_osds corrupts adjacent stack memory and can be leveraged for arbitrary kernel memory disclosure, not merely a bounded leak.\nI:H - Unbounded copy loops in apply_upmap() and get_temp_osds() write attacker-controlled u32 OSD IDs past the fixed osds[CEPH_PG_MAX_SIZE] stack array, enabling control-flow hijack and arbitrary kernel writes.\nA:H - The reported reproducer triggers KASAN stack-out-of-bounds followed by kernel BUG in ceph_pg_to_up_acting_osds, demonstrating a reliable kernel oops or panic from malformed osdmap processing on Ceph clients."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:00.131Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/66eec4af1e080b695229c9a20635648a6d12fedf"
},
{
"url": "https://git.kernel.org/stable/c/4daf06456677177f2a6044729abac59c1b49e87b"
},
{
"url": "https://git.kernel.org/stable/c/d5650ddbd4d42c1a916c8fe1a4c4cb573ef810a1"
},
{
"url": "https://git.kernel.org/stable/c/42bc06c67d94d5f2a6b33294b0c4b07d8a47c515"
},
{
"url": "https://git.kernel.org/stable/c/ebdf4b4f3b1474079980a2e5cd79ad65fb54db57"
},
{
"url": "https://git.kernel.org/stable/c/590b07ceea138d49c9b64f65d263aa902d3b4730"
},
{
"url": "https://git.kernel.org/stable/c/e36663145abd7024f0281dfb22fdef65f185845b"
},
{
"url": "https://git.kernel.org/stable/c/9f00f9cf2be293efe899db67dc5272e3a9c62717"
}
],
"title": "libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68159",
"datePublished": "2026-08-10T11:59:25.697Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-23T12:46:00.131Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64006 (GCVE-0-2026-64006)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-07-19 14:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix dst corruption in same register operation
For lshift and rshift, the shift operations are performed in a loop over
32-bit words. The loop calculates the shifted value and write it to dst,
and then immediately reads from src to calculate the carry for the next
iteration. Because src and dst could point to the same memory location,
the carry is incorrectly calculated using the newly modified dst value
instead of the original src value.
Adding a temporary local variable to cache the original value before
writing to dst and using it for the carry calculation solves the
problem. In addition, partial overlap is rejected from control plane for
all kind of operations including byteorder. This was tested with the
following bytecode:
table test_table ip flags 0 use 1 handle 1
ip test_table test_chain use 3 type filter hook input prio 0 policy accept packets 0 bytes 0 flags 1
ip test_table test_chain 2
[ immediate reg 1 0x44332211 0x88776655 ]
[ bitwise reg 1 = ( reg 1 << 0x08000000 ) ]
[ cmp eq reg 1 0x66443322 0x00887766 ]
[ counter pkts 0 bytes 0 ]
ip test_table test_chain 4 3
[ immediate reg 1 0x44332211 0x88776655 ]
[ bitwise reg 1 = ( reg 1 << 0x08000000 ) ]
[ cmp eq reg 1 0x55443322 0x00887766 ]
[ counter pkts 21794 bytes 1917798 ]
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/netfilter/nf_tables.h",
"net/netfilter/nft_bitwise.c",
"net/netfilter/nft_byteorder.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b80ef316e978de2ef81d5bee9c19800b4cf96fb8",
"status": "affected",
"version": "567d746b55bc66d3800c9ae91d50f0c5deb2fd93",
"versionType": "git"
},
{
"lessThan": "96bea2a7baac4a1137c188dc7610184487ab30a7",
"status": "affected",
"version": "567d746b55bc66d3800c9ae91d50f0c5deb2fd93",
"versionType": "git"
},
{
"lessThan": "a391afe74398b70107f111aa731eab608624949d",
"status": "affected",
"version": "567d746b55bc66d3800c9ae91d50f0c5deb2fd93",
"versionType": "git"
},
{
"lessThan": "18014147d3ee7831dce53fe65d7fc8d428b02552",
"status": "affected",
"version": "567d746b55bc66d3800c9ae91d50f0c5deb2fd93",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/netfilter/nf_tables.h",
"net/netfilter/nft_bitwise.c",
"net/netfilter/nft_byteorder.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix dst corruption in same register operation\n\nFor lshift and rshift, the shift operations are performed in a loop over\n32-bit words. The loop calculates the shifted value and write it to dst,\nand then immediately reads from src to calculate the carry for the next\niteration. Because src and dst could point to the same memory location,\nthe carry is incorrectly calculated using the newly modified dst value\ninstead of the original src value.\n\nAdding a temporary local variable to cache the original value before\nwriting to dst and using it for the carry calculation solves the\nproblem. In addition, partial overlap is rejected from control plane for\nall kind of operations including byteorder. This was tested with the\nfollowing bytecode:\n\ntable test_table ip flags 0 use 1 handle 1\nip test_table test_chain use 3 type filter hook input prio 0 policy accept packets 0 bytes 0 flags 1\nip test_table test_chain 2\n [ immediate reg 1 0x44332211 0x88776655 ]\n [ bitwise reg 1 = ( reg 1 \u003c\u003c 0x08000000 ) ]\n [ cmp eq reg 1 0x66443322 0x00887766 ]\n [ counter pkts 0 bytes 0 ]\nip test_table test_chain 4 3\n [ immediate reg 1 0x44332211 0x88776655 ]\n [ bitwise reg 1 = ( reg 1 \u003c\u003c 0x08000000 ) ]\n [ cmp eq reg 1 0x55443322 0x00887766 ]\n [ counter pkts 21794 bytes 1917798 ]"
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:56:22.321Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b80ef316e978de2ef81d5bee9c19800b4cf96fb8"
},
{
"url": "https://git.kernel.org/stable/c/96bea2a7baac4a1137c188dc7610184487ab30a7"
},
{
"url": "https://git.kernel.org/stable/c/a391afe74398b70107f111aa731eab608624949d"
},
{
"url": "https://git.kernel.org/stable/c/18014147d3ee7831dce53fe65d7fc8d428b02552"
}
],
"title": "netfilter: nf_tables: fix dst corruption in same register operation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64006",
"datePublished": "2026-07-19T14:56:22.321Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-07-19T14:56:22.321Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64538 (GCVE-0-2026-64538)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
fib6_nh_mtu_change() re-fetches idev via __in6_dev_get(arg->dev) and
dereferences idev->cnf.mtu6 without a NULL check. addrconf_ifdown()
clears dev->ip6_ptr with RCU_INIT_POINTER() after rt6_disable_ip() has
released tb6_lock, so the RA-driven MTU walk can observe a NULL idev and
oops. The caller rt6_mtu_change_route() guards its own __in6_dev_get(),
but this re-fetch is unguarded; nexthop-backed routes survive
addrconf_ifdown()'s flush, so the walk still reaches it after ip6_ptr is
nulled.
Return 0 when idev is NULL, matching rt6_mtu_change_route() and the
fib6_mtu() fix in commit 5ad509c1fdad ("ipv6: Fix null-ptr-deref in
fib6_mtu().").
Oops: general protection fault, ... KASAN: null-ptr-deref in range
[0x00000000000002a8-0x00000000000002af]
RIP: 0010:fib6_nh_mtu_change+0x203/0x990
rt6_mtu_change_route+0x141/0x1d0
__fib6_clean_all+0xd0/0x160
rt6_mtu_change+0xb4/0x100
ndisc_router_discovery+0x24b5/0x2cb0
icmpv6_rcv+0x12e9/0x1710
ipv6_rcv+0x39b/0x410
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c0b220cf7d80eb8a36ae9f12cae6df4577a6814e Version: c0b220cf7d80eb8a36ae9f12cae6df4577a6814e Version: c0b220cf7d80eb8a36ae9f12cae6df4577a6814e Version: c0b220cf7d80eb8a36ae9f12cae6df4577a6814e Version: c0b220cf7d80eb8a36ae9f12cae6df4577a6814e Version: c0b220cf7d80eb8a36ae9f12cae6df4577a6814e Version: c0b220cf7d80eb8a36ae9f12cae6df4577a6814e Version: c0b220cf7d80eb8a36ae9f12cae6df4577a6814e |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:41.449Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d08d019f2f43a6f9a71e81868bbc326b3afaf37b",
"status": "affected",
"version": "c0b220cf7d80eb8a36ae9f12cae6df4577a6814e",
"versionType": "git"
},
{
"lessThan": "1451deca9896957159f0666520a792c1b861af4f",
"status": "affected",
"version": "c0b220cf7d80eb8a36ae9f12cae6df4577a6814e",
"versionType": "git"
},
{
"lessThan": "b2c70dd3326809429b709a9c7e9220d29923051a",
"status": "affected",
"version": "c0b220cf7d80eb8a36ae9f12cae6df4577a6814e",
"versionType": "git"
},
{
"lessThan": "302d57ed7872838b40e56a868fb4c7da7da606e9",
"status": "affected",
"version": "c0b220cf7d80eb8a36ae9f12cae6df4577a6814e",
"versionType": "git"
},
{
"lessThan": "80600b5d0f3ecb9324120dc95b5e915130f516c5",
"status": "affected",
"version": "c0b220cf7d80eb8a36ae9f12cae6df4577a6814e",
"versionType": "git"
},
{
"lessThan": "b0d0eb13a0441a8ebf4f227843deaf494f1e2c33",
"status": "affected",
"version": "c0b220cf7d80eb8a36ae9f12cae6df4577a6814e",
"versionType": "git"
},
{
"lessThan": "6428634f7a0b7878144b4925c37856bef3224967",
"status": "affected",
"version": "c0b220cf7d80eb8a36ae9f12cae6df4577a6814e",
"versionType": "git"
},
{
"lessThan": "46c3b8191aad3d032776bf3bebf03efdf5f4b905",
"status": "affected",
"version": "c0b220cf7d80eb8a36ae9f12cae6df4577a6814e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: Fix null-ptr-deref in fib6_nh_mtu_change().\n\nfib6_nh_mtu_change() re-fetches idev via __in6_dev_get(arg-\u003edev) and\ndereferences idev-\u003ecnf.mtu6 without a NULL check. addrconf_ifdown()\nclears dev-\u003eip6_ptr with RCU_INIT_POINTER() after rt6_disable_ip() has\nreleased tb6_lock, so the RA-driven MTU walk can observe a NULL idev and\noops. The caller rt6_mtu_change_route() guards its own __in6_dev_get(),\nbut this re-fetch is unguarded; nexthop-backed routes survive\naddrconf_ifdown()\u0027s flush, so the walk still reaches it after ip6_ptr is\nnulled.\n\nReturn 0 when idev is NULL, matching rt6_mtu_change_route() and the\nfib6_mtu() fix in commit 5ad509c1fdad (\"ipv6: Fix null-ptr-deref in\nfib6_mtu().\").\n\n Oops: general protection fault, ... KASAN: null-ptr-deref in range\n [0x00000000000002a8-0x00000000000002af]\n RIP: 0010:fib6_nh_mtu_change+0x203/0x990\n rt6_mtu_change_route+0x141/0x1d0\n __fib6_clean_all+0xd0/0x160\n rt6_mtu_change+0xb4/0x100\n ndisc_router_discovery+0x24b5/0x2cb0\n icmpv6_rcv+0x12e9/0x1710\n ipv6_rcv+0x39b/0x410"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:14.474Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d08d019f2f43a6f9a71e81868bbc326b3afaf37b"
},
{
"url": "https://git.kernel.org/stable/c/1451deca9896957159f0666520a792c1b861af4f"
},
{
"url": "https://git.kernel.org/stable/c/b2c70dd3326809429b709a9c7e9220d29923051a"
},
{
"url": "https://git.kernel.org/stable/c/302d57ed7872838b40e56a868fb4c7da7da606e9"
},
{
"url": "https://git.kernel.org/stable/c/80600b5d0f3ecb9324120dc95b5e915130f516c5"
},
{
"url": "https://git.kernel.org/stable/c/b0d0eb13a0441a8ebf4f227843deaf494f1e2c33"
},
{
"url": "https://git.kernel.org/stable/c/6428634f7a0b7878144b4925c37856bef3224967"
},
{
"url": "https://git.kernel.org/stable/c/46c3b8191aad3d032776bf3bebf03efdf5f4b905"
}
],
"title": "ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64538",
"datePublished": "2026-07-27T20:10:32.779Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-09-08T08:50:41.449Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68126 (GCVE-0-2026-68126)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mac802154: hold an interface reference across the scan worker
mac802154_scan_worker() captures the scanning sub-interface under RCU
and then keeps dereferencing sdata->dev after rcu_read_unlock() and
outside the rtnl -- in the failure traces, in
mac802154_transmit_beacon_req() (skb->dev = sdata->dev), and in the
end_scan cleanup. Nothing keeps that netdev alive across the worker
iteration.
A concurrent DEL_INTERFACE or PHY removal can unregister the interface
once the worker drops the rtnl between its two drv_set_channel()
sections. unregister_netdevice() frees the netdev asynchronously from
netdev_run_todo() with the rtnl already dropped, so neither holding the
rtnl nor the per-PHY IEEE802154_IS_SCANNING flag prevents a stale worker
iteration from dereferencing the freed netdev -- a KASAN
slab-use-after-free, reachable by racing TRIGGER_SCAN against
DEL_INTERFACE (both CAP_NET_ADMIN).
Pin the netdev with netdev_hold() while the RCU read lock is still held,
and release it at every worker exit.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac802154/scan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bd7110f0caa32426140ff302a209c53294ef2cfd",
"status": "affected",
"version": "57588c71177f0bfc08509c2c3a9bfe32850c0786",
"versionType": "git"
},
{
"lessThan": "dd4754194a706163294b6141460101b99082c8c7",
"status": "affected",
"version": "57588c71177f0bfc08509c2c3a9bfe32850c0786",
"versionType": "git"
},
{
"lessThan": "59c1d5463b7bc5a2cdaae27108d1dfd67edc7d1b",
"status": "affected",
"version": "57588c71177f0bfc08509c2c3a9bfe32850c0786",
"versionType": "git"
},
{
"lessThan": "5f303f622f6bb8907c405e5123a0ab0f70fb0065",
"status": "affected",
"version": "57588c71177f0bfc08509c2c3a9bfe32850c0786",
"versionType": "git"
},
{
"lessThan": "234e5e898b713bc0b3a631b6f002897f43d046c8",
"status": "affected",
"version": "57588c71177f0bfc08509c2c3a9bfe32850c0786",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac802154/scan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: hold an interface reference across the scan worker\n\nmac802154_scan_worker() captures the scanning sub-interface under RCU\nand then keeps dereferencing sdata-\u003edev after rcu_read_unlock() and\noutside the rtnl -- in the failure traces, in\nmac802154_transmit_beacon_req() (skb-\u003edev = sdata-\u003edev), and in the\nend_scan cleanup. Nothing keeps that netdev alive across the worker\niteration.\n\nA concurrent DEL_INTERFACE or PHY removal can unregister the interface\nonce the worker drops the rtnl between its two drv_set_channel()\nsections. unregister_netdevice() frees the netdev asynchronously from\nnetdev_run_todo() with the rtnl already dropped, so neither holding the\nrtnl nor the per-PHY IEEE802154_IS_SCANNING flag prevents a stale worker\niteration from dereferencing the freed netdev -- a KASAN\nslab-use-after-free, reachable by racing TRIGGER_SCAN against\nDEL_INTERFACE (both CAP_NET_ADMIN).\n\nPin the netdev with netdev_hold() while the RCU read lock is still held,\nand release it at every worker exit."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:17.559Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bd7110f0caa32426140ff302a209c53294ef2cfd"
},
{
"url": "https://git.kernel.org/stable/c/dd4754194a706163294b6141460101b99082c8c7"
},
{
"url": "https://git.kernel.org/stable/c/59c1d5463b7bc5a2cdaae27108d1dfd67edc7d1b"
},
{
"url": "https://git.kernel.org/stable/c/5f303f622f6bb8907c405e5123a0ab0f70fb0065"
},
{
"url": "https://git.kernel.org/stable/c/234e5e898b713bc0b3a631b6f002897f43d046c8"
}
],
"title": "mac802154: hold an interface reference across the scan worker",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68126",
"datePublished": "2026-08-10T11:58:47.478Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-17T04:59:17.559Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72132 (GCVE-0-2026-72132)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-17 05:08
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
NFS: Charge unstable writes by request size, not folio size
nfs_folio_mark_unstable() and nfs_folio_clear_commit() charge and
uncharge NR_WRITEBACK/WB_WRITEBACK by folio_nr_pages(folio) once per
*request* added to or removed from a commit list. This is correct only
when a folio has a single associated request. When pg_test splits a
folio into N sub-folio requests (e.g. pNFS flexfiles striping with a
stripe unit smaller than the folio size, or plain wsize-limited
splitting), each of the N requests independently charges the whole
folio's page count, inflating the accounting by a factor of N per
folio. With large folios and small stripe units this reaches multiple
orders of magnitude: a 2 MiB folio split into 512 4 KiB requests can
charge up to 512x its real size, pushing global dirty+writeback
accounting past the system's dirty threshold and forcing every
buffered writer on the host into the hard-throttle path, including
unrelated in-kernel NFS server threads sharing the box.
Charge each request only for the pages it actually covers.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/nfs/internal.h",
"fs/nfs/pnfs_nfs.c",
"fs/nfs/write.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a442c258320b689f13d2205eaeeddf8b0e630288",
"status": "affected",
"version": "0c493b5cf16e28d761b6e77c7c32aa0e7af70813",
"versionType": "git"
},
{
"lessThan": "1f646e23372f3444dc5f0bcb5404a49d26756add",
"status": "affected",
"version": "0c493b5cf16e28d761b6e77c7c32aa0e7af70813",
"versionType": "git"
},
{
"lessThan": "0ffc032294a29601b1019dba91aa1a930d90df17",
"status": "affected",
"version": "0c493b5cf16e28d761b6e77c7c32aa0e7af70813",
"versionType": "git"
},
{
"lessThan": "a192b6c149c6ea10cc88869accb78165eb454456",
"status": "affected",
"version": "0c493b5cf16e28d761b6e77c7c32aa0e7af70813",
"versionType": "git"
},
{
"lessThan": "27934d02cbeb8a957dd11c985a579e58d30c5270",
"status": "affected",
"version": "0c493b5cf16e28d761b6e77c7c32aa0e7af70813",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/nfs/internal.h",
"fs/nfs/pnfs_nfs.c",
"fs/nfs/write.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Charge unstable writes by request size, not folio size\n\nnfs_folio_mark_unstable() and nfs_folio_clear_commit() charge and\nuncharge NR_WRITEBACK/WB_WRITEBACK by folio_nr_pages(folio) once per\n*request* added to or removed from a commit list. This is correct only\nwhen a folio has a single associated request. When pg_test splits a\nfolio into N sub-folio requests (e.g. pNFS flexfiles striping with a\nstripe unit smaller than the folio size, or plain wsize-limited\nsplitting), each of the N requests independently charges the whole\nfolio\u0027s page count, inflating the accounting by a factor of N per\nfolio. With large folios and small stripe units this reaches multiple\norders of magnitude: a 2 MiB folio split into 512 4 KiB requests can\ncharge up to 512x its real size, pushing global dirty+writeback\naccounting past the system\u0027s dirty threshold and forcing every\nbuffered writer on the host into the hard-throttle path, including\nunrelated in-kernel NFS server threads sharing the box.\n\nCharge each request only for the pages it actually covers."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:08:49.516Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a442c258320b689f13d2205eaeeddf8b0e630288"
},
{
"url": "https://git.kernel.org/stable/c/1f646e23372f3444dc5f0bcb5404a49d26756add"
},
{
"url": "https://git.kernel.org/stable/c/0ffc032294a29601b1019dba91aa1a930d90df17"
},
{
"url": "https://git.kernel.org/stable/c/a192b6c149c6ea10cc88869accb78165eb454456"
},
{
"url": "https://git.kernel.org/stable/c/27934d02cbeb8a957dd11c985a579e58d30c5270"
}
],
"title": "NFS: Charge unstable writes by request size, not folio size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72132",
"datePublished": "2026-08-15T05:53:08.096Z",
"dateReserved": "2026-08-09T03:40:39.907Z",
"dateUpdated": "2026-08-17T05:08:49.516Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64407 (GCVE-0-2026-64407)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()
During the v3 firmware download the controller sends a v3_data_req with a
32 bit offset and a 16 bit len. nxp_recv_fw_req_v3() checks only the lower
bound of the offset and then sends firmware from that offset.
nxpdev->fw_dnld_v3_offset = offset - nxpdev->fw_v3_offset_correction;
serdev_device_write_buf(nxpdev->serdev, nxpdev->fw->data +
nxpdev->fw_dnld_v3_offset, len);
Nothing checks that fw_dnld_v3_offset + len stays within nxpdev->fw->size,
so a controller that asks for an offset or length past the firmware image
makes the driver read past the end of nxpdev->fw->data and send that
memory back over UART.
nxp_recv_fw_req_v1() already bounds the same write. Add the equivalent
check to the v3 path, reject the request when it falls outside the firmware
image, and zero len on the error path so the fw_v3_prev_sent bookkeeping at
free_skb stays consistent.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btnxpuart.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "21e60eb4d95854196e7c0e77383f35e7ac95df61",
"status": "affected",
"version": "689ca16e523278470c38832a3010645a78c544d8",
"versionType": "git"
},
{
"lessThan": "441088792ffec3ca01f4efe2934060570eb11eb8",
"status": "affected",
"version": "689ca16e523278470c38832a3010645a78c544d8",
"versionType": "git"
},
{
"lessThan": "2a68a773089204af1c8581dc79668b775418c5ee",
"status": "affected",
"version": "689ca16e523278470c38832a3010645a78c544d8",
"versionType": "git"
},
{
"lessThan": "49bcb39e3a041ce26021f77971eaccb49a275118",
"status": "affected",
"version": "689ca16e523278470c38832a3010645a78c544d8",
"versionType": "git"
},
{
"lessThan": "badff6c3bed8923a1257a853f137d447976eec30",
"status": "affected",
"version": "689ca16e523278470c38832a3010645a78c544d8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btnxpuart.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()\n\nDuring the v3 firmware download the controller sends a v3_data_req with a\n32 bit offset and a 16 bit len. nxp_recv_fw_req_v3() checks only the lower\nbound of the offset and then sends firmware from that offset.\n\n nxpdev-\u003efw_dnld_v3_offset = offset - nxpdev-\u003efw_v3_offset_correction;\n serdev_device_write_buf(nxpdev-\u003eserdev, nxpdev-\u003efw-\u003edata +\n nxpdev-\u003efw_dnld_v3_offset, len);\n\nNothing checks that fw_dnld_v3_offset + len stays within nxpdev-\u003efw-\u003esize,\nso a controller that asks for an offset or length past the firmware image\nmakes the driver read past the end of nxpdev-\u003efw-\u003edata and send that\nmemory back over UART.\n\nnxp_recv_fw_req_v1() already bounds the same write. Add the equivalent\ncheck to the v3 path, reject the request when it falls outside the firmware\nimage, and zero len on the error path so the fw_v3_prev_sent bookkeeping at\nfree_skb stays consistent."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:05.687Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/21e60eb4d95854196e7c0e77383f35e7ac95df61"
},
{
"url": "https://git.kernel.org/stable/c/441088792ffec3ca01f4efe2934060570eb11eb8"
},
{
"url": "https://git.kernel.org/stable/c/2a68a773089204af1c8581dc79668b775418c5ee"
},
{
"url": "https://git.kernel.org/stable/c/49bcb39e3a041ce26021f77971eaccb49a275118"
},
{
"url": "https://git.kernel.org/stable/c/badff6c3bed8923a1257a853f137d447976eec30"
}
],
"title": "Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64407",
"datePublished": "2026-07-25T08:50:48.912Z",
"dateReserved": "2026-07-19T15:36:31.786Z",
"dateUpdated": "2026-08-17T04:55:05.687Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64121 (GCVE-0-2026-64121)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: ifb: report ethtool stats over num_tx_queues
ifb_dev_init() allocates dp->tx_private to dev->num_tx_queues
entries via kzalloc_objs(*txp, dev->num_tx_queues). Both IFB
per-queue RX and TX stats live in those entries: ifb_xmit() updates
txp->rx_stats using the skb queue mapping, ifb_ri_tasklet() updates
txp->tx_stats, and ifb_stats64() aggregates both over
dev->num_tx_queues.
The ethtool stats callbacks instead size and walk the per-queue
stats with dev->real_num_rx_queues and dev->real_num_tx_queues. With
an asymmetric device where the RX queue count exceeds the TX queue
count, for example:
ip link add name ifb10 numtxqueues 1 numrxqueues 8 type ifb
ethtool -S ifb10
ifb_get_ethtool_stats() indexes past the tx_private allocation and
copies adjacent slab data through ETHTOOL_GSTATS.
Use dev->num_tx_queues consistently for the stats strings, the
stats count, and the stats data walks. This reports one RX stats
group and one TX stats group for each backing ifb_q_private entry,
which is the queue set IFB can actually populate.
Reproduced under UML+KASAN at v7.1-rc2:
BUG: KASAN: slab-out-of-bounds in ifb_fill_stats_data+0x3c/0xae
Read of size 8 at addr 0000000062dbd228 by task ethtool/36
ifb_fill_stats_data+0x3c/0xae
ifb_get_ethtool_stats+0xc0/0x129
__dev_ethtool+0x1ca5/0x363c
dev_ethtool+0x123/0x1b3
dev_ioctl+0x56c/0x744
sock_do_ioctl+0x15f/0x1b2
sock_ioctl+0x4d5/0x50a
sys_ioctl+0xd8b/0xde9
With the patch applied, the same UML+KASAN repro is silent and
ethtool -S ifb10 reports only the stats backed by the single
allocated tx_private entry.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1 Version: a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1 Version: a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1 Version: a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1 Version: a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1 Version: a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ifb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6afdb8113cb007f9332f59a9b7fd45731b8a9de5",
"status": "affected",
"version": "a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1",
"versionType": "git"
},
{
"lessThan": "16bd798cb6d8337d7c3eea1adc412f31b5181d5b",
"status": "affected",
"version": "a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1",
"versionType": "git"
},
{
"lessThan": "301a554e458e2f5ec47f2c336a7cb03b877f9fd6",
"status": "affected",
"version": "a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1",
"versionType": "git"
},
{
"lessThan": "f8a5a76b4a683043c6eff2a060bcaa17f9316ad5",
"status": "affected",
"version": "a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1",
"versionType": "git"
},
{
"lessThan": "2638e1773904d7aa8f24c6e7fda2ed7d69df6fa4",
"status": "affected",
"version": "a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1",
"versionType": "git"
},
{
"lessThan": "5db89c99566fc4728cc92e941d8e1975711e24b5",
"status": "affected",
"version": "a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ifb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ifb: report ethtool stats over num_tx_queues\n\nifb_dev_init() allocates dp-\u003etx_private to dev-\u003enum_tx_queues\nentries via kzalloc_objs(*txp, dev-\u003enum_tx_queues). Both IFB\nper-queue RX and TX stats live in those entries: ifb_xmit() updates\ntxp-\u003erx_stats using the skb queue mapping, ifb_ri_tasklet() updates\ntxp-\u003etx_stats, and ifb_stats64() aggregates both over\ndev-\u003enum_tx_queues.\n\nThe ethtool stats callbacks instead size and walk the per-queue\nstats with dev-\u003ereal_num_rx_queues and dev-\u003ereal_num_tx_queues. With\nan asymmetric device where the RX queue count exceeds the TX queue\ncount, for example:\n\n ip link add name ifb10 numtxqueues 1 numrxqueues 8 type ifb\n ethtool -S ifb10\n\nifb_get_ethtool_stats() indexes past the tx_private allocation and\ncopies adjacent slab data through ETHTOOL_GSTATS.\n\nUse dev-\u003enum_tx_queues consistently for the stats strings, the\nstats count, and the stats data walks. This reports one RX stats\ngroup and one TX stats group for each backing ifb_q_private entry,\nwhich is the queue set IFB can actually populate.\n\nReproduced under UML+KASAN at v7.1-rc2:\n\n BUG: KASAN: slab-out-of-bounds in ifb_fill_stats_data+0x3c/0xae\n Read of size 8 at addr 0000000062dbd228 by task ethtool/36\n ifb_fill_stats_data+0x3c/0xae\n ifb_get_ethtool_stats+0xc0/0x129\n __dev_ethtool+0x1ca5/0x363c\n dev_ethtool+0x123/0x1b3\n dev_ioctl+0x56c/0x744\n sock_do_ioctl+0x15f/0x1b2\n sock_ioctl+0x4d5/0x50a\n sys_ioctl+0xd8b/0xde9\n\nWith the patch applied, the same UML+KASAN repro is silent and\nethtool -S ifb10 reports only the stats backed by the single\nallocated tx_private entry."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:19.745Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6afdb8113cb007f9332f59a9b7fd45731b8a9de5"
},
{
"url": "https://git.kernel.org/stable/c/16bd798cb6d8337d7c3eea1adc412f31b5181d5b"
},
{
"url": "https://git.kernel.org/stable/c/301a554e458e2f5ec47f2c336a7cb03b877f9fd6"
},
{
"url": "https://git.kernel.org/stable/c/f8a5a76b4a683043c6eff2a060bcaa17f9316ad5"
},
{
"url": "https://git.kernel.org/stable/c/2638e1773904d7aa8f24c6e7fda2ed7d69df6fa4"
},
{
"url": "https://git.kernel.org/stable/c/5db89c99566fc4728cc92e941d8e1975711e24b5"
}
],
"title": "net: ifb: report ethtool stats over num_tx_queues",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64121",
"datePublished": "2026-07-19T15:40:19.745Z",
"dateReserved": "2026-07-19T07:54:57.036Z",
"dateUpdated": "2026-07-19T15:40:19.745Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64600 (GCVE-0-2026-64600)
Vulnerability from cvelistv5
Published
2026-07-23 05:46
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode,
a data fork mapping, and a cow fork mapping. Unfortunately, these two
helpers cycle the ILOCK to grab a transaction, which means that the
mappings are stale as soon as we reacquire the ILOCK. Currently we
refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but
we don't refresh the data fork mapping beforehand, which means that the
xfs_bmap_trim_cow in that function queries the refcount btree about the
wrong physical blocks and returns an inaccurate value in *shared.
If *shared is now false, the directio write proceeds with a stale data
fork mapping. Fix this by querying the data fork mapping if the
sequence counter changes across the ILOCK cycle.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 Version: 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 Version: 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 Version: 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 Version: 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 Version: 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 Version: 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 |
||
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-08-03T20:31:20.507Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/07/22/14"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/07/22/18"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/07/22/19"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/07/31/3"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/03/4"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/03/8"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_reflink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dc11be133efca5fe3a2fb02b016dee825cc12f18",
"status": "affected",
"version": "3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5",
"versionType": "git"
},
{
"lessThan": "b8c9aa832b52680ee40d6cab0efb081f9a69df05",
"status": "affected",
"version": "3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5",
"versionType": "git"
},
{
"lessThan": "50f0012da1040f69a4e788cd9aed587c9a04983f",
"status": "affected",
"version": "3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5",
"versionType": "git"
},
{
"lessThan": "e705d81a7193dd19e69b8e2bad4696d78a4ea075",
"status": "affected",
"version": "3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5",
"versionType": "git"
},
{
"lessThan": "206c09b04dc5469c7ff14d8aceff2d47c88078d9",
"status": "affected",
"version": "3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5",
"versionType": "git"
},
{
"lessThan": "44f891bc088958399eec27f7604928694aa35581",
"status": "affected",
"version": "3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5",
"versionType": "git"
},
{
"lessThan": "2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7",
"status": "affected",
"version": "3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_reflink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: resample the data fork mapping after cycling ILOCK\n\nxfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode,\na data fork mapping, and a cow fork mapping. Unfortunately, these two\nhelpers cycle the ILOCK to grab a transaction, which means that the\nmappings are stale as soon as we reacquire the ILOCK. Currently we\nrefresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but\nwe don\u0027t refresh the data fork mapping beforehand, which means that the\nxfs_bmap_trim_cow in that function queries the refcount btree about the\nwrong physical blocks and returns an inaccurate value in *shared.\n\nIf *shared is now false, the directio write proceeds with a stale data\nfork mapping. Fix this by querying the data fork mapping if the\nsequence counter changes across the ILOCK cycle."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation uses local FICLONE and concurrent O_DIRECT write syscalls against an XFS filesystem.\nAC:L - The attacker controls both racing writers, can amplify the transaction-allocation window, and demonstrated exploitation typically succeeds within seconds.\nPR:L - A basic unprivileged local user needs only read access to the protected source and write access to a scratch file; no capabilities are required.\nUI:N - The attacker creates the reflink and triggers both sides of the race without any victim action.\nS:U - This is a standard local kernel-mediated privilege escalation affecting resources within the host operating system\u0027s existing security authority.\nC:H - Overwriting /etc/passwd or a readable SUID-root binary yields full root access and consequently unrestricted access to system-confidential data.\nI:H - The stale physical mapping provides attacker-controlled persistent writes into protected readable files while preserving their ownership and SUID metadata, enabling full root compromise.\nA:H - The attacker can persistently corrupt boot-critical binaries or configuration files and, after obtaining root, cause complete system unavailability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:23.073Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dc11be133efca5fe3a2fb02b016dee825cc12f18"
},
{
"url": "https://git.kernel.org/stable/c/b8c9aa832b52680ee40d6cab0efb081f9a69df05"
},
{
"url": "https://git.kernel.org/stable/c/50f0012da1040f69a4e788cd9aed587c9a04983f"
},
{
"url": "https://git.kernel.org/stable/c/e705d81a7193dd19e69b8e2bad4696d78a4ea075"
},
{
"url": "https://git.kernel.org/stable/c/206c09b04dc5469c7ff14d8aceff2d47c88078d9"
},
{
"url": "https://git.kernel.org/stable/c/44f891bc088958399eec27f7604928694aa35581"
},
{
"url": "https://git.kernel.org/stable/c/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7"
},
{
"url": "https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt"
}
],
"title": "xfs: resample the data fork mapping after cycling ILOCK",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64600",
"datePublished": "2026-07-23T05:46:56.149Z",
"dateReserved": "2026-07-19T15:36:31.799Z",
"dateUpdated": "2026-08-17T04:58:23.073Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74334 (GCVE-0-2026-74334)
Vulnerability from cvelistv5
Published
2026-08-15 05:58
Modified
2026-08-17 05:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/nldev: Fix locking when accessing mr->pd
Sashiko points out that, due to rereg_mr, the PD is actually variable and
all the touches in nldev are racy.
Use mr->device instead of mr->pd->device.
Getting the PD restrack ID is more tricky. To avoid disturbing all the
happy paths, add an rdma_restrack_sync() operation which is sort of like
flush_workqueue() or synchronize_irq(): after it returns, all the old
nldev touches to the mr are gone and everything sees the new PD. This
makes it safe to reach into the PD pointer.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/nldev.c",
"drivers/infiniband/core/restrack.c",
"drivers/infiniband/core/restrack.h",
"drivers/infiniband/core/uverbs_cmd.c",
"include/rdma/ib_verbs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1a132ee4e655288d9a0937ea5109a0d038431ae9",
"status": "affected",
"version": "da5c8507821573b8ed6e3f47e009f273493ffaf7",
"versionType": "git"
},
{
"lessThan": "50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3",
"status": "affected",
"version": "da5c8507821573b8ed6e3f47e009f273493ffaf7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/nldev.c",
"drivers/infiniband/core/restrack.c",
"drivers/infiniband/core/restrack.h",
"drivers/infiniband/core/uverbs_cmd.c",
"include/rdma/ib_verbs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/nldev: Fix locking when accessing mr-\u003epd\n\nSashiko points out that, due to rereg_mr, the PD is actually variable and\nall the touches in nldev are racy.\n\nUse mr-\u003edevice instead of mr-\u003epd-\u003edevice.\n\nGetting the PD restrack ID is more tricky. To avoid disturbing all the\nhappy paths, add an rdma_restrack_sync() operation which is sort of like\nflush_workqueue() or synchronize_irq(): after it returns, all the old\nnldev touches to the mr are gone and everything sees the new PD. This\nmakes it safe to reach into the PD pointer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached via local NETLINK_RDMA nldev MR resource dumps and concurrent IB_USER_VERBS_CMD_REREG_MR ioctl on /dev/infiniband/uverbs; it is not triggered by remote RDMA/InfiniBand/RoCE network traffic.\nAC:L - An attacker controls both race sides by spawning threads that hammer rereg_mr with IB_MR_REREG_PD and nldev RES_MR_GET dumps, optionally deallocating the old PD; no timing or layout conditions outside attacker control are required.\nPR:L - Exploitation needs only local uverbs access (device nodes default 0666) plus NETLINK_RDMA dumps; CAP_NET_ADMIN for netlink send is obtainable by unprivileged users via user namespaces, not real init-namespace root.\nUI:N - No victim interaction is required; the attacker triggers both the rereg_mr PD change and the concurrent nldev MR dump from their own process.\nS:U - Impact is kernel heap corruption and privilege escalation within the host kernel security boundary, not a VM escape, IOMMU bypass, or cross-authority sandbox breakout.\nC:H - Concurrent rereg_mr can free the old ib_pd while nldev still dereferences mr-\u003epd for device and res.id, creating a use-after-free that enables arbitrary kernel memory disclosure via controlled reuse of freed slab objects.\nI:H - The ib_pd UAF is exploitable for heap grooming and arbitrary kernel write or control-flow hijack, not merely a bounded data corruption or guaranteed crash.\nA:H - The race reliably causes kernel oops or panic from dereferencing a freed ib_pd during nldev dumps, and UAF exploitation can additionally crash or hang the system during heap manipulation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:46:03.176Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1a132ee4e655288d9a0937ea5109a0d038431ae9"
},
{
"url": "https://git.kernel.org/stable/c/50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3"
}
],
"title": "RDMA/nldev: Fix locking when accessing mr-\u003epd",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74334",
"datePublished": "2026-08-15T05:58:26.455Z",
"dateReserved": "2026-08-15T05:44:03.885Z",
"dateUpdated": "2026-08-17T05:46:03.176Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64014 (GCVE-0-2026-64014)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-07-19 14:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size
nexio_read_data() pulls data_len and x_len from a packed __be16 header
in the device's interrupt packet and then walks packet->data[0..x_len)
and packet->data[x_len..data_len) comparing each byte against a
threshold.
Both fields are 16-bit on the wire (max 65535). The existing
adjustments shave at most 0x100 / 0x80 off, so the loop bound can still
reach roughly 0xfeff. The URB transfer buffer for NEXIO is rept_size
(1024) bytes from usb_alloc_coherent(), with the first 7 occupied by the
packed header — so packet->data[] has 1017 valid bytes. read_data()
callbacks are not given urb->actual_length, and nothing else bounds the
walk.
A device that lies about its length can get a ~64 KiB out-of-bounds read
past the coherent DMA allocation. The first index whose byte exceeds
NEXIO_THRESHOLD lands in begin_x / begin_y and from there into the
reported touch coordinates, so adjacent kernel memory contents leak to
userspace as ABS_X / ABS_Y events. Far enough out, the read can also
hit an unmapped page and fault.
Fix this all by clamping data_len to the buffer's data[] capacity and
x_len to data_len.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5197424cdcccd2b0b1922babb93969b2515c43ce Version: 5197424cdcccd2b0b1922babb93969b2515c43ce Version: 5197424cdcccd2b0b1922babb93969b2515c43ce Version: 5197424cdcccd2b0b1922babb93969b2515c43ce Version: 5197424cdcccd2b0b1922babb93969b2515c43ce Version: 5197424cdcccd2b0b1922babb93969b2515c43ce Version: 5197424cdcccd2b0b1922babb93969b2515c43ce Version: 5197424cdcccd2b0b1922babb93969b2515c43ce |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/usbtouchscreen.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45c829e5eb3b974282bae50b7cca2cc891f74f0b",
"status": "affected",
"version": "5197424cdcccd2b0b1922babb93969b2515c43ce",
"versionType": "git"
},
{
"lessThan": "e7cdcb266ba06d8480809b78ab8bb2bf8ff51ccb",
"status": "affected",
"version": "5197424cdcccd2b0b1922babb93969b2515c43ce",
"versionType": "git"
},
{
"lessThan": "95f47331dfde243f93e679ce70bd0c24b37c683d",
"status": "affected",
"version": "5197424cdcccd2b0b1922babb93969b2515c43ce",
"versionType": "git"
},
{
"lessThan": "d883312061ccde8c536595998aaf687ec070077c",
"status": "affected",
"version": "5197424cdcccd2b0b1922babb93969b2515c43ce",
"versionType": "git"
},
{
"lessThan": "103d2de9f505f56da173e43f12dba62f92620278",
"status": "affected",
"version": "5197424cdcccd2b0b1922babb93969b2515c43ce",
"versionType": "git"
},
{
"lessThan": "0ca809ea8e0355299266c46e5f1755040aa8dcf3",
"status": "affected",
"version": "5197424cdcccd2b0b1922babb93969b2515c43ce",
"versionType": "git"
},
{
"lessThan": "7585b6aa55d8ac85ad22f522e1059f93507727b6",
"status": "affected",
"version": "5197424cdcccd2b0b1922babb93969b2515c43ce",
"versionType": "git"
},
{
"lessThan": "2905281cbda52ec9df540113b35b835feb5fafd3",
"status": "affected",
"version": "5197424cdcccd2b0b1922babb93969b2515c43ce",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/usbtouchscreen.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size\n\nnexio_read_data() pulls data_len and x_len from a packed __be16 header\nin the device\u0027s interrupt packet and then walks packet-\u003edata[0..x_len)\nand packet-\u003edata[x_len..data_len) comparing each byte against a\nthreshold.\n\nBoth fields are 16-bit on the wire (max 65535). The existing\nadjustments shave at most 0x100 / 0x80 off, so the loop bound can still\nreach roughly 0xfeff. The URB transfer buffer for NEXIO is rept_size\n(1024) bytes from usb_alloc_coherent(), with the first 7 occupied by the\npacked header \u2014 so packet-\u003edata[] has 1017 valid bytes. read_data()\ncallbacks are not given urb-\u003eactual_length, and nothing else bounds the\nwalk.\n\nA device that lies about its length can get a ~64 KiB out-of-bounds read\npast the coherent DMA allocation. The first index whose byte exceeds\nNEXIO_THRESHOLD lands in begin_x / begin_y and from there into the\nreported touch coordinates, so adjacent kernel memory contents leak to\nuserspace as ABS_X / ABS_Y events. Far enough out, the read can also\nhit an unmapped page and fault.\n\nFix this all by clamping data_len to the buffer\u0027s data[] capacity and\nx_len to data_len."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:56:27.995Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45c829e5eb3b974282bae50b7cca2cc891f74f0b"
},
{
"url": "https://git.kernel.org/stable/c/e7cdcb266ba06d8480809b78ab8bb2bf8ff51ccb"
},
{
"url": "https://git.kernel.org/stable/c/95f47331dfde243f93e679ce70bd0c24b37c683d"
},
{
"url": "https://git.kernel.org/stable/c/d883312061ccde8c536595998aaf687ec070077c"
},
{
"url": "https://git.kernel.org/stable/c/103d2de9f505f56da173e43f12dba62f92620278"
},
{
"url": "https://git.kernel.org/stable/c/0ca809ea8e0355299266c46e5f1755040aa8dcf3"
},
{
"url": "https://git.kernel.org/stable/c/7585b6aa55d8ac85ad22f522e1059f93507727b6"
},
{
"url": "https://git.kernel.org/stable/c/2905281cbda52ec9df540113b35b835feb5fafd3"
}
],
"title": "Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64014",
"datePublished": "2026-07-19T14:56:27.995Z",
"dateReserved": "2026-07-19T07:54:57.027Z",
"dateUpdated": "2026-07-19T14:56:27.995Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68368 (GCVE-0-2026-68368)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length
against frame_max but does not verify that the datagram fits within the
declared block length. Additionally, when decoding multiple NTBs from a
single socket buffer, subsequent block lengths are not checked against the
actual remaining buffer data.
With these checks missing, a malicious USB host can specify datagram
offsets and lengths that point beyond the block, or supply secondary NTB
headers declaring lengths larger than the buffer. skb_put_data() then
copies adjacent kernel memory from skb_shared_info into the network skb.
Fix this by verifying that sufficient buffer space remains for the NTB
header before parsing, handling zero-length block declarations, ensuring
that block lengths never exceed the remaining buffer space, and verifying
that each datagram payload stays strictly within the block boundary.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: f7e0611e207d8908c4f2858e244370529a76dbf7 Version: b88ad6e714284b33a47834f5f2a294c2b37c66aa Version: 471b23586387a32857778c511be60ab31c98dcfd Version: 4f529c4d1e436230d3af7c09a3239677a14d2b46 Version: ae6a5394d9fbe118bc95cfe376d6a9d91d7547e8 Version: 5bdf93a2f5459f944b416b188178ca4a92fd206f Version: ff3ba016263ee93a1c6209bf5ab1599de7ab1512 Version: e7ca00f35d8a17af1ae19d529193ebc21bfda164 Version: 4.9.235 ≤ Version: 4.14.196 ≤ Version: 4.19.143 ≤ Version: 5.4.62 ≤ Version: 5.8.6 ≤ Version: 4.14.328 ≤ Version: 4.19.297 ≤ Version: 5.4.259 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_ncm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "35d15bbaec0557330e774ec31412ef508de6e0e0",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "6b2be489eaa6293e60549005d91f15ceb150510f",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "f87ed889f0f7417b8938c98d8833f559b755373c",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "fff1059d139ef798bab917990524faaf25854ca8",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "40c706a0224bde194667e3378c689b542fec4b44",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "1febec7e47cdcd01f43fb0211094e3010474666e",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"status": "affected",
"version": "f7e0611e207d8908c4f2858e244370529a76dbf7",
"versionType": "git"
},
{
"status": "affected",
"version": "b88ad6e714284b33a47834f5f2a294c2b37c66aa",
"versionType": "git"
},
{
"status": "affected",
"version": "471b23586387a32857778c511be60ab31c98dcfd",
"versionType": "git"
},
{
"status": "affected",
"version": "4f529c4d1e436230d3af7c09a3239677a14d2b46",
"versionType": "git"
},
{
"status": "affected",
"version": "ae6a5394d9fbe118bc95cfe376d6a9d91d7547e8",
"versionType": "git"
},
{
"status": "affected",
"version": "5bdf93a2f5459f944b416b188178ca4a92fd206f",
"versionType": "git"
},
{
"status": "affected",
"version": "ff3ba016263ee93a1c6209bf5ab1599de7ab1512",
"versionType": "git"
},
{
"status": "affected",
"version": "e7ca00f35d8a17af1ae19d529193ebc21bfda164",
"versionType": "git"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.235",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.196",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.143",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.62",
"versionType": "semver"
},
{
"lessThan": "5.9",
"status": "affected",
"version": "5.8.6",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.328",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.297",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.259",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_ncm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.235",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.196",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.143",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.62",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.8.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.328",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.297",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.259",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()\n\nWhen unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length\nagainst frame_max but does not verify that the datagram fits within the\ndeclared block length. Additionally, when decoding multiple NTBs from a\nsingle socket buffer, subsequent block lengths are not checked against the\nactual remaining buffer data.\n\nWith these checks missing, a malicious USB host can specify datagram\noffsets and lengths that point beyond the block, or supply secondary NTB\nheaders declaring lengths larger than the buffer. skb_put_data() then\ncopies adjacent kernel memory from skb_shared_info into the network skb.\n\nFix this by verifying that sufficient buffer space remains for the NTB\nheader before parsing, handling zero-length block declarations, ensuring\nthat block lengths never exceed the remaining buffer space, and verifying\nthat each datagram payload stays strictly within the block boundary."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:26.235Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/35d15bbaec0557330e774ec31412ef508de6e0e0"
},
{
"url": "https://git.kernel.org/stable/c/6b2be489eaa6293e60549005d91f15ceb150510f"
},
{
"url": "https://git.kernel.org/stable/c/f87ed889f0f7417b8938c98d8833f559b755373c"
},
{
"url": "https://git.kernel.org/stable/c/e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f"
},
{
"url": "https://git.kernel.org/stable/c/fff1059d139ef798bab917990524faaf25854ca8"
},
{
"url": "https://git.kernel.org/stable/c/40c706a0224bde194667e3378c689b542fec4b44"
},
{
"url": "https://git.kernel.org/stable/c/41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c"
},
{
"url": "https://git.kernel.org/stable/c/1febec7e47cdcd01f43fb0211094e3010474666e"
}
],
"title": "usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68368",
"datePublished": "2026-08-10T12:03:45.579Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:26.235Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68353 (GCVE-0-2026-68353)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
The firmware-controlled num_msg field (u8, 0-255) drives the loop in
ath6kl_wmi_tx_complete_event_rx() without validation against the buffer
length. This allows out-of-bounds reads of up to 1020 bytes past the
WMI event buffer when the firmware sends an inflated num_msg.
Add a check that the buffer is large enough to hold the fixed struct
and the num_msg variable-length entries.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5297299c3fa6133275db0be99d69cd759b6cbfe9",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "35196a07603f8c94a4943093bc26d5b5826285f8",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "0e0fc04af9b443c6b425f00fb604ff599bc80d1d",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "69ac7ba3a3df6654e7daa82674575a8c4a1a63ea",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "289edc3c71344b89e6522891147cfb8f61b088bb",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "eb636fbc443149b3501c3f97e26225ddcb314a0f",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "c38b0d5c661951b5dd082bdf31f8a57a0ce6e540",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler\n\nThe firmware-controlled num_msg field (u8, 0-255) drives the loop in\nath6kl_wmi_tx_complete_event_rx() without validation against the buffer\nlength. This allows out-of-bounds reads of up to 1020 bytes past the\nWMI event buffer when the firmware sends an inflated num_msg.\n\nAdd a check that the buffer is large enough to hold the fixed struct\nand the num_msg variable-length entries."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable handler parses WMI control events delivered by the ath6kl AR600x wireless firmware over SDIO/USB; an attacker on the same wireless segment who subverts or influences the wireless device\u0027s firmware supplies the malformed event, matching the adjacent-network vector used for other ath driver event-parsing flaws.\nAC:L - Triggering requires only a WMI_TX_COMPLETE_EVENTID event whose payload is shorter than num_msg * 4 bytes; the loop bound is taken directly from the event with no validation, so the read happens deterministically every time.\nPR:N - The event is processed in the driver\u0027s asynchronous control-message receive path with no capability check, no syscall entry, and no authentication or association gate; the attacker needs no credentials on the target system.\nUI:N - The WMI event is handled automatically by the driver as soon as the interface is running; no victim action such as opening a file or issuing a command is needed.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Up to 1020 bytes past the event buffer are read and the contents are emitted through ath6kl_dbg() into the kernel log on debug builds, disclosing adjacent kernel heap data well beyond a small bounded read.\nI:N - The loop only reads and prints the out-of-bounds entries; there is no write to kernel memory and no attacker-controlled pointer is dereferenced for modification.\nA:H - The read can walk past the end of the slab allocation into unmapped or redzoned memory, producing an oops or a KASAN panic on hardened/debug kernels and thus a full loss of availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:58.283Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5297299c3fa6133275db0be99d69cd759b6cbfe9"
},
{
"url": "https://git.kernel.org/stable/c/35196a07603f8c94a4943093bc26d5b5826285f8"
},
{
"url": "https://git.kernel.org/stable/c/0e0fc04af9b443c6b425f00fb604ff599bc80d1d"
},
{
"url": "https://git.kernel.org/stable/c/69ac7ba3a3df6654e7daa82674575a8c4a1a63ea"
},
{
"url": "https://git.kernel.org/stable/c/289edc3c71344b89e6522891147cfb8f61b088bb"
},
{
"url": "https://git.kernel.org/stable/c/eb636fbc443149b3501c3f97e26225ddcb314a0f"
},
{
"url": "https://git.kernel.org/stable/c/c38b0d5c661951b5dd082bdf31f8a57a0ce6e540"
},
{
"url": "https://git.kernel.org/stable/c/3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495"
}
],
"title": "wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68353",
"datePublished": "2026-08-10T12:03:30.330Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:33:58.283Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43319 (GCVE-0-2026-43319)
Vulnerability from cvelistv5
Published
2026-05-08 13:26
Modified
2026-06-01 16:15
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
spi: spidev: fix lock inversion between spi_lock and buf_lock
The spidev driver previously used two mutexes, spi_lock and buf_lock,
but acquired them in different orders depending on the code path:
write()/read(): buf_lock -> spi_lock
ioctl(): spi_lock -> buf_lock
This AB-BA locking pattern triggers lockdep warnings and can
cause real deadlocks:
WARNING: possible circular locking dependency detected
spidev_ioctl() -> mutex_lock(&spidev->buf_lock)
spidev_sync_write() -> mutex_lock(&spidev->spi_lock)
*** DEADLOCK ***
The issue is reproducible with a simple userspace program that
performs write() and SPI_IOC_WR_MAX_SPEED_HZ ioctl() calls from
separate threads on the same spidev file descriptor.
Fix this by simplifying the locking model and removing the lock
inversion entirely. spidev_sync() no longer performs any locking,
and all callers serialize access using spi_lock.
buf_lock is removed since its functionality is fully covered by
spi_lock, eliminating the possibility of lock ordering issues.
This removes the lock inversion and prevents deadlocks without
changing userspace ABI or behaviour.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/spi/spidev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fabfed1afe273717ea33b8aee46b767360edbb80",
"status": "affected",
"version": "a720416d94634068951773cb9e9d6f1b73769e5b",
"versionType": "git"
},
{
"lessThan": "f8431b8672231d378b03176fe74c95adfd3522cf",
"status": "affected",
"version": "a720416d94634068951773cb9e9d6f1b73769e5b",
"versionType": "git"
},
{
"lessThan": "e341e18215030af2136836b78508e0d798916df7",
"status": "affected",
"version": "a720416d94634068951773cb9e9d6f1b73769e5b",
"versionType": "git"
},
{
"lessThan": "41ccfac7d302968a4f32b5f7b012d066c5f5cdf8",
"status": "affected",
"version": "a720416d94634068951773cb9e9d6f1b73769e5b",
"versionType": "git"
},
{
"lessThan": "40534d19ed2afb880ecf202dab26a8e7a5808d16",
"status": "affected",
"version": "a720416d94634068951773cb9e9d6f1b73769e5b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/spi/spidev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spidev: fix lock inversion between spi_lock and buf_lock\n\nThe spidev driver previously used two mutexes, spi_lock and buf_lock,\nbut acquired them in different orders depending on the code path:\n\n write()/read(): buf_lock -\u003e spi_lock\n ioctl(): spi_lock -\u003e buf_lock\n\nThis AB-BA locking pattern triggers lockdep warnings and can\ncause real deadlocks:\n\n WARNING: possible circular locking dependency detected\n spidev_ioctl() -\u003e mutex_lock(\u0026spidev-\u003ebuf_lock)\n spidev_sync_write() -\u003e mutex_lock(\u0026spidev-\u003espi_lock)\n *** DEADLOCK ***\n\nThe issue is reproducible with a simple userspace program that\nperforms write() and SPI_IOC_WR_MAX_SPEED_HZ ioctl() calls from\nseparate threads on the same spidev file descriptor.\n\nFix this by simplifying the locking model and removing the lock\ninversion entirely. spidev_sync() no longer performs any locking,\nand all callers serialize access using spi_lock.\n\nbuf_lock is removed since its functionality is fully covered by\nspi_lock, eliminating the possibility of lock ordering issues.\n\nThis removes the lock inversion and prevents deadlocks without\nchanging userspace ABI or behaviour."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-01T16:15:35.875Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fabfed1afe273717ea33b8aee46b767360edbb80"
},
{
"url": "https://git.kernel.org/stable/c/f8431b8672231d378b03176fe74c95adfd3522cf"
},
{
"url": "https://git.kernel.org/stable/c/e341e18215030af2136836b78508e0d798916df7"
},
{
"url": "https://git.kernel.org/stable/c/41ccfac7d302968a4f32b5f7b012d066c5f5cdf8"
},
{
"url": "https://git.kernel.org/stable/c/40534d19ed2afb880ecf202dab26a8e7a5808d16"
}
],
"title": "spi: spidev: fix lock inversion between spi_lock and buf_lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43319",
"datePublished": "2026-05-08T13:26:14.231Z",
"dateReserved": "2026-05-01T14:12:56.001Z",
"dateUpdated": "2026-06-01T16:15:35.875Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64598 (GCVE-0-2026-64598)
Vulnerability from cvelistv5
Published
2026-08-06 07:13
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb/client: Fix error code in smb2_aead_req_alloc()
The "*num_sgs" variable is a u32 so "ERR_PTR(*num_sgs)" doesn't work.
We would have to do something similar to the previous line where it's
cast to int and then long. However, it's simpler to store the return in
an int ret variable.
This bug would eventually result in a crash when dereference the invalid
error pointer.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "aa37f5fef78dd11cbf983269da2031e12625c56d",
"status": "affected",
"version": "d08089f649a0cfb2099c8551ac47eef0cc23fdf2",
"versionType": "git"
},
{
"lessThan": "cad756733dc3985188983f3e2eb77e2927209099",
"status": "affected",
"version": "d08089f649a0cfb2099c8551ac47eef0cc23fdf2",
"versionType": "git"
},
{
"lessThan": "a187883cc1dc784a4d32537f5d316f1b7b9ad76f",
"status": "affected",
"version": "d08089f649a0cfb2099c8551ac47eef0cc23fdf2",
"versionType": "git"
},
{
"lessThan": "a1cc432cb0b0a1f74f98a0db3b94ca880c7947ac",
"status": "affected",
"version": "d08089f649a0cfb2099c8551ac47eef0cc23fdf2",
"versionType": "git"
},
{
"lessThan": "61f28012e5650c619223decdb7970e0d3162e949",
"status": "affected",
"version": "d08089f649a0cfb2099c8551ac47eef0cc23fdf2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: Fix error code in smb2_aead_req_alloc()\n\nThe \"*num_sgs\" variable is a u32 so \"ERR_PTR(*num_sgs)\" doesn\u0027t work.\nWe would have to do something similar to the previous line where it\u0027s\ncast to int and then long. However, it\u0027s simpler to store the return in\nan int ret variable.\n\nThis bug would eventually result in a crash when dereference the invalid\nerror pointer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The buggy smb2_aead_req_alloc()/crypt_message() path runs in the in-kernel SMB3 client during encrypted transform processing over an SMB network session; the highest-severity scenario is a client mounting and using an untrusted or malicious SMB3 encrypted share.\nAC:L - When cifs_get_num_sgs() returns a negative errno, the u32 truncation makes ERR_PTR() bypass IS_ERR() deterministically on 64-bit, and the subsequent sg_init_marker()/pointer use crashes without requiring an attacker-uncontrollable race or memory layout.\nPR:N - The attacking SMB endpoint or network adversary needs no privileges or account on the victim client; client-side credentials used to mount the share are a victim condition, not attacker privileges.\nUI:R - A victim must mount or otherwise use an SMB3 share with encryption so the client encrypt/decrypt AEAD allocation path runs; per CVSS guidance, mounting a filesystem is user interaction.\nS:U - The invalid error-pointer dereference and resulting kernel memory access remain within the client kernel\u0027s security authority and do not cross a VM, IOMMU, or sandbox boundary.\nC:H - IS_ERR() failure leads to wild pointer use (uninitialized AEAD/sg state and invalid creq), which under the required uncertainty rule is treated as a high-impact kernel memory disclosure primitive rather than a pure non-leaking crash.\nI:H - The same path performs a wild write via sg_mark_end() on a bogus scatterlist address and may later kfree_sensitive() an invalid pointer, yielding kernel memory corruption; under uncertainty this is scored as high integrity impact.\nA:H - The commit-documented result is a kernel crash from dereferencing the invalid error pointer; sg_init_marker() on a NULL sgl with a huge truncated nents count causes a reliable oops/panic DoS."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:20.851Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/aa37f5fef78dd11cbf983269da2031e12625c56d"
},
{
"url": "https://git.kernel.org/stable/c/cad756733dc3985188983f3e2eb77e2927209099"
},
{
"url": "https://git.kernel.org/stable/c/a187883cc1dc784a4d32537f5d316f1b7b9ad76f"
},
{
"url": "https://git.kernel.org/stable/c/a1cc432cb0b0a1f74f98a0db3b94ca880c7947ac"
},
{
"url": "https://git.kernel.org/stable/c/61f28012e5650c619223decdb7970e0d3162e949"
}
],
"title": "smb/client: Fix error code in smb2_aead_req_alloc()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64598",
"datePublished": "2026-08-06T07:13:52.716Z",
"dateReserved": "2026-07-19T15:36:31.799Z",
"dateUpdated": "2026-08-17T04:58:20.851Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64409 (GCVE-0-2026-64409)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
Every once in a while we see a hung btmtksdio_flush() task:
INFO: task kworker/u17:0:189 blocked for more than 122 seconds.
__cancel_work_timer+0x3f4/0x460
cancel_work_sync+0x1c/0x2c
btmtksdio_flush+0x2c/0x40
hci_dev_open_sync+0x10c4/0x2190
[..]
It all boils down to incorrect time_is_before_jiffies() usage in
btmtksdio_txrx_work(). The btmtksdio_txrx_work() loop is expected
to be terminated if running for longer than 5*HZ. However the
timeout check is twisted: time_is_before_jiffies(old_jiffies + 5*HZ)
evaluates to true when old_jiffies + 5*HZ is in the past i.e. when a
timeout has occurred. Using OR with time_is_before_jiffies(txrx_timeout)
means that:
- before the 5-second timeout: the condition is `int_status || false`,
so it loops as long as there are pending interrupts.
- after the 5-second timeout: the condition becomes `int_status || true`,
which is always true.
When the loop becomes infinite btmtksdio_txrx_work() loop never
terminates and never releases the SDIO host.
Fix loop termination condition to actually enforce a 5*HZ timeout.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 26270bc189ea4b5a8356ec99561357fc87f00b32 Version: 26270bc189ea4b5a8356ec99561357fc87f00b32 Version: 26270bc189ea4b5a8356ec99561357fc87f00b32 Version: 26270bc189ea4b5a8356ec99561357fc87f00b32 Version: 26270bc189ea4b5a8356ec99561357fc87f00b32 Version: 26270bc189ea4b5a8356ec99561357fc87f00b32 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btmtksdio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f6682c23b6fac4780d297ae4662053d17e58fd52",
"status": "affected",
"version": "26270bc189ea4b5a8356ec99561357fc87f00b32",
"versionType": "git"
},
{
"lessThan": "466540e045d01fcacf383a5beb8a2dad2fc53a26",
"status": "affected",
"version": "26270bc189ea4b5a8356ec99561357fc87f00b32",
"versionType": "git"
},
{
"lessThan": "7b429d611060e87752e848851815537963726493",
"status": "affected",
"version": "26270bc189ea4b5a8356ec99561357fc87f00b32",
"versionType": "git"
},
{
"lessThan": "0039bdde36b23ccf1196635f1d52c5490481544d",
"status": "affected",
"version": "26270bc189ea4b5a8356ec99561357fc87f00b32",
"versionType": "git"
},
{
"lessThan": "0f0a83e26a9c7fd4b243c315ce07161d2496d83d",
"status": "affected",
"version": "26270bc189ea4b5a8356ec99561357fc87f00b32",
"versionType": "git"
},
{
"lessThan": "a257407e2bbbb099ed427719a50563f67fa366d8",
"status": "affected",
"version": "26270bc189ea4b5a8356ec99561357fc87f00b32",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btmtksdio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()\n\nEvery once in a while we see a hung btmtksdio_flush() task:\n\n INFO: task kworker/u17:0:189 blocked for more than 122 seconds.\n __cancel_work_timer+0x3f4/0x460\n cancel_work_sync+0x1c/0x2c\n btmtksdio_flush+0x2c/0x40\n hci_dev_open_sync+0x10c4/0x2190\n [..]\n\nIt all boils down to incorrect time_is_before_jiffies() usage in\nbtmtksdio_txrx_work(). The btmtksdio_txrx_work() loop is expected\nto be terminated if running for longer than 5*HZ. However the\ntimeout check is twisted: time_is_before_jiffies(old_jiffies + 5*HZ)\nevaluates to true when old_jiffies + 5*HZ is in the past i.e. when a\ntimeout has occurred. Using OR with time_is_before_jiffies(txrx_timeout)\nmeans that:\n- before the 5-second timeout: the condition is `int_status || false`,\n so it loops as long as there are pending interrupts.\n- after the 5-second timeout: the condition becomes `int_status || true`,\n which is always true.\n\nWhen the loop becomes infinite btmtksdio_txrx_work() loop never\nterminates and never releases the SDIO host.\n\nFix loop termination condition to actually enforce a 5*HZ timeout."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:07.875Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f6682c23b6fac4780d297ae4662053d17e58fd52"
},
{
"url": "https://git.kernel.org/stable/c/466540e045d01fcacf383a5beb8a2dad2fc53a26"
},
{
"url": "https://git.kernel.org/stable/c/7b429d611060e87752e848851815537963726493"
},
{
"url": "https://git.kernel.org/stable/c/0039bdde36b23ccf1196635f1d52c5490481544d"
},
{
"url": "https://git.kernel.org/stable/c/0f0a83e26a9c7fd4b243c315ce07161d2496d83d"
},
{
"url": "https://git.kernel.org/stable/c/a257407e2bbbb099ed427719a50563f67fa366d8"
}
],
"title": "Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64409",
"datePublished": "2026-07-25T08:50:50.604Z",
"dateReserved": "2026-07-19T15:36:31.786Z",
"dateUpdated": "2026-08-17T04:55:07.875Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74510 (GCVE-0-2026-74510)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: mgmt: fix UAF in pair command cancellation
The pairing completion and authentication failure callbacks look up the
pending MGMT_OP_PAIR_DEVICE command by walking hdev->mgmt_pending. The
lookup returned a command that was still linked on the shared pending list,
without keeping mgmt_pending_lock held for the later dereference and
removal.
A concurrent MGMT_OP_CANCEL_PAIR_DEVICE request can remove and free the
same pending command before the callback uses it. The reverse race is also
possible when cancel_pair_device() gets a command from pending_find() and a
callback removes it before the cancel path dereferences it. This can lead
to a use-after-free and a second list_del().
Make the pairing lookup helpers transfer ownership of the pending command
by removing it from hdev->mgmt_pending while holding mgmt_pending_lock.
The callbacks and cancel path then complete the command and free it
directly, so racing paths cannot find or free the same command again. Take
a temporary hci_conn reference in cancel_pair_device() because the command
completion drops the reference stored in the pending command.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "50af4280a587c9971b5388cbc438f1324e626b7b",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
},
{
"lessThan": "86ed4dd6548ccf277bc691bc912ca06e76b9d80c",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
},
{
"lessThan": "7c2a152a897cd1c184b2051484d4f74d803e7f4a",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
},
{
"lessThan": "c569def320aa8b1fde89227e2ea96606790fd86d",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
},
{
"lessThan": "51be7280980fddc90ebe874a69c2fe8ab02bb46a",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
},
{
"lessThan": "d0a7b48ad0921bd88effaee10bf970ab1d5d0ddd",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.39"
},
{
"lessThan": "2.6.39",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.39",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: mgmt: fix UAF in pair command cancellation\n\nThe pairing completion and authentication failure callbacks look up the\npending MGMT_OP_PAIR_DEVICE command by walking hdev-\u003emgmt_pending. The\nlookup returned a command that was still linked on the shared pending list,\nwithout keeping mgmt_pending_lock held for the later dereference and\nremoval.\n\nA concurrent MGMT_OP_CANCEL_PAIR_DEVICE request can remove and free the\nsame pending command before the callback uses it. The reverse race is also\npossible when cancel_pair_device() gets a command from pending_find() and a\ncallback removes it before the cancel path dereferences it. This can lead\nto a use-after-free and a second list_del().\n\nMake the pairing lookup helpers transfer ownership of the pending command\nby removing it from hdev-\u003emgmt_pending while holding mgmt_pending_lock.\nThe callbacks and cancel path then complete the command and free it\ndirectly, so racing paths cannot find or free the same command again. Take\na temporary hci_conn reference in cancel_pair_device() because the command\ncompletion drops the reference stored in the pending command."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is triggered through local AF_BLUETOOTH HCI_CHANNEL_CONTROL management commands (hci_sock_bind/sendmsg -\u003e hci_mgmt_cmd -\u003e pair_device/cancel_pair_device); remote Bluetooth peers cannot issue MGMT_OP_PAIR_DEVICE or MGMT_OP_CANCEL_PAIR_DEVICE over the air.\nAC:L - An attacker controls the race by concurrently issuing MGMT_OP_PAIR_DEVICE and MGMT_OP_CANCEL_PAIR_DEVICE from threads or sockets they own while pairing HCI callbacks fire, and can retry until cancel and completion/auth/SMP paths interleave on the same pending command.\nPR:L - pair_device and cancel_pair_device lack HCI_MGMT_UNTRUSTED and require HCI_SOCK_TRUSTED (CAP_NET_ADMIN at bind); per kernel CNA guidance CAP_NET_ADMIN reachable via unprivileged user namespaces (unshare -Urn) maps to PR:L, consistent with similar Bluetooth mgmt UAF scores.\nUI:N - No victim interaction is required beyond a powered Bluetooth controller; the attacker directly sends the conflicting PAIR_DEVICE and CANCEL_PAIR_DEVICE management commands that create the pending entry and race the unlocked find_pairing/pending_find paths against completion callbacks.\nS:U - Exploitation corrupts kernel Bluetooth MGMT heap objects (mgmt_pending_cmd) within the same host kernel security authority; this is standard local kernel memory corruption, not a VM, IOMMU, or cross-authority boundary escape.\nC:H - Use-after-free of mgmt_pending_cmd when find_pairing or pending_find returns a still-linked command without holding mgmt_pending_lock through later dereference and mgmt_pending_remove, enabling arbitrary kernel memory disclosure via slab reuse of the freed object.\nI:H - Slab UAF and double list_del on mgmt_pending_cmd during concurrent cancel_pair_device and pairing/auth/SMP completion callbacks provide attacker-influenced heap corruption primitives exploitable for arbitrary kernel writes and control-flow hijacking per kernel UAF guidance.\nA:H - Dereferencing or list_del on a freed mgmt_pending_cmd during the cancel versus callback race causes kernel oops or panic; repeated concurrent PAIR_DEVICE and CANCEL_PAIR_DEVICE commands during active pairing can reliably crash or hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:31.049Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/50af4280a587c9971b5388cbc438f1324e626b7b"
},
{
"url": "https://git.kernel.org/stable/c/86ed4dd6548ccf277bc691bc912ca06e76b9d80c"
},
{
"url": "https://git.kernel.org/stable/c/7c2a152a897cd1c184b2051484d4f74d803e7f4a"
},
{
"url": "https://git.kernel.org/stable/c/c569def320aa8b1fde89227e2ea96606790fd86d"
},
{
"url": "https://git.kernel.org/stable/c/51be7280980fddc90ebe874a69c2fe8ab02bb46a"
},
{
"url": "https://git.kernel.org/stable/c/d0a7b48ad0921bd88effaee10bf970ab1d5d0ddd"
}
],
"title": "Bluetooth: mgmt: fix UAF in pair command cancellation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74510",
"datePublished": "2026-08-15T12:27:32.503Z",
"dateReserved": "2026-08-15T05:44:03.909Z",
"dateUpdated": "2026-08-23T12:47:31.049Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68255 (GCVE-0-2026-68255)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/virtio: bound EDID block reads to the response buffer
virtio_get_edid_block() validates the read offset only against the
device-supplied resp->size field, never against the fixed-size resp->edid
array. The EDID block index is driven by the device-supplied extension
count, so a malicious virtio-gpu backend can advertise a large size
together with a high block count and read far past the array into adjacent
kernel memory, which is then surfaced in the parsed EDID (an out-of-bounds
read / info leak).
Also reject any read whose end exceeds the size of the edid array.
Conforming EDID responses stay within the array and are unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/virtio/virtgpu_vq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "65ce911f341ad8ff0c08922eff5bb6db75666eb0",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "64bedd2758eccbc74d39f7006a7ec16fa39dc901",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "3f506a85a905b080cadc029a1651a310479090a6",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "9fc2a017c5d597937e0c28b9a9669844aa796c42",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "2757e6e803092cf0aeaf4b735e16b5d3bdc705c5",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "35be0e2c6862abcd5e5f5445261f1fd910d4a9b4",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "375c1934ef0196d3b6d3a1eae3232bef8dae7bf7",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/virtio/virtgpu_vq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: bound EDID block reads to the response buffer\n\nvirtio_get_edid_block() validates the read offset only against the\ndevice-supplied resp-\u003esize field, never against the fixed-size resp-\u003eedid\narray. The EDID block index is driven by the device-supplied extension\ncount, so a malicious virtio-gpu backend can advertise a large size\ntogether with a high block count and read far past the array into adjacent\nkernel memory, which is then surfaced in the parsed EDID (an out-of-bounds\nread / info leak).\n\nAlso reject any read whose end exceeds the size of the edid array.\nConforming EDID responses stay within the array and are unaffected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The attacker is a malicious or compromised virtio-gpu backend (host/hypervisor device emulation or a vhost-user device process) supplying crafted EDID responses over the virtqueue; this is device-to-guest-kernel access, not remote network access.\nAC:L - The device fully controls resp-\u003esize, the EDID extension count and the timing of the read by raising VIRTIO_GPU_EVENT_DISPLAY config-change interrupts, so it can trigger the out-of-bounds read reliably and repeatedly with no conditions outside its control.\nPR:N - No guest credentials are needed at all: the vulnerable path runs in the virtio-gpu probe and the config-changed workqueue in kernel context, driven purely by device responses.\nUI:N - EDID re-reads are initiated automatically at probe and on device-raised display events; no guest user has to open, mount or interact with anything.\nS:U - The out-of-bounds read and the resulting disclosure both occur within the guest kernel\u0027s own security authority; no IOMMU, VM or sandbox boundary is crossed by the impact itself.\nC:H - Block indices up to 255 give start offsets of ~32 KB past the 1024-byte resp-\u003eedid array, reading far beyond the kmalloc\u0027d response object into adjacent kernel heap memory, which is then surfaced as parsed EDID via the connector blob property and world-readable sysfs edid file, and hex-dumped for bad blocks.\nI:N - Destination buffers in _drm_do_get_edid() are allocated from the block count, so the flaw is strictly an over-read of the response buffer with no out-of-bounds write or kernel data modification.\nA:H - The memcpy can walk tens of kilobytes past the slab object into unmapped or guarded memory, causing an oops/panic (and an immediate BUG under KASAN/hardened builds), and the device can repeat it at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:13.247Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/65ce911f341ad8ff0c08922eff5bb6db75666eb0"
},
{
"url": "https://git.kernel.org/stable/c/64bedd2758eccbc74d39f7006a7ec16fa39dc901"
},
{
"url": "https://git.kernel.org/stable/c/3f506a85a905b080cadc029a1651a310479090a6"
},
{
"url": "https://git.kernel.org/stable/c/9fc2a017c5d597937e0c28b9a9669844aa796c42"
},
{
"url": "https://git.kernel.org/stable/c/2757e6e803092cf0aeaf4b735e16b5d3bdc705c5"
},
{
"url": "https://git.kernel.org/stable/c/35be0e2c6862abcd5e5f5445261f1fd910d4a9b4"
},
{
"url": "https://git.kernel.org/stable/c/375c1934ef0196d3b6d3a1eae3232bef8dae7bf7"
},
{
"url": "https://git.kernel.org/stable/c/4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd"
}
],
"title": "drm/virtio: bound EDID block reads to the response buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68255",
"datePublished": "2026-08-10T12:01:24.835Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-23T12:46:13.247Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68326 (GCVE-0-2026-68326)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: bound uAP association event IEs to the event buffer
mwifiex_process_uap_event() handles EVENT_UAP_STA_ASSOC by exposing the
(re)association request IEs that the firmware copies into the event:
sinfo->assoc_req_ies = &event->data[len];
len = (u8 *)sinfo->assoc_req_ies - (u8 *)&event->frame_control;
sinfo->assoc_req_ies_len = le16_to_cpu(event->len) - (u16)len;
event->len is supplied by the device firmware and is never validated,
and the subtraction is unchecked. assoc_req_ies points into
adapter->event_body[MAX_EVENT_SIZE], a fixed-size array embedded in the
kmalloc()'d struct mwifiex_adapter.
On the ap_11n_enabled path mwifiex_set_sta_ht_cap() walks these IEs with
cfg80211_find_ie(), whose for_each_element() loop dereferences each
element header. A firmware-reported event->len larger than the bytes
actually received makes assoc_req_ies_len describe IEs that extend past
event_body, so the walk reads out of the adapter slab object, a
slab-out-of-bounds read (KASAN: slab-out-of-bounds in cfg80211_find_ie).
An event->len smaller than the header instead makes the int subtraction
negative, which wraps to a huge size_t when stored in assoc_req_ies_len.
The same length is handed to cfg80211_new_sta(), so a more modest
over-claim can also copy stale event_body bytes into the
NL80211_CMD_NEW_STATION notification.
A malicious or malfunctioning mwifiex device (USB/SDIO/PCIe) can deliver
such an event while the interface is in AP/uAP mode.
Validate event->len before use: reject a length that underflows the
header or that would place the IEs outside the event_body[] buffer the
event was copied into. event->len here is struct mwifiex_assoc_event.len,
a payload field internal to this event, not the transport frame length,
so it is validated in this handler rather than at the generic
MWIFIEX_TYPE_EVENT receive path, which only sees the event cause and the
transport frame length. The bound is against event_body[MAX_EVENT_SIZE]
rather than the actually-received length because the transports store the
event differently (USB and SDIO leave the 4-byte event header in
event_skb, PCIe strips it via skb_pull), whereas event_body is the single
fixed buffer all of them copy the event into. This is the event-path
analogue of the receive-path bounds checks added in commit 119585281617
("wifi: mwifiex: Fix OOB and integer underflow when rx packets").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/uap_event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a616616b938f7922a93e79bef16b4643c57c0922",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "1ae00b6d9a6c82eb3de151d9b04ed59e06cc100f",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "e7e93d3e8c240bdb70c41e79d169d74dfb442843",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "a3f47d7c75ddad1a14621a309286f9fae3cba191",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "ad26c75ae25749313248f06510ebe43b5bf4adcc",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "d21464d93f8ba464dc3d7b4b31c6e0adcd9f659c",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "b6766d7ea43edf5de9d5a572bc58b631d09efe4b",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "f0858bfc7d3cab411a447b88e3ef970e575032c9",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/uap_event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: bound uAP association event IEs to the event buffer\n\nmwifiex_process_uap_event() handles EVENT_UAP_STA_ASSOC by exposing the\n(re)association request IEs that the firmware copies into the event:\n\n\tsinfo-\u003eassoc_req_ies = \u0026event-\u003edata[len];\n\tlen = (u8 *)sinfo-\u003eassoc_req_ies - (u8 *)\u0026event-\u003eframe_control;\n\tsinfo-\u003eassoc_req_ies_len = le16_to_cpu(event-\u003elen) - (u16)len;\n\nevent-\u003elen is supplied by the device firmware and is never validated,\nand the subtraction is unchecked. assoc_req_ies points into\nadapter-\u003eevent_body[MAX_EVENT_SIZE], a fixed-size array embedded in the\nkmalloc()\u0027d struct mwifiex_adapter.\n\nOn the ap_11n_enabled path mwifiex_set_sta_ht_cap() walks these IEs with\ncfg80211_find_ie(), whose for_each_element() loop dereferences each\nelement header. A firmware-reported event-\u003elen larger than the bytes\nactually received makes assoc_req_ies_len describe IEs that extend past\nevent_body, so the walk reads out of the adapter slab object, a\nslab-out-of-bounds read (KASAN: slab-out-of-bounds in cfg80211_find_ie).\nAn event-\u003elen smaller than the header instead makes the int subtraction\nnegative, which wraps to a huge size_t when stored in assoc_req_ies_len.\nThe same length is handed to cfg80211_new_sta(), so a more modest\nover-claim can also copy stale event_body bytes into the\nNL80211_CMD_NEW_STATION notification.\n\nA malicious or malfunctioning mwifiex device (USB/SDIO/PCIe) can deliver\nsuch an event while the interface is in AP/uAP mode.\n\nValidate event-\u003elen before use: reject a length that underflows the\nheader or that would place the IEs outside the event_body[] buffer the\nevent was copied into. event-\u003elen here is struct mwifiex_assoc_event.len,\na payload field internal to this event, not the transport frame length,\nso it is validated in this handler rather than at the generic\nMWIFIEX_TYPE_EVENT receive path, which only sees the event cause and the\ntransport frame length. The bound is against event_body[MAX_EVENT_SIZE]\nrather than the actually-received length because the transports store the\nevent differently (USB and SDIO leave the 4-byte event header in\nevent_skb, PCIe strips it via skb_pull), whereas event_body is the single\nfixed buffer all of them copy the event into. This is the event-path\nanalogue of the receive-path bounds checks added in commit 119585281617\n(\"wifi: mwifiex: Fix OOB and integer underflow when rx packets\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The event payload is the firmware\u0027s rendering of an over-the-air (re)association request received by the mwifiex uAP interface, with event-\u003elen being the TLV length covering that frame, so the triggering input comes from a station within 802.11 radio range. This matches the Adjacent treatment used for other frame/event-driven mwifiex defects (CVE-2024-46755, CVE-2023-53226).\nAC:L - No race or attacker-uncontrollable state is involved: the attacker simply sends a crafted/oversized (re)association request to the AP, and the handler parses the resulting EVENT_UAP_STA_ASSOC unconditionally. The only precondition, an mwifiex interface in AP/uAP mode with ap_11n_enabled, is the normal steady state for tethering, Chromebook SoftAP and embedded AP deployments.\nPR:N - EVENT_UAP_STA_ASSOC is generated at association time, before the WPA/EAPOL handshake, so the attacker needs no credentials on or accepted association with the target host. No host user account or capability is involved anywhere on the path.\nUI:N - The event is consumed autonomously by mwifiex_process_uap_event() in the driver\u0027s main work handler as soon as the firmware delivers it; no local user or administrator action is required beyond the AP already running.\nS:U - The out-of-bounds read, the underflowed length and the resulting corruption are all confined to the host kernel\u0027s own security authority within the mwifiex/cfg80211 code; no hypervisor, IOMMU or sandbox boundary is crossed.\nC:H - An over-claimed event-\u003elen makes assoc_req_ies_len describe memory past adapter-\u003eevent_body[MAX_EVENT_SIZE], producing a slab-out-of-bounds read in cfg80211_find_ie() and, worse, causing nla_put() to copy up to tens of kilobytes of adjacent kernel slab memory into the NL80211_CMD_NEW_STATION notification delivered to userspace \u2014 an unbounded kernel heap disclosure, not a few stray bytes.\nI:H - An event-\u003elen below the header makes the int subtraction negative and wrap in size_t; that value reaches nla_put(), where nla_total_size() of the negative length evaluates to 0 and passes the tailroom check, so __nla_put()\u0027s memcpy() runs with the negative length widened to a huge size_t \u2014 an unbounded out-of-bounds write past the netlink skb. Driver 11n/AMSDU state is also set from out-of-bounds data.\nA:H - The commit documents a reproducible KASAN slab-out-of-bounds in cfg80211_find_ie, and the underflow path drives a memcpy of a near-2^64 length that guarantees an immediate kernel panic. The condition can be re-triggered at will by repeating the association attempt."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:21.015Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a616616b938f7922a93e79bef16b4643c57c0922"
},
{
"url": "https://git.kernel.org/stable/c/1ae00b6d9a6c82eb3de151d9b04ed59e06cc100f"
},
{
"url": "https://git.kernel.org/stable/c/e7e93d3e8c240bdb70c41e79d169d74dfb442843"
},
{
"url": "https://git.kernel.org/stable/c/a3f47d7c75ddad1a14621a309286f9fae3cba191"
},
{
"url": "https://git.kernel.org/stable/c/ad26c75ae25749313248f06510ebe43b5bf4adcc"
},
{
"url": "https://git.kernel.org/stable/c/d21464d93f8ba464dc3d7b4b31c6e0adcd9f659c"
},
{
"url": "https://git.kernel.org/stable/c/b6766d7ea43edf5de9d5a572bc58b631d09efe4b"
},
{
"url": "https://git.kernel.org/stable/c/f0858bfc7d3cab411a447b88e3ef970e575032c9"
}
],
"title": "wifi: mwifiex: bound uAP association event IEs to the event buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68326",
"datePublished": "2026-08-10T12:03:02.372Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:21.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68082 (GCVE-0-2026-68082)
Vulnerability from cvelistv5
Published
2026-08-08 09:17
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: fix two unsafe bare decodes in decode_lockers()
decode_lockers() in cls_lock_client.c contains two bare decode operations
that allow a malicious or compromised OSD to trigger slab-out-of-bounds
reads:
1. ceph_decode_32(p) at the num_lockers field has no preceding bounds
check. ceph_start_decoding() accepts struct_len=0 as valid -- the
internal ceph_decode_need(p, end, 0, bad) always passes -- so when an
OSD sends struct_len=0, ceph_start_decoding() returns success with
p == end. The immediately following bare ceph_decode_32(p) then reads
4 bytes past the validated buffer boundary. The garbage value is
passed directly to kzalloc_objs() as the locker count.
The sibling function decode_watchers() in osd_client.c already uses
ceph_decode_32_safe() after its own ceph_start_decoding() call.
decode_lockers() was the only site using the bare variant.
2. ceph_decode_8(p) after the decode_locker() loop has no preceding
bounds check. If an OSD crafts num_lockers such that the loop
advances p exactly to end, the subsequent bare ceph_decode_8(p) reads
one byte past the validated buffer boundary. The result is passed
directly into *type, which is used as a lock type discriminator by
callers, giving an OSD-controlled one-byte OOB read with direct
influence over the lock type field.
Fix both by replacing bare operations with their safe variants:
ceph_decode_32(p) -> ceph_decode_32_safe(p, end, *num_lockers,
err_inval)
ceph_decode_8(p) -> ceph_decode_8_safe(p, end, *type,
err_free_lockers)
The goto targets differ intentionally:
err_inval: is a new label returning -EINVAL directly. It is used for
the pre-allocation failure path where *lockers is not yet allocated
and must not be passed to ceph_free_lockers().
err_free_lockers: is the existing label. It is used for the
post-allocation failure path where *lockers is allocated and must
be freed.
ret is set to -EINVAL before ceph_decode_8_safe() so that
err_free_lockers returns the correct error code on bounds violation.
Without this, err_free_lockers would return a stale ret value (0 from
the successful decode_locker() loop), silently swallowing the error.
-EINVAL is correct for both failure paths. The data received from the
OSD is structurally malformed. -ENOMEM would misrepresent the failure
class to callers and to stable@ backporters triaging error paths.
Attacker model: a malicious or compromised OSD in a multi-tenant Ceph
deployment can trigger this against any kernel client that issues the
lock.get_info class method (e.g. during RBD exclusive lock acquisition).
[ idryomov: trim changelog, formatting ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/cls_lock_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c8ade01170a27d8ede0d761c255268af81e417f8",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "001835c599899ef1bd3506a815110a6374451554",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "7c422364acd93d7da1dfc27d6b54635a269653a1",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "02430f6f729b297e803d0605871f0a670b4eafd6",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "57ba829804fe6d34bbac3b826c4b15c1caa54862",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "89df5d71f83f8e2781286798fd8ae5e42cf5f1a7",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "a54be593d0b749161b08a1e56189b2cb9114267a",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "a109a556115271ca7896dcda7b4b7e45e156c227",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/cls_lock_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix two unsafe bare decodes in decode_lockers()\n\ndecode_lockers() in cls_lock_client.c contains two bare decode operations\nthat allow a malicious or compromised OSD to trigger slab-out-of-bounds\nreads:\n\n1. ceph_decode_32(p) at the num_lockers field has no preceding bounds\n check. ceph_start_decoding() accepts struct_len=0 as valid -- the\n internal ceph_decode_need(p, end, 0, bad) always passes -- so when an\n OSD sends struct_len=0, ceph_start_decoding() returns success with\n p == end. The immediately following bare ceph_decode_32(p) then reads\n 4 bytes past the validated buffer boundary. The garbage value is\n passed directly to kzalloc_objs() as the locker count.\n\n The sibling function decode_watchers() in osd_client.c already uses\n ceph_decode_32_safe() after its own ceph_start_decoding() call.\n decode_lockers() was the only site using the bare variant.\n\n2. ceph_decode_8(p) after the decode_locker() loop has no preceding\n bounds check. If an OSD crafts num_lockers such that the loop\n advances p exactly to end, the subsequent bare ceph_decode_8(p) reads\n one byte past the validated buffer boundary. The result is passed\n directly into *type, which is used as a lock type discriminator by\n callers, giving an OSD-controlled one-byte OOB read with direct\n influence over the lock type field.\n\nFix both by replacing bare operations with their safe variants:\n ceph_decode_32(p) -\u003e ceph_decode_32_safe(p, end, *num_lockers,\n err_inval)\n ceph_decode_8(p) -\u003e ceph_decode_8_safe(p, end, *type,\n err_free_lockers)\n\nThe goto targets differ intentionally:\n err_inval: is a new label returning -EINVAL directly. It is used for\n the pre-allocation failure path where *lockers is not yet allocated\n and must not be passed to ceph_free_lockers().\n\n err_free_lockers: is the existing label. It is used for the\n post-allocation failure path where *lockers is allocated and must\n be freed.\n\nret is set to -EINVAL before ceph_decode_8_safe() so that\nerr_free_lockers returns the correct error code on bounds violation.\nWithout this, err_free_lockers would return a stale ret value (0 from\nthe successful decode_locker() loop), silently swallowing the error.\n\n-EINVAL is correct for both failure paths. The data received from the\nOSD is structurally malformed. -ENOMEM would misrepresent the failure\nclass to callers and to stable@ backporters triaging error paths.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment can trigger this against any kernel client that issues the\nlock.get_info class method (e.g. during RBD exclusive lock acquisition).\n\n[ idryomov: trim changelog, formatting ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached when libceph decodes a crafted MOSDOpReply for the lock.get_info class method received over the Ceph messenger TCP session from a compromised or malicious OSD; no local syscall or ioctl is required on the victim.\nAC:L - A malicious OSD can deterministically send struct_len=0 or craft num_lockers so the decode pointer reaches end, triggering both bare decodes on every attempt without races, special memory layout, or rare kernel configuration.\nPR:N - The attacker acts as the remote Ceph OSD peer and needs no account or privileges on the victim Linux host; any kernel RBD client connected to a multi-tenant or attacker-controlled cluster is exposed during automatic exclusive-lock operations.\nUI:N - Once an RBD image is mapped, ceph_cls_lock_info() is invoked automatically during exclusive-lock acquisition and object-map lock recovery; no further victim user or administrator action is required at exploit time.\nS:U - The slab out-of-bounds reads and any resulting kernel memory corruption occur entirely within the victim host kernel running the Ceph client, without crossing VM, container, or IOMMU security boundaries.\nC:H - Bare ceph_decode_32/8 past the validated reply boundary perform slab out-of-bounds reads of adjacent kernel memory; the leaked u32 can drive kzalloc_objs() sizing and the OOB u8 directly controls the lock-type field consumed by RBD lock logic.\nI:H - Attacker-influenced out-of-bounds values feed heap allocation sizing and lock-type discrimination in kernel lock-handling paths, providing memory-corruption primitives in a privileged parser that can be leveraged beyond simple information disclosure.\nA:H - Slab out-of-bounds reads can trigger KASAN faults or kernel oops on instrumented builds, and attacker-controlled locker counts can force very large kzalloc attempts causing severe memory pressure, OOM conditions, and loss of availability on RBD client hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:46.891Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c8ade01170a27d8ede0d761c255268af81e417f8"
},
{
"url": "https://git.kernel.org/stable/c/001835c599899ef1bd3506a815110a6374451554"
},
{
"url": "https://git.kernel.org/stable/c/7c422364acd93d7da1dfc27d6b54635a269653a1"
},
{
"url": "https://git.kernel.org/stable/c/02430f6f729b297e803d0605871f0a670b4eafd6"
},
{
"url": "https://git.kernel.org/stable/c/57ba829804fe6d34bbac3b826c4b15c1caa54862"
},
{
"url": "https://git.kernel.org/stable/c/89df5d71f83f8e2781286798fd8ae5e42cf5f1a7"
},
{
"url": "https://git.kernel.org/stable/c/a54be593d0b749161b08a1e56189b2cb9114267a"
},
{
"url": "https://git.kernel.org/stable/c/a109a556115271ca7896dcda7b4b7e45e156c227"
}
],
"title": "libceph: fix two unsafe bare decodes in decode_lockers()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68082",
"datePublished": "2026-08-08T09:17:45.394Z",
"dateReserved": "2026-07-30T09:28:09.367Z",
"dateUpdated": "2026-08-23T12:45:46.891Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72251 (GCVE-0-2026-72251)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-17 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_nat_sip: reload possible stale data pointer
quoting sashiko:
------------------------------------------------------------------------
[..] noticed a potential memory bug and header corruption involving the
SIP NAT helper.
In net/netfilter/nf_nat_sip.c:nf_nat_sip():
if (skb_ensure_writable(skb, skb->len)) {
nf_ct_helper_log(skb, ct, "cannot mangle packet");
return NF_DROP;
}
uh = (void *)skb->data + protoff;
uh->dest = ct_sip_info->forced_dport;
if (!nf_nat_mangle_udp_packet(skb, ct, ctinfo, protoff,
0, 0, NULL, 0)) {
If a cloned or fragmented SKB is reallocated by skb_ensure_writable(), the
old data buffer is freed. However, nf_nat_sip() fails to update *dptr to
point to the new buffer.
It also appears to use nf_nat_mangle_udp_packet() on what could be a TCP
packet, which would overwrite the sequence number with a checksum update.
------------------------------------------------------------------------
nf_conntrack_sip linerizes skbs, hence no fragmented skb can be seen.
But clones are possible, so rebuild dptr.
Disable nf_nat_mangle_udp_packet() branch for TCP streams.
It doesn't look like this can ever happen, else we should have received
bug reports about this, so just check the conntrack is UDP and drop
otherwise.
The calling conntrack_sip set ->forced_dport for SIP_HDR_VIA_UDP messages,
so I don't think this is ever expected to be true for a TCP stream.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7266507d89991fa1e989283e4e032c6d9357fe26 Version: 7266507d89991fa1e989283e4e032c6d9357fe26 Version: 7266507d89991fa1e989283e4e032c6d9357fe26 Version: 7266507d89991fa1e989283e4e032c6d9357fe26 Version: 7266507d89991fa1e989283e4e032c6d9357fe26 Version: 7266507d89991fa1e989283e4e032c6d9357fe26 Version: 7266507d89991fa1e989283e4e032c6d9357fe26 Version: 7266507d89991fa1e989283e4e032c6d9357fe26 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_nat_sip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bded21a4bf9bf86a79148be735723a97ca9a7532",
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"versionType": "git"
},
{
"lessThan": "dc11f26685aa850f237226f0f463647aea58ab7c",
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"versionType": "git"
},
{
"lessThan": "e38143c9b477f2968024c47c647dd4456a40aff1",
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"versionType": "git"
},
{
"lessThan": "57e4e29644ec054d7021d296407e7ddd844afea2",
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"versionType": "git"
},
{
"lessThan": "eae9c6ccb5af69c713a65f8ae219f5c1aa32cd17",
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"versionType": "git"
},
{
"lessThan": "2bcf2c5052fb5e73e255140ab43f056aef409c27",
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"versionType": "git"
},
{
"lessThan": "0e76e3e886cc9ee027337d5ad39cb96f57b7bdc7",
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"versionType": "git"
},
{
"lessThan": "77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68",
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_nat_sip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"lessThan": "3.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_nat_sip: reload possible stale data pointer\n\nquoting sashiko:\n ------------------------------------------------------------------------\n [..] noticed a potential memory bug and header corruption involving the\n SIP NAT helper.\n\n In net/netfilter/nf_nat_sip.c:nf_nat_sip():\n\tif (skb_ensure_writable(skb, skb-\u003elen)) {\n\t\tnf_ct_helper_log(skb, ct, \"cannot mangle packet\");\n\t\treturn NF_DROP;\n\t}\n\tuh = (void *)skb-\u003edata + protoff;\n\tuh-\u003edest = ct_sip_info-\u003eforced_dport;\n\tif (!nf_nat_mangle_udp_packet(skb, ct, ctinfo, protoff,\n\t\t\t\t 0, 0, NULL, 0)) {\n\n If a cloned or fragmented SKB is reallocated by skb_ensure_writable(), the\n old data buffer is freed. However, nf_nat_sip() fails to update *dptr to\n point to the new buffer.\n\n It also appears to use nf_nat_mangle_udp_packet() on what could be a TCP\n packet, which would overwrite the sequence number with a checksum update.\n ------------------------------------------------------------------------\n\nnf_conntrack_sip linerizes skbs, hence no fragmented skb can be seen.\nBut clones are possible, so rebuild dptr.\n\nDisable nf_nat_mangle_udp_packet() branch for TCP streams.\nIt doesn\u0027t look like this can ever happen, else we should have received\nbug reports about this, so just check the conntrack is UDP and drop\notherwise.\n\nThe calling conntrack_sip set -\u003eforced_dport for SIP_HDR_VIA_UDP messages,\nso I don\u0027t think this is ever expected to be true for a TCP stream."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit in nf_nat_sip() from sip_help_udp/tcp() during nf_confirm() on POST_ROUTING/LOCAL_IN while processing attacker-supplied SIP/UDP or SIP/TCP packets traversing a netfilter NAT gateway, so exploitation is via remote network traffic rather than local syscalls or physical access.\nAC:L - Once nf_conntrack_sip and nf_nat_sip are active on a NATed SIP flow, a remote peer can set forced_dport with a crafted Via header and drive the reply-path skb_ensure_writable() reallocation on cloned skbs without races or rare layout luck.\nPR:N - Exploitation needs no privileges on the victim kernel; a remote SIP endpoint only has to send malicious SIP through an already-configured SIP conntrack/NAT helper, with no authentication or local access to the firewall or router.\nUI:N - No victim user action is required beyond normal automated packet forwarding; the SIP helper parses and NAT-rewrites attacker-supplied SIP data in softirq during connection-tracking confirmation without opening files, clicking links, or mounting filesystems.\nS:U - Impact stays within kernel netfilter/conntrack memory on the same security authority (for example a NAT firewall, SBC, or VoIP gateway). This is standard kernel memory corruption, not a VM escape, sandbox breakout, or cross-tenant boundary violation.\nC:H - skb_ensure_writable() can free the old linear buffer while *dptr still points into it; sip_help_tcp() then continues parsing with that stale pointer, giving a use-after-free read of freed skb data and enabling disclosure of adjacent kernel heap contents.\nI:H - The stale dptr UAF and, on TCP flows, mistaken nf_nat_mangle_udp_packet() header rewriting corrupt kernel packet-buffer memory; such heap corruption is exploitable with grooming for arbitrary writes, control-flow hijacking, and kernel code execution.\nA:H - Use-after-free and mis-mangled L4 headers during softirq SIP NAT processing can trigger kernel oops/panic or reliably drop or corrupt in-flight VoIP signaling, causing high availability impact on internet-facing NAT/SBC systems handling SIP."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:42:03.339Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bded21a4bf9bf86a79148be735723a97ca9a7532"
},
{
"url": "https://git.kernel.org/stable/c/dc11f26685aa850f237226f0f463647aea58ab7c"
},
{
"url": "https://git.kernel.org/stable/c/e38143c9b477f2968024c47c647dd4456a40aff1"
},
{
"url": "https://git.kernel.org/stable/c/57e4e29644ec054d7021d296407e7ddd844afea2"
},
{
"url": "https://git.kernel.org/stable/c/eae9c6ccb5af69c713a65f8ae219f5c1aa32cd17"
},
{
"url": "https://git.kernel.org/stable/c/2bcf2c5052fb5e73e255140ab43f056aef409c27"
},
{
"url": "https://git.kernel.org/stable/c/0e76e3e886cc9ee027337d5ad39cb96f57b7bdc7"
},
{
"url": "https://git.kernel.org/stable/c/77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68"
}
],
"title": "netfilter: nf_nat_sip: reload possible stale data pointer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72251",
"datePublished": "2026-08-15T05:54:39.983Z",
"dateReserved": "2026-08-09T03:40:39.915Z",
"dateUpdated": "2026-08-17T05:42:03.339Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64225 (GCVE-0-2026-64225)
Vulnerability from cvelistv5
Published
2026-07-24 15:23
Modified
2026-07-24 15:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: CGX: add bounds check to cgx_speed_mbps index
cgx_speed_mbps has 13 elements but RESP_LINKSTAT_SPEED can yield values
0-15. If it returns a value >= 13, this causes an out-of-bounds array
access. Add a bounds check and default to speed 0 if the index is out of
range.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 61071a871ea6eb2125ece91c1a0dbb124a318c8a Version: 61071a871ea6eb2125ece91c1a0dbb124a318c8a Version: 61071a871ea6eb2125ece91c1a0dbb124a318c8a Version: 61071a871ea6eb2125ece91c1a0dbb124a318c8a Version: 61071a871ea6eb2125ece91c1a0dbb124a318c8a Version: 61071a871ea6eb2125ece91c1a0dbb124a318c8a Version: 61071a871ea6eb2125ece91c1a0dbb124a318c8a Version: 61071a871ea6eb2125ece91c1a0dbb124a318c8a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/af/cgx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "94071141f00bc414e8f8f7f5db3b5143d535299f",
"status": "affected",
"version": "61071a871ea6eb2125ece91c1a0dbb124a318c8a",
"versionType": "git"
},
{
"lessThan": "985b5e38ac4f4d5ff03c8bfd8484353b440a1579",
"status": "affected",
"version": "61071a871ea6eb2125ece91c1a0dbb124a318c8a",
"versionType": "git"
},
{
"lessThan": "93d3dc81098cd60fb74d434ba7985ddfd9de5acb",
"status": "affected",
"version": "61071a871ea6eb2125ece91c1a0dbb124a318c8a",
"versionType": "git"
},
{
"lessThan": "e043017ac429caee73bd30c5a725659f1a3a4568",
"status": "affected",
"version": "61071a871ea6eb2125ece91c1a0dbb124a318c8a",
"versionType": "git"
},
{
"lessThan": "8201bf45cc7c1c1a09290c4db8ab1e19801f8fec",
"status": "affected",
"version": "61071a871ea6eb2125ece91c1a0dbb124a318c8a",
"versionType": "git"
},
{
"lessThan": "47a4cf2229be379cf88f92e32e1240337cd6273f",
"status": "affected",
"version": "61071a871ea6eb2125ece91c1a0dbb124a318c8a",
"versionType": "git"
},
{
"lessThan": "2c3d26b4a62454945ba9ef3af3174d3e40e7afef",
"status": "affected",
"version": "61071a871ea6eb2125ece91c1a0dbb124a318c8a",
"versionType": "git"
},
{
"lessThan": "c0bf0a4f3f1f5f57aa83e1400ba4f56f0abfd542",
"status": "affected",
"version": "61071a871ea6eb2125ece91c1a0dbb124a318c8a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/af/cgx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: CGX: add bounds check to cgx_speed_mbps index\n\ncgx_speed_mbps\u00a0has 13 elements but RESP_LINKSTAT_SPEED can yield values\n0-15. If it returns a value \u003e= 13, this causes an out-of-bounds array\naccess. Add a bounds check and default to speed 0 if the index is out of\nrange."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-24T15:23:09.785Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/94071141f00bc414e8f8f7f5db3b5143d535299f"
},
{
"url": "https://git.kernel.org/stable/c/985b5e38ac4f4d5ff03c8bfd8484353b440a1579"
},
{
"url": "https://git.kernel.org/stable/c/93d3dc81098cd60fb74d434ba7985ddfd9de5acb"
},
{
"url": "https://git.kernel.org/stable/c/e043017ac429caee73bd30c5a725659f1a3a4568"
},
{
"url": "https://git.kernel.org/stable/c/8201bf45cc7c1c1a09290c4db8ab1e19801f8fec"
},
{
"url": "https://git.kernel.org/stable/c/47a4cf2229be379cf88f92e32e1240337cd6273f"
},
{
"url": "https://git.kernel.org/stable/c/2c3d26b4a62454945ba9ef3af3174d3e40e7afef"
},
{
"url": "https://git.kernel.org/stable/c/c0bf0a4f3f1f5f57aa83e1400ba4f56f0abfd542"
}
],
"title": "octeontx2-af: CGX: add bounds check to cgx_speed_mbps index",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64225",
"datePublished": "2026-07-24T15:23:09.785Z",
"dateReserved": "2026-07-19T15:36:31.771Z",
"dateUpdated": "2026-07-24T15:23:09.785Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53263 (GCVE-0-2026-53263)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-06-25 08:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
6lowpan: fix off-by-one in multicast context address compression
The second memcpy in lowpan_iphc_mcast_ctx_addr_compress() uses
&data[1] as destination and &ipaddr->s6_addr[11] as source, but
both should be offset by one: &data[2] and &ipaddr->s6_addr[12]
respectively.
This off-by-one has two consequences:
1. data[1] is overwritten with s6_addr[11], corrupting the RIID
field in the compressed multicast address
2. data[5] is never written, so uninitialized kernel stack memory
is transmitted over the network via lowpan_push_hc_data(),
leaking kernel stack contents
The correct inline data layout must match what the decompression
function lowpan_uncompress_multicast_ctx_daddr() expects:
data[0..1] = s6_addr[1..2] (flags/scope + RIID)
data[2..5] = s6_addr[12..15] (group ID)
Also zero-initialize the data array as a defensive measure against
similar bugs in the future.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5609c185f24dffca5f6a9c127106869da150be03 Version: 5609c185f24dffca5f6a9c127106869da150be03 Version: 5609c185f24dffca5f6a9c127106869da150be03 Version: 5609c185f24dffca5f6a9c127106869da150be03 Version: 5609c185f24dffca5f6a9c127106869da150be03 Version: 5609c185f24dffca5f6a9c127106869da150be03 Version: 5609c185f24dffca5f6a9c127106869da150be03 Version: 5609c185f24dffca5f6a9c127106869da150be03 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/6lowpan/iphc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f24a58c72a45f4c109f3557a760cc4b60b7a6037",
"status": "affected",
"version": "5609c185f24dffca5f6a9c127106869da150be03",
"versionType": "git"
},
{
"lessThan": "da8cbb64b47e9066b40af0de170901caf17b768c",
"status": "affected",
"version": "5609c185f24dffca5f6a9c127106869da150be03",
"versionType": "git"
},
{
"lessThan": "4485d79617520d84ba5a14515e2b5136007d6deb",
"status": "affected",
"version": "5609c185f24dffca5f6a9c127106869da150be03",
"versionType": "git"
},
{
"lessThan": "06ce6fc106b16dec9b535950db626261be865e5b",
"status": "affected",
"version": "5609c185f24dffca5f6a9c127106869da150be03",
"versionType": "git"
},
{
"lessThan": "dcb1bec1c32ee5c3878354e087cf5dbee2b7c7af",
"status": "affected",
"version": "5609c185f24dffca5f6a9c127106869da150be03",
"versionType": "git"
},
{
"lessThan": "c32f30ef5e66adbfa102348e2e8a23776eb007cb",
"status": "affected",
"version": "5609c185f24dffca5f6a9c127106869da150be03",
"versionType": "git"
},
{
"lessThan": "da8808463882c3f3c357b072e25053c2121f1419",
"status": "affected",
"version": "5609c185f24dffca5f6a9c127106869da150be03",
"versionType": "git"
},
{
"lessThan": "2a58899d11009bffc7b4b32a571858f381121837",
"status": "affected",
"version": "5609c185f24dffca5f6a9c127106869da150be03",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/6lowpan/iphc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\n6lowpan: fix off-by-one in multicast context address compression\n\nThe second memcpy in lowpan_iphc_mcast_ctx_addr_compress() uses\n\u0026data[1] as destination and \u0026ipaddr-\u003es6_addr[11] as source, but\nboth should be offset by one: \u0026data[2] and \u0026ipaddr-\u003es6_addr[12]\nrespectively.\n\nThis off-by-one has two consequences:\n1. data[1] is overwritten with s6_addr[11], corrupting the RIID\n field in the compressed multicast address\n2. data[5] is never written, so uninitialized kernel stack memory\n is transmitted over the network via lowpan_push_hc_data(),\n leaking kernel stack contents\n\nThe correct inline data layout must match what the decompression\nfunction lowpan_uncompress_multicast_ctx_daddr() expects:\n data[0..1] = s6_addr[1..2] (flags/scope + RIID)\n data[2..5] = s6_addr[12..15] (group ID)\n\nAlso zero-initialize the data array as a defensive measure against\nsimilar bugs in the future."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-25T08:39:51.215Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f24a58c72a45f4c109f3557a760cc4b60b7a6037"
},
{
"url": "https://git.kernel.org/stable/c/da8cbb64b47e9066b40af0de170901caf17b768c"
},
{
"url": "https://git.kernel.org/stable/c/4485d79617520d84ba5a14515e2b5136007d6deb"
},
{
"url": "https://git.kernel.org/stable/c/06ce6fc106b16dec9b535950db626261be865e5b"
},
{
"url": "https://git.kernel.org/stable/c/dcb1bec1c32ee5c3878354e087cf5dbee2b7c7af"
},
{
"url": "https://git.kernel.org/stable/c/c32f30ef5e66adbfa102348e2e8a23776eb007cb"
},
{
"url": "https://git.kernel.org/stable/c/da8808463882c3f3c357b072e25053c2121f1419"
},
{
"url": "https://git.kernel.org/stable/c/2a58899d11009bffc7b4b32a571858f381121837"
}
],
"title": "6lowpan: fix off-by-one in multicast context address compression",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53263",
"datePublished": "2026-06-25T08:39:51.215Z",
"dateReserved": "2026-06-09T07:44:35.394Z",
"dateUpdated": "2026-06-25T08:39:51.215Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46319 (GCVE-0-2026-46319)
Vulnerability from cvelistv5
Published
2026-06-09 12:11
Modified
2026-08-05 12:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_ct: Only release RCU read lock after ct_ft
When looking up a flow table in act_ct in tcf_ct_flow_table_get(),
rhashtable_lookup_fast() internally opens and closes an RCU read critical
section before returning ct_ft.
The tcf_ct_flow_table_cleanup_work() can complete before refcount_inc_not_zero()
is invoked on the returned ct_ft resulting in a UAF on the already freed ct_ft
object. This vulnerability can lead to privilege escalation.
Analysis from zdi-disclosures@trendmicro.com:
When initializing act_ct, tcf_ct_init() is called, which internally triggers
tcf_ct_flow_table_get().
static int tcf_ct_flow_table_get(struct net *net, struct tcf_ct_params *params)
{
struct zones_ht_key key = { .net = net, .zone = params->zone };
struct tcf_ct_flow_table *ct_ft;
int err = -ENOMEM;
mutex_lock(&zones_mutex);
ct_ft = rhashtable_lookup_fast(&zones_ht, &key, zones_params); // [1]
if (ct_ft && refcount_inc_not_zero(&ct_ft->ref)) // [2]
goto out_unlock;
...
}
static __always_inline void *rhashtable_lookup_fast(
struct rhashtable *ht, const void *key,
const struct rhashtable_params params)
{
void *obj;
rcu_read_lock();
obj = rhashtable_lookup(ht, key, params);
rcu_read_unlock();
return obj;
}
At [1], rhashtable_lookup_fast() looks up and returns the corresponding ct_ft
from zones_ht . The lookup is performed within an RCU read critical section
through rcu_read_lock() / rcu_read_unlock(), which prevents the object from
being freed. However, at the point of function return, rcu_read_unlock() has
already been called, and there is nothing preventing ct_ft from being freed
before reaching refcount_inc_not_zero(&ct_ft->ref) at [2]. This interval becomes
the race window, during which ct_ft can be freed.
Free Process:
tcf_ct_flow_table_put() is executed through the path tcf_ct_cleanup() call_rcu()
tcf_ct_params_free_rcu() tcf_ct_params_free() tcf_ct_flow_table_put().
static void tcf_ct_flow_table_put(struct tcf_ct_flow_table *ct_ft)
{
if (refcount_dec_and_test(&ct_ft->ref)) {
rhashtable_remove_fast(&zones_ht, &ct_ft->node, zones_params);
INIT_RCU_WORK(&ct_ft->rwork, tcf_ct_flow_table_cleanup_work); // [3]
queue_rcu_work(act_ct_wq, &ct_ft->rwork);
}
}
At [3], tcf_ct_flow_table_cleanup_work() is scheduled as RCU work
static void tcf_ct_flow_table_cleanup_work(struct work_struct *work)
{
struct tcf_ct_flow_table *ct_ft;
struct flow_block *block;
ct_ft = container_of(to_rcu_work(work), struct tcf_ct_flow_table,
rwork);
nf_flow_table_free(&ct_ft->nf_ft);
block = &ct_ft->nf_ft.flow_block;
down_write(&ct_ft->nf_ft.flow_block_lock);
WARN_ON(!list_empty(&block->cb_list));
up_write(&ct_ft->nf_ft.flow_block_lock);
kfree(ct_ft); // [4]
module_put(THIS_MODULE);
}
tcf_ct_flow_table_cleanup_work() frees ct_ft at [4]. When this function executes
between [1] and [2], UAF occurs.
This race condition has a very short race window, making it generally
difficult to trigger. Therefore, to trigger the vulnerability an msleep(100) was
inserted after[1]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 138470a9b2cc2e26e6018300394afc3858a54e6a Version: 138470a9b2cc2e26e6018300394afc3858a54e6a Version: 138470a9b2cc2e26e6018300394afc3858a54e6a Version: 138470a9b2cc2e26e6018300394afc3858a54e6a Version: 138470a9b2cc2e26e6018300394afc3858a54e6a Version: 138470a9b2cc2e26e6018300394afc3858a54e6a Version: 138470a9b2cc2e26e6018300394afc3858a54e6a Version: 138470a9b2cc2e26e6018300394afc3858a54e6a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/act_ct.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ece578ca61e572df96cfc80456357ebfae0b4b9e",
"status": "affected",
"version": "138470a9b2cc2e26e6018300394afc3858a54e6a",
"versionType": "git"
},
{
"lessThan": "a2e0c045c87aa252eb61412e67dd91f2c2b19f81",
"status": "affected",
"version": "138470a9b2cc2e26e6018300394afc3858a54e6a",
"versionType": "git"
},
{
"lessThan": "67c9ecc9f2575273ed1323e312881fc98ac83d6d",
"status": "affected",
"version": "138470a9b2cc2e26e6018300394afc3858a54e6a",
"versionType": "git"
},
{
"lessThan": "f23424a0ddadb494d4bd57056a7ca703312d3a7b",
"status": "affected",
"version": "138470a9b2cc2e26e6018300394afc3858a54e6a",
"versionType": "git"
},
{
"lessThan": "17dfb67cb399b660105d9a8c6100851c0d0cdc70",
"status": "affected",
"version": "138470a9b2cc2e26e6018300394afc3858a54e6a",
"versionType": "git"
},
{
"lessThan": "4c727c6967a41b37efe0f26332ca9ec5b74785a3",
"status": "affected",
"version": "138470a9b2cc2e26e6018300394afc3858a54e6a",
"versionType": "git"
},
{
"lessThan": "3e20e1b3058e0b94638e7b931c138e840e266724",
"status": "affected",
"version": "138470a9b2cc2e26e6018300394afc3858a54e6a",
"versionType": "git"
},
{
"lessThan": "f462dca0c8415bf0058d0ffa476354c4476d0f09",
"status": "affected",
"version": "138470a9b2cc2e26e6018300394afc3858a54e6a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/act_ct.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: Only release RCU read lock after ct_ft\n\nWhen looking up a flow table in act_ct in tcf_ct_flow_table_get(),\nrhashtable_lookup_fast() internally opens and closes an RCU read critical\nsection before returning ct_ft.\nThe tcf_ct_flow_table_cleanup_work() can complete before refcount_inc_not_zero()\nis invoked on the returned ct_ft resulting in a UAF on the already freed ct_ft\nobject. This vulnerability can lead to privilege escalation.\n\nAnalysis from zdi-disclosures@trendmicro.com:\nWhen initializing act_ct, tcf_ct_init() is called, which internally triggers\ntcf_ct_flow_table_get().\n\nstatic int tcf_ct_flow_table_get(struct net *net, struct tcf_ct_params *params)\n\n{\n struct zones_ht_key key = { .net = net, .zone = params-\u003ezone };\n struct tcf_ct_flow_table *ct_ft;\n int err = -ENOMEM;\n\n mutex_lock(\u0026zones_mutex);\n ct_ft = rhashtable_lookup_fast(\u0026zones_ht, \u0026key, zones_params); // [1]\n if (ct_ft \u0026\u0026 refcount_inc_not_zero(\u0026ct_ft-\u003eref)) // [2]\n goto out_unlock;\n ...\n}\n\nstatic __always_inline void *rhashtable_lookup_fast(\n struct rhashtable *ht, const void *key,\n const struct rhashtable_params params)\n{\n void *obj;\n\n rcu_read_lock();\n obj = rhashtable_lookup(ht, key, params);\n rcu_read_unlock();\n\n return obj;\n}\n\nAt [1], rhashtable_lookup_fast() looks up and returns the corresponding ct_ft\nfrom zones_ht . The lookup is performed within an RCU read critical section\nthrough rcu_read_lock() / rcu_read_unlock(), which prevents the object from\nbeing freed. However, at the point of function return, rcu_read_unlock() has\nalready been called, and there is nothing preventing ct_ft from being freed\nbefore reaching refcount_inc_not_zero(\u0026ct_ft-\u003eref) at [2]. This interval becomes\nthe race window, during which ct_ft can be freed.\n\nFree Process:\n\ntcf_ct_flow_table_put() is executed through the path tcf_ct_cleanup() call_rcu()\ntcf_ct_params_free_rcu() tcf_ct_params_free() tcf_ct_flow_table_put().\n\nstatic void tcf_ct_flow_table_put(struct tcf_ct_flow_table *ct_ft)\n{\n if (refcount_dec_and_test(\u0026ct_ft-\u003eref)) {\n rhashtable_remove_fast(\u0026zones_ht, \u0026ct_ft-\u003enode, zones_params);\n INIT_RCU_WORK(\u0026ct_ft-\u003erwork, tcf_ct_flow_table_cleanup_work); // [3]\n queue_rcu_work(act_ct_wq, \u0026ct_ft-\u003erwork);\n }\n}\n\nAt [3], tcf_ct_flow_table_cleanup_work() is scheduled as RCU work\n\nstatic void tcf_ct_flow_table_cleanup_work(struct work_struct *work)\n\n{\n struct tcf_ct_flow_table *ct_ft;\n struct flow_block *block;\n\n ct_ft = container_of(to_rcu_work(work), struct tcf_ct_flow_table,\n rwork);\n nf_flow_table_free(\u0026ct_ft-\u003enf_ft);\n block = \u0026ct_ft-\u003enf_ft.flow_block;\n down_write(\u0026ct_ft-\u003enf_ft.flow_block_lock);\n WARN_ON(!list_empty(\u0026block-\u003ecb_list));\n up_write(\u0026ct_ft-\u003enf_ft.flow_block_lock);\n kfree(ct_ft); // [4]\n\n module_put(THIS_MODULE);\n}\n\ntcf_ct_flow_table_cleanup_work() frees ct_ft at [4]. When this function executes\nbetween [1] and [2], UAF occurs.\n\nThis race condition has a very short race window, making it generally\ndifficult to trigger. Therefore, to trigger the vulnerability an msleep(100) was\ninserted after[1]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is triggered only during act_ct TC action configuration via RTM_NEWACTION/RTM_DELACTION or RTM_NEWTFILTER netlink messages, not by processing remote network packets. Per kernel guidance, tc/netlink qdisc paths are Local attack vector.\nAC:L - The race is between flow-table lookup and refcount increment during concurrent create/delete/replace of ct actions, and an attacker with CAP_NET_ADMIN controls both sides by issuing parallel netlink operations on actions sharing the same zone. UAF races where the attacker controls timing are scored AC:L.\nPR:L - All non-GET rtnetlink TC operations require CAP_NET_ADMIN, checked in rtnetlink_rcv_msg() and tc_ctl_action(). CAP_NET_ADMIN is obtainable by an unprivileged user inside a user+network namespace (unshare -Urn), which per kernel guidance is PR:L not PR:H.\nUI:N - Exploitation requires only the attacker\u0027s own netlink configuration traffic; no victim user action such as opening a file or mounting a filesystem is needed.\nS:U - A successful exploit yields kernel-level privilege escalation within the same kernel security domain. This is standard local kernel compromise, not a cross-boundary escape such as VM guest-to-host or IOMMU bypass.\nC:H - The bug is a heap use-after-free on struct tcf_ct_flow_table during refcount_inc_not_zero() on memory that tcf_ct_flow_table_cleanup_work() may have already kfree()\u0027d. UAF on kernel heap objects enables arbitrary memory read primitives and is scored C:H.\nI:H - Freed tcf_ct_flow_table slabs can be reallocated and corrupted via the dangling refcount operation, providing heap manipulation primitives that ZDI and the fix commit describe as leading to privilege escalation. Memory corruption UAF is scored I:H.\nA:H - Hitting the UAF during refcount manipulation on freed memory can cause kernel oops/panic or deliberate denial of service, and UAF bugs inherently threaten availability even when exploitation is attempted. Any kernel crash or UAF is scored A:H."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:31:14.097Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ece578ca61e572df96cfc80456357ebfae0b4b9e"
},
{
"url": "https://git.kernel.org/stable/c/a2e0c045c87aa252eb61412e67dd91f2c2b19f81"
},
{
"url": "https://git.kernel.org/stable/c/67c9ecc9f2575273ed1323e312881fc98ac83d6d"
},
{
"url": "https://git.kernel.org/stable/c/f23424a0ddadb494d4bd57056a7ca703312d3a7b"
},
{
"url": "https://git.kernel.org/stable/c/17dfb67cb399b660105d9a8c6100851c0d0cdc70"
},
{
"url": "https://git.kernel.org/stable/c/4c727c6967a41b37efe0f26332ca9ec5b74785a3"
},
{
"url": "https://git.kernel.org/stable/c/3e20e1b3058e0b94638e7b931c138e840e266724"
},
{
"url": "https://git.kernel.org/stable/c/f462dca0c8415bf0058d0ffa476354c4476d0f09"
}
],
"title": "net/sched: act_ct: Only release RCU read lock after ct_ft",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46319",
"datePublished": "2026-06-09T12:11:12.128Z",
"dateReserved": "2026-05-13T15:03:33.112Z",
"dateUpdated": "2026-08-05T12:31:14.097Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68271 (GCVE-0-2026-68271)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix reversed error cleanup order in ucopy functions
nouveau_uvmm_vm_bind_ucopy() and nouveau_exec_ucopy() place their error
cleanup labels in allocation order rather than reverse allocation order.
On a u_memcpya() failure for in_sync.s, the goto to err_free_ops (or
err_free_pushs) frees the first allocation and then falls through to
err_free_ins, which calls u_free() on args->in_sync.s.
Since args->in_sync.s still holds the ERR_PTR returned by the failed
u_memcpya(), and ERR_PTR values are not caught by ZERO_OR_NULL_PTR(),
kvfree() proceeds to dereference it, which can result in a kernel oops.
A failure for out_sync.s instead jumps to err_free_ins and skips freeing
the first allocation, leading to a memory leak.
Fix by swapping the cleanup label order so resources are freed in the
correct reverse allocation sequence.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/nouveau/nouveau_exec.c",
"drivers/gpu/drm/nouveau/nouveau_uvmm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2473ac314387a5def7244eb6d6a345934ed140bf",
"status": "affected",
"version": "b88baab828713ce0b49b185444b2ee83bed373a8",
"versionType": "git"
},
{
"lessThan": "e15c25c7972d38a9f6bf8c3f7f29179a67263eba",
"status": "affected",
"version": "b88baab828713ce0b49b185444b2ee83bed373a8",
"versionType": "git"
},
{
"lessThan": "4e109faa9ea2b6c04cc5a99e76db3126575a59d1",
"status": "affected",
"version": "b88baab828713ce0b49b185444b2ee83bed373a8",
"versionType": "git"
},
{
"lessThan": "ebbaf64d2635d1e78196c067fa8fa582a7dc17f7",
"status": "affected",
"version": "b88baab828713ce0b49b185444b2ee83bed373a8",
"versionType": "git"
},
{
"lessThan": "ab99ead646b1b833ecd57fe577a2816f2e848167",
"status": "affected",
"version": "b88baab828713ce0b49b185444b2ee83bed373a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/nouveau/nouveau_exec.c",
"drivers/gpu/drm/nouveau/nouveau_uvmm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: fix reversed error cleanup order in ucopy functions\n\nnouveau_uvmm_vm_bind_ucopy() and nouveau_exec_ucopy() place their error\ncleanup labels in allocation order rather than reverse allocation order.\nOn a u_memcpya() failure for in_sync.s, the goto to err_free_ops (or\nerr_free_pushs) frees the first allocation and then falls through to\nerr_free_ins, which calls u_free() on args-\u003ein_sync.s.\n\nSince args-\u003ein_sync.s still holds the ERR_PTR returned by the failed\nu_memcpya(), and ERR_PTR values are not caught by ZERO_OR_NULL_PTR(),\nkvfree() proceeds to dereference it, which can result in a kernel oops.\nA failure for out_sync.s instead jumps to err_free_ins and skips freeing\nthe first allocation, leading to a memory leak.\n\nFix by swapping the cleanup label order so resources are freed in the\ncorrect reverse allocation sequence."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:04.681Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2473ac314387a5def7244eb6d6a345934ed140bf"
},
{
"url": "https://git.kernel.org/stable/c/e15c25c7972d38a9f6bf8c3f7f29179a67263eba"
},
{
"url": "https://git.kernel.org/stable/c/4e109faa9ea2b6c04cc5a99e76db3126575a59d1"
},
{
"url": "https://git.kernel.org/stable/c/ebbaf64d2635d1e78196c067fa8fa582a7dc17f7"
},
{
"url": "https://git.kernel.org/stable/c/ab99ead646b1b833ecd57fe577a2816f2e848167"
}
],
"title": "drm/nouveau: fix reversed error cleanup order in ucopy functions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68271",
"datePublished": "2026-08-10T12:01:46.534Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:02:04.681Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68391 (GCVE-0-2026-68391)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
Dereferencing RCU-protected pointers outside critical sections is
invalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also
needs to hold refcount to avoid UAF.
Take appropriate locks for hci_conn lookups, and take refcount for
hci_conn pointers stored in mgmt_pending_cmd so that the pointer stays
valid.
When accessing conn->state, ensure hdev->lock is held to avoid data
race.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b56f2ecafc08f372bf0529f9c4f3f429cb1702dc",
"status": "affected",
"version": "7b445e220db9a2c58be5d09bbbd322abf1b1452a",
"versionType": "git"
},
{
"lessThan": "f915e74b6f18293d1d69a2a3305ef321ff7c0172",
"status": "affected",
"version": "7b445e220db9a2c58be5d09bbbd322abf1b1452a",
"versionType": "git"
},
{
"lessThan": "d5b3b484b62bb0f4542e7622789d28871626cdf0",
"status": "affected",
"version": "7b445e220db9a2c58be5d09bbbd322abf1b1452a",
"versionType": "git"
},
{
"lessThan": "ecdcb55ea1c01dda074406f38058785a69526734",
"status": "affected",
"version": "7b445e220db9a2c58be5d09bbbd322abf1b1452a",
"versionType": "git"
},
{
"lessThan": "da55f570191d5d72f10c607a7043b947eb05ea46",
"status": "affected",
"version": "7b445e220db9a2c58be5d09bbbd322abf1b1452a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds\n\nDereferencing RCU-protected pointers outside critical sections is\ninvalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also\nneeds to hold refcount to avoid UAF.\n\nTake appropriate locks for hci_conn lookups, and take refcount for\nhci_conn pointers stored in mgmt_pending_cmd so that the pointer stays\nvalid.\n\nWhen accessing conn-\u003estate, ensure hdev-\u003elock is held to avoid data\nrace."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Both sides of the race are local: the vulnerable path is entered only by writing MGMT_OP_GET_CONN_INFO/MGMT_OP_GET_CLOCK_INFO to an AF_BLUETOOTH/BTPROTO_HCI socket bound to HCI_CHANNEL_CONTROL, and the free is driven by a local disconnect/device-teardown. A remote or adjacent Bluetooth peer cannot inject mgmt commands, so the vector is local even though the subsystem is Bluetooth.\nAC:L - The attacker owns both sides of the race: one thread loops GET_CONN_INFO/GET_CLOCK_INFO, whose sync callback blocks in __hci_cmd_sync waiting on the controller for up to HCI_CMD_TIMEOUT, while another issues MGMT_OP_DISCONNECT or HCIDEVDOWN to free the hci_conn inside that wide window; with an emulated controller the response timing is fully controlled, and the sequence can be retried indefinitely.\nPR:L - The opcodes lack HCI_MGMT_UNTRUSTED so they need a trusted mgmt socket (CAP_NET_ADMIN), which kernel CNA practice for the Bluetooth mgmt interface treats as low privilege: it is a delegable capability held by the non-root bluetoothd service account and Android\u0027s sandboxed Bluetooth process rather than full init-namespace root.\nUI:N - The attacker performs every step itself \u2014 queueing the mgmt command and tearing down the connection or the HCI index \u2014 with no victim action, pairing, or user-initiated Bluetooth operation required.\nS:U - The use-after-free and the resulting heap corruption stay entirely within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - get_conn_info_complete()/get_clock_info_complete() read rssi, tx_power, max_tx_power, clock and clock_accuracy from a freed hci_conn and return them to userspace over the mgmt socket; hci_conn comes from a general-purpose kmalloc cache, so grooming the reclaimed slab turns this into a repeatable kernel-memory disclosure oracle.\nI:H - The dangling cmd-\u003euser_data points at a freed, sprayable struct-device-embedded object that can be reclaimed with attacker-shaped data and is later put/released, and the unlocked lookup also propagates a stale conn-\u003ehandle into hci_read_rssi_sync/hci_read_clock_sync so the host acts on a handle that may have been reused by another link \u2014 sufficient for controlled corruption after heap grooming.\nA:H - Dereferencing the freed hci_conn in the hci_cmd_sync completion callback is a slab use-after-free that produces a KASAN splat and can oops or panic the kernel when the slab has been returned to the page allocator, and it can be re-triggered in a loop for sustained denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:39.043Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b56f2ecafc08f372bf0529f9c4f3f429cb1702dc"
},
{
"url": "https://git.kernel.org/stable/c/f915e74b6f18293d1d69a2a3305ef321ff7c0172"
},
{
"url": "https://git.kernel.org/stable/c/d5b3b484b62bb0f4542e7622789d28871626cdf0"
},
{
"url": "https://git.kernel.org/stable/c/ecdcb55ea1c01dda074406f38058785a69526734"
},
{
"url": "https://git.kernel.org/stable/c/da55f570191d5d72f10c607a7043b947eb05ea46"
}
],
"title": "Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68391",
"datePublished": "2026-08-10T12:04:10.564Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-17T05:04:39.043Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43110 (GCVE-0-2026-43110)
Vulnerability from cvelistv5
Published
2026-05-06 07:40
Modified
2026-08-05 12:25
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: validate bsscfg indices in IF events
brcmf_fweh_handle_if_event() validates the firmware-provided interface
index before it touches drvr->iflist[], but it still uses the raw
bsscfgidx field as an array index without a matching range check.
Reject IF events whose bsscfg index does not fit in drvr->iflist[]
before indexing the interface array.
[add missing wifi prefix]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2880b86859967af710c72f7d34fb421a86a71e22 Version: 2880b86859967af710c72f7d34fb421a86a71e22 Version: 2880b86859967af710c72f7d34fb421a86a71e22 Version: 2880b86859967af710c72f7d34fb421a86a71e22 Version: 2880b86859967af710c72f7d34fb421a86a71e22 Version: 2880b86859967af710c72f7d34fb421a86a71e22 Version: 2880b86859967af710c72f7d34fb421a86a71e22 Version: 2880b86859967af710c72f7d34fb421a86a71e22 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/fweh.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b329fbcf075949a038045d8e9b86ae3d5bbd8a54",
"status": "affected",
"version": "2880b86859967af710c72f7d34fb421a86a71e22",
"versionType": "git"
},
{
"lessThan": "2ae3ccb78c0a9ef5ee3d80d02ab319ac1d5af734",
"status": "affected",
"version": "2880b86859967af710c72f7d34fb421a86a71e22",
"versionType": "git"
},
{
"lessThan": "9c81bcc2c695e0082012a2a3d36a0eefaa51579c",
"status": "affected",
"version": "2880b86859967af710c72f7d34fb421a86a71e22",
"versionType": "git"
},
{
"lessThan": "3ec7437e9d11374105c2c4e47ae671537729d7e6",
"status": "affected",
"version": "2880b86859967af710c72f7d34fb421a86a71e22",
"versionType": "git"
},
{
"lessThan": "9fca68c2512a362cad258e4df12a307bb2ee4b8e",
"status": "affected",
"version": "2880b86859967af710c72f7d34fb421a86a71e22",
"versionType": "git"
},
{
"lessThan": "1ae1e1caa428844e481231f6dbe9b4f475f1d52d",
"status": "affected",
"version": "2880b86859967af710c72f7d34fb421a86a71e22",
"versionType": "git"
},
{
"lessThan": "b427c2b05222db36d32ee141609de6128e9091bb",
"status": "affected",
"version": "2880b86859967af710c72f7d34fb421a86a71e22",
"versionType": "git"
},
{
"lessThan": "304950a467d83678bd0b0f46331882e2ac23b12d",
"status": "affected",
"version": "2880b86859967af710c72f7d34fb421a86a71e22",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/fweh.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"lessThan": "3.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.136",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.83",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.24",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.136",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.83",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.24",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.14",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "3.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: validate bsscfg indices in IF events\n\nbrcmf_fweh_handle_if_event() validates the firmware-provided interface\nindex before it touches drvr-\u003eiflist[], but it still uses the raw\nbsscfgidx field as an array index without a matching range check.\n\nReject IF events whose bsscfg index does not fit in drvr-\u003eiflist[]\nbefore indexing the interface array.\n\n[add missing wifi prefix]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable brcmfmac firmware-event path is reachable from WiFi-adjacent attack scenarios involving crafted Broadcom event frames or malicious event injection through the wireless device path. It does not require routable IP network access, but does require proximity to the affected WiFi interface.\nAC:L - Once the event path is reachable, the attacker-controlled IF-event payload directly supplies the unchecked bsscfgidx and no race or hard-to-satisfy heap condition is required to trigger the out-of-bounds access. The higher-severity choice is appropriate because the malformed index is consumed deterministically.\nPR:N - In the highest reasonable WiFi-adjacent scenario, the attacker sends crafted wireless traffic/event data without any local account or administrative privilege on the victim. Local nl80211 interface creation has admin gating, but that is not the highest-severity reachable scenario for this driver class.\nUI:N - No victim action is required once the affected wireless interface is active in a reachable deployment. The vulnerable worker processes queued firmware events asynchronously without prompting the user.\nS:U - The corruption occurs within the host kernel driver and impacts the same kernel security authority. This is not a VM escape, IOMMU bypass, or cross-authority boundary change.\nC:H - The unchecked bsscfgidx indexes beyond drvr-\u003eiflist[], and subsequent paths can treat adjacent kernel memory as interface pointers. As kernel memory corruption, this can reasonably be leveraged for high-impact information disclosure.\nI:H - The IF_ADD path can write a newly allocated brcmf_if pointer through an out-of-bounds drvr-\u003eiflist[] slot, corrupting adjacent kernel state. This is an out-of-bounds write primitive and is scored as high integrity impact.\nA:H - Malformed indices can cause invalid pointer dereferences, bogus interface removal/reset operations, or broader kernel memory corruption. These conditions can crash or destabilize the kernel, so availability impact is high."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:25:57.498Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b329fbcf075949a038045d8e9b86ae3d5bbd8a54"
},
{
"url": "https://git.kernel.org/stable/c/2ae3ccb78c0a9ef5ee3d80d02ab319ac1d5af734"
},
{
"url": "https://git.kernel.org/stable/c/9c81bcc2c695e0082012a2a3d36a0eefaa51579c"
},
{
"url": "https://git.kernel.org/stable/c/3ec7437e9d11374105c2c4e47ae671537729d7e6"
},
{
"url": "https://git.kernel.org/stable/c/9fca68c2512a362cad258e4df12a307bb2ee4b8e"
},
{
"url": "https://git.kernel.org/stable/c/1ae1e1caa428844e481231f6dbe9b4f475f1d52d"
},
{
"url": "https://git.kernel.org/stable/c/b427c2b05222db36d32ee141609de6128e9091bb"
},
{
"url": "https://git.kernel.org/stable/c/304950a467d83678bd0b0f46331882e2ac23b12d"
}
],
"title": "wifi: brcmfmac: validate bsscfg indices in IF events",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43110",
"datePublished": "2026-05-06T07:40:37.250Z",
"dateReserved": "2026-05-01T14:12:55.986Z",
"dateUpdated": "2026-08-05T12:25:57.498Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80529 (GCVE-0-2026-80529)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-26 14:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfs: don't swallow dquot recovery verification errors
xlog_recover_dquot_commit_pass2() validates the recovered dquot with
xfs_dqblk_verify() and, on failure, sets error = -EFSCORRUPTED and jumps
to out_release. But out_release unconditionally returns 0, so the
corruption error is discarded: the caller xlog_recover_items_pass2()
sees success, log recovery proceeds as if the dquot were valid, and the
corrupt quota buffer can be written back to disk.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7880b1f0adef4d363f42d6bb42aab3211291351b Version: 3581868f51a2edb027a898988b5b5a4ba379ee55 Version: 9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02 Version: 9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02 Version: 9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02 Version: 9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02 Version: 6.1.128 ≤ Version: 6.6.17 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_dquot_item_recover.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e506e127fcb4e2bad1045805f1740b395eea9618",
"status": "affected",
"version": "7880b1f0adef4d363f42d6bb42aab3211291351b",
"versionType": "git"
},
{
"lessThan": "5b756fbb60b5d26063f46a11a3c7daa7eb616d79",
"status": "affected",
"version": "3581868f51a2edb027a898988b5b5a4ba379ee55",
"versionType": "git"
},
{
"lessThan": "a233b3362a3c7bf23f5143b4ef4b17ec337fcb4d",
"status": "affected",
"version": "9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02",
"versionType": "git"
},
{
"lessThan": "38a4dbe588bd028a07a77dc5cee62ee3ce21e87d",
"status": "affected",
"version": "9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02",
"versionType": "git"
},
{
"lessThan": "36a31b12540c0a0a3b77a01fda86de646f2961fb",
"status": "affected",
"version": "9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02",
"versionType": "git"
},
{
"lessThan": "e2b4a856085e9bd939bde2dee0d08b1d41babde9",
"status": "affected",
"version": "9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.128",
"versionType": "semver"
},
{
"lessThan": "6.6.153",
"status": "affected",
"version": "6.6.17",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_dquot_item_recover.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.128",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "6.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don\u0027t swallow dquot recovery verification errors\n\nxlog_recover_dquot_commit_pass2() validates the recovered dquot with\nxfs_dqblk_verify() and, on failure, sets error = -EFSCORRUPTED and jumps\nto out_release. But out_release unconditionally returns 0, so the\ncorruption error is discarded: the caller xlog_recover_items_pass2()\nsees success, log recovery proceeds as if the dquot were valid, and the\ncorrupt quota buffer can be written back to disk."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T14:37:07.390Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e506e127fcb4e2bad1045805f1740b395eea9618"
},
{
"url": "https://git.kernel.org/stable/c/5b756fbb60b5d26063f46a11a3c7daa7eb616d79"
},
{
"url": "https://git.kernel.org/stable/c/a233b3362a3c7bf23f5143b4ef4b17ec337fcb4d"
},
{
"url": "https://git.kernel.org/stable/c/38a4dbe588bd028a07a77dc5cee62ee3ce21e87d"
},
{
"url": "https://git.kernel.org/stable/c/36a31b12540c0a0a3b77a01fda86de646f2961fb"
},
{
"url": "https://git.kernel.org/stable/c/e2b4a856085e9bd939bde2dee0d08b1d41babde9"
}
],
"title": "xfs: don\u0027t swallow dquot recovery verification errors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80529",
"datePublished": "2026-08-26T14:37:07.390Z",
"dateReserved": "2026-08-26T14:34:25.764Z",
"dateUpdated": "2026-08-26T14:37:07.390Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-31392 (GCVE-0-2026-31392)
Vulnerability from cvelistv5
Published
2026-04-03 15:15
Modified
2026-08-05 12:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix krb5 mount with username option
Customer reported that some of their krb5 mounts were failing against
a single server as the client was trying to mount the shares with
wrong credentials. It turned out the client was reusing SMB session
from first mount to try mounting the other shares, even though a
different username= option had been specified to the other mounts.
By using username mount option along with sec=krb5 to search for
principals from keytab is supported by cifs.upcall(8) since
cifs-utils-4.8. So fix this by matching username mount option in
match_session() even with Kerberos.
For example, the second mount below should fail with -ENOKEY as there
is no 'foobar' principal in keytab (/etc/krb5.keytab). The client
ends up reusing SMB session from first mount to perform the second
one, which is wrong.
```
$ ktutil
ktutil: add_entry -password -p testuser -k 1 -e aes256-cts
Password for testuser@ZELDA.TEST:
ktutil: write_kt /etc/krb5.keytab
ktutil: quit
$ klist -ke
Keytab name: FILE:/etc/krb5.keytab
KVNO Principal
---- ----------------------------------------------------------------
1 testuser@ZELDA.TEST (aes256-cts-hmac-sha1-96)
$ mount.cifs //w22-root2/scratch /mnt/1 -o sec=krb5,username=testuser
$ mount.cifs //w22-root2/scratch /mnt/2 -o sec=krb5,username=foobar
$ mount -t cifs | grep -Po 'username=\K\w+'
testuser
testuser
```
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4ff67b720c02c36e54d55b88c2931879b7db1cd2 Version: 4ff67b720c02c36e54d55b88c2931879b7db1cd2 Version: 4ff67b720c02c36e54d55b88c2931879b7db1cd2 Version: 4ff67b720c02c36e54d55b88c2931879b7db1cd2 Version: 4ff67b720c02c36e54d55b88c2931879b7db1cd2 Version: 4ff67b720c02c36e54d55b88c2931879b7db1cd2 Version: 223c7f082d2836ac719b3b228bdcfab35e5e5330 Version: 88720224330a655ab6268e20109b65b11cfd7f6a Version: 2.6.32.44 ≤ Version: 2.6.34.12 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/connect.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fd4547830720647d4af02ee50f883c4b1cca06e4",
"status": "affected",
"version": "4ff67b720c02c36e54d55b88c2931879b7db1cd2",
"versionType": "git"
},
{
"lessThan": "9229709ec8bf85ae7ca53aeee9aa14814cdc1bd2",
"status": "affected",
"version": "4ff67b720c02c36e54d55b88c2931879b7db1cd2",
"versionType": "git"
},
{
"lessThan": "d33cbf0bf8979d779900da9be2505d68d9d8da25",
"status": "affected",
"version": "4ff67b720c02c36e54d55b88c2931879b7db1cd2",
"versionType": "git"
},
{
"lessThan": "9ee803bfdba0cf739038dbdabdd4c02582c8f2b2",
"status": "affected",
"version": "4ff67b720c02c36e54d55b88c2931879b7db1cd2",
"versionType": "git"
},
{
"lessThan": "6e9ff1eb7feedcf46ff2d0503759960ab58e7775",
"status": "affected",
"version": "4ff67b720c02c36e54d55b88c2931879b7db1cd2",
"versionType": "git"
},
{
"lessThan": "12b4c5d98cd7ca46d5035a57bcd995df614c14e1",
"status": "affected",
"version": "4ff67b720c02c36e54d55b88c2931879b7db1cd2",
"versionType": "git"
},
{
"status": "affected",
"version": "223c7f082d2836ac719b3b228bdcfab35e5e5330",
"versionType": "git"
},
{
"status": "affected",
"version": "88720224330a655ab6268e20109b65b11cfd7f6a",
"versionType": "git"
},
{
"lessThan": "2.6.33",
"status": "affected",
"version": "2.6.32.44",
"versionType": "semver"
},
{
"lessThan": "2.6.35",
"status": "affected",
"version": "2.6.34.12",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/connect.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.36"
},
{
"lessThan": "2.6.36",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.20",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.167",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.20",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.10",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.6.32.44",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.6.34.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix krb5 mount with username option\n\nCustomer reported that some of their krb5 mounts were failing against\na single server as the client was trying to mount the shares with\nwrong credentials. It turned out the client was reusing SMB session\nfrom first mount to try mounting the other shares, even though a\ndifferent username= option had been specified to the other mounts.\n\nBy using username mount option along with sec=krb5 to search for\nprincipals from keytab is supported by cifs.upcall(8) since\ncifs-utils-4.8. So fix this by matching username mount option in\nmatch_session() even with Kerberos.\n\nFor example, the second mount below should fail with -ENOKEY as there\nis no \u0027foobar\u0027 principal in keytab (/etc/krb5.keytab). The client\nends up reusing SMB session from first mount to perform the second\none, which is wrong.\n\n```\n$ ktutil\nktutil: add_entry -password -p testuser -k 1 -e aes256-cts\nPassword for testuser@ZELDA.TEST:\nktutil: write_kt /etc/krb5.keytab\nktutil: quit\n$ klist -ke\nKeytab name: FILE:/etc/krb5.keytab\nKVNO Principal\n ---- ----------------------------------------------------------------\n 1 testuser@ZELDA.TEST (aes256-cts-hmac-sha1-96)\n$ mount.cifs //w22-root2/scratch /mnt/1 -o sec=krb5,username=testuser\n$ mount.cifs //w22-root2/scratch /mnt/2 -o sec=krb5,username=foobar\n$ mount -t cifs | grep -Po \u0027username=\\K\\w+\u0027\ntestuser\ntestuser\n```"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached through local CIFS/SMB mount setup, via the mount/fs_context path into SMB client session matching. It is not directly triggerable by remote SMB packets alone.\nAC:L - Once Kerberos CIFS mounts are in use, the bug is triggered reliably by mounting the same server with sec=krb5 and a different username option while the cred_uid matches an existing session. No race or attacker-uncontrolled timing is required.\nPR:H - CIFS and SMB3 filesystems are not marked FS_USERNS_MOUNT, so final mount creation requires real CAP_SYS_ADMIN in the initial namespace. Unprivileged user namespaces do not provide access to this path.\nUI:N - The attacker with the required local administrative privilege can perform the mount sequence directly. No separate victim action is required.\nS:C - The kernel SMB client session-confusion flaw can cause access to resources governed by a separate SMB/Kerberos server security authority using the wrong authenticated principal. That crosses from the client kernel\u0027s mount/session selection into remote server authorization.\nC:H - Reusing the wrong Kerberos SMB session can expose files and shares accessible to the previously authenticated principal rather than the requested username. In a high-impact deployment, that principal may have broad access to sensitive remote data.\nI:H - File operations on the unintended mount use the reused principal\u0027s SMB session, so writes, deletes, ACL changes, or other modifications may be authorized as that principal. If that account has broad write rights, integrity impact is high.\nA:L - The flaw does not indicate kernel memory corruption, panic, or hang, but it can cause intended Kerberos mounts to fail or bind to the wrong session. This can interrupt access to the intended SMB share without a full availability loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:22:03.739Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fd4547830720647d4af02ee50f883c4b1cca06e4"
},
{
"url": "https://git.kernel.org/stable/c/9229709ec8bf85ae7ca53aeee9aa14814cdc1bd2"
},
{
"url": "https://git.kernel.org/stable/c/d33cbf0bf8979d779900da9be2505d68d9d8da25"
},
{
"url": "https://git.kernel.org/stable/c/9ee803bfdba0cf739038dbdabdd4c02582c8f2b2"
},
{
"url": "https://git.kernel.org/stable/c/6e9ff1eb7feedcf46ff2d0503759960ab58e7775"
},
{
"url": "https://git.kernel.org/stable/c/12b4c5d98cd7ca46d5035a57bcd995df614c14e1"
}
],
"title": "smb: client: fix krb5 mount with username option",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-31392",
"datePublished": "2026-04-03T15:15:57.491Z",
"dateReserved": "2026-03-09T15:48:24.085Z",
"dateUpdated": "2026-08-05T12:22:03.739Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68267 (GCVE-0-2026-68267)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
Unconditionally whitelisting OA registers is a security violation. Set
RING_FORCE_TO_NONPRIV_DENY bit in OA nonpriv slots, so that OA registers
don't get whitelisted by default after probe, gt reset, resume and engine
reset.
(cherry picked from commit 90511bdcfda97211c01f1d945d4ea616578d8fca)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/xe/xe_reg_whitelist.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9852aa87ecba95d7bf9fb94a9d6c4f69312c9682",
"status": "affected",
"version": "828a8eaf37c3fac6ba048995f55f1647a4ac542d",
"versionType": "git"
},
{
"lessThan": "7982678fa21eda02a9111d2646be6762b5e3a64d",
"status": "affected",
"version": "828a8eaf37c3fac6ba048995f55f1647a4ac542d",
"versionType": "git"
},
{
"lessThan": "1e6d07abbc0c41cb3259042794ad3deca79dd14e",
"status": "affected",
"version": "828a8eaf37c3fac6ba048995f55f1647a4ac542d",
"versionType": "git"
},
{
"lessThan": "e70086a3a06d276b4a5d9a2c51c9330c6cf72780",
"status": "affected",
"version": "828a8eaf37c3fac6ba048995f55f1647a4ac542d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/xe/xe_reg_whitelist.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists\n\nUnconditionally whitelisting OA registers is a security violation. Set\nRING_FORCE_TO_NONPRIV_DENY bit in OA nonpriv slots, so that OA registers\ndon\u0027t get whitelisted by default after probe, gt reset, resume and engine\nreset.\n\n(cherry picked from commit 90511bdcfda97211c01f1d945d4ea616578d8fca)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:00.297Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9852aa87ecba95d7bf9fb94a9d6c4f69312c9682"
},
{
"url": "https://git.kernel.org/stable/c/7982678fa21eda02a9111d2646be6762b5e3a64d"
},
{
"url": "https://git.kernel.org/stable/c/1e6d07abbc0c41cb3259042794ad3deca79dd14e"
},
{
"url": "https://git.kernel.org/stable/c/e70086a3a06d276b4a5d9a2c51c9330c6cf72780"
}
],
"title": "drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68267",
"datePublished": "2026-08-10T12:01:42.551Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:02:00.297Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64530 (GCVE-0-2026-64530)
Vulnerability from cvelistv5
Published
2026-07-26 06:28
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the
defragmentation engine (e.g. act_ct on out-of-order fragments). When
that happens the skb is no longer owned by the caller and must not be
touched again.
tcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the
switch and returned the skb to the caller as if classification had
passed. The only qdisc that wires up qevents today is RED, via three call sites
(qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop)
red_enqueue() was continuing to operate on an skb it no longer owns in this
case -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF.
tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10
tc filter add block 10 ... action ct
(with ct defrag enabled and traffic that produces out-of-order
fragments, e.g. a fragmented UDP stream)
Handle TC_ACT_CONSUMED in tcf_qevent_handle() the same way the ingress
and egress fast paths do: treat it as stolen and return NULL without
touching the skb. Unlike the TC_ACT_STOLEN case, the skb must not be
dropped/freed here, as it is no longer owned by us.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 172ba7d46c202e679f3ccb10264c67416aaeb1c4 Version: 0b5b831122fc3789fff75be433ba3e4dd7b779d4 Version: 73f7da5fd124f2cda9161e2e46114915e6e82e97 Version: 3f14b377d01d8357eba032b4cabc8c1149b458b6 Version: 3f14b377d01d8357eba032b4cabc8c1149b458b6 Version: 3f14b377d01d8357eba032b4cabc8c1149b458b6 Version: 3f14b377d01d8357eba032b4cabc8c1149b458b6 Version: f5346df0591d10bc948761ca854b1fae6d2ef441 Version: 5.15.148 ≤ Version: 6.1.75 ≤ Version: 6.6.14 ≤ Version: 6.7.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/cls_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5ed3d6f85991656667059d3fa5a1d683ac58c447",
"status": "affected",
"version": "172ba7d46c202e679f3ccb10264c67416aaeb1c4",
"versionType": "git"
},
{
"lessThan": "f42e8134a3a1074b834a574d404352f867ba994a",
"status": "affected",
"version": "0b5b831122fc3789fff75be433ba3e4dd7b779d4",
"versionType": "git"
},
{
"lessThan": "447d493034a9cf7bf13a2abac86d0573d907ec2f",
"status": "affected",
"version": "73f7da5fd124f2cda9161e2e46114915e6e82e97",
"versionType": "git"
},
{
"lessThan": "e1270e69dcf2c3512c453484178f2e9dc0db3f05",
"status": "affected",
"version": "3f14b377d01d8357eba032b4cabc8c1149b458b6",
"versionType": "git"
},
{
"lessThan": "2140c2f3f2e7b066e1ae616ede8856cafd8015e9",
"status": "affected",
"version": "3f14b377d01d8357eba032b4cabc8c1149b458b6",
"versionType": "git"
},
{
"lessThan": "e28aedab9488343924d227b5a896faed67ce84d5",
"status": "affected",
"version": "3f14b377d01d8357eba032b4cabc8c1149b458b6",
"versionType": "git"
},
{
"lessThan": "a8a02897f2b479127db261de05cbf0c28b98d159",
"status": "affected",
"version": "3f14b377d01d8357eba032b4cabc8c1149b458b6",
"versionType": "git"
},
{
"status": "affected",
"version": "f5346df0591d10bc948761ca854b1fae6d2ef441",
"versionType": "git"
},
{
"lessThan": "5.15.212",
"status": "affected",
"version": "5.15.148",
"versionType": "semver"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.75",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.14",
"versionType": "semver"
},
{
"lessThan": "6.8",
"status": "affected",
"version": "6.7.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/cls_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.15.148",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.75",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.7.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle\n\ntcf_classify() can return TC_ACT_CONSUMED while the skb is held by the\ndefragmentation engine (e.g. act_ct on out-of-order fragments). When\nthat happens the skb is no longer owned by the caller and must not be\ntouched again.\n\ntcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the\nswitch and returned the skb to the caller as if classification had\npassed. The only qdisc that wires up qevents today is RED, via three call sites\n(qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop)\nred_enqueue() was continuing to operate on an skb it no longer owns in this\ncase -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF.\n\n tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10\n tc filter add block 10 ... action ct\n\n (with ct defrag enabled and traffic that produces out-of-order\n fragments, e.g. a fragmented UDP stream)\n\nHandle TC_ACT_CONSUMED in tcf_qevent_handle() the same way the ingress\nand egress fast paths do: treat it as stolen and return NULL without\ntouching the skb. Unlike the TC_ACT_STOLEN case, the skb must not be\ndropped/freed here, as it is no longer owned by us."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On a transparent bridge or traffic-shaping gateway configured with the RED qevent and act_ct, unauthenticated remote IP fragments reach red_enqueue() through normal receive, bridge-forwarding, and egress-qdisc processing. No local netlink access is required to trigger the deployed configuration.\nAC:L - The attacker controls fragment contents and ordering and can drive RED into deterministic hard-mark or drop conditions with sustained traffic. No race or condition outside the attacker\u0027s control must be won.\nPR:N - CAP_NET_ADMIN is required to create the vulnerable configuration, but a remote attacker sending fragments through an already configured appliance needs no privileges or authentication. Local triggering is also possible with namespaced CAP_NET_ADMIN.\nUI:N - Triggering requires only attacker-generated fragmented traffic and does not depend on a victim performing any action.\nS:U - The corruption occurs within the host kernel and compromises resources governed by that same security authority. This remains unchanged scope even when used for namespace escape or kernel privilege escalation.\nC:H - The reclaimable sk_buff use-after-free and corrupted defragmentation-tree links can be leveraged through attacker-controlled network heap spraying to disclose arbitrary kernel memory.\nI:H - RED overwrites linkage fields that overlap the defragmentation RB node and may free the object while it remains referenced, enabling subsequent writes through freed or attacker-reclaimed kernel objects and potential code execution.\nA:H - The dangling fragment-tree entry can cause immediate or deferred use-after-free, double-free, invalid tree operations, and kernel panic when another fragment arrives or the queue expires. The attacker can trigger this repeatedly with fragmented traffic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:07.900Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5ed3d6f85991656667059d3fa5a1d683ac58c447"
},
{
"url": "https://git.kernel.org/stable/c/f42e8134a3a1074b834a574d404352f867ba994a"
},
{
"url": "https://git.kernel.org/stable/c/447d493034a9cf7bf13a2abac86d0573d907ec2f"
},
{
"url": "https://git.kernel.org/stable/c/e1270e69dcf2c3512c453484178f2e9dc0db3f05"
},
{
"url": "https://git.kernel.org/stable/c/2140c2f3f2e7b066e1ae616ede8856cafd8015e9"
},
{
"url": "https://git.kernel.org/stable/c/e28aedab9488343924d227b5a896faed67ce84d5"
},
{
"url": "https://git.kernel.org/stable/c/a8a02897f2b479127db261de05cbf0c28b98d159"
}
],
"title": "net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64530",
"datePublished": "2026-07-26T06:28:42.970Z",
"dateReserved": "2026-07-19T15:36:31.794Z",
"dateUpdated": "2026-08-17T04:57:07.900Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63801 (GCVE-0-2026-63801)
Vulnerability from cvelistv5
Published
2026-07-19 12:02
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
tipc_aead_decrypt() goes straight from tipc_bearer_hold(b) to
crypto_aead_decrypt(req) without taking a reference on the netns, unlike
the encrypt path. When crypto_aead_decrypt() is offloaded asynchronously
(e.g. the SIMD aead wrapper queuing to cryptd), the cryptd worker runs
tipc_aead_decrypt_done() later. If the bearer's netns is torn down in the
meantime, cleanup_net() -> tipc_exit_net() -> tipc_crypto_stop() frees the
per-netns tipc_crypto, and the completion then reads it:
tipc_aead_decrypt_done() dereferences aead->crypto->stats and
aead->crypto->net, and tipc_crypto_rcv_complete() dereferences
aead->crypto->aead[] and the node table -- reading freed memory.
Decoded KASAN splat (v7.1-rc7, CONFIG_KASAN_INLINE + TIPC + TIPC_CRYPTO):
BUG: KASAN: slab-use-after-free in tipc_aead_decrypt_done (net/tipc/crypto.c:999)
Read of size 8 at addr ffff8881056258a8 by task kworker/u16:2/51
Workqueue: events_unbound
Call Trace:
tipc_aead_decrypt_done (net/tipc/crypto.c:999)
process_one_work (kernel/workqueue.c:3314)
worker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
Allocated by task 169:
__kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)
tipc_crypto_start (net/tipc/crypto.c:1502)
tipc_init_net (net/tipc/core.c:72)
ops_init (net/core/net_namespace.c:137)
setup_net (net/core/net_namespace.c:446)
copy_net_ns (net/core/net_namespace.c:579)
create_new_namespaces (kernel/nsproxy.c:132)
__x64_sys_unshare (kernel/fork.c:3316)
do_syscall_64 (arch/x86/entry/syscall_64.c:63)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Freed by task 8:
kfree (mm/slub.c:6566)
tipc_exit_net (net/tipc/core.c:119)
cleanup_net (net/core/net_namespace.c:704)
process_one_work (kernel/workqueue.c:3314)
kthread (kernel/kthread.c:436)
This is the same class of bug that commit e279024617134 ("net/tipc: fix
slab-use-after-free Read in tipc_aead_encrypt_done") fixed for the encrypt
side. The encrypt path takes maybe_get_net(aead->crypto->net) before
crypto_aead_encrypt() and drops it with put_net() on the synchronous
return paths and in tipc_aead_encrypt_done(); the -EINPROGRESS/-EBUSY
return keeps the reference for the async callback to release. The decrypt
path was left without the equivalent guard.
Mirror the encrypt-side fix on the decrypt path: take a net reference
before crypto_aead_decrypt() (failing with -ENODEV and the matching
bearer put if it cannot be acquired), keep it across the
-EINPROGRESS/-EBUSY async return, and drop it with put_net() on the
synchronous success/error return and at the end of
tipc_aead_decrypt_done().
Reproduced under KASAN on v7.1-rc7: a UDP bearer with a cluster key is
flooded with crafted encrypted frames from an unknown peer (driving the
cluster-key decrypt path) while the bearer's netns is repeatedly torn
down. The completion must run asynchronously to outlive
tipc_crypto_stop(); on x86 the stock aesni gcm(aes) now decrypts
synchronously, so the async path was exercised via cryptd offload. The
unguarded aead->crypto dereference in tipc_aead_decrypt_done() is the
unpatched upstream path; tipc_aead_decrypt() still lacks
maybe_get_net(aead->crypto->net), so the completion can outlive the free
on any config where crypto_aead_decrypt() goes async.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 Version: fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 Version: fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 Version: fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 Version: fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 Version: fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 Version: fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 Version: fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/crypto.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "171d31245d11bf84836fad3b394cb465a4d008ec",
"status": "affected",
"version": "fc1b6d6de2208774efd2a20bf0daddb02d18b1e0",
"versionType": "git"
},
{
"lessThan": "2d1f21419ec121232c916d3a3fc9b6766473a0e7",
"status": "affected",
"version": "fc1b6d6de2208774efd2a20bf0daddb02d18b1e0",
"versionType": "git"
},
{
"lessThan": "0a780653b2a7569a7af9be7d0b00b1251baca63a",
"status": "affected",
"version": "fc1b6d6de2208774efd2a20bf0daddb02d18b1e0",
"versionType": "git"
},
{
"lessThan": "eaca7dae02fab70c8d223cffe03cec1b93249ce2",
"status": "affected",
"version": "fc1b6d6de2208774efd2a20bf0daddb02d18b1e0",
"versionType": "git"
},
{
"lessThan": "dca7713fe044a2067387948557ea099056e1679e",
"status": "affected",
"version": "fc1b6d6de2208774efd2a20bf0daddb02d18b1e0",
"versionType": "git"
},
{
"lessThan": "e18769616fd5a90ec1e12aabbba544c488284292",
"status": "affected",
"version": "fc1b6d6de2208774efd2a20bf0daddb02d18b1e0",
"versionType": "git"
},
{
"lessThan": "1eea5e1820a2f5164d706bd1277bc97ff31ce32d",
"status": "affected",
"version": "fc1b6d6de2208774efd2a20bf0daddb02d18b1e0",
"versionType": "git"
},
{
"lessThan": "bda3348872a2ef0d19f2df6aa8cb5025adce2f20",
"status": "affected",
"version": "fc1b6d6de2208774efd2a20bf0daddb02d18b1e0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/crypto.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.260",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.260",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix slab-use-after-free Read in tipc_aead_decrypt_done\n\ntipc_aead_decrypt() goes straight from tipc_bearer_hold(b) to\ncrypto_aead_decrypt(req) without taking a reference on the netns, unlike\nthe encrypt path. When crypto_aead_decrypt() is offloaded asynchronously\n(e.g. the SIMD aead wrapper queuing to cryptd), the cryptd worker runs\ntipc_aead_decrypt_done() later. If the bearer\u0027s netns is torn down in the\nmeantime, cleanup_net() -\u003e tipc_exit_net() -\u003e tipc_crypto_stop() frees the\nper-netns tipc_crypto, and the completion then reads it:\ntipc_aead_decrypt_done() dereferences aead-\u003ecrypto-\u003estats and\naead-\u003ecrypto-\u003enet, and tipc_crypto_rcv_complete() dereferences\naead-\u003ecrypto-\u003eaead[] and the node table -- reading freed memory.\n\nDecoded KASAN splat (v7.1-rc7, CONFIG_KASAN_INLINE + TIPC + TIPC_CRYPTO):\n\n BUG: KASAN: slab-use-after-free in tipc_aead_decrypt_done (net/tipc/crypto.c:999)\n Read of size 8 at addr ffff8881056258a8 by task kworker/u16:2/51\n Workqueue: events_unbound\n Call Trace:\n tipc_aead_decrypt_done (net/tipc/crypto.c:999)\n process_one_work (kernel/workqueue.c:3314)\n worker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\n Allocated by task 169:\n __kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)\n tipc_crypto_start (net/tipc/crypto.c:1502)\n tipc_init_net (net/tipc/core.c:72)\n ops_init (net/core/net_namespace.c:137)\n setup_net (net/core/net_namespace.c:446)\n copy_net_ns (net/core/net_namespace.c:579)\n create_new_namespaces (kernel/nsproxy.c:132)\n __x64_sys_unshare (kernel/fork.c:3316)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\n Freed by task 8:\n kfree (mm/slub.c:6566)\n tipc_exit_net (net/tipc/core.c:119)\n cleanup_net (net/core/net_namespace.c:704)\n process_one_work (kernel/workqueue.c:3314)\n kthread (kernel/kthread.c:436)\n\nThis is the same class of bug that commit e279024617134 (\"net/tipc: fix\nslab-use-after-free Read in tipc_aead_encrypt_done\") fixed for the encrypt\nside. The encrypt path takes maybe_get_net(aead-\u003ecrypto-\u003enet) before\ncrypto_aead_encrypt() and drops it with put_net() on the synchronous\nreturn paths and in tipc_aead_encrypt_done(); the -EINPROGRESS/-EBUSY\nreturn keeps the reference for the async callback to release. The decrypt\npath was left without the equivalent guard.\n\nMirror the encrypt-side fix on the decrypt path: take a net reference\nbefore crypto_aead_decrypt() (failing with -ENODEV and the matching\nbearer put if it cannot be acquired), keep it across the\n-EINPROGRESS/-EBUSY async return, and drop it with put_net() on the\nsynchronous success/error return and at the end of\ntipc_aead_decrypt_done().\n\nReproduced under KASAN on v7.1-rc7: a UDP bearer with a cluster key is\nflooded with crafted encrypted frames from an unknown peer (driving the\ncluster-key decrypt path) while the bearer\u0027s netns is repeatedly torn\ndown. The completion must run asynchronously to outlive\ntipc_crypto_stop(); on x86 the stock aesni gcm(aes) now decrypts\nsynchronously, so the async path was exercised via cryptd offload. The\nunguarded aead-\u003ecrypto dereference in tipc_aead_decrypt_done() is the\nunpatched upstream path; tipc_aead_decrypt() still lacks\nmaybe_get_net(aead-\u003ecrypto-\u003enet), so the completion can outlive the free\non any config where crypto_aead_decrypt() goes async.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code is reached from the TIPC packet receive path (UDP bearer on port 6118 or L2 bearer) when encrypted frames arrive from a remote peer; no local syscall is required to enter tipc_aead_decrypt().\nAC:L - The attacker can reliably win the race by flooding packets to queue async decrypt completions while repeatedly destroying the network namespace; the repro demonstrates full control of both sides of the timing window.\nPR:L - Reliable exploitation is demonstrated via unshare-created user/network namespaces where the attacker gains CAP_NET_ADMIN-equivalent control to configure TIPC crypto and cycle namespace teardown, which per kernel CNA guidance maps to Low rather than High.\nUI:N - Exploitation requires only sending network packets and namespace lifecycle manipulation; no victim user action such as opening a file or mounting a filesystem is needed.\nS:U - Impact is confined to kernel memory within the same security authority; this is a standard kernel UAF/privilege-escalation class bug, not a VM escape or cross-authority boundary bypass.\nC:H - The UAF reads freed slab memory including aead-\u003ecrypto-\u003estats, aead-\u003ecrypto-\u003enet, and aead[] pointers in tipc_crypto_rcv_complete, enabling arbitrary kernel memory disclosure via controlled reuse of the freed tipc_crypto object.\nI:H - Use-after-free of tipc_crypto structures can be leveraged for heap spraying and arbitrary write primitives, and tipc_crypto_rcv_complete continues processing with freed pointers including key attachment and node table operations.\nA:H - KASAN confirmed slab-use-after-free in tipc_aead_decrypt_done on a workqueue thread; UAF on this path causes kernel oops/panic even when not fully exploited for code execution."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:06.693Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/171d31245d11bf84836fad3b394cb465a4d008ec"
},
{
"url": "https://git.kernel.org/stable/c/2d1f21419ec121232c916d3a3fc9b6766473a0e7"
},
{
"url": "https://git.kernel.org/stable/c/0a780653b2a7569a7af9be7d0b00b1251baca63a"
},
{
"url": "https://git.kernel.org/stable/c/eaca7dae02fab70c8d223cffe03cec1b93249ce2"
},
{
"url": "https://git.kernel.org/stable/c/dca7713fe044a2067387948557ea099056e1679e"
},
{
"url": "https://git.kernel.org/stable/c/e18769616fd5a90ec1e12aabbba544c488284292"
},
{
"url": "https://git.kernel.org/stable/c/1eea5e1820a2f5164d706bd1277bc97ff31ce32d"
},
{
"url": "https://git.kernel.org/stable/c/bda3348872a2ef0d19f2df6aa8cb5025adce2f20"
}
],
"title": "tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63801",
"datePublished": "2026-07-19T12:02:07.457Z",
"dateReserved": "2026-07-19T07:54:57.013Z",
"dateUpdated": "2026-08-17T04:51:06.693Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72307 (GCVE-0-2026-72307)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-17 05:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
When mlxsw_sp_vrs_lpm_tree_replace() fails after replacing some VRs,
the error rollback loop does not correctly revert the preceding
replacements. The loop decrements the index but fails to update the
vr pointer, which still points to the VR that caused the failure. As
a result, the condition and the rollback call always operate on the
same VR, potentially calling mlxsw_sp_vr_lpm_tree_replace() multiple
times on it while never rolling back the earlier VRs. Those VRs
continue to hold a reference to new_tree acquired via
mlxsw_sp_lpm_tree_hold(), leaking the reference count of new_tree.
Fix by reinitializing vr inside the error loop with the updated index:
vr = &mlxsw_sp->router->vrs[i];
so that the loop correctly iterates over all VRs that were actually
replaced.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fc922bb0dd9406dd9897fd47df958789891c380e Version: fc922bb0dd9406dd9897fd47df958789891c380e Version: fc922bb0dd9406dd9897fd47df958789891c380e Version: fc922bb0dd9406dd9897fd47df958789891c380e Version: fc922bb0dd9406dd9897fd47df958789891c380e Version: fc922bb0dd9406dd9897fd47df958789891c380e Version: fc922bb0dd9406dd9897fd47df958789891c380e Version: fc922bb0dd9406dd9897fd47df958789891c380e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c2c75c45b54f3b12eafb28a4eb47f8821512c1aa",
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"versionType": "git"
},
{
"lessThan": "7203ac71d3895fa5948b319dd724f0e1cffbc4a1",
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"versionType": "git"
},
{
"lessThan": "f6454a5fbf2224ad30ec70e686a6c592561da1f2",
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"versionType": "git"
},
{
"lessThan": "220d41bdce41fe5a39a7f419faab1e907b4093c2",
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"versionType": "git"
},
{
"lessThan": "9e4a6185679922305ea1df68403f00ccc512656b",
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"versionType": "git"
},
{
"lessThan": "3a2b47d1b4b3de54d030a7fdb6a322c970513ee3",
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"versionType": "git"
},
{
"lessThan": "8adebf07b46df79a0e49a6d4ae384f0db7c91db6",
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"versionType": "git"
},
{
"lessThan": "21cf8dc478a49e8de039c2739b1646a774cb1944",
"status": "affected",
"version": "fc922bb0dd9406dd9897fd47df958789891c380e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()\n\nWhen mlxsw_sp_vrs_lpm_tree_replace() fails after replacing some VRs,\nthe error rollback loop does not correctly revert the preceding\nreplacements. The loop decrements the index but fails to update the\nvr pointer, which still points to the VR that caused the failure. As\na result, the condition and the rollback call always operate on the\nsame VR, potentially calling mlxsw_sp_vr_lpm_tree_replace() multiple\ntimes on it while never rolling back the earlier VRs. Those VRs\ncontinue to hold a reference to new_tree acquired via\nmlxsw_sp_lpm_tree_hold(), leaking the reference count of new_tree.\n\nFix by reinitializing vr inside the error loop with the updated index:\n\n\tvr = \u0026mlxsw_sp-\u003erouter-\u003evrs[i];\n\nso that the loop correctly iterates over all VRs that were actually\nreplaced."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:12:11.806Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c2c75c45b54f3b12eafb28a4eb47f8821512c1aa"
},
{
"url": "https://git.kernel.org/stable/c/7203ac71d3895fa5948b319dd724f0e1cffbc4a1"
},
{
"url": "https://git.kernel.org/stable/c/f6454a5fbf2224ad30ec70e686a6c592561da1f2"
},
{
"url": "https://git.kernel.org/stable/c/220d41bdce41fe5a39a7f419faab1e907b4093c2"
},
{
"url": "https://git.kernel.org/stable/c/9e4a6185679922305ea1df68403f00ccc512656b"
},
{
"url": "https://git.kernel.org/stable/c/3a2b47d1b4b3de54d030a7fdb6a322c970513ee3"
},
{
"url": "https://git.kernel.org/stable/c/8adebf07b46df79a0e49a6d4ae384f0db7c91db6"
},
{
"url": "https://git.kernel.org/stable/c/21cf8dc478a49e8de039c2739b1646a774cb1944"
}
],
"title": "mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72307",
"datePublished": "2026-08-15T05:55:24.622Z",
"dateReserved": "2026-08-09T03:40:39.918Z",
"dateUpdated": "2026-08-17T05:12:11.806Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72343 (GCVE-0-2026-72343)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-17 05:43
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
mlx5e_hv_vhca_stats_create() is called from mlx5e_nic_enable(),
before mlx5e_open(). At that point priv->stats_nch is still zero,
because it is only ever incremented in mlx5e_channel_stats_alloc(),
which is reached only from mlx5e_open_channel().
mlx5e_hv_vhca_stats_buf_size() therefore returns 0, and
kvzalloc(0, GFP_KERNEL) returns ZERO_SIZE_PTR ((void *)16) rather
than NULL. The "if (!buf)" guard does not catch this, and
mlx5e_hv_vhca_stats_create() completes "successfully" with
priv->stats_agent.buf set to ZERO_SIZE_PTR.
Once channels are opened (priv->stats_nch > 0) and the hypervisor
enables stats reporting, mlx5e_hv_vhca_stats_work() recomputes
buf_len using the new non-zero stats_nch and calls
memset(buf, 0, buf_len) on ZERO_SIZE_PTR, faulting at address 0x10.
Allocate the buffer based on priv->max_nch, which is set in
mlx5e_priv_init() and is the upper bound on stats_nch:
- Add a separate helper mlx5e_hv_vhca_stats_buf_max_size() that
returns sizeof(per_ring_stats) * max(max_nch, stats_nch), and
use it for the kvzalloc() in mlx5e_hv_vhca_stats_create().
- Keep mlx5e_hv_vhca_stats_buf_size() (which returns based on
stats_nch) for the worker's active payload size, so the wire
format (block->rings = stats_nch) and the amount of data filled
by mlx5e_hv_vhca_fill_stats() are unchanged.
The max(max_nch, stats_nch) guard handles the rare case where
mlx5e_attach_netdev() recomputes max_nch downward across a
detach/resume cycle while priv->stats_nch persists (mlx5e_detach_netdev
does not call mlx5e_priv_cleanup, so stats_nch is only reset when
the netdev is destroyed). Without the guard, the worker could compute
buf_len from stats_nch and overrun the smaller buffer allocated based
on the reduced max_nch.
Allocating a non-zero buffer also makes the kvzalloc() failure path in
mlx5e_hv_vhca_stats_create() reachable for the first time: it returns
early without (re)creating the agent. Clear
priv->stats_agent.{agent,buf} in mlx5e_hv_vhca_stats_destroy() after
freeing them, so that if a later create() bails out on this path, a
subsequent teardown does not double-free the stale agent/buffer left
from a previous enable/disable cycle.
This mirrors the existing mlx5e pattern of preallocating arrays of
size max_nch (e.g. priv->channel_stats) and lazily populating
entries up to stats_nch on demand.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fa691d0c9c0812b9045f3a9420862e47b3b92518 Version: fa691d0c9c0812b9045f3a9420862e47b3b92518 Version: fa691d0c9c0812b9045f3a9420862e47b3b92518 Version: fa691d0c9c0812b9045f3a9420862e47b3b92518 Version: fa691d0c9c0812b9045f3a9420862e47b3b92518 Version: fa691d0c9c0812b9045f3a9420862e47b3b92518 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3b3a552cf88e10bb7bda88b29cf1fd8267043d50",
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"versionType": "git"
},
{
"lessThan": "5b927dcec5f1087942bf123a82e64a3f66475f01",
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"versionType": "git"
},
{
"lessThan": "22c1d5ecccf92c849bdca1556179aafc95794baf",
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"versionType": "git"
},
{
"lessThan": "420aabb32da4381d8d7cdcaa6a77fad9eaceb0a4",
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"versionType": "git"
},
{
"lessThan": "abc4c56427f144c96b2827a4db3b90eb5b7349a2",
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"versionType": "git"
},
{
"lessThan": "25f6b929c7e379cbea7cb8caa67b49b2d1efae17",
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix HV VHCA stats zero-sized buffer allocation\n\nmlx5e_hv_vhca_stats_create() is called from mlx5e_nic_enable(),\nbefore mlx5e_open(). At that point priv-\u003estats_nch is still zero,\nbecause it is only ever incremented in mlx5e_channel_stats_alloc(),\nwhich is reached only from mlx5e_open_channel().\n\nmlx5e_hv_vhca_stats_buf_size() therefore returns 0, and\nkvzalloc(0, GFP_KERNEL) returns ZERO_SIZE_PTR ((void *)16) rather\nthan NULL. The \"if (!buf)\" guard does not catch this, and\nmlx5e_hv_vhca_stats_create() completes \"successfully\" with\npriv-\u003estats_agent.buf set to ZERO_SIZE_PTR.\n\nOnce channels are opened (priv-\u003estats_nch \u003e 0) and the hypervisor\nenables stats reporting, mlx5e_hv_vhca_stats_work() recomputes\nbuf_len using the new non-zero stats_nch and calls\nmemset(buf, 0, buf_len) on ZERO_SIZE_PTR, faulting at address 0x10.\n\nAllocate the buffer based on priv-\u003emax_nch, which is set in\nmlx5e_priv_init() and is the upper bound on stats_nch:\n\n - Add a separate helper mlx5e_hv_vhca_stats_buf_max_size() that\n returns sizeof(per_ring_stats) * max(max_nch, stats_nch), and\n use it for the kvzalloc() in mlx5e_hv_vhca_stats_create().\n - Keep mlx5e_hv_vhca_stats_buf_size() (which returns based on\n stats_nch) for the worker\u0027s active payload size, so the wire\n format (block-\u003erings = stats_nch) and the amount of data filled\n by mlx5e_hv_vhca_fill_stats() are unchanged.\n\nThe max(max_nch, stats_nch) guard handles the rare case where\nmlx5e_attach_netdev() recomputes max_nch downward across a\ndetach/resume cycle while priv-\u003estats_nch persists (mlx5e_detach_netdev\ndoes not call mlx5e_priv_cleanup, so stats_nch is only reset when\nthe netdev is destroyed). Without the guard, the worker could compute\nbuf_len from stats_nch and overrun the smaller buffer allocated based\non the reduced max_nch.\n\nAllocating a non-zero buffer also makes the kvzalloc() failure path in\nmlx5e_hv_vhca_stats_create() reachable for the first time: it returns\nearly without (re)creating the agent. Clear\npriv-\u003estats_agent.{agent,buf} in mlx5e_hv_vhca_stats_destroy() after\nfreeing them, so that if a later create() bails out on this path, a\nsubsequent teardown does not double-free the stale agent/buffer left\nfrom a previous enable/disable cycle.\n\nThis mirrors the existing mlx5e pattern of preallocating arrays of\nsize max_nch (e.g. priv-\u003echannel_stats) and lazily populating\nentries up to stats_nch on demand."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached via the Hyper-V VMBus PCI config back-channel (PCI_INVALIDATE_BLOCK) into mlx5e HV VHCA stats handling during mlx5e driver operation on Azure mlx5 NICs, not via remote network packets or guest syscall/ioctl paths.\nAC:L - mlx5e_nic_enable always calls mlx5e_hv_vhca_stats_create before mlx5e_open, so kvzalloc(0) deterministically stores ZERO_SIZE_PTR; once channels open and the hypervisor enables stats reporting, the worker always memset()s with buf_len\u003e0 and faults.\nPR:N - On Azure/Hyper-V mlx5 VMs the host routinely drives VHCA stats collection over the PCI config back-channel during normal operation; no guest credentials, CAP_NET_ADMIN, or other elevated guest privileges are required beyond standard VM boot with the NIC active.\nUI:N - Triggering requires only normal VM boot and mlx5e driver bring-up with channels opened; no victim file open, mount, or other interactive administrator action is needed to reach the faulty memset path.\nS:U - Kernel memory corruption and panic are confined to the guest kernel running mlx5e on the affected VM; the bug does not cross VM/host, IOMMU, or other security boundaries into a separate authority.\nC:H - memset(buf,0,buf_len) on ZERO_SIZE_PTR is an out-of-bounds write from a near-NULL kernel address; per kernel guidance any such memory corruption can be leveraged for information disclosure even though the immediate operation writes zeros.\nI:H - The worker performs a large out-of-bounds write via memset on the bogus buffer pointer, and the pre-fix sizing logic can also overrun a too-small allocation when stats_nch exceeds max_nch after detach/resume, enabling arbitrary kernel write primitives.\nA:H - The memset on ZERO_SIZE_PTR faults at address 0x10 causing a kernel oops or panic, reliably denying availability of Azure/Hyper-V guests using CONFIG_PCI_HYPERV_INTERFACE mlx5 NICs whenever the hypervisor enables stats reporting."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:43:01.870Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3b3a552cf88e10bb7bda88b29cf1fd8267043d50"
},
{
"url": "https://git.kernel.org/stable/c/5b927dcec5f1087942bf123a82e64a3f66475f01"
},
{
"url": "https://git.kernel.org/stable/c/22c1d5ecccf92c849bdca1556179aafc95794baf"
},
{
"url": "https://git.kernel.org/stable/c/420aabb32da4381d8d7cdcaa6a77fad9eaceb0a4"
},
{
"url": "https://git.kernel.org/stable/c/abc4c56427f144c96b2827a4db3b90eb5b7349a2"
},
{
"url": "https://git.kernel.org/stable/c/25f6b929c7e379cbea7cb8caa67b49b2d1efae17"
}
],
"title": "net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72343",
"datePublished": "2026-08-15T05:55:49.067Z",
"dateReserved": "2026-08-09T03:40:39.920Z",
"dateUpdated": "2026-08-17T05:43:01.870Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68214 (GCVE-0-2026-68214)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: rtl2832: fix use-after-free in rtl2832_remove()
cancel_delayed_work_sync() is called before i2c_mux_del_adapters()
in rtl2832_remove(). While the cancel waits for any running instance
of i2c_gate_work to finish, it does not prevent the timer from being
rescheduled by a concurrent thread.
During probe, the r820t_attach() call attempts I2C transfers through
the mux adapter. These transfers go through i2c_mux_master_xfer(),
which calls rtl2832_deselect() after the transfer completes,
rescheduling i2c_gate_work via schedule_delayed_work(). If this
transfer is still in flight when rtl2832_remove() runs,
rtl2832_deselect() can reschedule i2c_gate_work after it has been
cancelled, causing a use-after-free when kfree(dev) is called.
Fix this by calling i2c_mux_del_adapters() before
cancel_delayed_work_sync(). Once the mux adapter is unregistered, no
new I2C transfers can go through it, so rtl2832_deselect() can no
longer reschedule i2c_gate_work. The subsequent
cancel_delayed_work_sync() is then guaranteed to be final.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1e8a6bc19403661661fed5ae82f6eca6c9cdfad2",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "68a9c0290897c1436ddceb8cea604c93377a0299",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "13c06056699e66ff7109ba68658cc6ea4a23f516",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "9acd5bbbe1df8e487e49488692c224496d4c9e16",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "24bef237eef8dd1ebcffb129ba21891ddad0d309",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "2c71bda6edc630a1f8c3c45d8df5fc22d234e042",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "90d781711418881f8c836c2a859cc2886625d750",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "680daf40a82d483949f87f0d8f98639dc47e610c",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rtl2832: fix use-after-free in rtl2832_remove()\n\ncancel_delayed_work_sync() is called before i2c_mux_del_adapters()\nin rtl2832_remove(). While the cancel waits for any running instance\nof i2c_gate_work to finish, it does not prevent the timer from being\nrescheduled by a concurrent thread.\n\nDuring probe, the r820t_attach() call attempts I2C transfers through\nthe mux adapter. These transfers go through i2c_mux_master_xfer(),\nwhich calls rtl2832_deselect() after the transfer completes,\nrescheduling i2c_gate_work via schedule_delayed_work(). If this\ntransfer is still in flight when rtl2832_remove() runs,\nrtl2832_deselect() can reschedule i2c_gate_work after it has been\ncancelled, causing a use-after-free when kfree(dev) is called.\n\nFix this by calling i2c_mux_del_adapters() before\ncancel_delayed_work_sync(). Once the mux adapter is unregistered, no\nnew I2C transfers can go through it, so rtl2832_deselect() can no\nlonger reschedule i2c_gate_work. The subsequent\ncancel_delayed_work_sync() is then guaranteed to be final."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:42.193Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1e8a6bc19403661661fed5ae82f6eca6c9cdfad2"
},
{
"url": "https://git.kernel.org/stable/c/68a9c0290897c1436ddceb8cea604c93377a0299"
},
{
"url": "https://git.kernel.org/stable/c/13c06056699e66ff7109ba68658cc6ea4a23f516"
},
{
"url": "https://git.kernel.org/stable/c/9acd5bbbe1df8e487e49488692c224496d4c9e16"
},
{
"url": "https://git.kernel.org/stable/c/24bef237eef8dd1ebcffb129ba21891ddad0d309"
},
{
"url": "https://git.kernel.org/stable/c/2c71bda6edc630a1f8c3c45d8df5fc22d234e042"
},
{
"url": "https://git.kernel.org/stable/c/90d781711418881f8c836c2a859cc2886625d750"
},
{
"url": "https://git.kernel.org/stable/c/680daf40a82d483949f87f0d8f98639dc47e610c"
}
],
"title": "media: rtl2832: fix use-after-free in rtl2832_remove()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68214",
"datePublished": "2026-08-10T12:00:33.539Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:42.193Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64286 (GCVE-0-2026-64286)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
flush_hyp_vcpu() copies the host vCPU context into the hyp's private
vCPU on every run. ctxt_to_vcpu() expects a guest context to have a
NULL __hyp_running_vcpu, which is only ever set on the host context, so
that it resolves the vCPU via container_of(). While this is generally
the case, flush_hyp_vcpu() copies the context verbatim and does not
enforce this, so a value provided by the host is dereferenced at EL2
(host -> EL2).
Fix by clearing __hyp_running_vcpu after the copy.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/arm64/kvm/hyp/nvhe/hyp-main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "477145860dba4c30f0b4e36f02f4c5291c1c888b",
"status": "affected",
"version": "be66e67f175096f283c9d5614c4991fc9e7ed975",
"versionType": "git"
},
{
"lessThan": "dfaef40d8a1533940fc1af788d70fce07362b4ce",
"status": "affected",
"version": "be66e67f175096f283c9d5614c4991fc9e7ed975",
"versionType": "git"
},
{
"lessThan": "6bea2f8becdb20d34378493c3b77a9b9cf8c6cfa",
"status": "affected",
"version": "be66e67f175096f283c9d5614c4991fc9e7ed975",
"versionType": "git"
},
{
"lessThan": "d4f4d61715d1061ba83b88196a3605662be30750",
"status": "affected",
"version": "be66e67f175096f283c9d5614c4991fc9e7ed975",
"versionType": "git"
},
{
"lessThan": "e8042f6e1d7befb2fb6b10a75918642bcd0acf9a",
"status": "affected",
"version": "be66e67f175096f283c9d5614c4991fc9e7ed975",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/arm64/kvm/hyp/nvhe/hyp-main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU\n\nflush_hyp_vcpu() copies the host vCPU context into the hyp\u0027s private\nvCPU on every run. ctxt_to_vcpu() expects a guest context to have a\nNULL __hyp_running_vcpu, which is only ever set on the host context, so\nthat it resolves the vCPU via container_of(). While this is generally\nthe case, flush_hyp_vcpu() copies the context verbatim and does not\nenforce this, so a value provided by the host is dereferenced at EL2\n(host -\u003e EL2).\n\nFix by clearing __hyp_running_vcpu after the copy."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - A malicious or compromised local EL1 host can place the pointer in the host vCPU context and trigger the vulnerable pKVM path through KVM_RUN; no remote input path reaches it.\nAC:L - The attacker-selected pointer is copied and dereferenced deterministically on every vCPU run, without a race, and EL2 addresses of host-donated metadata are derivable by the host.\nPR:H - Exploitation requires host-kernel control or an equivalent arbitrary kernel write. The KVM userspace register API does not expose __hyp_running_vcpu, and user namespaces do not bypass this restriction.\nUI:N - Once the malicious host context is prepared, invoking the vCPU run path requires no action by another user.\nS:C - The vulnerability crosses the intended isolation boundary from the untrusted EL1 host into the pKVM hypervisor at EL2 and can affect protected-VM resources.\nC:H - The forged pointer drives EL2-private memory dereferences during system-register restoration. Chaining these reads with the write-side corruption can compromise EL2 and expose hypervisor or protected-guest memory.\nI:H - The system-register save path can write through the attacker-selected vCPU pointer into EL2-accessible memory. This can corrupt trusted hypervisor metadata and plausibly enable control-flow or protected-guest state modification.\nA:H - An invalid or unmapped pointer causes a synchronous EL2 fault followed by the nVHE HYP panic handler, which explicitly panics the host kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:42.012Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/477145860dba4c30f0b4e36f02f4c5291c1c888b"
},
{
"url": "https://git.kernel.org/stable/c/dfaef40d8a1533940fc1af788d70fce07362b4ce"
},
{
"url": "https://git.kernel.org/stable/c/6bea2f8becdb20d34378493c3b77a9b9cf8c6cfa"
},
{
"url": "https://git.kernel.org/stable/c/d4f4d61715d1061ba83b88196a3605662be30750"
},
{
"url": "https://git.kernel.org/stable/c/e8042f6e1d7befb2fb6b10a75918642bcd0acf9a"
}
],
"title": "KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64286",
"datePublished": "2026-07-25T08:49:27.542Z",
"dateReserved": "2026-07-19T15:36:31.778Z",
"dateUpdated": "2026-08-17T04:52:42.012Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43077 (GCVE-0-2026-43077)
Vulnerability from cvelistv5
Published
2026-05-06 07:40
Modified
2026-05-11 22:17
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Fix minimum RX size check for decryption
The check for the minimum receive buffer size did not take the
tag size into account during decryption. Fix this by adding the
required extra length.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d887c52d6ae43aeebd249b5f2f1333e60236aa60 Version: d887c52d6ae43aeebd249b5f2f1333e60236aa60 Version: d887c52d6ae43aeebd249b5f2f1333e60236aa60 Version: d887c52d6ae43aeebd249b5f2f1333e60236aa60 Version: d887c52d6ae43aeebd249b5f2f1333e60236aa60 Version: d887c52d6ae43aeebd249b5f2f1333e60236aa60 Version: d887c52d6ae43aeebd249b5f2f1333e60236aa60 Version: d887c52d6ae43aeebd249b5f2f1333e60236aa60 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"crypto/algif_aead.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "74a66fdb5282d89e348b00c42cfca3a936946d94",
"status": "affected",
"version": "d887c52d6ae43aeebd249b5f2f1333e60236aa60",
"versionType": "git"
},
{
"lessThan": "fd427dd84f224309afbcc2cb67c7bb770a01265c",
"status": "affected",
"version": "d887c52d6ae43aeebd249b5f2f1333e60236aa60",
"versionType": "git"
},
{
"lessThan": "1c76b5675119f694458293a2a81f40731c69bd32",
"status": "affected",
"version": "d887c52d6ae43aeebd249b5f2f1333e60236aa60",
"versionType": "git"
},
{
"lessThan": "e86ab1e5661386a874fbb8551f0c04b8e9f8ad22",
"status": "affected",
"version": "d887c52d6ae43aeebd249b5f2f1333e60236aa60",
"versionType": "git"
},
{
"lessThan": "af2fa2fbbced26129813274b8b3f7705f280e174",
"status": "affected",
"version": "d887c52d6ae43aeebd249b5f2f1333e60236aa60",
"versionType": "git"
},
{
"lessThan": "78cea133daf721698876e56135049a96d39d610a",
"status": "affected",
"version": "d887c52d6ae43aeebd249b5f2f1333e60236aa60",
"versionType": "git"
},
{
"lessThan": "3afdc15d6173614d7d834517d9b65e7aa5a08548",
"status": "affected",
"version": "d887c52d6ae43aeebd249b5f2f1333e60236aa60",
"versionType": "git"
},
{
"lessThan": "3d14bd48e3a77091cbce637a12c2ae31b4a1687c",
"status": "affected",
"version": "d887c52d6ae43aeebd249b5f2f1333e60236aa60",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"crypto/algif_aead.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.254",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.204",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.170",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.136",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.83",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.24",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.254",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.204",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.170",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.136",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.83",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.24",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.14",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Fix minimum RX size check for decryption\n\nThe check for the minimum receive buffer size did not take the\ntag size into account during decryption. Fix this by adding the\nrequired extra length."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:17:16.763Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/74a66fdb5282d89e348b00c42cfca3a936946d94"
},
{
"url": "https://git.kernel.org/stable/c/fd427dd84f224309afbcc2cb67c7bb770a01265c"
},
{
"url": "https://git.kernel.org/stable/c/1c76b5675119f694458293a2a81f40731c69bd32"
},
{
"url": "https://git.kernel.org/stable/c/e86ab1e5661386a874fbb8551f0c04b8e9f8ad22"
},
{
"url": "https://git.kernel.org/stable/c/af2fa2fbbced26129813274b8b3f7705f280e174"
},
{
"url": "https://git.kernel.org/stable/c/78cea133daf721698876e56135049a96d39d610a"
},
{
"url": "https://git.kernel.org/stable/c/3afdc15d6173614d7d834517d9b65e7aa5a08548"
},
{
"url": "https://git.kernel.org/stable/c/3d14bd48e3a77091cbce637a12c2ae31b4a1687c"
}
],
"title": "crypto: algif_aead - Fix minimum RX size check for decryption",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43077",
"datePublished": "2026-05-06T07:40:14.409Z",
"dateReserved": "2026-05-01T14:12:55.983Z",
"dateUpdated": "2026-05-11T22:17:16.763Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68226 (GCVE-0-2026-68226)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: cx23885: add ioremap return check and cleanup
Add a check for the return value of pci_ioremap_bar()
in cx23885_dev_setup().
If ioremap for BAR0 fails, release the already allocated
PCI memory region,
decrement the device count, and return -ENODEV.
This prevents a potential null pointer dereference and
ensures proper cleanup
on memory mapping failure.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/cx23885/cx23885-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f58f4b571bd75c78bbf15441086ba0c2830c1aa5",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "9052fec0bb84eace81ac7bad071266052870cdf3",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "6a7636e3d5204fb18fdf1c3f909a3d9d9e24064c",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "8fbdca4c99f68734e9b6c030973fb61a11bede15",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "83540d86d717735b52a43e4ba1b784da5cc2310a",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "c68c4ce72feb6fcccc843eb3baa7af60189ed567",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "ff3c670a1de3a714f5644e37b9446fe7c3299fd3",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "a0701e387b46e2481c05b47f1235b954bfc2af3e",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/cx23885/cx23885-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx23885: add ioremap return check and cleanup\n\nAdd a check for the return value of pci_ioremap_bar()\nin cx23885_dev_setup().\nIf ioremap for BAR0 fails, release the already allocated\nPCI memory region,\ndecrement the device count, and return -ENODEV.\n\nThis prevents a potential null pointer dereference and\nensures proper cleanup\non memory mapping failure."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:56.630Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f58f4b571bd75c78bbf15441086ba0c2830c1aa5"
},
{
"url": "https://git.kernel.org/stable/c/9052fec0bb84eace81ac7bad071266052870cdf3"
},
{
"url": "https://git.kernel.org/stable/c/6a7636e3d5204fb18fdf1c3f909a3d9d9e24064c"
},
{
"url": "https://git.kernel.org/stable/c/8fbdca4c99f68734e9b6c030973fb61a11bede15"
},
{
"url": "https://git.kernel.org/stable/c/83540d86d717735b52a43e4ba1b784da5cc2310a"
},
{
"url": "https://git.kernel.org/stable/c/c68c4ce72feb6fcccc843eb3baa7af60189ed567"
},
{
"url": "https://git.kernel.org/stable/c/ff3c670a1de3a714f5644e37b9446fe7c3299fd3"
},
{
"url": "https://git.kernel.org/stable/c/a0701e387b46e2481c05b47f1235b954bfc2af3e"
}
],
"title": "media: cx23885: add ioremap return check and cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68226",
"datePublished": "2026-08-10T12:00:48.349Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:31:56.630Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64257 (GCVE-0-2026-64257)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: reject overlapping data areas in SMB2 responses
Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to
responses without data area") restricted the implied bcc[0] length
exception to responses without a data area. However, the overlap
handling in __smb2_calc_size() clears data_length, which can make an
invalid response appear to have no data area and so qualify for the
exception.
Track data area overlap separately and reject such responses before
applying the length compatibility exceptions.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 31c6312608c60b72a1feb99a5afb680645a3e8a3 Version: 573e502d14714d2947e22e7eff40ec20a6a44a42 Version: 419ec1b604d7fb60c10aec2dc062371f9fcd4940 Version: ceb875a375dedbf51c9425c1d13a2d7a8435c08c Version: 6e9d10f62773b99bd927940fd9cbdfe7207e23ff Version: 53b7c271f06be4dd5cfc8c6ef552a8355c891a7f Version: 8d0bbc78046d264bbf6a574ea6f9072258a43e35 Version: b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0 Version: 5.10.261 ≤ Version: 5.15.212 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "445ece263131780dee273d727a4d6f11934feec7",
"status": "affected",
"version": "31c6312608c60b72a1feb99a5afb680645a3e8a3",
"versionType": "git"
},
{
"lessThan": "36bfa52459e45c0d5b668de2f1c91f6dc5c67775",
"status": "affected",
"version": "573e502d14714d2947e22e7eff40ec20a6a44a42",
"versionType": "git"
},
{
"lessThan": "4a9d2657d3e05f6ed09c148cb127b4e58702275f",
"status": "affected",
"version": "419ec1b604d7fb60c10aec2dc062371f9fcd4940",
"versionType": "git"
},
{
"lessThan": "fdafa1e68dc75045b7b617e6e7d2854950804d83",
"status": "affected",
"version": "ceb875a375dedbf51c9425c1d13a2d7a8435c08c",
"versionType": "git"
},
{
"lessThan": "57cba95f0e97c6f6e45e6731da30aff091bd7460",
"status": "affected",
"version": "6e9d10f62773b99bd927940fd9cbdfe7207e23ff",
"versionType": "git"
},
{
"lessThan": "8986c932905ea508d66da421eb2eb6e676ace1fe",
"status": "affected",
"version": "53b7c271f06be4dd5cfc8c6ef552a8355c891a7f",
"versionType": "git"
},
{
"status": "affected",
"version": "8d0bbc78046d264bbf6a574ea6f9072258a43e35",
"versionType": "git"
},
{
"status": "affected",
"version": "b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0",
"versionType": "git"
},
{
"lessThan": "5.11",
"status": "affected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.212",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux"
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.10.261",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.212",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: reject overlapping data areas in SMB2 responses\n\nCommit 53b7c271f06b (\"smb: client: restrict implied bcc[0] exemption to\nresponses without data area\") restricted the implied bcc[0] length\nexception to responses without a data area. However, the overlap\nhandling in __smb2_calc_size() clears data_length, which can make an\ninvalid response appear to have no data area and so qualify for the\nexception.\n\nTrack data area overlap separately and reject such responses before\napplying the length compatibility exceptions."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious or compromised SMB server can deliver the crafted SMB2 response over TCP during client negotiation.\nAC:L - The overlapping offset and oversized length are attacker-controlled and deterministically bypass validation; no race or uncontrolled memory layout is required to trigger the out-of-bounds read.\nPR:N - The vulnerable NEGOTIATE response is processed before SMB authentication or signature verification, requiring no privileges or credentials on the target.\nUI:N - An already configured SMB mount can negotiate during automatic mounting or reconnection without a human opening crafted content.\nS:U - The vulnerable parser and the affected kernel memory remain within the Linux kernel\u0027s security authority.\nC:H - The validation mismatch permits an attacker-controlled ASN.1 length to read far beyond the 448-byte receive object, potentially traversing tens of kilobytes of adjacent kernel memory.\nI:N - The investigated paths provide an out-of-bounds read but no out-of-bounds write, use-after-free, type confusion, or other arbitrary modification primitive.\nA:H - The slab out-of-bounds access is repeatable and can produce a kernel fault or panic, particularly on hardened or memory-safety-instrumented deployments."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:09.787Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/445ece263131780dee273d727a4d6f11934feec7"
},
{
"url": "https://git.kernel.org/stable/c/36bfa52459e45c0d5b668de2f1c91f6dc5c67775"
},
{
"url": "https://git.kernel.org/stable/c/4a9d2657d3e05f6ed09c148cb127b4e58702275f"
},
{
"url": "https://git.kernel.org/stable/c/fdafa1e68dc75045b7b617e6e7d2854950804d83"
},
{
"url": "https://git.kernel.org/stable/c/57cba95f0e97c6f6e45e6731da30aff091bd7460"
},
{
"url": "https://git.kernel.org/stable/c/8986c932905ea508d66da421eb2eb6e676ace1fe"
}
],
"title": "smb: client: reject overlapping data areas in SMB2 responses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64257",
"datePublished": "2026-07-25T08:49:09.345Z",
"dateReserved": "2026-07-19T15:36:31.773Z",
"dateUpdated": "2026-08-17T04:52:09.787Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64486 (GCVE-0-2026-64486)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: cmipci: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails.
snd_cmipci_spdif_controls() does not check the return value before
dereferencing kctl->id.device, which can lead to a NULL pointer
dereference.
Add NULL checks after snd_ctl_new1() calls and return -ENOMEM if any
fails.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3454490e0396191f8f9c215fccf5deef76abffb5 Version: f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 Version: f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 Version: f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 Version: f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 Version: f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 Version: 7bf12707fa3db4c14fbe8ab93efb421d8ca93bf8 Version: 6.1.34 ≤ Version: 6.3.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/pci/cmipci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b44888c33c4f11277d0e5e023338f2740232a4ed",
"status": "affected",
"version": "3454490e0396191f8f9c215fccf5deef76abffb5",
"versionType": "git"
},
{
"lessThan": "8825a06bfa7932a7a74dec01669d405df0b47286",
"status": "affected",
"version": "f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9",
"versionType": "git"
},
{
"lessThan": "4dd5b0b1a52a8d6e59a3f217204817228ce0238b",
"status": "affected",
"version": "f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9",
"versionType": "git"
},
{
"lessThan": "af2b009b773bc42995546507963e5e78970dc3ed",
"status": "affected",
"version": "f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9",
"versionType": "git"
},
{
"lessThan": "67e9ea92cd598cba1783ff701553c776a6cedee9",
"status": "affected",
"version": "f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9",
"versionType": "git"
},
{
"lessThan": "c205bd1b28fb7e5f1061a4e78813fad7d315cb3e",
"status": "affected",
"version": "f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9",
"versionType": "git"
},
{
"status": "affected",
"version": "7bf12707fa3db4c14fbe8ab93efb421d8ca93bf8",
"versionType": "git"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.34",
"versionType": "semver"
},
{
"lessThan": "6.4",
"status": "affected",
"version": "6.3.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/pci/cmipci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: cmipci: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_cmipci_spdif_controls() does not check the return value before\ndereferencing kctl-\u003eid.device, which can lead to a NULL pointer\ndereference.\n\nAdd NULL checks after snd_ctl_new1() calls and return -ENOMEM if any\nfails."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:33.629Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b44888c33c4f11277d0e5e023338f2740232a4ed"
},
{
"url": "https://git.kernel.org/stable/c/8825a06bfa7932a7a74dec01669d405df0b47286"
},
{
"url": "https://git.kernel.org/stable/c/4dd5b0b1a52a8d6e59a3f217204817228ce0238b"
},
{
"url": "https://git.kernel.org/stable/c/af2b009b773bc42995546507963e5e78970dc3ed"
},
{
"url": "https://git.kernel.org/stable/c/67e9ea92cd598cba1783ff701553c776a6cedee9"
},
{
"url": "https://git.kernel.org/stable/c/c205bd1b28fb7e5f1061a4e78813fad7d315cb3e"
}
],
"title": "ALSA: cmipci: check snd_ctl_new1() return value",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64486",
"datePublished": "2026-07-25T08:51:45.982Z",
"dateReserved": "2026-07-19T15:36:31.792Z",
"dateUpdated": "2026-08-17T04:56:33.629Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68243 (GCVE-0-2026-68243)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
Setting context engine slot N into I915_ENGINE_CLASS_INVALID /
I915_ENGINE_CLASS_INVALID_NONE and attempting to apply
I915_CONTEXT_PARAM_SSEU to the same slot N will deref NULL.
Fix that.
Discovered using AI-assisted static analysis confirmed by
Intel Product Security.
(cherry picked from commit 36eda5b5c2d40da41cc0a5403c26986237cf9e87)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97a4872ef927dee301d76085cb19f6e36d4a53a4",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "b226dee4ee1fff2909f79e8ad700b7082f8d3569",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "edd2edaca52ada833c341c8b264aaea9dd93369c",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "9923c223d38fcd9602f41cc31d480e5299d9a38e",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "726f27bca93e6c83b263542669132ee1d0eb693e",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "97f236379f06a5082d37c6a764edd56bb58a94cd",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "2b56757a9a7456825eb668fde92299e01c5e2721",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU\n\nSetting context engine slot N into I915_ENGINE_CLASS_INVALID /\nI915_ENGINE_CLASS_INVALID_NONE and attempting to apply\nI915_CONTEXT_PARAM_SSEU to the same slot N will deref NULL.\nFix that.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit 36eda5b5c2d40da41cc0a5403c26986237cf9e87)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:08.740Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97a4872ef927dee301d76085cb19f6e36d4a53a4"
},
{
"url": "https://git.kernel.org/stable/c/b226dee4ee1fff2909f79e8ad700b7082f8d3569"
},
{
"url": "https://git.kernel.org/stable/c/edd2edaca52ada833c341c8b264aaea9dd93369c"
},
{
"url": "https://git.kernel.org/stable/c/9923c223d38fcd9602f41cc31d480e5299d9a38e"
},
{
"url": "https://git.kernel.org/stable/c/726f27bca93e6c83b263542669132ee1d0eb693e"
},
{
"url": "https://git.kernel.org/stable/c/97f236379f06a5082d37c6a764edd56bb58a94cd"
},
{
"url": "https://git.kernel.org/stable/c/2b56757a9a7456825eb668fde92299e01c5e2721"
}
],
"title": "drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68243",
"datePublished": "2026-08-10T12:01:09.484Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:08.740Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64312 (GCVE-0-2026-64312)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: pcrypt - restore callback for non-parallel fallback
pcrypt installs pcrypt_aead_done() on the child AEAD request before
trying to submit it through padata. If padata_do_parallel() returns
-EBUSY, pcrypt falls back to calling the child AEAD directly.
That fallback must not keep the padata completion callback. Otherwise
an asynchronous completion runs pcrypt_aead_done() even though the
request was never enrolled in padata.
Restore the original request callback and callback data before calling
the child AEAD directly. This keeps the fallback path aligned with a
direct AEAD request while leaving the parallel path unchanged.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a92ccd3618e42333ac6f150ecdac14dca298bc7a Version: 96001f52ae8c70e2c736d3e1e5dc53d5b521e5ca Version: 92834692a539b5b7f409e467a14667d64713b732 Version: 5edae7a9a35606017ee6e05911c290acee9fee5a Version: 7ddab756f2de5b7b43c122ebebdf37f400fb2b6f Version: 662f2f13e66d3883b9238b0b96b17886179e60e2 Version: 662f2f13e66d3883b9238b0b96b17886179e60e2 Version: 662f2f13e66d3883b9238b0b96b17886179e60e2 Version: dd8bf8eb5beba1e7c3b11a9a5a58ccbf345a69e6 Version: fca8aed12218f96b38e374ff264d78ea1fbd23cc Version: a8e0074ffb38c9a5964a221bb998034d016c93a2 Version: 5.10.231 ≤ Version: 5.15.174 ≤ Version: 6.1.120 ≤ Version: 6.6.64 ≤ Version: 6.12.2 ≤ Version: 4.19.325 ≤ Version: 5.4.287 ≤ Version: 6.11.11 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"crypto/pcrypt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "81ce16d938db9b88cdc231522c0358395ae8c6b5",
"status": "affected",
"version": "a92ccd3618e42333ac6f150ecdac14dca298bc7a",
"versionType": "git"
},
{
"lessThan": "3920c5f6edc341729d20d0507e466c6d3b11f372",
"status": "affected",
"version": "96001f52ae8c70e2c736d3e1e5dc53d5b521e5ca",
"versionType": "git"
},
{
"lessThan": "ae93c5b3e2a2968b56d772ca1d06615927b7cc36",
"status": "affected",
"version": "92834692a539b5b7f409e467a14667d64713b732",
"versionType": "git"
},
{
"lessThan": "82789a44415e3e31168229421b138278dfb16412",
"status": "affected",
"version": "5edae7a9a35606017ee6e05911c290acee9fee5a",
"versionType": "git"
},
{
"lessThan": "4711ca06bd169a2cbc9cc59a6de2ed512c41a880",
"status": "affected",
"version": "7ddab756f2de5b7b43c122ebebdf37f400fb2b6f",
"versionType": "git"
},
{
"lessThan": "c4bd2f4c35b0e15b6040c2f7e7e7986780c066cf",
"status": "affected",
"version": "662f2f13e66d3883b9238b0b96b17886179e60e2",
"versionType": "git"
},
{
"lessThan": "83fa1397d5853de1e27dd52ec44b068ff358ca18",
"status": "affected",
"version": "662f2f13e66d3883b9238b0b96b17886179e60e2",
"versionType": "git"
},
{
"lessThan": "ed459fe319376e876de433d12b6c6772e612ca36",
"status": "affected",
"version": "662f2f13e66d3883b9238b0b96b17886179e60e2",
"versionType": "git"
},
{
"status": "affected",
"version": "dd8bf8eb5beba1e7c3b11a9a5a58ccbf345a69e6",
"versionType": "git"
},
{
"status": "affected",
"version": "fca8aed12218f96b38e374ff264d78ea1fbd23cc",
"versionType": "git"
},
{
"status": "affected",
"version": "a8e0074ffb38c9a5964a221bb998034d016c93a2",
"versionType": "git"
},
{
"lessThan": "5.10.261",
"status": "affected",
"version": "5.10.231",
"versionType": "semver"
},
{
"lessThan": "5.15.212",
"status": "affected",
"version": "5.15.174",
"versionType": "semver"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.120",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.64",
"versionType": "semver"
},
{
"lessThan": "6.12.96",
"status": "affected",
"version": "6.12.2",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.325",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.287",
"versionType": "semver"
},
{
"lessThan": "6.12",
"status": "affected",
"version": "6.11.11",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"crypto/pcrypt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.10.231",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.15.174",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.120",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.64",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.12.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.325",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.287",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.11.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: pcrypt - restore callback for non-parallel fallback\n\npcrypt installs pcrypt_aead_done() on the child AEAD request before\ntrying to submit it through padata. If padata_do_parallel() returns\n-EBUSY, pcrypt falls back to calling the child AEAD directly.\n\nThat fallback must not keep the padata completion callback. Otherwise\nan asynchronous completion runs pcrypt_aead_done() even though the\nrequest was never enrolled in padata.\n\nRestore the original request callback and callback data before calling\nthe child AEAD directly. This keeps the fallback path aligned with a\ndirect AEAD request while leaving the parallel path unchanged."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - pcrypt is designed for network-facing IPsec use, and an inbound ESP packet can traverse xfrm_input(), esp_input(), crypto_aead_decrypt(), and pcrypt_aead_decrypt().\nAC:L - In load-responsive CPU-hotplug deployments, an attacker can flood qualifying ESP requests across repeated PADATA_RESET windows without precise timing or an uncontrollable memory-layout condition.\nPR:N - The ESP SPI is transmitted in clear, and the faulty path is reached before the child AEAD validates the integrity tag, so an unauthenticated on-path attacker needs no target-system privileges.\nUI:N - Packet delivery and asynchronous completion require no victim action.\nS:U - The failure affects the same kernel security authority processing the request and does not cross a VM, IOMMU, or sandbox boundary.\nC:N - The rejected request retains a zero padata-\u003epd pointer, producing a NULL dereference without an out-of-bounds read or information disclosure.\nI:N - The callback writes only the completion status into its valid request context before dereferencing NULL; it provides no attacker-directed corruption or write primitive.\nA:H - padata_do_serial() dereferences the uninitialized padata-\u003epd pointer, causing a kernel oops or panic that can terminate the system and can be retriggered."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:12.187Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/81ce16d938db9b88cdc231522c0358395ae8c6b5"
},
{
"url": "https://git.kernel.org/stable/c/3920c5f6edc341729d20d0507e466c6d3b11f372"
},
{
"url": "https://git.kernel.org/stable/c/ae93c5b3e2a2968b56d772ca1d06615927b7cc36"
},
{
"url": "https://git.kernel.org/stable/c/82789a44415e3e31168229421b138278dfb16412"
},
{
"url": "https://git.kernel.org/stable/c/4711ca06bd169a2cbc9cc59a6de2ed512c41a880"
},
{
"url": "https://git.kernel.org/stable/c/c4bd2f4c35b0e15b6040c2f7e7e7986780c066cf"
},
{
"url": "https://git.kernel.org/stable/c/83fa1397d5853de1e27dd52ec44b068ff358ca18"
},
{
"url": "https://git.kernel.org/stable/c/ed459fe319376e876de433d12b6c6772e612ca36"
}
],
"title": "crypto: pcrypt - restore callback for non-parallel fallback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64312",
"datePublished": "2026-07-25T08:49:43.940Z",
"dateReserved": "2026-07-19T15:36:31.779Z",
"dateUpdated": "2026-08-17T04:53:12.187Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68362 (GCVE-0-2026-68362)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
In ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set
unconditionally even when ath11k_core_qmi_firmware_ready() fails.
This leaves the driver in an inconsistent state where
initialization is considered complete although the firmware ready
handling did not finish successfully. During the subsequent SSR,
the driver enters the restart path based on this incorrect state
and dereferences uninitialized srng members, resulting in a NULL
pointer dereference.
Call trace:
ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P)
ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k]
ath11k_core_restart+0x40/0x168 [ath11k]
Fix this by:
- skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set
- setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds
- setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling
on error
Tested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/qmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "66bf998b18334ca97321433e4ab783b6ff267e9d",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "e517e207300edcf7f3a8f6c45f9155c0e419ffb9",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "d6bba659ac30d862ee7bab92862cd6e514f07521",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "e5394605f9a985cc3a8263e610ba84b33cbe7b0c",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "4abb4e284d8897176e91d7a3168ee29ed876bb41",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "e8d85672dd7e2523f774caafba8f858384e18df7",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/qmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin\n\nIn ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set\nunconditionally even when ath11k_core_qmi_firmware_ready() fails.\nThis leaves the driver in an inconsistent state where\ninitialization is considered complete although the firmware ready\nhandling did not finish successfully. During the subsequent SSR,\nthe driver enters the restart path based on this incorrect state\nand dereferences uninitialized srng members, resulting in a NULL\npointer dereference.\n\nCall trace:\n ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P)\n ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k]\n ath11k_core_restart+0x40/0x168 [ath11k]\n\nFix this by:\n- skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set\n- setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds\n- setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling\non error\n\nTested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:15.793Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/66bf998b18334ca97321433e4ab783b6ff267e9d"
},
{
"url": "https://git.kernel.org/stable/c/e517e207300edcf7f3a8f6c45f9155c0e419ffb9"
},
{
"url": "https://git.kernel.org/stable/c/d6bba659ac30d862ee7bab92862cd6e514f07521"
},
{
"url": "https://git.kernel.org/stable/c/e5394605f9a985cc3a8263e610ba84b33cbe7b0c"
},
{
"url": "https://git.kernel.org/stable/c/4abb4e284d8897176e91d7a3168ee29ed876bb41"
},
{
"url": "https://git.kernel.org/stable/c/e8d85672dd7e2523f774caafba8f858384e18df7"
}
],
"title": "wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68362",
"datePublished": "2026-08-10T12:03:39.363Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:15.793Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64388 (GCVE-0-2026-64388)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb/client: fix chown/chgrp with SMB3 POSIX Extensions
Ownership (chown) and group (chgrp) modifications were being ignored when
mounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or
CIFS_MOUNT_MODE_FROM_SID were also explicitly set.
Fix this by checking for posix_extensions in cifs_setattr_nounix() when
updating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map
and set the ownership/group information on the server.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/inode.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "550cfb8a81181331d4d0f76ab75ee58a0bf41e3e",
"status": "affected",
"version": "b326614ea2159ea5c835d320f261d05d080cd201",
"versionType": "git"
},
{
"lessThan": "760ef2c579c2609cf17fb1cd5392f64d42d43d33",
"status": "affected",
"version": "b326614ea2159ea5c835d320f261d05d080cd201",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/inode.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: fix chown/chgrp with SMB3 POSIX Extensions\n\nOwnership (chown) and group (chgrp) modifications were being ignored when\nmounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or\nCIFS_MOUNT_MODE_FROM_SID were also explicitly set.\n\nFix this by checking for posix_extensions in cifs_setattr_nounix() when\nupdating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map\nand set the ownership/group information on the server."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable branch is reached through local chown/chgrp syscalls on an already mounted SMB3 POSIX share; unsolicited SMB traffic cannot invoke it.\nAC:L - With the affected mount configuration, the client deterministically skips the ownership update and returns success; no race, heap layout, or uncontrollable timing is required.\nPR:L - A basic local user can exercise the path on accessible share objects, and noperm deliberately defers authorization to the server whose ownership check is bypassed because no request is sent. The attacker need not create the mount.\nUI:N - The attacker can invoke the syscall directly and exploit continued rights or falsely cached ownership through automated services without human action.\nS:U - The defect affects resources governed through the vulnerable kernel and mounted share without escaping a VM, sandbox, or other distinct security authority.\nC:H - Because the intended ownership change never reaches the server, the prior owner or group can retain read access to an entire data tree believed to have been transferred or revoked.\nI:H - The prior owner can retain arbitrary modification rights, while falsely cached privileged ownership can cause privileged consumers to trust or execute attacker-controlled content.\nA:H - Retained ownership of writable files or directories can permit truncation or deletion of an entire service data tree, and privileged execution through false ownership can cause a complete outage."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:40.545Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/550cfb8a81181331d4d0f76ab75ee58a0bf41e3e"
},
{
"url": "https://git.kernel.org/stable/c/760ef2c579c2609cf17fb1cd5392f64d42d43d33"
}
],
"title": "smb/client: fix chown/chgrp with SMB3 POSIX Extensions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64388",
"datePublished": "2026-07-25T08:50:36.202Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-08-17T04:54:40.545Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68324 (GCVE-0-2026-68324)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
dmar_latency_disable() intends to zero out only the single
latency_statistic entry for the given type, but the memset size was
computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire
array starting from &lstat[type].
When type > 0, this writes beyond the end of the allocated array,
corrupting adjacent memory.
Fix by using sizeof(*lstat) to clear only the target entry.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iommu/intel/perf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "80f3605991461679c298ea2045c350ee3cf36de3",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "104d89cf5b01cb66ff975d91ed42f61b3904df53",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "3078d82e7fe9048a2b90a992e71af7cd7ef881fa",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "866a35735e56b9dc81cbc33899255134adf6d8b3",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "d06fea9b85f038690f55e72fe0c45e113715a85a",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "0e28ca1c3204b51068579defc904a0dfba5e5c57",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "754f8efe45f87e3a9c6871b645b2f9d46d1b407b",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iommu/intel/perf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/intel: Fix out-of-bounds memset in dmar_latency_disable()\n\ndmar_latency_disable() intends to zero out only the single\nlatency_statistic entry for the given type, but the memset size was\ncomputed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire\narray starting from \u0026lstat[type].\n\nWhen type \u003e 0, this writes beyond the end of the allocated array,\ncorrupting adjacent memory.\n\nFix by using sizeof(*lstat) to clear only the target entry."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:15.575Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/80f3605991461679c298ea2045c350ee3cf36de3"
},
{
"url": "https://git.kernel.org/stable/c/104d89cf5b01cb66ff975d91ed42f61b3904df53"
},
{
"url": "https://git.kernel.org/stable/c/3078d82e7fe9048a2b90a992e71af7cd7ef881fa"
},
{
"url": "https://git.kernel.org/stable/c/866a35735e56b9dc81cbc33899255134adf6d8b3"
},
{
"url": "https://git.kernel.org/stable/c/d06fea9b85f038690f55e72fe0c45e113715a85a"
},
{
"url": "https://git.kernel.org/stable/c/0e28ca1c3204b51068579defc904a0dfba5e5c57"
},
{
"url": "https://git.kernel.org/stable/c/754f8efe45f87e3a9c6871b645b2f9d46d1b407b"
}
],
"title": "iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68324",
"datePublished": "2026-08-10T12:03:00.073Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:15.575Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72036 (GCVE-0-2026-72036)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-17 05:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
multiq_dequeue() takes a packet from a band's child with a direct
->dequeue() call after multiq_peek() peeked it. When the child is
non-work-conserving the peek stashes the skb in the child's gso_skb, so
the direct dequeue returns a different skb and orphans the stash,
desyncing the child's qlen/backlog. With a qfq child reached through a
peeking parent (e.g. tbf) this re-enters the child on an emptied list and
dereferences NULL, panicking the kernel from softirq on ordinary egress.
Take the packet through qdisc_dequeue_peeked(), as sch_prio already does
and as sch_red and sch_sfb were just fixed to do. The helper is a no-op
when the child has no stash, so a work-conserving child is unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 77be155cba4e163e8bba9fd27222a8b6189ec4f7 Version: 77be155cba4e163e8bba9fd27222a8b6189ec4f7 Version: 77be155cba4e163e8bba9fd27222a8b6189ec4f7 Version: 77be155cba4e163e8bba9fd27222a8b6189ec4f7 Version: 77be155cba4e163e8bba9fd27222a8b6189ec4f7 Version: 77be155cba4e163e8bba9fd27222a8b6189ec4f7 Version: 77be155cba4e163e8bba9fd27222a8b6189ec4f7 Version: 77be155cba4e163e8bba9fd27222a8b6189ec4f7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/sch_multiq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3e5fd9d14f2d228e7260251f2e4a1d41ba8f705a",
"status": "affected",
"version": "77be155cba4e163e8bba9fd27222a8b6189ec4f7",
"versionType": "git"
},
{
"lessThan": "eb1a9637f0bd84b5db8803af65dfb1f44785406f",
"status": "affected",
"version": "77be155cba4e163e8bba9fd27222a8b6189ec4f7",
"versionType": "git"
},
{
"lessThan": "7a5a1582710981ef6637de9f074a60a5b1d63222",
"status": "affected",
"version": "77be155cba4e163e8bba9fd27222a8b6189ec4f7",
"versionType": "git"
},
{
"lessThan": "86a61e46a1919e8abf4d227c204773dabb24068a",
"status": "affected",
"version": "77be155cba4e163e8bba9fd27222a8b6189ec4f7",
"versionType": "git"
},
{
"lessThan": "1b9cc255e8089606b92b2adf504e334573682821",
"status": "affected",
"version": "77be155cba4e163e8bba9fd27222a8b6189ec4f7",
"versionType": "git"
},
{
"lessThan": "5889064919a1e5c0a9469c54895000414fc46944",
"status": "affected",
"version": "77be155cba4e163e8bba9fd27222a8b6189ec4f7",
"versionType": "git"
},
{
"lessThan": "fffeb2ab5eeb823d4c2330571a098f63237c9049",
"status": "affected",
"version": "77be155cba4e163e8bba9fd27222a8b6189ec4f7",
"versionType": "git"
},
{
"lessThan": "54f6b0c843e228d499eb4b6bbb89df68cad9ad5d",
"status": "affected",
"version": "77be155cba4e163e8bba9fd27222a8b6189ec4f7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/sch_multiq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.29"
},
{
"lessThan": "2.6.29",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.29",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked\n\nmultiq_dequeue() takes a packet from a band\u0027s child with a direct\n-\u003edequeue() call after multiq_peek() peeked it. When the child is\nnon-work-conserving the peek stashes the skb in the child\u0027s gso_skb, so\nthe direct dequeue returns a different skb and orphans the stash,\ndesyncing the child\u0027s qlen/backlog. With a qfq child reached through a\npeeking parent (e.g. tbf) this re-enters the child on an emptied list and\ndereferences NULL, panicking the kernel from softirq on ordinary egress.\n\nTake the packet through qdisc_dequeue_peeked(), as sch_prio already does\nand as sch_red and sch_sfb were just fixed to do. The helper is a no-op\nwhen the child has no stash, so a work-conserving child is unaffected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires locally installing a tbf\u2192multiq\u2192qfq hierarchy on a multiqueue netdev via RTM_NEWQDISC/tc netlink before egress can hit multiq_dequeue(); per kernel CNA guidance, tc/qdisc configuration bugs are Local even though the panic fires from softirq during packet transmission.\nAC:L - Once the hierarchy exists, the peek/dequeue mismatch is a deterministic logic bug: tbf peek stashes the QFQ child\u0027s skb in gso_skb, then multiq_dequeue\u0027s direct child-\u003edequeue() bypasses that stash and re-enters QFQ on an emptied list; ping reproducers for sch_red/sfb show no race or layout dependency.\nPR:L - RTM_NEWQDISC and qdisc grafting are gated by netlink_net_capable(skb, CAP_NET_ADMIN) in rtnetlink_rcv_msg, evaluated against net-\u003euser_ns; unprivileged users obtain CAP_NET_ADMIN via user/network namespaces (unshare -Urn) without init-namespace root.\nUI:N - No victim interaction is needed after qdisc setup; triggering the NULL dereference requires only attacker-generated egress traffic (e.g., ping) through the defective tbf\u2192multiq\u2192qfq dequeue path.\nS:U - The qlen/backlog desync, orphaned gso_skb stash, and resulting kernel panic occur entirely within the host kernel packet scheduler; no VM, IOMMU, or sandbox security boundary is crossed.\nC:H - Peek stashes the skb in the non-work-conserving child\u0027s gso_skb while direct dequeue returns a different packet, desyncing qlen/backlog\u2014the same scheduler-accounting corruption primitive seen in prior net/sched CVEs and capable of exposing corrupted or freed kernel scheduler memory.\nI:H - Orphaning the gso_skb stash corrupts parent/child queue linkage and QFQ aggregate scheduling state; inconsistent qlen drives invalid list operations in qfq_dequeue, yielding attacker-influenced memory corruption beyond the demonstrated NULL dereference.\nA:H - The desync re-enters QFQ on an emptied aggregate list and dereferences NULL in qfq_dequeue from softirq during ordinary egress, panicking the kernel as documented in the fix commit and matching KASAN null-ptr-deref traces in the related sch_red/sch_sfb reports."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:39:39.361Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3e5fd9d14f2d228e7260251f2e4a1d41ba8f705a"
},
{
"url": "https://git.kernel.org/stable/c/eb1a9637f0bd84b5db8803af65dfb1f44785406f"
},
{
"url": "https://git.kernel.org/stable/c/7a5a1582710981ef6637de9f074a60a5b1d63222"
},
{
"url": "https://git.kernel.org/stable/c/86a61e46a1919e8abf4d227c204773dabb24068a"
},
{
"url": "https://git.kernel.org/stable/c/1b9cc255e8089606b92b2adf504e334573682821"
},
{
"url": "https://git.kernel.org/stable/c/5889064919a1e5c0a9469c54895000414fc46944"
},
{
"url": "https://git.kernel.org/stable/c/fffeb2ab5eeb823d4c2330571a098f63237c9049"
},
{
"url": "https://git.kernel.org/stable/c/54f6b0c843e228d499eb4b6bbb89df68cad9ad5d"
}
],
"title": "net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72036",
"datePublished": "2026-08-15T05:51:57.012Z",
"dateReserved": "2026-08-09T03:40:39.901Z",
"dateUpdated": "2026-08-17T05:39:39.361Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64131 (GCVE-0-2026-64131)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/memory: fix spurious warning when unmapping device-private/exclusive pages
Device private and exclusive entries are only supported for anonymous
folios. This condition is tested in __migrate_device_pages() and
make_device_exclusive() using folio_test_anon(). However the unmap path
tests this assumption using vma_is_anonymous().
This is wrong because whilst anonymous VMAs can only contain folios where
folio_test_anon() is true the opposite relation does not hold. A folio
for which folio_test_anon() is true does not imply vma_is_anonymous() is
true. Such a condition can occur if for example a folio is part of a
private filebacked mapping.
In this case vma_is_anonymous() is false as the mapping is filebacked, but
folio_test_anon() may be true, thus permitting devices to migrate the
folio to device private memory. This can lead to the following spurious
warnings during process teardown:
[ 772.737706] ------------[ cut here ]------------
[ 772.739201] WARNING: mm/memory.c:1754 at unmap_page_range.cold+0x26/0x18a, CPU#17: hmm-tests/2041
[ 772.742050] Modules linked in: test_hmm nvidia_uvm(O) nvidia(O)
[ 772.743959] CPU: 17 UID: 0 PID: 2041 Comm: hmm-tests Tainted: G W O 7.0.0+ #387 PREEMPT(full)
[ 772.747104] Tainted: [W]=WARN, [O]=OOT_MODULE
[ 772.748509] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014
[ 772.752117] RIP: 0010:unmap_page_range.cold+0x26/0x18a
[ 772.753780] Code: 7e fe ff ff 48 89 4c 24 78 4c 89 44 24 38 e8 f2 ff b1 00 48 8b 4c 24 78 4c 8b 44 24 38 48 8b 44 24 18 48 83 78 48 00 74 04 90 <0f> 0b 90 48 89 ca b8 ff ff 37 00 48 c1 ea 03 48 c1 e0 2a 80 3c 02
[ 772.759602] RSP: 0018:ffff888112607550 EFLAGS: 00010286
[ 772.761310] RAX: ffff88811bbf4dc0 RBX: dffffc0000000000 RCX: ffffea03e9bfffd8
[ 772.763583] RDX: 1ffff1102377e9c1 RSI: 0000000000000008 RDI: ffff88811bbf4e08
[ 772.765914] RBP: 0000000000000006 R08: ffff8881059f7448 R09: ffffed10224c0e68
[ 772.768184] R10: ffff888112607347 R11: 0000000000000001 R12: 0000000000000001
[ 772.770461] R13: ffffea03e9bfffc0 R14: ffff888112607908 R15: ffffea03e9bfffc0
[ 772.772782] FS: 00007f327caa2780(0000) GS:ffff888427b7d000(0000) knlGS:0000000000000000
[ 772.775328] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 772.777187] CR2: 00007f327ca89000 CR3: 00000001994d5000 CR4: 00000000000006f0
[ 772.779135] Call Trace:
[ 772.779792] <TASK>
[ 772.780317] ? dmirror_interval_invalidate+0x1a3/0x290 [test_hmm]
[ 772.781873] ? vm_normal_page_pud+0x2b0/0x2b0
[ 772.782992] ? __rwlock_init+0x150/0x150
[ 772.784006] ? lock_release+0x216/0x2b0
[ 772.785008] ? __mmu_notifier_invalidate_range_start+0x505/0x6e0
[ 772.786522] ? lock_release+0x216/0x2b0
[ 772.787498] ? unmap_single_vma+0xb6/0x210
[ 772.788573] unmap_vmas+0x27d/0x520
[ 772.789506] ? unmap_single_vma+0x210/0x210
[ 772.790607] ? mas_update_gap.part.0+0x620/0x620
[ 772.791834] unmap_region+0x19e/0x350
[ 772.792769] ? remove_vma+0x130/0x130
[ 772.793684] ? mas_alloc_nodes+0x1f2/0x300
[ 772.794730] vms_complete_munmap_vmas+0x8c1/0xe20
[ 772.795926] ? unmap_region+0x350/0x350
[ 772.796917] do_vmi_align_munmap+0x36a/0x4e0
[ 772.798018] ? lock_release+0x216/0x2b0
[ 772.799024] ? vma_shrink+0x620/0x620
[ 772.799983] do_vmi_munmap+0x150/0x2c0
[ 772.800939] __vm_munmap+0x161/0x2c0
[ 772.801872] ? expand_downwards+0xd60/0xd60
[ 772.802948] ? clockevents_program_event+0x1ef/0x540
[ 772.804217] ? lock_release+0x216/0x2b0
[ 772.805158] __x64_sys_munmap+0x59/0x80
[ 772.805776] do_syscall_64+0xfc/0x670
[ 772.806336] ? irqentry_exit+0xda/0x580
[ 772.806976] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 772.807772] RIP: 0033:0x7f327cbb2717
[ 772.808323] Code: 73 01 c3 48 8b 0d f9 76 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 0b 00 00 00 0f 05 <48> 3d 01 f0 ff
---truncated---
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 999dad824c39ed14dee7c4412aae531ba9e74a90 Version: 999dad824c39ed14dee7c4412aae531ba9e74a90 Version: 999dad824c39ed14dee7c4412aae531ba9e74a90 Version: 999dad824c39ed14dee7c4412aae531ba9e74a90 Version: 999dad824c39ed14dee7c4412aae531ba9e74a90 Version: 999dad824c39ed14dee7c4412aae531ba9e74a90 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/memory.c",
"tools/testing/selftests/mm/hmm-tests.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e81446b559db4c98a6c2c5e039ac9cb23658432e",
"status": "affected",
"version": "999dad824c39ed14dee7c4412aae531ba9e74a90",
"versionType": "git"
},
{
"lessThan": "e7af1b15c884ed12bb69da11aec095045d861ee8",
"status": "affected",
"version": "999dad824c39ed14dee7c4412aae531ba9e74a90",
"versionType": "git"
},
{
"lessThan": "a825691b804b35141aaf4eac91003a70846e316d",
"status": "affected",
"version": "999dad824c39ed14dee7c4412aae531ba9e74a90",
"versionType": "git"
},
{
"lessThan": "2fff0cdd942261497fb8922a194b4da3315ae864",
"status": "affected",
"version": "999dad824c39ed14dee7c4412aae531ba9e74a90",
"versionType": "git"
},
{
"lessThan": "52f72b3f8f6fa64abb71b711962b97f1f6aced1c",
"status": "affected",
"version": "999dad824c39ed14dee7c4412aae531ba9e74a90",
"versionType": "git"
},
{
"lessThan": "be3f38d05cc5a7c3f13e51994c5dd043ab604d28",
"status": "affected",
"version": "999dad824c39ed14dee7c4412aae531ba9e74a90",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/memory.c",
"tools/testing/selftests/mm/hmm-tests.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/memory: fix spurious warning when unmapping device-private/exclusive pages\n\nDevice private and exclusive entries are only supported for anonymous\nfolios. This condition is tested in __migrate_device_pages() and\nmake_device_exclusive() using folio_test_anon(). However the unmap path\ntests this assumption using vma_is_anonymous().\n\nThis is wrong because whilst anonymous VMAs can only contain folios where\nfolio_test_anon() is true the opposite relation does not hold. A folio\nfor which folio_test_anon() is true does not imply vma_is_anonymous() is\ntrue. Such a condition can occur if for example a folio is part of a\nprivate filebacked mapping.\n\nIn this case vma_is_anonymous() is false as the mapping is filebacked, but\nfolio_test_anon() may be true, thus permitting devices to migrate the\nfolio to device private memory. This can lead to the following spurious\nwarnings during process teardown:\n\n[ 772.737706] ------------[ cut here ]------------\n[ 772.739201] WARNING: mm/memory.c:1754 at unmap_page_range.cold+0x26/0x18a, CPU#17: hmm-tests/2041\n[ 772.742050] Modules linked in: test_hmm nvidia_uvm(O) nvidia(O)\n[ 772.743959] CPU: 17 UID: 0 PID: 2041 Comm: hmm-tests Tainted: G W O 7.0.0+ #387 PREEMPT(full)\n[ 772.747104] Tainted: [W]=WARN, [O]=OOT_MODULE\n[ 772.748509] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n[ 772.752117] RIP: 0010:unmap_page_range.cold+0x26/0x18a\n[ 772.753780] Code: 7e fe ff ff 48 89 4c 24 78 4c 89 44 24 38 e8 f2 ff b1 00 48 8b 4c 24 78 4c 8b 44 24 38 48 8b 44 24 18 48 83 78 48 00 74 04 90 \u003c0f\u003e 0b 90 48 89 ca b8 ff ff 37 00 48 c1 ea 03 48 c1 e0 2a 80 3c 02\n[ 772.759602] RSP: 0018:ffff888112607550 EFLAGS: 00010286\n[ 772.761310] RAX: ffff88811bbf4dc0 RBX: dffffc0000000000 RCX: ffffea03e9bfffd8\n[ 772.763583] RDX: 1ffff1102377e9c1 RSI: 0000000000000008 RDI: ffff88811bbf4e08\n[ 772.765914] RBP: 0000000000000006 R08: ffff8881059f7448 R09: ffffed10224c0e68\n[ 772.768184] R10: ffff888112607347 R11: 0000000000000001 R12: 0000000000000001\n[ 772.770461] R13: ffffea03e9bfffc0 R14: ffff888112607908 R15: ffffea03e9bfffc0\n[ 772.772782] FS: 00007f327caa2780(0000) GS:ffff888427b7d000(0000) knlGS:0000000000000000\n[ 772.775328] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 772.777187] CR2: 00007f327ca89000 CR3: 00000001994d5000 CR4: 00000000000006f0\n[ 772.779135] Call Trace:\n[ 772.779792] \u003cTASK\u003e\n[ 772.780317] ? dmirror_interval_invalidate+0x1a3/0x290 [test_hmm]\n[ 772.781873] ? vm_normal_page_pud+0x2b0/0x2b0\n[ 772.782992] ? __rwlock_init+0x150/0x150\n[ 772.784006] ? lock_release+0x216/0x2b0\n[ 772.785008] ? __mmu_notifier_invalidate_range_start+0x505/0x6e0\n[ 772.786522] ? lock_release+0x216/0x2b0\n[ 772.787498] ? unmap_single_vma+0xb6/0x210\n[ 772.788573] unmap_vmas+0x27d/0x520\n[ 772.789506] ? unmap_single_vma+0x210/0x210\n[ 772.790607] ? mas_update_gap.part.0+0x620/0x620\n[ 772.791834] unmap_region+0x19e/0x350\n[ 772.792769] ? remove_vma+0x130/0x130\n[ 772.793684] ? mas_alloc_nodes+0x1f2/0x300\n[ 772.794730] vms_complete_munmap_vmas+0x8c1/0xe20\n[ 772.795926] ? unmap_region+0x350/0x350\n[ 772.796917] do_vmi_align_munmap+0x36a/0x4e0\n[ 772.798018] ? lock_release+0x216/0x2b0\n[ 772.799024] ? vma_shrink+0x620/0x620\n[ 772.799983] do_vmi_munmap+0x150/0x2c0\n[ 772.800939] __vm_munmap+0x161/0x2c0\n[ 772.801872] ? expand_downwards+0xd60/0xd60\n[ 772.802948] ? clockevents_program_event+0x1ef/0x540\n[ 772.804217] ? lock_release+0x216/0x2b0\n[ 772.805158] __x64_sys_munmap+0x59/0x80\n[ 772.805776] do_syscall_64+0xfc/0x670\n[ 772.806336] ? irqentry_exit+0xda/0x580\n[ 772.806976] entry_SYSCALL_64_after_hwframe+0x4b/0x53\n[ 772.807772] RIP: 0033:0x7f327cbb2717\n[ 772.808323] Code: 73 01 c3 48 8b 0d f9 76 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 0b 00 00 00 0f 05 \u003c48\u003e 3d 01 f0 ff\n---truncated---"
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:26.854Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e81446b559db4c98a6c2c5e039ac9cb23658432e"
},
{
"url": "https://git.kernel.org/stable/c/e7af1b15c884ed12bb69da11aec095045d861ee8"
},
{
"url": "https://git.kernel.org/stable/c/a825691b804b35141aaf4eac91003a70846e316d"
},
{
"url": "https://git.kernel.org/stable/c/2fff0cdd942261497fb8922a194b4da3315ae864"
},
{
"url": "https://git.kernel.org/stable/c/52f72b3f8f6fa64abb71b711962b97f1f6aced1c"
},
{
"url": "https://git.kernel.org/stable/c/be3f38d05cc5a7c3f13e51994c5dd043ab604d28"
}
],
"title": "mm/memory: fix spurious warning when unmapping device-private/exclusive pages",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64131",
"datePublished": "2026-07-19T15:40:26.854Z",
"dateReserved": "2026-07-19T07:54:57.036Z",
"dateUpdated": "2026-07-19T15:40:26.854Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64381 (GCVE-0-2026-64381)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: Fix next buffer leak in receive_encrypted_standard()
receive_encrypted_standard() allocates next_buffer before checking
whether the number of compound PDUs already reached MAX_COMPOUND. If
the limit check fails, the function returns immediately and the newly
allocated next_buffer is not assigned to server->smallbuf/server->bigbuf,
making it leaked.
Move the MAX_COMPOUND check before allocating next_buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b24df3e30cbf48255db866720fb71f14bf9d2f39 Version: b24df3e30cbf48255db866720fb71f14bf9d2f39 Version: b24df3e30cbf48255db866720fb71f14bf9d2f39 Version: b24df3e30cbf48255db866720fb71f14bf9d2f39 Version: b24df3e30cbf48255db866720fb71f14bf9d2f39 Version: b24df3e30cbf48255db866720fb71f14bf9d2f39 Version: b24df3e30cbf48255db866720fb71f14bf9d2f39 Version: b24df3e30cbf48255db866720fb71f14bf9d2f39 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "94e4f672db029414b9888b5137a7559f1febf2d8",
"status": "affected",
"version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
"versionType": "git"
},
{
"lessThan": "68fc0b6cc03ca58060c0f36454e169f5fe258974",
"status": "affected",
"version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
"versionType": "git"
},
{
"lessThan": "07e0ab81df1790afa35732a4e8e07ff831b29008",
"status": "affected",
"version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
"versionType": "git"
},
{
"lessThan": "9136a08dc29328edd9867f2545e73906ac9df93b",
"status": "affected",
"version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
"versionType": "git"
},
{
"lessThan": "67097772df7791c53d608f04bd31c676ccf79b83",
"status": "affected",
"version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
"versionType": "git"
},
{
"lessThan": "297243e365fc9fe2f8e9b7dd535a65d922cd108b",
"status": "affected",
"version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
"versionType": "git"
},
{
"lessThan": "927d4805aea0a287d36dd4f826ee24d69a2afee3",
"status": "affected",
"version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
"versionType": "git"
},
{
"lessThan": "1c6267a1d5cf4c73b656f8181b310cbbb3e4767b",
"status": "affected",
"version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix next buffer leak in receive_encrypted_standard()\n\nreceive_encrypted_standard() allocates next_buffer before checking\nwhether the number of compound PDUs already reached MAX_COMPOUND. If\nthe limit check fails, the function returns immediately and the newly\nallocated next_buffer is not assigned to server-\u003esmallbuf/server-\u003ebigbuf,\nmaking it leaked.\n\nMove the MAX_COMPOUND check before allocating next_buffer."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:32.853Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/94e4f672db029414b9888b5137a7559f1febf2d8"
},
{
"url": "https://git.kernel.org/stable/c/68fc0b6cc03ca58060c0f36454e169f5fe258974"
},
{
"url": "https://git.kernel.org/stable/c/07e0ab81df1790afa35732a4e8e07ff831b29008"
},
{
"url": "https://git.kernel.org/stable/c/9136a08dc29328edd9867f2545e73906ac9df93b"
},
{
"url": "https://git.kernel.org/stable/c/67097772df7791c53d608f04bd31c676ccf79b83"
},
{
"url": "https://git.kernel.org/stable/c/297243e365fc9fe2f8e9b7dd535a65d922cd108b"
},
{
"url": "https://git.kernel.org/stable/c/927d4805aea0a287d36dd4f826ee24d69a2afee3"
},
{
"url": "https://git.kernel.org/stable/c/1c6267a1d5cf4c73b656f8181b310cbbb3e4767b"
}
],
"title": "smb: client: Fix next buffer leak in receive_encrypted_standard()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64381",
"datePublished": "2026-07-25T08:50:31.209Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-08-17T04:54:32.853Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74518 (GCVE-0-2026-74518)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: fix list corruption in allocate_file_region_entries()
allocate_file_region_entries() tops up resv->region_cache with freshly
allocated file_region descriptors. The allocation uses GFP_KERNEL, so
resv->lock is dropped around it: the new entries are gathered on a
stack-local list head, allocated_regions, and spliced into
resv->region_cache once the lock is re-acquired.
The splice used list_splice(), which moves the entries but does not
re-initialize the source head, so allocated_regions is left pointing at an
entry that now lives on resv->region_cache. The top-up runs in a while
loop that re-checks the cache deficit after re-acquiring the lock. For a
shared mapping the resv_map is shared by every mapper of the hugetlbfs
inode, so a concurrent region_chg()/region_add()/region_del() on the same
resv_map can consume cache entries during the unlocked window and force a
second iteration. That iteration calls list_add() on the stale head and
corrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check
trips:
list_add corruption. next->prev should be prev (ffffc900011ff7f8),
but was ffff88814c281460. (next=ffff88814c545640).
kernel BUG at lib/list_debug.c:31!
allocate_file_region_entries+0x191/0x420
region_chg+0x267/0x300
hugetlb_reserve_pages+0x387/0xc80
hugetlbfs_file_mmap+0x2ce/0x3f0
mmap_region+0x1348/0x1a80
do_mmap+0x85e/0xb90
vm_mmap_pgoff+0x18c/0x330
ksys_mmap_pgoff+0x2a1/0x3e0
do_syscall_64+0xd7/0x420
Without CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack
address into resv->region_cache, leading to later use-after-free.
This was observed as a real host panic on a dense KVM host where a QEMU
guest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate
SPDK/DPDK vhost-user target, generating concurrent region_* traffic on one
shared resv_map.
Use list_splice_init() so the source head is re-initialized empty after
each splice, making the retry loop safe.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/hugetlb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "01b8569233e47693d6ff7efa96d9854c55f936fc",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "9c5fdffc5e1ce84403c58289ee72697051803bf7",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "f3e54f6a5e1681f83d13e8716bc92ef5ecf121d3",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "62e1c2741a4d923d9854efd5927a6212aad7a187",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "587a0accc2b4fccc5cf7baf0fe34e50efde51f9c",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "126a70bf1a08ddc9d79c471ebdaa2b08cfbab8df",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "ac1bb7fd45088d0db57a22ce7729f258ebd63cf5",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "dd9623f58ec702a07b2d67179d6fcea79c52231a",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/hugetlb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix list corruption in allocate_file_region_entries()\n\nallocate_file_region_entries() tops up resv-\u003eregion_cache with freshly\nallocated file_region descriptors. The allocation uses GFP_KERNEL, so\nresv-\u003elock is dropped around it: the new entries are gathered on a\nstack-local list head, allocated_regions, and spliced into\nresv-\u003eregion_cache once the lock is re-acquired.\n\nThe splice used list_splice(), which moves the entries but does not\nre-initialize the source head, so allocated_regions is left pointing at an\nentry that now lives on resv-\u003eregion_cache. The top-up runs in a while\nloop that re-checks the cache deficit after re-acquiring the lock. For a\nshared mapping the resv_map is shared by every mapper of the hugetlbfs\ninode, so a concurrent region_chg()/region_add()/region_del() on the same\nresv_map can consume cache entries during the unlocked window and force a\nsecond iteration. That iteration calls list_add() on the stale head and\ncorrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check\ntrips:\n\n list_add corruption. next-\u003eprev should be prev (ffffc900011ff7f8),\n but was ffff88814c281460. (next=ffff88814c545640).\n kernel BUG at lib/list_debug.c:31!\n allocate_file_region_entries+0x191/0x420\n region_chg+0x267/0x300\n hugetlb_reserve_pages+0x387/0xc80\n hugetlbfs_file_mmap+0x2ce/0x3f0\n mmap_region+0x1348/0x1a80\n do_mmap+0x85e/0xb90\n vm_mmap_pgoff+0x18c/0x330\n ksys_mmap_pgoff+0x2a1/0x3e0\n do_syscall_64+0xd7/0x420\n\nWithout CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack\naddress into resv-\u003eregion_cache, leading to later use-after-free.\n\nThis was observed as a real host panic on a dense KVM host where a QEMU\nguest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate\nSPDK/DPDK vhost-user target, generating concurrent region_* traffic on one\nshared resv_map.\n\nUse list_splice_init() so the source head is re-initialized empty after\neach splice, making the retry loop safe."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local hugetlb reservation paths (mmap/memfd_create/fault syscalls into region_chg/region_add/region_del); no network protocol or remote packet handler invokes allocate_file_region_entries().\nAC:L - Exploitation needs a race while resv-\u003elock is dropped during GFP_KERNEL allocation, but an attacker can spawn concurrent MAP_SHARED mappers/faulters on one hugetlb inode and controls both sides of that race.\nPR:L - Unprivileged local users can trigger this via memfd_create(MFD_HUGETLB) plus MAP_SHARED mmap/fault activity, or by mapping accessible shared hugetlbfs files, without init-namespace root or special capabilities.\nUI:N - No victim interaction is required; the attacker drives the needed concurrent syscalls and shared hugetlb mappings themselves to hit the corrupted list splice retry path.\nS:U - Impact is kernel hugetlb resv_map list/memory corruption on the host; it does not by itself cross a VM, IOMMU, or separate security-authority boundary even though KVM/DPDK hosts are a prime deployment.\nC:H - Without CONFIG_DEBUG_LIST, stale list_splice leaves a kernel-stack pointer in resv-\u003eregion_cache, producing later use-after-free that can be turned into arbitrary kernel memory read/disclosure primitives.\nI:H - Corrupted region_cache pointers let subsequent region_add/region_del/cache operations write through attacker-influenced list links, enabling heap metadata corruption and potential arbitrary kernel write or code execution.\nA:H - Real host panics were reported on dense KVM hugetlb workloads; DEBUG_LIST kernels BUG on list_add corruption, and default builds can crash from UAF while walking the poisoned region_cache."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:19.402Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/01b8569233e47693d6ff7efa96d9854c55f936fc"
},
{
"url": "https://git.kernel.org/stable/c/9c5fdffc5e1ce84403c58289ee72697051803bf7"
},
{
"url": "https://git.kernel.org/stable/c/f3e54f6a5e1681f83d13e8716bc92ef5ecf121d3"
},
{
"url": "https://git.kernel.org/stable/c/62e1c2741a4d923d9854efd5927a6212aad7a187"
},
{
"url": "https://git.kernel.org/stable/c/587a0accc2b4fccc5cf7baf0fe34e50efde51f9c"
},
{
"url": "https://git.kernel.org/stable/c/126a70bf1a08ddc9d79c471ebdaa2b08cfbab8df"
},
{
"url": "https://git.kernel.org/stable/c/ac1bb7fd45088d0db57a22ce7729f258ebd63cf5"
},
{
"url": "https://git.kernel.org/stable/c/dd9623f58ec702a07b2d67179d6fcea79c52231a"
}
],
"title": "mm/hugetlb: fix list corruption in allocate_file_region_entries()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74518",
"datePublished": "2026-08-15T12:27:37.480Z",
"dateReserved": "2026-08-15T05:44:03.910Z",
"dateUpdated": "2026-08-19T16:38:19.402Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74318 (GCVE-0-2026-74318)
Vulnerability from cvelistv5
Published
2026-08-15 05:58
Modified
2026-08-17 05:17
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix deadlock cloning inline extent when using flushoncommit
In commit b48c980b6a7e ("btrfs: fix deadlock between reflink and
transaction commit when using flushoncommit") a deadlock was fixed
between reflinks and transaction commits when the fs is mounted with the
flushoncommit option. This happened when we had to copy an inline extent's
data to the destination file. However the issue was fixed only for the
case where the destination offset is 0, it missed the case when the offset
is greater than zero.
Fix this by ensuring we get i_size update whenever we copied an inline
extent's data into the destination file.
Syzbot reported this with the following trace:
INFO: task kworker/u8:3:57 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:kworker/u8:3 state:D stack:21600 pid:57 tgid:57 ppid:2 task_flags:0x4208160 flags:0x00080000
Workqueue: writeback wb_workfn (flush-btrfs-129)
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5402 [inline]
__schedule+0x16f9/0x5500 kernel/sched/core.c:7204
__schedule_loop kernel/sched/core.c:7283 [inline]
schedule+0x164/0x360 kernel/sched/core.c:7298
wait_extent_bit fs/btrfs/extent-io-tree.c:905 [inline]
btrfs_lock_extent_bits+0x59c/0x700 fs/btrfs/extent-io-tree.c:2008
btrfs_lock_extent fs/btrfs/extent-io-tree.h:152 [inline]
btrfs_invalidate_folio+0x440/0xc00 fs/btrfs/inode.c:7718
extent_writepage fs/btrfs/extent_io.c:1848 [inline]
extent_write_cache_pages fs/btrfs/extent_io.c:2552 [inline]
btrfs_writepages+0x12f3/0x2410 fs/btrfs/extent_io.c:2684
do_writepages+0x32e/0x550 mm/page-writeback.c:2571
__writeback_single_inode+0x133/0x10e0 fs/fs-writeback.c:1764
writeback_sb_inodes+0x97f/0x1980 fs/fs-writeback.c:2056
wb_writeback+0x445/0xb00 fs/fs-writeback.c:2241
wb_do_writeback fs/fs-writeback.c:2388 [inline]
wb_workfn+0x3fd/0xf20 fs/fs-writeback.c:2428
process_one_work+0x98b/0x1630 kernel/workqueue.c:3318
process_scheduled_works kernel/workqueue.c:3401 [inline]
worker_thread+0xb49/0x1140 kernel/workqueue.c:3482
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
INFO: task syz.0.145:8523 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz.0.145 state:D stack:22752 pid:8523 tgid:8522 ppid:5850 task_flags:0x400140 flags:0x00080002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5402 [inline]
__schedule+0x16f9/0x5500 kernel/sched/core.c:7204
__schedule_loop kernel/sched/core.c:7283 [inline]
schedule+0x164/0x360 kernel/sched/core.c:7298
wb_wait_for_completion+0x3e8/0x790 fs/fs-writeback.c:227
__writeback_inodes_sb_nr+0x24c/0x2d0 fs/fs-writeback.c:2847
try_to_writeback_inodes_sb+0x9a/0xc0 fs/fs-writeback.c:2895
btrfs_start_delalloc_flush fs/btrfs/transaction.c:2182 [inline]
btrfs_commit_transaction+0x813/0x2fc0 fs/btrfs/transaction.c:2371
btrfs_sync_file+0xdf4/0x1230 fs/btrfs/file.c:1822
generic_write_sync include/linux/fs.h:2663 [inline]
btrfs_do_write_iter+0x6a9/0x840 fs/btrfs/file.c:1473
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x629/0xba0 fs/read_write.c:688
ksys_write+0x156/0x270 fs/read_write.c:740
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x15f/0x560 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f5a0bdece59
RSP: 002b:00007f5a0b446028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f5a0c065fa0 RCX: 00007f5a0bdece59
RDX: 000000000000029f RSI: 0000200000
---truncated---
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/reflink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "06283034cec0fa357cbd85784ef7d3f5b2ce0790",
"status": "affected",
"version": "05a5a7621ce66c142e081ffc24dd6ade6e912061",
"versionType": "git"
},
{
"lessThan": "2aa37c8ef1092c6f088e23a90bffefc672831c09",
"status": "affected",
"version": "05a5a7621ce66c142e081ffc24dd6ade6e912061",
"versionType": "git"
},
{
"lessThan": "ea3452726ccb6bcaa732f43cc57bb928eca3dd59",
"status": "affected",
"version": "05a5a7621ce66c142e081ffc24dd6ade6e912061",
"versionType": "git"
},
{
"lessThan": "532085d00eb54c074bdeae648b194765239f4d11",
"status": "affected",
"version": "05a5a7621ce66c142e081ffc24dd6ade6e912061",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/reflink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock cloning inline extent when using flushoncommit\n\nIn commit b48c980b6a7e (\"btrfs: fix deadlock between reflink and\ntransaction commit when using flushoncommit\") a deadlock was fixed\nbetween reflinks and transaction commits when the fs is mounted with the\nflushoncommit option. This happened when we had to copy an inline extent\u0027s\ndata to the destination file. However the issue was fixed only for the\ncase where the destination offset is 0, it missed the case when the offset\nis greater than zero.\n\nFix this by ensuring we get i_size update whenever we copied an inline\nextent\u0027s data into the destination file.\n\nSyzbot reported this with the following trace:\n\n INFO: task kworker/u8:3:57 blocked for more than 143 seconds.\n Not tainted syzkaller #0\n \"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:kworker/u8:3 state:D stack:21600 pid:57 tgid:57 ppid:2 task_flags:0x4208160 flags:0x00080000\n Workqueue: writeback wb_workfn (flush-btrfs-129)\n Call Trace:\n \u003cTASK\u003e\n context_switch kernel/sched/core.c:5402 [inline]\n __schedule+0x16f9/0x5500 kernel/sched/core.c:7204\n __schedule_loop kernel/sched/core.c:7283 [inline]\n schedule+0x164/0x360 kernel/sched/core.c:7298\n wait_extent_bit fs/btrfs/extent-io-tree.c:905 [inline]\n btrfs_lock_extent_bits+0x59c/0x700 fs/btrfs/extent-io-tree.c:2008\n btrfs_lock_extent fs/btrfs/extent-io-tree.h:152 [inline]\n btrfs_invalidate_folio+0x440/0xc00 fs/btrfs/inode.c:7718\n extent_writepage fs/btrfs/extent_io.c:1848 [inline]\n extent_write_cache_pages fs/btrfs/extent_io.c:2552 [inline]\n btrfs_writepages+0x12f3/0x2410 fs/btrfs/extent_io.c:2684\n do_writepages+0x32e/0x550 mm/page-writeback.c:2571\n __writeback_single_inode+0x133/0x10e0 fs/fs-writeback.c:1764\n writeback_sb_inodes+0x97f/0x1980 fs/fs-writeback.c:2056\n wb_writeback+0x445/0xb00 fs/fs-writeback.c:2241\n wb_do_writeback fs/fs-writeback.c:2388 [inline]\n wb_workfn+0x3fd/0xf20 fs/fs-writeback.c:2428\n process_one_work+0x98b/0x1630 kernel/workqueue.c:3318\n process_scheduled_works kernel/workqueue.c:3401 [inline]\n worker_thread+0xb49/0x1140 kernel/workqueue.c:3482\n kthread+0x388/0x470 kernel/kthread.c:436\n ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n \u003c/TASK\u003e\n INFO: task syz.0.145:8523 blocked for more than 143 seconds.\n Not tainted syzkaller #0\n \"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:syz.0.145 state:D stack:22752 pid:8523 tgid:8522 ppid:5850 task_flags:0x400140 flags:0x00080002\n Call Trace:\n \u003cTASK\u003e\n context_switch kernel/sched/core.c:5402 [inline]\n __schedule+0x16f9/0x5500 kernel/sched/core.c:7204\n __schedule_loop kernel/sched/core.c:7283 [inline]\n schedule+0x164/0x360 kernel/sched/core.c:7298\n wb_wait_for_completion+0x3e8/0x790 fs/fs-writeback.c:227\n __writeback_inodes_sb_nr+0x24c/0x2d0 fs/fs-writeback.c:2847\n try_to_writeback_inodes_sb+0x9a/0xc0 fs/fs-writeback.c:2895\n btrfs_start_delalloc_flush fs/btrfs/transaction.c:2182 [inline]\n btrfs_commit_transaction+0x813/0x2fc0 fs/btrfs/transaction.c:2371\n btrfs_sync_file+0xdf4/0x1230 fs/btrfs/file.c:1822\n generic_write_sync include/linux/fs.h:2663 [inline]\n btrfs_do_write_iter+0x6a9/0x840 fs/btrfs/file.c:1473\n new_sync_write fs/read_write.c:595 [inline]\n vfs_write+0x629/0xba0 fs/read_write.c:688\n ksys_write+0x156/0x270 fs/read_write.c:740\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x15f/0x560 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n RIP: 0033:0x7f5a0bdece59\n RSP: 002b:00007f5a0b446028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\n RAX: ffffffffffffffda RBX: 00007f5a0c065fa0 RCX: 00007f5a0bdece59\n RDX: 000000000000029f RSI: 0000200000\n---truncated---"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:17:08.156Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/06283034cec0fa357cbd85784ef7d3f5b2ce0790"
},
{
"url": "https://git.kernel.org/stable/c/2aa37c8ef1092c6f088e23a90bffefc672831c09"
},
{
"url": "https://git.kernel.org/stable/c/ea3452726ccb6bcaa732f43cc57bb928eca3dd59"
},
{
"url": "https://git.kernel.org/stable/c/532085d00eb54c074bdeae648b194765239f4d11"
}
],
"title": "btrfs: fix deadlock cloning inline extent when using flushoncommit",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74318",
"datePublished": "2026-08-15T05:58:15.499Z",
"dateReserved": "2026-08-15T05:44:03.884Z",
"dateUpdated": "2026-08-17T05:17:08.156Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46078 (GCVE-0-2026-46078)
Vulnerability from cvelistv5
Published
2026-05-27 12:58
Modified
2026-08-05 12:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
erofs: fix the out-of-bounds nameoff handling for trailing dirents
Currently we already have boundary-checks for nameoffs, but the trailing
dirents are special since the namelens are calculated with strnlen()
with unchecked nameoffs.
If a crafted EROFS has a trailing dirent with nameoff >= maxsize,
maxsize - nameoff can underflow, causing strnlen() to read past the
directory block.
nameoff0 should also be verified to be a multiple of
`sizeof(struct erofs_dirent)` as well [1].
[1] https://sashiko.dev/#/patchset/20260416063511.3173774-1-hsiangkao%40linux.alibaba.com
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3aa8ec716e52c02360457fa018296629b4d0becf Version: 3aa8ec716e52c02360457fa018296629b4d0becf Version: 3aa8ec716e52c02360457fa018296629b4d0becf Version: 3aa8ec716e52c02360457fa018296629b4d0becf Version: 3aa8ec716e52c02360457fa018296629b4d0becf Version: 3aa8ec716e52c02360457fa018296629b4d0becf Version: 3aa8ec716e52c02360457fa018296629b4d0becf Version: 3aa8ec716e52c02360457fa018296629b4d0becf |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/erofs/dir.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a8ee527807f7d97e55ce2ef2906f7f34975eb1c7",
"status": "affected",
"version": "3aa8ec716e52c02360457fa018296629b4d0becf",
"versionType": "git"
},
{
"lessThan": "aa16dca1b062355181ef215229eeac249d7c0d61",
"status": "affected",
"version": "3aa8ec716e52c02360457fa018296629b4d0becf",
"versionType": "git"
},
{
"lessThan": "80a23c6d1aba35be8746d74ac14e6ba5ae46da21",
"status": "affected",
"version": "3aa8ec716e52c02360457fa018296629b4d0becf",
"versionType": "git"
},
{
"lessThan": "222055e6b4063abd2d9e13c3d49bbd1724c50789",
"status": "affected",
"version": "3aa8ec716e52c02360457fa018296629b4d0becf",
"versionType": "git"
},
{
"lessThan": "48b27a955d22391c7f30169fa7b6b2e1977f1ce4",
"status": "affected",
"version": "3aa8ec716e52c02360457fa018296629b4d0becf",
"versionType": "git"
},
{
"lessThan": "8ebb951a284b7446e025afc7dc5e9516ef9a7214",
"status": "affected",
"version": "3aa8ec716e52c02360457fa018296629b4d0becf",
"versionType": "git"
},
{
"lessThan": "1d55445226c75ddd4e78b09b3e7d99109b28c366",
"status": "affected",
"version": "3aa8ec716e52c02360457fa018296629b4d0becf",
"versionType": "git"
},
{
"lessThan": "d18a3b5d337fa412a38e776e6b4b857a58836575",
"status": "affected",
"version": "3aa8ec716e52c02360457fa018296629b4d0becf",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/erofs/dir.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.86",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.27",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.86",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.27",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.4",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix the out-of-bounds nameoff handling for trailing dirents\n\nCurrently we already have boundary-checks for nameoffs, but the trailing\ndirents are special since the namelens are calculated with strnlen()\nwith unchecked nameoffs.\n\nIf a crafted EROFS has a trailing dirent with nameoff \u003e= maxsize,\nmaxsize - nameoff can underflow, causing strnlen() to read past the\ndirectory block.\n\nnameoff0 should also be verified to be a multiple of\n`sizeof(struct erofs_dirent)` as well [1].\n\n[1] https://sashiko.dev/#/patchset/20260416063511.3173774-1-hsiangkao%40linux.alibaba.com"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is triggered by parsing a maliciously crafted EROFS filesystem image during a directory read; the data is processed locally after the image is presented (file/loop/removable media), with no network reachability for the readdir path.\nAC:L - An attacker fully controls the on-disk `nameoff` field of the trailing dirent in the crafted image, so the unsigned underflow and resulting out-of-bounds `strnlen` are reproduced deterministically every time the directory is read.\nPR:N - Once the crafted image is mounted, triggering the bug requires only an ordinary directory listing (getdents/readdir), which needs no special privileges; this matches the sibling crafted-image EROFS CVE-2026-43166.\nUI:R - EROFS lacks FS_USERNS_MOUNT and requires CAP_SYS_ADMIN to mount, so a separate user/automounter must mount the attacker-supplied image before the vulnerable readdir path can execute.\nS:U - The out-of-bounds access stays within the kernel\u0027s own memory and security authority; there is no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - The underflowed length drives an unbounded `strnlen` that reads kernel memory far past the directory-block buffer; per the OOB-read guidance this unbounded read is High.\nI:N - The defect is strictly a read (strnlen over adjacent memory); no out-of-bounds write, use-after-free, or type confusion occurs, so no data can be modified.\nA:H - Scanning up to ~4 GB past the buffer readily walks into unmapped memory, producing a kernel oops/panic and denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:29:31.009Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a8ee527807f7d97e55ce2ef2906f7f34975eb1c7"
},
{
"url": "https://git.kernel.org/stable/c/aa16dca1b062355181ef215229eeac249d7c0d61"
},
{
"url": "https://git.kernel.org/stable/c/80a23c6d1aba35be8746d74ac14e6ba5ae46da21"
},
{
"url": "https://git.kernel.org/stable/c/222055e6b4063abd2d9e13c3d49bbd1724c50789"
},
{
"url": "https://git.kernel.org/stable/c/48b27a955d22391c7f30169fa7b6b2e1977f1ce4"
},
{
"url": "https://git.kernel.org/stable/c/8ebb951a284b7446e025afc7dc5e9516ef9a7214"
},
{
"url": "https://git.kernel.org/stable/c/1d55445226c75ddd4e78b09b3e7d99109b28c366"
},
{
"url": "https://git.kernel.org/stable/c/d18a3b5d337fa412a38e776e6b4b857a58836575"
}
],
"title": "erofs: fix the out-of-bounds nameoff handling for trailing dirents",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46078",
"datePublished": "2026-05-27T12:58:11.916Z",
"dateReserved": "2026-05-13T15:03:33.096Z",
"dateUpdated": "2026-08-05T12:29:31.009Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68108 (GCVE-0-2026-68108)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vce: fix integer overflow in image size
Fix a security vulnerability where malicious VCE command streams
with oversized dimensions (e.g. 65536×65536) cause 32-bit integer
overflow, wrapping the calculated buffer size to 0. This bypasses
validation and allows GPU firmware to perform out-of-bound memory
access.
The fix uses 64-bit arithmetic to detect overflow and rejects
invalid dimensions before they reach the hardware.
V2: remove redundant check
V3: modify max height value
V4: remove size64
(cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "893db20383800cfe92e638705984eebb13bc81a5",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "a07430abd556de3707adfcadcc60db3fa64e4b2b",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "a6d7065b91a14790980ce6f4960db0ca8c3c9940",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "7eebef042c12dfe0568593ee6a8926d16505925e",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "00c311a13d225266800c712f2b7db2711c6897de",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "186bfdc4e26d019b2e7570cb121964a1d89b2e5b",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vce: fix integer overflow in image size\n\nFix a security vulnerability where malicious VCE command streams\nwith oversized dimensions (e.g. 65536\u00d765536) cause 32-bit integer\noverflow, wrapping the calculated buffer size to 0. This bypasses\nvalidation and allows GPU firmware to perform out-of-bound memory\naccess.\n\nThe fix uses 64-bit arithmetic to detect overflow and rejects\ninvalid dimensions before they reach the hardware.\n\nV2: remove redundant check\nV3: modify max height value\nV4: remove size64\n\n(cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only through the AMDGPU_CS DRM ioctl on a local render node (/dev/dri/renderD*); there is no network, adjacent-radio, or physical-device path to the VCE command-stream parser.\nAC:L - On affected AMD GPUs using physical-mode VCE parsing, an attacker fully controls the IB and can set create-command dimensions (e.g., 65536x65536) to deterministically overflow the 32-bit size to zero without races or uncontrollable layout conditions.\nPR:L - Exploitation requires only unprivileged local access to the amdgpu DRM render node; AMDGPU_CS is gated by DRM_AUTH|DRM_RENDER_ALLOW with no root, DRM-master, or non-namespace capability requirement.\nUI:N - No victim interaction is needed beyond the attacker submitting crafted VCE command buffers through their own render-node context; no third party must open files or take other actions.\nS:C - Bypassing size-based BO relocation/validation lets VCE firmware DMA outside the intended buffer boundaries, crossing the GPU memory-isolation boundary that kernel validation is meant to enforce on GART/VRAM mappings.\nC:H - With validation defeated, VCE firmware can read arbitrarily beyond undersized encode/context/MV buffers, exposing other GPU-accessible memory including GTT-mapped system memory and adjacent VRAM allocations.\nI:H - The same out-of-bounds VCE firmware accesses enable arbitrary writes to GPU-mapped memory beyond validated buffers, providing memory-corruption primitives suitable for privilege escalation or control-flow influence.\nA:H - Oversized VCE operations against undersized buffers can trigger GPU page faults, engine hangs, GPU resets, or broader system disruption that the attacker can repeat via further command submissions."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:22.109Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/893db20383800cfe92e638705984eebb13bc81a5"
},
{
"url": "https://git.kernel.org/stable/c/a07430abd556de3707adfcadcc60db3fa64e4b2b"
},
{
"url": "https://git.kernel.org/stable/c/a6d7065b91a14790980ce6f4960db0ca8c3c9940"
},
{
"url": "https://git.kernel.org/stable/c/7eebef042c12dfe0568593ee6a8926d16505925e"
},
{
"url": "https://git.kernel.org/stable/c/00c311a13d225266800c712f2b7db2711c6897de"
},
{
"url": "https://git.kernel.org/stable/c/186bfdc4e26d019b2e7570cb121964a1d89b2e5b"
}
],
"title": "drm/amdgpu/vce: fix integer overflow in image size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68108",
"datePublished": "2026-08-10T11:58:25.241Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:22.109Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64539 (GCVE-0-2026-64539)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
eir_create_adv_data() builds the advertising data into a fixed-size
buffer ("size", 31 for the legacy path). It may prepend a 3-byte "Flags"
AD structure (LE_AD_NO_BREDR on an LE-only controller) and then copies
the per-instance data without checking that it still fits:
memcpy(ptr, adv->adv_data, adv->adv_data_len);
tlv_data_max_len() only reserves those 3 bytes when the user-supplied
flags carry a managed-flags bit, so an instance added with flags == 0 is
accepted with adv_data_len up to the full buffer. At advertise time the
flags are still prepended, and the memcpy() writes 3 + adv_data_len
bytes into the size-byte buffer:
BUG: KASAN: stack-out-of-bounds in eir_create_adv_data (net/bluetooth/eir.c:301)
Write of size 31 at addr ffff88800a547bdc by task kworker/u9:0/65
Workqueue: hci0 hci_cmd_sync_work
__asan_memcpy (mm/kasan/shadow.c:106)
eir_create_adv_data (net/bluetooth/eir.c:301)
hci_update_adv_data_sync (net/bluetooth/hci_sync.c:1310)
hci_schedule_adv_instance_sync (net/bluetooth/hci_sync.c:1817)
hci_cmd_sync_work (net/bluetooth/hci_sync.c:332)
This frame has 1 object:
[32, 64) 'cp'
The "Flags" structure is added by the kernel, not requested by
userspace, so only prepend it when it fits together with the instance
advertising data; when there is no room for both, drop the flags rather
than the user-provided data.
Reachable by a local user with CAP_NET_ADMIN owning an LE-only
controller on the legacy advertising path.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/eir.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f0b6232af56441d0a2dcb173cc4f8d8aab39014",
"status": "affected",
"version": "b44133ff03be30b55f23036e62f403a3f7784fce",
"versionType": "git"
},
{
"lessThan": "09301f1fdf2aef8cce34d0c4650c30e7edb1ced9",
"status": "affected",
"version": "b44133ff03be30b55f23036e62f403a3f7784fce",
"versionType": "git"
},
{
"lessThan": "f1b4df9c260c51726da2e86e19322825fddeefd0",
"status": "affected",
"version": "b44133ff03be30b55f23036e62f403a3f7784fce",
"versionType": "git"
},
{
"lessThan": "57077eeb586c42f124bc09e018449362223067b3",
"status": "affected",
"version": "b44133ff03be30b55f23036e62f403a3f7784fce",
"versionType": "git"
},
{
"lessThan": "6f5fb689fdf80bdd143f22a502f9eb1f3c85e286",
"status": "affected",
"version": "b44133ff03be30b55f23036e62f403a3f7784fce",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/eir.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: eir: Fix stack OOB write when prepending the Flags AD\n\neir_create_adv_data() builds the advertising data into a fixed-size\nbuffer (\"size\", 31 for the legacy path). It may prepend a 3-byte \"Flags\"\nAD structure (LE_AD_NO_BREDR on an LE-only controller) and then copies\nthe per-instance data without checking that it still fits:\n\n\tmemcpy(ptr, adv-\u003eadv_data, adv-\u003eadv_data_len);\n\ntlv_data_max_len() only reserves those 3 bytes when the user-supplied\nflags carry a managed-flags bit, so an instance added with flags == 0 is\naccepted with adv_data_len up to the full buffer. At advertise time the\nflags are still prepended, and the memcpy() writes 3 + adv_data_len\nbytes into the size-byte buffer:\n\n BUG: KASAN: stack-out-of-bounds in eir_create_adv_data (net/bluetooth/eir.c:301)\n Write of size 31 at addr ffff88800a547bdc by task kworker/u9:0/65\n Workqueue: hci0 hci_cmd_sync_work\n __asan_memcpy (mm/kasan/shadow.c:106)\n eir_create_adv_data (net/bluetooth/eir.c:301)\n hci_update_adv_data_sync (net/bluetooth/hci_sync.c:1310)\n hci_schedule_adv_instance_sync (net/bluetooth/hci_sync.c:1817)\n hci_cmd_sync_work (net/bluetooth/hci_sync.c:332)\n This frame has 1 object:\n [32, 64) \u0027cp\u0027\n\nThe \"Flags\" structure is added by the kernel, not requested by\nuserspace, so only prepend it when it fits together with the instance\nadvertising data; when there is no room for both, drop the flags rather\nthan the user-provided data.\n\nReachable by a local user with CAP_NET_ADMIN owning an LE-only\ncontroller on the legacy advertising path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The overflow is driven entirely by locally supplied advertising data written to an AF_BLUETOOTH HCI control socket (MGMT_OP_ADD_ADVERTISING / ADD_EXT_ADV_DATA / MESH_SEND); no remote or adjacent Bluetooth peer can influence the length or contents. Consistent with the same-class CVE-2026-53209 and CVE-2026-64126, this is a local-only trigger.\nAC:L - The attacker fully controls both preconditions \u2014 submit an instance with flags==0 and adv_data_len at the maximum, containing no EIR_FLAGS element \u2014 and the kernel then deterministically prepends the 3-byte Flags AD on any LE-only controller. No race, no memory-layout luck, no retry needed.\nPR:L - Reaching the mgmt handler requires HCI_SOCK_TRUSTED, granted by CAP_NET_ADMIN, which is a delegated capability routinely held by the Bluetooth stack daemon rather than full system root, and this CNA scores the identical CAP_NET_ADMIN-gated Bluetooth mgmt paths (CVE-2026-64126, CVE-2026-53209, CVE-2026-31511) as PR:L. Choosing the higher-severity option where the privilege boundary is arguable.\nUI:N - The attacker issues the mgmt commands itself and the overflow fires from hci_cmd_sync_work when the instance is scheduled for advertising. No victim action of any kind is involved.\nS:U - The corruption is confined to the kernel\u0027s own stack within the same security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - On the extended-advertising path the inflated length (254 \u003e 251) makes struct_size() copy 3 bytes of adjacent kernel stack past the DEFINE_FLEX pdu into the HCI command skb, which is exposed via the HCI monitor channel and handed to the controller for broadcast, and the stack corruption is generally leverageable for further disclosure.\nI:H - This is an out-of-bounds write of fully attacker-controlled bytes (the tail of the user-supplied adv_data) past a local stack object, and it additionally leaves hdev-\u003eadv_data_len set to a value larger than the data actually stored. An attacker-controlled linear stack overflow is treated as high integrity impact.\nA:H - Overwriting bytes immediately past the stack object corrupts adjacent frame state and, with CONFIG_STACKPROTECTOR, will trip __stack_chk_fail leading to a kernel panic; the reported KASAN stack-out-of-bounds confirms real memory corruption in hci_cmd_sync_work."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:15.586Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f0b6232af56441d0a2dcb173cc4f8d8aab39014"
},
{
"url": "https://git.kernel.org/stable/c/09301f1fdf2aef8cce34d0c4650c30e7edb1ced9"
},
{
"url": "https://git.kernel.org/stable/c/f1b4df9c260c51726da2e86e19322825fddeefd0"
},
{
"url": "https://git.kernel.org/stable/c/57077eeb586c42f124bc09e018449362223067b3"
},
{
"url": "https://git.kernel.org/stable/c/6f5fb689fdf80bdd143f22a502f9eb1f3c85e286"
}
],
"title": "Bluetooth: eir: Fix stack OOB write when prepending the Flags AD",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64539",
"datePublished": "2026-07-27T20:10:33.363Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:15.586Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64386 (GCVE-0-2026-64386)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix query_info() replay double-free
A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_query_info_init() fails before the next send,
cleanup retains the previous buffer type and frees that response again.
Reset response bookkeeping before each attempt to prevent the stale free.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 433042a91f9373241307725b52de573933ffedbf Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 6.6.32 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "100fb7c455fa86d248b8bd7bb9de757c192870b4",
"status": "affected",
"version": "433042a91f9373241307725b52de573933ffedbf",
"versionType": "git"
},
{
"lessThan": "3c81dda84799f76b42aec598564316e2964440db",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "f1add4acb656f5a82806a1ab0e63fed3d8b1bfca",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "89234773e8348918111aa15f6922b58cf3843364",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "2a88561d66eb855813cf004a0abe648bbb17de5e",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.32",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix query_info() replay double-free\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_query_info_init() fails before the next send,\ncleanup retains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious or compromised SMB2/3 server can remotely return a response-bearing replayable error and manipulate the subsequent connection state, reaching the vulnerable client over TCP.\nAC:L - The server controls the error response, disconnect, and reconnection sequence and can repeat it until the stale free occurs. Replay-enabled hard or retrans-configured SMB mounts are a reasonable deployment.\nPR:N - The malicious SMB peer needs no privileges or credentials on the client; SMB session setup authenticates the client to the server, not the attacker to the victim kernel.\nUI:N - Once the share is mounted, ordinary or automated file and metadata operations issue query-info requests, and exploitation requires no human action during the crafted response and reconnect sequence.\nS:U - The corruption and resulting impacts occur within the same Linux kernel security authority, without crossing a VM, sandbox, or IOMMU boundary.\nC:H - The double-free corrupts SMB response-buffer slab and mempool state, enabling aliased or use-after-free buffers that can be leveraged to expose kernel memory.\nI:H - Allocator freelist corruption and reuse of one buffer by concurrent SMB operations can provide attacker-controlled modification of live kernel memory and support control-flow hijacking.\nA:H - The repeated free can immediately cause allocator corruption, a BUG, kernel oops, or panic, and the malicious server can trigger the sequence repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:38.353Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/100fb7c455fa86d248b8bd7bb9de757c192870b4"
},
{
"url": "https://git.kernel.org/stable/c/3c81dda84799f76b42aec598564316e2964440db"
},
{
"url": "https://git.kernel.org/stable/c/f1add4acb656f5a82806a1ab0e63fed3d8b1bfca"
},
{
"url": "https://git.kernel.org/stable/c/89234773e8348918111aa15f6922b58cf3843364"
},
{
"url": "https://git.kernel.org/stable/c/2a88561d66eb855813cf004a0abe648bbb17de5e"
}
],
"title": "smb: client: fix query_info() replay double-free",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64386",
"datePublished": "2026-07-25T08:50:34.729Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-08-17T04:54:38.353Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-39964 (GCVE-0-2025-39964)
Vulnerability from cvelistv5
Published
2025-10-13 13:48
Modified
2026-09-08 08:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Issuing two writes to the same af_alg socket is bogus as the
data will be interleaved in an unpredictable fashion. Furthermore,
concurrent writes may create inconsistencies in the internal
socket state.
Disallow this by adding a new ctx->write field that indiciates
exclusive ownership for writing.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 Version: 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 Version: 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 Version: 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 Version: 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 Version: 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 Version: 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 |
||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-39964",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-10T20:40:19.988750Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-11T17:53:37.586Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:42:37.537Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"crypto/af_alg.c",
"include/crypto/if_alg.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
"status": "affected",
"version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
"versionType": "git"
},
{
"lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
"status": "affected",
"version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
"versionType": "git"
},
{
"lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
"status": "affected",
"version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
"versionType": "git"
},
{
"lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
"status": "affected",
"version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
"versionType": "git"
},
{
"lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
"status": "affected",
"version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
"versionType": "git"
},
{
"lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
"status": "affected",
"version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
"versionType": "git"
},
{
"lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
"status": "affected",
"version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"crypto/af_alg.c",
"include/crypto/if_alg.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.38"
},
{
"lessThan": "2.6.38",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.245",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.194",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.16.*",
"status": "unaffected",
"version": "6.16.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.17",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.245",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.194",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.154",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.108",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.49",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16.9",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17",
"versionStartIncluding": "2.6.38",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion. Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx-\u003ewrite field that indiciates\nexclusive ownership for writing."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is reached through the AF_ALG socket family via `socket()`/`bind()`/`sendmsg()`/`recvmsg()` syscalls, which requires local system access. There is no remote or adjacent-network path to `af_alg_sendmsg()`.\nAC:L - The attacker controls both sides of the race entirely \u2014 two of its own threads on a socket it owns \u2014 and can force writer A to park deterministically in `af_alg_wait_for_wmem()` by sizing `SO_SNDBUF` and filling it, then wake it on demand with its own `recvmsg()`. The error exit that leaves `cur == 0` is triggered at will with a deliberately faulting user buffer, so no condition is outside the attacker\u0027s control.\nPR:L - `alg_create()`, `alg_bind()` and `alg_setkey()` perform no capability checks whatsoever, so any unprivileged local user \u2014 including one inside a container or unprivileged user namespace \u2014 can open, bind and write to an AF_ALG skcipher/aead socket. The required modules are auto-loaded on demand via `MODULE_ALIAS_NETPROTO(AF_ALG)` and `request_module(\"algif-%s\")`.\nUI:N - The attacking process performs every step itself \u2014 socket creation, bind, and the two concurrent `sendmsg()` calls. No victim action or interaction of any kind is needed.\nS:U - The corruption is confined to kernel heap objects (`struct af_alg_tsgl`/scatterlist and adjacent slab memory) within the same security authority. No hypervisor, IOMMU, or other trust boundary is crossed.\nC:H - The out-of-bounds scatterlist entry is fabricated from kernel list pointers and is subsequently handed to the cipher by `skcipher_recvmsg`/`aead_recvmsg` via `af_alg_pull_tsgl()`, so arbitrary kernel memory is encrypted/decrypted and returned to userspace. This yields a kernel memory disclosure primitive, not merely a pointer leak.\nI:H - `memcpy_from_msg(page_address(sg_page(sg)) + sg-\u003eoffset + sg-\u003elength, msg, len)` on the underflowed scatterlist writes attacker-controlled data of attacker-chosen length to an address derived from attacker-influenceable heap contents. Combined with heap grooming of the 4KB tsgl allocations, this is a controlled kernel write suitable for privilege escalation.\nA:H - Dereferencing `page_address(sg_page(sg))` on a bogus page_link, and the later `put_page()` on that fabricated page, reliably produce an oops/panic or page refcount corruption. Any unprivileged user can trigger this repeatedly, crashing the machine."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:06:33.126Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
},
{
"url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
},
{
"url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
},
{
"url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
},
{
"url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
},
{
"url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
},
{
"url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
}
],
"title": "crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-39964",
"datePublished": "2025-10-13T13:48:30.334Z",
"dateReserved": "2025-04-16T07:20:57.149Z",
"dateUpdated": "2026-09-08T08:42:37.537Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63970 (GCVE-0-2026-63970)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: bind uarg before filling zerocopy skb
virtio_transport_send_pkt_info() allocates or reuses the zerocopy uarg
before entering the send loop, but virtio_transport_alloc_skb() still
fills the skb before it inherits that uarg. When fixed-buffer vectored
zerocopy hits MAX_SKB_FRAGS, io_sg_from_iter() may partially attach
managed frags and return -EMSGSIZE. The rollback path call kfree_skb()
to free an skb that carries SKBFL_MANAGED_FRAG_REFS but no uarg, so
skb_release_data() falls through to ordinary frag unref.
Pass the uarg into virtio_transport_alloc_skb() and bind it immediately
before virtio_transport_fill_skb(). This keeps control or no-payload skbs
untouched while ensuring success and rollback share one lifetime rule.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/virtio_transport_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "72194f65050958e4c8e069adb6c5d89ef81ca197",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
},
{
"lessThan": "b62e2b2b4a50953ca952f3cd3f77dd62dc50fd5d",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
},
{
"lessThan": "5d317573f1d48e76cce5fb6250452b6e4102e0fb",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
},
{
"lessThan": "1e584c304cfb94a759417130b1fc6d30b30c4cce",
"status": "affected",
"version": "581512a6dc939ef122e49336626ae159f3b8a345",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/virtio_transport_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: bind uarg before filling zerocopy skb\n\nvirtio_transport_send_pkt_info() allocates or reuses the zerocopy uarg\nbefore entering the send loop, but virtio_transport_alloc_skb() still\nfills the skb before it inherits that uarg. When fixed-buffer vectored\nzerocopy hits MAX_SKB_FRAGS, io_sg_from_iter() may partially attach\nmanaged frags and return -EMSGSIZE. The rollback path call kfree_skb()\nto free an skb that carries SKBFL_MANAGED_FRAG_REFS but no uarg, so\nskb_release_data() falls through to ordinary frag unref.\n\nPass the uarg into virtio_transport_alloc_skb() and bind it immediately\nbefore virtio_transport_fill_skb(). This keeps control or no-payload skbs\nuntouched while ensuring success and rollback share one lifetime rule."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local AF_VSOCK transmission (syscall/io_uring send on a connected virtio vsock socket), not by processing remote network packets. Per kernel CVSS guidance, vsock is Local.\nAC:L - An attacker fully controls the trigger: SO_ZEROCOPY, io_uring IORING_OP_SEND_ZC with IORING_RECVSEND_FIXED_BUF and a vectored iov exceeding MAX_SKB_FRAGS (17), causing io_sg_from_iter() to return -EMSGSIZE on a deterministic error rollback path.\nPR:L - Exploitation requires only an unprivileged local process that can open a vsock connection and use io_uring zerocopy send; no CAP_NET_ADMIN or real root is needed beyond ordinary local user access in a virtio-vsock environment (KVM/Firecracker/cloud microVMs).\nUI:N - No victim interaction is required; the attacker triggers the bug directly through their own socket send/io_uring operation.\nS:U - Impact is kernel memory corruption and privilege escalation within the same security domain where the send occurs (guest kernel or host kernel). It is not a cross-boundary VM escape on the receive path; the flaw is in the sender\u0027s local skb teardown.\nC:H - Incorrect __skb_frag_unref() on SKBFL_MANAGED_FRAG_REFS pages without a bound uarg corrupts refcount/lifetime of io_uring registered buffer pages, yielding use-after-free and arbitrary kernel memory read primitives.\nI:H - The refcount corruption is a memory-safety bug in kernel heap/page management that can be leveraged for arbitrary write and control-flow hijacking, not merely a bounded data change.\nA:H - The erroneous frag unref on managed zerocopy pages can cause immediate kernel oops/panic from refcount underflow or use-after-free during skb teardown, independent of full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:41.706Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/72194f65050958e4c8e069adb6c5d89ef81ca197"
},
{
"url": "https://git.kernel.org/stable/c/b62e2b2b4a50953ca952f3cd3f77dd62dc50fd5d"
},
{
"url": "https://git.kernel.org/stable/c/5d317573f1d48e76cce5fb6250452b6e4102e0fb"
},
{
"url": "https://git.kernel.org/stable/c/1e584c304cfb94a759417130b1fc6d30b30c4cce"
}
],
"title": "vsock/virtio: bind uarg before filling zerocopy skb",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63970",
"datePublished": "2026-07-19T14:55:57.067Z",
"dateReserved": "2026-07-19T07:54:57.024Z",
"dateUpdated": "2026-08-05T12:37:41.706Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72221 (GCVE-0-2026-72221)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-17 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sunrpc: wait for in-flight TLS handshake callback when cancel loses race
When wait_for_completion_interruptible_timeout() in
svc_tcp_handshake() returns 0 (timeout) or -ERESTARTSYS (signal) and
tls_handshake_cancel() then returns false, handshake_complete() has
won the cancellation race: it has set HANDSHAKE_F_REQ_COMPLETED and
is about to invoke svc_tcp_handshake_done(), but the callback's
side effects on xpt_flags and on svsk->sk_handshake_done have not
yet committed.
The current code reads xpt_flags immediately to decide whether the
session succeeded. Two races result.
If the callback has executed set_bit(XPT_TLS_SESSION) but not yet
clear_bit(XPT_HANDSHAKE), svc_tcp_handshake() sees a session,
enqueues the transport, and returns. svc_xprt_received() then
clears XPT_BUSY, a worker thread picks the transport up, the
dispatcher in svc_handle_xprt() observes XPT_HANDSHAKE still set,
and xpo_handshake is invoked a second time. That svc_tcp_handshake()
calls init_completion(&svsk->sk_handshake_done) while the original
callback concurrently calls complete_all() on it, corrupting the
embedded swait_queue.
If the callback has set HANDSHAKE_F_REQ_COMPLETED but not yet
entered svc_tcp_handshake_done(), svc_tcp_handshake() reads
XPT_TLS_SESSION as clear and tears the connection down even though
the handshake is about to succeed.
Wait for the callback to commit before inspecting xpt_flags. The
completion is guaranteed to fire because handshake_complete()
invokes svc_tcp_handshake_done() unconditionally once it has set
HANDSHAKE_F_REQ_COMPLETED.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sunrpc/svcsock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0d8ceb39884148dc7a2fdf71e1cac5961ed1d2b9",
"status": "affected",
"version": "b3cbf98e2fdf3cb147a95161560cd25987284330",
"versionType": "git"
},
{
"lessThan": "e0f4691d42a54d359d8b64509fd9ab938d4f2a33",
"status": "affected",
"version": "b3cbf98e2fdf3cb147a95161560cd25987284330",
"versionType": "git"
},
{
"lessThan": "65b23bec1fca6e9ebdc3e6041ebf8c6ab074141b",
"status": "affected",
"version": "b3cbf98e2fdf3cb147a95161560cd25987284330",
"versionType": "git"
},
{
"lessThan": "a4f878e8ecd729ccf2e50993444e217583adeace",
"status": "affected",
"version": "b3cbf98e2fdf3cb147a95161560cd25987284330",
"versionType": "git"
},
{
"lessThan": "d00e32f84ca1a77cb67a3fbf59f58dada95f5a21",
"status": "affected",
"version": "b3cbf98e2fdf3cb147a95161560cd25987284330",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sunrpc/svcsock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: wait for in-flight TLS handshake callback when cancel loses race\n\nWhen wait_for_completion_interruptible_timeout() in\nsvc_tcp_handshake() returns 0 (timeout) or -ERESTARTSYS (signal) and\ntls_handshake_cancel() then returns false, handshake_complete() has\nwon the cancellation race: it has set HANDSHAKE_F_REQ_COMPLETED and\nis about to invoke svc_tcp_handshake_done(), but the callback\u0027s\nside effects on xpt_flags and on svsk-\u003esk_handshake_done have not\nyet committed.\n\nThe current code reads xpt_flags immediately to decide whether the\nsession succeeded. Two races result.\n\nIf the callback has executed set_bit(XPT_TLS_SESSION) but not yet\nclear_bit(XPT_HANDSHAKE), svc_tcp_handshake() sees a session,\nenqueues the transport, and returns. svc_xprt_received() then\nclears XPT_BUSY, a worker thread picks the transport up, the\ndispatcher in svc_handle_xprt() observes XPT_HANDSHAKE still set,\nand xpo_handshake is invoked a second time. That svc_tcp_handshake()\ncalls init_completion(\u0026svsk-\u003esk_handshake_done) while the original\ncallback concurrently calls complete_all() on it, corrupting the\nembedded swait_queue.\n\nIf the callback has set HANDSHAKE_F_REQ_COMPLETED but not yet\nentered svc_tcp_handshake_done(), svc_tcp_handshake() reads\nXPT_TLS_SESSION as clear and tears the connection down even though\nthe handshake is about to succeed.\n\nWait for the callback to commit before inspecting xpt_flags. The\ncompletion is guaranteed to fire because handshake_complete()\ninvokes svc_tcp_handshake_done() unconditionally once it has set\nHANDSHAKE_F_REQ_COMPLETED."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Reachable over TCP by any remote peer of an in-kernel NFS/RPC server (nfsd) via the pre-auth RPC_AUTH_TLS NULL-procedure STARTTLS path that invokes svc_tcp_handshake() on the accepted SUNRPC transport.\nAC:L - The attacker controls both sides of the race by timing TLS client handshake messages against the fixed 5-second SVC_HANDSHAKE_TO and opening many parallel connections to reliably hit the cancel-lost window.\nPR:N - No credentials or export authorization are required; svcauth_tls_accept() accepts empty AUTH_TLS on RPC NULL from any TCP client, and svcauth_unix_set_client() skips IP export checks when rq_proc==0.\nUI:N - Exploitation requires only scripted network connections and TLS client traffic to nfsd; no victim user interaction such as mounting a filesystem or opening a file is needed.\nS:U - Memory corruption occurs in nfsd kernel worker context on the same host; impact is kernel privilege compromise within the server security authority, not a VM escape or IOMMU boundary bypass.\nC:H - A second svc_tcp_handshake() can call init_completion() while svc_tcp_handshake_done() concurrently calls complete_all(), corrupting the embedded swait_queue in heap-allocated svc_sock and enabling arbitrary kernel memory disclosure.\nI:H - Corrupting completion wait-queue metadata in the svc_sock heap object can be leveraged for arbitrary kernel writes and control-flow hijacking to achieve local privilege escalation on the NFS server.\nA:H - The swait_queue corruption can trigger kernel oops/panic, and the alternate race path tears down connections whose TLS handshake is about to succeed, enabling repeatable remote denial-of-service against nfsd."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:41:42.766Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0d8ceb39884148dc7a2fdf71e1cac5961ed1d2b9"
},
{
"url": "https://git.kernel.org/stable/c/e0f4691d42a54d359d8b64509fd9ab938d4f2a33"
},
{
"url": "https://git.kernel.org/stable/c/65b23bec1fca6e9ebdc3e6041ebf8c6ab074141b"
},
{
"url": "https://git.kernel.org/stable/c/a4f878e8ecd729ccf2e50993444e217583adeace"
},
{
"url": "https://git.kernel.org/stable/c/d00e32f84ca1a77cb67a3fbf59f58dada95f5a21"
}
],
"title": "sunrpc: wait for in-flight TLS handshake callback when cancel loses race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72221",
"datePublished": "2026-08-15T05:54:14.539Z",
"dateReserved": "2026-08-09T03:40:39.913Z",
"dateUpdated": "2026-08-17T05:41:42.766Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68189 (GCVE-0-2026-68189)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: Protect UUID list traversal
The hci_sync conversion moved class-of-device and EIR generation from an
HCI request built under hdev->lock to asynchronous command sync work.
The worker holds hdev->req_lock, but that lock does not serialize access
to hdev->uuids against add_uuid() and remove_uuid(), which update the
list under hdev->lock.
The following interleaving can therefore occur:
CPU0 (command sync work) CPU1 (management socket)
fetch uuid from the list
list_del(&uuid->list)
kfree(uuid)
read uuid->size
KASAN reports the resulting use-after-free:
BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0
Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87
Workqueue: hci0 hci_cmd_sync_work
Call Trace:
eir_create+0xb8f/0xee0
hci_update_eir_sync+0x1c0/0x330
hci_cmd_sync_work+0x13c/0x290
process_one_work+0x63a/0x1070
worker_thread+0x45b/0xd10
Allocated by task 86:
__kasan_kmalloc+0x8f/0xa0
add_uuid+0x18a/0x4b0
hci_sock_sendmsg+0x1033/0x1ea0
Freed by task 92:
__kasan_slab_free+0x43/0x70
kfree+0x131/0x3c0
remove_uuid+0x25e/0x560
hci_sock_sendmsg+0x1033/0x1ea0
Hold hdev->lock while generating and committing the class-of-device and
EIR snapshots. Release it before sending an HCI command, so controller
waits do not happen under the device lock. This protects all UUID list
walks in these paths and restores the serialization lost in the command
sync conversion.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "30bc6248f035a792d1b1f4cc761b32fd5827b55f",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "e4fa2c5c261d736b8e58759fdef3a968d510630c",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "a351f68fb24828b23a971e00b8238ee0e8a40380",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "a42f5536ea9c00e13f0c0fbb330feed95e2365ca",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "fe13adc258df88d95789e5673c7ba5178b5f8b28",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "e9027ffbf5a0f3c12ca8900822e884eae9f0821b",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Protect UUID list traversal\n\nThe hci_sync conversion moved class-of-device and EIR generation from an\nHCI request built under hdev-\u003elock to asynchronous command sync work.\nThe worker holds hdev-\u003ereq_lock, but that lock does not serialize access\nto hdev-\u003euuids against add_uuid() and remove_uuid(), which update the\nlist under hdev-\u003elock.\n\nThe following interleaving can therefore occur:\n\n CPU0 (command sync work) CPU1 (management socket)\n fetch uuid from the list\n list_del(\u0026uuid-\u003elist)\n kfree(uuid)\n read uuid-\u003esize\n\nKASAN reports the resulting use-after-free:\n\n BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0\n Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87\n Workqueue: hci0 hci_cmd_sync_work\n Call Trace:\n eir_create+0xb8f/0xee0\n hci_update_eir_sync+0x1c0/0x330\n hci_cmd_sync_work+0x13c/0x290\n process_one_work+0x63a/0x1070\n worker_thread+0x45b/0xd10\n\n Allocated by task 86:\n __kasan_kmalloc+0x8f/0xa0\n add_uuid+0x18a/0x4b0\n hci_sock_sendmsg+0x1033/0x1ea0\n\n Freed by task 92:\n __kasan_slab_free+0x43/0x70\n kfree+0x131/0x3c0\n remove_uuid+0x25e/0x560\n hci_sock_sendmsg+0x1033/0x1ea0\n\nHold hdev-\u003elock while generating and committing the class-of-device and\nEIR snapshots. Release it before sending an HCI command, so controller\nwaits do not happen under the device lock. This protects all UUID list\nwalks in these paths and restores the serialization lost in the command\nsync conversion."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires concurrent MGMT_OP_ADD_UUID/MGMT_REMOVE_UUID commands through a local AF_BLUETOOTH HCI management socket (hci_sock_sendmsg), not reception of over-the-air Bluetooth protocol traffic from a remote peer.\nAC:L - The attacker controls both sides of the race by issuing concurrent management socket commands from threads or processes they own; KASAN shows reliable interleaving between hci_cmd_sync_work and remove_uuid without attacker-uncontrollable timing or memory layout.\nPR:L - MGMT_OP_ADD_UUID and MGMT_OP_REMOVE_UUID require HCI_SOCK_TRUSTED, set only when the socket binder holds CAP_NET_ADMIN; per kernel CNA guidance CAP_NET_ADMIN reachable via user namespaces (unshare -Urn) maps to PR:L, not PR:H.\nUI:N - No victim interaction is required; the attacker directly issues local management commands that queue hci_cmd_sync_work and concurrently modify the UUID list to trigger the use-after-free.\nS:U - The vulnerability causes kernel heap corruption and local privilege escalation within the same host security authority; it does not cross VM, container, or IOMMU security boundaries.\nC:H - KASAN-confirmed slab use-after-free reading freed bt_uuid fields (uuid-\u003esize and uuid data) during eir_create traversal enables arbitrary kernel memory disclosure via heap spraying and reuse of freed kmalloc objects.\nI:H - Slab UAF on bt_uuid during list traversal enables attacker-controlled reallocation of freed objects, providing heap corruption primitives that can be leveraged for arbitrary kernel writes and control-flow hijacking.\nA:H - The confirmed use-after-free in eir_create on the hci_cmd_sync_work path causes kernel oops or panic; repeated concurrent add/remove UUID operations can reliably crash or hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:01.944Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/30bc6248f035a792d1b1f4cc761b32fd5827b55f"
},
{
"url": "https://git.kernel.org/stable/c/e4fa2c5c261d736b8e58759fdef3a968d510630c"
},
{
"url": "https://git.kernel.org/stable/c/a351f68fb24828b23a971e00b8238ee0e8a40380"
},
{
"url": "https://git.kernel.org/stable/c/a42f5536ea9c00e13f0c0fbb330feed95e2365ca"
},
{
"url": "https://git.kernel.org/stable/c/fe13adc258df88d95789e5673c7ba5178b5f8b28"
},
{
"url": "https://git.kernel.org/stable/c/e9027ffbf5a0f3c12ca8900822e884eae9f0821b"
}
],
"title": "Bluetooth: hci_sync: Protect UUID list traversal",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68189",
"datePublished": "2026-08-10T12:00:01.711Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:31:01.944Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64387 (GCVE-0-2026-64387)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix query directory replay double-free
A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_query_directory_init() fails before the next send,
cleanup retains the previous buffer type and frees that response again.
Reset response bookkeeping before each attempt to prevent the stale free.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 433042a91f9373241307725b52de573933ffedbf Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 4f1fffa2376922f3d1d506e49c0fd445b023a28e Version: 6.6.32 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3409aedf3c81a810243da94164f6621c9d205c98",
"status": "affected",
"version": "433042a91f9373241307725b52de573933ffedbf",
"versionType": "git"
},
{
"lessThan": "1665f25b1dea30bf2d02e16245d203a944c9d994",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "00b0fa425941438b664950a8ee65dfba2def4336",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "3317a5d015fca976475aa71df224056777316fde",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "9647492b5e41954be59d5157eddbcd4cdc1656f7",
"status": "affected",
"version": "4f1fffa2376922f3d1d506e49c0fd445b023a28e",
"versionType": "git"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.32",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix query directory replay double-free\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_query_directory_init() fails before the next send,\ncleanup retains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious remote SMB server can trigger the flaw through crafted responses to SMB2 QUERY_DIRECTORY requests over the established network connection.\nAC:L - On a hard/retrans-enabled mount, the server controls the replayable error and can repeatedly induce disconnect/reconnect conditions before request reinitialization, without relying on an uncontrollable race.\nPR:N - The attacker needs no account or privilege on the client; the client authenticates to the attacker-controlled SMB server, and ordinary accessible-share enumeration reaches the code.\nUI:N - In a reasonable auto-mounted deployment, routine directory enumeration can be performed automatically by a daemon or application without human participation.\nS:U - The corruption occurs within the client kernel and compromises resources governed by that same kernel security authority.\nC:H - Double-freeing the attacker-influenced CIFS response object can poison the slab freelist or create overlapping allocations, providing UAF-style primitives capable of exposing arbitrary kernel memory.\nI:H - Allocator corruption and aliased CIFS buffers can enable attacker-influenced writes and potentially control-flow hijacking or kernel code execution.\nA:H - The double-free can immediately trigger allocator diagnostics, an oops, or a kernel panic, and corrupted freelists can cause subsequent fatal faults."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:39.446Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3409aedf3c81a810243da94164f6621c9d205c98"
},
{
"url": "https://git.kernel.org/stable/c/1665f25b1dea30bf2d02e16245d203a944c9d994"
},
{
"url": "https://git.kernel.org/stable/c/00b0fa425941438b664950a8ee65dfba2def4336"
},
{
"url": "https://git.kernel.org/stable/c/3317a5d015fca976475aa71df224056777316fde"
},
{
"url": "https://git.kernel.org/stable/c/9647492b5e41954be59d5157eddbcd4cdc1656f7"
}
],
"title": "smb: client: fix query directory replay double-free",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64387",
"datePublished": "2026-07-25T08:50:35.543Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-08-17T04:54:39.446Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74269 (GCVE-0-2026-74269)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bnxt: fix head underflow on XDP head-grow
The xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on
a bnxt machine (and also crashes in NIPA).
It seems that the bug is an underflow in bnxt_rx_multi_page_skb, which
builds the skb head:
napi_build_skb(data_ptr - bp->rx_offset, rxr->rx_page_size);
The problem with this expression is that in page mode, rx_offset is:
bp->rx_offset = NET_IP_ALIGN + XDP_PACKET_HEADROOM;
Which evaluates (at least on x86_64) to 258.
The test test_xdp_native_adjst_head_grow_data tests a case where the
head is adjusted by -256.
When this test runs, data_ptr is shifted to frag_start + 2 (where
frag_start = page_address(page) + offset).
Then, bnxt_rx_multi_page_skb is invoked and the napi_build_skb
expression subtracts 258, landing at an address before frag_start. This
could be either the previous fragment or the previous physical page when
the offset is < 256 (e.g. if the fragment started at offset 0).
When the skb is freed, the page pool fragment reference is dropped on
either the wrong page or the wrong frag of the right page. In either
case, the corrupted reference count can lead to the page being
prematurely recycled while still in use. Once (incorrectly) recycled, it
can be handed out again and on driver teardown this would result in a
double free.
The commit under fixes updated this code to handle the case where the
native page size is >= 64k, but it unintentionally broke the head grow
case.
To fix this, add an offset field to struct bnxt_sw_rx_bd, mirroring the
existing offset field in struct bnxt_sw_rx_agg_bd. Populate it on
allocation and preserve it on reuse.
In bnxt_rx_multi_page_skb, use the newly added offset field to compute
the fragment start and pass that to napi_build_skb. Adjust the layout
with skb_reserve.
There are two cases, the non-adjustment case and the adjustment case.
In both cases, the skb is built at page_address(page) + offset to
account for the case where the native page size >= 64K and skb_reserve
is called with data_ptr - (page_address(page) + offset). That
difference equals bp->rx_offset when data_ptr was not moved, or
bp->rx_offset + xdp_adjust when XDP adjusted the head.
Re-running the failing test with this commit applied causes the test to
run successfully to completion.
The other rx_skb_func implementations don't have this issue.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/broadcom/bnxt/bnxt.c",
"drivers/net/ethernet/broadcom/bnxt/bnxt.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bb72b1c6755631c74b7e0878ee55bb81c06776c0",
"status": "affected",
"version": "f6974b4c2d8e1062b5a52228ee47293c15b4ee1e",
"versionType": "git"
},
{
"lessThan": "e26657fe3b85c068b01f42bb0c602f242d643ba9",
"status": "affected",
"version": "f6974b4c2d8e1062b5a52228ee47293c15b4ee1e",
"versionType": "git"
},
{
"status": "affected",
"version": "e9f11bfc03fb0d3c86f91b8ae945bb10f7e19c16",
"versionType": "git"
},
{
"status": "affected",
"version": "ae0e135dc900827687ecc684c2bbb57aae48d318",
"versionType": "git"
},
{
"lessThan": "6.2",
"status": "affected",
"version": "6.1.45",
"versionType": "semver"
},
{
"lessThan": "6.5",
"status": "affected",
"version": "6.4.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/broadcom/bnxt/bnxt.c",
"drivers/net/ethernet/broadcom/bnxt/bnxt.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.1.45",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt: fix head underflow on XDP head-grow\n\nThe xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on\na bnxt machine (and also crashes in NIPA).\n\nIt seems that the bug is an underflow in bnxt_rx_multi_page_skb, which\nbuilds the skb head:\n\n napi_build_skb(data_ptr - bp-\u003erx_offset, rxr-\u003erx_page_size);\n\nThe problem with this expression is that in page mode, rx_offset is:\n\n bp-\u003erx_offset = NET_IP_ALIGN + XDP_PACKET_HEADROOM;\n\nWhich evaluates (at least on x86_64) to 258.\n\nThe test test_xdp_native_adjst_head_grow_data tests a case where the\nhead is adjusted by -256.\n\nWhen this test runs, data_ptr is shifted to frag_start + 2 (where\nfrag_start = page_address(page) + offset).\n\nThen, bnxt_rx_multi_page_skb is invoked and the napi_build_skb\nexpression subtracts 258, landing at an address before frag_start. This\ncould be either the previous fragment or the previous physical page when\nthe offset is \u003c 256 (e.g. if the fragment started at offset 0).\n\nWhen the skb is freed, the page pool fragment reference is dropped on\neither the wrong page or the wrong frag of the right page. In either\ncase, the corrupted reference count can lead to the page being\nprematurely recycled while still in use. Once (incorrectly) recycled, it\ncan be handed out again and on driver teardown this would result in a\ndouble free.\n\nThe commit under fixes updated this code to handle the case where the\nnative page size is \u003e= 64k, but it unintentionally broke the head grow\ncase.\n\nTo fix this, add an offset field to struct bnxt_sw_rx_bd, mirroring the\nexisting offset field in struct bnxt_sw_rx_agg_bd. Populate it on\nallocation and preserve it on reuse.\n\nIn bnxt_rx_multi_page_skb, use the newly added offset field to compute\nthe fragment start and pass that to napi_build_skb. Adjust the layout\nwith skb_reserve.\n\nThere are two cases, the non-adjustment case and the adjustment case.\n\nIn both cases, the skb is built at page_address(page) + offset to\naccount for the case where the native page size \u003e= 64K and skb_reserve\nis called with data_ptr - (page_address(page) + offset). That\ndifference equals bp-\u003erx_offset when data_ptr was not moved, or\nbp-\u003erx_offset + xdp_adjust when XDP adjusted the head.\n\nRe-running the failing test with this commit applied causes the test to\nrun successfully to completion.\n\nThe other rx_skb_func implementations don\u0027t have this issue."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached in bnxt hardware RX/NAPI processing when network packets arrive; the reproducing selftest triggers it by exchanging UDP packets over the network after XDP head-grow on receive.\nAC:L - Once a bnxt interface runs XDP multi-buffer with jumbo MTU, an attacker can reliably trigger bpf_xdp_adjust_head(-256) with packets larger than rx_copybreak (256 bytes); no race or attacker-uncontrollable memory layout is required.\nPR:N - The vulnerable receive path performs no authentication on incoming packets. Attaching the XDP program and enabling jumbo MTU are deployment preconditions on affected bnxt servers, not privileges the remote attacker needs.\nUI:N - After the affected bnxt interface is configured with XDP and jumbo MTU, exploitation requires only sending crafted network traffic; no additional victim action such as opening files or mounting filesystems is needed.\nS:U - Impact is kernel memory corruption and denial of service within the host networking stack. This is standard in-kernel privilege/integrity impact, not a VM escape, IOMMU bypass, or other cross-security-boundary violation.\nC:H - Pointer underflow builds the skb on the wrong page-pool fragment or prior physical page, corrupting refcount accounting and allowing pages to be recycled while still referenced, yielding a use-after-free that can expose kernel memory.\nI:H - Corrupted page-pool reference counts can prematurely recycle receive buffers still in use and lead to double-free on teardown, providing exploitable kernel heap memory corruption beyond a simple crash.\nA:H - The bug crashes bnxt systems during XDP head-grow testing and can be triggered repeatedly via received traffic, causing kernel oops, resource exhaustion, or panic especially when panic_on_warn is enabled."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:45:15.603Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bb72b1c6755631c74b7e0878ee55bb81c06776c0"
},
{
"url": "https://git.kernel.org/stable/c/e26657fe3b85c068b01f42bb0c602f242d643ba9"
}
],
"title": "bnxt: fix head underflow on XDP head-grow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74269",
"datePublished": "2026-08-15T05:57:43.559Z",
"dateReserved": "2026-08-15T05:44:03.878Z",
"dateUpdated": "2026-08-17T05:45:15.603Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53076 (GCVE-0-2026-53076)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-08-05 12:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix OOB in pcpu_init_value
An out-of-bounds read occurs when copying element from a
BPF_MAP_TYPE_CGROUP_STORAGE map to another pcpu map with the
same value_size that is not rounded up to 8 bytes.
The issue happens when:
1. A CGROUP_STORAGE map is created with value_size not aligned to
8 bytes (e.g., 4 bytes)
2. A pcpu map is created with the same value_size (e.g., 4 bytes)
3. Update element in 2 with data in 1
pcpu_init_value assumes that all sources are rounded up to 8 bytes,
and invokes copy_map_value_long to make a data copy, However, the
assumption doesn't stand since there are some cases where the source
may not be rounded up to 8 bytes, e.g., CGROUP_STORAGE, skb->data.
the verifier verifies exactly the size that the source claims, not
the size rounded up to 8 bytes by kernel, an OOB happens when the
source has only 4 bytes while the copy size(4) is rounded up to 8.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d3bec0138bfbe58606fc1d6f57a4cdc1a20218db Version: d3bec0138bfbe58606fc1d6f57a4cdc1a20218db Version: d3bec0138bfbe58606fc1d6f57a4cdc1a20218db Version: d3bec0138bfbe58606fc1d6f57a4cdc1a20218db Version: d3bec0138bfbe58606fc1d6f57a4cdc1a20218db Version: c602ad2b52dcbca5af08e5137bd5575c039b52e3 Version: ab68b940dd6f7b5f8e2557937162dcb8a0583a05 Version: 5.4.78 ≤ Version: 5.9.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/bpf/hashtab.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e19c5ed9f1922a6854073f8651a63fa7be26e9e9",
"status": "affected",
"version": "d3bec0138bfbe58606fc1d6f57a4cdc1a20218db",
"versionType": "git"
},
{
"lessThan": "e0378419b0e20178b5d100b27c9cc7e51064202e",
"status": "affected",
"version": "d3bec0138bfbe58606fc1d6f57a4cdc1a20218db",
"versionType": "git"
},
{
"lessThan": "6086079e6d1c32ba4c4b422612b8aebb1129a96c",
"status": "affected",
"version": "d3bec0138bfbe58606fc1d6f57a4cdc1a20218db",
"versionType": "git"
},
{
"lessThan": "634a793d0e1c822412095d25a1338f8831ad894c",
"status": "affected",
"version": "d3bec0138bfbe58606fc1d6f57a4cdc1a20218db",
"versionType": "git"
},
{
"lessThan": "576afddfee8d1108ee299bf10f581593540d1a36",
"status": "affected",
"version": "d3bec0138bfbe58606fc1d6f57a4cdc1a20218db",
"versionType": "git"
},
{
"status": "affected",
"version": "c602ad2b52dcbca5af08e5137bd5575c039b52e3",
"versionType": "git"
},
{
"status": "affected",
"version": "ab68b940dd6f7b5f8e2557937162dcb8a0583a05",
"versionType": "git"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.78",
"versionType": "semver"
},
{
"lessThan": "5.10",
"status": "affected",
"version": "5.9.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/bpf/hashtab.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.78",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.9.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix OOB in pcpu_init_value\n\nAn out-of-bounds read occurs when copying element from a\nBPF_MAP_TYPE_CGROUP_STORAGE map to another pcpu map with the\nsame value_size that is not rounded up to 8 bytes.\n\nThe issue happens when:\n1. A CGROUP_STORAGE map is created with value_size not aligned to\n 8 bytes (e.g., 4 bytes)\n2. A pcpu map is created with the same value_size (e.g., 4 bytes)\n3. Update element in 2 with data in 1\n\npcpu_init_value assumes that all sources are rounded up to 8 bytes,\nand invokes copy_map_value_long to make a data copy, However, the\nassumption doesn\u0027t stand since there are some cases where the source\nmay not be rounded up to 8 bytes, e.g., CGROUP_STORAGE, skb-\u003edata.\nthe verifier verifies exactly the size that the source claims, not\nthe size rounded up to 8 bytes by kernel, an OOB happens when the\nsource has only 4 bytes while the copy size(4) is rounded up to 8."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached through local `bpf(2)` activity: creating BPF maps, loading a BPF program, and invoking `bpf_map_update_elem()` from that program. It is not directly reachable by remote packets without a local attacker-controlled BPF program already installed.\nAC:L - The trigger is deterministic: use a non-8-byte-aligned value size and pass a verifier-valid source buffer into a per-CPU hash update that previously copied the rounded-up size. No race or attacker-external timing condition is required.\nPR:L - A basic local user can reach the most severe reasonable case on systems where unprivileged BPF is enabled, including via socket-filter BPF and packet data sources; otherwise it requires BPF-related capabilities. Under the required higher-severity rule, this is PR:L rather than PR:H.\nUI:N - After the local attacker loads the BPF program and creates the maps, exploitation requires no victim action. The attacker triggers the helper path directly.\nS:U - The affected component and impacted resources are within the same kernel security authority. This is not a VM escape, IOMMU bypass, or cross-scope boundary violation.\nC:H - The bug is an out-of-bounds kernel read whose extra bytes are copied into per-CPU map padding that can be returned through per-CPU map lookup paths. Even though each read is small, repeated attacker-controlled executions can disclose kernel memory, so the higher severity confidentiality value is warranted.\nI:N - The faulty copy writes only into the destination per-CPU map slot\u0027s allocated rounded padding, not past the allocated destination or into security-relevant map value bytes. I found no path turning this into attacker-controlled kernel data modification or control-flow corruption.\nA:H - The reported reproducer is a KASAN slab-out-of-bounds read in a deterministic BPF helper path, and such reachable kernel OOB reads can oops or panic on hardened/sanitized or unlucky layouts. Following the kernel scoring guidance and higher-severity rule, availability is H."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:33:09.042Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e19c5ed9f1922a6854073f8651a63fa7be26e9e9"
},
{
"url": "https://git.kernel.org/stable/c/e0378419b0e20178b5d100b27c9cc7e51064202e"
},
{
"url": "https://git.kernel.org/stable/c/6086079e6d1c32ba4c4b422612b8aebb1129a96c"
},
{
"url": "https://git.kernel.org/stable/c/634a793d0e1c822412095d25a1338f8831ad894c"
},
{
"url": "https://git.kernel.org/stable/c/576afddfee8d1108ee299bf10f581593540d1a36"
}
],
"title": "bpf: Fix OOB in pcpu_init_value",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53076",
"datePublished": "2026-06-24T16:30:17.092Z",
"dateReserved": "2026-06-09T07:44:35.383Z",
"dateUpdated": "2026-08-05T12:33:09.042Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43271 (GCVE-0-2026-43271)
Vulnerability from cvelistv5
Published
2026-05-06 11:28
Modified
2026-05-11 22:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
md-cluster: fix NULL pointer dereference in process_metadata_update
The function process_metadata_update() blindly dereferences the 'thread'
pointer (acquired via rcu_dereference_protected) within the wait_event()
macro.
While the code comment states "daemon thread must exist", there is a valid
race condition window during the MD array startup sequence (md_run):
1. bitmap_load() is called, which invokes md_cluster_ops->join().
2. join() starts the "cluster_recv" thread (recv_daemon).
3. At this point, recv_daemon is active and processing messages.
4. However, mddev->thread (the main MD thread) is not initialized until
later in md_run().
If a METADATA_UPDATED message is received from a remote node during this
specific window, process_metadata_update() will be called while
mddev->thread is still NULL, leading to a kernel panic.
To fix this, we must validate the 'thread' pointer. If it is NULL, we
release the held lock (no_new_dev_lockres) and return early, safely
ignoring the update request as the array is not yet fully ready to
process it.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/md-cluster.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a61c1bc84c4a0f1e7c2fe55b0f43d7d94af4adf1",
"status": "affected",
"version": "0ba959774e93911caff596de6391f085fb640ac4",
"versionType": "git"
},
{
"lessThan": "dec123825c1ed74d98fd5fc7571a851dea4f46ff",
"status": "affected",
"version": "0ba959774e93911caff596de6391f085fb640ac4",
"versionType": "git"
},
{
"lessThan": "721599e837d3f4c0e6cc14da059612c017b6d3ec",
"status": "affected",
"version": "0ba959774e93911caff596de6391f085fb640ac4",
"versionType": "git"
},
{
"lessThan": "dceb5a843910004cb118148e267036104fc3ee43",
"status": "affected",
"version": "0ba959774e93911caff596de6391f085fb640ac4",
"versionType": "git"
},
{
"lessThan": "f150e753cb8dd756085f46e86f2c35ce472e0a3c",
"status": "affected",
"version": "0ba959774e93911caff596de6391f085fb640ac4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/md-cluster.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd-cluster: fix NULL pointer dereference in process_metadata_update\n\nThe function process_metadata_update() blindly dereferences the \u0027thread\u0027\npointer (acquired via rcu_dereference_protected) within the wait_event()\nmacro.\n\nWhile the code comment states \"daemon thread must exist\", there is a valid\nrace condition window during the MD array startup sequence (md_run):\n\n1. bitmap_load() is called, which invokes md_cluster_ops-\u003ejoin().\n2. join() starts the \"cluster_recv\" thread (recv_daemon).\n3. At this point, recv_daemon is active and processing messages.\n4. However, mddev-\u003ethread (the main MD thread) is not initialized until\n later in md_run().\n\nIf a METADATA_UPDATED message is received from a remote node during this\nspecific window, process_metadata_update() will be called while\nmddev-\u003ethread is still NULL, leading to a kernel panic.\n\nTo fix this, we must validate the \u0027thread\u0027 pointer. If it is NULL, we\nrelease the held lock (no_new_dev_lockres) and return early, safely\nignoring the update request as the array is not yet fully ready to\nprocess it."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:21:19.841Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a61c1bc84c4a0f1e7c2fe55b0f43d7d94af4adf1"
},
{
"url": "https://git.kernel.org/stable/c/dec123825c1ed74d98fd5fc7571a851dea4f46ff"
},
{
"url": "https://git.kernel.org/stable/c/721599e837d3f4c0e6cc14da059612c017b6d3ec"
},
{
"url": "https://git.kernel.org/stable/c/dceb5a843910004cb118148e267036104fc3ee43"
},
{
"url": "https://git.kernel.org/stable/c/f150e753cb8dd756085f46e86f2c35ce472e0a3c"
}
],
"title": "md-cluster: fix NULL pointer dereference in process_metadata_update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43271",
"datePublished": "2026-05-06T11:28:55.507Z",
"dateReserved": "2026-05-01T14:12:55.998Z",
"dateUpdated": "2026-05-11T22:21:19.841Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72262 (GCVE-0-2026-72262)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
The ipc_control_data buffer is allocated as kzalloc(max_size), where
max_size covers the entire struct sof_ipc_ctrl_data including its
flexible array payload. However, the bounds checks in bytes_ext_put
and _bytes_ext_get compared user data lengths against max_size
directly, ignoring that cdata->data sits at an offset of
sizeof(struct sof_ipc_ctrl_data) bytes into the allocation.
This allowed writing up to sizeof(struct sof_ipc_ctrl_data) bytes past
the end of the heap buffer from unprivileged userspace via the ALSA TLV
kcontrol interface, and similarly allowed over-reading adjacent heap
data on the get path.
Fix all bounds checks to subtract sizeof(*cdata) from max_size so they
reflect the actual space available at the cdata->data offset. Also fix
the error-path restore in bytes_ext_put which wrote to cdata->data
instead of cdata, causing the same overflow.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/sof/ipc3-control.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "af4b437a463ac0482ba705434a44da06783778e6",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
},
{
"lessThan": "1adde1941bba7b0d7104b86ed819d48d81cb0ad9",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
},
{
"lessThan": "eaa67e139c9217099e2a7b717aeeb46c65de3494",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
},
{
"lessThan": "121577383b5cf221e86581e0f2bcca4c66f17469",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
},
{
"lessThan": "f4933e1d11b97b6a0951648b7c3e53850e1b33a9",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
},
{
"lessThan": "fd46668d538993218eea19c6925c868ac0f2630c",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/sof/ipc3-control.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get\n\nThe ipc_control_data buffer is allocated as kzalloc(max_size), where\nmax_size covers the entire struct sof_ipc_ctrl_data including its\nflexible array payload. However, the bounds checks in bytes_ext_put\nand _bytes_ext_get compared user data lengths against max_size\ndirectly, ignoring that cdata-\u003edata sits at an offset of\nsizeof(struct sof_ipc_ctrl_data) bytes into the allocation.\n\nThis allowed writing up to sizeof(struct sof_ipc_ctrl_data) bytes past\nthe end of the heap buffer from unprivileged userspace via the ALSA TLV\nkcontrol interface, and similarly allowed over-reading adjacent heap\ndata on the get path.\n\nFix all bounds checks to subtract sizeof(*cdata) from max_size so they\nreflect the actual space available at the cdata-\u003edata offset. Also fix\nthe error-path restore in bytes_ext_put which wrote to cdata-\u003edata\ninstead of cdata, causing the same overflow."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local ioctl on /dev/snd/controlC* (SNDRV_CTL_IOCTL_TLV_WRITE/READ) through the ALSA control device; there is no network, adjacent-radio, or physical-bus attack surface for this SOF IPC3 kcontrol path.\nAC:L - On affected SOF IPC3 systems with topology bytes_ext controls, an attacker can deterministically trigger the bug by issuing TLV writes with header.length equal to max_size, causing copy_from_user/memcpy to overrun the kzalloc(max_size) buffer by sizeof(struct sof_ipc_ctrl_data).\nPR:L - The fix commit states the overflow is reachable from unprivileged userspace via ALSA TLV kcontrols; any local user who can open the sound control device (typically membership in the audio group on Linux, or an app with audio access on Android/ChromeOS) can reach the vulnerable code without real root.\nUI:N - Exploitation is performed entirely by the attacker issuing ALSA TLV ioctls against an existing bytes_ext kcontrol; no victim click, mount, or other interactive action beyond the attacker\u0027s own access to the sound control interface is required.\nS:U - The vulnerability corrupts kernel heap memory from a local userspace context and enables standard kernel privilege escalation or denial of service; it does not cross a VM, container, or IOMMU security boundary into a separate authority.\nC:H - The get path can copy_to_user up to sizeof(struct sof_ipc_ctrl_data) bytes beyond the allocated ipc_control_data buffer, leaking adjacent kernel heap contents; combined with the controllable overflow, this is an out-of-bounds read/memory corruption primitive consistent with arbitrary disclosure potential.\nI:H - The put path performs an out-of-bounds heap write of up to sizeof(struct sof_ipc_ctrl_data) bytes past the kzalloc(max_size) allocation (including via the err_restore memcpy), enabling heap metadata/object corruption that can be developed into arbitrary kernel write or code execution.\nA:H - Heap out-of-bounds writes of roughly 96 bytes into adjacent slab objects can corrupt kernel structures and trigger oops/panic or wedged audio/subsystem state; repeated TLV operations make denial of service reliably achievable even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:11.302Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/af4b437a463ac0482ba705434a44da06783778e6"
},
{
"url": "https://git.kernel.org/stable/c/1adde1941bba7b0d7104b86ed819d48d81cb0ad9"
},
{
"url": "https://git.kernel.org/stable/c/eaa67e139c9217099e2a7b717aeeb46c65de3494"
},
{
"url": "https://git.kernel.org/stable/c/121577383b5cf221e86581e0f2bcca4c66f17469"
},
{
"url": "https://git.kernel.org/stable/c/f4933e1d11b97b6a0951648b7c3e53850e1b33a9"
},
{
"url": "https://git.kernel.org/stable/c/fd46668d538993218eea19c6925c868ac0f2630c"
}
],
"title": "ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72262",
"datePublished": "2026-08-15T05:54:49.635Z",
"dateReserved": "2026-08-09T03:40:39.915Z",
"dateUpdated": "2026-08-23T12:47:11.302Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64055 (GCVE-0-2026-64055)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: cortina: Carry over frag counter
The gmac_rx() NAPI poll function assembles packets in an
SKB from a ring buffer.
If the ring buffer gets completely emptied during a poll cycle,
we exit gmac_rx(), but the packet is not yet completely
assembled in the SKB, yet the fragment counter frag_nr is
reset to zero on the next invocation.
Solve this by making the RX fragment counter a part of the
port struct, and carry it over between invocations.
Reset the fragment counter only right after calling
napi_gro_frags(), on error (after calling napi_free_frags())
or if stopping the port.
Reset it in some place where not strictly necessary just to
emphasize what is going on.
This was found by Sashiko during normal patch review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 Version: 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cortina/gemini.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "df31e3b64455293df1ea89c7da7d5c9bfbcdd253",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "7af1fabdee744b7995fe01b30b77dfc397657cb5",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "75105fcf73f1ce7d9f769aaefec6e6d6645d5ac0",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "78cf08b3be47c28f07008a76c932bad7cdffa9d8",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "7123cf481e21b54eb6adc4cb0d8dc2876aeaee41",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "c373b34877afea61c89e0dd2e38948c624249b9b",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "46806096f35b8d3dfa2f321ddd77f597edcdb85f",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
},
{
"lessThan": "ebd8ec2b309e3a447851b456ccaf8fb39f3661e7",
"status": "affected",
"version": "4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cortina/gemini.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.16"
},
{
"lessThan": "4.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: cortina: Carry over frag counter\n\nThe gmac_rx() NAPI poll function assembles packets in an\nSKB from a ring buffer.\n\nIf the ring buffer gets completely emptied during a poll cycle,\nwe exit gmac_rx(), but the packet is not yet completely\nassembled in the SKB, yet the fragment counter frag_nr is\nreset to zero on the next invocation.\n\nSolve this by making the RX fragment counter a part of the\nport struct, and carry it over between invocations.\n\nReset the fragment counter only right after calling\nnapi_gro_frags(), on error (after calling napi_free_frags())\nor if stopping the port.\n\nReset it in some place where not strictly necessary just to\nemphasize what is going on.\n\nThis was found by Sashiko during normal patch review."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in the Cortina Gemini GMAC RX NAPI path (gmac_rx), which processes incoming Ethernet frames delivered by hardware DMA; a remote attacker on any routable network can send crafted multi-fragment frames to the device\u0027s NIC without local access.\nAC:L - An attacker controls frame size (jumbo frames exceeding the 2048-byte RX buffer fragment size) and traffic timing to drain the RX ring mid-packet across NAPI poll cycles, reliably reproducing the lost frag_nr condition without depending on uncontrollable system state.\nPR:N - Exploitation requires only the ability to send Ethernet frames to the target interface; no local account, kernel capability, or authentication on the victim system is needed.\nUI:N - Packet reception and NAPI processing are fully automatic; no victim user action such as mounting a filesystem or opening a file is required.\nS:U - The vulnerability corrupts kernel skb metadata in the network driver and affects only the kernel\u0027s own security domain; it does not cross a VM, container, or IOMMU boundary by itself.\nC:H - Resetting frag_nr to zero while rx_skb retains prior fragments causes skb_fill_page_desc to overwrite fragment slot 0, shrinks nr_frags while inflating skb-\u003elen, and can trigger out-of-bounds kernel reads when GRO and the network stack process the corrupted skb.\nI:H - The bug corrupts kernel heap skb fragment metadata (overwritten page descriptors, inconsistent nr_frags versus len), which is memory corruption in kernel structures that can be leveraged for arbitrary write or control-flow hijack primitives.\nA:H - Submitting a corrupted multi-fragment skb to napi_gro_frags and the upper network stack can cause kernel oops, BUG, or panic during fragment traversal, checksum, or GRO processing."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:44.658Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/df31e3b64455293df1ea89c7da7d5c9bfbcdd253"
},
{
"url": "https://git.kernel.org/stable/c/7af1fabdee744b7995fe01b30b77dfc397657cb5"
},
{
"url": "https://git.kernel.org/stable/c/75105fcf73f1ce7d9f769aaefec6e6d6645d5ac0"
},
{
"url": "https://git.kernel.org/stable/c/78cf08b3be47c28f07008a76c932bad7cdffa9d8"
},
{
"url": "https://git.kernel.org/stable/c/7123cf481e21b54eb6adc4cb0d8dc2876aeaee41"
},
{
"url": "https://git.kernel.org/stable/c/c373b34877afea61c89e0dd2e38948c624249b9b"
},
{
"url": "https://git.kernel.org/stable/c/46806096f35b8d3dfa2f321ddd77f597edcdb85f"
},
{
"url": "https://git.kernel.org/stable/c/ebd8ec2b309e3a447851b456ccaf8fb39f3661e7"
}
],
"title": "net: ethernet: cortina: Carry over frag counter",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64055",
"datePublished": "2026-07-19T15:39:37.077Z",
"dateReserved": "2026-07-19T07:54:57.030Z",
"dateUpdated": "2026-08-05T12:38:44.658Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64249 (GCVE-0-2026-64249)
Vulnerability from cvelistv5
Published
2026-07-24 15:31
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fpga: region: fix use-after-free in child_regions_with_firmware()
Move of_node_put(child_region) after the error print to avoid accessing
freed memory when pr_err() references child_region.
[ Yilun: Fix the Fixes tag ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0fa20cdfcc1f68847cdfc47824476301eedc8297 Version: 0fa20cdfcc1f68847cdfc47824476301eedc8297 Version: 0fa20cdfcc1f68847cdfc47824476301eedc8297 Version: 0fa20cdfcc1f68847cdfc47824476301eedc8297 Version: 0fa20cdfcc1f68847cdfc47824476301eedc8297 Version: 0fa20cdfcc1f68847cdfc47824476301eedc8297 Version: 0fa20cdfcc1f68847cdfc47824476301eedc8297 Version: 0fa20cdfcc1f68847cdfc47824476301eedc8297 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/fpga/of-fpga-region.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e918942bcc5355ad5b44ba557935dffc0727b0eb",
"status": "affected",
"version": "0fa20cdfcc1f68847cdfc47824476301eedc8297",
"versionType": "git"
},
{
"lessThan": "866184fc7ae42a0070f1141ae8c5dca7c24a59e2",
"status": "affected",
"version": "0fa20cdfcc1f68847cdfc47824476301eedc8297",
"versionType": "git"
},
{
"lessThan": "070b0ce947b18fa3dec0729695147f7e19599649",
"status": "affected",
"version": "0fa20cdfcc1f68847cdfc47824476301eedc8297",
"versionType": "git"
},
{
"lessThan": "fbaf509ad7cb2f7dafe73ca20c956104cfcc9d68",
"status": "affected",
"version": "0fa20cdfcc1f68847cdfc47824476301eedc8297",
"versionType": "git"
},
{
"lessThan": "e79afcb0a66d2b3c33e510eade902537e656fc00",
"status": "affected",
"version": "0fa20cdfcc1f68847cdfc47824476301eedc8297",
"versionType": "git"
},
{
"lessThan": "369496d885b4cf6e8647cf4dc5cf3ac68fdf37a1",
"status": "affected",
"version": "0fa20cdfcc1f68847cdfc47824476301eedc8297",
"versionType": "git"
},
{
"lessThan": "5e098e40e8bac43ed58645c10d5fad781966efe4",
"status": "affected",
"version": "0fa20cdfcc1f68847cdfc47824476301eedc8297",
"versionType": "git"
},
{
"lessThan": "54f3c5643ec523a04b6ec0e7c19eb10f5ebebdd3",
"status": "affected",
"version": "0fa20cdfcc1f68847cdfc47824476301eedc8297",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/fpga/of-fpga-region.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.260",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.260",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: region: fix use-after-free in child_regions_with_firmware()\n\nMove of_node_put(child_region) after the error print to avoid accessing\nfreed memory when pr_err() references child_region.\n\n[ Yilun: Fix the Fixes tag ]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:00.712Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e918942bcc5355ad5b44ba557935dffc0727b0eb"
},
{
"url": "https://git.kernel.org/stable/c/866184fc7ae42a0070f1141ae8c5dca7c24a59e2"
},
{
"url": "https://git.kernel.org/stable/c/070b0ce947b18fa3dec0729695147f7e19599649"
},
{
"url": "https://git.kernel.org/stable/c/fbaf509ad7cb2f7dafe73ca20c956104cfcc9d68"
},
{
"url": "https://git.kernel.org/stable/c/e79afcb0a66d2b3c33e510eade902537e656fc00"
},
{
"url": "https://git.kernel.org/stable/c/369496d885b4cf6e8647cf4dc5cf3ac68fdf37a1"
},
{
"url": "https://git.kernel.org/stable/c/5e098e40e8bac43ed58645c10d5fad781966efe4"
},
{
"url": "https://git.kernel.org/stable/c/54f3c5643ec523a04b6ec0e7c19eb10f5ebebdd3"
}
],
"title": "fpga: region: fix use-after-free in child_regions_with_firmware()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64249",
"datePublished": "2026-07-24T15:31:16.458Z",
"dateReserved": "2026-07-19T15:36:31.772Z",
"dateUpdated": "2026-08-17T04:52:00.712Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64581 (GCVE-0-2026-64581)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),
i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with
rcu_dereference_protected(), stores NULL and dst_release()s the old dst.
That is only safe if no other thread modifies sk_dst_cache concurrently.
For a connected UDP socket that does not hold: the transmit fast path
(udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly
with an atomic xchg(). A per-socket policy change racing a send can make
both sides observe the same old dst and each dst_release() it, dropping
the socket's single reference twice and freeing the xfrm_dst bundle while
it is still referenced:
BUG: KASAN: slab-use-after-free in dst_release
Write of size 4 at addr ffff88801897b6c0 by task exploit/155
Call Trace:
...
dst_release (... ./include/linux/rcuref.h:109)
xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)
do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)
ip_setsockopt (net/ipv4/ip_sockglue.c:1417)
do_sock_setsockopt (net/socket.c:2368)
__sys_setsockopt (net/socket.c:2393)
__x64_sys_setsockopt (net/socket.c:2396)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Reachable by an unprivileged user via a user+network namespace.
Use the atomic sk_dst_reset() so the cache is cleared and released with a
single xchg(): whichever side wins releases the dst once, the other sees
NULL and does nothing. Behaviour is otherwise unchanged.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 72f157be2f81910ae759bfe2e5c2256fc4625645 Version: 9e9fe58a92a46c6d154d2901735bf230d91b8507 Version: adc1ec6cdc20d430aa01b86497220709b9149466 Version: b54033eb1cfd77aba471269ddd804ed8d3e35dea Version: c9e82cb34c3c2ee895af01bc899c6ed0bc6eb04a Version: 5eef9b51114fcc65651d671add52f267f91b9451 Version: 3.16.52 ≤ Version: 4.4.163 ≤ Version: 3.18.101 ≤ Version: 4.1.52 ≤ Version: 4.4.123 ≤ Version: 4.9.89 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_state.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e8686fd8d18b99f3a9038683045b2f2338a7706d",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "a9340ebdc13f8bb5063c0bc0b037ee7e640d4ae9",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "f833821e4b52ab6335d443ede5fb79c38e61d19a",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "f0ab9a71167bae308e05ab13b65e2007504a603f",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "8dd8929b71c4f06c614f8f54c2cc070453faae16",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "0ea8f06454012d9e7f9c6e6253df710949bf6294",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "96b678d08268b5f5c6fc99d4289d9b7e334fc683",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "c283e9ada7fcb7dd4b10592623086b2e6d2f9925",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"status": "affected",
"version": "72f157be2f81910ae759bfe2e5c2256fc4625645",
"versionType": "git"
},
{
"status": "affected",
"version": "9e9fe58a92a46c6d154d2901735bf230d91b8507",
"versionType": "git"
},
{
"status": "affected",
"version": "adc1ec6cdc20d430aa01b86497220709b9149466",
"versionType": "git"
},
{
"status": "affected",
"version": "b54033eb1cfd77aba471269ddd804ed8d3e35dea",
"versionType": "git"
},
{
"status": "affected",
"version": "c9e82cb34c3c2ee895af01bc899c6ed0bc6eb04a",
"versionType": "git"
},
{
"status": "affected",
"version": "5eef9b51114fcc65651d671add52f267f91b9451",
"versionType": "git"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.52",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.163",
"versionType": "semver"
},
{
"lessThan": "3.19",
"status": "affected",
"version": "3.18.101",
"versionType": "semver"
},
{
"lessThan": "4.2",
"status": "affected",
"version": "4.1.52",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.123",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.89",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_state.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.52",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.163",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.18.101",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.1.52",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.123",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.89",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix sk_dst_cache double-free in xfrm_user_policy()\n\nxfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),\ni.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with\nrcu_dereference_protected(), stores NULL and dst_release()s the old dst.\nThat is only safe if no other thread modifies sk_dst_cache concurrently.\n\nFor a connected UDP socket that does not hold: the transmit fast path\n(udp_sendmsg -\u003e sk_dst_check -\u003e sk_dst_reset) resets the cache locklessly\nwith an atomic xchg(). A per-socket policy change racing a send can make\nboth sides observe the same old dst and each dst_release() it, dropping\nthe socket\u0027s single reference twice and freeing the xfrm_dst bundle while\nit is still referenced:\n\n BUG: KASAN: slab-use-after-free in dst_release\n Write of size 4 at addr ffff88801897b6c0 by task exploit/155\n Call Trace:\n ...\n dst_release (... ./include/linux/rcuref.h:109)\n xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)\n do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)\n ip_setsockopt (net/ipv4/ip_sockglue.c:1417)\n do_sock_setsockopt (net/socket.c:2368)\n __sys_setsockopt (net/socket.c:2393)\n __x64_sys_setsockopt (net/socket.c:2396)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nReachable by an unprivileged user via a user+network namespace.\n\nUse the atomic sk_dst_reset() so the cache is cleared and released with a\nsingle xchg(): whichever side wins releases the dst once, the other sees\nNULL and does nothing. Behaviour is otherwise unchanged."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via setsockopt(IP_XFRM_POLICY/IP_IPSEC_POLICY) on a local socket racing concurrent udp_sendmsg; entry is a local syscall path (do_ip_setsockopt -\u003e xfrm_user_policy), not packet processing.\nAC:L - Attacker controls both sides of the race (one thread setsockopt to clear/apply per-socket xfrm policy, another sendmsg on the same connected UDP socket) and can create the obsolete xfrm_dst precondition in their netns, retrying until the double dst_release wins.\nPR:L - Path requires CAP_NET_ADMIN checked with sockopt_ns_capable(sock_net(sk)-\u003euser_ns), which an unprivileged user obtains via user+network namespaces; the fix commit explicitly states this reachability.\nUI:N - Exploitation uses only the attacker\u0027s own socket, threads, and setsockopt/sendmsg loops; no victim action or cooperation is required.\nS:U - Double-free/UAF of the socket\u0027s dst_entry/xfrm_dst is standard local kernel memory corruption within the host kernel authority, not a VM escape or other cross-boundary impact.\nC:H - Double dst_release frees the xfrm_dst slab object while still referenced, yielding a use-after-free that can be reclaimed/sprayed to disclose kernel memory via corrupted dst contents and ops.\nI:H - The UAF targets a dst_entry with function pointers (ops/input/output) used on transmit, enabling heap reuse for arbitrary write and control-flow hijack consistent with comparable sk_dst_cache races.\nA:H - The KASAN slab-use-after-free in dst_release demonstrates kernel memory corruption that can oops/panic, and the attacker can repeat the race freely."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:44.254Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e8686fd8d18b99f3a9038683045b2f2338a7706d"
},
{
"url": "https://git.kernel.org/stable/c/a9340ebdc13f8bb5063c0bc0b037ee7e640d4ae9"
},
{
"url": "https://git.kernel.org/stable/c/f833821e4b52ab6335d443ede5fb79c38e61d19a"
},
{
"url": "https://git.kernel.org/stable/c/f0ab9a71167bae308e05ab13b65e2007504a603f"
},
{
"url": "https://git.kernel.org/stable/c/8dd8929b71c4f06c614f8f54c2cc070453faae16"
},
{
"url": "https://git.kernel.org/stable/c/0ea8f06454012d9e7f9c6e6253df710949bf6294"
},
{
"url": "https://git.kernel.org/stable/c/96b678d08268b5f5c6fc99d4289d9b7e334fc683"
},
{
"url": "https://git.kernel.org/stable/c/c283e9ada7fcb7dd4b10592623086b2e6d2f9925"
}
],
"title": "xfrm: fix sk_dst_cache double-free in xfrm_user_policy()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64581",
"datePublished": "2026-08-05T08:09:35.556Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-27T12:39:44.254Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68433 (GCVE-0-2026-68433)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: bound get_version reply decode to front len
handle_get_version_reply() uses msg->front_alloc_len as the decode
boundary for MON_GET_VERSION_REPLY. That is the size of the reused
reply buffer, not the number of bytes actually received.
A truncated reply can therefore pass ceph_decode_need() and decode the
second u64 from stale tail bytes left in the buffer by an earlier
message, causing an uninitialized memory read.
Use msg->front.iov_len as the receive-side decode boundary, matching
other libceph reply handlers and limiting decoding to the bytes that
were actually read from the wire.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1307028f082756bf453e1889aee9983d30643a4b",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "f6cbf6878f3a1503c872ba8f1e69a58ee68d8b2e",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "72a35070fcefa229b1b031aa7482ad3788e18f07",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "340e0386aa39da181015bee38f309018c335ce16",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "d60de8253c85a02d0e6194b0735e7a562981a04c",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "4e7ebfaa0d14cf50e44041bfde38070d6dbc019f",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "0d934c934ec746d53fc7e4f53239792647bbae63",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: bound get_version reply decode to front len\n\nhandle_get_version_reply() uses msg-\u003efront_alloc_len as the decode\nboundary for MON_GET_VERSION_REPLY. That is the size of the reused\nreply buffer, not the number of bytes actually received.\n\nA truncated reply can therefore pass ceph_decode_need() and decode the\nsecond u64 from stale tail bytes left in the buffer by an earlier\nmessage, causing an uninitialized memory read.\n\nUse msg-\u003efront.iov_len as the receive-side decode boundary, matching\nother libceph reply handlers and limiting decoding to the bytes that\nwere actually read from the wire."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The malformed MON_GET_VERSION_REPLY arrives over the ceph messenger TCP connection to a monitor; a malicious/compromised ceph-mon or an on-path attacker on the msgr1/crc-mode session triggers the bug purely with received network data.\nAC:L - The attacker fully controls the reply\u0027s hdr.front_len and tid, so truncating the reply to 8 bytes reliably makes the handler decode past the received data every time; no race or memory-layout condition outside attacker control is involved.\nPR:N - The vulnerable decode runs on any reply the client accepts for an outstanding generic request; the attacker acts as the remote server/peer and needs no credentials or account on the victim kernel client.\nUI:N - An already-mounted CephFS/RBD client issues mon_get_version requests automatically (osdmap checks, pool-dne checks, remount/latest-map waits), so no local user action is needed once the client is connected.\nS:U - The uninitialized read and the resulting bogus epoch stay within the kernel\u0027s own libceph client state; no security authority other than the affected kernel is impacted.\nC:L - Eight bytes of uninitialized kvmalloc\u0027d heap (or stale bytes of a prior reply) are consumed as req-\u003eu.newest; the read stays inside the 32-byte allocation and is not copied to userspace, so it is a small bounded uninitialized-memory disclosure that only leaks indirectly through client behaviour.\nI:L - The attacker causes kernel state (req-\u003eu.newest, r_map_dne_bound, linger map_dne_bound) to be populated from uninitialized memory rather than the wire, corrupting osdmap-epoch bookkeeping and leading to wrong pool-does-not-exist decisions, but gives no arbitrary write.\nA:H - A zero stale value trips WARN_ON(greq-\u003eresult || !greq-\u003eu.newest) in map_check_cb()/linger_map_check_cb() (panic with panic_on_warn), while a huge garbage epoch makes ceph_monc_wait_osdmap() block until mount_timeout or indefinitely and makes check_pool_dne() abort in-flight requests with -ENOENT; all repeatable at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:33.508Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1307028f082756bf453e1889aee9983d30643a4b"
},
{
"url": "https://git.kernel.org/stable/c/f6cbf6878f3a1503c872ba8f1e69a58ee68d8b2e"
},
{
"url": "https://git.kernel.org/stable/c/72a35070fcefa229b1b031aa7482ad3788e18f07"
},
{
"url": "https://git.kernel.org/stable/c/340e0386aa39da181015bee38f309018c335ce16"
},
{
"url": "https://git.kernel.org/stable/c/d60de8253c85a02d0e6194b0735e7a562981a04c"
},
{
"url": "https://git.kernel.org/stable/c/4e7ebfaa0d14cf50e44041bfde38070d6dbc019f"
},
{
"url": "https://git.kernel.org/stable/c/0d934c934ec746d53fc7e4f53239792647bbae63"
},
{
"url": "https://git.kernel.org/stable/c/d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0"
}
],
"title": "libceph: bound get_version reply decode to front len",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68433",
"datePublished": "2026-08-12T00:07:20.455Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:33.508Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43448 (GCVE-0-2026-43448)
Vulnerability from cvelistv5
Published
2026-05-08 14:22
Modified
2026-05-11 22:24
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvme-pci: Fix race bug in nvme_poll_irqdisable()
In the following scenario, pdev can be disabled between (1) and (3) by
(2). This sets pdev->msix_enabled = 0. Then, pci_irq_vector() will
return MSI-X IRQ(>15) for (1) whereas return INTx IRQ(<=15) for (2).
This causes IRQ warning because it tries to enable INTx IRQ that has
never been disabled before.
To fix this, save IRQ number into a local variable and ensure
disable_irq() and enable_irq() operate on the same IRQ number. Even if
pci_free_irq_vectors() frees the IRQ concurrently, disable_irq() and
enable_irq() on a stale IRQ number is still valid and safe, and the
depth accounting reamins balanced.
task 1:
nvme_poll_irqdisable()
disable_irq(pci_irq_vector(pdev, nvmeq->cq_vector)) ...(1)
enable_irq(pci_irq_vector(pdev, nvmeq->cq_vector)) ...(3)
task 2:
nvme_reset_work()
nvme_dev_disable()
pdev->msix_enable = 0; ...(2)
crash log:
------------[ cut here ]------------
Unbalanced enable for IRQ 10
WARNING: kernel/irq/manage.c:753 at __enable_irq+0x102/0x190 kernel/irq/manage.c:753, CPU#1: kworker/1:0H/26
Modules linked in:
CPU: 1 UID: 0 PID: 26 Comm: kworker/1:0H Not tainted 6.19.0-dirty #9 PREEMPT(voluntary)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
Workqueue: kblockd blk_mq_timeout_work
RIP: 0010:__enable_irq+0x107/0x190 kernel/irq/manage.c:753
Code: ff df 48 89 fa 48 c1 ea 03 0f b6 14 02 48 89 f8 83 e0 07 83 c0 03 38 d0 7c 04 84 d2 75 79 48 8d 3d 2e 7a 3f 05 41 8b 74 24 2c <67> 48 0f b9 3a e8 ef b9 21 00 5b 41 5c 5d e9 46 54 66 03 e8 e1 b9
RSP: 0018:ffffc900001bf550 EFLAGS: 00010046
RAX: 0000000000000007 RBX: 0000000000000000 RCX: ffffffffb20c0e90
RDX: 0000000000000000 RSI: 000000000000000a RDI: ffffffffb74b88f0
RBP: ffffc900001bf560 R08: ffff88800197cf00 R09: 0000000000000001
R10: 0000000000000003 R11: 0000000000000003 R12: ffff8880012a6000
R13: 1ffff92000037eae R14: 000000000000000a R15: 0000000000000293
FS: 0000000000000000(0000) GS:ffff8880b49f7000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000555da4a25fa8 CR3: 00000000208e8000 CR4: 00000000000006f0
Call Trace:
<TASK>
enable_irq+0x121/0x1e0 kernel/irq/manage.c:797
nvme_poll_irqdisable+0x162/0x1c0 drivers/nvme/host/pci.c:1494
nvme_timeout+0x965/0x14b0 drivers/nvme/host/pci.c:1744
blk_mq_rq_timed_out block/blk-mq.c:1653 [inline]
blk_mq_handle_expired+0x227/0x2d0 block/blk-mq.c:1721
bt_iter+0x2fc/0x3a0 block/blk-mq-tag.c:292
__sbitmap_for_each_set include/linux/sbitmap.h:269 [inline]
sbitmap_for_each_set include/linux/sbitmap.h:290 [inline]
bt_for_each block/blk-mq-tag.c:324 [inline]
blk_mq_queue_tag_busy_iter+0x969/0x1e80 block/blk-mq-tag.c:536
blk_mq_timeout_work+0x627/0x870 block/blk-mq.c:1763
process_one_work+0x956/0x1aa0 kernel/workqueue.c:3257
process_scheduled_works kernel/workqueue.c:3340 [inline]
worker_thread+0x65c/0xe60 kernel/workqueue.c:3421
kthread+0x41a/0x930 kernel/kthread.c:463
ret_from_fork+0x6f8/0x8c0 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246
</TASK>
irq event stamp: 74478
hardirqs last enabled at (74477): [<ffffffffb5720a9c>] __raw_spin_unlock_irq include/linux/spinlock_api_smp.h:159 [inline]
hardirqs last enabled at (74477): [<ffffffffb5720a9c>] _raw_spin_unlock_irq+0x2c/0x60 kernel/locking/spinlock.c:202
hardirqs last disabled at (74478): [<ffffffffb57207b5>] __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:108 [inline]
hardirqs last disabled at (74478): [<ffffffffb57207b5>] _raw_spin_lock_irqsave+0x85/0xa0 kernel/locking/spinlock.c:162
softirqs last enabled at (74304): [<ffffffffb1e9466c>] __do_softirq kernel/softirq.c:656 [inline]
softirqs last enabled at (74304): [<ffffffffb1e9466c>] invoke_softirq kernel/softirq.c:496 [inline]
softirqs last enabled at (74304): [<ffffffffb1e9466c>] __irq_exit_rcu+0xdc/0x120
---truncated---
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fa059b856a593a7bddd4d3779ae8ab1380e05d91 Version: fa059b856a593a7bddd4d3779ae8ab1380e05d91 Version: fa059b856a593a7bddd4d3779ae8ab1380e05d91 Version: fa059b856a593a7bddd4d3779ae8ab1380e05d91 Version: fa059b856a593a7bddd4d3779ae8ab1380e05d91 Version: fa059b856a593a7bddd4d3779ae8ab1380e05d91 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nvme/host/pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "265dbc9bc33c29f60f90be3e0afe1c4067ebb70b",
"status": "affected",
"version": "fa059b856a593a7bddd4d3779ae8ab1380e05d91",
"versionType": "git"
},
{
"lessThan": "628773eba024d1107cc9ec157a682cbb42ac912a",
"status": "affected",
"version": "fa059b856a593a7bddd4d3779ae8ab1380e05d91",
"versionType": "git"
},
{
"lessThan": "843e913cef4e33723663a899727f685a95ab53fe",
"status": "affected",
"version": "fa059b856a593a7bddd4d3779ae8ab1380e05d91",
"versionType": "git"
},
{
"lessThan": "b56c49897bdac5cb49e3495ef421c391628ee9bb",
"status": "affected",
"version": "fa059b856a593a7bddd4d3779ae8ab1380e05d91",
"versionType": "git"
},
{
"lessThan": "e311d84c62eb76e025e11a44155b402e55950b83",
"status": "affected",
"version": "fa059b856a593a7bddd4d3779ae8ab1380e05d91",
"versionType": "git"
},
{
"lessThan": "fc71f409b22ca831a9f87a2712eaa09ef2bb4a5e",
"status": "affected",
"version": "fa059b856a593a7bddd4d3779ae8ab1380e05d91",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nvme/host/pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.19",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.167",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.19",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.9",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: Fix race bug in nvme_poll_irqdisable()\n\nIn the following scenario, pdev can be disabled between (1) and (3) by\n(2). This sets pdev-\u003emsix_enabled = 0. Then, pci_irq_vector() will\nreturn MSI-X IRQ(\u003e15) for (1) whereas return INTx IRQ(\u003c=15) for (2).\nThis causes IRQ warning because it tries to enable INTx IRQ that has\nnever been disabled before.\n\nTo fix this, save IRQ number into a local variable and ensure\ndisable_irq() and enable_irq() operate on the same IRQ number. Even if\npci_free_irq_vectors() frees the IRQ concurrently, disable_irq() and\nenable_irq() on a stale IRQ number is still valid and safe, and the\ndepth accounting reamins balanced.\n\ntask 1:\nnvme_poll_irqdisable()\n disable_irq(pci_irq_vector(pdev, nvmeq-\u003ecq_vector)) ...(1)\n enable_irq(pci_irq_vector(pdev, nvmeq-\u003ecq_vector)) ...(3)\n\ntask 2:\nnvme_reset_work()\n nvme_dev_disable()\n pdev-\u003emsix_enable = 0; ...(2)\n\ncrash log:\n\n------------[ cut here ]------------\nUnbalanced enable for IRQ 10\nWARNING: kernel/irq/manage.c:753 at __enable_irq+0x102/0x190 kernel/irq/manage.c:753, CPU#1: kworker/1:0H/26\nModules linked in:\nCPU: 1 UID: 0 PID: 26 Comm: kworker/1:0H Not tainted 6.19.0-dirty #9 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\nWorkqueue: kblockd blk_mq_timeout_work\nRIP: 0010:__enable_irq+0x107/0x190 kernel/irq/manage.c:753\nCode: ff df 48 89 fa 48 c1 ea 03 0f b6 14 02 48 89 f8 83 e0 07 83 c0 03 38 d0 7c 04 84 d2 75 79 48 8d 3d 2e 7a 3f 05 41 8b 74 24 2c \u003c67\u003e 48 0f b9 3a e8 ef b9 21 00 5b 41 5c 5d e9 46 54 66 03 e8 e1 b9\nRSP: 0018:ffffc900001bf550 EFLAGS: 00010046\nRAX: 0000000000000007 RBX: 0000000000000000 RCX: ffffffffb20c0e90\nRDX: 0000000000000000 RSI: 000000000000000a RDI: ffffffffb74b88f0\nRBP: ffffc900001bf560 R08: ffff88800197cf00 R09: 0000000000000001\nR10: 0000000000000003 R11: 0000000000000003 R12: ffff8880012a6000\nR13: 1ffff92000037eae R14: 000000000000000a R15: 0000000000000293\nFS: 0000000000000000(0000) GS:ffff8880b49f7000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000555da4a25fa8 CR3: 00000000208e8000 CR4: 00000000000006f0\nCall Trace:\n \u003cTASK\u003e\n enable_irq+0x121/0x1e0 kernel/irq/manage.c:797\n nvme_poll_irqdisable+0x162/0x1c0 drivers/nvme/host/pci.c:1494\n nvme_timeout+0x965/0x14b0 drivers/nvme/host/pci.c:1744\n blk_mq_rq_timed_out block/blk-mq.c:1653 [inline]\n blk_mq_handle_expired+0x227/0x2d0 block/blk-mq.c:1721\n bt_iter+0x2fc/0x3a0 block/blk-mq-tag.c:292\n __sbitmap_for_each_set include/linux/sbitmap.h:269 [inline]\n sbitmap_for_each_set include/linux/sbitmap.h:290 [inline]\n bt_for_each block/blk-mq-tag.c:324 [inline]\n blk_mq_queue_tag_busy_iter+0x969/0x1e80 block/blk-mq-tag.c:536\n blk_mq_timeout_work+0x627/0x870 block/blk-mq.c:1763\n process_one_work+0x956/0x1aa0 kernel/workqueue.c:3257\n process_scheduled_works kernel/workqueue.c:3340 [inline]\n worker_thread+0x65c/0xe60 kernel/workqueue.c:3421\n kthread+0x41a/0x930 kernel/kthread.c:463\n ret_from_fork+0x6f8/0x8c0 arch/x86/kernel/process.c:158\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246\n \u003c/TASK\u003e\nirq event stamp: 74478\nhardirqs last enabled at (74477): [\u003cffffffffb5720a9c\u003e] __raw_spin_unlock_irq include/linux/spinlock_api_smp.h:159 [inline]\nhardirqs last enabled at (74477): [\u003cffffffffb5720a9c\u003e] _raw_spin_unlock_irq+0x2c/0x60 kernel/locking/spinlock.c:202\nhardirqs last disabled at (74478): [\u003cffffffffb57207b5\u003e] __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:108 [inline]\nhardirqs last disabled at (74478): [\u003cffffffffb57207b5\u003e] _raw_spin_lock_irqsave+0x85/0xa0 kernel/locking/spinlock.c:162\nsoftirqs last enabled at (74304): [\u003cffffffffb1e9466c\u003e] __do_softirq kernel/softirq.c:656 [inline]\nsoftirqs last enabled at (74304): [\u003cffffffffb1e9466c\u003e] invoke_softirq kernel/softirq.c:496 [inline]\nsoftirqs last enabled at (74304): [\u003cffffffffb1e9466c\u003e] __irq_exit_rcu+0xdc/0x120\n---truncated---"
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:24:47.245Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/265dbc9bc33c29f60f90be3e0afe1c4067ebb70b"
},
{
"url": "https://git.kernel.org/stable/c/628773eba024d1107cc9ec157a682cbb42ac912a"
},
{
"url": "https://git.kernel.org/stable/c/843e913cef4e33723663a899727f685a95ab53fe"
},
{
"url": "https://git.kernel.org/stable/c/b56c49897bdac5cb49e3495ef421c391628ee9bb"
},
{
"url": "https://git.kernel.org/stable/c/e311d84c62eb76e025e11a44155b402e55950b83"
},
{
"url": "https://git.kernel.org/stable/c/fc71f409b22ca831a9f87a2712eaa09ef2bb4a5e"
}
],
"title": "nvme-pci: Fix race bug in nvme_poll_irqdisable()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43448",
"datePublished": "2026-05-08T14:22:14.633Z",
"dateReserved": "2026-05-01T14:12:56.010Z",
"dateUpdated": "2026-05-11T22:24:47.245Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68238 (GCVE-0-2026-68238)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-25 05:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Release VFCT ACPI table reference
amdgpu_acpi_vfct_bios() fetches the VFCT table with acpi_get_table()
but never releases it. acpi_get_table() takes a reference on the
table (incrementing its validation_count and mapping it on the 0->1
transition); without a paired acpi_put_table() the mapping is leaked
on every call, whether or not a matching VBIOS image is found.
Route all exit paths after the table is acquired through a common
acpi_put_table(). The VBIOS image is copied out with kmemdup() before
the table is released, so it remains valid for the caller.
(cherry picked from commit ca5988682b4cba4cd125a0fa99b2de1239164ae4)
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_bios.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "312278b3091912fa56a6a587609f17dcb33465c2",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "9b7de3ee5d2c5ee2a706e5f7ca0126f4fbea4da8",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "65bff26617607c1331283232016c0e89088c5b78",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_bios.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Release VFCT ACPI table reference\n\namdgpu_acpi_vfct_bios() fetches the VFCT table with acpi_get_table()\nbut never releases it. acpi_get_table() takes a reference on the\ntable (incrementing its validation_count and mapping it on the 0-\u003e1\ntransition); without a paired acpi_put_table() the mapping is leaked\non every call, whether or not a matching VBIOS image is found.\n\nRoute all exit paths after the table is acquired through a common\nacpi_put_table(). The VBIOS image is copied out with kmemdup() before\nthe table is released, so it remains valid for the caller.\n\n(cherry picked from commit ca5988682b4cba4cd125a0fa99b2de1239164ae4)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:23:09.441Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/312278b3091912fa56a6a587609f17dcb33465c2"
},
{
"url": "https://git.kernel.org/stable/c/9b7de3ee5d2c5ee2a706e5f7ca0126f4fbea4da8"
},
{
"url": "https://git.kernel.org/stable/c/65bff26617607c1331283232016c0e89088c5b78"
}
],
"title": "drm/amdgpu: Release VFCT ACPI table reference",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68238",
"datePublished": "2026-08-10T12:01:03.277Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-25T05:23:09.441Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74509 (GCVE-0-2026-74509)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: Fix advertising data UAFs
hci_find_adv_instance() returns an adv_info pointer that is valid only
while hdev->lock is held. The advertising command-sync paths perform
instance lookups without that lock and, in some cases, retain the pointer
while waiting for a controller response.
An advertising termination event can therefore interleave as follows:
hci_cmd_sync_work hci_rx_work
hci_find_adv_instance()
__hci_cmd_sync_status()
wait for controller reply hci_dev_lock()
hci_remove_adv_instance()
kfree(adv)
adv->scan_rsp_changed = false
KASAN reported:
BUG: KASAN: slab-use-after-free in hci_set_ext_scan_rsp_data_sync+0x2e1/0x300
Write of size 1 at addr ffff88810a45d21d by task kworker/u17:0/88
Workqueue: hci0 hci_cmd_sync_work
Call Trace:
hci_set_ext_scan_rsp_data_sync+0x2e1/0x300
hci_schedule_adv_instance_sync+0x390/0x4c0
hci_cmd_sync_work+0x173/0x300
Allocated by task 87:
hci_add_adv_instance+0x538/0xac0
add_advertising+0x885/0x1160
Freed by task 89:
kfree+0x131/0x3c0
hci_remove_adv_instance+0x1d8/0x3b0
hci_le_ext_adv_term_evt+0x17b/0x730
Protect the instance lookup and payload construction in the extended
advertising, scan response, and periodic advertising data paths. Snapshot
the advertising parameters under hdev->lock, but release the lock before
waiting for the controller.
Clear advertising-data dirty bits before issuing their commands and
restore them after a failure using a fresh lookup. Likewise, update the
reported transmit power through a fresh lookup after the parameter command
completes. No adv_info pointer then survives an HCI command wait.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: 42fe380baaaccbe635c34ca07b29d19b9ec2498d Version: 5.15.210 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "565971488191bf54a87a417abafab6ad0de72201",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"lessThan": "c4cec575a6d6f7c36808a3a0017b0675968bb06b",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"lessThan": "95cdcd8c82a501931fd3ae9b3811b0b6da167e94",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"lessThan": "eb1d8318764de7216e6dbba29a24d69f7ce51348",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"lessThan": "b16ebdbebd2d37f4cdc590bc3e9db71fe90350a3",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"lessThan": "cdc36db204ffd97b947d64374cf23a210dc74777",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"status": "affected",
"version": "42fe380baaaccbe635c34ca07b29d19b9ec2498d",
"versionType": "git"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.210",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.210",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Fix advertising data UAFs\n\nhci_find_adv_instance() returns an adv_info pointer that is valid only\nwhile hdev-\u003elock is held. The advertising command-sync paths perform\ninstance lookups without that lock and, in some cases, retain the pointer\nwhile waiting for a controller response.\n\nAn advertising termination event can therefore interleave as follows:\n\n hci_cmd_sync_work hci_rx_work\n hci_find_adv_instance()\n __hci_cmd_sync_status()\n wait for controller reply hci_dev_lock()\n hci_remove_adv_instance()\n kfree(adv)\n adv-\u003escan_rsp_changed = false\n\nKASAN reported:\n\n BUG: KASAN: slab-use-after-free in hci_set_ext_scan_rsp_data_sync+0x2e1/0x300\n Write of size 1 at addr ffff88810a45d21d by task kworker/u17:0/88\n Workqueue: hci0 hci_cmd_sync_work\n Call Trace:\n hci_set_ext_scan_rsp_data_sync+0x2e1/0x300\n hci_schedule_adv_instance_sync+0x390/0x4c0\n hci_cmd_sync_work+0x173/0x300\n Allocated by task 87:\n hci_add_adv_instance+0x538/0xac0\n add_advertising+0x885/0x1160\n Freed by task 89:\n kfree+0x131/0x3c0\n hci_remove_adv_instance+0x1d8/0x3b0\n hci_le_ext_adv_term_evt+0x17b/0x730\n\nProtect the instance lookup and payload construction in the extended\nadvertising, scan response, and periodic advertising data paths. Snapshot\nthe advertising parameters under hdev-\u003elock, but release the lock before\nwaiting for the controller.\n\nClear advertising-data dirty bits before issuing their commands and\nrestore them after a failure using a fresh lookup. Likewise, update the\nreported transmit power through a fresh lookup after the parameter command\ncompletes. No adv_info pointer then survives an HCI command wait."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is in the Bluetooth HCI LE extended-advertising path; a remote/adjacent peer can deliver the LE Extended Advertising Set Terminated HCI event that frees adv_info while hci_cmd_sync_work waits on the controller during scan-response/advertising-data updates on phones and other BLE devices.\nAC:L - This is a use-after-free race between hci_cmd_sync_work and hci_rx_work where the attacker controls the terminating side by repeatedly initiating BLE connections/terminations during the up-to-2s HCI command wait, and can also drive the setup side via MGMT advertising commands.\nPR:N - An adjacent Bluetooth attacker needs no account, credentials, or capabilities on the victim; exploitation only requires the victim stack to be configuring BLE advertising (normal on Android phones, laptops, and IoT) while the attacker sends over-the-air BLE traffic to trigger hci_le_ext_adv_term_evt.\nUI:N - No deliberate victim action is required beyond a device running Bluetooth with LE advertising updates (common default behavior); the attacker triggers the race remotely without social engineering, file opens, or mounts.\nS:U - Impact is kernel heap corruption and potential local privilege escalation within the same kernel security domain; it does not cross a VM, container, or IOMMU boundary.\nC:H - Multiple UAF paths read freed adv_info (e.g., eir_create_scan_rsp/adv_data) and retain dangling pointers across __hci_cmd_sync_status waits, enabling slab reuse and arbitrary kernel memory disclosure via heap grooming.\nI:H - KASAN shows a post-free write to adv_info (scan_rsp_changed); similar paths write adv_data_changed and tx_power on freed objects, providing exploitable heap corruption for arbitrary kernel writes and code execution.\nA:H - Use-after-free on adv_info in hci_cmd_sync_work can cause immediate kernel oops/panic or hung BLE subsystem during advertising reconfiguration, and is reachable from unauthenticated adjacent BLE interaction on actively advertising devices."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:46.394Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/565971488191bf54a87a417abafab6ad0de72201"
},
{
"url": "https://git.kernel.org/stable/c/c4cec575a6d6f7c36808a3a0017b0675968bb06b"
},
{
"url": "https://git.kernel.org/stable/c/95cdcd8c82a501931fd3ae9b3811b0b6da167e94"
},
{
"url": "https://git.kernel.org/stable/c/eb1d8318764de7216e6dbba29a24d69f7ce51348"
},
{
"url": "https://git.kernel.org/stable/c/b16ebdbebd2d37f4cdc590bc3e9db71fe90350a3"
},
{
"url": "https://git.kernel.org/stable/c/cdc36db204ffd97b947d64374cf23a210dc74777"
}
],
"title": "Bluetooth: hci_sync: Fix advertising data UAFs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74509",
"datePublished": "2026-08-15T12:27:31.896Z",
"dateReserved": "2026-08-15T05:44:03.909Z",
"dateUpdated": "2026-08-27T12:39:46.394Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64568 (GCVE-0-2026-64568)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
ieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old
template before allocating the replacement. If the kzalloc() then fails,
it returns -ENOMEM while link->u.ap.unsol_bcast_probe_resp still points
at the object already queued for freeing. A later update or AP teardown
re-queues that same rcu_head; the second free is caught by KASAN when the
RCU sheaf is processed in softirq:
BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)
Free of addr ffff88800d06f300 by task exploit/145
...
__rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)
rcu_free_sheaf (mm/slub.c:5850)
rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)
handle_softirqs (kernel/softirq.c:622)
The buggy address belongs to the cache kmalloc-128 of size 128
Queue the old object for kfree_rcu() only after the new one is published,
matching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/cfg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ca27a81cd77b698e5eb586a011bee6800c7ee4bd",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "0ace76e410d7f7d813b605825a3e593a79c3958f",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "1d067abcd37062426c59ec73dbc4e87a63f33fea",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/cfg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure\n\nieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old\ntemplate before allocating the replacement. If the kzalloc() then fails,\nit returns -ENOMEM while link-\u003eu.ap.unsol_bcast_probe_resp still points\nat the object already queued for freeing. A later update or AP teardown\nre-queues that same rcu_head; the second free is caught by KASAN when the\nRCU sheaf is processed in softirq:\n\n BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n Free of addr ffff88800d06f300 by task exploit/145\n ...\n __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n rcu_free_sheaf (mm/slub.c:5850)\n rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n handle_softirqs (kernel/softirq.c:622)\n The buggy address belongs to the cache kmalloc-128 of size 128\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered only via local nl80211 SoftAP config (NL80211_CMD_START_AP/SET_BEACON/CHANNEL_SWITCH/COLOR_CHANGE \u2192 ieee80211_set_unsol_bcast_probe_resp), not by processing over-the-air WiFi frames or remote packets.\nAC:L - The attacker fully controls the SET_BEACON/STOP_AP sequence and can force the GFP_KERNEL kzalloc failure (e.g. memory pressure/memcg) with an attacker-chosen template size; no race or condition outside attacker influence is required.\nPR:L - START_AP and SET_BEACON use GENL_UNS_ADMIN_PERM (CAP_NET_ADMIN in the wiphy netns user_ns). Per CNA guidance that capability via user namespaces scores Low, not init-namespace root High.\nUI:N - The attacker issues the nl80211 commands to set the unsolicited broadcast probe response template and later tear down or update the AP; no separate victim action is required.\nS:U - Impact stays inside the host kernel mac80211 heap (local privilege-escalation class) and does not cross a VM, IOMMU, or other separate security authority.\nC:H - After the failed alloc the dangling unsol_bcast_probe_resp pointer can be read via ieee80211_get_unsol_bcast_probe_resp_tmpl and the object is double-freed; double-free/UAF enables heap reuse and arbitrary kernel memory disclosure.\nI:H - Double-free of the attacker-sized kmalloc unsol_bcast_probe_resp template (and subsequent stop_ap/update re-free) is classic heap corruption enabling spray/arbitrary-write and control-flow hijack primitives.\nA:H - The bug is a KASAN-confirmed double-free in rcu_free_sheaf softirq processing (task exploit/145) and can oops/panic the kernel, fully denying availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:46.839Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ca27a81cd77b698e5eb586a011bee6800c7ee4bd"
},
{
"url": "https://git.kernel.org/stable/c/d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae"
},
{
"url": "https://git.kernel.org/stable/c/0ace76e410d7f7d813b605825a3e593a79c3958f"
},
{
"url": "https://git.kernel.org/stable/c/1d067abcd37062426c59ec73dbc4e87a63f33fea"
}
],
"title": "wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64568",
"datePublished": "2026-08-05T08:08:06.625Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-17T04:57:46.839Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64412 (GCVE-0-2026-64412)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ebtables: module names must be null-terminated
We need to explicitly check the length, else we may pass non-null
terminated string to request_module().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bcf4934288402be3464110109a4dae3bd6fb3e93 Version: bcf4934288402be3464110109a4dae3bd6fb3e93 Version: bcf4934288402be3464110109a4dae3bd6fb3e93 Version: bcf4934288402be3464110109a4dae3bd6fb3e93 Version: bcf4934288402be3464110109a4dae3bd6fb3e93 Version: bcf4934288402be3464110109a4dae3bd6fb3e93 Version: bcf4934288402be3464110109a4dae3bd6fb3e93 Version: bcf4934288402be3464110109a4dae3bd6fb3e93 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:34.392Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bridge/netfilter/ebtables.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "43dd2332b8a27b3ac5108791680cade654ab0f96",
"status": "affected",
"version": "bcf4934288402be3464110109a4dae3bd6fb3e93",
"versionType": "git"
},
{
"lessThan": "5777c8f1c3610786d8482b8f620f40fccaf1542b",
"status": "affected",
"version": "bcf4934288402be3464110109a4dae3bd6fb3e93",
"versionType": "git"
},
{
"lessThan": "0ddca0f90fa3395111d078ae4399615cf3ea94aa",
"status": "affected",
"version": "bcf4934288402be3464110109a4dae3bd6fb3e93",
"versionType": "git"
},
{
"lessThan": "d2367d99f2455f373996d9ddbe833dbe9f942213",
"status": "affected",
"version": "bcf4934288402be3464110109a4dae3bd6fb3e93",
"versionType": "git"
},
{
"lessThan": "da32e78bbb187ed7b137e0007034185570a3a172",
"status": "affected",
"version": "bcf4934288402be3464110109a4dae3bd6fb3e93",
"versionType": "git"
},
{
"lessThan": "13a5f532e3a4fc75c33060a026def1572c208643",
"status": "affected",
"version": "bcf4934288402be3464110109a4dae3bd6fb3e93",
"versionType": "git"
},
{
"lessThan": "7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8",
"status": "affected",
"version": "bcf4934288402be3464110109a4dae3bd6fb3e93",
"versionType": "git"
},
{
"lessThan": "084d23f818321390509e9738a0b08bbf46df6425",
"status": "affected",
"version": "bcf4934288402be3464110109a4dae3bd6fb3e93",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bridge/netfilter/ebtables.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: module names must be null-terminated\n\nWe need to explicitly check the length, else we may pass non-null\nterminated string to request_module()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable ebtables replacement path is reached through a local setsockopt syscall, not through received network traffic.\nAC:L - The attacker controls the complete table blob, including offsets, allocation size, and unterminated match name; no race or uncontrollable condition is required.\nPR:L - The path requires CAP_NET_ADMIN in the socket network namespace, which an unprivileged user can obtain by creating user and network namespaces on deployments permitting unprivileged user namespaces.\nUI:N - Exploitation requires no action by another user after the attacker invokes setsockopt with the crafted table.\nS:U - The vulnerability affects the host kernel within the same security authority and does not cross a virtualization or IOMMU boundary.\nC:H - The unbounded %s traversal constitutes an out-of-bounds kernel read that can continue beyond the match-name field and table allocation; under the required higher-severity treatment for unbounded OOB reads, confidentiality impact is High.\nI:N - The vulnerable operation only reads while formatting a module name; there is no demonstrated out-of-bounds write, use-after-free, or control-flow modification primitive.\nA:H - A page-aligned nonzero table blob can make vsnprintf scan into the vmalloc guard page, causing a kernel oops or panic, and the attacker can repeat the trigger."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:11.246Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/43dd2332b8a27b3ac5108791680cade654ab0f96"
},
{
"url": "https://git.kernel.org/stable/c/5777c8f1c3610786d8482b8f620f40fccaf1542b"
},
{
"url": "https://git.kernel.org/stable/c/0ddca0f90fa3395111d078ae4399615cf3ea94aa"
},
{
"url": "https://git.kernel.org/stable/c/d2367d99f2455f373996d9ddbe833dbe9f942213"
},
{
"url": "https://git.kernel.org/stable/c/da32e78bbb187ed7b137e0007034185570a3a172"
},
{
"url": "https://git.kernel.org/stable/c/13a5f532e3a4fc75c33060a026def1572c208643"
},
{
"url": "https://git.kernel.org/stable/c/7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8"
},
{
"url": "https://git.kernel.org/stable/c/084d23f818321390509e9738a0b08bbf46df6425"
}
],
"title": "netfilter: ebtables: module names must be null-terminated",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64412",
"datePublished": "2026-07-25T08:50:52.946Z",
"dateReserved": "2026-07-19T15:36:31.786Z",
"dateUpdated": "2026-09-08T08:50:34.392Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72466 (GCVE-0-2026-72466)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xprtrdma: Fix bcall rep leak and unbounded peek
rpcrdma_is_bcall() decodes a reply's first words to decide whether
the frame is a backchannel call. Two issues in that decode path
let a short or malformed reply leak the receive buffer and drain
the Receive queue.
First, the speculative peek
p = xdr_inline_decode(xdr, 0);
/* five p++ reads follow */
asks xdr_inline_decode() for zero bytes, which returns xdr->p
without consulting xdr->end. The five subsequent __be32 reads can
then walk up to 20 bytes past the wire payload into stale regbuf
contents and misclassify the reply as a backchannel call.
Second, after the post-peek
p = xdr_inline_decode(xdr, 3 * sizeof(*p));
if (unlikely(!p))
return true;
the short-header arm returns true without calling
rpcrdma_bc_receive_call(). The contract with the caller is that a
true return transfers ownership of rep to the backchannel path:
rpcrdma_reply_handler()
if (rpcrdma_is_bcall(r_xprt, rep))
return; /* bare return, skips out_post */
...
out_post:
rpcrdma_post_recvs(r_xprt, credits + ...);
Because rpcrdma_bc_receive_call() never ran, no one took rep, but
rpcrdma_reply_handler still bare-returns past rpcrdma_rep_put()
and rpcrdma_post_recvs(). The rep, with its persistently
DMA-mapped receive buffer, is orphaned on rb_all_reps and freed
only at transport teardown. This completion reposts nothing, so
its slot is reclaimed only when a later forward-channel reply
reaches out_post and rpcrdma_post_recvs() allocates a fresh rep to
backfill; absent that traffic the Receive queue drains and the
peer's Sends draw RNR NAKs.
Fix by consulting xdr->end after the zero-length peek so the five
__be32 reads cannot run unless 20 bytes of wire payload remain. A
byte-precise comparison against xdr->end is required because a
non-4-aligned receive rounds the stream's word count up past the
true payload. Also return false from the short-header arm so the
reply falls through the normal out_norqst cleanup chain
(rpcrdma_rep_put() plus rpcrdma_post_recvs()).
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 41c8f70f5a3db7e06179186b6525fd9ee1d7d314 Version: 41c8f70f5a3db7e06179186b6525fd9ee1d7d314 Version: 41c8f70f5a3db7e06179186b6525fd9ee1d7d314 Version: 41c8f70f5a3db7e06179186b6525fd9ee1d7d314 Version: 41c8f70f5a3db7e06179186b6525fd9ee1d7d314 Version: 41c8f70f5a3db7e06179186b6525fd9ee1d7d314 Version: 41c8f70f5a3db7e06179186b6525fd9ee1d7d314 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sunrpc/xprtrdma/rpc_rdma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0cee8f9c3b14bd6dee9c4310090a7f45b89b834f",
"status": "affected",
"version": "41c8f70f5a3db7e06179186b6525fd9ee1d7d314",
"versionType": "git"
},
{
"lessThan": "7afc2f8d2fd9394724df9eaf22ce7a71029a5fba",
"status": "affected",
"version": "41c8f70f5a3db7e06179186b6525fd9ee1d7d314",
"versionType": "git"
},
{
"lessThan": "88b5346284a184a6b7d019912232a571d672d3e3",
"status": "affected",
"version": "41c8f70f5a3db7e06179186b6525fd9ee1d7d314",
"versionType": "git"
},
{
"lessThan": "07aa506436be7634e381e1e1f6d0efa9efc81ecc",
"status": "affected",
"version": "41c8f70f5a3db7e06179186b6525fd9ee1d7d314",
"versionType": "git"
},
{
"lessThan": "d7a2870dde3bb09d51d6b9c877642996ad6b92dd",
"status": "affected",
"version": "41c8f70f5a3db7e06179186b6525fd9ee1d7d314",
"versionType": "git"
},
{
"lessThan": "118a16a18c59f7ad8084b2d13988839b669fca10",
"status": "affected",
"version": "41c8f70f5a3db7e06179186b6525fd9ee1d7d314",
"versionType": "git"
},
{
"lessThan": "c7653d5cebc8492c77ec0415b5e9c0fb3e644bc6",
"status": "affected",
"version": "41c8f70f5a3db7e06179186b6525fd9ee1d7d314",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sunrpc/xprtrdma/rpc_rdma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Fix bcall rep leak and unbounded peek\n\nrpcrdma_is_bcall() decodes a reply\u0027s first words to decide whether\nthe frame is a backchannel call. Two issues in that decode path\nlet a short or malformed reply leak the receive buffer and drain\nthe Receive queue.\n\nFirst, the speculative peek\n\n p = xdr_inline_decode(xdr, 0);\n /* five p++ reads follow */\n\nasks xdr_inline_decode() for zero bytes, which returns xdr-\u003ep\nwithout consulting xdr-\u003eend. The five subsequent __be32 reads can\nthen walk up to 20 bytes past the wire payload into stale regbuf\ncontents and misclassify the reply as a backchannel call.\n\nSecond, after the post-peek\n\n p = xdr_inline_decode(xdr, 3 * sizeof(*p));\n if (unlikely(!p))\n return true;\n\nthe short-header arm returns true without calling\nrpcrdma_bc_receive_call(). The contract with the caller is that a\ntrue return transfers ownership of rep to the backchannel path:\n\n rpcrdma_reply_handler()\n if (rpcrdma_is_bcall(r_xprt, rep))\n return; /* bare return, skips out_post */\n ...\n out_post:\n rpcrdma_post_recvs(r_xprt, credits + ...);\n\nBecause rpcrdma_bc_receive_call() never ran, no one took rep, but\nrpcrdma_reply_handler still bare-returns past rpcrdma_rep_put()\nand rpcrdma_post_recvs(). The rep, with its persistently\nDMA-mapped receive buffer, is orphaned on rb_all_reps and freed\nonly at transport teardown. This completion reposts nothing, so\nits slot is reclaimed only when a later forward-channel reply\nreaches out_post and rpcrdma_post_recvs() allocates a fresh rep to\nbackfill; absent that traffic the Receive queue drains and the\npeer\u0027s Sends draw RNR NAKs.\n\nFix by consulting xdr-\u003eend after the zero-length peek so the five\n__be32 reads cannot run unless 20 bytes of wire payload remain. A\nbyte-precise comparison against xdr-\u003eend is required because a\nnon-4-aligned receive rounds the stream\u0027s word count up past the\ntrue payload. Also return false from the short-header arm so the\nreply falls through the normal out_norqst cleanup chain\n(rpcrdma_rep_put() plus rpcrdma_post_recvs())."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached when a remote RDMA peer\u0027s inbound message completes in rpcrdma_wc_receive() and rpcrdma_reply_handler() decodes it; a malicious or compromised NFS-over-RDMA server can send crafted short rdma_msg replies over the established RPC/RDMA connection without local access.\nAC:L - On an active NFSv4.1+ RPC/RDMA session the attacker fully controls inbound replies and can repeatedly send short/malformed rdma_msg frames to hit the zero-length peek and short-header return-true paths, reliably leaking receive buffers and draining the Receive queue.\nPR:N - Exploitation requires only network reachability as the connected RDMA/RPC peer (e.g., a malicious NFS server); no local account, mount privileges, or namespaced capabilities on the victim NFS client are needed to deliver the malformed RDMA replies.\nUI:N - Once an NFS-over-RDMA mount and NFSv4.1 backchannel session exist, triggering the flaw needs no additional victim action beyond the attacker sending malicious RDMA receive payloads during normal client-server communication.\nS:U - The vulnerability and its impact remain within the NFS client\u0027s kernel SUNRPC/xprtrdma transport context; it does not cross a VM, container, or IOMMU security boundary to affect other authorities.\nC:H - xdr_inline_decode(xdr,0) permits up to five subsequent __be32 reads past the wire payload into stale receive-buffer contents, an out-of-bounds read that can misclassify replies and expose remnants of prior RPC/NFS data to unintended processing paths.\nI:H - Stale-buffer-assisted misclassification can treat a forward-channel reply as a backchannel RPC_CALL, a type confusion that routes attacker-influenced bytes into rpcrdma_bc_receive_call()/NFSv4 callback handling and can corrupt client session state.\nA:H - Each successful trigger orphans a DMA-mapped rpcrdma_rep and skips rpcrdma_post_recvs(), monotonically draining the RDMA Receive queue until the peer gets RNR NAKs and the NFS-over-RDMA connection becomes unusable, enabling sustained remote denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:44:32.887Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0cee8f9c3b14bd6dee9c4310090a7f45b89b834f"
},
{
"url": "https://git.kernel.org/stable/c/7afc2f8d2fd9394724df9eaf22ce7a71029a5fba"
},
{
"url": "https://git.kernel.org/stable/c/88b5346284a184a6b7d019912232a571d672d3e3"
},
{
"url": "https://git.kernel.org/stable/c/07aa506436be7634e381e1e1f6d0efa9efc81ecc"
},
{
"url": "https://git.kernel.org/stable/c/d7a2870dde3bb09d51d6b9c877642996ad6b92dd"
},
{
"url": "https://git.kernel.org/stable/c/118a16a18c59f7ad8084b2d13988839b669fca10"
},
{
"url": "https://git.kernel.org/stable/c/c7653d5cebc8492c77ec0415b5e9c0fb3e644bc6"
}
],
"title": "xprtrdma: Fix bcall rep leak and unbounded peek",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72466",
"datePublished": "2026-08-15T05:57:09.847Z",
"dateReserved": "2026-08-09T03:40:39.933Z",
"dateUpdated": "2026-08-17T05:44:32.887Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72463 (GCVE-0-2026-72463)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: Fix dev use-after-free in xfrm async resumption
xfrm async resumption hold skb->dev refcnt until after transport_finish.
However, xfrm_rcv_cb may modify skb->dev to tunnel dev without taking
device reference, such as vti_rcv_cb. The subsequent async resumption
will decrement the tunnel device's reference count, which lead to uaf
of tunnel dev and refcnt leak of orig dev as below:
unregister_netdevice: waiting for vti1 to become free. Usage count = -2
Stash the original skb->dev to fix refcnt imbalance. The new skb->dev set
by xfrm_rcv_cb can race with device teardown. Extend rcu protection over
xfrm_rcv_cb and transport_finish to prevent races.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1c428b03840094410c5fb6a5db30640486bbbfcb Version: 1c428b03840094410c5fb6a5db30640486bbbfcb Version: 4236c30b437b80f673b9e08c8fae38b8d471ac9e Version: 0f451b43c88bf2b9c038b414be580efee42e031b Version: 5002beda5cac69d522dc54da0d5d463ed9c963d2 Version: 6.12.94 ≤ Version: 6.18.23 ≤ Version: 6.19.13 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/xfrm4_input.c",
"net/ipv6/xfrm6_input.c",
"net/xfrm/xfrm_input.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "63a30015199912bd5055bead8001b1ae68a67cdb",
"status": "affected",
"version": "1c428b03840094410c5fb6a5db30640486bbbfcb",
"versionType": "git"
},
{
"lessThan": "8045c0df98d4f14c54e5cb875f1c9c0ce89fe4ff",
"status": "affected",
"version": "1c428b03840094410c5fb6a5db30640486bbbfcb",
"versionType": "git"
},
{
"status": "affected",
"version": "4236c30b437b80f673b9e08c8fae38b8d471ac9e",
"versionType": "git"
},
{
"status": "affected",
"version": "0f451b43c88bf2b9c038b414be580efee42e031b",
"versionType": "git"
},
{
"status": "affected",
"version": "5002beda5cac69d522dc54da0d5d463ed9c963d2",
"versionType": "git"
},
{
"lessThan": "6.13",
"status": "affected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThan": "6.19",
"status": "affected",
"version": "6.18.23",
"versionType": "semver"
},
{
"lessThan": "6.20",
"status": "affected",
"version": "6.19.13",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/xfrm4_input.c",
"net/ipv6/xfrm6_input.c",
"net/xfrm/xfrm_input.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.0"
},
{
"lessThan": "7.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.12.94",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.18.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.19.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: Fix dev use-after-free in xfrm async resumption\n\nxfrm async resumption hold skb-\u003edev refcnt until after transport_finish.\nHowever, xfrm_rcv_cb may modify skb-\u003edev to tunnel dev without taking\ndevice reference, such as vti_rcv_cb. The subsequent async resumption\nwill decrement the tunnel device\u0027s reference count, which lead to uaf\nof tunnel dev and refcnt leak of orig dev as below:\n\nunregister_netdevice: waiting for vti1 to become free. Usage count = -2\n\nStash the original skb-\u003edev to fix refcnt imbalance. The new skb-\u003edev set\nby xfrm_rcv_cb can race with device teardown. Extend rcu protection over\nxfrm_rcv_cb and transport_finish to prevent races."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Reachable from the network receive path: remote ESP/AH (or UDP-encapsulated IPsec) packets hit ip_rcv \u2192 xfrm4/xfrm6 protocol handlers \u2192 vti/xfrmi input \u2192 xfrm_input() \u2192 async crypto resume, on Internet-facing IPsec/VTI/xfrmi VPN gateways and cloud endpoints.\nAC:L - Once async decryption resumes (encap_type=-1), vti_rcv_cb/xfrmi_rcv_cb retarget skb-\u003edev and the stale dev_put is deterministic; the attacker controls packet rate/volume to drive -EINPROGRESS and can race netdev teardown, so no uncontrollable victim-only conditions apply.\nPR:N - No local account, shell, or capability on the victim is required\u2014only network-delivered IPsec traffic accepted by a pre-configured VTI/xfrmi gateway (e.g., VPN peer, site-to-site endpoint); administrative IPsec setup is deployment state, not attacker privilege on the host.\nUI:N - Exploitation is fully automated by sending IPsec packets; no victim interaction such as mounting filesystems, opening files, or clicking links is needed.\nS:U - Impact is kernel net_device refcount corruption/UAF within the host kernel security authority; it does not cross VM, IOMMU, or sandbox boundaries (standard kernel privilege escalation, not escape).\nC:H - Use-after-free of a net_device after refcount underflow (e.g., usage count=-2) exposes freed netdev/slab memory; per kernel UAF guidance this provides a high-impact arbitrary-read primitive via heap grooming.\nI:H - Corrupting freed net_device structures and reference counts is classic heap UAF that can be shaped into arbitrary kernel writes and control-flow hijack for code execution, per kernel memory-corruption guidance.\nA:H - Refcount imbalance causes unregister_netdevice to hang (usage count=-2), kernel oops/panic during tunnel teardown, and reliable denial of service on IPsec gateways even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:44:29.613Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/63a30015199912bd5055bead8001b1ae68a67cdb"
},
{
"url": "https://git.kernel.org/stable/c/8045c0df98d4f14c54e5cb875f1c9c0ce89fe4ff"
}
],
"title": "xfrm: Fix dev use-after-free in xfrm async resumption",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72463",
"datePublished": "2026-08-15T05:57:07.413Z",
"dateReserved": "2026-08-09T03:40:39.933Z",
"dateUpdated": "2026-08-17T05:44:29.613Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63891 (GCVE-0-2026-63891)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-07-19 14:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
A DIRECTORY entry's value field is used as the dir_offset for a
recursive call into __tb_property_parse_dir() with no depth counter.
A crafted peer that chains DIRECTORY entries into a back-reference
loop drives the parser until the kernel stack is exhausted and the
guard page fires. Any untrusted XDomain peer (cable, dock, in-line
inspector, adjacent host) that reaches the PROPERTIES_REQUEST
control-plane exchange can trigger this without authentication.
Thread a depth counter through tb_property_parse() and
__tb_property_parse_dir(), and reject blocks that exceed
TB_PROPERTY_MAX_DEPTH = 8. That is comfortably larger than any
observed legitimate XDomain layout.
Operators who do not need XDomain host-to-host discovery can disable
the path entirely with thunderbolt.xdomain=0 on the kernel command
line.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cdae7c07e3e3509eaabc18c1640a55dc5b99c179 Version: cdae7c07e3e3509eaabc18c1640a55dc5b99c179 Version: cdae7c07e3e3509eaabc18c1640a55dc5b99c179 Version: cdae7c07e3e3509eaabc18c1640a55dc5b99c179 Version: cdae7c07e3e3509eaabc18c1640a55dc5b99c179 Version: cdae7c07e3e3509eaabc18c1640a55dc5b99c179 Version: cdae7c07e3e3509eaabc18c1640a55dc5b99c179 Version: cdae7c07e3e3509eaabc18c1640a55dc5b99c179 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/thunderbolt/property.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2b5f47a710172c962ef42d1b732b04d2ad0dce21",
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"versionType": "git"
},
{
"lessThan": "95839a67ea56ca35732aad7f711404a3127cfe2d",
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"versionType": "git"
},
{
"lessThan": "0a84ab9271936c11e84e511bb52fc5682f8b6726",
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"versionType": "git"
},
{
"lessThan": "b4621e5ef63405c317a84b711faf3bd75b3c6a94",
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"versionType": "git"
},
{
"lessThan": "f31c6d220f455b5af63590302b30e1b932d14599",
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"versionType": "git"
},
{
"lessThan": "830c8a9b467e7d3a158483d37fa7dc13892b293a",
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"versionType": "git"
},
{
"lessThan": "ed9455ef4bd9babc90f92e526abe3fb68c1a8709",
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"versionType": "git"
},
{
"lessThan": "928abe19fbf0127003abcb1ea69cabc1c897d0ab",
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/thunderbolt/property.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: property: Cap recursion depth in __tb_property_parse_dir()\n\nA DIRECTORY entry\u0027s value field is used as the dir_offset for a\nrecursive call into __tb_property_parse_dir() with no depth counter.\nA crafted peer that chains DIRECTORY entries into a back-reference\nloop drives the parser until the kernel stack is exhausted and the\nguard page fires. Any untrusted XDomain peer (cable, dock, in-line\ninspector, adjacent host) that reaches the PROPERTIES_REQUEST\ncontrol-plane exchange can trigger this without authentication.\n\nThread a depth counter through tb_property_parse() and\n__tb_property_parse_dir(), and reject blocks that exceed\nTB_PROPERTY_MAX_DEPTH = 8. That is comfortably larger than any\nobserved legitimate XDomain layout.\n\nOperators who do not need XDomain host-to-host discovery can disable\nthe path entirely with thunderbolt.xdomain=0 on the kernel command\nline."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:55:02.840Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2b5f47a710172c962ef42d1b732b04d2ad0dce21"
},
{
"url": "https://git.kernel.org/stable/c/95839a67ea56ca35732aad7f711404a3127cfe2d"
},
{
"url": "https://git.kernel.org/stable/c/0a84ab9271936c11e84e511bb52fc5682f8b6726"
},
{
"url": "https://git.kernel.org/stable/c/b4621e5ef63405c317a84b711faf3bd75b3c6a94"
},
{
"url": "https://git.kernel.org/stable/c/f31c6d220f455b5af63590302b30e1b932d14599"
},
{
"url": "https://git.kernel.org/stable/c/830c8a9b467e7d3a158483d37fa7dc13892b293a"
},
{
"url": "https://git.kernel.org/stable/c/ed9455ef4bd9babc90f92e526abe3fb68c1a8709"
},
{
"url": "https://git.kernel.org/stable/c/928abe19fbf0127003abcb1ea69cabc1c897d0ab"
}
],
"title": "thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63891",
"datePublished": "2026-07-19T14:55:02.840Z",
"dateReserved": "2026-07-19T07:54:57.019Z",
"dateUpdated": "2026-07-19T14:55:02.840Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68123 (GCVE-0-2026-68123)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix GSO userspace truncation underflow
OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb
length in OVS_CB(skb)->cutlen. When a later userspace action segments a
GSO skb, queue_gso_packets() reuses that delta for each smaller segment.
A segment can then reach queue_userspace_packet() with cutlen greater
than skb->len, underflowing the length passed to skb_zerocopy().
Store the maximum preserved length instead and bound each consumer
against the current skb length. Use U32_MAX as the no-truncation
sentinel so the value remains valid if skb geometry changes before a
consumer handles it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/openvswitch/actions.c",
"net/openvswitch/datapath.c",
"net/openvswitch/datapath.h",
"net/openvswitch/vport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "50a6a85f3d6b1d22d8436848606cdef5d2c490b4",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "2623c48cc3a8da9a1886fd8f65c0e348f4406fd6",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "e211b081901ffca76674082c73eeaed53524c369",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dc",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "100a23b1613e9218e0af654ef102352c713f0263",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "ea85dbcbe8d4056ecb54352f97743d138ea4c407",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "4032f8ed10fcb84d41c508dfb04be96589f78dfe",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/openvswitch/actions.c",
"net/openvswitch/datapath.c",
"net/openvswitch/datapath.h",
"net/openvswitch/vport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: fix GSO userspace truncation underflow\n\nOVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb\nlength in OVS_CB(skb)-\u003ecutlen. When a later userspace action segments a\nGSO skb, queue_gso_packets() reuses that delta for each smaller segment.\nA segment can then reach queue_userspace_packet() with cutlen greater\nthan skb-\u003elen, underflowing the length passed to skb_zerocopy().\n\nStore the maximum preserved length instead and bound each consumer\nagainst the current skb length. Use U32_MAX as the no-truncation\nsentinel so the value remains valid if skb geometry changes before a\nconsumer handles it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Ingress packets reach ovs_vport_receive() through netdev rx_handlers or tunnel vports; GRO-coalesced GSO skbs from remote senders traverse this path into queue_gso_packets(), so the underflow is reachable from the network without physical access.\nAC:L - The attacker chooses truncation max_len relative to GSO super-skb size and sends traffic that GRO segments predictably; no timing race or fragile heap layout is required to make cutlen exceed a child segment length after __skb_gso_segment().\nPR:N - In multi-tenant cloud/OVN deployments, a remote VM or container can send crafted GSO traffic into the host OVS datapath to hit provider-installed TRUNC+USERSPACE sampling flows without possessing any Linux capabilities on the host.\nUI:N - Triggering the flaw requires only network traffic matching existing OVS flow actions; no victim login, file open, mount, or other interactive step is needed.\nS:U - Impact is kernel memory corruption and crash/escalation within the host kernel security domain; it does not cross a guest-to-hypervisor, VM, or hardware IOMMU trust boundary by itself.\nC:H - Unsigned underflow makes skb-\u003elen-cutlen enormous for skb_zerocopy()/skb_copy_bits(), enabling out-of-bounds reads from the source skb and adjacent slab data, i.e., an exploitable information-disclosure primitive.\nI:H - The same underflowed length can expand destination skbs via skb_len_add()/nlattr sizing, corrupting kernel heap metadata and yielding a write primitive suitable for control-flow hijacking.\nA:H - The miscopied lengths can BUG the skb helpers or cause immediate kernel oops/panic during zerocopy/trim handling, and corrupted metadata can crash the system even if exploitation is not completed."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:34.391Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/50a6a85f3d6b1d22d8436848606cdef5d2c490b4"
},
{
"url": "https://git.kernel.org/stable/c/2623c48cc3a8da9a1886fd8f65c0e348f4406fd6"
},
{
"url": "https://git.kernel.org/stable/c/e211b081901ffca76674082c73eeaed53524c369"
},
{
"url": "https://git.kernel.org/stable/c/a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855"
},
{
"url": "https://git.kernel.org/stable/c/fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dc"
},
{
"url": "https://git.kernel.org/stable/c/100a23b1613e9218e0af654ef102352c713f0263"
},
{
"url": "https://git.kernel.org/stable/c/ea85dbcbe8d4056ecb54352f97743d138ea4c407"
},
{
"url": "https://git.kernel.org/stable/c/4032f8ed10fcb84d41c508dfb04be96589f78dfe"
}
],
"title": "openvswitch: fix GSO userspace truncation underflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68123",
"datePublished": "2026-08-10T11:58:43.727Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:34.391Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53001 (GCVE-0-2026-53001)
Vulnerability from cvelistv5
Published
2026-06-24 16:29
Modified
2026-09-08 08:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xtables: restrict several matches to inet family
This is a partial revert of:
commit ab4f21e6fb1c ("netfilter: xtables: use NFPROTO_UNSPEC in more extensions")
to allow ipv4 and ipv6 only.
- xt_mac
- xt_owner
- xt_physdev
These extensions are not used by ebtables in userspace.
Moreover, xt_realm is only for ipv4, since dst->tclassid is ipv4
specific.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ab4f21e6fb1c09b13c4c3cb8357babe8223471bd Version: ab4f21e6fb1c09b13c4c3cb8357babe8223471bd Version: ab4f21e6fb1c09b13c4c3cb8357babe8223471bd Version: ab4f21e6fb1c09b13c4c3cb8357babe8223471bd Version: ab4f21e6fb1c09b13c4c3cb8357babe8223471bd Version: ab4f21e6fb1c09b13c4c3cb8357babe8223471bd Version: ab4f21e6fb1c09b13c4c3cb8357babe8223471bd Version: ab4f21e6fb1c09b13c4c3cb8357babe8223471bd |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:49:54.277Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/xt_mac.c",
"net/netfilter/xt_owner.c",
"net/netfilter/xt_physdev.c",
"net/netfilter/xt_realm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "14203f9edf944b3fb63faadd62f38452421ecdfc",
"status": "affected",
"version": "ab4f21e6fb1c09b13c4c3cb8357babe8223471bd",
"versionType": "git"
},
{
"lessThan": "7eaf9c740f33230cb224dc265f3c69f8531ff57b",
"status": "affected",
"version": "ab4f21e6fb1c09b13c4c3cb8357babe8223471bd",
"versionType": "git"
},
{
"lessThan": "9a109751b297b0f2135495749ef5a18ba31ec7d4",
"status": "affected",
"version": "ab4f21e6fb1c09b13c4c3cb8357babe8223471bd",
"versionType": "git"
},
{
"lessThan": "cbeb259f31382de70a70a59ffd0e66f5e80d9818",
"status": "affected",
"version": "ab4f21e6fb1c09b13c4c3cb8357babe8223471bd",
"versionType": "git"
},
{
"lessThan": "689a91ff18d6448d94c1ab7c076fecdb2b668bef",
"status": "affected",
"version": "ab4f21e6fb1c09b13c4c3cb8357babe8223471bd",
"versionType": "git"
},
{
"lessThan": "76160e04440c9698b989dbd9492a7ec4f520c9ee",
"status": "affected",
"version": "ab4f21e6fb1c09b13c4c3cb8357babe8223471bd",
"versionType": "git"
},
{
"lessThan": "fa88161ef56e29bdaa05cc89dbc4ee221e94bfe9",
"status": "affected",
"version": "ab4f21e6fb1c09b13c4c3cb8357babe8223471bd",
"versionType": "git"
},
{
"lessThan": "b6fe26f86a1649f84e057f3f15605b08eda15497",
"status": "affected",
"version": "ab4f21e6fb1c09b13c4c3cb8357babe8223471bd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/xt_mac.c",
"net/netfilter/xt_owner.c",
"net/netfilter/xt_physdev.c",
"net/netfilter/xt_realm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"lessThan": "2.6.28",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xtables: restrict several matches to inet family\n\nThis is a partial revert of:\n\n commit ab4f21e6fb1c (\"netfilter: xtables: use NFPROTO_UNSPEC in more extensions\")\n\nto allow ipv4 and ipv6 only.\n\n- xt_mac\n- xt_owner\n- xt_physdev\n\nThese extensions are not used by ebtables in userspace.\n\nMoreover, xt_realm is only for ipv4, since dst-\u003etclassid is ipv4\nspecific."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-24T16:29:13.513Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/14203f9edf944b3fb63faadd62f38452421ecdfc"
},
{
"url": "https://git.kernel.org/stable/c/7eaf9c740f33230cb224dc265f3c69f8531ff57b"
},
{
"url": "https://git.kernel.org/stable/c/9a109751b297b0f2135495749ef5a18ba31ec7d4"
},
{
"url": "https://git.kernel.org/stable/c/cbeb259f31382de70a70a59ffd0e66f5e80d9818"
},
{
"url": "https://git.kernel.org/stable/c/689a91ff18d6448d94c1ab7c076fecdb2b668bef"
},
{
"url": "https://git.kernel.org/stable/c/76160e04440c9698b989dbd9492a7ec4f520c9ee"
},
{
"url": "https://git.kernel.org/stable/c/fa88161ef56e29bdaa05cc89dbc4ee221e94bfe9"
},
{
"url": "https://git.kernel.org/stable/c/b6fe26f86a1649f84e057f3f15605b08eda15497"
}
],
"title": "netfilter: xtables: restrict several matches to inet family",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53001",
"datePublished": "2026-06-24T16:29:13.513Z",
"dateReserved": "2026-06-09T07:44:35.377Z",
"dateUpdated": "2026-09-08T08:49:54.277Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68193 (GCVE-0-2026-68193)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:00
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and
mt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus.
mt7925_mac_tx_free() cleans the DMA tx queues with
mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the
mmio queue ops implement that callback; on USB it is NULL, so a
TXRX_NOTIFY there calls a NULL pointer in the RX worker:
BUG: kernel NULL pointer dereference, address: 0000000000000000
RIP: 0010:0x0
Call Trace:
mt7925_mac_tx_free+0x58/0x350 [mt7925_common]
mt7925_rx_check+0xe2/0x130 [mt7925_common]
mt76u_rx_worker+0x1b9/0x620 [mt76_usb]
Drop the event on non-mmio buses via mt76_is_mmio(), as in
commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for
non-mmio devices").
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0c8c4cd0ca60b45c4b05a39e3769b8473d6836eb",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
},
{
"lessThan": "9cb72f67e1502aabba51aab9ac04ae7c386ee194",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
},
{
"lessThan": "9677e86a5f7d680fe280a5f8999bc57353e360d7",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
},
{
"lessThan": "feeff151c83e7f0ffcdedcad5343852d23d1f6e1",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses\n\nPKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and\nmt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus.\nmt7925_mac_tx_free() cleans the DMA tx queues with\nmt76_queue_tx_cleanup(), which calls queue_ops-\u003etx_cleanup(). Only the\nmmio queue ops implement that callback; on USB it is NULL, so a\nTXRX_NOTIFY there calls a NULL pointer in the RX worker:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n RIP: 0010:0x0\n Call Trace:\n mt7925_mac_tx_free+0x58/0x350 [mt7925_common]\n mt7925_rx_check+0xe2/0x130 [mt7925_common]\n mt76u_rx_worker+0x1b9/0x620 [mt76_usb]\n\nDrop the event on non-mmio buses via mt76_is_mmio(), as in\ncommit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for\nnon-mmio devices\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:00:36.015Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0c8c4cd0ca60b45c4b05a39e3769b8473d6836eb"
},
{
"url": "https://git.kernel.org/stable/c/9cb72f67e1502aabba51aab9ac04ae7c386ee194"
},
{
"url": "https://git.kernel.org/stable/c/9677e86a5f7d680fe280a5f8999bc57353e360d7"
},
{
"url": "https://git.kernel.org/stable/c/feeff151c83e7f0ffcdedcad5343852d23d1f6e1"
}
],
"title": "wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68193",
"datePublished": "2026-08-10T12:00:11.110Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-17T05:00:36.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72222 (GCVE-0-2026-72222)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-17 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
svc_tcp_handshake() stores the raw svc_xprt pointer in
tls_handshake_args.ta_data and submits the request through
tls_server_hello_x509(). The handshake core takes only
sock_hold(req->hr_sk); nothing references the embedding struct
svc_sock that svc_tcp_handshake_done() reaches via container_of().
Two close races leave the in-flight callback writing through a freed
svc_sock. svc_sock_free() calls tls_handshake_cancel() and discards
its return value: a false return means handshake_complete() has
already set HANDSHAKE_F_REQ_COMPLETED but hp_done() may not have
finished, yet svc_sock_free() proceeds to kfree(svsk). The
cancel-loser fall-through inside svc_tcp_handshake() itself produces
the same window: when wait_for_completion_interruptible_timeout()
returns <= 0 (timeout or signal) and tls_handshake_cancel() returns
false, the function does not drain, returns, and svc_handle_xprt()
calls svc_xprt_received(), which clears XPT_BUSY and can drop the
last reference. A concurrent close then runs svc_sock_free() while
svc_tcp_handshake_done() is still updating xpt_flags and walking
svsk->sk_handshake_done.
The corruption surfaces as set_bit/clear_bit RMW into the freed
xpt_flags slab slot and as complete_all() walking and writing the
freed wait_queue_head_t list embedded in sk_handshake_done -- a
slab-corruption primitive, not a benign read. The path is reachable
on any TLS-enabled NFS server whenever a connection close overlaps
the tlshd downcall delivery window; the interruptible wait means
signal delivery suffices, not just SVC_HANDSHAKE_TO expiry.
Take svc_xprt_get(xprt) immediately before tls_server_hello_x509()
so the in-flight callback owns its own reference. Release it on the
two edges where the callback is guaranteed not to fire -- submission
failure from tls_server_hello_x509() and a successful
tls_handshake_cancel() -- and at the tail of
svc_tcp_handshake_done() after complete_all().
[cel: rewrote commit message to describe the actual change]
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sunrpc/svcsock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f3b55945dd99f29d83e1965d0141040a35262346",
"status": "affected",
"version": "b3cbf98e2fdf3cb147a95161560cd25987284330",
"versionType": "git"
},
{
"lessThan": "2d4f97d13fff91e0bc539216be88b884b544d49f",
"status": "affected",
"version": "b3cbf98e2fdf3cb147a95161560cd25987284330",
"versionType": "git"
},
{
"lessThan": "3f9ee75a97a769be258784c22b89657acb5ed9bd",
"status": "affected",
"version": "b3cbf98e2fdf3cb147a95161560cd25987284330",
"versionType": "git"
},
{
"lessThan": "083e9c2ec7e8bb13b79c9fd7b337abdd758ecc5f",
"status": "affected",
"version": "b3cbf98e2fdf3cb147a95161560cd25987284330",
"versionType": "git"
},
{
"lessThan": "4f988f3a2808fb659f3880c282041ff067acad78",
"status": "affected",
"version": "b3cbf98e2fdf3cb147a95161560cd25987284330",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sunrpc/svcsock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: pin svc_xprt across the asynchronous TLS handshake callback\n\nsvc_tcp_handshake() stores the raw svc_xprt pointer in\ntls_handshake_args.ta_data and submits the request through\ntls_server_hello_x509(). The handshake core takes only\nsock_hold(req-\u003ehr_sk); nothing references the embedding struct\nsvc_sock that svc_tcp_handshake_done() reaches via container_of().\n\nTwo close races leave the in-flight callback writing through a freed\nsvc_sock. svc_sock_free() calls tls_handshake_cancel() and discards\nits return value: a false return means handshake_complete() has\nalready set HANDSHAKE_F_REQ_COMPLETED but hp_done() may not have\nfinished, yet svc_sock_free() proceeds to kfree(svsk). The\ncancel-loser fall-through inside svc_tcp_handshake() itself produces\nthe same window: when wait_for_completion_interruptible_timeout()\nreturns \u003c= 0 (timeout or signal) and tls_handshake_cancel() returns\nfalse, the function does not drain, returns, and svc_handle_xprt()\ncalls svc_xprt_received(), which clears XPT_BUSY and can drop the\nlast reference. A concurrent close then runs svc_sock_free() while\nsvc_tcp_handshake_done() is still updating xpt_flags and walking\nsvsk-\u003esk_handshake_done.\n\nThe corruption surfaces as set_bit/clear_bit RMW into the freed\nxpt_flags slab slot and as complete_all() walking and writing the\nfreed wait_queue_head_t list embedded in sk_handshake_done -- a\nslab-corruption primitive, not a benign read. The path is reachable\non any TLS-enabled NFS server whenever a connection close overlaps\nthe tlshd downcall delivery window; the interruptible wait means\nsignal delivery suffices, not just SVC_HANDSHAKE_TO expiry.\n\nTake svc_xprt_get(xprt) immediately before tls_server_hello_x509()\nso the in-flight callback owns its own reference. Release it on the\ntwo edges where the callback is guaranteed not to fire -- submission\nfailure from tls_server_hello_x509() and a successful\ntls_handshake_cancel() -- and at the tail of\nsvc_tcp_handshake_done() after complete_all().\n\n[cel: rewrote commit message to describe the actual change]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in nfsd\u0027s server-side SUNRPC/TCP TLS handshake (net/sunrpc/svcsock.c), reached when a remote peer connects to port 2049 and sends a pre-authentication AUTH_TLS NULL STARTTLS probe that triggers svc_tcp_handshake() via svcauth_tls_accept().\nAC:L - The attacker controls both sides of the race by initiating AUTH_TLS handshakes and concurrently resetting/closing TCP or waiting for SVC_HANDSHAKE_TO while tlshd delivers completion; repeated parallel connections make the overlap window reliably reachable.\nPR:N - AUTH_TLS is processed on RPC procedure 0 before credentials are verified, so an unauthenticated remote client can reach svc_tcp_handshake() and the asynchronous callback without any account, export access, or kernel capability.\nUI:N - nfsd worker threads automatically accept the TCP connection, process the STARTTLS probe, run the TLS handshake, and handle teardown/completion callbacks without any local user or administrator action.\nS:U - Exploitation corrupts kernel memory on the NFS server host itself and does not cross a VM-guest/host, sandbox, or IOMMU security boundary; impact stays within the kernel\u0027s security authority.\nC:H - svc_tcp_handshake_done() use-after-frees svc_sock and performs set_bit/clear_bit RMW on freed xpt_flags plus complete_all() on freed sk_handshake_done, a slab-corruption UAF that can disclose arbitrary kernel memory.\nI:H - The same UAF delivers attacker-timed writes into reclaimed slab slots through atomic bit operations and wait-queue list updates, enabling heap grooming and further kernel memory corruption for arbitrary modification or code execution.\nA:H - Slab corruption and UAF during handshake completion can cause kernel oops/panic, and unauthenticated remote peers can trigger the fault repeatedly by overlapping TLS handshake completion with connection close."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:41:44.196Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f3b55945dd99f29d83e1965d0141040a35262346"
},
{
"url": "https://git.kernel.org/stable/c/2d4f97d13fff91e0bc539216be88b884b544d49f"
},
{
"url": "https://git.kernel.org/stable/c/3f9ee75a97a769be258784c22b89657acb5ed9bd"
},
{
"url": "https://git.kernel.org/stable/c/083e9c2ec7e8bb13b79c9fd7b337abdd758ecc5f"
},
{
"url": "https://git.kernel.org/stable/c/4f988f3a2808fb659f3880c282041ff067acad78"
}
],
"title": "sunrpc: pin svc_xprt across the asynchronous TLS handshake callback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72222",
"datePublished": "2026-08-15T05:54:15.277Z",
"dateReserved": "2026-08-09T03:40:39.913Z",
"dateUpdated": "2026-08-17T05:41:44.196Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74550 (GCVE-0-2026-74550)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: do not send ICMP/NDISC Redirects when peer allocation fails
When inet_getpeer_v4() or inet_getpeer_v6() fails to allocate a peer entry
under memory pressure or tree size caps, redirect handlers previously fell
back to sending un-rate-limited ICMP/NDISC Redirect messages.
In IPv4, ip_rt_send_redirect() called icmp_send() directly when peer == NULL.
In IPv6, ip6_forward() and ndisc_send_redirect() passed a NULL peer into
inet_peer_xrlim_allow(), which returned true when peer == NULL.
Because ICMP/NDISC Redirects are not part of the default global rate limit
mask (sysctl_icmp_ratemask), sending redirects when peer == NULL creates
an un-rate-limited ICMP packet storm.
Fix this by failing closed in ip_rt_send_redirect(), ip6_forward(), and
ndisc_send_redirect() when peer is NULL.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/route.c",
"net/ipv6/ip6_output.c",
"net/ipv6/ndisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c0adf8b4247bcc5a145a25c1929006eb392580bb",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
},
{
"lessThan": "f5ecaa7ea7686fa7ecdb6affc9d3a9a42e4524b1",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
},
{
"lessThan": "21666f7af49a90ef44d474916b8ef4402dfd74f5",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
},
{
"lessThan": "5ec5f00fc606a6df8434948c4552b3cb1176595d",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
},
{
"lessThan": "828f6670d110ff2bf44c743037b38badc315704c",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
},
{
"lessThan": "dbc3791e3b2472e1ccc08947e0f83b443470ff4f",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/route.c",
"net/ipv6/ip6_output.c",
"net/ipv6/ndisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.39"
},
{
"lessThan": "2.6.39",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.39",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: do not send ICMP/NDISC Redirects when peer allocation fails\n\nWhen inet_getpeer_v4() or inet_getpeer_v6() fails to allocate a peer entry\nunder memory pressure or tree size caps, redirect handlers previously fell\nback to sending un-rate-limited ICMP/NDISC Redirect messages.\n\nIn IPv4, ip_rt_send_redirect() called icmp_send() directly when peer == NULL.\nIn IPv6, ip6_forward() and ndisc_send_redirect() passed a NULL peer into\ninet_peer_xrlim_allow(), which returned true when peer == NULL.\n\nBecause ICMP/NDISC Redirects are not part of the default global rate limit\nmask (sysctl_icmp_ratemask), sending redirects when peer == NULL creates\nan un-rate-limited ICMP packet storm.\n\nFix this by failing closed in ip_rt_send_redirect(), ip6_forward(), and\nndisc_send_redirect() when peer is NULL."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in IPv4/IPv6 packet forwarding paths (ip_forward/ip6_forward) reached when a remote host sends IP traffic processed by a forwarding router; this is standard net stack input handling, not a local-only API.\nAC:L - An attacker can reliably trigger redirect-eligible forwarded packets, flood unique source/destination addresses to stress inet_peer allocation, and induce memory pressure so peer allocation fails, controlling the conditions needed for the un-rate-limited redirect storm.\nPR:N - Exploitation requires only the ability to send IP packets to a forwarding host; no local account, capabilities, or authentication on the victim is needed.\nUI:N - No victim user action is required; the redirect storm is triggered entirely by attacker-sent network packets processed during kernel forwarding.\nS:U - Impact is confined to the kernel/network stack of the targeted forwarding system and its network availability; it does not cross VM, container, or IOMMU security boundaries.\nC:N - The bug bypasses redirect rate limiting to generate ICMP/NDISC storms; it does not involve memory corruption, out-of-bounds access, or unintended disclosure of sensitive kernel memory.\nI:N - The vulnerability causes excessive transmission of otherwise-valid redirect messages; it does not grant arbitrary data modification, code execution, or attacker-controlled corruption of kernel or application state.\nA:H - When peer allocation fails, ICMP/NDISC Redirects are sent without any rate limit (excluded from sysctl_icmp_ratemask), enabling a sustained packet storm that can exhaust CPU, memory, and bandwidth and deny service to the router and adjacent networks."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:44.870Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c0adf8b4247bcc5a145a25c1929006eb392580bb"
},
{
"url": "https://git.kernel.org/stable/c/f5ecaa7ea7686fa7ecdb6affc9d3a9a42e4524b1"
},
{
"url": "https://git.kernel.org/stable/c/21666f7af49a90ef44d474916b8ef4402dfd74f5"
},
{
"url": "https://git.kernel.org/stable/c/5ec5f00fc606a6df8434948c4552b3cb1176595d"
},
{
"url": "https://git.kernel.org/stable/c/828f6670d110ff2bf44c743037b38badc315704c"
},
{
"url": "https://git.kernel.org/stable/c/dbc3791e3b2472e1ccc08947e0f83b443470ff4f"
}
],
"title": "net: do not send ICMP/NDISC Redirects when peer allocation fails",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74550",
"datePublished": "2026-08-15T12:27:57.615Z",
"dateReserved": "2026-08-15T05:44:03.915Z",
"dateUpdated": "2026-08-19T16:38:44.870Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64344 (GCVE-0-2026-64344)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: idmouse: fix use-after-free on disconnect race
mutex_unlock() may access the mutex structure after releasing the lock
and therefore cannot be used to manage lifetime of objects directly
(unlike spinlocks and refcounts). [1][2]
Use a kref to release the driver data to avoid use-after-free in
mutex_unlock() when release() races with disconnect().
[1] a51749ab34d9 ("locking/mutex: Document that mutex_unlock() is
non-atomic")
[2] 2b9d9e0a9ba0 ("locking/mutex: Clarify that mutex_unlock(), and most
other sleeping locks, can still use the lock object
after it's unlocked")
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 54d2bc068fd21bcb096660938bce7c7265613a24 Version: 54d2bc068fd21bcb096660938bce7c7265613a24 Version: 54d2bc068fd21bcb096660938bce7c7265613a24 Version: 54d2bc068fd21bcb096660938bce7c7265613a24 Version: 54d2bc068fd21bcb096660938bce7c7265613a24 Version: 54d2bc068fd21bcb096660938bce7c7265613a24 Version: 54d2bc068fd21bcb096660938bce7c7265613a24 Version: 54d2bc068fd21bcb096660938bce7c7265613a24 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/idmouse.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "31e75fed8f90cfea9f8285e7ed135b0e452bf872",
"status": "affected",
"version": "54d2bc068fd21bcb096660938bce7c7265613a24",
"versionType": "git"
},
{
"lessThan": "8d53b14ad4ccbff6d306b3a39c812303f4a87d41",
"status": "affected",
"version": "54d2bc068fd21bcb096660938bce7c7265613a24",
"versionType": "git"
},
{
"lessThan": "f62622e947f82a3854a8502d09492ffbdeb252b4",
"status": "affected",
"version": "54d2bc068fd21bcb096660938bce7c7265613a24",
"versionType": "git"
},
{
"lessThan": "60fc5ef4ecea3e3d1fe556cecf53ddd13096ef09",
"status": "affected",
"version": "54d2bc068fd21bcb096660938bce7c7265613a24",
"versionType": "git"
},
{
"lessThan": "d0f61acb51a8c8f3fd41c303ddb7770cd83e7ed4",
"status": "affected",
"version": "54d2bc068fd21bcb096660938bce7c7265613a24",
"versionType": "git"
},
{
"lessThan": "54c2b7356b4aeea467f9fb13b85e9e036bc428cb",
"status": "affected",
"version": "54d2bc068fd21bcb096660938bce7c7265613a24",
"versionType": "git"
},
{
"lessThan": "e88cff5fbaa629f3cab45c8b46f395d62c2eb515",
"status": "affected",
"version": "54d2bc068fd21bcb096660938bce7c7265613a24",
"versionType": "git"
},
{
"lessThan": "ff002c153f9722caece3983cc23dc4d9d4652cb4",
"status": "affected",
"version": "54d2bc068fd21bcb096660938bce7c7265613a24",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/idmouse.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: idmouse: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is\n non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n other sleeping locks, can still use the lock object\n after it\u0027s unlocked\")"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:48.283Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/31e75fed8f90cfea9f8285e7ed135b0e452bf872"
},
{
"url": "https://git.kernel.org/stable/c/8d53b14ad4ccbff6d306b3a39c812303f4a87d41"
},
{
"url": "https://git.kernel.org/stable/c/f62622e947f82a3854a8502d09492ffbdeb252b4"
},
{
"url": "https://git.kernel.org/stable/c/60fc5ef4ecea3e3d1fe556cecf53ddd13096ef09"
},
{
"url": "https://git.kernel.org/stable/c/d0f61acb51a8c8f3fd41c303ddb7770cd83e7ed4"
},
{
"url": "https://git.kernel.org/stable/c/54c2b7356b4aeea467f9fb13b85e9e036bc428cb"
},
{
"url": "https://git.kernel.org/stable/c/e88cff5fbaa629f3cab45c8b46f395d62c2eb515"
},
{
"url": "https://git.kernel.org/stable/c/ff002c153f9722caece3983cc23dc4d9d4652cb4"
}
],
"title": "USB: idmouse: fix use-after-free on disconnect race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64344",
"datePublished": "2026-07-25T08:50:06.461Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:48.283Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53142 (GCVE-0-2026-53142)
Vulnerability from cvelistv5
Published
2026-06-25 08:38
Modified
2026-07-04 11:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/display: fix oops in suspend/shutdown without display
The xe driver keeps track of whether to probe display, and whether
display hardware is there, using xe->info.probe_display. It gets set to
false if there's no display after intel_display_device_probe(). However,
the display may also be disabled via fuses, detected at a later time in
intel_display_device_info_runtime_init().
In this case, the xe driver does for_each_intel_crtc() on uninitialized
mode config in xe_display_flush_cleanup_work(), leading to a NULL
pointer dereference, and generally calls display code with display info
cleared.
Check for intel_display_device_present() after
intel_display_device_info_runtime_init(), and reset
xe->info.probe_display as necessary. Also do unset_display_features()
for completeness, although display runtime init has already done
that. This will need to be unified across all cases later.
Move intel_display_device_info_runtime_init() call slightly earlier,
similar to i915, to avoid a bunch of unnecessary setup for no display
cases.
Note #1: The xe driver has no business doing low level display plumbing
like for_each_intel_crtc() to begin with. It all needs to happen in
display code.
Note #2: The actual bug is present already in commit 44e694958b95
("drm/xe/display: Implement display support"), but the oops was likely
introduced later at commit ddf6492e0e50 ("drm/xe/display: Make display
suspend/resume work on discrete").
(cherry picked from commit 7c3eb9f47533220888a67266448185fd0775d4da)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/xe/display/xe_display.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ddf1fe4c043aa42e46aef87b815d5deeed2fcd7b",
"status": "affected",
"version": "44e694958b95395bd1c41508c88c8ca141bf9bd7",
"versionType": "git"
},
{
"lessThan": "0f68ddfaaebfbb5581ee931779757d31f4dc9e24",
"status": "affected",
"version": "44e694958b95395bd1c41508c88c8ca141bf9bd7",
"versionType": "git"
},
{
"lessThan": "238bcdaae8f2abc65e182de7d1f69cf8f611a610",
"status": "affected",
"version": "44e694958b95395bd1c41508c88c8ca141bf9bd7",
"versionType": "git"
},
{
"lessThan": "68938cc08e23a94fd881e845837ff918de005ce7",
"status": "affected",
"version": "44e694958b95395bd1c41508c88c8ca141bf9bd7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/xe/display/xe_display.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/display: fix oops in suspend/shutdown without display\n\nThe xe driver keeps track of whether to probe display, and whether\ndisplay hardware is there, using xe-\u003einfo.probe_display. It gets set to\nfalse if there\u0027s no display after intel_display_device_probe(). However,\nthe display may also be disabled via fuses, detected at a later time in\nintel_display_device_info_runtime_init().\n\nIn this case, the xe driver does for_each_intel_crtc() on uninitialized\nmode config in xe_display_flush_cleanup_work(), leading to a NULL\npointer dereference, and generally calls display code with display info\ncleared.\n\nCheck for intel_display_device_present() after\nintel_display_device_info_runtime_init(), and reset\nxe-\u003einfo.probe_display as necessary. Also do unset_display_features()\nfor completeness, although display runtime init has already done\nthat. This will need to be unified across all cases later.\n\nMove intel_display_device_info_runtime_init() call slightly earlier,\nsimilar to i915, to avoid a bunch of unnecessary setup for no display\ncases.\n\nNote #1: The xe driver has no business doing low level display plumbing\nlike for_each_intel_crtc() to begin with. It all needs to happen in\ndisplay code.\n\nNote #2: The actual bug is present already in commit 44e694958b95\n(\"drm/xe/display: Implement display support\"), but the oops was likely\nintroduced later at commit ddf6492e0e50 (\"drm/xe/display: Make display\nsuspend/resume work on discrete\").\n\n(cherry picked from commit 7c3eb9f47533220888a67266448185fd0775d4da)"
}
],
"providerMetadata": {
"dateUpdated": "2026-07-04T11:50:53.138Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ddf1fe4c043aa42e46aef87b815d5deeed2fcd7b"
},
{
"url": "https://git.kernel.org/stable/c/0f68ddfaaebfbb5581ee931779757d31f4dc9e24"
},
{
"url": "https://git.kernel.org/stable/c/238bcdaae8f2abc65e182de7d1f69cf8f611a610"
},
{
"url": "https://git.kernel.org/stable/c/68938cc08e23a94fd881e845837ff918de005ce7"
}
],
"title": "drm/xe/display: fix oops in suspend/shutdown without display",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53142",
"datePublished": "2026-06-25T08:38:30.158Z",
"dateReserved": "2026-06-09T07:44:35.387Z",
"dateUpdated": "2026-07-04T11:50:53.138Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68125 (GCVE-0-2026-68125)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mac802154: llsec: reject frames shorter than the authentication tag
llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as
assoclen += datalen - authlen;
where datalen is the number of bytes after the MAC header and authlen
(4, 8 or 16) is the length of the authentication tag. Nothing verifies
that the frame actually carries at least authlen payload bytes. A
secured frame whose payload is shorter than the tag makes
datalen - authlen negative; assoclen is then passed to
aead_request_set_ad() as an unsigned value close to 4 GiB, so
crypto_aead_decrypt() walks far off the end of the scatterlist that
only spans the real frame.
The frame is fully attacker-controlled and reaches this path from any
IEEE 802.15.4 peer in radio range. Reject frames whose payload is
shorter than the authentication tag before the subtraction.
Dynamically reproduced on a KASAN kernel as a general-protection-fault
in the AEAD scatterwalk, and the fix confirmed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac802154/llsec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f27ce82eb04960465df71634b196a48a4ecafd50",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "2d6b42a61373144298070668fddf06efe79cf2ff",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "ec7e62d77193131227df49d654d118fdf5a59892",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "5bbf0cd9b6a7076af86c75e87e180099be2e11ae",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "de80808f37d99c6dc67bb6f97eea00c8f57a8821",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "f20dedce0429b293d4bad604e0d3f65d8ac96c83",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "e09e0301d616c1ef38a5e64e8e4326fd39df13cc",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "fd3a3f28ed60c6af4b2a39933b151d6b27842c3b",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac802154/llsec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: llsec: reject frames shorter than the authentication tag\n\nllsec_do_decrypt_auth() computes the associated-data length for the\nAEAD request as\n\n\tassoclen += datalen - authlen;\n\nwhere datalen is the number of bytes after the MAC header and authlen\n(4, 8 or 16) is the length of the authentication tag. Nothing verifies\nthat the frame actually carries at least authlen payload bytes. A\nsecured frame whose payload is shorter than the tag makes\ndatalen - authlen negative; assoclen is then passed to\naead_request_set_ad() as an unsigned value close to 4 GiB, so\ncrypto_aead_decrypt() walks far off the end of the scatterlist that\nonly spans the real frame.\n\nThe frame is fully attacker-controlled and reaches this path from any\nIEEE 802.15.4 peer in radio range. Reject frames whose payload is\nshorter than the authentication tag before the subtraction.\n\nDynamically reproduced on a KASAN kernel as a general-protection-fault\nin the AEAD scatterwalk, and the fix confirmed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Exploitation requires sending crafted IEEE 802.15.4 frames over the WPAN radio interface; any peer within RF range can reach mac802154 receive/decrypt without IP routing or local shell access, matching Adjacent wireless attack guidance like Bluetooth.\nAC:L - The attacker fully controls frame length and security header fields; once LLSEC is enabled on the victim, a single undersized MIC-only secured frame reliably triggers the assoclen underflow and was dynamically reproduced as a KASAN GPF.\nPR:N - No Linux credentials or capabilities are required on the target; exploitation is performed by an over-the-air 802.15.4 peer spoofing a known PAN device/key/frame counter, not via local syscalls, ioctl, or netlink.\nUI:N - No victim user action is needed beyond normal operation of an LLSEC-enabled 802.15.4 interface; the malicious frame is processed automatically in the softirq receive path before delivery to userspace.\nS:U - Impact is confined to kernel memory and availability on the attacked host\u0027s WPAN stack; it does not cross a VM, container, or IOMMU security boundary into a separate authority.\nC:H - The wrapped assoclen makes crypto_aead_decrypt() scatterwalk read gigabytes beyond the skb-backed scatterlist, causing out-of-bounds kernel memory reads that can disclose adjacent heap or slab data and enable further exploitation primitives.\nI:H - Kernel memory corruption in the AEAD decrypt scatterwalk path can be leveraged for control-flow hijack or arbitrary write primitives beyond the demonstrated crash, consistent with high integrity impact for exploitable OOB access in crypto handlers.\nA:H - The bug was reproduced on a KASAN kernel as a general-protection fault in the AEAD scatterwalk, and repeated malicious frames can panic or hang the kernel on LLSEC-enabled coordinators, gateways, and IoT border routers."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:39.507Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f27ce82eb04960465df71634b196a48a4ecafd50"
},
{
"url": "https://git.kernel.org/stable/c/2d6b42a61373144298070668fddf06efe79cf2ff"
},
{
"url": "https://git.kernel.org/stable/c/ec7e62d77193131227df49d654d118fdf5a59892"
},
{
"url": "https://git.kernel.org/stable/c/5bbf0cd9b6a7076af86c75e87e180099be2e11ae"
},
{
"url": "https://git.kernel.org/stable/c/de80808f37d99c6dc67bb6f97eea00c8f57a8821"
},
{
"url": "https://git.kernel.org/stable/c/f20dedce0429b293d4bad604e0d3f65d8ac96c83"
},
{
"url": "https://git.kernel.org/stable/c/e09e0301d616c1ef38a5e64e8e4326fd39df13cc"
},
{
"url": "https://git.kernel.org/stable/c/fd3a3f28ed60c6af4b2a39933b151d6b27842c3b"
}
],
"title": "mac802154: llsec: reject frames shorter than the authentication tag",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68125",
"datePublished": "2026-08-10T11:58:46.198Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:39.507Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68346 (GCVE-0-2026-68346)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: hda: cs35l41: validate and free ACPI mute object
cs35l41_get_acpi_mute_state() evaluates a _DSM method to get the ACPI
mute state and reads the first byte from the returned object.
However, the returned ACPI object is owned by the caller and is never
freed after use, so each successful query leaks the _DSM result object.
The code also assumes that the returned object is a buffer with at least
one byte. A malformed firmware response can return a different object
type or an empty buffer, and the direct ret->buffer.pointer dereference
can then access an invalid pointer.
Use the typed _DSM helper, validate that the returned buffer contains at
least one byte, and free the ACPI object after reading it.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/hda/codecs/side-codecs/cs35l41_hda.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7fea0c89ed39a13d9a31163a74f8c62de30a4ffc",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
},
{
"lessThan": "08433c71f15984ddd5f5a307cf3f0aa9b84583aa",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
},
{
"lessThan": "d5dfdf43259ad9d054052012095b1630e7366dcf",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
},
{
"lessThan": "3b597d24dc0455ae926f1053f97c2725038fc3cd",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/hda/codecs/side-codecs/cs35l41_hda.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: cs35l41: validate and free ACPI mute object\n\ncs35l41_get_acpi_mute_state() evaluates a _DSM method to get the ACPI\nmute state and reads the first byte from the returned object.\n\nHowever, the returned ACPI object is owned by the caller and is never\nfreed after use, so each successful query leaks the _DSM result object.\n\nThe code also assumes that the returned object is a buffer with at least\none byte. A malformed firmware response can return a different object\ntype or an empty buffer, and the direct ret-\u003ebuffer.pointer dereference\ncan then access an invalid pointer.\n\nUse the typed _DSM helper, validate that the returned buffer contains at\nleast one byte, and free the ACPI object after reading it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:46.731Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7fea0c89ed39a13d9a31163a74f8c62de30a4ffc"
},
{
"url": "https://git.kernel.org/stable/c/08433c71f15984ddd5f5a307cf3f0aa9b84583aa"
},
{
"url": "https://git.kernel.org/stable/c/d5dfdf43259ad9d054052012095b1630e7366dcf"
},
{
"url": "https://git.kernel.org/stable/c/3b597d24dc0455ae926f1053f97c2725038fc3cd"
}
],
"title": "ALSA: hda: cs35l41: validate and free ACPI mute object",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68346",
"datePublished": "2026-08-10T12:03:23.079Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-17T05:03:46.731Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68284 (GCVE-0-2026-68284)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which
drops and reacquires the socket lock. Its error path tries to decide
whether msg_tx names the local temporary message by comparing it with
the current value of psock->cork.
This comparison is unsafe when two threads send on the same socket:
Thread A Thread B
msg_tx = psock->cork
sk_msg_alloc() fails
sk_stream_wait_memory()
releases the socket lock acquires the socket lock
completes the cork
psock->cork = NULL
frees the cork
reacquires the socket lock
msg_tx != psock->cork
sk_msg_free(msg_tx)
The stale cork is therefore mistaken for the local temporary message
and freed again. KASAN reported:
BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50
Read of size 4 at addr ffff88810c908800 by task poc/90
Call Trace:
sk_msg_free+0x49/0x50
tcp_bpf_sendmsg+0x14f5/0x1cc0
__sys_sendto+0x32c/0x3a0
__x64_sys_sendto+0xdb/0x1b0
Allocated by task 89:
__kasan_kmalloc+0x8f/0xa0
tcp_bpf_sendmsg+0x16b3/0x1cc0
Freed by task 91:
__kasan_slab_free+0x43/0x70
kfree+0x131/0x3c0
tcp_bpf_sendmsg+0xec3/0x1cc0
msg_tx can only name the stack-local tmp or the shared cork. Check for
tmp directly so a changed psock->cork cannot turn a shared message into
an apparent local one.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_bpf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0688e6fe599d2d39147ae9ece97944c6e1815ebf",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "b2bcbeabfd843d47468fa095b1bd08ddb90cf616",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "54be47e7cbb936429c3bbdfc526ea943954aaf80",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "ee762f684eefa59de34d9ed93cab08336e834f47",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "cde4d6bcd9b73073c66498f6723c7b364c4dbc18",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "786d690257ec7a0c839f8710456e444ce3f1348b",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "752b1159ed5d0c48fe169a3721b96660a9822aa1",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "2d66a033864e27ab8d5e44cb36f31d9d2413bee4",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_bpf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()\n\ntcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which\ndrops and reacquires the socket lock. Its error path tries to decide\nwhether msg_tx names the local temporary message by comparing it with\nthe current value of psock-\u003ecork.\n\nThis comparison is unsafe when two threads send on the same socket:\n\n Thread A Thread B\n msg_tx = psock-\u003ecork\n sk_msg_alloc() fails\n sk_stream_wait_memory()\n releases the socket lock acquires the socket lock\n completes the cork\n psock-\u003ecork = NULL\n frees the cork\n reacquires the socket lock\n msg_tx != psock-\u003ecork\n sk_msg_free(msg_tx)\n\nThe stale cork is therefore mistaken for the local temporary message\nand freed again. KASAN reported:\n\n BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50\n Read of size 4 at addr ffff88810c908800 by task poc/90\n Call Trace:\n sk_msg_free+0x49/0x50\n tcp_bpf_sendmsg+0x14f5/0x1cc0\n __sys_sendto+0x32c/0x3a0\n __x64_sys_sendto+0xdb/0x1b0\n Allocated by task 89:\n __kasan_kmalloc+0x8f/0xa0\n tcp_bpf_sendmsg+0x16b3/0x1cc0\n Freed by task 91:\n __kasan_slab_free+0x43/0x70\n kfree+0x131/0x3c0\n tcp_bpf_sendmsg+0xec3/0x1cc0\n\nmsg_tx can only name the stack-local tmp or the shared cork. Check for\ntmp directly so a changed psock-\u003ecork cannot turn a shared message into\nan apparent local one."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is triggered by local `sendmsg()`/`sendto()` syscalls issued concurrently by two threads on the same TCP socket attached to a BPF sockmap; the remote peer cannot drive the race, so this is a local attack surface.\nAC:L - The attacker controls both sides of the race: it owns both sending threads, can force the `wait_for_memory` path deterministically with a small SO_SNDBUF plus a large blocking send, and can force `sk_stream_wait_memory()` to fail via SO_SNDTIMEO or a socket error, making the stale-cork free reliably reachable.\nPR:L - Once the sockmap and sk_msg verdict/cork program are installed by the platform (a standard deployment such as Cilium/Istio sockops acceleration), an ordinary unprivileged local process owning a socket in the map triggers the bug with plain send syscalls; no capability check guards `tcp_bpf_sendmsg()` itself.\nUI:N - The attacker\u0027s own two threads perform all the required sends; no action by any other user or victim process is needed.\nS:U - The use-after-free corrupts kernel slab and page state within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - `sk_msg_free()` reads the freed `sk_msg` cork object (KASAN slab-use-after-free read), and by reclaiming that slab object with attacker-groomed data the freed scatterlist can be steered to leak or expose arbitrary kernel memory contents.\nI:H - Beyond the stale read, the path re-frees the cork\u0027s scatterlist pages and uncharges socket memory, giving a double-free/page-refcount-underflow primitive on an attacker-groomable slab object, which is classically leveraged into arbitrary kernel write and control-flow hijack.\nA:H - The use-after-free and duplicate page release corrupt slab and page allocator state, reliably producing a kernel oops or panic and taking the whole system down."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:41.174Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0688e6fe599d2d39147ae9ece97944c6e1815ebf"
},
{
"url": "https://git.kernel.org/stable/c/b2bcbeabfd843d47468fa095b1bd08ddb90cf616"
},
{
"url": "https://git.kernel.org/stable/c/54be47e7cbb936429c3bbdfc526ea943954aaf80"
},
{
"url": "https://git.kernel.org/stable/c/ee762f684eefa59de34d9ed93cab08336e834f47"
},
{
"url": "https://git.kernel.org/stable/c/cde4d6bcd9b73073c66498f6723c7b364c4dbc18"
},
{
"url": "https://git.kernel.org/stable/c/786d690257ec7a0c839f8710456e444ce3f1348b"
},
{
"url": "https://git.kernel.org/stable/c/752b1159ed5d0c48fe169a3721b96660a9822aa1"
},
{
"url": "https://git.kernel.org/stable/c/2d66a033864e27ab8d5e44cb36f31d9d2413bee4"
}
],
"title": "bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68284",
"datePublished": "2026-08-10T12:02:16.572Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-19T16:32:41.174Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64440 (GCVE-0-2026-64440)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB write in HT_caps_handler()
HT_caps_handler() iterates pIE->length bytes and writes into
HT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struct
HT_caps_element). Because pIE->length is a raw u8 from an over-the-air
802.11 AssocResponse frame and is never validated, a malicious AP can
set it up to 255, causing up to 229 bytes of out-of-bounds writes into
adjacent fields of struct mlme_ext_info.
Truncate the iteration count to the size of HT_caps.u.HT_cap using
umin() so that data from a longer-than-expected IE is silently ignored
rather than written out of bounds, preserving interoperability with APs
that pad the element. An early return on oversized IEs was considered
but rejected: it would bypass the pmlmeinfo->HT_caps_enable = 1
assignment that precedes the loop, silently disabling HT mode for APs
that append extra bytes to the HT Capabilities IE.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_wlan_util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "37f642d47c3648a707df3ceb092eee1adffbfd28",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "8c872b47c7fc32e95e0da1db7512388794adcd69",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "918537a0fbed85aab61fa28ad75e6279070610c9",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "6f91621fc45025ad3c0be796b70e6e4cee22fc69",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "f8001e1a516ba3b495728c65b61f799cbfad6bd0",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_wlan_util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB write in HT_caps_handler()\n\nHT_caps_handler() iterates pIE-\u003elength bytes and writes into\nHT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struct\nHT_caps_element). Because pIE-\u003elength is a raw u8 from an over-the-air\n802.11 AssocResponse frame and is never validated, a malicious AP can\nset it up to 255, causing up to 229 bytes of out-of-bounds writes into\nadjacent fields of struct mlme_ext_info.\n\nTruncate the iteration count to the size of HT_caps.u.HT_cap using\numin() so that data from a longer-than-expected IE is silently ignored\nrather than written out of bounds, preserving interoperability with APs\nthat pad the element. An early return on oversized IEs was considered\nbut rejected: it would bypass the pmlmeinfo-\u003eHT_caps_enable = 1\nassignment that precedes the loop, silently disabling HT mode for APs\nthat append extra bytes to the HT Capabilities IE."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - A nearby attacker can transmit a crafted 802.11 association response over the air; WiFi management-frame injection requires radio proximity and is not routable.\nAC:L - A malicious AP controls the IE length, contents, and handshake timing, making the bit-clearing overwrite deterministic without a race or uncontrollable condition.\nPR:N - The frame is processed before WPA or 802.1X credential verification, and OnAssocRsp does not authenticate its source BSSID; no target privilege or network credential is required.\nUI:N - Mobile, embedded, and headless systems commonly associate or roam automatically, allowing an evil-twin AP to reach the handler without human action.\nS:U - The corruption affects host-kernel driver state without crossing a VM, IOMMU, sandbox, or other security-authority boundary.\nC:N - The primitive only AND-clears following HT and network metadata and cannot reach pointer-bearing fields; no secret-bearing read or attacker-visible disclosure path was found.\nI:H - The oversized IE causes up to 229 attacker-controlled bit-mask writes beyond the 26-byte array, corrupting live kernel HT information and saved network metadata.\nA:H - The attacker can repeatedly corrupt BSSID, SSID, rate, IE-length, and HT state to prevent association; on a WiFi-dependent controller or IoT device this can sustain total loss of connectivity."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:42.056Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/37f642d47c3648a707df3ceb092eee1adffbfd28"
},
{
"url": "https://git.kernel.org/stable/c/8c872b47c7fc32e95e0da1db7512388794adcd69"
},
{
"url": "https://git.kernel.org/stable/c/bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a"
},
{
"url": "https://git.kernel.org/stable/c/918537a0fbed85aab61fa28ad75e6279070610c9"
},
{
"url": "https://git.kernel.org/stable/c/6f91621fc45025ad3c0be796b70e6e4cee22fc69"
},
{
"url": "https://git.kernel.org/stable/c/225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d"
},
{
"url": "https://git.kernel.org/stable/c/f8001e1a516ba3b495728c65b61f799cbfad6bd0"
}
],
"title": "staging: rtl8723bs: fix OOB write in HT_caps_handler()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64440",
"datePublished": "2026-07-25T08:51:13.138Z",
"dateReserved": "2026-07-19T15:36:31.788Z",
"dateUpdated": "2026-08-17T04:55:42.056Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64487 (GCVE-0-2026-64487)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
snd_usb_caiaq_tks4_dispatch() decodes the Traktor Kontrol S4 input
stream in fixed 16-byte (TKS4_MSGBLOCK_SIZE) message blocks. On every
iteration it advances buf and subtracts the block size while looping on
"while (len)".
len is urb->actual_length. That value is supplied by the device and is
not guaranteed to be a multiple of 16. When a final short block leaves
len between 1 and 15, the loop runs once more, reads up to buf[15], and
then does "len -= TKS4_MSGBLOCK_SIZE". As len is unsigned this underflows
to a huge value. The loop then keeps iterating and walking buf far past
the end of the 512-byte ep4_in_buf, reading out of bounds until a bogus
block id happens to be hit.
Iterate only while a full message block is available. This stops the
unsigned underflow and silently drops any trailing partial block, which
carries no complete control value anyway.
The sibling endpoint-4 parsers are not affected. The Traktor Kontrol X1
and Maschine arms in snd_usb_caiaq_ep4_reply_dispatch() floor
urb->actual_length before dispatching.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 15c5ab607045e278ebf4d2ca4aea2250617d50ca Version: 15c5ab607045e278ebf4d2ca4aea2250617d50ca Version: 15c5ab607045e278ebf4d2ca4aea2250617d50ca Version: 15c5ab607045e278ebf4d2ca4aea2250617d50ca Version: 15c5ab607045e278ebf4d2ca4aea2250617d50ca Version: 15c5ab607045e278ebf4d2ca4aea2250617d50ca Version: 15c5ab607045e278ebf4d2ca4aea2250617d50ca Version: 15c5ab607045e278ebf4d2ca4aea2250617d50ca |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/usb/caiaq/input.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "de5f9edc705497b1b2c6b173b22f283486d2fd91",
"status": "affected",
"version": "15c5ab607045e278ebf4d2ca4aea2250617d50ca",
"versionType": "git"
},
{
"lessThan": "70d6d4cfa4ad09688aed2ec8a0cfa72c31f60334",
"status": "affected",
"version": "15c5ab607045e278ebf4d2ca4aea2250617d50ca",
"versionType": "git"
},
{
"lessThan": "884f575cc6acb136eb4a161d925147f85b59c27e",
"status": "affected",
"version": "15c5ab607045e278ebf4d2ca4aea2250617d50ca",
"versionType": "git"
},
{
"lessThan": "05df59b9a61f7ca66548df079d306c41da23845d",
"status": "affected",
"version": "15c5ab607045e278ebf4d2ca4aea2250617d50ca",
"versionType": "git"
},
{
"lessThan": "3cad86197c7bf8b45bb1d8adc1099d0913e80469",
"status": "affected",
"version": "15c5ab607045e278ebf4d2ca4aea2250617d50ca",
"versionType": "git"
},
{
"lessThan": "a5fd3122283bf75c04f6414bf610100beb0565b0",
"status": "affected",
"version": "15c5ab607045e278ebf4d2ca4aea2250617d50ca",
"versionType": "git"
},
{
"lessThan": "0680413f2f10aab43878dd3db711a6a9e45bab7c",
"status": "affected",
"version": "15c5ab607045e278ebf4d2ca4aea2250617d50ca",
"versionType": "git"
},
{
"lessThan": "f7f3f9fd81e7adbaa12c2e62ee07f0e094a543fd",
"status": "affected",
"version": "15c5ab607045e278ebf4d2ca4aea2250617d50ca",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/usb/caiaq/input.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser\n\nsnd_usb_caiaq_tks4_dispatch() decodes the Traktor Kontrol S4 input\nstream in fixed 16-byte (TKS4_MSGBLOCK_SIZE) message blocks. On every\niteration it advances buf and subtracts the block size while looping on\n\"while (len)\".\n\nlen is urb-\u003eactual_length. That value is supplied by the device and is\nnot guaranteed to be a multiple of 16. When a final short block leaves\nlen between 1 and 15, the loop runs once more, reads up to buf[15], and\nthen does \"len -= TKS4_MSGBLOCK_SIZE\". As len is unsigned this underflows\nto a huge value. The loop then keeps iterating and walking buf far past\nthe end of the 512-byte ep4_in_buf, reading out of bounds until a bogus\nblock id happens to be hit.\n\nIterate only while a full message block is available. This stops the\nunsigned underflow and silently drops any trailing partial block, which\ncarries no complete control value anyway.\n\nThe sibling endpoint-4 parsers are not affected. The Traktor Kontrol X1\nand Maschine arms in snd_usb_caiaq_ep4_reply_dispatch() floor\nurb-\u003eactual_length before dispatching."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:34.866Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/de5f9edc705497b1b2c6b173b22f283486d2fd91"
},
{
"url": "https://git.kernel.org/stable/c/70d6d4cfa4ad09688aed2ec8a0cfa72c31f60334"
},
{
"url": "https://git.kernel.org/stable/c/884f575cc6acb136eb4a161d925147f85b59c27e"
},
{
"url": "https://git.kernel.org/stable/c/05df59b9a61f7ca66548df079d306c41da23845d"
},
{
"url": "https://git.kernel.org/stable/c/3cad86197c7bf8b45bb1d8adc1099d0913e80469"
},
{
"url": "https://git.kernel.org/stable/c/a5fd3122283bf75c04f6414bf610100beb0565b0"
},
{
"url": "https://git.kernel.org/stable/c/0680413f2f10aab43878dd3db711a6a9e45bab7c"
},
{
"url": "https://git.kernel.org/stable/c/f7f3f9fd81e7adbaa12c2e62ee07f0e094a543fd"
}
],
"title": "ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64487",
"datePublished": "2026-07-25T08:51:46.711Z",
"dateReserved": "2026-07-19T15:36:31.792Z",
"dateUpdated": "2026-08-17T04:56:34.866Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68231 (GCVE-0-2026-68231)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: airspy: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
airspy_start_streaming() returned -ENODEV early when the USB device had
been disconnected (s->udev == NULL) without returning any buffers that
buf_queue() had already accepted. Take v4l2_lock first and jump to the
existing err_clear_bit label, which already drains s->queued_bufs via
vb2_buffer_done(..., VB2_BUF_STATE_QUEUED) before unlocking.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/airspy/airspy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "badceeb82a9d8d8e98d07859f3c89130ae1998b9",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "122ce0c0af629a8765ddf1adf6fb85c6db3d47cb",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "bcdf261c4c29077fc3da6449f7eda77357046205",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "877686a74ecdc93dcaee09dbac566e819059c9e7",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "cd42623d698b59f1fe5768f78a4101c28d5feb2e",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "73bd2779865372b1017d4f555b45270aa2d0d710",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "170fcc945bc094b1c956bf555c070692826a3eff",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "04344d0b4929caa94c0df72f767752aa0935ef5d",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/airspy/airspy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: airspy: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nairspy_start_streaming() returned -ENODEV early when the USB device had\nbeen disconnected (s-\u003eudev == NULL) without returning any buffers that\nbuf_queue() had already accepted. Take v4l2_lock first and jump to the\nexisting err_clear_bit label, which already drains s-\u003equeued_bufs via\nvb2_buffer_done(..., VB2_BUF_STATE_QUEUED) before unlocking.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:04.017Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/badceeb82a9d8d8e98d07859f3c89130ae1998b9"
},
{
"url": "https://git.kernel.org/stable/c/122ce0c0af629a8765ddf1adf6fb85c6db3d47cb"
},
{
"url": "https://git.kernel.org/stable/c/bcdf261c4c29077fc3da6449f7eda77357046205"
},
{
"url": "https://git.kernel.org/stable/c/877686a74ecdc93dcaee09dbac566e819059c9e7"
},
{
"url": "https://git.kernel.org/stable/c/cd42623d698b59f1fe5768f78a4101c28d5feb2e"
},
{
"url": "https://git.kernel.org/stable/c/73bd2779865372b1017d4f555b45270aa2d0d710"
},
{
"url": "https://git.kernel.org/stable/c/170fcc945bc094b1c956bf555c070692826a3eff"
},
{
"url": "https://git.kernel.org/stable/c/04344d0b4929caa94c0df72f767752aa0935ef5d"
}
],
"title": "media: airspy: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68231",
"datePublished": "2026-08-10T12:00:54.801Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:32:04.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68355 (GCVE-0-2026-68355)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
When the first entry in msdu_details has a zero buffer address,
the code accesses msdu_details[i - 1] with i == 0, causing a
buffer underflow.
Fix similarly to ath12k_wifi7_hal_rx_msdu_list_get() by adding
a separate check for i == 0 before the main condition to prevent
the out-of-bounds access.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/dp_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "085a5fde5bac29c01059e69399b417e91c0a6c18",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "31ea4b175bc3ab430be15834d9ee8a1ce65bee15",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "20d18a5ec6ec364fcaf0d03af6fc43dcc42c6591",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "69a6a4f60b2da92c0bdfd9264b8ffe053f51f52a",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "904367381a922aa2dc3e8bd2488e6c9180516c7a",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "a154ca3c441a67d36b3a9ea63a4f11b06abe6223",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "725c1c3a8c5d920a7d3f5887412f2ad8e95a74f5",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "7f11e70629650ff6ea140984e5ce188b775b2683",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/dp_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()\n\nWhen the first entry in msdu_details has a zero buffer address,\nthe code accesses msdu_details[i - 1] with i == 0, causing a\nbuffer underflow.\n\nFix similarly to ath12k_wifi7_hal_rx_msdu_list_get() by adding\na separate check for i == 0 before the main condition to prevent\nthe out-of-bounds access.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:03.197Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/085a5fde5bac29c01059e69399b417e91c0a6c18"
},
{
"url": "https://git.kernel.org/stable/c/31ea4b175bc3ab430be15834d9ee8a1ce65bee15"
},
{
"url": "https://git.kernel.org/stable/c/20d18a5ec6ec364fcaf0d03af6fc43dcc42c6591"
},
{
"url": "https://git.kernel.org/stable/c/69a6a4f60b2da92c0bdfd9264b8ffe053f51f52a"
},
{
"url": "https://git.kernel.org/stable/c/904367381a922aa2dc3e8bd2488e6c9180516c7a"
},
{
"url": "https://git.kernel.org/stable/c/a154ca3c441a67d36b3a9ea63a4f11b06abe6223"
},
{
"url": "https://git.kernel.org/stable/c/725c1c3a8c5d920a7d3f5887412f2ad8e95a74f5"
},
{
"url": "https://git.kernel.org/stable/c/7f11e70629650ff6ea140984e5ce188b775b2683"
}
],
"title": "wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68355",
"datePublished": "2026-08-10T12:03:32.321Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:03.197Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68188 (GCVE-0-2026-68188)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: Fix session UAF in set_termios
rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and
later passes the pointer to rfcomm_send_rpn(). The latter dereferences
both session->initiator and session->sock. Meanwhile, krfcommd can
unlink the DLC and free the session while holding rfcomm_mutex.
The race can proceed as follows:
TTY ioctl task krfcommd
-------------- --------
load dlc->session
enter rfcomm_send_rpn()
lock rfcomm_mutex
clear dlc->session
free session
unlock rfcomm_mutex
read session->initiator
KASAN reported:
BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0
Read of size 4 at addr ffff88810012a850 by task poc/92
Call Trace:
rfcomm_send_rpn+0x297/0x2a0
rfcomm_tty_set_termios+0x50d/0x850
tty_set_termios+0x596/0x950
set_termios+0x46a/0x6e0
tty_mode_ioctl+0x152/0xbd0
tty_ioctl+0x915/0x1240
__x64_sys_ioctl+0x134/0x1c0
Allocated by task 92:
rfcomm_session_add+0x9e/0x2e0
rfcomm_dlc_open+0x8b1/0xe00
rfcomm_dev_activate+0x85/0x1a0
rfcomm_tty_open+0x90/0x280
Freed by task 68:
kfree+0x131/0x3c0
rfcomm_session_del+0x119/0x180
rfcomm_run+0x737/0x4710
Add rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies
that the DLC is still attached and sends the RPN frame. Have the TTY
path use the helper and drop its unlocked session check. This keeps the
session valid through both the frame construction and socket send.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/rfcomm.h",
"net/bluetooth/rfcomm/core.c",
"net/bluetooth/rfcomm/tty.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4eac4576a072084b06459de6c054b4ebc764b4ea",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "82c383f9031f1ce919ac6c3c06bc5bd492a6b078",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "c5c060597247131f90f39ea7c8c978fa0c2e79d0",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "2894bd8c68e97accd758ca6e5fc375d7e9e8882c",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "a82a9d3891f5607030b0672c255087a12bb9837b",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "780b04d09c941262ee2a2b4a09906451b69df8a6",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "c783399efc22d035443f1dfbf2a09bf9562aaa5e",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/rfcomm.h",
"net/bluetooth/rfcomm/core.c",
"net/bluetooth/rfcomm/tty.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.14"
},
{
"lessThan": "2.6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: Fix session UAF in set_termios\n\nrfcomm_tty_set_termios() tests dlc-\u003esession without rfcomm_mutex and\nlater passes the pointer to rfcomm_send_rpn(). The latter dereferences\nboth session-\u003einitiator and session-\u003esock. Meanwhile, krfcommd can\nunlink the DLC and free the session while holding rfcomm_mutex.\n\nThe race can proceed as follows:\n\n TTY ioctl task krfcommd\n -------------- --------\n load dlc-\u003esession\n enter rfcomm_send_rpn()\n lock rfcomm_mutex\n clear dlc-\u003esession\n free session\n unlock rfcomm_mutex\n read session-\u003einitiator\n\nKASAN reported:\n\n BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0\n Read of size 4 at addr ffff88810012a850 by task poc/92\n\n Call Trace:\n rfcomm_send_rpn+0x297/0x2a0\n rfcomm_tty_set_termios+0x50d/0x850\n tty_set_termios+0x596/0x950\n set_termios+0x46a/0x6e0\n tty_mode_ioctl+0x152/0xbd0\n tty_ioctl+0x915/0x1240\n __x64_sys_ioctl+0x134/0x1c0\n\n Allocated by task 92:\n rfcomm_session_add+0x9e/0x2e0\n rfcomm_dlc_open+0x8b1/0xe00\n rfcomm_dev_activate+0x85/0x1a0\n rfcomm_tty_open+0x90/0x280\n\n Freed by task 68:\n kfree+0x131/0x3c0\n rfcomm_session_del+0x119/0x180\n rfcomm_run+0x737/0x4710\n\nAdd rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies\nthat the DLC is still attached and sends the RPN frame. Have the TTY\npath use the helper and drop its unlocked session check. This keeps the\nsession valid through both the frame construction and socket send."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:59.491Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4eac4576a072084b06459de6c054b4ebc764b4ea"
},
{
"url": "https://git.kernel.org/stable/c/82c383f9031f1ce919ac6c3c06bc5bd492a6b078"
},
{
"url": "https://git.kernel.org/stable/c/c5c060597247131f90f39ea7c8c978fa0c2e79d0"
},
{
"url": "https://git.kernel.org/stable/c/2894bd8c68e97accd758ca6e5fc375d7e9e8882c"
},
{
"url": "https://git.kernel.org/stable/c/a82a9d3891f5607030b0672c255087a12bb9837b"
},
{
"url": "https://git.kernel.org/stable/c/780b04d09c941262ee2a2b4a09906451b69df8a6"
},
{
"url": "https://git.kernel.org/stable/c/98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea"
},
{
"url": "https://git.kernel.org/stable/c/c783399efc22d035443f1dfbf2a09bf9562aaa5e"
}
],
"title": "Bluetooth: RFCOMM: Fix session UAF in set_termios",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68188",
"datePublished": "2026-08-10T12:00:00.521Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:59.491Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80654 (GCVE-0-2026-80654)
Vulnerability from cvelistv5
Published
2026-08-28 06:49
Modified
2026-08-28 06:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
soc: xilinx: Shutdown and free rx mailbox channel
A mbox rx channel is requested using mbox_request_channel_byname() in
probe. In remove callback, the rx mailbox channel is cleaned up when the
rx_chan is NULL due to incorrect condition check. The mailbox channel is
not shutdown and it can receive messages even after the device removal.
This leads to use after free. Also the channel resources are not freed.
Fix this by checking the rx_chan correctly.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/soc/xilinx/zynqmp_power.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b0f748c563921a7918c78e6a599cefd54de7d688",
"status": "affected",
"version": "ffdbae28d9d1af70b7d63ffd7827e9795cd8d0df",
"versionType": "git"
},
{
"lessThan": "a83e77d1e52c01c50096e6e97c57d34e0590d628",
"status": "affected",
"version": "ffdbae28d9d1af70b7d63ffd7827e9795cd8d0df",
"versionType": "git"
},
{
"lessThan": "b5d2240c2c7bc8370e7ba54a2e1fe3919f55aee5",
"status": "affected",
"version": "ffdbae28d9d1af70b7d63ffd7827e9795cd8d0df",
"versionType": "git"
},
{
"lessThan": "fdee7c66c0d7b6869c36b9f9a915abf29ab5b550",
"status": "affected",
"version": "ffdbae28d9d1af70b7d63ffd7827e9795cd8d0df",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/soc/xilinx/zynqmp_power.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: xilinx: Shutdown and free rx mailbox channel\n\nA mbox rx channel is requested using mbox_request_channel_byname() in\nprobe. In remove callback, the rx mailbox channel is cleaned up when the\nrx_chan is NULL due to incorrect condition check. The mailbox channel is\nnot shutdown and it can receive messages even after the device removal.\nThis leads to use after free. Also the channel resources are not freed.\nFix this by checking the rx_chan correctly."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T06:49:01.311Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b0f748c563921a7918c78e6a599cefd54de7d688"
},
{
"url": "https://git.kernel.org/stable/c/a83e77d1e52c01c50096e6e97c57d34e0590d628"
},
{
"url": "https://git.kernel.org/stable/c/b5d2240c2c7bc8370e7ba54a2e1fe3919f55aee5"
},
{
"url": "https://git.kernel.org/stable/c/fdee7c66c0d7b6869c36b9f9a915abf29ab5b550"
}
],
"title": "soc: xilinx: Shutdown and free rx mailbox channel",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80654",
"datePublished": "2026-08-28T06:49:01.311Z",
"dateReserved": "2026-08-26T14:34:25.780Z",
"dateUpdated": "2026-08-28T06:49:01.311Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72495 (GCVE-0-2026-72495)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
Applications can request multiple WC pages for the same ucontext.
As of now, only 1 WC page per ucontext is supported. Add a lock to
avoid concurrent access and a check to fail repeated requests.
Also, if the mmap entry insert fails for the WC, free the Doorbell
page index mapped for the WC page.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/ib_verbs.c",
"drivers/infiniband/hw/bnxt_re/ib_verbs.h",
"drivers/infiniband/hw/bnxt_re/uapi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "478c4d24193fe3e6aa2accd4874ae43000e4a217",
"status": "affected",
"version": "360da60d6c6edb9740de7a8e6d8969d62ceff956",
"versionType": "git"
},
{
"lessThan": "da406b8b49c1dfe661a497483940d7ee781430db",
"status": "affected",
"version": "360da60d6c6edb9740de7a8e6d8969d62ceff956",
"versionType": "git"
},
{
"lessThan": "441baa79043431807115fd030d7d0bb14ed441a0",
"status": "affected",
"version": "360da60d6c6edb9740de7a8e6d8969d62ceff956",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/ib_verbs.c",
"drivers/infiniband/hw/bnxt_re/ib_verbs.h",
"drivers/infiniband/hw/bnxt_re/uapi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Avoid repeated requests to allocate WC pages\n\nApplications can request multiple WC pages for the same ucontext.\nAs of now, only 1 WC page per ucontext is supported. Add a lock to\navoid concurrent access and a check to fail repeated requests.\nAlso, if the mmap entry insert fails for the WC, free the Doorbell\npage index mapped for the WC page."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is in BNXT_RE_METHOD_ALLOC_PAGE, reached only via write/ioctl on /dev/infiniband/uverbs* after IB ucontext creation; remote RoCE packet handling and in-kernel RDMA target/server paths never invoke this WC DPI allocation routine.\nAC:L - An attacker can deterministically trigger the bug by issuing repeated or concurrent BNXT_RE_ALLOC_WC_PAGE calls from multiple threads on the same ucontext; they control both sides of the race and need no uncontrollable memory layout or victim-specific state.\nPR:N - Standard uverbs character devices are created mode 0666, so any local process can open the bnxt_re device, allocate a ucontext, and invoke BNXT_RE_METHOD_ALLOC_PAGE without CAP_SYS_ADMIN, init-namespace root, or other elevated capabilities.\nUI:N - No victim interaction is required; exploitation needs only the attacker (or a compromised local RDMA workload) repeatedly or concurrently calling ALLOC_PAGE on resources it already controls through normal RDMA verbs.\nS:C - On HPC/cloud hosts exposing bnxt_re to tenant containers or unprivileged RDMA workloads, corrupting shared per-device DPI bookkeeping or exhausting finite doorbell indices crosses the container/tenant boundary to impact the host/kernel security authority.\nC:H - Without serialization or duplicate checks, corrupt DPI index bookkeeping and premature slot reuse can alias WC doorbell BAR pages across contexts, exposing other users\u0027 doorbell state and providing resource-corruption primitives usable for information disclosure.\nI:H - Destroying one ALLOC_PAGE object can deallocate another object\u0027s live WC DPI slot while its BAR mmap remains active, letting a later allocation share the same doorbell page and enabling cross-context WC doorbell writes that corrupt other tenants\u0027 RDMA queue signaling.\nA:H - Each orphaned DPI entry permanently consumes a finite per-device doorbell index (exhaustible via repeated or concurrent ALLOC_PAGE), denying RDMA service cluster-wide; unsynchronized wcdpi updates can also destabilize kernel DPI teardown paths."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:44:56.649Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/478c4d24193fe3e6aa2accd4874ae43000e4a217"
},
{
"url": "https://git.kernel.org/stable/c/da406b8b49c1dfe661a497483940d7ee781430db"
},
{
"url": "https://git.kernel.org/stable/c/441baa79043431807115fd030d7d0bb14ed441a0"
}
],
"title": "RDMA/bnxt_re: Avoid repeated requests to allocate WC pages",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72495",
"datePublished": "2026-08-15T05:57:28.920Z",
"dateReserved": "2026-08-09T03:40:39.937Z",
"dateUpdated": "2026-08-17T05:44:56.649Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64146 (GCVE-0-2026-64146)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
erofs: fix metabuf leak in inode xattr initialization
commit bb88e8da0025 ("erofs: use meta buffers for xattr operations")
converted xattr operations to use on-stack erofs_buf instances.
erofs_init_inode_xattrs() uses such a metabuf while reading the inline
xattr header and shared xattr id array.
Some error paths after erofs_read_metabuf() leave through out_unlock
without dropping the metabuf, so the folio reference can leak.
Consolidate the cleanup at out_unlock. erofs_put_metabuf() is a
no-op if no folio has been acquired, and this keeps all paths after
taking EROFS_I_BL_XATTR_BIT covered by a single cleanup site.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/erofs/xattr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "492c73b21fefa36f3869cb2b188ffb7fe37b3a9b",
"status": "affected",
"version": "bb88e8da00253bea0e7f0f4cdfd7910572d7799f",
"versionType": "git"
},
{
"lessThan": "79b09c54c6563df9846ca3094bcfd72082c3e1d7",
"status": "affected",
"version": "bb88e8da00253bea0e7f0f4cdfd7910572d7799f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/erofs/xattr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix metabuf leak in inode xattr initialization\n\ncommit bb88e8da0025 (\"erofs: use meta buffers for xattr operations\")\nconverted xattr operations to use on-stack erofs_buf instances.\nerofs_init_inode_xattrs() uses such a metabuf while reading the inline\nxattr header and shared xattr id array.\n\nSome error paths after erofs_read_metabuf() leave through out_unlock\nwithout dropping the metabuf, so the folio reference can leak.\n\nConsolidate the cleanup at out_unlock. erofs_put_metabuf() is a\nno-op if no folio has been acquired, and this keeps all paths after\ntaking EROFS_I_BL_XATTR_BIT covered by a single cleanup site."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:37.474Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/492c73b21fefa36f3869cb2b188ffb7fe37b3a9b"
},
{
"url": "https://git.kernel.org/stable/c/79b09c54c6563df9846ca3094bcfd72082c3e1d7"
}
],
"title": "erofs: fix metabuf leak in inode xattr initialization",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64146",
"datePublished": "2026-07-19T15:40:37.474Z",
"dateReserved": "2026-07-19T07:54:57.037Z",
"dateUpdated": "2026-07-19T15:40:37.474Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72254 (GCVE-0-2026-72254)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-17 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_fib: reject fib expression on the netdev egress hook
A fib expression in a netdev egress base chain dereferences nft_in(pkt),
NULL on the transmit path, causing a NULL pointer dereference at eval.
nft_fib_validate() masks the hook with NF_INET_* values, but netdev hook
numbers are a separate enum that aliases them (NF_NETDEV_EGRESS ==
NF_INET_LOCAL_IN), so an egress chain passes validation and then faults.
Add nft_fib_netdev_validate() that limits each result/flag to the netdev
hook where the device it reads exists: the input-device cases (OIF,
OIFNAME, ADDRTYPE with F_IIF) to ingress, the output-device case (ADDRTYPE
with F_OIF) to egress, ADDRTYPE with no device flag to both. Also restrict
nft_fib_validate() to NFPROTO_IPV4/IPV6/INET so its NF_INET_* masks are
not applied to another family's hooks.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_fib.c",
"net/netfilter/nft_fib_netdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4fee43759b489559a491f7c95f9bfa7a1d0c7a10",
"status": "affected",
"version": "42df6e1d221dddc0f2acf2be37e68d553ad65f96",
"versionType": "git"
},
{
"lessThan": "568931f26af4727a51e8521f72efbc78d3b82410",
"status": "affected",
"version": "42df6e1d221dddc0f2acf2be37e68d553ad65f96",
"versionType": "git"
},
{
"lessThan": "d01c913febead04a01a5f3a6374d1f45504dc523",
"status": "affected",
"version": "42df6e1d221dddc0f2acf2be37e68d553ad65f96",
"versionType": "git"
},
{
"lessThan": "f68305267ebda7e839b5e8f77e8d77535a3d5a0f",
"status": "affected",
"version": "42df6e1d221dddc0f2acf2be37e68d553ad65f96",
"versionType": "git"
},
{
"lessThan": "d07955dd34ecae17d35d8c7d0a273a3fba653a8c",
"status": "affected",
"version": "42df6e1d221dddc0f2acf2be37e68d553ad65f96",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_fib.c",
"net/netfilter/nft_fib_netdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_fib: reject fib expression on the netdev egress hook\n\nA fib expression in a netdev egress base chain dereferences nft_in(pkt),\nNULL on the transmit path, causing a NULL pointer dereference at eval.\nnft_fib_validate() masks the hook with NF_INET_* values, but netdev hook\nnumbers are a separate enum that aliases them (NF_NETDEV_EGRESS ==\nNF_INET_LOCAL_IN), so an egress chain passes validation and then faults.\n\nAdd nft_fib_netdev_validate() that limits each result/flag to the netdev\nhook where the device it reads exists: the input-device cases (OIF,\nOIFNAME, ADDRTYPE with F_IIF) to ingress, the output-device case (ADDRTYPE\nwith F_OIF) to egress, ADDRTYPE with no device flag to both. Also restrict\nnft_fib_validate() to NFPROTO_IPV4/IPV6/INET so its NF_INET_* masks are\nnot applied to another family\u0027s hooks."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Once a netdev egress fib rule is installed, evaluation runs on the packet transmit datapath (nf_hook_egress in __dev_queue_xmit); a remote peer can trigger it by causing the host to send matching IPv4/IPv6 traffic through the hooked interface, matching prior netfilter CNA treatment of pre-deployed nftables rules (e.g. CVE-2026-52998).\nAC:L - No race or uncontrollable victim state is required; with an affected egress fib rule present, the attacker reliably triggers the NULL dereference on the next matching outbound packet by controlling protocol headers and normal connection traffic.\nPR:N - Runtime exploitation needs only network traffic through the netdev egress hook; although installing the fib rule requires CAP_NET_ADMIN, validation incorrectly accepts it as legal, so orchestration or administrators can deploy it and remote attackers need no target credentials or local privileges.\nUI:N - No victim interaction is required beyond ordinary network traffic processing; the kernel automatically evaluates the fib expression on egress without mounts, file opens, or user prompts.\nS:U - Impact is a kernel NULL-pointer fault and host-wide denial of service within the same kernel/network-filtering security authority; it does not constitute VM escape, IOMMU bypass, or another cross-authority boundary change.\nC:N - The failure mode is a NULL pointer dereference of nft_in(pkt) on egress (in is NULL in nf_hook_state_init); there is no use-after-free, out-of-bounds read, or other attacker-controlled memory disclosure primitive.\nI:N - The bug does not corrupt writable memory or provide control-flow hijack; it only dereferences a NULL input device pointer during fib lookup/skipping and cannot modify kernel or user data beyond the immediate fault.\nA:H - The NULL dereference in nft_fib_netdev_eval/nft_fib4_eval/nft_fib6_eval on netdev egress causes a kernel oops/panic-class fault during packet transmission, denying system availability until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:42:07.408Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4fee43759b489559a491f7c95f9bfa7a1d0c7a10"
},
{
"url": "https://git.kernel.org/stable/c/568931f26af4727a51e8521f72efbc78d3b82410"
},
{
"url": "https://git.kernel.org/stable/c/d01c913febead04a01a5f3a6374d1f45504dc523"
},
{
"url": "https://git.kernel.org/stable/c/f68305267ebda7e839b5e8f77e8d77535a3d5a0f"
},
{
"url": "https://git.kernel.org/stable/c/d07955dd34ecae17d35d8c7d0a273a3fba653a8c"
}
],
"title": "netfilter: nft_fib: reject fib expression on the netdev egress hook",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72254",
"datePublished": "2026-08-15T05:54:42.239Z",
"dateReserved": "2026-08-09T03:40:39.915Z",
"dateUpdated": "2026-08-17T05:42:07.408Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-23230 (GCVE-0-2026-23230)
Vulnerability from cvelistv5
Published
2026-02-18 14:53
Modified
2026-08-05 12:20
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: split cached_fid bitfields to avoid shared-byte RMW races
is_open, has_lease and on_list are stored in the same bitfield byte in
struct cached_fid but are updated in different code paths that may run
concurrently. Bitfield assignments generate byte read–modify–write
operations (e.g. `orb $mask, addr` on x86_64), so updating one flag can
restore stale values of the others.
A possible interleaving is:
CPU1: load old byte (has_lease=1, on_list=1)
CPU2: clear both flags (store 0)
CPU1: RMW store (old | IS_OPEN) -> reintroduces cleared bits
To avoid this class of races, convert these flags to separate bool
fields.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ebe98f1447bbccf8228335c62d86af02a0ed23f7 Version: ebe98f1447bbccf8228335c62d86af02a0ed23f7 Version: ebe98f1447bbccf8228335c62d86af02a0ed23f7 Version: ebe98f1447bbccf8228335c62d86af02a0ed23f7 Version: ebe98f1447bbccf8228335c62d86af02a0ed23f7 Version: ebe98f1447bbccf8228335c62d86af02a0ed23f7 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "RUGGEDCOM RST2428P",
"vendor": "Siemens",
"versions": [
{
"lessThan": "V4.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-02T13:01:05.733Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/cached_dir.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "569fecc56bfe4df66f05734d67daef887746656b",
"status": "affected",
"version": "ebe98f1447bbccf8228335c62d86af02a0ed23f7",
"versionType": "git"
},
{
"lessThan": "4386f6af8aaedd0c5ad6f659b40cadcc8f423828",
"status": "affected",
"version": "ebe98f1447bbccf8228335c62d86af02a0ed23f7",
"versionType": "git"
},
{
"lessThan": "3eaa22d688311c708b73f3c68bc6d0c8e3f0f77a",
"status": "affected",
"version": "ebe98f1447bbccf8228335c62d86af02a0ed23f7",
"versionType": "git"
},
{
"lessThan": "c4b9edd55987384a1f201d3d07ff71e448d79c1b",
"status": "affected",
"version": "ebe98f1447bbccf8228335c62d86af02a0ed23f7",
"versionType": "git"
},
{
"lessThan": "4cfa4c37dcbcfd70866e856200ed8a2894cac578",
"status": "affected",
"version": "ebe98f1447bbccf8228335c62d86af02a0ed23f7",
"versionType": "git"
},
{
"lessThan": "ec306600d5ba7148c9dbf8f5a8f1f5c1a044a241",
"status": "affected",
"version": "ebe98f1447bbccf8228335c62d86af02a0ed23f7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/cached_dir.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.164",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.125",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.72",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.164",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.125",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.72",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.11",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.1",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: split cached_fid bitfields to avoid shared-byte RMW races\n\nis_open, has_lease and on_list are stored in the same bitfield byte in\nstruct cached_fid but are updated in different code paths that may run\nconcurrently. Bitfield assignments generate byte read\u2013modify\u2013write\noperations (e.g. `orb $mask, addr` on x86_64), so updating one flag can\nrestore stale values of the others.\n\nA possible interleaving is:\n CPU1: load old byte (has_lease=1, on_list=1)\n CPU2: clear both flags (store 0)\n CPU1: RMW store (old | IS_OPEN) -\u003e reintroduces cleared bits\n\nTo avoid this class of races, convert these flags to separate bool\nfields."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerability is in the SMB client code (fs/smb/client/). The race is triggered between processing a server\u0027s create response (setting is_open) and the server sending a lease break notification. A malicious SMB server can trigger this remotely over the network.\nAC:L - The attacker (malicious SMB server) controls when lease breaks are sent and can time them immediately after the create response. The attacker can retry many times across many directory opens, and the RMW race window is inherent to every bitfield write, making it reliably triggerable.\nPR:N - The attacker is the SMB server, requiring no privileges on the victim system. The lease break is processed as part of normal SMB protocol handling with no additional authentication check beyond the existing session.\nUI:R - The victim must mount an SMB share from the attacker\u0027s server (or a compromised server), which requires explicit user or administrator action.\nS:U - The vulnerability impacts the kernel where the SMB client runs; it does not cross a security boundary such as a VM or sandbox.\nC:H - The race can restore has_lease after the lease reference was dropped, leading to reference count corruption and use-after-free. UAF on heap objects gives the attacker read primitives over arbitrary kernel memory through heap spraying.\nI:H - The use-after-free from reference count corruption allows the attacker to reclaim the freed cached_fid object with controlled data, enabling arbitrary kernel write primitives and potential code execution.\nA:H - The reference count corruption and list corruption caused by the restored stale flags will lead to double-free, use-after-free, or list corruption, all of which reliably cause kernel panics/oops."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:20:46.650Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/569fecc56bfe4df66f05734d67daef887746656b"
},
{
"url": "https://git.kernel.org/stable/c/4386f6af8aaedd0c5ad6f659b40cadcc8f423828"
},
{
"url": "https://git.kernel.org/stable/c/3eaa22d688311c708b73f3c68bc6d0c8e3f0f77a"
},
{
"url": "https://git.kernel.org/stable/c/c4b9edd55987384a1f201d3d07ff71e448d79c1b"
},
{
"url": "https://git.kernel.org/stable/c/4cfa4c37dcbcfd70866e856200ed8a2894cac578"
},
{
"url": "https://git.kernel.org/stable/c/ec306600d5ba7148c9dbf8f5a8f1f5c1a044a241"
}
],
"title": "smb: client: split cached_fid bitfields to avoid shared-byte RMW races",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-23230",
"datePublished": "2026-02-18T14:53:34.078Z",
"dateReserved": "2026-01-13T15:37:45.988Z",
"dateUpdated": "2026-08-05T12:20:46.650Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72069 (GCVE-0-2026-72069)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
rt_spin_unlock() releases the RCU protection before unlocking the
lock. That opens the door for the following UAF scenario:
T1 T2
spin_lock(&p->lock); rcu_read_lock();
invalidate(p); p = rcu_dereference(ptr);
rcu_assign_pointer(ptr, NULL); if (!p) return;
spin_unlock(&p->lock); spin_lock(&p->lock)
lock(&lock->lock);
rcu_read_lock();
kfree_rcu(p); rcu_read_unlock();
....
spin_unlock(&p->lock)
rcu_read_unlock(); // Ends grace period
rcu_do_batch()
kfree(p);
UAF -> rt_mutex_cmpxchg_release(&lock->lock...)
Regular spinlocks keep preemption disabled accross the unlock operation,
which provides full RCU protection, but the RT substitution fails to
resemble that. Same applies for the rwlock substitution.
Move the rcu_read_unlock() invocation past the unlock operations to match
the non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but
that's harmless as the caller needs to hold RCU read lock across the lock
operation. The migrate_enable() call stays before the unlock operation
because there is no per CPU operation in the unlock path which would
require migration to be kept disabled.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/locking/spinlock_rt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "af28d801cd2db4cc7378554499bd4a5d84a5517e",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "9d1fcd64ab81200e02b7a6db5eb1da8e244e8289",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "3cfaac77b3c32ac3940df28866de263c3f45d24c",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "1f0d56d3f1e88f20f6e46109402f8c15d59bac37",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "633cadbc0b8323f5cc140a285d2432089dbb534e",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "83f9fb561c1c3917e19f95523dd933c7d30291aa",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "89038cc87d80c77e7aa6f42a64b2573b74af339f",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/locking/spinlock_rt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/rt: Fix the incorrect RCU protection in rt_spin_unlock()\n\nrt_spin_unlock() releases the RCU protection before unlocking the\nlock. That opens the door for the following UAF scenario:\n\n T1\t\t\t\t\tT2\n spin_lock(\u0026p-\u003elock);\t\trcu_read_lock();\n invalidate(p);\t\t\tp = rcu_dereference(ptr);\n rcu_assign_pointer(ptr, NULL);\tif (!p) return;\n spin_unlock(\u0026p-\u003elock);\t\tspin_lock(\u0026p-\u003elock)\n \t\t\t\t lock(\u0026lock-\u003elock);\n\t\t\t\t rcu_read_lock();\n kfree_rcu(p);\t\t\trcu_read_unlock();\n\t\t\t\t....\n\t\t\t\tspin_unlock(\u0026p-\u003elock)\n\t\t\t\t rcu_read_unlock(); // Ends grace period\n rcu_do_batch()\n kfree(p);\n\t\t\t UAF -\u003e\t rt_mutex_cmpxchg_release(\u0026lock-\u003elock...)\n\nRegular spinlocks keep preemption disabled accross the unlock operation,\nwhich provides full RCU protection, but the RT substitution fails to\nresemble that. Same applies for the rwlock substitution.\n\nMove the rcu_read_unlock() invocation past the unlock operations to match\nthe non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but\nthat\u0027s harmless as the caller needs to hold RCU read lock across the lock\noperation. The migrate_enable() call stays before the unlock operation\nbecause there is no per CPU operation in the unlock path which would\nrequire migration to be kept disabled."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On CONFIG_PREEMPT_RT, every spin_unlock() is substituted by rt_spin_unlock(); network subsystems such as netfilter xt_hashlimit process inbound packets through hashlimit_mt_common(), spin_lock/unlock on RCU-protected dsthash_ent objects concurrently freed via call_rcu by GC\u2014the exact embedded-spinlock UAF pattern from the fix.\nAC:L - The bug is a cross-CPU race where rt_spin_unlock() calls rcu_read_unlock() before releasing the rtmutex, ending the RCU grace period while still dereferencing the lock; syzbot triggered this reliably on PREEMPT_RT via concurrent unlinkat and dentry teardown, and attackers control both sides with parallel syscalls or packet/GC load.\nPR:N - Remote attackers need no account, capability, or authentication to send packets that hit deployed hashlimit rules on internet-facing PREEMPT_RT gateways; the proven syzbot unlinkat path needs only directory write permission (PR:L), but PR:N reflects the highest-severity unauthenticated network packet scenario.\nUI:N - No victim interaction is required; the attacker drives the race through their own concurrent filesystem syscalls (syzbot: unlinkat racing __fput/dentry_kill) or sustained inbound traffic overlapping netfilter GC, without needing another user to open files or mount filesystems.\nS:U - The UAF corrupts kernel slab memory containing embedded spinlock/rtmutex fields and enables privilege escalation within the same kernel security authority; it does not inherently cross VM/guest, container sandbox, or IOMMU hardware isolation boundaries.\nC:H - Syzbot reported KASAN slab-use-after-free Read in rt_mutex_slowunlock during spin_unlock on a freed dentry in shrink_dcache_tree; the systemic UAF lets attackers read freed objects (dentry, dsthash_ent, etc.) after premature RCU grace-period completion, enabling kernel pointer and memory disclosure.\nI:H - UAF on embedded rtmutex fields inside freed slab objects (dentry-\u003ed_lock per syzbot) permits heap grooming and reallocation of attacker-controlled data, providing standard kernel heap corruption primitives for arbitrary write and control-flow hijack beyond the immediate crash.\nA:H - Syzbot hit KASAN slab-use-after-free causing kernel fault in shrink_dcache_tree via rt_spin_unlock on PREEMPT_RT; the bug can oops/panic any RT kernel whenever spin_unlock races RCU-deferred free of the containing object, enabling repeatable denial of service via concurrent VFS or netfilter operations."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:41.836Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/af28d801cd2db4cc7378554499bd4a5d84a5517e"
},
{
"url": "https://git.kernel.org/stable/c/9d1fcd64ab81200e02b7a6db5eb1da8e244e8289"
},
{
"url": "https://git.kernel.org/stable/c/3cfaac77b3c32ac3940df28866de263c3f45d24c"
},
{
"url": "https://git.kernel.org/stable/c/1f0d56d3f1e88f20f6e46109402f8c15d59bac37"
},
{
"url": "https://git.kernel.org/stable/c/633cadbc0b8323f5cc140a285d2432089dbb534e"
},
{
"url": "https://git.kernel.org/stable/c/83f9fb561c1c3917e19f95523dd933c7d30291aa"
},
{
"url": "https://git.kernel.org/stable/c/89038cc87d80c77e7aa6f42a64b2573b74af339f"
}
],
"title": "locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72069",
"datePublished": "2026-08-15T05:52:21.752Z",
"dateReserved": "2026-08-09T03:40:39.903Z",
"dateUpdated": "2026-08-23T12:46:41.836Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68429 (GCVE-0-2026-68429)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
A hotplug or link-loss event can tear down the MST topology
(setting mgr->mst_state = false and mgr->mst_primary = NULL) concurrently
with a caller invoking drm_dp_mst_topology_queue_probe(). Since the check
is already performed under mgr->lock, the condition is not a programming
error but a valid race -- the topology was valid when the caller decided
to call this function, but was torn down before the lock was acquired.
Replace the drm_WARN_ON() with a graceful early return. This eliminates
spurious kernel warnings and the resulting compositor crashes observed
when connecting/disconnecting DP MST monitors, while keeping the correct
behavior of doing nothing when MST is not active. A drm_dbg_mst() trace
is added so the skipped probe remains observable under MST debug logging.
The existing WARN_ON(mgr->mst_primary) in drm_dp_mst_topology_mgr_set_mst()
already catches the case where the topology is initialized twice, so no
diagnostic coverage is lost.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5f57a96e92c60f62da91d58ceb5e5acd40e7d594 Version: dbaeef363ea54f4c18112874b77503c72ba60fec Version: dbaeef363ea54f4c18112874b77503c72ba60fec Version: dbaeef363ea54f4c18112874b77503c72ba60fec Version: dbaeef363ea54f4c18112874b77503c72ba60fec Version: 6.6.86 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b1d05cc61dfa6c4bd5e67855bec6a03e955f512d",
"status": "affected",
"version": "5f57a96e92c60f62da91d58ceb5e5acd40e7d594",
"versionType": "git"
},
{
"lessThan": "4ed6d08c4a59ee6a8cb806347f6d9873de5d229e",
"status": "affected",
"version": "dbaeef363ea54f4c18112874b77503c72ba60fec",
"versionType": "git"
},
{
"lessThan": "8c6d84a54823cd839e6ce22af559925f1320c310",
"status": "affected",
"version": "dbaeef363ea54f4c18112874b77503c72ba60fec",
"versionType": "git"
},
{
"lessThan": "afdff9103818656627920c21822e48a6dae2906f",
"status": "affected",
"version": "dbaeef363ea54f4c18112874b77503c72ba60fec",
"versionType": "git"
},
{
"lessThan": "613059875958e7b217b250ed14c3b189f9488421",
"status": "affected",
"version": "dbaeef363ea54f4c18112874b77503c72ba60fec",
"versionType": "git"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.86",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.86",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()\n\nA hotplug or link-loss event can tear down the MST topology\n(setting mgr-\u003emst_state = false and mgr-\u003emst_primary = NULL) concurrently\nwith a caller invoking drm_dp_mst_topology_queue_probe(). Since the check\nis already performed under mgr-\u003elock, the condition is not a programming\nerror but a valid race -- the topology was valid when the caller decided\nto call this function, but was torn down before the lock was acquired.\n\nReplace the drm_WARN_ON() with a graceful early return. This eliminates\nspurious kernel warnings and the resulting compositor crashes observed\nwhen connecting/disconnecting DP MST monitors, while keeping the correct\nbehavior of doing nothing when MST is not active. A drm_dbg_mst() trace\nis added so the skipped probe remains observable under MST debug logging.\n\nThe existing WARN_ON(mgr-\u003emst_primary) in drm_dp_mst_topology_mgr_set_mst()\nalready catches the case where the topology is initialized twice, so no\ndiagnostic coverage is lost."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:25.387Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b1d05cc61dfa6c4bd5e67855bec6a03e955f512d"
},
{
"url": "https://git.kernel.org/stable/c/4ed6d08c4a59ee6a8cb806347f6d9873de5d229e"
},
{
"url": "https://git.kernel.org/stable/c/8c6d84a54823cd839e6ce22af559925f1320c310"
},
{
"url": "https://git.kernel.org/stable/c/afdff9103818656627920c21822e48a6dae2906f"
},
{
"url": "https://git.kernel.org/stable/c/613059875958e7b217b250ed14c3b189f9488421"
}
],
"title": "drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68429",
"datePublished": "2026-08-12T00:07:14.640Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-17T05:05:25.387Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68085 (GCVE-0-2026-68085)
Vulnerability from cvelistv5
Published
2026-08-10 11:51
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
HCI_UART_SENDING bit in tx_state means write_work is pending and blocks
queueing it again. Currently this bit is not cleared when canceling the
work in hci_uart_close(), which blocks future writes when device is
reopened later if write_work was pending.
Fix by clearing HCI_UART_SENDING when canceling the work.
Also make clearing of tx_skb safe by using disable_work_sync +
enable_work instead of just cancel_work_sync. hci_uart_flush() purges
the proto tx queue so we can cancel the pending write_work there,
instead of doing it just in hci_uart_close(). Re-enable and possibly
requeue the work after queue flush.
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 81c7a3c22a0f2808cf4ae0b4908f59763b23606d Version: 192cb0f1ca706d9a1bc36ae0ad5f666d1e4fd894 Version: c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b Version: c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b Version: 78aad93e938f013d9272fe0ee168f27883afa95c Version: e2d19969c8d9198ecc3090bcd5312ecd503a3339 Version: c85cff648a2bc92322912db5f1727ad05afae7b6 Version: 9d20d48be2c4a071fb015eb09bda2cecd25daf34 Version: 7338031946bd06f6dff149e67b60c4cd083bfea8 Version: 6.12.92 ≤ Version: 6.18.34 ≤ Version: 5.10.258 ≤ Version: 5.15.209 ≤ Version: 6.1.175 ≤ Version: 6.6.142 ≤ Version: 7.0.11 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/hci_ldisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d52446b3e735cfdbdc2a58342163803bc2e64249",
"status": "affected",
"version": "81c7a3c22a0f2808cf4ae0b4908f59763b23606d",
"versionType": "git"
},
{
"lessThan": "b9dd39cf1667e378b25a082ca796d495d578c5d3",
"status": "affected",
"version": "192cb0f1ca706d9a1bc36ae0ad5f666d1e4fd894",
"versionType": "git"
},
{
"lessThan": "714d861d35d937f23375a4517569b13917bbbe51",
"status": "affected",
"version": "c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b",
"versionType": "git"
},
{
"lessThan": "1b0d946d6f08bd39211385bc703a440911b41e46",
"status": "affected",
"version": "c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b",
"versionType": "git"
},
{
"status": "affected",
"version": "78aad93e938f013d9272fe0ee168f27883afa95c",
"versionType": "git"
},
{
"status": "affected",
"version": "e2d19969c8d9198ecc3090bcd5312ecd503a3339",
"versionType": "git"
},
{
"status": "affected",
"version": "c85cff648a2bc92322912db5f1727ad05afae7b6",
"versionType": "git"
},
{
"status": "affected",
"version": "9d20d48be2c4a071fb015eb09bda2cecd25daf34",
"versionType": "git"
},
{
"status": "affected",
"version": "7338031946bd06f6dff149e67b60c4cd083bfea8",
"versionType": "git"
},
{
"lessThan": "6.12.96",
"status": "affected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThan": "6.18.39",
"status": "affected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThan": "5.11",
"status": "affected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThan": "6.2",
"status": "affected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThan": "6.7",
"status": "affected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThan": "7.1",
"status": "affected",
"version": "7.0.11",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/hci_ldisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"lessThan": "7.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.12.92",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.18.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.10.258",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.209",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.1.175",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.6.142",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7.0.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled\n\nHCI_UART_SENDING bit in tx_state means write_work is pending and blocks\nqueueing it again. Currently this bit is not cleared when canceling the\nwork in hci_uart_close(), which blocks future writes when device is\nreopened later if write_work was pending.\n\nFix by clearing HCI_UART_SENDING when canceling the work.\n\nAlso make clearing of tx_skb safe by using disable_work_sync +\nenable_work instead of just cancel_work_sync. hci_uart_flush() purges\nthe proto tx queue so we can cancel the pending write_work there,\ninstead of doing it just in hci_uart_close(). Re-enable and possibly\nrequeue the work after queue flush."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The flaw is in the Bluetooth HCI UART TX teardown path; an adjacent Bluetooth peer can drive HCI traffic to keep write_work pending while privileged stack management (HCIDEVRESET/close during adapter recovery) executes hci_uart_close/flush.\nAC:L - An attacker controls both sides of the race by generating HCI TX to set HCI_UART_SENDING and concurrently triggering adapter close/reset (e.g., HCIDEVRESET), making the stuck-bit and tx_skb teardown races reliably reachable.\nPR:L - Direct exploitation requires CAP_NET_ADMIN to attach the N_HCI TTY line discipline and issue HCIDEVDOWN/HCIDEVRESET ioctls; this capability is available to unprivileged users inside user namespaces, not only init-namespace root.\nUI:N - No victim interaction is required beyond normal Bluetooth operation; exploitation is achieved through attacker-driven HCI traffic and adapter close/reset timing without the user opening files or confirming prompts.\nS:U - Impact is confined to kernel Bluetooth/UART state on the host (permanent TX failure or kernel crash); it does not cross a VM, container, or IOMMU security boundary to affect a different authority.\nC:H - The vulnerable hci_uart_flush path can race with protocol timers requeueing write_work, causing tx_skb double-free/UAF heap corruption that can expose kernel memory contents, not merely a functional TX stall.\nI:H - Concurrent flush and write_work on tx_skb enables heap corruption primitives typical of double-free/UAF bugs in the kernel slab allocator, which can be leveraged for arbitrary memory writes and code execution.\nA:H - Leaving HCI_UART_SENDING set after cancel permanently blocks all future Bluetooth transmissions after reopen until full teardown, and the tx_skb corruption race can trigger kernel oops/panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:33.786Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d52446b3e735cfdbdc2a58342163803bc2e64249"
},
{
"url": "https://git.kernel.org/stable/c/b9dd39cf1667e378b25a082ca796d495d578c5d3"
},
{
"url": "https://git.kernel.org/stable/c/714d861d35d937f23375a4517569b13917bbbe51"
},
{
"url": "https://git.kernel.org/stable/c/1b0d946d6f08bd39211385bc703a440911b41e46"
}
],
"title": "Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68085",
"datePublished": "2026-08-10T11:51:39.079Z",
"dateReserved": "2026-07-30T09:28:09.367Z",
"dateUpdated": "2026-08-17T04:58:33.786Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68297 (GCVE-0-2026-68297)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix u16 MTU truncation in media and bearer MTU validation
Both TIPC_NL_MEDIA_SET and TIPC_NL_BEARER_SET accept user-supplied
MTU values but only enforce a minimum bound, not a maximum. When a user
sets the MTU to a value exceeding U16_MAX (65535), it passes validation
but is silently truncated when assigned to u16 fields l->mtu and
l->advertised_mtu in tipc_link_create(). Values like 65536 (0x10000)
truncate to 0, causing a division by zero in tipc_link_set_queue_limits()
which computes TIPC_MAX_PUBL / (l->mtu / ITEM_SIZE). Other overflowing
values (e.g. 65537-131071) produce small incorrect MTU values, resulting
in link malfunction behaviors.
Crash stack (triggered as unprivileged user via user namespace):
tipc_link_set_queue_limits net/tipc/link.c:2531
tipc_link_create net/tipc/link.c:520
tipc_node_check_dest net/tipc/node.c:1279
tipc_disc_rcv net/tipc/discover.c:252
tipc_rcv net/tipc/node.c:2129
tipc_udp_recv net/tipc/udp_media.c:392
Two independent paths lack the upper bound check:
1. tipc_udp_mtu_bad() -- called from __tipc_nl_media_set() (MEDIA_SET)
2. inline check in __tipc_nl_bearer_set() at bearer.c:1160 (BEARER_SET)
Fix both by rejecting MTU values above U16_MAX.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8bfdfe0dbb36a650b7c4dec1aeae078319938a0b",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "dc4b577a083b361d25e118dc96d8281255ebe22c",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "dfdfd987f1917c84766e097a6120a1f3f1634940",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "f02334a9e378f7e07232b26dc3d2ab353339f040",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "f4013598b69457dbea350df52e52daea6faef8eb",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "1b8fb5a20508bfb0db854e01214888c761b3a911",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "c1cda72f6acec02ebd45d913bf8527ff77336ba6",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "9f29cd8a8e7901a2617c8064ce9f50fc67b97cb8",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix u16 MTU truncation in media and bearer MTU validation\n\nBoth TIPC_NL_MEDIA_SET and TIPC_NL_BEARER_SET accept user-supplied\nMTU values but only enforce a minimum bound, not a maximum. When a user\nsets the MTU to a value exceeding U16_MAX (65535), it passes validation\nbut is silently truncated when assigned to u16 fields l-\u003emtu and\nl-\u003eadvertised_mtu in tipc_link_create(). Values like 65536 (0x10000)\ntruncate to 0, causing a division by zero in tipc_link_set_queue_limits()\nwhich computes TIPC_MAX_PUBL / (l-\u003emtu / ITEM_SIZE). Other overflowing\nvalues (e.g. 65537-131071) produce small incorrect MTU values, resulting\nin link malfunction behaviors.\n\nCrash stack (triggered as unprivileged user via user namespace):\n\n tipc_link_set_queue_limits net/tipc/link.c:2531\n tipc_link_create net/tipc/link.c:520\n tipc_node_check_dest net/tipc/node.c:1279\n tipc_disc_rcv net/tipc/discover.c:252\n tipc_rcv net/tipc/node.c:2129\n tipc_udp_recv net/tipc/udp_media.c:392\n\nTwo independent paths lack the upper bound check:\n1. tipc_udp_mtu_bad() -- called from __tipc_nl_media_set() (MEDIA_SET)\n2. inline check in __tipc_nl_bearer_set() at bearer.c:1160 (BEARER_SET)\n\nFix both by rejecting MTU values above U16_MAX."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The attack begins with a local TIPC netlink command (TIPC_NL_BEARER_SET/TIPC_NL_MEDIA_SET) setting an out-of-range MTU, with the crash/corruption then triggered by locally generated discovery traffic and sendmsg() in the attacker\u0027s own network namespace.\nAC:L - The attacker fully controls both the bad MTU value and the discovery packet that creates the link, so the truncation and subsequent divide-by-zero or undersized-fragment path trigger deterministically on every attempt.\nPR:L - Both netlink ops are gated by GENL_UNS_ADMIN_PERM, i.e. CAP_NET_ADMIN in the owning user namespace, which any unprivileged user obtains via `unshare -Urn`; the commit message explicitly reports the crash reproduced as an unprivileged user through a user namespace.\nUI:N - The attacker performs every step (bearer setup, MTU configuration, packet injection, sendmsg) with no action from any other user or administrator.\nS:U - The truncated MTU corrupts only kernel state within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Truncated MTUs below the TIPC header size propagate into tipc_msg_build() as pktmax, driving negative fragment remainders and oversized copies into undersized skbs; the resulting heap corruption and adjacent-object exposure can be leveraged to read kernel memory.\nI:H - The undersized-fragment path writes INT_H_SIZE plus header bytes and then a negative-length (huge unsigned) user copy into a buffer allocated at the truncated MTU size, giving an attacker-controlled linear heap overflow suitable for control-flow hijacking.\nA:H - MTU values truncating to under 20 make tipc_link_set_queue_limits() divide by zero inside tipc_link_create(), which runs in softirq context from tipc_udp_recv()/tipc_disc_rcv(), producing a kernel oops that is typically fatal in interrupt context."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:46.091Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8bfdfe0dbb36a650b7c4dec1aeae078319938a0b"
},
{
"url": "https://git.kernel.org/stable/c/dc4b577a083b361d25e118dc96d8281255ebe22c"
},
{
"url": "https://git.kernel.org/stable/c/dfdfd987f1917c84766e097a6120a1f3f1634940"
},
{
"url": "https://git.kernel.org/stable/c/f02334a9e378f7e07232b26dc3d2ab353339f040"
},
{
"url": "https://git.kernel.org/stable/c/f4013598b69457dbea350df52e52daea6faef8eb"
},
{
"url": "https://git.kernel.org/stable/c/1b8fb5a20508bfb0db854e01214888c761b3a911"
},
{
"url": "https://git.kernel.org/stable/c/c1cda72f6acec02ebd45d913bf8527ff77336ba6"
},
{
"url": "https://git.kernel.org/stable/c/9f29cd8a8e7901a2617c8064ce9f50fc67b97cb8"
}
],
"title": "tipc: fix u16 MTU truncation in media and bearer MTU validation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68297",
"datePublished": "2026-08-10T12:02:30.721Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:46.091Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68303 (GCVE-0-2026-68303)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vc4: hvs/v3d: Fix null dereference in unbind
The hvs and v3d drivers use dev_get_drvdata(master) in their unbind
functions. Since the vc4-drm gets removed before its dependent drivers
(vc4_hvs/vc4_v3d) the vc4_hvs_unbind/vc4_v3d_unbind functions try to
get drvdata of its master and fails with a null dereference error.
Use the data pointer passed to the unbind functions directly instead of
dev_get_drvdata(master). This avoids using potentially freed memory.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_hvs.c",
"drivers/gpu/drm/vc4/vc4_v3d.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "261f0a3f0ac03248284f5116d3258f89c9642215",
"status": "affected",
"version": "c8b75bca92cbf064b9fa125fc74a85994452e935",
"versionType": "git"
},
{
"lessThan": "7dc3680b7ffe01add3e9299fde8471d2dd53a8ae",
"status": "affected",
"version": "c8b75bca92cbf064b9fa125fc74a85994452e935",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_hvs.c",
"drivers/gpu/drm/vc4/vc4_v3d.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.4"
},
{
"lessThan": "4.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: hvs/v3d: Fix null dereference in unbind\n\nThe hvs and v3d drivers use dev_get_drvdata(master) in their unbind\nfunctions. Since the vc4-drm gets removed before its dependent drivers\n(vc4_hvs/vc4_v3d) the vc4_hvs_unbind/vc4_v3d_unbind functions try to\nget drvdata of its master and fails with a null dereference error.\n\nUse the data pointer passed to the unbind functions directly instead of\ndev_get_drvdata(master). This avoids using potentially freed memory."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:55.269Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/261f0a3f0ac03248284f5116d3258f89c9642215"
},
{
"url": "https://git.kernel.org/stable/c/7dc3680b7ffe01add3e9299fde8471d2dd53a8ae"
}
],
"title": "drm/vc4: hvs/v3d: Fix null dereference in unbind",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68303",
"datePublished": "2026-08-10T12:02:37.512Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-17T05:02:55.269Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43109 (GCVE-0-2026-43109)
Vulnerability from cvelistv5
Published
2026-05-06 07:40
Modified
2026-05-17 15:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
x86: shadow stacks: proper error handling for mmap lock
김영민 reports that shstk_pop_sigframe() doesn't check for errors from
mmap_read_lock_killable(), which is a silly oversight, and also shows
that we haven't marked those functions with "__must_check", which would
have immediately caught it.
So let's fix both issues.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kernel/shstk.c",
"include/linux/mmap_lock.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c79cf42321600e931933e11f94aba8b245d4cd66",
"status": "affected",
"version": "7fad2a432cd35bbf104d2d9d426e74902f22aa95",
"versionType": "git"
},
{
"lessThan": "1a30468eff661937d978495644d2e5ebfeef5ce6",
"status": "affected",
"version": "7fad2a432cd35bbf104d2d9d426e74902f22aa95",
"versionType": "git"
},
{
"lessThan": "c64cebcc5c4f223dbcbe7dcdf74908fc092a0aa4",
"status": "affected",
"version": "7fad2a432cd35bbf104d2d9d426e74902f22aa95",
"versionType": "git"
},
{
"lessThan": "262b6d38a81d51b135db81e1f30c13d30e38feee",
"status": "affected",
"version": "7fad2a432cd35bbf104d2d9d426e74902f22aa95",
"versionType": "git"
},
{
"lessThan": "52f657e34d7b21b47434d9d8b26fa7f6778b63a0",
"status": "affected",
"version": "7fad2a432cd35bbf104d2d9d426e74902f22aa95",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kernel/shstk.c",
"include/linux/mmap_lock.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.88",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.24",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.88",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.24",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.14",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86: shadow stacks: proper error handling for mmap lock\n\n\uae40\uc601\ubbfc reports that shstk_pop_sigframe() doesn\u0027t check for errors from\nmmap_read_lock_killable(), which is a silly oversight, and also shows\nthat we haven\u0027t marked those functions with \"__must_check\", which would\nhave immediately caught it.\n\nSo let\u0027s fix both issues."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-17T15:21:37.731Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c79cf42321600e931933e11f94aba8b245d4cd66"
},
{
"url": "https://git.kernel.org/stable/c/1a30468eff661937d978495644d2e5ebfeef5ce6"
},
{
"url": "https://git.kernel.org/stable/c/c64cebcc5c4f223dbcbe7dcdf74908fc092a0aa4"
},
{
"url": "https://git.kernel.org/stable/c/262b6d38a81d51b135db81e1f30c13d30e38feee"
},
{
"url": "https://git.kernel.org/stable/c/52f657e34d7b21b47434d9d8b26fa7f6778b63a0"
}
],
"title": "x86: shadow stacks: proper error handling for mmap lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43109",
"datePublished": "2026-05-06T07:40:36.532Z",
"dateReserved": "2026-05-01T14:12:55.986Z",
"dateUpdated": "2026-05-17T15:21:37.731Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53223 (GCVE-0-2026-53223)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: guard timestamp cmsgs to real error queue skbs
skb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb
from sk_error_queue. That assumption is not true for AF_PACKET sockets:
outgoing packet taps are also delivered to packet sockets with
skb->pkt_type == PACKET_OUTGOING, but their skb->cb is owned by AF_PACKET
instead of struct sock_exterr_skb.
If such an skb is received with timestamping enabled, the generic
timestamp cmsg path can read AF_PACKET control-buffer state as
sock_exterr_skb::opt_stats. With SO_RXQ_OVFL enabled, the packet drop
counter overlaps opt_stats. An odd drop count makes the path emit
SCM_TIMESTAMPING_OPT_STATS with skb->len and skb->data. For non-linear
skbs this copies past the linear head and can trigger hardened usercopy or
disclose adjacent heap contents.
Keep skb_is_err_queue() local to net/socket.c, but make it verify that
the PACKET_OUTGOING marker is paired with the sock_rmem_free destructor
installed by sock_queue_err_skb(). AF_PACKET receive skbs use normal
receive ownership and no longer pass as error-queue skbs, while legitimate
sk_error_queue entries keep the PACKET_OUTGOING marker and sock_rmem_free
ownership.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8605330aac5a5785630aec8f64378a54891937cc Version: 8605330aac5a5785630aec8f64378a54891937cc Version: 8605330aac5a5785630aec8f64378a54891937cc Version: 8605330aac5a5785630aec8f64378a54891937cc Version: 8605330aac5a5785630aec8f64378a54891937cc Version: 8605330aac5a5785630aec8f64378a54891937cc Version: 8605330aac5a5785630aec8f64378a54891937cc Version: 8605330aac5a5785630aec8f64378a54891937cc Version: cdaf15b43bd31003220cb080bcbbd57787a2fca9 Version: 4.10.14 ≤ |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:05.974Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/sock.h",
"net/core/skbuff.c",
"net/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "24a0d548d3a765cd4558224e4f8e06e14cba26e3",
"status": "affected",
"version": "8605330aac5a5785630aec8f64378a54891937cc",
"versionType": "git"
},
{
"lessThan": "71ff5cdd5da61d0438e902aa0fd68c28bc901abe",
"status": "affected",
"version": "8605330aac5a5785630aec8f64378a54891937cc",
"versionType": "git"
},
{
"lessThan": "ad9a0374ee6d11048e1f74cd5180bad58b9848b4",
"status": "affected",
"version": "8605330aac5a5785630aec8f64378a54891937cc",
"versionType": "git"
},
{
"lessThan": "b903e9b5629ec8dd6db92174070045bf81ad7060",
"status": "affected",
"version": "8605330aac5a5785630aec8f64378a54891937cc",
"versionType": "git"
},
{
"lessThan": "e0665b2a8e90bb08bd205062c75662b502d31797",
"status": "affected",
"version": "8605330aac5a5785630aec8f64378a54891937cc",
"versionType": "git"
},
{
"lessThan": "3dde4fb941fa5649ab809f6cd3e20e0c424a4e31",
"status": "affected",
"version": "8605330aac5a5785630aec8f64378a54891937cc",
"versionType": "git"
},
{
"lessThan": "eb51a9ad3ceb01bc6c0fb608dbc856e03ee6f24a",
"status": "affected",
"version": "8605330aac5a5785630aec8f64378a54891937cc",
"versionType": "git"
},
{
"lessThan": "1ee90b77b727df903033db873c75caac5c27ec98",
"status": "affected",
"version": "8605330aac5a5785630aec8f64378a54891937cc",
"versionType": "git"
},
{
"status": "affected",
"version": "cdaf15b43bd31003220cb080bcbbd57787a2fca9",
"versionType": "git"
},
{
"lessThan": "4.11",
"status": "affected",
"version": "4.10.14",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/sock.h",
"net/core/skbuff.c",
"net/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.10.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: guard timestamp cmsgs to real error queue skbs\n\nskb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb\nfrom sk_error_queue. That assumption is not true for AF_PACKET sockets:\noutgoing packet taps are also delivered to packet sockets with\nskb-\u003epkt_type == PACKET_OUTGOING, but their skb-\u003ecb is owned by AF_PACKET\ninstead of struct sock_exterr_skb.\n\nIf such an skb is received with timestamping enabled, the generic\ntimestamp cmsg path can read AF_PACKET control-buffer state as\nsock_exterr_skb::opt_stats. With SO_RXQ_OVFL enabled, the packet drop\ncounter overlaps opt_stats. An odd drop count makes the path emit\nSCM_TIMESTAMPING_OPT_STATS with skb-\u003elen and skb-\u003edata. For non-linear\nskbs this copies past the linear head and can trigger hardened usercopy or\ndisclose adjacent heap contents.\n\nKeep skb_is_err_queue() local to net/socket.c, but make it verify that\nthe PACKET_OUTGOING marker is paired with the sock_rmem_free destructor\ninstalled by sock_queue_err_skb(). AF_PACKET receive skbs use normal\nreceive ownership and no longer pass as error-queue skbs, while legitimate\nsk_error_queue entries keep the PACKET_OUTGOING marker and sock_rmem_free\nownership."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached through local socket syscalls on an AF_PACKET socket, including setsockopt(), sending traffic that is tapped as PACKET_OUTGOING, and recvmsg(). Remote packets alone do not reach the bug without a local attacker-controlled packet socket.\nAC:L - The attacker controls the socket options, packet-socket receive queue pressure/drop count, and outgoing traffic needed to make the timestamp cmsg path run. No uncontrollable race or rare environmental condition is required for the highest-impact disclosure/crash scenario.\nPR:L - Creating AF_PACKET sockets requires CAP_NET_RAW in the governing user namespace. Because this capability can be obtained by an unprivileged local user in user/network namespaces on common deployments, this is Low rather than High.\nUI:N - No victim action is required after the attacker has local execution; the attacker can configure the socket and trigger recvmsg() themselves. The bug is not dependent on opening a file, mounting media, or other user-assisted behavior.\nS:U - The impact remains within the kernel and the local host security authority. It does not cross a hypervisor, VM, IOMMU, or other separate security scope boundary.\nC:H - The bogus SCM_TIMESTAMPING_OPT_STATS cmsg can copy skb-\u003elen bytes from skb-\u003edata even when the skb is non-linear, reading past the linear head. That can disclose adjacent kernel heap contents to userspace, which is a high confidentiality impact.\nI:N - The investigated bug is an out-of-bounds read/copy-to-user and misclassification of skb metadata, not a kernel write primitive. I found no direct modification of kernel memory or protected data.\nA:H - The same invalid copy can trigger hardened usercopy failures or kernel oops/panic on hardened deployments. The local attacker can repeat the trigger, so availability impact is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:34:15.752Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/24a0d548d3a765cd4558224e4f8e06e14cba26e3"
},
{
"url": "https://git.kernel.org/stable/c/71ff5cdd5da61d0438e902aa0fd68c28bc901abe"
},
{
"url": "https://git.kernel.org/stable/c/ad9a0374ee6d11048e1f74cd5180bad58b9848b4"
},
{
"url": "https://git.kernel.org/stable/c/b903e9b5629ec8dd6db92174070045bf81ad7060"
},
{
"url": "https://git.kernel.org/stable/c/e0665b2a8e90bb08bd205062c75662b502d31797"
},
{
"url": "https://git.kernel.org/stable/c/3dde4fb941fa5649ab809f6cd3e20e0c424a4e31"
},
{
"url": "https://git.kernel.org/stable/c/eb51a9ad3ceb01bc6c0fb608dbc856e03ee6f24a"
},
{
"url": "https://git.kernel.org/stable/c/1ee90b77b727df903033db873c75caac5c27ec98"
}
],
"title": "net: guard timestamp cmsgs to real error queue skbs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53223",
"datePublished": "2026-06-25T08:39:24.588Z",
"dateReserved": "2026-06-09T07:44:35.392Z",
"dateUpdated": "2026-09-08T08:50:05.974Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64420 (GCVE-0-2026-64420)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mfd: cros_ec: Delay dev_set_drvdata() until probe success
If ec_device_probe() fails, cros_ec_class_release releases memory for the
cros_ec_dev structure. However, because the drvdata was already set,
sub-drivers like cros_ec_typec can still retrieve the stale pointer via the
platform device. This leads to a use-after-free when cros_ec_typec attempts
to access &typec->ec->ec->dev on a device that has already been released.
Move dev_set_drvdata() to ensure that the pointer is only made available
once all initialization steps have succeeded.
sysfs: cannot create duplicate filename '/class/chromeos/cros_ec'
Call trace:
sysfs_do_create_link_sd+0x94/0xdc
sysfs_create_link+0x30/0x44
device_add_class_symlinks+0x90/0x13c
device_add+0xf0/0x50c
ec_device_probe+0x150/0x4f0
platform_probe+0xa0/0xe0
...
BUG: KASAN: invalid-access in __memcpy+0x44/0x230
Write at addr f5ffff809e2d33ac by task kworker/u32:5/125
Pointer tag: [f5], memory tag: [fe]
Tainted : [W]=WARN, [O]=OOT_MODULE
Hardware name: Google Navi unprovisioned 0x7FFFFFFF/sku0 board/sku3
Workqueue: events_unbound deferred_probe_work_func
Call trace:
__memcpy+0x44/0x230
cros_ec_check_features+0x60/0xcc [cros_ec_proto]
cros_typec_probe+0xe8/0x6e0 [cros_ec_typec]
platform_probe+0xa0/0xe0
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b Version: 1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b Version: 1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b Version: 1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b Version: 1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b Version: 1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b Version: 1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b Version: 1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/mfd/cros_ec_dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "24522713034d521ea4b5f5f36342e2b2f7e73bd6",
"status": "affected",
"version": "1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b",
"versionType": "git"
},
{
"lessThan": "f7e81dc181d9fe8ab977158042cd193e8cc12091",
"status": "affected",
"version": "1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b",
"versionType": "git"
},
{
"lessThan": "257203d83204b192d1265a916b42ca0d499bb117",
"status": "affected",
"version": "1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b",
"versionType": "git"
},
{
"lessThan": "729ae27dc2503a7c1f92da1859efb45da03e4fa0",
"status": "affected",
"version": "1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b",
"versionType": "git"
},
{
"lessThan": "ed2941e5db016a0c600b25f1972620e6e223d9fa",
"status": "affected",
"version": "1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b",
"versionType": "git"
},
{
"lessThan": "b5f41d5bf08e7b1b14fa0bd640975e6d78dc006d",
"status": "affected",
"version": "1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b",
"versionType": "git"
},
{
"lessThan": "fc030c5b116f668d4ca86dca63742ddbc98d1665",
"status": "affected",
"version": "1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b",
"versionType": "git"
},
{
"lessThan": "8b2c1d41bc36c100b38ce5ee6def246c527eaf8a",
"status": "affected",
"version": "1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/mfd/cros_ec_dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: cros_ec: Delay dev_set_drvdata() until probe success\n\nIf ec_device_probe() fails, cros_ec_class_release releases memory for the\ncros_ec_dev structure. However, because the drvdata was already set,\nsub-drivers like cros_ec_typec can still retrieve the stale pointer via the\nplatform device. This leads to a use-after-free when cros_ec_typec attempts\nto access \u0026typec-\u003eec-\u003eec-\u003edev on a device that has already been released.\nMove dev_set_drvdata() to ensure that the pointer is only made available\nonce all initialization steps have succeeded.\n\n sysfs: cannot create duplicate filename \u0027/class/chromeos/cros_ec\u0027\n Call trace:\n sysfs_do_create_link_sd+0x94/0xdc\n sysfs_create_link+0x30/0x44\n device_add_class_symlinks+0x90/0x13c\n device_add+0xf0/0x50c\n ec_device_probe+0x150/0x4f0\n platform_probe+0xa0/0xe0\n ...\n BUG: KASAN: invalid-access in __memcpy+0x44/0x230\n Write at addr f5ffff809e2d33ac by task kworker/u32:5/125\n Pointer tag: [f5], memory tag: [fe]\n Tainted : [W]=WARN, [O]=OOT_MODULE\n Hardware name: Google Navi unprovisioned 0x7FFFFFFF/sku0 board/sku3\n Workqueue: events_unbound deferred_probe_work_func\n Call trace:\n __memcpy+0x44/0x230\n cros_ec_check_features+0x60/0xcc [cros_ec_proto]\n cros_typec_probe+0xe8/0x6e0 [cros_ec_typec]\n platform_probe+0xa0/0xe0"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF occurs in local platform-device probe work for an internally connected ChromeOS EC and its Type-C child, with no network or USB-peer entry point. Exploitation would require local heap shaping or probe-timing influence.\nAC:H - Exploitation requires EC probe failure, such as a duplicate class name, while the Type-C probe concurrently captures the pointer before driver-core cleanup, followed by useful slab reuse. An unprivileged attacker cannot directly control both sides of this race.\nPR:L - On a device whose firmware topology already produces the failure, no capability check protects the automatic probe path, and an unprivileged local process can attempt heap grooming and timing manipulation. User namespaces cannot directly create or rebind these platform devices, but real-root privileges are not required for that exploitation role.\nUI:N - The kernel automatically enumerates and probes both devices through platform-bus workqueues. No victim action such as opening a file, mounting something, or attaching a peripheral is required.\nS:U - The vulnerable driver and the affected kernel memory share the same operating-system security authority. This is not a VM escape, IOMMU bypass, or other scope-changing boundary crossing.\nC:H - The freed object contains kernel pointers and may be replaced by another kmalloc object before stale accesses occur. Exploitable UAF reuse can provide kernel-memory disclosure, so confidentiality impact is High.\nI:H - cros_ec_check_features() can copy an eight-byte EC feature response into the freed object, corrupting any replacement object occupying that slab slot. Heap shaping could turn this write-after-free into control-flow corruption or kernel code execution.\nA:H - The observed write-after-free occurs in a kernel workqueue and can produce an oops or panic. It can also disrupt device initialization or repeatedly prevent a vulnerable system from completing a reliable boot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:19.958Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/24522713034d521ea4b5f5f36342e2b2f7e73bd6"
},
{
"url": "https://git.kernel.org/stable/c/f7e81dc181d9fe8ab977158042cd193e8cc12091"
},
{
"url": "https://git.kernel.org/stable/c/257203d83204b192d1265a916b42ca0d499bb117"
},
{
"url": "https://git.kernel.org/stable/c/729ae27dc2503a7c1f92da1859efb45da03e4fa0"
},
{
"url": "https://git.kernel.org/stable/c/ed2941e5db016a0c600b25f1972620e6e223d9fa"
},
{
"url": "https://git.kernel.org/stable/c/b5f41d5bf08e7b1b14fa0bd640975e6d78dc006d"
},
{
"url": "https://git.kernel.org/stable/c/fc030c5b116f668d4ca86dca63742ddbc98d1665"
},
{
"url": "https://git.kernel.org/stable/c/8b2c1d41bc36c100b38ce5ee6def246c527eaf8a"
}
],
"title": "mfd: cros_ec: Delay dev_set_drvdata() until probe success",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64420",
"datePublished": "2026-07-25T08:50:59.115Z",
"dateReserved": "2026-07-19T15:36:31.786Z",
"dateUpdated": "2026-08-17T04:55:19.958Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63923 (GCVE-0-2026-63923)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify
rvu_mbox_handler_rep_event_notify() in drivers/net/ethernet/marvell/
octeontx2/af/rvu_rep.c queues a sender-controlled REP_EVENT_NOTIFY
request body verbatim, and rvu_rep_up_notify() then forwards
event->pcifunc (the nested body field, distinct from the
AF-normalised header pcifunc) into rvu_get_pfvf(), rvu_get_pf() and
the AF->PF mailbox device index without any bounds check.
A VF attached to a PF that has been put into switchdev
representor mode reaches this path: the VF mailbox handler
otx2_pfvf_mbox_handler() forwards every message id including
MBOX_MSG_REP_EVENT_NOTIFY to AF without an allowlist, and the AF
dispatcher rewrites only msg->pcifunc, leaving struct
rep_event::pcifunc attacker-controlled. The sibling
rvu_mbox_handler_esw_cfg() refuses requests whose header pcifunc
is not rvu->rep_pcifunc; this handler has no equivalent gate.
An out-of-range body pcifunc selects an &rvu->pf[]/&rvu->hwvf[]
element past the allocated array and, for RVU_EVENT_MAC_ADDR_CHANGE,
turns into a six-byte attacker-chosen OOB ether_addr_copy() target
inside the queued worker; KASAN reports a slab-out-of-bounds write
in rvu_rep_wq_handler.
Reject malformed requests at the handler entry by gating on
is_pf_func_valid(), which is already the canonical PF/VF range check
in this driver; expose it via rvu.h so callers in rvu_rep.c can use
it instead of open-coding the same range arithmetic.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/af/rvu.c",
"drivers/net/ethernet/marvell/octeontx2/af/rvu.h",
"drivers/net/ethernet/marvell/octeontx2/af/rvu_rep.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4467fa514482bbce82f73788943c815f3d126ab3",
"status": "affected",
"version": "b8fea84a0468404fe3b3327ad54d583950be9dec",
"versionType": "git"
},
{
"lessThan": "68be0260e2a02ff9b18a8678d5f8d1715fa20138",
"status": "affected",
"version": "b8fea84a0468404fe3b3327ad54d583950be9dec",
"versionType": "git"
},
{
"lessThan": "2156a29aecfffa2eb7c558255690084efbe9f3b0",
"status": "affected",
"version": "b8fea84a0468404fe3b3327ad54d583950be9dec",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/af/rvu.c",
"drivers/net/ethernet/marvell/octeontx2/af/rvu.h",
"drivers/net/ethernet/marvell/octeontx2/af/rvu_rep.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify\n\nrvu_mbox_handler_rep_event_notify() in drivers/net/ethernet/marvell/\nocteontx2/af/rvu_rep.c queues a sender-controlled REP_EVENT_NOTIFY\nrequest body verbatim, and rvu_rep_up_notify() then forwards\nevent-\u003epcifunc (the nested body field, distinct from the\nAF-normalised header pcifunc) into rvu_get_pfvf(), rvu_get_pf() and\nthe AF-\u003ePF mailbox device index without any bounds check.\n\nA VF attached to a PF that has been put into switchdev\nrepresentor mode reaches this path: the VF mailbox handler\notx2_pfvf_mbox_handler() forwards every message id including\nMBOX_MSG_REP_EVENT_NOTIFY to AF without an allowlist, and the AF\ndispatcher rewrites only msg-\u003epcifunc, leaving struct\nrep_event::pcifunc attacker-controlled. The sibling\nrvu_mbox_handler_esw_cfg() refuses requests whose header pcifunc\nis not rvu-\u003erep_pcifunc; this handler has no equivalent gate.\n\nAn out-of-range body pcifunc selects an \u0026rvu-\u003epf[]/\u0026rvu-\u003ehwvf[]\nelement past the allocated array and, for RVU_EVENT_MAC_ADDR_CHANGE,\nturns into a six-byte attacker-chosen OOB ether_addr_copy() target\ninside the queued worker; KASAN reports a slab-out-of-bounds write\nin rvu_rep_wq_handler.\n\nReject malformed requests at the handler entry by gating on\nis_pf_func_valid(), which is already the canonical PF/VF range check\nin this driver; expose it via rvu.h so callers in rvu_rep.c can use\nit instead of open-coding the same range arithmetic."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the OcteonTX2 VF\u2192PF\u2192AF PCI mailbox control path, not through packet reception or any network protocol. Exploitation requires local access to an assigned SR-IOV VF device on a Marvell OCTEONTX2/CN9K/CN10K NIC.\nAC:L - Once a VF is assigned in switchdev representor mode, the attacker fully controls the malicious `rep_event` body fields (including `pcifunc`, event flags, and MAC data) and can trigger the path deterministically via repeated mailbox messages without races or uncontrollable timing.\nPR:L - Exploitation requires control of an assigned VF (typical cloud/tenant VM or container with SR-IOV passthrough), not host root; the PF mailbox forwarder passes every VF message ID including `MBOX_MSG_REP_EVENT_NOTIFY` to AF without an allowlist or trusted-VF gate on this path.\nUI:N - No victim user action (mounting, clicking, opening files) is required; the attacker triggers the vulnerable handler directly by sending a crafted mailbox message from their VF.\nS:C - In the highest-impact deployment (SR-IOV VF assigned to an untrusted VM/container tenant), corruption occurs in the host AF driver, crossing the guest/host security boundary analogous to device-mediated VM escape rather than a same-authority local privilege change.\nC:H - An out-of-range body `pcifunc` makes `rvu_get_pfvf()` return a pointer past the allocated `rvu-\u003epf[]`/`rvu-\u003ehwvf[]` arrays, and the slab-out-of-bounds write corrupts adjacent kernel heap memory in a way that can be leveraged for arbitrary kernel memory disclosure.\nI:H - For `RVU_EVENT_MAC_ADDR_CHANGE`, the worker performs a six-byte attacker-chosen `ether_addr_copy()` to an out-of-bounds `rvu_pfvf` target, constituting an exploitable out-of-bounds kernel heap write suitable for control-flow or privilege-escalation primitives.\nA:H - The out-of-bounds heap write in `rvu_rep_wq_handler` can trigger a kernel oops/panic (as confirmed by KASAN slab-out-of-bounds reports) and can be repeated on demand to deny service to the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:18.035Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4467fa514482bbce82f73788943c815f3d126ab3"
},
{
"url": "https://git.kernel.org/stable/c/68be0260e2a02ff9b18a8678d5f8d1715fa20138"
},
{
"url": "https://git.kernel.org/stable/c/2156a29aecfffa2eb7c558255690084efbe9f3b0"
}
],
"title": "octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63923",
"datePublished": "2026-07-19T14:55:24.985Z",
"dateReserved": "2026-07-19T07:54:57.021Z",
"dateUpdated": "2026-08-05T12:37:18.035Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64144 (GCVE-0-2026-64144)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btmtk: fix urb->setup_packet leak in error paths
The setup_packet of control urb is not freed if usb_submit_urb fails or
the submitted urb is killed. Add free in these two paths.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btmtk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2a1905730e0c771b999906a7b509722f795563c6",
"status": "affected",
"version": "a1c49c434e15050b5dafe3b6f5cc732d4f02d657",
"versionType": "git"
},
{
"lessThan": "68c027c2003b0a8a1439d0301c59c6fd1eb3b844",
"status": "affected",
"version": "a1c49c434e15050b5dafe3b6f5cc732d4f02d657",
"versionType": "git"
},
{
"lessThan": "a0f5268c77eb73f84ba7c210ddfc54b1c73ff80c",
"status": "affected",
"version": "a1c49c434e15050b5dafe3b6f5cc732d4f02d657",
"versionType": "git"
},
{
"lessThan": "0d2572bafea33c7cd1d77c6a25f25ff31a432482",
"status": "affected",
"version": "a1c49c434e15050b5dafe3b6f5cc732d4f02d657",
"versionType": "git"
},
{
"lessThan": "dd1dda6b8d6e1f4376a5b3055a04f0ecbdb4d6bd",
"status": "affected",
"version": "a1c49c434e15050b5dafe3b6f5cc732d4f02d657",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btmtk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtk: fix urb-\u003esetup_packet leak in error paths\n\nThe setup_packet of control urb is not freed if usb_submit_urb fails or\nthe submitted urb is killed. Add free in these two paths."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:36.041Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2a1905730e0c771b999906a7b509722f795563c6"
},
{
"url": "https://git.kernel.org/stable/c/68c027c2003b0a8a1439d0301c59c6fd1eb3b844"
},
{
"url": "https://git.kernel.org/stable/c/a0f5268c77eb73f84ba7c210ddfc54b1c73ff80c"
},
{
"url": "https://git.kernel.org/stable/c/0d2572bafea33c7cd1d77c6a25f25ff31a432482"
},
{
"url": "https://git.kernel.org/stable/c/dd1dda6b8d6e1f4376a5b3055a04f0ecbdb4d6bd"
}
],
"title": "Bluetooth: btmtk: fix urb-\u003esetup_packet leak in error paths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64144",
"datePublished": "2026-07-19T15:40:36.041Z",
"dateReserved": "2026-07-19T07:54:57.037Z",
"dateUpdated": "2026-07-19T15:40:36.041Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68327 (GCVE-0-2026-68327)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wan: wanxl: Only reset hardware after BAR mapping
wanxl_pci_init_one() stores the freshly allocated card in driver data
before the PLX BAR is mapped. Several early probe failures then unwind
through wanxl_pci_remove_one(), including failure to allocate the coherent
status area or to restore the DMA mask.
wanxl_pci_remove_one() unconditionally calls wanxl_reset(), and
wanxl_reset() dereferences card->plx. On those early failures card->plx
is still NULL, so the error path can dereference a NULL MMIO pointer.
Only issue the hardware reset once the BAR mapping exists. The remaining
cleanup in wanxl_pci_remove_one() already checks whether later resources
were allocated.
This issue was found by a static analysis checker and confirmed by
manual source review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wan/wanxl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ef394eeb9d5ec6db8d979eec6d27f56c2ebc6523",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3d9617d856ebddcdddbab0ce877c397420f59f55",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "897e289db1e4d00ca6419cfe733c646492147270",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f4834132773f15ffb255127499c8443947fa7d0f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b9e2ff70e96acf83693b27987e0390bad9f83efa",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "59cbe6cfa0fa23c192351cc284e30707309f6741",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2fe22d58b3797d741570f9873b26653fd511576c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "91957b89da995607cb654b1f9a3c126ddbaee10f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wan/wanxl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwan: wanxl: Only reset hardware after BAR mapping\n\nwanxl_pci_init_one() stores the freshly allocated card in driver data\nbefore the PLX BAR is mapped. Several early probe failures then unwind\nthrough wanxl_pci_remove_one(), including failure to allocate the coherent\nstatus area or to restore the DMA mask.\n\nwanxl_pci_remove_one() unconditionally calls wanxl_reset(), and\nwanxl_reset() dereferences card-\u003eplx. On those early failures card-\u003eplx\nis still NULL, so the error path can dereference a NULL MMIO pointer.\n\nOnly issue the hardware reset once the BAR mapping exists. The remaining\ncleanup in wanxl_pci_remove_one() already checks whether later resources\nwere allocated.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:23.256Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ef394eeb9d5ec6db8d979eec6d27f56c2ebc6523"
},
{
"url": "https://git.kernel.org/stable/c/3d9617d856ebddcdddbab0ce877c397420f59f55"
},
{
"url": "https://git.kernel.org/stable/c/897e289db1e4d00ca6419cfe733c646492147270"
},
{
"url": "https://git.kernel.org/stable/c/f4834132773f15ffb255127499c8443947fa7d0f"
},
{
"url": "https://git.kernel.org/stable/c/b9e2ff70e96acf83693b27987e0390bad9f83efa"
},
{
"url": "https://git.kernel.org/stable/c/59cbe6cfa0fa23c192351cc284e30707309f6741"
},
{
"url": "https://git.kernel.org/stable/c/2fe22d58b3797d741570f9873b26653fd511576c"
},
{
"url": "https://git.kernel.org/stable/c/91957b89da995607cb654b1f9a3c126ddbaee10f"
}
],
"title": "wan: wanxl: Only reset hardware after BAR mapping",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68327",
"datePublished": "2026-08-10T12:03:03.398Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:23.256Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74556 (GCVE-0-2026-74556)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
iscsi_tcp_hdr_dissect() receives the data segment of several PDU types
into the fixed-size conn->data buffer, which is allocated for
ISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes. For the LOGIN_RSP, TEXT_RSP,
REJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU
whose DataSegmentLength exceeds that buffer.
The SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its
data segment (sense/response data) into conn->data via
iscsi_tcp_data_recv_prep(), but it does so without the same check. The
only upstream bound on in.datalen is conn->max_recv_dlength, the
initiator's advertised MaxRecvDataSegmentLength, which is commonly
negotiated well above 8192 (open-iscsi defaults to 262144). A target
that returns a SCSI Response with a DataSegmentLength between 8193 and
max_recv_dlength therefore overflows the 8192-byte conn->data buffer.
Once the same bound applies, ISCSI_OP_SCSI_CMD_RSP is handled exactly
like those responses: bound the data segment, receive it into conn->data
when present, and otherwise complete the PDU with no data. Fold the
opcode into that case group rather than duplicating the check.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/scsi/libiscsi_tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a51812842084fd390590ab8dc0431f10c73ddc56",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "a8f94cc9f0e5759252551be3a172960c57f21f54",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "f1a3a51fc5dba0e99532379665069f1700da6b44",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "c97b5265cc47775f77fd2a23d6bde0426997b233",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "084af0253673425ce2ae62e3c7f74f0dd023711b",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "72815741715bd41556dac5eeb068bf0f8af06ee7",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "b0aa3e8e2ab4ca92adb28a3ef41873b3363b8676",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "c1dea15f819cded9b3faf58f8bec72323568b6e6",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/scsi/libiscsi_tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.29"
},
{
"lessThan": "2.6.29",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.29",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer\n\niscsi_tcp_hdr_dissect() receives the data segment of several PDU types\ninto the fixed-size conn-\u003edata buffer, which is allocated for\nISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes. For the LOGIN_RSP, TEXT_RSP,\nREJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU\nwhose DataSegmentLength exceeds that buffer.\n\nThe SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its\ndata segment (sense/response data) into conn-\u003edata via\niscsi_tcp_data_recv_prep(), but it does so without the same check. The\nonly upstream bound on in.datalen is conn-\u003emax_recv_dlength, the\ninitiator\u0027s advertised MaxRecvDataSegmentLength, which is commonly\nnegotiated well above 8192 (open-iscsi defaults to 262144). A target\nthat returns a SCSI Response with a DataSegmentLength between 8193 and\nmax_recv_dlength therefore overflows the 8192-byte conn-\u003edata buffer.\n\nOnce the same bound applies, ISCSI_OP_SCSI_CMD_RSP is handled exactly\nlike those responses: bound the data segment, receive it into conn-\u003edata\nwhen present, and otherwise complete the PDU with no data. Fold the\nopcode into that case group rather than duplicating the check."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious or compromised iSCSI target delivers crafted SCSI Command Response PDUs over the established TCP iSCSI session; reception flows through iscsi_sw_tcp_recv/iscsi_tcp_recv_skb into iscsi_tcp_hdr_dissect without local access.\nAC:L - The attacker controls the target and can set DataSegmentLength between 8193 and negotiated max_recv_dlength (open-iscsi commonly 262144) on SCSI_CMD_RSP for any outstanding command ITT; no races or victim-specific heap layout are required.\nPR:N - No privileges on the victim host are needed; a remote attacker acting as or MITMing the iSCSI target sends malicious responses after session login, independent of victim user accounts or capabilities.\nUI:N - On systems with persistent iSCSI sessions (cloud VMs, SAN-boot hosts, Kubernetes iSCSI volumes), exploitation triggers automatically during normal SCSI I/O when command responses are received; no victim action is needed at attack time.\nS:U - Heap corruption is confined to the kernel iSCSI initiator on the affected host; successful exploitation yields kernel compromise or DoS within the same security authority, not a VM escape or cross-boundary scope change.\nC:H - iscsi_tcp_segment_recv memcpy writes up to max_recv_dlength bytes into an 8192-byte conn-\u003edata buffer, causing a large heap overflow whose controlled corruption can be leveraged for arbitrary kernel memory disclosure.\nI:H - Attacker-controlled response data is copied past the fixed conn-\u003edata allocation via iscsi_tcp_data_recv_prep/iscsi_segment_init_linear, enabling heap metadata/object corruption exploitable for arbitrary kernel write and privilege escalation.\nA:H - Overflowing the conn-\u003edata heap buffer can immediately corrupt adjacent kernel allocations and cause oops/panic; a malicious target can repeatedly trigger this on active sessions to deny storage availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:57.393Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a51812842084fd390590ab8dc0431f10c73ddc56"
},
{
"url": "https://git.kernel.org/stable/c/a8f94cc9f0e5759252551be3a172960c57f21f54"
},
{
"url": "https://git.kernel.org/stable/c/f1a3a51fc5dba0e99532379665069f1700da6b44"
},
{
"url": "https://git.kernel.org/stable/c/c97b5265cc47775f77fd2a23d6bde0426997b233"
},
{
"url": "https://git.kernel.org/stable/c/084af0253673425ce2ae62e3c7f74f0dd023711b"
},
{
"url": "https://git.kernel.org/stable/c/72815741715bd41556dac5eeb068bf0f8af06ee7"
},
{
"url": "https://git.kernel.org/stable/c/b0aa3e8e2ab4ca92adb28a3ef41873b3363b8676"
},
{
"url": "https://git.kernel.org/stable/c/c1dea15f819cded9b3faf58f8bec72323568b6e6"
}
],
"title": "scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74556",
"datePublished": "2026-08-15T12:28:01.359Z",
"dateReserved": "2026-08-15T05:44:03.916Z",
"dateUpdated": "2026-08-19T16:38:57.393Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63926 (GCVE-0-2026-63926)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: sockmap: fix tail fragment offset in bpf_msg_push_data
When bpf_msg_push_data() inserts data in the middle of a scatterlist
entry, it splits the original entry into a left fragment and a right
fragment.
The right fragment offset is page-local, but the code advances it with
`start`, which is the message-global insertion point. For inserts into a
non-first SG entry, this over-advances the offset and leaves the split
layout inconsistent.
Advance the right fragment offset by the fragment-local delta,
`start - offset`, which matches the length removed from the front of the
original entry.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f14609d8146707452e0822f3c8154674ce677251",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "d81b323af2dcee47573907ccb89c0df9b45cb2e2",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "aeb95146848d12206e1b2cfacd4f40e21ce81d94",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "96b72672ce849a1402730238e64d9b20bf06a96d",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "3075c21d2d76c0067f4a382765b43d6cc10470f1",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "5e19028667963fb371ebb00cecc2a473ef92056b",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "63f64a510c7917658ddf4d073ece73914ee25346",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "f72eed9b84fb771019a955908132410a9ba9ea3f",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: sockmap: fix tail fragment offset in bpf_msg_push_data\n\nWhen bpf_msg_push_data() inserts data in the middle of a scatterlist\nentry, it splits the original entry into a left fragment and a right\nfragment.\n\nThe right fragment offset is page-local, but the code advances it with\n`start`, which is the message-global insertion point. For inserts into a\nnon-first SG entry, this over-advances the offset and leaves the split\nlayout inconsistent.\n\nAdvance the right fragment offset by the fragment-local delta,\n`start - offset`, which matches the length removed from the front of the\noriginal entry."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the BPF sk_msg/sockmap send path (sendmsg \u2192 tcp_bpf_send_verdict \u2192 sk_psock_msg_verdict \u2192 bpf_msg_push_data), which requires local syscalls and BPF setup; per kernel CNA guidance, BPF/sockmap issues are scored as Local rather than Network.\nAC:L - An attacker who can load a sk_msg BPF program fully controls the insertion offset and can reliably build multi-fragment scatterlist messages (e.g., via large sendmsg/sendfile) to hit the non-first-entry split path; a public PoC demonstrates deterministic triggering without races or external victim state.\nPR:N - While direct exploitation requires CAP_NET_ADMIN+CAP_BPF to load sockmap/sk_msg programs (obtainable as PR:L via user namespaces), the highest-impact reasonable scenario is an unauthenticated remote client triggering a pre-deployed internet-facing kTLS/sockmap proxy whose sk_msg BPF calls bpf_msg_push_data during outbound processing, requiring no privileges on the victim host.\nUI:N - Exploitation requires no victim user interaction beyond normal network I/O to a service that already runs sockmap/sk_msg BPF; the attacker does not need the victim to mount filesystems, open files, or take other deliberate actions.\nS:U - Impact is kernel heap memory corruption within the same kernel security authority (privilege escalation, memory disclosure, or crash), not a cross-boundary escape such as VM guest-to-host or IOMMU bypass.\nC:H - The incorrect rsge.offset over-advances the page-local offset for non-first scatterlist fragments, causing out-of-bounds reads when subsequent helpers (e.g., bpf_msg_pull_data via sg_virt/memcpy) or the TCP send path consume the corrupted entry; the public PoC shows a 32,752-byte OOB read/UAF.\nI:H - Scatterlist metadata corruption produces inconsistent length/offset pairs that can drive out-of-bounds kernel memory access and is a standard heap corruption primitive potentially weaponizable for arbitrary write or control-flow hijack, not merely a bounded data error.\nA:H - Corrupted scatterlist state can cause kernel oops/panic from out-of-bounds page access (as shown in the PoC KASAN trace) or destabilize subsequent sk_msg/TCP/kTLS transmit processing, resulting in denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:21.277Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f14609d8146707452e0822f3c8154674ce677251"
},
{
"url": "https://git.kernel.org/stable/c/d81b323af2dcee47573907ccb89c0df9b45cb2e2"
},
{
"url": "https://git.kernel.org/stable/c/aeb95146848d12206e1b2cfacd4f40e21ce81d94"
},
{
"url": "https://git.kernel.org/stable/c/96b72672ce849a1402730238e64d9b20bf06a96d"
},
{
"url": "https://git.kernel.org/stable/c/3075c21d2d76c0067f4a382765b43d6cc10470f1"
},
{
"url": "https://git.kernel.org/stable/c/5e19028667963fb371ebb00cecc2a473ef92056b"
},
{
"url": "https://git.kernel.org/stable/c/63f64a510c7917658ddf4d073ece73914ee25346"
},
{
"url": "https://git.kernel.org/stable/c/f72eed9b84fb771019a955908132410a9ba9ea3f"
}
],
"title": "bpf: sockmap: fix tail fragment offset in bpf_msg_push_data",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63926",
"datePublished": "2026-07-19T14:55:27.154Z",
"dateReserved": "2026-07-19T07:54:57.021Z",
"dateUpdated": "2026-08-05T12:37:21.277Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63996 (GCVE-0-2026-63996)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ethtool: cmis: require exact CDB reply length
Malicious SFP module could respond with rpl_len longer than
what cmis_cdb_process_reply() expected, leading to OOB writes.
Malicious HW is a bit theoretical but some modules may just
be buggy and/or the reads may occasionally get corrupted,
so let's protect the kernel.
The existing check protects from short replies. We need to
protect from long ones, too. All callers that pass a non-zero
rpl_exp_len cast the reply payload to a fixed-layout struct
and read fields at fixed offsets, with no version negotiation
or short-reply handling:
- cmis_cdb_validate_password()
- cmis_cdb_module_features_get()
- cmis_fw_update_fw_mng_features_get()
so let's assume that responses longer than expected do not
have to be handled gracefully here. Add a warning message
to make the debug easier in case my understanding is wrong...
Note that page_data->length (argument of kmalloc) comes from
last arg to ethtool_cmis_page_init() which is rpl_exp_len.
Note2 that AIs also like to point out overflows in args->req.payload
itself (which is a fixed-size 120 B buffer, on the stack),
but callers should be reading structs defined by the standard,
so protecting from requests for more data than max seem like
defensive programming.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ethtool/cmis_cdb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2f818cc98fd2c63a08239cb48995f6c3bfe9d9b3",
"status": "affected",
"version": "a39c84d796254e6b1662ca0c46dbc313379e9291",
"versionType": "git"
},
{
"lessThan": "4d42fb88ec61f2e98c33a9e3a2de371d5edbc6b1",
"status": "affected",
"version": "a39c84d796254e6b1662ca0c46dbc313379e9291",
"versionType": "git"
},
{
"lessThan": "eb5dcd740cd7fa27bc2caeff2d28ef28e93ff4d3",
"status": "affected",
"version": "a39c84d796254e6b1662ca0c46dbc313379e9291",
"versionType": "git"
},
{
"lessThan": "6c3f999a9d1338c6c89a9ff4549eafe72bc2e7b1",
"status": "affected",
"version": "a39c84d796254e6b1662ca0c46dbc313379e9291",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ethtool/cmis_cdb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: cmis: require exact CDB reply length\n\nMalicious SFP module could respond with rpl_len longer than\nwhat cmis_cdb_process_reply() expected, leading to OOB writes.\nMalicious HW is a bit theoretical but some modules may just\nbe buggy and/or the reads may occasionally get corrupted,\nso let\u0027s protect the kernel.\n\nThe existing check protects from short replies. We need to\nprotect from long ones, too. All callers that pass a non-zero\nrpl_exp_len cast the reply payload to a fixed-layout struct\nand read fields at fixed offsets, with no version negotiation\nor short-reply handling:\n\n - cmis_cdb_validate_password()\n - cmis_cdb_module_features_get()\n - cmis_fw_update_fw_mng_features_get()\n\nso let\u0027s assume that responses longer than expected do not\nhave to be handled gracefully here. Add a warning message\nto make the debug easier in case my understanding is wrong...\n\nNote that page_data-\u003elength (argument of kmalloc) comes from\nlast arg to ethtool_cmis_page_init() which is rpl_exp_len.\n\nNote2 that AIs also like to point out overflows in args-\u003ereq.payload\nitself (which is a fixed-size 120 B buffer, on the stack),\nbut callers should be reading structs defined by the standard,\nso protecting from requests for more data than max seem like\ndefensive programming."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only via the local ethtool genetlink firmware-flash path (ETHTOOL_MSG_MODULE_FW_FLASH_ACT), not from remote network input; a malicious transceiver supplies the malformed CDB reply once that local ioctl-like operation is invoked.\nAC:L - A malicious CMIS module can reliably set rpl_len up to 255 on CDB replies; no race or uncontrollable memory layout is required, and an attacker with CAP_NET_ADMIN can bring the netdev down and initiate flashing deterministically.\nPR:L - Triggering module firmware flash requires CAP_NET_ADMIN, which is enforced via GENL_UNS_ADMIN_PERM/netlink_ns_capable and is obtainable by unprivileged users inside a user namespace (unshare -Urn), not only by init-namespace root.\nUI:N - Exploitation does not require a separate victim user action beyond the attacker (or compromised local process with CAP_NET_ADMIN) issuing the ethtool module firmware-flash command; no interactive victim steps are needed.\nS:U - Impact is kernel stack corruption and potential privilege escalation or denial of service within the same kernel security boundary; this is not a VM escape, sandbox escape, or cross-authority boundary crossing.\nC:H - The out-of-bounds stack write corrupts adjacent kernel stack memory and can be leveraged for arbitrary kernel memory disclosure; related CMIS ethtool bugs in the same path have already caused demonstrable stack corruption.\nI:H - memcpy() can write up to 135 bytes past the 120-byte payload buffer on the kernel stack, enabling control-data corruption and potential arbitrary kernel code execution, not merely a bounded modification.\nA:H - Stack corruption in this CMIS firmware-flash workqueue path can trigger kernel oops/panic (as seen in the related CVE-2025-37791 stack-protector failure in the same call chain) or hang the affected system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:00.530Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2f818cc98fd2c63a08239cb48995f6c3bfe9d9b3"
},
{
"url": "https://git.kernel.org/stable/c/4d42fb88ec61f2e98c33a9e3a2de371d5edbc6b1"
},
{
"url": "https://git.kernel.org/stable/c/eb5dcd740cd7fa27bc2caeff2d28ef28e93ff4d3"
},
{
"url": "https://git.kernel.org/stable/c/6c3f999a9d1338c6c89a9ff4549eafe72bc2e7b1"
}
],
"title": "ethtool: cmis: require exact CDB reply length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63996",
"datePublished": "2026-07-19T14:56:15.256Z",
"dateReserved": "2026-07-19T07:54:57.026Z",
"dateUpdated": "2026-08-05T12:38:00.530Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68352 (GCVE-0-2026-68352)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len
fields in ath6kl_wmi_connect_event_rx() are not validated against the
buffer length. Their sum (up to 765) can exceed the actual WMI event
data, causing out-of-bounds reads during IE parsing and state corruption
of wmi->is_wmm_enabled.
Add a check that the total IE length fits within the buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7cae33e3e09a080db96e3a8980c2c8d288318320",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "1eeed9efc9a40e0635e910c37fee86543041b4e1",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "a38d7d6376b295245b53bc98b7ca682c027abaf7",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "d70c0a850c21b57a6f46ce363860203389bbeaa6",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "33b5342d2080657054ddf89ef1199b426a37dae8",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "94e1bfcefe8264a207c2fda2febb954e70a34b42",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "6b47b29730de3232b919d8362749f6814c5f2a33",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB read from firmware IE lengths in connect event\n\nThe firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len\nfields in ath6kl_wmi_connect_event_rx() are not validated against the\nbuffer length. Their sum (up to 765) can exceed the actual WMI event\ndata, causing out-of-bounds reads during IE parsing and state corruption\nof wmi-\u003eis_wmm_enabled.\n\nAdd a check that the total IE length fits within the buffer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The malformed connect event is produced from the 802.11 association exchange with the peer AP, so a rogue/evil-twin AP or frame-injecting attacker within radio range of the ath6kl station supplies the oversized IE lengths; no local access is needed but the attacker must share the wireless link layer.\nAC:L - The attacker controls the beacon/assoc-request/assoc-response IE content and declared lengths and can force repeated (re)association or roaming with deauth frames until the connect event is emitted, so triggering is reliable and repeatable with no conditions outside the attacker\u0027s control.\nPR:N - No credentials or local account are required; the connect event is processed as part of establishing the link with an attacker-controlled AP, before any user-level authorization on the victim system is involved.\nUI:N - No victim action is needed \u2014 a station with a saved profile auto-associates, and the SME_CONNECTED roam path (cfg80211_roamed) processes the same event while the station is already connected, entirely attacker-driven.\nS:U - The out-of-bounds read, the corrupted wmi-\u003eis_wmm_enabled state and any resulting crash are all confined to the kernel of the affected host; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Up to 765 bytes of adjacent kernel heap past the WMI event buffer are read and then exported to userspace: copied into the cfg80211 BSS IE cache (readable via unprivileged nl80211 GET_SCAN) and delivered as req_ie/resp_ie in cfg80211_connect_result()/cfg80211_roamed(), a repeatable kernel memory disclosure rather than a few stray bytes.\nI:L - There is no out-of-bounds write, but out-of-bounds bytes drive driver state: wmi-\u003eis_wmm_enabled is set from memory beyond the buffer and bogus IE data is inserted into the cfg80211 BSS cache, giving limited attacker-influenced modification of kernel-held data.\nA:H - The IE walk dereferences up to 765 bytes past the received skb and can run off the end of the allocation into unmapped memory (or trip KASAN/DEBUG_PAGEALLOC), producing a kernel oops/panic that the adjacent attacker can retrigger at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:55.758Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7cae33e3e09a080db96e3a8980c2c8d288318320"
},
{
"url": "https://git.kernel.org/stable/c/1eeed9efc9a40e0635e910c37fee86543041b4e1"
},
{
"url": "https://git.kernel.org/stable/c/a38d7d6376b295245b53bc98b7ca682c027abaf7"
},
{
"url": "https://git.kernel.org/stable/c/1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e"
},
{
"url": "https://git.kernel.org/stable/c/d70c0a850c21b57a6f46ce363860203389bbeaa6"
},
{
"url": "https://git.kernel.org/stable/c/33b5342d2080657054ddf89ef1199b426a37dae8"
},
{
"url": "https://git.kernel.org/stable/c/94e1bfcefe8264a207c2fda2febb954e70a34b42"
},
{
"url": "https://git.kernel.org/stable/c/6b47b29730de3232b919d8362749f6814c5f2a33"
}
],
"title": "wifi: ath6kl: fix OOB read from firmware IE lengths in connect event",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68352",
"datePublished": "2026-08-10T12:03:29.304Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:55.758Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64471 (GCVE-0-2026-64471)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btusb: fix use-after-free on registration failure
Make sure to release the sibling interfaces in case controller
registration fails to avoid use-after-free and double-free when they are
eventually disconnected.
This issue was reported by Sashiko while reviewing a fix for a wakeup
source leak in the btusb probe errors paths.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9bfa35fe422c74882e27cc54450a5f76c96aad68 Version: 9bfa35fe422c74882e27cc54450a5f76c96aad68 Version: 9bfa35fe422c74882e27cc54450a5f76c96aad68 Version: 9bfa35fe422c74882e27cc54450a5f76c96aad68 Version: 9bfa35fe422c74882e27cc54450a5f76c96aad68 Version: 9bfa35fe422c74882e27cc54450a5f76c96aad68 Version: 9bfa35fe422c74882e27cc54450a5f76c96aad68 Version: 9bfa35fe422c74882e27cc54450a5f76c96aad68 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e09ac7d0c6859a360bf36e7104aef03f88184e0b",
"status": "affected",
"version": "9bfa35fe422c74882e27cc54450a5f76c96aad68",
"versionType": "git"
},
{
"lessThan": "468fcdfaeb937163dd250773a9fed17ab1fa203c",
"status": "affected",
"version": "9bfa35fe422c74882e27cc54450a5f76c96aad68",
"versionType": "git"
},
{
"lessThan": "1ce5012944afaddbda939ec6bae9800fce84abbc",
"status": "affected",
"version": "9bfa35fe422c74882e27cc54450a5f76c96aad68",
"versionType": "git"
},
{
"lessThan": "e6313b800da61a26c2fdd5eba0105e197c0ab3bc",
"status": "affected",
"version": "9bfa35fe422c74882e27cc54450a5f76c96aad68",
"versionType": "git"
},
{
"lessThan": "14e02f1449ba425a44dedbec9a21efafb056e09f",
"status": "affected",
"version": "9bfa35fe422c74882e27cc54450a5f76c96aad68",
"versionType": "git"
},
{
"lessThan": "8db0ce3de78367f61c2970c0f16d9adee8830a23",
"status": "affected",
"version": "9bfa35fe422c74882e27cc54450a5f76c96aad68",
"versionType": "git"
},
{
"lessThan": "da7d7758fe884b256ddc9fef562e5ddef7952383",
"status": "affected",
"version": "9bfa35fe422c74882e27cc54450a5f76c96aad68",
"versionType": "git"
},
{
"lessThan": "eedc6867ebad73edbfaf9a0a65fbef7115cc4753",
"status": "affected",
"version": "9bfa35fe422c74882e27cc54450a5f76c96aad68",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.27"
},
{
"lessThan": "2.6.27",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.27",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: fix use-after-free on registration failure\n\nMake sure to release the sibling interfaces in case controller\nregistration fails to avoid use-after-free and double-free when they are\neventually disconnected.\n\nThis issue was reported by Sashiko while reviewing a fix for a wakeup\nsource leak in the btusb probe errors paths."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:17.111Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e09ac7d0c6859a360bf36e7104aef03f88184e0b"
},
{
"url": "https://git.kernel.org/stable/c/468fcdfaeb937163dd250773a9fed17ab1fa203c"
},
{
"url": "https://git.kernel.org/stable/c/1ce5012944afaddbda939ec6bae9800fce84abbc"
},
{
"url": "https://git.kernel.org/stable/c/e6313b800da61a26c2fdd5eba0105e197c0ab3bc"
},
{
"url": "https://git.kernel.org/stable/c/14e02f1449ba425a44dedbec9a21efafb056e09f"
},
{
"url": "https://git.kernel.org/stable/c/8db0ce3de78367f61c2970c0f16d9adee8830a23"
},
{
"url": "https://git.kernel.org/stable/c/da7d7758fe884b256ddc9fef562e5ddef7952383"
},
{
"url": "https://git.kernel.org/stable/c/eedc6867ebad73edbfaf9a0a65fbef7115cc4753"
}
],
"title": "Bluetooth: btusb: fix use-after-free on registration failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64471",
"datePublished": "2026-07-25T08:51:35.245Z",
"dateReserved": "2026-07-19T15:36:31.790Z",
"dateUpdated": "2026-08-17T04:56:17.111Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64434 (GCVE-0-2026-64434)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
l2cap_chan_timeout() runs asynchronously and accesses chan->conn. If
the connection is torn down while the timer is running or pending,
chan->conn can be freed, leading to a use-after-free when the timer
worker attempts to lock conn->lock:
| BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inline]
| BUG: KASAN: slab-use-after-free in atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]
| BUG: KASAN: slab-use-after-free in __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]
| BUG: KASAN: slab-use-after-free in mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318
| Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83
|
| CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full)
| Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
| Workqueue: events l2cap_chan_timeout
| Call Trace:
| <TASK>
| instrument_atomic_read_write include/linux/instrumented.h:112 [inline]
| atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]
| __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]
| mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318
| l2cap_chan_timeout+0x5d/0x1b0 net/bluetooth/l2cap_core.c:422
| process_one_work kernel/workqueue.c:3326 [inline]
| process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409
| worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490
| kthread+0x346/0x430 kernel/kthread.c:436
| ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158
| ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
| </TASK>
|
| Allocated by task 320:
| l2cap_conn_add+0xa7/0x820 net/bluetooth/l2cap_core.c:7075
| l2cap_connect_cfm+0xdb/0xd70 net/bluetooth/l2cap_core.c:7452
| hci_connect_cfm include/net/bluetooth/hci_core.h:2139 [inline]
| hci_remote_features_evt+0x52f/0x9f0 net/bluetooth/hci_event.c:3760
| hci_event_func net/bluetooth/hci_event.c:7796 [inline]
| hci_event_packet+0x561/0xa70 net/bluetooth/hci_event.c:7847
| hci_rx_work+0x370/0x890 net/bluetooth/hci_core.c:4040
| process_one_work kernel/workqueue.c:3326 [inline]
| process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409
| worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490
| kthread+0x346/0x430 kernel/kthread.c:436
| ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158
| ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
|
| Freed by task 322:
| hci_disconn_cfm include/net/bluetooth/hci_core.h:2154 [inline]
| hci_conn_hash_flush+0x101/0x1f0 net/bluetooth/hci_conn.c:2736
| hci_dev_close_sync+0x889/0xde0 net/bluetooth/hci_sync.c:5405
| hci_dev_do_close net/bluetooth/hci_core.c:502 [inline]
| hci_unregister_dev+0x1f7/0x370 net/bluetooth/hci_core.c:2679
| vhci_release+0x12a/0x180 drivers/bluetooth/hci_vhci.c:690
| __fput+0x369/0x890 fs/file_table.c:510
| task_work_run+0x160/0x1d0 kernel/task_work.c:233
| get_signal+0xf5b/0x1120 kernel/signal.c:2810
| arch_do_signal_or_restart+0x4d/0x600 arch/x86/kernel/signal.c:337
| __exit_to_user_mode_loop kernel/entry/common.c:64 [inline]
| exit_to_user_mode_loop+0x85/0x510 kernel/entry/common.c:98
| do_syscall_64+0x263/0x3d0 arch/x86/entry/syscall_64.c:100
| entry_SYSCALL_64_after_hwframe+0x77/0x7f
|
| The buggy address belongs to the object at ffff8881298d9400
| which belongs to the cache kmalloc-512 of size 512
| The buggy address is located 336 bytes inside of
| freed 512-byte region [ffff8881298d9400, ffff8881298d9600)
Fix it by having chan->conn hold a reference to l2cap_conn (via
l2cap_conn_get) when the channel is added to the connection, and
releasing it in the channel destructor. This ensures the l2cap_conn
remains alive as long as the channel exists.
A new FLAG_DEL channel flag is introduced to indicate that the ch
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3634cbdc2eb414b69ffa752ddbe5e0458518e321 Version: e1c100e2d61bd8c718b7d91fe3e050780a9bf72d Version: deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9 Version: 89dec92041717b027216e110599e4f6d6c921b79 Version: 50dfec218808b148ab4247b1858031b7a32015c5 Version: 859d3ace791ed878ae9ba5522c7844d960da8f88 Version: 8c8e620467a7b51562dbcefbd1f09f288d7d710d Version: 8c8e620467a7b51562dbcefbd1f09f288d7d710d Version: 7555fd885a0603f50e49a655850a1f2bd8a25398 Version: 5.10.259 ≤ Version: 5.15.210 ≤ Version: 6.1.176 ≤ Version: 6.6.143 ≤ Version: 6.12.93 ≤ Version: 6.18.35 ≤ Version: 7.0.12 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/l2cap.h",
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8f90405a4a6f1f1880dc07996b47bf57c712bd8a",
"status": "affected",
"version": "3634cbdc2eb414b69ffa752ddbe5e0458518e321",
"versionType": "git"
},
{
"lessThan": "32d783cafb46ff3ca58e6f9fd62c9c5f35eaf26b",
"status": "affected",
"version": "e1c100e2d61bd8c718b7d91fe3e050780a9bf72d",
"versionType": "git"
},
{
"lessThan": "8922c7940bae9ce4b1736dddb6362370793835c2",
"status": "affected",
"version": "deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9",
"versionType": "git"
},
{
"lessThan": "91047a4396a8b1857a6f712a90cf33ec0012b189",
"status": "affected",
"version": "89dec92041717b027216e110599e4f6d6c921b79",
"versionType": "git"
},
{
"lessThan": "0b0e2bf39cf99e458d991b9df253727e036a7d7d",
"status": "affected",
"version": "50dfec218808b148ab4247b1858031b7a32015c5",
"versionType": "git"
},
{
"lessThan": "d3b739db5dc6f688a60d56da872fabaf65246032",
"status": "affected",
"version": "859d3ace791ed878ae9ba5522c7844d960da8f88",
"versionType": "git"
},
{
"lessThan": "50c38d9f42a529691e4e67ea9cedf4f0bfc8d277",
"status": "affected",
"version": "8c8e620467a7b51562dbcefbd1f09f288d7d710d",
"versionType": "git"
},
{
"lessThan": "b66774b48dd98f07254951f74ea6f513efe7ff8b",
"status": "affected",
"version": "8c8e620467a7b51562dbcefbd1f09f288d7d710d",
"versionType": "git"
},
{
"status": "affected",
"version": "7555fd885a0603f50e49a655850a1f2bd8a25398",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThan": "6.12.97",
"status": "affected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThan": "6.18.39",
"status": "affected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThan": "7.1",
"status": "affected",
"version": "7.0.12",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/l2cap.h",
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"lessThan": "7.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.259",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.210",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.176",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.143",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.12.93",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.18.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7.0.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref\n\nl2cap_chan_timeout() runs asynchronously and accesses chan-\u003econn. If\nthe connection is torn down while the timer is running or pending,\nchan-\u003econn can be freed, leading to a use-after-free when the timer\nworker attempts to lock conn-\u003elock:\n\n| BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inline]\n| BUG: KASAN: slab-use-after-free in atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]\n| BUG: KASAN: slab-use-after-free in __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]\n| BUG: KASAN: slab-use-after-free in mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318\n| Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83\n|\n| CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full)\n| Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n| Workqueue: events l2cap_chan_timeout\n| Call Trace:\n| \u003cTASK\u003e\n| instrument_atomic_read_write include/linux/instrumented.h:112 [inline]\n| atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]\n| __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]\n| mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318\n| l2cap_chan_timeout+0x5d/0x1b0 net/bluetooth/l2cap_core.c:422\n| process_one_work kernel/workqueue.c:3326 [inline]\n| process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409\n| worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490\n| kthread+0x346/0x430 kernel/kthread.c:436\n| ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158\n| ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n| \u003c/TASK\u003e\n|\n| Allocated by task 320:\n| l2cap_conn_add+0xa7/0x820 net/bluetooth/l2cap_core.c:7075\n| l2cap_connect_cfm+0xdb/0xd70 net/bluetooth/l2cap_core.c:7452\n| hci_connect_cfm include/net/bluetooth/hci_core.h:2139 [inline]\n| hci_remote_features_evt+0x52f/0x9f0 net/bluetooth/hci_event.c:3760\n| hci_event_func net/bluetooth/hci_event.c:7796 [inline]\n| hci_event_packet+0x561/0xa70 net/bluetooth/hci_event.c:7847\n| hci_rx_work+0x370/0x890 net/bluetooth/hci_core.c:4040\n| process_one_work kernel/workqueue.c:3326 [inline]\n| process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409\n| worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490\n| kthread+0x346/0x430 kernel/kthread.c:436\n| ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158\n| ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n|\n| Freed by task 322:\n| hci_disconn_cfm include/net/bluetooth/hci_core.h:2154 [inline]\n| hci_conn_hash_flush+0x101/0x1f0 net/bluetooth/hci_conn.c:2736\n| hci_dev_close_sync+0x889/0xde0 net/bluetooth/hci_sync.c:5405\n| hci_dev_do_close net/bluetooth/hci_core.c:502 [inline]\n| hci_unregister_dev+0x1f7/0x370 net/bluetooth/hci_core.c:2679\n| vhci_release+0x12a/0x180 drivers/bluetooth/hci_vhci.c:690\n| __fput+0x369/0x890 fs/file_table.c:510\n| task_work_run+0x160/0x1d0 kernel/task_work.c:233\n| get_signal+0xf5b/0x1120 kernel/signal.c:2810\n| arch_do_signal_or_restart+0x4d/0x600 arch/x86/kernel/signal.c:337\n| __exit_to_user_mode_loop kernel/entry/common.c:64 [inline]\n| exit_to_user_mode_loop+0x85/0x510 kernel/entry/common.c:98\n| do_syscall_64+0x263/0x3d0 arch/x86/entry/syscall_64.c:100\n| entry_SYSCALL_64_after_hwframe+0x77/0x7f\n|\n| The buggy address belongs to the object at ffff8881298d9400\n| which belongs to the cache kmalloc-512 of size 512\n| The buggy address is located 336 bytes inside of\n| freed 512-byte region [ffff8881298d9400, ffff8881298d9600)\n\nFix it by having chan-\u003econn hold a reference to l2cap_conn (via\nl2cap_conn_get) when the channel is added to the connection, and\nreleasing it in the channel destructor. This ensures the l2cap_conn\nremains alive as long as the channel exists.\n\nA new FLAG_DEL channel flag is introduced to indicate that the ch\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - An unauthenticated Bluetooth peer within radio range can reach the vulnerable worker by creating a half-configured L2CAP channel and subsequently terminating the ACL connection.\nAC:L - The attacker controls both channel creation and connection teardown, can leave the 40-second channel timer armed, and can repeat or parallelize attempts to win the race.\nPR:N - The BR/EDR signaling path processes incoming L2CAP requests before application acceptance, and an SDP listener permits this path without pairing or authentication.\nUI:N - Exploitation requires no victim action because an already-running Bluetooth service and the kernel independently process the connection, timer, and disconnection.\nS:U - The UAF compromises the host kernel within the same security authority and does not inherently cross a VM, IOMMU, or comparable boundary.\nC:H - The freed kmalloc object can be reclaimed with attacker-influenced contents, allowing the UAF to support kernel-memory disclosure primitives.\nI:H - The worker performs mutex writes into the freed allocation, enabling heap corruption and potentially arbitrary write or kernel control-flow hijacking after heap grooming.\nA:H - The stale mutex access can corrupt memory, trigger an oops or panic, and can be retriggered by a nearby Bluetooth peer."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:16.061Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8f90405a4a6f1f1880dc07996b47bf57c712bd8a"
},
{
"url": "https://git.kernel.org/stable/c/32d783cafb46ff3ca58e6f9fd62c9c5f35eaf26b"
},
{
"url": "https://git.kernel.org/stable/c/8922c7940bae9ce4b1736dddb6362370793835c2"
},
{
"url": "https://git.kernel.org/stable/c/91047a4396a8b1857a6f712a90cf33ec0012b189"
},
{
"url": "https://git.kernel.org/stable/c/0b0e2bf39cf99e458d991b9df253727e036a7d7d"
},
{
"url": "https://git.kernel.org/stable/c/d3b739db5dc6f688a60d56da872fabaf65246032"
},
{
"url": "https://git.kernel.org/stable/c/50c38d9f42a529691e4e67ea9cedf4f0bfc8d277"
},
{
"url": "https://git.kernel.org/stable/c/b66774b48dd98f07254951f74ea6f513efe7ff8b"
}
],
"title": "Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64434",
"datePublished": "2026-07-25T08:51:09.066Z",
"dateReserved": "2026-07-19T15:36:31.787Z",
"dateUpdated": "2026-08-19T16:28:16.061Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68138 (GCVE-0-2026-68138)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: serialize qdisc_rtab_list against concurrent get/put
qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly
linked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no
lock. This was only safe because every caller historically held the RTNL
mutex, which serialized all rate-table lookups, inserts and frees.
That invariant no longer holds. cls_flower sets
TCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false
for it and sets TCA_ACT_FLAGS_NO_RTNL. That flag propagates through
tcf_exts_validate_ex() -> tcf_action_init() -> tcf_action_init_1() ->
tcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the
RTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each
adding a flower filter with a police action carrying the same rate, then
race on qdisc_rtab_list and on the non-atomic refcnt, leading to a
use-after-free / double-free of the kmalloc-2k struct qdisc_rate_table.
qdisc_rtab_list is a single global (not per-netns), so the corrupted
object is shared system-wide.
BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160
qdisc_put_rtab+0x12f/0x160
tcf_police_init+0xda9/0x1590
tcf_action_init_1+0x460/0x6b0
tcf_action_init+0x439/0xa40
tcf_exts_validate_ex+0x42d/0x550
fl_change+0xddd/0x7da0
tc_new_tfilter+0xaa7/0x2420
rtnetlink_rcv_msg+0x95e/0xe90
which belongs to the cache kmalloc-2k of size 2048
Protect qdisc_rtab_list and the refcount with a dedicated spinlock. The
(sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before
taking the lock; if a concurrent inserter added an identical table in the
meantime the freshly allocated one is freed under the lock, so no
duplicate is leaked. qdisc_put_rtab() now decrements the refcount and
unlinks under the same lock.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/sch_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1b050d09dd1a0ddae83bf012cf4956b7a960235f",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "6e0241f6cbb149d926ee8efee2c734fea71452cf",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "f93c89392bd3b180b5b7abc6fdae8e3dd667a313",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "4131dd0b6f67acddd616ed7c244e1d3eedd46e7b",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "d981098b76756ed71666a27518eeb69883657c43",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "8ddc2eb0d2da9c83f54f1e5720525b461b8480c4",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "fb29e1b41052488ee3f2d115d4a870497ebd7f7d",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "f43ee0c0730d6191629b5ee1ceae27b1ebfdc047",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/sch_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: serialize qdisc_rtab_list against concurrent get/put\n\nqdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly\nlinked list qdisc_rtab_list and a plain non-atomic \u0027int refcnt\u0027 with no\nlock. This was only safe because every caller historically held the RTNL\nmutex, which serialized all rate-table lookups, inserts and frees.\n\nThat invariant no longer holds. cls_flower sets\nTCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false\nfor it and sets TCA_ACT_FLAGS_NO_RTNL. That flag propagates through\ntcf_exts_validate_ex() -\u003e tcf_action_init() -\u003e tcf_action_init_1() -\u003e\ntcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the\nRTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each\nadding a flower filter with a police action carrying the same rate, then\nrace on qdisc_rtab_list and on the non-atomic refcnt, leading to a\nuse-after-free / double-free of the kmalloc-2k struct qdisc_rate_table.\nqdisc_rtab_list is a single global (not per-netns), so the corrupted\nobject is shared system-wide.\n\n BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160\n qdisc_put_rtab+0x12f/0x160\n tcf_police_init+0xda9/0x1590\n tcf_action_init_1+0x460/0x6b0\n tcf_action_init+0x439/0xa40\n tcf_exts_validate_ex+0x42d/0x550\n fl_change+0xddd/0x7da0\n tc_new_tfilter+0xaa7/0x2420\n rtnetlink_rcv_msg+0x95e/0xe90\n which belongs to the cache kmalloc-2k of size 2048\n\nProtect qdisc_rtab_list and the refcount with a dedicated spinlock. The\n(sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before\ntaking the lock; if a concurrent inserter added an identical table in the\nmeantime the freshly allocated one is freed under the lock, so no\nduplicate is leaked. qdisc_put_rtab() now decrements the refcount and\nunlinks under the same lock."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local RTM_NEWTFILTER rtnetlink messages (tc flower filter with police action) through rtnetlink_rcv_msg\u2192tc_new_tfilter\u2192fl_change\u2192tcf_police_init\u2192qdisc_get_rtab/qdisc_put_rtab; no remote packet or network protocol path exists.\nAC:L - cls_flower is TCF_PROTO_OPS_DOIT_UNLOCKED, so concurrent RTM_NEWTFILTER requests run without RTNL; the attacker controls both racing threads/CPUs and can repeatedly install flower filters with identical police rate tables to deterministically hit the global qdisc_rtab_list/refcnt race.\nPR:L - Non-GET rtnetlink handlers require netlink_net_capable(CAP_NET_ADMIN); this is namespace-scoped, so an unprivileged local user obtains CAP_NET_ADMIN via user namespaces (unshare -Urn), sets up clsact/ingress, and installs flower+police rules without init-namespace root.\nUI:N - Exploitation is fully self-contained: the attacker issues the concurrent tc/netlink commands from its own processes and needs no victim to mount filesystems, click links, or perform any other interactive action.\nS:U - Impact is heap corruption and UAF/double-free in kernel kmalloc-2k slabs within the same kernel security authority; although qdisc_rtab_list is global across netns, this is standard kernel memory corruption/privilege escalation, not a VM, IOMMU, or sandbox boundary escape.\nC:H - Concurrent non-atomic refcnt and list updates cause slab use-after-free/double-free of struct qdisc_rate_table (KASAN-confirmed in qdisc_put_rtab); freed 2KB objects are attacker-influenceable via kmalloc timing and are classically weaponizable for arbitrary kernel memory disclosure.\nI:H - The race corrupts a process-global singly linked list and can double-free a kmalloc-2k qdisc_rate_table, yielding classic heap metadata/object corruption primitives that can be developed into arbitrary kernel writes and local privilege escalation/code execution.\nA:H - Demonstrated KASAN slab-use-after-free in qdisc_put_rtab on the error/teardown path, and concurrent double-free of the same rate table can panic the kernel; the trigger is repeatable at will with concurrent netlink requests and causes task death or system-wide instability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:55.796Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1b050d09dd1a0ddae83bf012cf4956b7a960235f"
},
{
"url": "https://git.kernel.org/stable/c/6e0241f6cbb149d926ee8efee2c734fea71452cf"
},
{
"url": "https://git.kernel.org/stable/c/f93c89392bd3b180b5b7abc6fdae8e3dd667a313"
},
{
"url": "https://git.kernel.org/stable/c/4131dd0b6f67acddd616ed7c244e1d3eedd46e7b"
},
{
"url": "https://git.kernel.org/stable/c/d981098b76756ed71666a27518eeb69883657c43"
},
{
"url": "https://git.kernel.org/stable/c/8ddc2eb0d2da9c83f54f1e5720525b461b8480c4"
},
{
"url": "https://git.kernel.org/stable/c/fb29e1b41052488ee3f2d115d4a870497ebd7f7d"
},
{
"url": "https://git.kernel.org/stable/c/f43ee0c0730d6191629b5ee1ceae27b1ebfdc047"
}
],
"title": "net/sched: serialize qdisc_rtab_list against concurrent get/put",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68138",
"datePublished": "2026-08-10T11:59:01.744Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-23T12:45:55.796Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68229 (GCVE-0-2026-68229)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: cedrus: skip invalid H.264 reference list entries
Cedrus consumes H.264 ref_pic_list0/ref_pic_list1 entries from the
stateless slice control and later uses their indices to look up
decode->dpb[] in _cedrus_write_ref_list().
Rejecting such controls in cedrus_try_ctrl() would break existing
userspace, since stateless H.264 reference lists may legitimately carry
out-of-range indices for missing references. Instead, guard the actual
DPB lookup in Cedrus and skip entries whose indices do not fit the fixed
V4L2_H264_NUM_DPB_ENTRIES array.
This keeps the fix local to the driver use site and avoids out-of-bounds
reads from malformed or unsupported reference list entries.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/sunxi/cedrus/cedrus_h264.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a6a109771c51920beb620f30778c29da823cc34c",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "7ff6f728a2433b420bb372cb0e8a4eea3f2e1a4b",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "1db34683b0fbbcb3bc162380c11514ea0a44e8ab",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "2ee8327c85b3ac7b532d2d6a1e3a295d5ad7414a",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "0af8945fcae742d099f59f3c725eb67235953a31",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "9924cb548ee7753a6473997949c3ec48092de0b0",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "e53112c2de88982e66c369aee2120d5efd78df30",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "10358ea986c3c85516d1c8206486464f79d36e76",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/sunxi/cedrus/cedrus_h264.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cedrus: skip invalid H.264 reference list entries\n\nCedrus consumes H.264 ref_pic_list0/ref_pic_list1 entries from the\nstateless slice control and later uses their indices to look up\ndecode-\u003edpb[] in _cedrus_write_ref_list().\n\nRejecting such controls in cedrus_try_ctrl() would break existing\nuserspace, since stateless H.264 reference lists may legitimately carry\nout-of-range indices for missing references. Instead, guard the actual\nDPB lookup in Cedrus and skip entries whose indices do not fit the fixed\nV4L2_H264_NUM_DPB_ENTRIES array.\n\nThis keeps the fix local to the driver use site and avoids out-of-bounds\nreads from malformed or unsupported reference list entries."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the local V4L2 interface on the cedrus video device node (/dev/videoN) via VIDIOC_S_EXT_CTRLS plus QBUF/STREAMON ioctls. There is no remote or network-facing path to the stateless H.264 decoder.\nAC:L - The attacker fully and deterministically controls the out-of-range value: ref_pic_list0/1[i].index is a u8 copied verbatim from the control payload with no validation, so any index in 16..255 immediately produces the out-of-bounds dpb[] access on the next decode run. No race, timing, or uncontrollable memory-layout condition is involved.\nPR:L - Only an unprivileged local account with access to the cedrus video device node is needed (typically the \u0027video\u0027 group, or the media/camera service on Android and embedded Allwinner devices). No capability, CAP_SYS_ADMIN, or root check exists anywhere on the path \u2014 cedrus_try_ctrl() validates only SPS chroma format and bit depth.\nUI:N - The attacking process performs the entire sequence itself \u2014 open the device, set the crafted H.264 slice-params control, queue buffers, start streaming. No victim action, file open, or media mount is required.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no VM, IOMMU, or sandbox boundary is crossed. This is a standard in-kernel driver memory-safety defect.\nC:H - decode-\u003edpb[] holds 16 32-byte entries at the start of a ~560-byte control allocation, so an attacker-chosen index up to 255 reads at offset 8160 \u2014 about 7.6 KB of adjacent kernel heap beyond the object. The read flags/reference_ts values are consumed by the ACTIVE test and vb2_find_buffer() timestamp lookup, giving an attacker-steerable oracle over unrelated kernel heap contents.\nI:N - The defect is purely a read: num_ref is bounded to V4L2_H264_REF_LIST_LEN by v4l2-ctrls-core.c, so the sram_array[CEDRUS_MAX_REF_IDX] stores stay in bounds, and only a legitimately-looked-up buffer position is written to hardware SRAM. No kernel memory is modified out of bounds.\nA:H - Reading several kilobytes past the end of a slab object can walk off the slab page into an unmapped or poisoned region, and trips KASAN/hardening checks, producing a kernel oops. The trigger is trivially repeatable from an unprivileged process, so the crash can be induced at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:01.546Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a6a109771c51920beb620f30778c29da823cc34c"
},
{
"url": "https://git.kernel.org/stable/c/7ff6f728a2433b420bb372cb0e8a4eea3f2e1a4b"
},
{
"url": "https://git.kernel.org/stable/c/1db34683b0fbbcb3bc162380c11514ea0a44e8ab"
},
{
"url": "https://git.kernel.org/stable/c/2ee8327c85b3ac7b532d2d6a1e3a295d5ad7414a"
},
{
"url": "https://git.kernel.org/stable/c/0af8945fcae742d099f59f3c725eb67235953a31"
},
{
"url": "https://git.kernel.org/stable/c/9924cb548ee7753a6473997949c3ec48092de0b0"
},
{
"url": "https://git.kernel.org/stable/c/e53112c2de88982e66c369aee2120d5efd78df30"
},
{
"url": "https://git.kernel.org/stable/c/10358ea986c3c85516d1c8206486464f79d36e76"
}
],
"title": "media: cedrus: skip invalid H.264 reference list entries",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68229",
"datePublished": "2026-08-10T12:00:51.935Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:32:01.546Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64543 (GCVE-0-2026-64543)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
bearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(),
but tipc_disc_rcv() still dereferences b->disc in RX softirq under
rcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv).
L2 bearers are safe thanks to the synchronize_net() in
tipc_disable_l2_media(), but the UDP bearer defers that call to the
cleanup_bearer() workqueue, so the discoverer is freed with no grace
period:
BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149)
Read of size 8 at addr ffff88802348b728 by task poc_tipc/184
<IRQ>
tipc_disc_rcv (net/tipc/discover.c:149)
tipc_rcv (net/tipc/node.c:2126)
tipc_udp_recv (net/tipc/udp_media.c:391)
udp_rcv (net/ipv4/udp.c:2643)
ip_local_deliver_finish (net/ipv4/ip_input.c:241)
</IRQ>
Freed by task 181:
kfree (mm/slub.c:6565)
bearer_disable (net/tipc/bearer.c:418)
tipc_nl_bearer_disable (net/tipc/bearer.c:1001)
The bearer is freed with kfree_rcu(); free the discoverer the same way.
Add an rcu_head to struct tipc_discoverer and free it and its skb from an
RCU callback.
Because the RCU callback (tipc_disc_free_rcu) lives in module text, a
call_rcu() that is still pending when the tipc module is unloaded would
invoke a freed function. Add an rcu_barrier() to tipc_exit() after the
bearer subsystem has been torn down, so all pending discoverer callbacks
have run before the module text goes away.
Reachable from an unprivileged user namespace: the TIPCv2 genl family is
netnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC
and CONFIG_TIPC_MEDIA_UDP.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/core.c",
"net/tipc/discover.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "380413cdfd29fb9fa486c82889132b680c4983c5",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "f05b3f4c78370469286879c765f5a1dd39dbcd32",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "4da2ac7749411971e1b222b992da5a172ce45f98",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "5e215bf1c47fdddf8203a0fe80a0ed594065f101",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "ec7d54d8cc1723921d671e3272b427c96366506f",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "b65289e1c3f352a9f92c6e19713ddd647e033253",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "1579342d71133da7f00daa02c75cebec7372097b",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/core.c",
"net/tipc/discover.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix use-after-free of the discoverer in tipc_disc_rcv()\n\nbearer_disable() frees b-\u003edisc with tipc_disc_delete()\u0027s plain kfree(),\nbut tipc_disc_rcv() still dereferences b-\u003edisc in RX softirq under\nrcu_read_lock() (tipc_udp_recv -\u003e tipc_rcv -\u003e tipc_disc_rcv).\n\nL2 bearers are safe thanks to the synchronize_net() in\ntipc_disable_l2_media(), but the UDP bearer defers that call to the\ncleanup_bearer() workqueue, so the discoverer is freed with no grace\nperiod:\n\n BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149)\n Read of size 8 at addr ffff88802348b728 by task poc_tipc/184\n \u003cIRQ\u003e\n tipc_disc_rcv (net/tipc/discover.c:149)\n tipc_rcv (net/tipc/node.c:2126)\n tipc_udp_recv (net/tipc/udp_media.c:391)\n udp_rcv (net/ipv4/udp.c:2643)\n ip_local_deliver_finish (net/ipv4/ip_input.c:241)\n \u003c/IRQ\u003e\n Freed by task 181:\n kfree (mm/slub.c:6565)\n bearer_disable (net/tipc/bearer.c:418)\n tipc_nl_bearer_disable (net/tipc/bearer.c:1001)\n\nThe bearer is freed with kfree_rcu(); free the discoverer the same way.\nAdd an rcu_head to struct tipc_discoverer and free it and its skb from an\nRCU callback.\n\nBecause the RCU callback (tipc_disc_free_rcu) lives in module text, a\ncall_rcu() that is still pending when the tipc module is unloaded would\ninvoke a freed function. Add an rcu_barrier() to tipc_exit() after the\nbearer subsystem has been torn down, so all pending discoverer callbacks\nhave run before the module text goes away.\n\nReachable from an unprivileged user namespace: the TIPCv2 genl family is\nnetnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC\nand CONFIG_TIPC_MEDIA_UDP."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The free side is only reachable through the local TIPCv2 generic-netlink `BEARER_DISABLE` command (or netns teardown); a remote peer can supply the discovery packet that performs the use-after-free access but cannot itself cause `bearer_disable()` to run, so the complete attack requires local access.\nAC:L - The attacker controls both sides of the race \u2014 one thread floods TIPC discovery packets at the bearer\u0027s UDP port while another disables the bearer \u2014 and `bearer_disable()` clears `b-\u003eup` and then `kfree()`s the discoverer with no synchronization whatsoever, leaving a wide window that a multi-CPU packet flood hits reliably (a working PoC exists).\nPR:L - `tipc_genl_family` is `.netnsok = true` and the bearer enable/disable ops carry no `GENL_ADMIN_PERM` or other capability check, so an unprivileged user can do everything inside `unshare -Urn` after autoloading tipc via `socket(AF_TIPC, ...)`.\nUI:N - The attacking process performs both the bearer disable and the packet injection itself; no victim action or cooperating user is involved.\nS:U - The corruption stays within the kernel\u0027s own security authority \u2014 no VM, IOMMU, or hypervisor boundary is crossed.\nC:H - `d-\u003enet` is read from the freed slab object and dereferenced as a `struct net *`; after reclaiming the kmalloc-192 allocation with sprayed data the attacker gains a controlled-pointer dereference chain usable for arbitrary kernel memory disclosure.\nI:H - `msg_set_prevnode(buf_msg(d-\u003eskb), sugg_addr)` writes a wire-controlled 32-bit value through the dangling `d-\u003eskb` pointer, and `tipc_disc_add_dest()` takes a spinlock and increments a counter in freed memory \u2014 together a controlled-address/controlled-value write suitable for control-flow hijacking.\nA:H - The use-after-free reliably produces a KASAN slab-use-after-free in softirq context and, on production kernels, a corrupted-pointer dereference or spinlock manipulation on reclaimed memory leading to kernel panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:28.342Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/380413cdfd29fb9fa486c82889132b680c4983c5"
},
{
"url": "https://git.kernel.org/stable/c/f05b3f4c78370469286879c765f5a1dd39dbcd32"
},
{
"url": "https://git.kernel.org/stable/c/4da2ac7749411971e1b222b992da5a172ce45f98"
},
{
"url": "https://git.kernel.org/stable/c/5e215bf1c47fdddf8203a0fe80a0ed594065f101"
},
{
"url": "https://git.kernel.org/stable/c/ec7d54d8cc1723921d671e3272b427c96366506f"
},
{
"url": "https://git.kernel.org/stable/c/a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2"
},
{
"url": "https://git.kernel.org/stable/c/b65289e1c3f352a9f92c6e19713ddd647e033253"
},
{
"url": "https://git.kernel.org/stable/c/1579342d71133da7f00daa02c75cebec7372097b"
}
],
"title": "tipc: fix use-after-free of the discoverer in tipc_disc_rcv()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64543",
"datePublished": "2026-07-27T20:10:35.565Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-19T16:28:28.342Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68359 (GCVE-0-2026-68359)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nzxt-smart2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "761249a3d92db83ae19670c4ecdf73c0a85bcb61",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "185c0880397aee9def0af5a59ea65f22f37ad658",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "a2a15de020597efbff84b4281dd472e5860b7e3e",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "205cff797a94757ec88ba299c8e2bf2e1e3f4bbf",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "18d7c523891004226bccdba39dd681eca22ceb8a",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nzxt-smart2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop\n\nCalling hid_hw_stop() does not stop the device IO.\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\nthe driver probe function. If the probe operation fails after \"io start\"\nhas been initiated, this race condition will result in a UAF vulnerability.\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:08.117Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/761249a3d92db83ae19670c4ecdf73c0a85bcb61"
},
{
"url": "https://git.kernel.org/stable/c/185c0880397aee9def0af5a59ea65f22f37ad658"
},
{
"url": "https://git.kernel.org/stable/c/a2a15de020597efbff84b4281dd472e5860b7e3e"
},
{
"url": "https://git.kernel.org/stable/c/205cff797a94757ec88ba299c8e2bf2e1e3f4bbf"
},
{
"url": "https://git.kernel.org/stable/c/18d7c523891004226bccdba39dd681eca22ceb8a"
},
{
"url": "https://git.kernel.org/stable/c/59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e"
}
],
"title": "hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68359",
"datePublished": "2026-08-10T12:03:36.254Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:08.117Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68262 (GCVE-0-2026-68262)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: Fix user array stride in pvr_set_uobj_array()
pvr_set_uobj_array() copies an array of kernel objects to a userspace
array whose element size is described by out->stride. When out->stride
is different from the kernel object size, the slow path advances the
userspace pointer by the kernel object size and the kernel pointer by the
userspace stride.
This reverses the intended layout. For larger userspace strides, later
copies read from the wrong kernel addresses. For smaller userspace
strides, later copies are written at the wrong userspace offsets. The
padding clear is also done only for the first element instead of the
padding area for each element.
Advance the userspace pointer by out->stride and the kernel pointer by
obj_size, and clear per-element padding while the current userspace
pointer is still available.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bbebc39a70f6fc9b02637c8624349e30325873cb",
"status": "affected",
"version": "f99f5f3ea7efd54ba0529c4f2d7c72712918a522",
"versionType": "git"
},
{
"lessThan": "b983a35dad3701399c692d7c6eb57d8b6ffc0929",
"status": "affected",
"version": "f99f5f3ea7efd54ba0529c4f2d7c72712918a522",
"versionType": "git"
},
{
"lessThan": "09beaf4aec05b0525f2153dce693f3eb3166697a",
"status": "affected",
"version": "f99f5f3ea7efd54ba0529c4f2d7c72712918a522",
"versionType": "git"
},
{
"lessThan": "8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a",
"status": "affected",
"version": "f99f5f3ea7efd54ba0529c4f2d7c72712918a522",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Fix user array stride in pvr_set_uobj_array()\n\npvr_set_uobj_array() copies an array of kernel objects to a userspace\narray whose element size is described by out-\u003estride. When out-\u003estride\nis different from the kernel object size, the slow path advances the\nuserspace pointer by the kernel object size and the kernel pointer by the\nuserspace stride.\n\nThis reverses the intended layout. For larger userspace strides, later\ncopies read from the wrong kernel addresses. For smaller userspace\nstrides, later copies are written at the wrong userspace offsets. The\npadding clear is also done only for the first element instead of the\npadding area for each element.\n\nAdvance the userspace pointer by out-\u003estride and the kernel pointer by\nobj_size, and clear per-element padding while the current userspace\npointer is still available."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the DRM_IOCTL_PVR_DEV_QUERY ioctl on the Imagination PowerVR render node (/dev/dri/renderD*), requiring local access to the device file; there is no remote or adjacent path.\nAC:L - The attacker fully controls the drm_pvr_obj_array stride and count fields passed to the ioctl, so the mis-advanced kernel pointer and the resulting out-of-bounds read occur deterministically on every call, with no race or unpredictable precondition.\nPR:L - The DEV_QUERY ioctl is marked DRM_RENDER_ALLOW, so it needs neither DRM master nor authentication - any unprivileged local user or sandboxed app that can open the render node (standard for GUI/Android/embedded graphics clients) can invoke it.\nUI:N - The attacking process triggers the flaw entirely on its own by issuing a single ioctl; no action by another user or victim process is needed.\nS:U - The out-of-bounds read and the disclosure occur within the kernel and are delivered to the calling process; no other security authority (VM, IOMMU domain) is crossed.\nC:H - With stride \u003e obj_size the kernel source pointer advances by the attacker-chosen stride (up to ~4 GiB) past the static_data_areas array, and copy_to_user hands 16 bytes per element back to userspace; repeating the ioctl with varying strides yields a repeatable read of arbitrary kernel memory at chosen offsets from a known symbol, leaking pointers, keys and other kernel data.\nI:N - Because min_stride equals the object size, only the stride \u003e obj_size case is reachable, so all userspace writes stay inside the caller\u0027s own count*stride buffer and no kernel memory is written; the only integrity effect is misplaced/uncleared data in the caller\u0027s own buffer.\nA:H - The kernel-side reads walk far outside the static array into unmapped, text or slab memory; with hardened usercopy or KASAN enabled this triggers usercopy_abort()/BUG and a KASAN out-of-bounds report, killing the task or panicking the system, and the fault is trivially repeatable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:54.563Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bbebc39a70f6fc9b02637c8624349e30325873cb"
},
{
"url": "https://git.kernel.org/stable/c/b983a35dad3701399c692d7c6eb57d8b6ffc0929"
},
{
"url": "https://git.kernel.org/stable/c/09beaf4aec05b0525f2153dce693f3eb3166697a"
},
{
"url": "https://git.kernel.org/stable/c/8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a"
}
],
"title": "drm/imagination: Fix user array stride in pvr_set_uobj_array()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68262",
"datePublished": "2026-08-10T12:01:36.582Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:01:54.563Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74669 (GCVE-0-2026-74669)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipvs: clear IPv4 options after rebasing tunnel ICMP errors
ip_vs_in_icmp() rebases an skb from the outer ICMP packet to the
quoted original request before passing it to icmp_send(). However,
IPCB(skb)->opt still describes the outer IPv4 header.
A timestamp option in the outer header can therefore leave an offset
that points into the quoted transport header after the rebase.
__ip_options_echo() treats a byte at that stale location as the option
length and copies it into the fixed-size option storage on the
__icmp_send() stack, causing a stack out-of-bounds write.
Clear the stale option metadata after resetting the network header.
Keep the remaining control block fields, including the ingress
interface used by the ICMP response path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipvs/ip_vs_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "79ffa99202c944467e28b13b513bf2998732edff",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "c9413b50204738fbc429bb86bf01353c393a6c28",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "37c61b3745129cbd682c557b51345828120972e5",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "ed246dd85ebf27c1f6b7897834d40786c0ca3006",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "6f46fc460e9316062bdcdf89199eb5d7a33da33b",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "75eec935444db4af2123e0491936f6e273d7ea00",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "384b4dae14277d369221d187e9b3af56c79d2e50",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "e0ba936287dfe9783426aac27e5fd76fe35b38c9",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipvs/ip_vs_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.7"
},
{
"lessThan": "3.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: clear IPv4 options after rebasing tunnel ICMP errors\n\nip_vs_in_icmp() rebases an skb from the outer ICMP packet to the\nquoted original request before passing it to icmp_send(). However,\nIPCB(skb)-\u003eopt still describes the outer IPv4 header.\n\nA timestamp option in the outer header can therefore leave an offset\nthat points into the quoted transport header after the rebase.\n__ip_options_echo() treats a byte at that stale location as the option\nlength and copies it into the fixed-size option storage on the\n__icmp_send() stack, causing a stack out-of-bounds write.\n\nClear the stale option metadata after resetting the network header.\nKeep the remaining control block fields, including the ingress\ninterface used by the ICMP response path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit when a remote peer sends a crafted ICMP error to an IPVS load balancer; processing occurs in the IPv4 LOCAL_IN/FORWARD netfilter path on received network packets before icmp_send().\nAC:L - An attacker can reliably trigger the path by opening IPVS tunnel traffic, then sending an ICMP error whose outer IPv4 header includes a timestamp option and whose quoted payload aligns bytes at the stale option offset to a large length.\nPR:N - Exploitation requires only the ability to send IPv4/ICMP to the target; the remote attacker needs no local account, capability, or authentication on the victim host.\nUI:N - No victim user action is required beyond normal exposure of an IPVS tunnel load balancer to the network; exploitation is driven entirely by attacker-sent packets.\nS:U - Impact is confined to kernel memory/stack corruption and privilege boundaries within the host kernel; it does not cross into another security authority such as a VM guest or separate sandbox domain.\nC:H - The stale IPCB option metadata drives __ip_options_echo() to memcpy() from attacker-influenced skb bytes into a 40-byte stack buffer, enabling out-of-bounds kernel memory access that can disclose stack/kernel data.\nI:H - The stack out-of-bounds write in __icmp_send() is attacker-controlled in length and content via crafted quoted headers, providing a standard memory-corruption primitive that can corrupt return addresses and enable arbitrary kernel code execution.\nA:H - Corrupting the __icmp_send() stack frame can immediately panic or oops the kernel during ICMP processing, causing complete loss of availability on the load balancer."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:24.114Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/79ffa99202c944467e28b13b513bf2998732edff"
},
{
"url": "https://git.kernel.org/stable/c/c9413b50204738fbc429bb86bf01353c393a6c28"
},
{
"url": "https://git.kernel.org/stable/c/37c61b3745129cbd682c557b51345828120972e5"
},
{
"url": "https://git.kernel.org/stable/c/ed246dd85ebf27c1f6b7897834d40786c0ca3006"
},
{
"url": "https://git.kernel.org/stable/c/6f46fc460e9316062bdcdf89199eb5d7a33da33b"
},
{
"url": "https://git.kernel.org/stable/c/75eec935444db4af2123e0491936f6e273d7ea00"
},
{
"url": "https://git.kernel.org/stable/c/384b4dae14277d369221d187e9b3af56c79d2e50"
},
{
"url": "https://git.kernel.org/stable/c/e0ba936287dfe9783426aac27e5fd76fe35b38c9"
}
],
"title": "ipvs: clear IPv4 options after rebasing tunnel ICMP errors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74669",
"datePublished": "2026-08-22T15:32:40.221Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-25T05:41:24.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46115 (GCVE-0-2026-46115)
Vulnerability from cvelistv5
Published
2026-05-28 09:35
Modified
2026-08-05 12:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
block: add pgmap check to biovec_phys_mergeable
biovec_phys_mergeable() is used by the request merge, DMA mapping,
and integrity merge paths to decide if two physically contiguous
bvec segments can be coalesced into one. It currently has no check
for whether the segments belong to different dev_pagemaps.
When zone device memory is registered in multiple chunks, each chunk
gets its own dev_pagemap. A single bio can legitimately contain
bvecs from different pgmaps -- iov_iter_extract_bvecs() breaks at
pgmap boundaries but the outer loop in bio_iov_iter_get_pages()
continues filling the same bio. If such bvecs are physically
contiguous, biovec_phys_mergeable() will coalesce them, making it
impossible to recover the correct pgmap for the merged segment
via page_pgmap().
Add a zone_device_pages_have_same_pgmap() check to prevent merging
bvec segments that span different pgmaps.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"block/blk.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3d2ecbd444b01d6500671d1a582b7393943cf539",
"status": "affected",
"version": "49580e690755d0e51ed7aa2c33225dd884fa738a",
"versionType": "git"
},
{
"lessThan": "a7f3aa8c9df3905fe820ae36b67ba56b81587574",
"status": "affected",
"version": "49580e690755d0e51ed7aa2c33225dd884fa738a",
"versionType": "git"
},
{
"lessThan": "f17d521075325b8afc42d1baa1c28a5e9aca111f",
"status": "affected",
"version": "49580e690755d0e51ed7aa2c33225dd884fa738a",
"versionType": "git"
},
{
"lessThan": "f632dab4b841554cd6416058c61886d7db176581",
"status": "affected",
"version": "49580e690755d0e51ed7aa2c33225dd884fa738a",
"versionType": "git"
},
{
"lessThan": "13920e4b7b784b40cf4519ff1f0f3e513476a499",
"status": "affected",
"version": "49580e690755d0e51ed7aa2c33225dd884fa738a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"block/blk.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.88",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.30",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.88",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.30",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: add pgmap check to biovec_phys_mergeable\n\nbiovec_phys_mergeable() is used by the request merge, DMA mapping,\nand integrity merge paths to decide if two physically contiguous\nbvec segments can be coalesced into one. It currently has no check\nfor whether the segments belong to different dev_pagemaps.\n\nWhen zone device memory is registered in multiple chunks, each chunk\ngets its own dev_pagemap. A single bio can legitimately contain\nbvecs from different pgmaps -- iov_iter_extract_bvecs() breaks at\npgmap boundaries but the outer loop in bio_iov_iter_get_pages()\ncontinues filling the same bio. If such bvecs are physically\ncontiguous, biovec_phys_mergeable() will coalesce them, making it\nimpossible to recover the correct pgmap for the merged segment\nvia page_pgmap().\n\nAdd a zone_device_pages_have_same_pgmap() check to prevent merging\nbvec segments that span different pgmaps."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Reachable via remotely-initiated NVMe-oF (nvmet-tcp/nvmet-rdma) I/O on a P2PDMA-backed namespace; remote read/write commands drive the block-layer merge/SG-mapping path (`biovec_phys_mergeable`) over P2P buffers on the target.\nAC:L - Adjacent chunks of multi-chunk P2P/zone-device memory are physically contiguous, so the missing pgmap check makes the bad coalesce occur deterministically once such memory backs the I/O; repeated/large I/O reliably straddles a pgmap boundary.\nPR:N - NVMe-oF targets are commonly deployed without in-band cryptographic authentication, so a connected (unauthenticated) initiator can issue the I/O that reaches the vulnerable path.\nUI:N - Exploitation requires only that the attacker issue normal I/O commands; no victim/administrator interaction is needed.\nS:U - The corruption stays within the kernel\u0027s own block/DMA handling and adjacent device memory; it does not cross into a separately-managed security authority such as a VM host.\nC:H - A misdirected DMA on a read maps the spillover pages to the wrong pgmap\u0027s bus address, so data from unrelated device memory can be returned to the attacker \u2014 an arbitrary-read/disclosure-class primitive.\nI:H - A misdirected DMA on a write transfers data to the wrong physical/device address, corrupting unrelated device or host memory \u2014 an out-of-bounds write primitive.\nA:H - Wrong/invalid DMA bus addresses cause IOMMU faults, device errors, and kernel oops/hangs, crashing the I/O path or the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:29:47.285Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3d2ecbd444b01d6500671d1a582b7393943cf539"
},
{
"url": "https://git.kernel.org/stable/c/a7f3aa8c9df3905fe820ae36b67ba56b81587574"
},
{
"url": "https://git.kernel.org/stable/c/f17d521075325b8afc42d1baa1c28a5e9aca111f"
},
{
"url": "https://git.kernel.org/stable/c/f632dab4b841554cd6416058c61886d7db176581"
},
{
"url": "https://git.kernel.org/stable/c/13920e4b7b784b40cf4519ff1f0f3e513476a499"
}
],
"title": "block: add pgmap check to biovec_phys_mergeable",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46115",
"datePublished": "2026-05-28T09:35:26.735Z",
"dateReserved": "2026-05-13T15:03:33.098Z",
"dateUpdated": "2026-08-05T12:29:47.285Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68156 (GCVE-0-2026-68156)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: refresh auth->authorizer_buf{,_len} after authorizer update
ceph_x_create_authorizer() caches au->buf->vec.iov_base and
au->buf->vec.iov_len in struct ceph_auth_handshake. These
cached values are then used by the messenger connect code when
sending the authorizer.
ceph_x_update_authorizer() can rebuild the authorizer when a newer
service ticket is available. If the rebuilt authorizer no longer
fits in the existing buffer, ceph_x_build_authorizer() drops its
reference to au->buf and allocates a new one. If this is the final
reference, ceph_buffer_put() frees the old ceph_buffer and its
vec.iov_base, but auth->authorizer_buf still points at that freed
memory.
A subsequent msgr1 reconnect can therefore queue the stale pointer
and trigger a KASAN slab-use-after-free in _copy_from_iter() while
tcp_sendmsg() copies the authorizer.
Refresh auth->authorizer_buf and auth->authorizer_buf_len after a
successful authorizer rebuild so the messenger sends the current
buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 29c65a277a64645af853e8c9a9b3dda0ddc421e0 Version: d2c7223497cf8228416c70e3f4238ddd6c5bdf3c Version: 3.4.50 ≤ Version: 3.9.7 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/auth_x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2334e9997308305ee4fd508fdfe6086c4150ed60",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "79a273df64238a4ade8b709689a78589f755b8ef",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "26f814187abceee90dbb29a02133adb4786fbb13",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "9d37aec9ffe4e743dabc3f84502e9723e17a30d4",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "75e82e8944ac1efe9fdb88bd2f14d9a031282bdf",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "0060ec912292a550198d8d18ac95b433c92a7091",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "5ecfcd5c05866f185357700b81b461dae4f5ebb2",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "937d61f86d377a3aa578adae7a3dfcecdddf9d89",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"status": "affected",
"version": "29c65a277a64645af853e8c9a9b3dda0ddc421e0",
"versionType": "git"
},
{
"status": "affected",
"version": "d2c7223497cf8228416c70e3f4238ddd6c5bdf3c",
"versionType": "git"
},
{
"lessThan": "3.5",
"status": "affected",
"version": "3.4.50",
"versionType": "semver"
},
{
"lessThan": "3.10",
"status": "affected",
"version": "3.9.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/auth_x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.4.50",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.9.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: refresh auth-\u003eauthorizer_buf{,_len} after authorizer update\n\nceph_x_create_authorizer() caches au-\u003ebuf-\u003evec.iov_base and\nau-\u003ebuf-\u003evec.iov_len in struct ceph_auth_handshake. These\ncached values are then used by the messenger connect code when\nsending the authorizer.\n\nceph_x_update_authorizer() can rebuild the authorizer when a newer\nservice ticket is available. If the rebuilt authorizer no longer\nfits in the existing buffer, ceph_x_build_authorizer() drops its\nreference to au-\u003ebuf and allocates a new one. If this is the final\nreference, ceph_buffer_put() frees the old ceph_buffer and its\nvec.iov_base, but auth-\u003eauthorizer_buf still points at that freed\nmemory.\n\nA subsequent msgr1 reconnect can therefore queue the stale pointer\nand trigger a KASAN slab-use-after-free in _copy_from_iter() while\ntcp_sendmsg() copies the authorizer.\n\nRefresh auth-\u003eauthorizer_buf and auth-\u003eauthorizer_buf_len after a\nsuccessful authorizer rebuild so the messenger sends the current\nbuffer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A compromised or malicious Ceph monitor/OSD delivers rotated cephx service tickets over TCP that increase secret_id and can enlarge the authorizer; on subsequent msgr1 reconnect the stale authorizer_buf is copied in tcp_sendmsg, so the UAF is reachable from the network peer without local syscall access.\nAC:L - An attacker controlling the Ceph cluster can deterministically issue a larger rotated ticket to force ceph_buffer realloc in ceph_x_update_authorizer, then trigger an msgr1 OSD/MDS/MON reconnect; no victim-specific memory layout or uncontrollable race is required.\nPR:N - Exploitation requires no privileges on the victim host; any kernel Ceph/RBD/CephFS client already connected to an attacker-controlled or compromised cluster is sufficient, matching other libceph client CVEs where the remote peer drives the bug.\nUI:N - After initial Ceph client setup, service-ticket rotation and messenger reconnects occur automatically; no further interactive user action is needed to reach the stale-buffer send path.\nS:U - The slab UAF corrupts kernel heap memory on the Ceph client host for local privilege escalation or crash, but does not cross VM, IOMMU, or container sandbox boundaries to another security authority.\nC:H - KASAN-confirmed slab use-after-free in _copy_from_iter during authorizer transmission reads freed kmalloc memory, which can disclose adjacent kernel pointers and is classed as exploitable arbitrary read per kernel UAF guidance.\nI:H - Freed authorizer buffers can be reclaimed with attacker-controlled data before reconnect, enabling heap corruption and control-flow hijack during the stale-pointer copy, consistent with kernel UAF write primitive scoring.\nA:H - The reported KASAN slab-use-after-free in tcp_sendmsg while copying the authorizer reliably causes kernel oops or panic on Ceph client reconnect, and remains repeatable whenever tickets are rotated and msgr1 reconnects."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:25.089Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2334e9997308305ee4fd508fdfe6086c4150ed60"
},
{
"url": "https://git.kernel.org/stable/c/79a273df64238a4ade8b709689a78589f755b8ef"
},
{
"url": "https://git.kernel.org/stable/c/26f814187abceee90dbb29a02133adb4786fbb13"
},
{
"url": "https://git.kernel.org/stable/c/9d37aec9ffe4e743dabc3f84502e9723e17a30d4"
},
{
"url": "https://git.kernel.org/stable/c/75e82e8944ac1efe9fdb88bd2f14d9a031282bdf"
},
{
"url": "https://git.kernel.org/stable/c/0060ec912292a550198d8d18ac95b433c92a7091"
},
{
"url": "https://git.kernel.org/stable/c/5ecfcd5c05866f185357700b81b461dae4f5ebb2"
},
{
"url": "https://git.kernel.org/stable/c/937d61f86d377a3aa578adae7a3dfcecdddf9d89"
}
],
"title": "libceph: refresh auth-\u003eauthorizer_buf{,_len} after authorizer update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68156",
"datePublished": "2026-08-10T11:59:22.514Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:25.089Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68350 (GCVE-0-2026-68350)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: fix OOB read from off-by-two in TX status handler
The bounds check in carl9170_tx_process_status() uses
`i > ((cmd->hdr.len / 2) + 1)` which is off by two, allowing
2 extra iterations past valid _tx_status entries when the firmware-
controlled hdr.ext exceeds hdr.len/2. Fix by using the correct
comparison `i >= (cmd->hdr.len / 2)`.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/tx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9bf8d8510b7bed20320dead0f8cdcf8e610ec8db",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "2c030c20f112bd8f6aa59d09501835605f01bf9d",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "73462e8e602047a03e538d971a79ad67a4ba9a5d",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "7ed0dce8613c92111d2a3836ced2ab03190ba20e",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "e8a862a3da457ddc50633c346dc645d559da09ae",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "fab6ff91d5b8c4af62e2ced42fb357fa3eb9fd59",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "423c836f934814b8fdbe53b24a79d021a0ee8454",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "a3f42f1049ad80c65560d2b078ad426c3134f78d",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/tx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: fix OOB read from off-by-two in TX status handler\n\nThe bounds check in carl9170_tx_process_status() uses\n`i \u003e ((cmd-\u003ehdr.len / 2) + 1)` which is off by two, allowing\n2 extra iterations past valid _tx_status entries when the firmware-\ncontrolled hdr.ext exceeds hdr.len/2. Fix by using the correct\ncomparison `i \u003e= (cmd-\u003ehdr.len / 2)`."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:50.606Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9bf8d8510b7bed20320dead0f8cdcf8e610ec8db"
},
{
"url": "https://git.kernel.org/stable/c/2c030c20f112bd8f6aa59d09501835605f01bf9d"
},
{
"url": "https://git.kernel.org/stable/c/73462e8e602047a03e538d971a79ad67a4ba9a5d"
},
{
"url": "https://git.kernel.org/stable/c/7ed0dce8613c92111d2a3836ced2ab03190ba20e"
},
{
"url": "https://git.kernel.org/stable/c/e8a862a3da457ddc50633c346dc645d559da09ae"
},
{
"url": "https://git.kernel.org/stable/c/fab6ff91d5b8c4af62e2ced42fb357fa3eb9fd59"
},
{
"url": "https://git.kernel.org/stable/c/423c836f934814b8fdbe53b24a79d021a0ee8454"
},
{
"url": "https://git.kernel.org/stable/c/a3f42f1049ad80c65560d2b078ad426c3134f78d"
}
],
"title": "wifi: carl9170: fix OOB read from off-by-two in TX status handler",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68350",
"datePublished": "2026-08-10T12:03:27.314Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:50.606Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68252 (GCVE-0-2026-68252)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit 9723a8bed3aa251a26bee4583bac9d8fb064dd44)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v7_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "395bf099ef7153227600a2d8cb087f45c4a277b6",
"status": "affected",
"version": "b412351e91bde3a6ec546b598087bdc3fcc458ee",
"versionType": "git"
},
{
"lessThan": "4c09483325360373656214cc7a2fd29dc73037a5",
"status": "affected",
"version": "b412351e91bde3a6ec546b598087bdc3fcc458ee",
"versionType": "git"
},
{
"lessThan": "bcbd53d25da879bbce75faad9888c9a56e942fec",
"status": "affected",
"version": "b412351e91bde3a6ec546b598087bdc3fcc458ee",
"versionType": "git"
},
{
"lessThan": "e80e28f398f5d9f6e361ffb56382d2e74fc87556",
"status": "affected",
"version": "b412351e91bde3a6ec546b598087bdc3fcc458ee",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v7_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit 9723a8bed3aa251a26bee4583bac9d8fb064dd44)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:52.977Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/395bf099ef7153227600a2d8cb087f45c4a277b6"
},
{
"url": "https://git.kernel.org/stable/c/4c09483325360373656214cc7a2fd29dc73037a5"
},
{
"url": "https://git.kernel.org/stable/c/bcbd53d25da879bbce75faad9888c9a56e942fec"
},
{
"url": "https://git.kernel.org/stable/c/e80e28f398f5d9f6e361ffb56382d2e74fc87556"
}
],
"title": "drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68252",
"datePublished": "2026-08-10T12:01:18.379Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-18T06:55:52.977Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68158 (GCVE-0-2026-68158)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix multiplication overflow in decode_new_up_state_weight()
If a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted
osdmap, out-of-bounds memory accesses may occur in
decode_new_up_state_weight(). This happens because the bounds check for
the new_state part is based on calculating its length depending on a len
value read from the incoming message. This calculation may overflow
leading to an incorrect bounds check. Subsequently, out-of-bounds reads
may occur when decoding this part.
This patch switches the multiplication to use check_mul_overflow() to
abort processing the osdmap if an overflow occurred. Therefore,
osdmaps/messages containing large values for len that result in a
multiplication overflow are treated as invalid.
[ idryomov: rename new_state_len -> new_state_item_size, formatting ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 1196c36fd53c3b1615eb02f986cb727b1dfc1047 Version: bbc3aa6b0e6050b2b2e04a08dd4d6423d576b196 Version: 6b96b2d473701b45df3fea8dd9796b6ec39e6d54 Version: 7405d73cea0d0e6c541f5c534078feeb46188844 Version: 8777c9f654637d56f4c4ca54eb1bc7c609b70085 Version: 6831c98ce0b8a3e88db64aa224372effd0dcc694 Version: 032951d32c13b7564dfba82758260cb7aa1149d2 Version: 14877928f10667a5606383885d004f7185f33718 Version: 3.10.103 ≤ Version: 3.12.63 ≤ Version: 3.14.75 ≤ Version: 3.16.39 ≤ Version: 3.18.39 ≤ Version: 4.1.30 ≤ Version: 4.4.17 ≤ Version: 4.6.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2ceee3b77b83052648c40fef965f836fd7699d26",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "e4473751cc37db41f3f7da25d64a23e0c74570f1",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "f6961070c326bd158c38fa48756cde2bd78c4aaa",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "05c90e059269f087becfcce23348496085835c29",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "143ba49ead77ec483c0326f8aaad8649874e99c4",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "1732d89dfcd74f6fde9ce70900d316c4a151c153",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "bee4b5b53e7bff0467fd916cc44c9b190733c6bd",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "98917a499ec7064c14fc56d180a4fd636fc2784c",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"status": "affected",
"version": "1196c36fd53c3b1615eb02f986cb727b1dfc1047",
"versionType": "git"
},
{
"status": "affected",
"version": "bbc3aa6b0e6050b2b2e04a08dd4d6423d576b196",
"versionType": "git"
},
{
"status": "affected",
"version": "6b96b2d473701b45df3fea8dd9796b6ec39e6d54",
"versionType": "git"
},
{
"status": "affected",
"version": "7405d73cea0d0e6c541f5c534078feeb46188844",
"versionType": "git"
},
{
"status": "affected",
"version": "8777c9f654637d56f4c4ca54eb1bc7c609b70085",
"versionType": "git"
},
{
"status": "affected",
"version": "6831c98ce0b8a3e88db64aa224372effd0dcc694",
"versionType": "git"
},
{
"status": "affected",
"version": "032951d32c13b7564dfba82758260cb7aa1149d2",
"versionType": "git"
},
{
"status": "affected",
"version": "14877928f10667a5606383885d004f7185f33718",
"versionType": "git"
},
{
"lessThan": "3.11",
"status": "affected",
"version": "3.10.103",
"versionType": "semver"
},
{
"lessThan": "3.13",
"status": "affected",
"version": "3.12.63",
"versionType": "semver"
},
{
"lessThan": "3.15",
"status": "affected",
"version": "3.14.75",
"versionType": "semver"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.39",
"versionType": "semver"
},
{
"lessThan": "3.19",
"status": "affected",
"version": "3.18.39",
"versionType": "semver"
},
{
"lessThan": "4.2",
"status": "affected",
"version": "4.1.30",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.17",
"versionType": "semver"
},
{
"lessThan": "4.7",
"status": "affected",
"version": "4.6.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.10.103",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.12.63",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.14.75",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.18.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.1.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix multiplication overflow in decode_new_up_state_weight()\n\nIf a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted\nosdmap, out-of-bounds memory accesses may occur in\ndecode_new_up_state_weight(). This happens because the bounds check for\nthe new_state part is based on calculating its length depending on a len\nvalue read from the incoming message. This calculation may overflow\nleading to an incorrect bounds check. Subsequently, out-of-bounds reads\nmay occur when decoding this part.\n\nThis patch switches the multiplication to use check_mul_overflow() to\nabort processing the osdmap if an overflow occurred. Therefore,\nosdmaps/messages containing large values for len that result in a\nmultiplication overflow are treated as invalid.\n\n[ idryomov: rename new_state_len -\u003e new_state_item_size, formatting ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Malformed incremental osdmap data is delivered in CEPH_MSG_OSD_MAP over TCP from a Ceph monitor (mon_dispatch) or OSD (osd_dispatch) to libceph clients (CephFS/RBD), and the overflow is triggered while decoding received network bytes in osdmap_apply_incremental().\nAC:L - A compromised or attacker-controlled monitor/OSD can publish an incremental osdmap with epoch N+1 and a crafted new_state length that wraps the multiply, reliably bypassing bounds checks without races or victim-specific memory layout.\nPR:N - Exploitation requires no privileges on the victim host; a malicious cluster peer or on-path attacker that can deliver forged osdmaps to an already-connected kernel Ceph client needs no local account, capabilities, or user-namespace tricks.\nUI:N - Once a host is a Ceph client, osdmap subscriptions and updates are applied automatically by the kernel; no additional mount, open, or interactive step is needed at exploit time beyond the existing client session.\nS:U - Impact is confined to kernel memory and libceph client state on the Ceph client host (info leak, map corruption, crash, or privilege escalation); it does not cross VM, IOMMU, or sandbox boundaries to another security authority.\nC:H - Integer-overflow bypass lets decode_new_up_state_weight() run bare ceph_decode_32/8 loops past the message end, performing out-of-bounds reads of adjacent kernel heap/slack memory that can disclose pointers and other sensitive data.\nI:H - Misaligned decoding also drives attacker-controlled osd/xorstate/weight values into map-\u003eosd_weight[], map-\u003eosd_state[], and map-\u003eosd_addr[] updates (including memset), corrupting kernel osdmap state in ways usable for further exploitation.\nA:H - Unbounded out-of-bounds reads while parsing osdmaps can fault on unmapped pages and trigger kernel oops/panic; map corruption can also cause persistent client failure, repeatable on each malicious incremental map."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:30.014Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2ceee3b77b83052648c40fef965f836fd7699d26"
},
{
"url": "https://git.kernel.org/stable/c/e4473751cc37db41f3f7da25d64a23e0c74570f1"
},
{
"url": "https://git.kernel.org/stable/c/f6961070c326bd158c38fa48756cde2bd78c4aaa"
},
{
"url": "https://git.kernel.org/stable/c/05c90e059269f087becfcce23348496085835c29"
},
{
"url": "https://git.kernel.org/stable/c/143ba49ead77ec483c0326f8aaad8649874e99c4"
},
{
"url": "https://git.kernel.org/stable/c/1732d89dfcd74f6fde9ce70900d316c4a151c153"
},
{
"url": "https://git.kernel.org/stable/c/bee4b5b53e7bff0467fd916cc44c9b190733c6bd"
},
{
"url": "https://git.kernel.org/stable/c/98917a499ec7064c14fc56d180a4fd636fc2784c"
}
],
"title": "libceph: Fix multiplication overflow in decode_new_up_state_weight()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68158",
"datePublished": "2026-08-10T11:59:24.675Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:30.014Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68157 (GCVE-0-2026-68157)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: guard missing CRUSH type name lookup
Localized read selection can walk a parent bucket whose name exists in
the CRUSH map while its type has no matching entry in type_names.
get_immediate_parent() then dereferences a NULL type_cn and passes an
invalid pointer into strcmp(), causing a null-ptr-deref.
Skip such malformed parent buckets unless both the bucket name and type
name metadata are present. This keeps malformed hierarchy data from
crashing locality lookup and safely falls back to "not local".
[ idryomov: add WARN_ON_ONCE ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cbfcba275326c8c7dae9acd8f4a0d4c316fdafb0",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "8ff579ac03d6e9d17d6d9c8443110167c14a382d",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "6a4b75d90f0cfbf22c14742ab35a803bc13f36ec",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "c46d82c47afc968d6ee8ef4470fa2dd35b765c21",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "3767c9f0c1bbd98dd25cb088356a0fc6c1f09f50",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "4716a64b7cc2797741f7be4e283ace78a9dff37d",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "db9cc9fd9660b2d69ee66f5a4cbec83c21a1c64d",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "bbeae12fda3384a90fbebc8a19ba9d33f85b5361",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: guard missing CRUSH type name lookup\n\nLocalized read selection can walk a parent bucket whose name exists in\nthe CRUSH map while its type has no matching entry in type_names.\nget_immediate_parent() then dereferences a NULL type_cn and passes an\ninvalid pointer into strcmp(), causing a null-ptr-deref.\n\nSkip such malformed parent buckets unless both the bucket name and type\nname metadata are present. This keeps malformed hierarchy data from\ncrashing locality lookup and safely falls back to \"not local\".\n\n[ idryomov: add WARN_ON_ONCE ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Malformed CRUSH hierarchy data is delivered to the kernel Ceph client in CEPH_MSG_OSD_MAP over TCP from a monitor or OSD peer, stored in libceph, and later triggers get_immediate_parent() during localized-read target selection on RBD/CephFS client I/O.\nAC:L - A compromised or attacker-controlled Ceph monitor can publish an osdmap whose CRUSH buckets have names but missing type_names entries; once applied, the NULL dereference is reliably hit on subsequent localize-read calc_target() paths without further attacker-controlled timing.\nPR:N - Exploitation requires no privileges on the victim host; any machine acting as a kernel Ceph client that receives a forged osdmap from a cluster peer over the network can be attacked without local capabilities or user-namespace tricks.\nUI:N - No victim user action is needed at exploitation time beyond the host already being a Ceph client with localized reads enabled; forged osdmaps are applied automatically and the crash fires on subsequent kernel client read or map-rescan operations.\nS:U - Impact is confined to kernel memory on the Ceph client host (crash or potential escalation within that host); it does not cross VM, IOMMU, or sandbox boundaries to other security authorities.\nC:N - The failure is a NULL pointer dereference when accessing type_cn-\u003ecn_name; there is no out-of-bounds read, use-after-free, or other memory corruption that could disclose kernel data.\nI:N - The bug causes a NULL pointer dereference crash only; no attacker-controlled write, heap corruption, or control-flow hijack primitive is created by this defect.\nA:H - The NULL pointer dereference in get_immediate_parent() during CRUSH locality lookup causes a kernel oops or panic, denying all service on the affected Ceph client host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:27.540Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cbfcba275326c8c7dae9acd8f4a0d4c316fdafb0"
},
{
"url": "https://git.kernel.org/stable/c/8ff579ac03d6e9d17d6d9c8443110167c14a382d"
},
{
"url": "https://git.kernel.org/stable/c/6a4b75d90f0cfbf22c14742ab35a803bc13f36ec"
},
{
"url": "https://git.kernel.org/stable/c/c46d82c47afc968d6ee8ef4470fa2dd35b765c21"
},
{
"url": "https://git.kernel.org/stable/c/3767c9f0c1bbd98dd25cb088356a0fc6c1f09f50"
},
{
"url": "https://git.kernel.org/stable/c/4716a64b7cc2797741f7be4e283ace78a9dff37d"
},
{
"url": "https://git.kernel.org/stable/c/db9cc9fd9660b2d69ee66f5a4cbec83c21a1c64d"
},
{
"url": "https://git.kernel.org/stable/c/bbeae12fda3384a90fbebc8a19ba9d33f85b5361"
}
],
"title": "libceph: guard missing CRUSH type name lookup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68157",
"datePublished": "2026-08-10T11:59:23.692Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:27.540Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64296 (GCVE-0-2026-64296)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
exfat: bound uniname advance in exfat_find_dir_entry()
In exfat_find_dir_entry(), each TYPE_EXTEND (file name) entry advances the
output pointer by a fixed amount while the loop guard only tracks the
accumulated name length:
if (++order == 2)
uniname = p_uniname->name;
else
uniname += EXFAT_FILE_NAME_LEN;
len = exfat_extract_uni_name(ep, entry_uniname);
name_len += len;
unichar = *(uniname+len);
*(uniname+len) = 0x0;
uniname grows by EXFAT_FILE_NAME_LEN (15) per name entry, but name_len
grows only by the actual extracted length, which is shorter when a name
fragment contains an early NUL. The only guard is
`name_len >= MAX_NAME_LENGTH`, so a crafted directory with many short
name fragments lets uniname run far past the
p_uniname->name[MAX_NAME_LENGTH + 3] buffer while name_len stays small,
causing an out-of-bounds read and write at *(uniname+len).
The sibling extractor exfat_get_uniname_from_ext_entry() already stops
on a short fragment (the lockstep `len != EXFAT_FILE_NAME_LEN` guard
added in commit d42334578eba ("exfat: check if filename entries exceeds
max filename length")); exfat_find_dir_entry() never got the
equivalent. Track the per-entry write offset as a count and reject a
fragment once the offset, or the offset plus the extracted length, would
exceed MAX_NAME_LENGTH, before forming the output pointer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 Version: ca06197382bde0a3bc20215595d1c9ce20c6e341 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/exfat/dir.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "72a2589d82eb001c94b74bcfe6f9a599bd9bef60",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "fae76a94b35ee8c0e2eb6f64caca01d75c6d34e4",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "cf85180b8a015029ee147694eaf4e0b3537e9432",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "ce4736c1e6c4cfbf1ac409a8c328a0b69546c9a0",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "727bf7783a2936ffd55c628dddfd69343e511dcf",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "33c0b96d7e1672be1de0053786637ea46fb81507",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "c8e041c68c0bbb73aa62371ee63947bb6949d8b2",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
},
{
"lessThan": "3a1230e7b043c62737b05a3e9275ca83a43ad20a",
"status": "affected",
"version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/exfat/dir.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: bound uniname advance in exfat_find_dir_entry()\n\nIn exfat_find_dir_entry(), each TYPE_EXTEND (file name) entry advances the\noutput pointer by a fixed amount while the loop guard only tracks the\naccumulated name length:\n\n\tif (++order == 2)\n\t\tuniname = p_uniname-\u003ename;\n\telse\n\t\tuniname += EXFAT_FILE_NAME_LEN;\n\tlen = exfat_extract_uni_name(ep, entry_uniname);\n\tname_len += len;\n\tunichar = *(uniname+len);\n\t*(uniname+len) = 0x0;\n\nuniname grows by EXFAT_FILE_NAME_LEN (15) per name entry, but name_len\ngrows only by the actual extracted length, which is shorter when a name\nfragment contains an early NUL. The only guard is\n`name_len \u003e= MAX_NAME_LENGTH`, so a crafted directory with many short\nname fragments lets uniname run far past the\np_uniname-\u003ename[MAX_NAME_LENGTH + 3] buffer while name_len stays small,\ncausing an out-of-bounds read and write at *(uniname+len).\n\nThe sibling extractor exfat_get_uniname_from_ext_entry() already stops\non a short fragment (the lockstep `len != EXFAT_FILE_NAME_LEN` guard\nadded in commit d42334578eba (\"exfat: check if filename entries exceeds\nmax filename length\")); exfat_find_dir_entry() never got the\nequivalent. Track the per-entry write offset as a count and reject a\nfragment once the offset, or the offset plus the extracted length, would\nexceed MAX_NAME_LENGTH, before forming the output pointer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - A crafted exFAT image is reached through local pathname operations such as openat(), which call exfat_lookup(), exfat_find(), and exfat_find_dir_entry(); loop-backed images make physical access unnecessary.\nAC:L - The attacker controls the stream hash, declared name length, extension-entry sequence, and early NUL characters, making the out-of-bounds access deterministic without a race or uncontrollable condition.\nPR:L - Although exFAT cannot be mounted directly from a user namespace, common storage brokers allow an active unprivileged user to mount a loop-backed non-system image. Once mounted, triggering lookup requires only ordinary directory search access and no capability.\nUI:N - The unprivileged attacker can mount the crafted image through such a storage broker and issue the triggering pathname lookup without another user\u0027s action.\nS:U - The vulnerable filesystem parser and the affected kernel memory belong to the same security authority; ordinary kernel privilege escalation does not change scope.\nC:H - Crafted entries cause repeated out-of-bounds 16-bit reads across the kernel stack, and filename comparison behavior can provide an oracle over attacker-selected stack locations. Successful control-flow corruption could disclose arbitrary kernel memory.\nI:H - The function writes zero beyond the stack buffer, and the successful-match path can jump to found without restoring the overwritten value. Attacker-selected stack control data or pointers can therefore be corrupted, potentially enabling arbitrary writes or kernel code execution.\nA:H - Zero-length fragments can advance the pointer until it reaches a stack guard page or corrupts control data, causing an oops, panic, or persistent lockup."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:53.790Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/72a2589d82eb001c94b74bcfe6f9a599bd9bef60"
},
{
"url": "https://git.kernel.org/stable/c/fae76a94b35ee8c0e2eb6f64caca01d75c6d34e4"
},
{
"url": "https://git.kernel.org/stable/c/cf85180b8a015029ee147694eaf4e0b3537e9432"
},
{
"url": "https://git.kernel.org/stable/c/ce4736c1e6c4cfbf1ac409a8c328a0b69546c9a0"
},
{
"url": "https://git.kernel.org/stable/c/727bf7783a2936ffd55c628dddfd69343e511dcf"
},
{
"url": "https://git.kernel.org/stable/c/33c0b96d7e1672be1de0053786637ea46fb81507"
},
{
"url": "https://git.kernel.org/stable/c/c8e041c68c0bbb73aa62371ee63947bb6949d8b2"
},
{
"url": "https://git.kernel.org/stable/c/3a1230e7b043c62737b05a3e9275ca83a43ad20a"
}
],
"title": "exfat: bound uniname advance in exfat_find_dir_entry()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64296",
"datePublished": "2026-07-25T08:49:33.847Z",
"dateReserved": "2026-07-19T15:36:31.778Z",
"dateUpdated": "2026-08-17T04:52:53.790Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52946 (GCVE-0-2026-52946)
Vulnerability from cvelistv5
Published
2026-06-24 16:26
Modified
2026-09-08 08:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
A SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in
send_sigio() and send_sigurg() when a process group receives a signal.
When FASYNC is configured for a process group (PIDTYPE_PGID), both
functions use read_lock(&tasklist_lock) to traverse the task list.
However, they are frequently called from softirq context:
- send_sigio() via input_inject_event -> kill_fasync
- send_sigurg() via tcp_check_urg -> sk_send_sigurg (NET_RX_SOFTIRQ)
The deadlock is caused by the rwlock writer fairness mechanism:
1. CPU 0 (process context) holds read_lock(&tasklist_lock) in do_wait().
2. CPU 1 (process context) attempts write_lock(&tasklist_lock) in
fork() or exit() and spins, which blocks all new readers.
3. CPU 0 is interrupted by a softirq (e.g., TCP URG packet reception).
4. The softirq calls send_sigurg() and attempts to acquire
read_lock(&tasklist_lock), deadlocking because CPU 1 is waiting.
Since PID hashing and do_each_pid_task() traversals are already
RCU-protected, the read_lock on tasklist_lock is no longer strictly
required for safe traversal. Fix this by replacing tasklist_lock with
rcu_read_lock(), aligning the process group signaling path with the
single-PID path. This also mitigates a potential remote denial of
service vector via TCP URG packets.
Lockdep splat:
=====================================================
WARNING: SOFTIRQ-safe -> SOFTIRQ-unsafe lock order detected
[...]
Chain exists of:
&dev->event_lock --> &f_owner->lock --> tasklist_lock
Possible interrupt unsafe locking scenario:
CPU0 CPU1
---- ----
lock(tasklist_lock);
local_irq_disable();
lock(&dev->event_lock);
lock(&f_owner->lock);
<Interrupt>
lock(&dev->event_lock);
*** DEADLOCK ***
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:49:46.963Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/fcntl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "54626335ea4174ab2d9a183b511d825f6765e47b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "897d6a7247739fb1528f98c575df4f2e5de7f994",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "32dbd5ce4be3a3ed7e00f8af18795cc84fc50a33",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b5fa9e32fb6718f70c986ee14dd5d01b4846f331",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1bee417678f1135e35b25a37734db46aa94258d2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "20a93e397abe850c49b6fa0e8cc827b5f634a8f5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "bfcc8e8d8a495bb34cae9e620adfb75fb13a3954",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "36c1b57b2ecf3c61ac93f5f07bd29b6f21e226ed",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "00633c4683828acd5256fa8d5163f440d74bbe71",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/fcntl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling\n\nA SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in\nsend_sigio() and send_sigurg() when a process group receives a signal.\n\nWhen FASYNC is configured for a process group (PIDTYPE_PGID), both\nfunctions use read_lock(\u0026tasklist_lock) to traverse the task list.\nHowever, they are frequently called from softirq context:\n- send_sigio() via input_inject_event -\u003e kill_fasync\n- send_sigurg() via tcp_check_urg -\u003e sk_send_sigurg (NET_RX_SOFTIRQ)\n\nThe deadlock is caused by the rwlock writer fairness mechanism:\n1. CPU 0 (process context) holds read_lock(\u0026tasklist_lock) in do_wait().\n2. CPU 1 (process context) attempts write_lock(\u0026tasklist_lock) in\n fork() or exit() and spins, which blocks all new readers.\n3. CPU 0 is interrupted by a softirq (e.g., TCP URG packet reception).\n4. The softirq calls send_sigurg() and attempts to acquire\n read_lock(\u0026tasklist_lock), deadlocking because CPU 1 is waiting.\n\nSince PID hashing and do_each_pid_task() traversals are already\nRCU-protected, the read_lock on tasklist_lock is no longer strictly\nrequired for safe traversal. Fix this by replacing tasklist_lock with\nrcu_read_lock(), aligning the process group signaling path with the\nsingle-PID path. This also mitigates a potential remote denial of\nservice vector via TCP URG packets.\n\nLockdep splat:\n=====================================================\nWARNING: SOFTIRQ-safe -\u003e SOFTIRQ-unsafe lock order detected\n[...]\nChain exists of:\n \u0026dev-\u003eevent_lock --\u003e \u0026f_owner-\u003elock --\u003e tasklist_lock\n\nPossible interrupt unsafe locking scenario:\n CPU0 CPU1\n ---- ----\n lock(tasklist_lock);\n local_irq_disable();\n lock(\u0026dev-\u003eevent_lock);\n lock(\u0026f_owner-\u003elock);\n \u003cInterrupt\u003e\n lock(\u0026dev-\u003eevent_lock);\n\n*** DEADLOCK ***"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A remote TCP peer can reach tcp_check_urg()-\u003esk_send_sigurg()-\u003esend_sigurg() by sending TCP packets with the URG flag to a service whose socket owner is configured as a process group. The fix explicitly identifies TCP URG packet reception as a potential remote denial-of-service vector.\nAC:L - The vulnerable condition is a lock-order deadlock, but an attacker can repeatedly send URG packets and, in a plausible forking/waiting network service, induce connection churn that exercises the other tasklist_lock paths. There is no memory-layout dependency or other hard-to-satisfy condition.\nPR:N - The network attacker does not need local privileges or authentication to send TCP URG traffic to an exposed service. The fcntl process-group ownership is target service state, not an attacker privilege requirement.\nUI:N - Exploitation does not require a user to open a file or perform an interactive action. Once the service is reachable and configured, packets alone can trigger the vulnerable path.\nS:U - The impact is within the Linux kernel and the same host security authority. It does not cross a VM, sandbox, or hardware isolation boundary.\nC:N - The bug is a lock ordering deadlock, not a memory disclosure or use-after-free. The fixed traversal is RCU-safe and does not imply an attacker read primitive.\nI:N - The vulnerability does not corrupt memory or provide a write/control-flow primitive. It only causes unsafe lock acquisition ordering during signal delivery.\nA:H - The deadlock can hang kernel execution in softirq/tasklist_lock paths and deny service to the affected system. A kernel deadlock is a high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:50:23.794Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/54626335ea4174ab2d9a183b511d825f6765e47b"
},
{
"url": "https://git.kernel.org/stable/c/897d6a7247739fb1528f98c575df4f2e5de7f994"
},
{
"url": "https://git.kernel.org/stable/c/32dbd5ce4be3a3ed7e00f8af18795cc84fc50a33"
},
{
"url": "https://git.kernel.org/stable/c/b5fa9e32fb6718f70c986ee14dd5d01b4846f331"
},
{
"url": "https://git.kernel.org/stable/c/1bee417678f1135e35b25a37734db46aa94258d2"
},
{
"url": "https://git.kernel.org/stable/c/20a93e397abe850c49b6fa0e8cc827b5f634a8f5"
},
{
"url": "https://git.kernel.org/stable/c/bfcc8e8d8a495bb34cae9e620adfb75fb13a3954"
},
{
"url": "https://git.kernel.org/stable/c/36c1b57b2ecf3c61ac93f5f07bd29b6f21e226ed"
},
{
"url": "https://git.kernel.org/stable/c/00633c4683828acd5256fa8d5163f440d74bbe71"
}
],
"title": "fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52946",
"datePublished": "2026-06-24T16:26:04.419Z",
"dateReserved": "2026-06-09T07:44:35.371Z",
"dateUpdated": "2026-09-08T08:49:46.963Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72035 (GCVE-0-2026-72035)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked
When taprio's software path peeks a non-work-conserving child qdisc, the
child stashes the peeked skb in its gso_skb; taprio_dequeue_from_txq()
then takes the packet with a direct child ->dequeue() call, which ignores
that stash, orphans the peeked skb and desyncs the child's qlen/backlog.
With a qfq child this re-enters the child on an emptied list and
dereferences NULL, panicking the kernel from softirq on ordinary egress.
Take the packet through qdisc_dequeue_peeked(), as sch_red and sch_sfb
now do. The helper returns the child's stashed skb first and is a no-op
when there is none, so a work-conserving child is unaffected and the
gated path now consumes the skb whose length was charged to the budget.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/sch_taprio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "51f8af240aed903e988755af33d7491030b50ae9",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "17ab5f76f3899f67e5569722f334591f4b88b17b",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "f60d5c12e0551012cee5c272b0bcbcc78f7bb506",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "6ee5a7665a9080bcb05d703bf981a579436fd05e",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "18d580cb00c55805633bae45e90cf22ed6b8e424",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "e2b7ee61989f2d39df6c2cc06f9db1aea69bdb09",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "2dcebbd1ad2e180fe7b98bf346ced69a872e11e6",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "e056e1dfcddca877dd46d704e8ec9860cfc9ec44",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/sch_taprio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked\n\nWhen taprio\u0027s software path peeks a non-work-conserving child qdisc, the\nchild stashes the peeked skb in its gso_skb; taprio_dequeue_from_txq()\nthen takes the packet with a direct child -\u003edequeue() call, which ignores\nthat stash, orphans the peeked skb and desyncs the child\u0027s qlen/backlog.\nWith a qfq child this re-enters the child on an emptied list and\ndereferences NULL, panicking the kernel from softirq on ordinary egress.\n\nTake the packet through qdisc_dequeue_peeked(), as sch_red and sch_sfb\nnow do. The helper returns the child\u0027s stashed skb first and is a no-op\nwhen there is none, so a work-conserving child is unaffected and the\ngated path now consumes the skb whose length was charged to the budget."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The fault is in taprio\u0027s software egress dequeue path (`__dev_queue_xmit` \u2192 `__qdisc_run` \u2192 `taprio_dequeue` \u2192 `taprio_dequeue_from_txq`) during ordinary packet transmission in softirq; on TSN/automotive/industrial gateways where taprio+qfq is already deployed, any remote peer can trigger it by sending traffic that causes egress through the gated queues.\nAC:L - Once taprio is configured with a non-work-conserving child such as qfq on the software path (no full offload, TXTIME_ASSIST disabled), peek followed by the incorrect direct `dequeue()` deterministically orphans the stashed skb, desyncs qlen/backlog, and re-enters qfq on an emptied list; the attacker fully controls triggering traffic with no uncontrollable races.\nPR:N - Installing taprio and grafting a qfq child requires CAP_NET_ADMIN via RTM_NEWQDISC, but on reasonably deployed TSN/industrial systems where operators have already configured this stack, triggering the bug requires only the ability to send packets through the affected interface\u2014no credentials or capabilities on the victim host.\nUI:N - Exploitation needs only attacker-generated network traffic (or any local sender) once the qdisc hierarchy exists; no victim login, mount, file open, or other interactive action is required at trigger time.\nS:U - The NULL dereference kernel panic and qdisc qlen/backlog corruption occur entirely within the host kernel\u0027s security authority; this is not a VM escape, container breakout, or IOMMU/DMA boundary bypass.\nC:N - The published failure mode is a NULL pointer dereference in qfq after taprio mishandles the peek stash; although the peeked skb is orphaned and child counters desync, there is no use-after-free, out-of-bounds read, or demonstrated arbitrary kernel memory disclosure primitive.\nI:L - Calling `child-\u003eops-\u003edequeue()` instead of `qdisc_dequeue_peeked()` orphans the peek-stashed skb and corrupts the child qdisc\u0027s qlen/backlog accounting before the fatal qfq re-entry, enabling attacker-driven mis-accounting of queued traffic on the affected egress path prior to panic.\nA:H - With a qfq child the desynchronized dequeue path dereferences NULL from softirq during ordinary egress, panicking the kernel; the condition is repeatable whenever gated transmission exercises the peek/dequeue mismatch, causing total host availability loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:29.870Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/51f8af240aed903e988755af33d7491030b50ae9"
},
{
"url": "https://git.kernel.org/stable/c/17ab5f76f3899f67e5569722f334591f4b88b17b"
},
{
"url": "https://git.kernel.org/stable/c/f60d5c12e0551012cee5c272b0bcbcc78f7bb506"
},
{
"url": "https://git.kernel.org/stable/c/6ee5a7665a9080bcb05d703bf981a579436fd05e"
},
{
"url": "https://git.kernel.org/stable/c/18d580cb00c55805633bae45e90cf22ed6b8e424"
},
{
"url": "https://git.kernel.org/stable/c/e2b7ee61989f2d39df6c2cc06f9db1aea69bdb09"
},
{
"url": "https://git.kernel.org/stable/c/2dcebbd1ad2e180fe7b98bf346ced69a872e11e6"
},
{
"url": "https://git.kernel.org/stable/c/e056e1dfcddca877dd46d704e8ec9860cfc9ec44"
}
],
"title": "net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72035",
"datePublished": "2026-08-15T05:51:56.374Z",
"dateReserved": "2026-08-09T03:40:39.901Z",
"dateUpdated": "2026-08-23T12:46:29.870Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53388 (GCVE-0-2026-53388)
Vulnerability from cvelistv5
Published
2026-07-19 11:59
Modified
2026-08-17 04:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fuse: re-lock request before replacing page cache folio
fuse_try_move_folio() unlocks the request on entry but does not
re-lock it on the success path. This means fuse_chan_abort() can end the
request and free the fuse_io_args (eg fuse_readpages_end()) while the
subsequent copy chain logic after fuse_try_move_folio() accesses the
fuse_io_args, leading to use-after-free issues.
Fix this by calling lock_request() before replace_page_cache_folio().
This ensures the request is locked on the success path which will
prevent the fuse_io_args from being freed while the later copying logic
runs, and also ensures that the ap->folios[i]->mapping is never null
since ap->folios[i] will always point to the newfolio after
replace_page_cache_folio().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ce534fb052928ce556639d7ecf01cbf4e01321e1 Version: ce534fb052928ce556639d7ecf01cbf4e01321e1 Version: ce534fb052928ce556639d7ecf01cbf4e01321e1 Version: ce534fb052928ce556639d7ecf01cbf4e01321e1 Version: ce534fb052928ce556639d7ecf01cbf4e01321e1 Version: ce534fb052928ce556639d7ecf01cbf4e01321e1 Version: ce534fb052928ce556639d7ecf01cbf4e01321e1 Version: ce534fb052928ce556639d7ecf01cbf4e01321e1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/fuse/dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7c18691e0cfda29672f79bafde8abdb7710674f6",
"status": "affected",
"version": "ce534fb052928ce556639d7ecf01cbf4e01321e1",
"versionType": "git"
},
{
"lessThan": "5927b43a4f8d89e86930f524bf63e9c7e66f61b4",
"status": "affected",
"version": "ce534fb052928ce556639d7ecf01cbf4e01321e1",
"versionType": "git"
},
{
"lessThan": "030fe3e9d8abdee303dd7e9e42f45082d382a407",
"status": "affected",
"version": "ce534fb052928ce556639d7ecf01cbf4e01321e1",
"versionType": "git"
},
{
"lessThan": "46473ddccdc5065033e397d6e62c280dbcd3d9c2",
"status": "affected",
"version": "ce534fb052928ce556639d7ecf01cbf4e01321e1",
"versionType": "git"
},
{
"lessThan": "af2892249d982a1c036ca456cc135374e68b6677",
"status": "affected",
"version": "ce534fb052928ce556639d7ecf01cbf4e01321e1",
"versionType": "git"
},
{
"lessThan": "0223f452532d9cd8a5e87c45de828fd93c99bd25",
"status": "affected",
"version": "ce534fb052928ce556639d7ecf01cbf4e01321e1",
"versionType": "git"
},
{
"lessThan": "e28db6ac4792d065ab32565fd9f0a2361c3d4666",
"status": "affected",
"version": "ce534fb052928ce556639d7ecf01cbf4e01321e1",
"versionType": "git"
},
{
"lessThan": "a078484921052d0badd827fcc2770b5cfc1d4120",
"status": "affected",
"version": "ce534fb052928ce556639d7ecf01cbf4e01321e1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/fuse/dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.35"
},
{
"lessThan": "2.6.35",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.37",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.37",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.14",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.2",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.35",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: re-lock request before replacing page cache folio\n\nfuse_try_move_folio() unlocks the request on entry but does not\nre-lock it on the success path. This means fuse_chan_abort() can end the\nrequest and free the fuse_io_args (eg fuse_readpages_end()) while the\nsubsequent copy chain logic after fuse_try_move_folio() accesses the\nfuse_io_args, leading to use-after-free issues.\n\nFix this by calling lock_request() before replace_page_cache_folio().\nThis ensures the request is locked on the success path which will\nprevent the fuse_io_args from being freed while the later copying logic\nruns, and also ensures that the ap-\u003efolios[i]-\u003emapping is never null\nsince ap-\u003efolios[i] will always point to the newfolio after\nreplace_page_cache_folio()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local syscalls: mounting a FUSE filesystem, reading files to trigger readpages, and the FUSE daemon writing replies to /dev/fuse via splice_write with SPLICE_F_MOVE.\nAC:L - The race is between the attacker\u0027s own splice reply and a concurrent abort they trigger (e.g., via sysfs abort or unmount); the attacker controls both threads and can retry until the window is hit.\nPR:L - Exploitation requires mounting and operating a FUSE filesystem via /dev/fuse, which needs local user privileges; on typical systems this is reachable by unprivileged users via user namespaces (CAP_SYS_ADMIN in a user namespace) without init-namespace root.\nUI:N - No victim interaction is required; the attacker mounts the filesystem, runs the FUSE daemon, and triggers the concurrent abort themselves.\nS:U - Impact is kernel memory corruption and potential local privilege escalation within the same kernel security domain, not a cross-boundary escape such as guest-to-host or sandbox breakout.\nC:H - The vulnerability is a use-after-free of fuse_io_args and associated folio pointers in kernel heap memory, which can be leveraged for arbitrary kernel memory read via heap reuse.\nI:H - Use-after-free of fuse_io_args enables heap spraying and controlled reuse of freed kernel objects, providing a path to arbitrary kernel memory write or code execution.\nA:H - The UAF and the race with folio replacement can cause kernel oops/panic, including NULL pointer dereference when fuse_readpages_end accesses a folio with a NULL mapping."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:50:39.284Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7c18691e0cfda29672f79bafde8abdb7710674f6"
},
{
"url": "https://git.kernel.org/stable/c/5927b43a4f8d89e86930f524bf63e9c7e66f61b4"
},
{
"url": "https://git.kernel.org/stable/c/030fe3e9d8abdee303dd7e9e42f45082d382a407"
},
{
"url": "https://git.kernel.org/stable/c/46473ddccdc5065033e397d6e62c280dbcd3d9c2"
},
{
"url": "https://git.kernel.org/stable/c/af2892249d982a1c036ca456cc135374e68b6677"
},
{
"url": "https://git.kernel.org/stable/c/0223f452532d9cd8a5e87c45de828fd93c99bd25"
},
{
"url": "https://git.kernel.org/stable/c/e28db6ac4792d065ab32565fd9f0a2361c3d4666"
},
{
"url": "https://git.kernel.org/stable/c/a078484921052d0badd827fcc2770b5cfc1d4120"
}
],
"title": "fuse: re-lock request before replacing page cache folio",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53388",
"datePublished": "2026-07-19T11:59:34.456Z",
"dateReserved": "2026-06-09T07:44:35.402Z",
"dateUpdated": "2026-08-17T04:50:39.284Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68209 (GCVE-0-2026-68209)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: sun4i-csi: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
sun4i_csi_start_streaming() returned -EINVAL when no matching CSI
format could be found, before any setup (scratch buffer allocation,
pipeline start) had been performed. The remaining error paths already
converge on the err_clear_dma_queue label, which calls
return_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock. Jump
to that label directly: the intermediate err_disable_device /
err_disable_pipeline / err_free_scratch_buffer labels are skipped,
which is correct because nothing they would undo has happened yet.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "29fce7bcb3b959f6d4fdcdff7d26330152fdf98d",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "7c2c30e282745a83d332c3cf92d1c0bcc491ac54",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "4872161e6fbe4e1783daea8bff79caddfae0fb82",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "a8abecc638a7feb20b78fabd563b05e30c071331",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "b5184b3f0e9d4cc47059ba1138c9a73d43d2493f",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "668face37fdb6b6900645dc8777195498541c9a7",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "bbba3e260a62810a717b4442a3bb96d0ec0f6309",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: sun4i-csi: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nsun4i_csi_start_streaming() returned -EINVAL when no matching CSI\nformat could be found, before any setup (scratch buffer allocation,\npipeline start) had been performed. The remaining error paths already\nconverge on the err_clear_dma_queue label, which calls\nreturn_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi-\u003eqlock. Jump\nto that label directly: the intermediate err_disable_device /\nerr_disable_pipeline / err_free_scratch_buffer labels are skipped,\nwhich is correct because nothing they would undo has happened yet.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through local V4L2 ioctls (VIDIOC_S_FMT, VIDIOC_REQBUFS, VIDIOC_QBUF, VIDIOC_STREAMON) on the sun4i-csi /dev/videoN character device. There is no network, adjacent-network, or remote data path into sun4i_csi_start_streaming().\nAC:L - The attacker deterministically drives the sequence itself: configure the capture format, queue buffers, then issue STREAMON so the driver returns an error after vb2 has already handed the buffers over. No race, timing window, or memory layout outside the attacker\u0027s control is involved, and the sequence can be retried without limit.\nPR:L - sun4i_csi_open() and the entire queue/streamon path perform no capability checks; only an open file descriptor on the video node is needed, which udev grants to the active local user via the video group and 70-uaccess.rules (or the Android CAMERA context). That is ordinary unprivileged local access, not root.\nUI:N - The attacker performs the whole open/S_FMT/QBUF/STREAMON/REQBUFS sequence inside its own process. No victim action, cooperation, or pre-existing session state is required.\nS:U - The damage is confined to kernel heap and sun4i-csi driver state within the same OS security authority. Nothing crosses a hypervisor, IOMMU, or sandbox boundary.\nC:H - Buffers stay linked on csi-\u003ebuf_list after vb2 force-reclaims them, and the list head is only initialized once at probe. A later REQBUFS(0) or close frees those vb2 buffers while the driver still holds pointers, so sun4i_csi_buffer_fill_all()/return_all_buffers() read through freed slab objects the attacker can reclaim and shape, disclosing kernel heap contents.\nI:H - The stale list linkage yields list_add_tail()/list_del() operations on freed nodes, giving a write-what-where style list-corruption primitive, and the DMA fill path writes buffer addresses through the dangling entries. Under conservative memory-corruption scoring this is high integrity impact.\nA:H - The immediate effect is the WARN_ON(owned_by_drv_count) splat in vb2_start_streaming(), which panics on panic_on_warn systems, and the resulting dangling buf_list produces use-after-free oopses or slab corruption on the next streaming attempt or buffer release."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:31.902Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/29fce7bcb3b959f6d4fdcdff7d26330152fdf98d"
},
{
"url": "https://git.kernel.org/stable/c/7c2c30e282745a83d332c3cf92d1c0bcc491ac54"
},
{
"url": "https://git.kernel.org/stable/c/3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a"
},
{
"url": "https://git.kernel.org/stable/c/4872161e6fbe4e1783daea8bff79caddfae0fb82"
},
{
"url": "https://git.kernel.org/stable/c/a8abecc638a7feb20b78fabd563b05e30c071331"
},
{
"url": "https://git.kernel.org/stable/c/b5184b3f0e9d4cc47059ba1138c9a73d43d2493f"
},
{
"url": "https://git.kernel.org/stable/c/668face37fdb6b6900645dc8777195498541c9a7"
},
{
"url": "https://git.kernel.org/stable/c/bbba3e260a62810a717b4442a3bb96d0ec0f6309"
}
],
"title": "media: sun4i-csi: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68209",
"datePublished": "2026-08-10T12:00:28.245Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:31.902Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68320 (GCVE-0-2026-68320)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the
capacity limit for ep->auth_chunk_list, allowing it to hold up to
20 chunk entries (param_hdr.length up to 24). However, the copy
destination asoc->c.auth_chunks in struct sctp_cookie is only
SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16
chunks are added, sctp_association_init() memcpy overflows the
destination by up to 4 bytes.
Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching
the destination capacity.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3d22a7da2e264f407c729f33a0a346ff76108bc6",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "6837c1c19a259518974cbc5a52017646e3906564",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "54bb4c03fa17cdcb157c26c33e60a78cf32960f5",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "5a365f1e423444c5da7eb689a8661633dad43e48",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "886e28e14ab655012779016d251fef53d103aa12",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "11092d79eb2b7c0068382f72fc2416d1786bb2e0",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "b6ea3dda09eb4d5caf7bbc00f857688cf9e98255",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "ff04b26794a16a8a879eb4fd2c02c2d6b03850e9",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid\n\nsctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the\ncapacity limit for ep-\u003eauth_chunk_list, allowing it to hold up to\n20 chunk entries (param_hdr.length up to 24). However, the copy\ndestination asoc-\u003ec.auth_chunks in struct sctp_cookie is only\nSCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16\nchunks are added, sctp_association_init() memcpy overflows the\ndestination by up to 4 bytes.\n\nFix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching\nthe destination capacity."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The overflow condition can only be created locally: an attacker must call setsockopt(SCTP_AUTH_SUPPORTED) and then setsockopt(SCTP_AUTH_CHUNK) more than 16 times on an SCTP socket they own. A remote peer can trigger the memcpy by connecting to such a socket, but cannot itself populate the oversized chunk list.\nAC:L - The sequence is fully deterministic and entirely under attacker control \u2014 enable AUTH, add 17-20 distinct chunk IDs, then create an association via connect() or accept(); no race, timing window, or memory-layout condition is involved.\nPR:L - Creating an IPPROTO_SCTP socket and issuing SCTP_AUTH_SUPPORTED/SCTP_AUTH_CHUNK setsockopts requires no capability; sctp_setsockopt_auth_supported() enables AUTH per-endpoint regardless of the net.sctp.auth_enable sysctl, so any unprivileged local user reaches the bug.\nUI:N - The attacker performs every step from their own process \u2014 socket setup, setsockopt calls, and association establishment \u2014 with no action required from any other user or administrator.\nS:U - The corruption and the over-read are confined to the kernel\u0027s own SCTP association object; no other security authority or privilege domain is crossed.\nC:L - sctp_make_init()/sctp_make_init_ack() copy ntohs(auth_chunks-\u003elength) bytes from the 20-byte field, emitting up to 4 bytes past it (the adjacent raw_addr_list_len) inside the CHUNKS parameter of INIT/INIT-ACK sent to the remote peer \u2014 a real but small, strictly bounded out-of-bounds read.\nI:H - sctp_association_init() writes up to 4 bytes of fully attacker-chosen data (the chunk-ID values) past the end of asoc-\u003ec.auth_chunks into the adjacent kernel struct field, an out-of-bounds write of controlled content into kernel memory.\nA:H - On CONFIG_FORTIFY_SOURCE kernels the memcpy is flagged as a field-spanning write and emits a WARN, which is fatal on the widely used panic_on_warn configurations, and the out-of-bounds write itself corrupts SCTP association state; the trigger is cheap and repeatable by any local user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:10.661Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3d22a7da2e264f407c729f33a0a346ff76108bc6"
},
{
"url": "https://git.kernel.org/stable/c/6837c1c19a259518974cbc5a52017646e3906564"
},
{
"url": "https://git.kernel.org/stable/c/54bb4c03fa17cdcb157c26c33e60a78cf32960f5"
},
{
"url": "https://git.kernel.org/stable/c/5a365f1e423444c5da7eb689a8661633dad43e48"
},
{
"url": "https://git.kernel.org/stable/c/886e28e14ab655012779016d251fef53d103aa12"
},
{
"url": "https://git.kernel.org/stable/c/11092d79eb2b7c0068382f72fc2416d1786bb2e0"
},
{
"url": "https://git.kernel.org/stable/c/b6ea3dda09eb4d5caf7bbc00f857688cf9e98255"
},
{
"url": "https://git.kernel.org/stable/c/ff04b26794a16a8a879eb4fd2c02c2d6b03850e9"
}
],
"title": "sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68320",
"datePublished": "2026-08-10T12:02:55.144Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:10.661Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68116 (GCVE-0-2026-68116)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: mdb: Fix source list corruption on a failed replace
When replacing the source list of an MDB remote entry, all existing
sources are first marked for deletion and vxlan_mdb_remote_srcs_add()
is then called to add the new source list. Sources present in the new
list have their deletion mark cleared, and any sources left marked
afterwards are removed.
If vxlan_mdb_remote_srcs_add() fails partway through, its error path
deletes all entries on the remote's source list. That rollback is only
correct for its other caller, vxlan_mdb_remote_add(), where the remote
was just allocated and the list contains solely entries added during
the call. On the replace path the list also holds pre-existing sources,
so a failed replace tears them down together with their (S, G)
forwarding entries instead of leaving the entry unchanged.
This is reachable from an existing (*, G) remote. An EXCLUDE filter
that loses sources starts forwarding traffic that should be blocked,
while an INCLUDE filter that loses sources drops traffic that should be
forwarded.
Mark entries created during the current pass with a new
VXLAN_SGRP_F_NEW flag. On failure, delete only those entries and clear
the deletion mark on the pre-existing ones, so a failed replace leaves
the source list untouched. Retain the flag until the whole operation
succeeds and then clear it. Also stop vxlan_mdb_remote_src_add() from
deleting a pre-existing entry it only looked up when adding that
entry's forwarding entry fails.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_mdb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5bc8fc1d2ff802eec839e03adef5df597421898d",
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"versionType": "git"
},
{
"lessThan": "2c54dff57606590fa4abec46bab6bea3133f1539",
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"versionType": "git"
},
{
"lessThan": "79370b573e92e8f190eb5f9a511fa5398340d8b2",
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"versionType": "git"
},
{
"lessThan": "54a3c27b357dfb34f327f89bfadeb998bef8051e",
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"versionType": "git"
},
{
"lessThan": "dcd9b465965422b9654f6026e8a2fa8984f74c3c",
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_mdb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: mdb: Fix source list corruption on a failed replace\n\nWhen replacing the source list of an MDB remote entry, all existing\nsources are first marked for deletion and vxlan_mdb_remote_srcs_add()\nis then called to add the new source list. Sources present in the new\nlist have their deletion mark cleared, and any sources left marked\nafterwards are removed.\n\nIf vxlan_mdb_remote_srcs_add() fails partway through, its error path\ndeletes all entries on the remote\u0027s source list. That rollback is only\ncorrect for its other caller, vxlan_mdb_remote_add(), where the remote\nwas just allocated and the list contains solely entries added during\nthe call. On the replace path the list also holds pre-existing sources,\nso a failed replace tears them down together with their (S, G)\nforwarding entries instead of leaving the entry unchanged.\n\nThis is reachable from an existing (*, G) remote. An EXCLUDE filter\nthat loses sources starts forwarding traffic that should be blocked,\nwhile an INCLUDE filter that loses sources drops traffic that should be\nforwarded.\n\nMark entries created during the current pass with a new\nVXLAN_SGRP_F_NEW flag. On failure, delete only those entries and clear\nthe deletion mark on the pre-existing ones, so a failed replace leaves\nthe source list untouched. Retain the flag until the whole operation\nsucceeds and then clear it. Also stop vxlan_mdb_remote_src_add() from\ndeleting a pre-existing entry it only looked up when adding that\nentry\u0027s forwarding entry fails."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.9,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is only reachable via the RTM_NEWMDB rtnetlink control path (ndo_mdb_add); multicast data-plane packets use vxlan_mdb_xmit and never hit the replace/rollback logic.\nAC:L - An attacker with CAP_NET_ADMIN can create an existing (*,G) remote, issue NLM_F_REPLACE with a new source list, and reliably force vxlan_mdb_remote_srcs_add() to fail mid-loop (e.g., ENOMEM via memory pressure) to trigger the bad rollback.\nPR:L - rtnetlink requires CAP_NET_ADMIN for RTM_NEWMDB; this capability is obtainable by unprivileged users inside user/network namespaces, not solely by init-namespace root.\nUI:N - Exploitation requires only crafted rtnetlink MDB messages from a process with network-admin capability; no victim user action is needed.\nS:C - A corrupted EXCLUDE source list forwards multicast that policy intended to block to VXLAN remote peers, crossing intended overlay segmentation boundaries beyond the misconfigured netdev\u0027s local authority.\nC:L - EXCLUDE filter corruption removes per-source block rules, causing multicast payloads from previously blocked sources to be encapsulated and delivered to unauthorized VXLAN remotes.\nI:L - Failed replace corrupts MDB source lists and (S,G) forwarding state, causing unauthorized multicast delivery (EXCLUDE) or dropping traffic that should be forwarded (INCLUDE).\nA:H - INCLUDE filter corruption can wipe all source entries on a (*,G) remote, causing vxlan_mdb_xmit to permanently drop all multicast for that group until MDB state is manually repaired."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:06.287Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5bc8fc1d2ff802eec839e03adef5df597421898d"
},
{
"url": "https://git.kernel.org/stable/c/2c54dff57606590fa4abec46bab6bea3133f1539"
},
{
"url": "https://git.kernel.org/stable/c/79370b573e92e8f190eb5f9a511fa5398340d8b2"
},
{
"url": "https://git.kernel.org/stable/c/54a3c27b357dfb34f327f89bfadeb998bef8051e"
},
{
"url": "https://git.kernel.org/stable/c/dcd9b465965422b9654f6026e8a2fa8984f74c3c"
}
],
"title": "vxlan: mdb: Fix source list corruption on a failed replace",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68116",
"datePublished": "2026-08-10T11:58:34.612Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-17T04:59:06.287Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68260 (GCVE-0-2026-68260)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
The drm gpuvm code doesn't protect find operation against map operation,
and the driver needs to ensure a map operation shouldn't happen when a
find operation is in progress.
In some cases a find operation will be in progress when doing map/unmap
operations, and the find operation will do a NULL pointer dereference.
An example of the stack trace of such NULL dereference is shown below:
```
Unable to handle kernel access to user memory without uaccess routines at
virtual address 0000000000000010
[<ffffffff01e989d4>] drm_gpuva_find+0x28/0x6c [drm_gpuvm]
[<ffffffff01ed3a40>] pvr_vm_unmap+0x34/0x68 [powervr]
[<ffffffff01ec69da>] pvr_ioctl_vm_unmap+0x2e/0x50 [powervr]
[<ffffffff8080ce0a>] drm_ioctl_kernel+0x8e/0xdc
[<ffffffff8080d016>] drm_ioctl+0x1be/0x3e0
[<ffffffff802bec3e>] __riscv_sys_ioctl+0xba/0xc4
[<ffffffff80d858b2>] do_trap_ecall_u+0x23e/0x3f4
[<ffffffff80d92288>] handle_exception+0x168/0x174
```
As all occurences of drm_gpuva_find*() are already guarded by
vm_ctx->lock, make pvr_vm_map() to acquire this lock to prevent
disturbing any find operation. This fixes the NULL deference problem in
drm_gpuva_find*().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_vm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1f1f2618e44b21a7d4eb30d3bbd7e015ffbbbadf",
"status": "affected",
"version": "ff5f643de0bf27874c4033cd57a0bd034b5c7d11",
"versionType": "git"
},
{
"lessThan": "6253bb56bb2ebdf317d8b599ce737a2510cc2e17",
"status": "affected",
"version": "ff5f643de0bf27874c4033cd57a0bd034b5c7d11",
"versionType": "git"
},
{
"lessThan": "15f58d44c24477a6ebffa44ec05207b81cfa55d9",
"status": "affected",
"version": "ff5f643de0bf27874c4033cd57a0bd034b5c7d11",
"versionType": "git"
},
{
"lessThan": "17e2030f37600994440f875dc410615d5c66ee6d",
"status": "affected",
"version": "ff5f643de0bf27874c4033cd57a0bd034b5c7d11",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_vm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: acquire vm_ctx-\u003elock before mapping memory to GPU VM\n\nThe drm gpuvm code doesn\u0027t protect find operation against map operation,\nand the driver needs to ensure a map operation shouldn\u0027t happen when a\nfind operation is in progress.\n\nIn some cases a find operation will be in progress when doing map/unmap\noperations, and the find operation will do a NULL pointer dereference.\n\nAn example of the stack trace of such NULL dereference is shown below:\n\n```\nUnable to handle kernel access to user memory without uaccess routines at\nvirtual address 0000000000000010\n\n[\u003cffffffff01e989d4\u003e] drm_gpuva_find+0x28/0x6c [drm_gpuvm]\n[\u003cffffffff01ed3a40\u003e] pvr_vm_unmap+0x34/0x68 [powervr]\n[\u003cffffffff01ec69da\u003e] pvr_ioctl_vm_unmap+0x2e/0x50 [powervr]\n[\u003cffffffff8080ce0a\u003e] drm_ioctl_kernel+0x8e/0xdc\n[\u003cffffffff8080d016\u003e] drm_ioctl+0x1be/0x3e0\n[\u003cffffffff802bec3e\u003e] __riscv_sys_ioctl+0xba/0xc4\n[\u003cffffffff80d858b2\u003e] do_trap_ecall_u+0x23e/0x3f4\n[\u003cffffffff80d92288\u003e] handle_exception+0x168/0x174\n```\n\nAs all occurences of drm_gpuva_find*() are already guarded by\nvm_ctx-\u003elock, make pvr_vm_map() to acquire this lock to prevent\ndisturbing any find operation. This fixes the NULL deference problem in\ndrm_gpuva_find*()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered through the DRM_IOCTL_PVR_VM_MAP/VM_UNMAP ioctls on the PowerVR render node (/dev/dri/renderD*), which requires local access to the device file; no network or physical path exists.\nAC:L - The attacker owns both sides of the race, issuing concurrent VM_MAP and VM_UNMAP ioctls from two threads on the same fd and vm_ctx handle, and can retry indefinitely with attacker-chosen mapping layouts that force split/remap (free) paths.\nPR:L - The ioctls are marked DRM_RENDER_ALLOW, so no DRM master, root, or capability is needed; any unprivileged process able to open the render node (world-accessible or graphics-group on Android/embedded PowerVR devices) can reach the code.\nUI:N - The attacker performs the entire sequence itself by opening the render node, creating a VM context and issuing concurrent map/unmap ioctls; no victim action is involved.\nS:U - The corruption stays within the kernel\u0027s own security authority on the affected host; no VM, IOMMU or sandbox boundary is crossed by the flaw itself.\nC:H - The unlocked map path frees drm_gpuva objects via pvr_vm_gpuva_remap()/pvr_vm_gpuva_unmap() while a concurrent find returns them, yielding a use-after-free whose reclaimed contents the attacker can groom to read kernel memory; racing MMU updates can also leave GPU page tables mapping unintended pages.\nI:H - The same use-after-free plus unsynchronized rb interval-tree insert/remove gives attacker-influenced writes through a freed/corrupted structure, and the racing pvr_mmu_map/unmap operations can corrupt GPU page tables, which is leveragable into arbitrary memory modification.\nA:H - The reported failure is an immediate kernel NULL pointer dereference in drm_gpuva_find(), and tree corruption or use-after-free reliably produces oopses, and the ioctl can be re-issued to crash the system at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:52.352Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1f1f2618e44b21a7d4eb30d3bbd7e015ffbbbadf"
},
{
"url": "https://git.kernel.org/stable/c/6253bb56bb2ebdf317d8b599ce737a2510cc2e17"
},
{
"url": "https://git.kernel.org/stable/c/15f58d44c24477a6ebffa44ec05207b81cfa55d9"
},
{
"url": "https://git.kernel.org/stable/c/17e2030f37600994440f875dc410615d5c66ee6d"
}
],
"title": "drm/imagination: acquire vm_ctx-\u003elock before mapping memory to GPU VM",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68260",
"datePublished": "2026-08-10T12:01:34.414Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:01:52.352Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64445 (GCVE-0-2026-64445)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
OnAuth() has two bugs in the shared-key authentication path.
When the Privacy bit is set, rtw_wep_decrypt() is called without
verifying that the frame is long enough to contain a valid WEP IV and
ICV. Inside rtw_wep_decrypt(), length is computed as:
length = len - WLAN_HDR_A3_LEN - iv_len
and then passed as (length - 4) to crc32_le(). If len is less than
WLAN_HDR_A3_LEN + iv_len + icv_len (32 bytes), length - 4 is negative
and, after the implicit cast to size_t, causes crc32_le() to read far
beyond the frame buffer. Add a minimum length check before accessing
the IV field and calling the decryption path.
When processing a seq=3 response, rtw_get_ie() stores the Challenge
Text IE length in ie_len, but the subsequent memcmp() always reads 128
bytes regardless of ie_len. IEEE 802.11 mandates a challenge text of
exactly 128 bytes; reject any IE whose length field differs, matching
the check already applied to OnAuthClient().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "665e1ecb68b4e8419604e70a33f02d1c8b0222c6",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "87cccc2a767f17dcab71e3b9fe5ae29b5516c5ce",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "c9000c93078e5c0a5a651b077c0ec92a4bc7d580",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "1f6c9d255bdda41216b6e34c96aa2b1abee0bb84",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "3e44a7665f3abd320a80d9c64ee4a93317041b8b",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "64ec4192d9c10e96922245d4a6747304cc76b19d",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "d90b9f39f375c9826ef145605dfe97765d0ecb91",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "a1fc19d61f661d47204f095b593de507884849f7",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()\n\nOnAuth() has two bugs in the shared-key authentication path.\n\nWhen the Privacy bit is set, rtw_wep_decrypt() is called without\nverifying that the frame is long enough to contain a valid WEP IV and\nICV. Inside rtw_wep_decrypt(), length is computed as:\n\n length = len - WLAN_HDR_A3_LEN - iv_len\n\nand then passed as (length - 4) to crc32_le(). If len is less than\nWLAN_HDR_A3_LEN + iv_len + icv_len (32 bytes), length - 4 is negative\nand, after the implicit cast to size_t, causes crc32_le() to read far\nbeyond the frame buffer. Add a minimum length check before accessing\nthe IV field and calling the decryption path.\n\nWhen processing a seq=3 response, rtw_get_ie() stores the Challenge\nText IE length in ie_len, but the subsequent memcmp() always reads 128\nbytes regardless of ie_len. IEEE 802.11 mandates a challenge text of\nexactly 128 bytes; reject any IE whose length field differs, matching\nthe check already applied to OnAuthClient()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - A nearby attacker can inject crafted 802.11 authentication management frames over the wireless channel to an RTL8723BS interface operating in AP mode.\nAC:L - A single attacker-controlled protected authentication frame can trigger the underflow without knowing a WEP key, winning a race, or satisfying conditions outside the attacker\u0027s control.\nPR:N - The vulnerable decryption executes before authentication, association, MAC ACL enforcement, and authentication-algorithm validation, so no credentials or privileges are required.\nUI:N - Once the affected interface is operating normally in AP mode, exploitation requires no action by a victim user.\nS:U - The vulnerable driver and the affected kernel resources belong to the same operating-system security authority; this is not a guest-host or other scope-boundary escape.\nC:H - The CRC underflow supplies a near-SIZE_MAX length to crc32_le(), producing a massive kernel out-of-bounds read, while the short-IE comparison can read up to 127 bytes beyond the Challenge Text IE.\nI:H - For protected frames shorter than 28 bytes, the negative signed length is converted to an approximately 4-GiB unsigned length for the in-place arc4_crypt(), causing extensive out-of-bounds writes capable of corrupting adjacent kernel heap state.\nA:H - The enormous ARC4 operation or CRC read will cross the receive-buffer allocation and can cause an oops, panic, hang, or severe heap corruption; unauthenticated attackers can trigger this repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:47.787Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/665e1ecb68b4e8419604e70a33f02d1c8b0222c6"
},
{
"url": "https://git.kernel.org/stable/c/87cccc2a767f17dcab71e3b9fe5ae29b5516c5ce"
},
{
"url": "https://git.kernel.org/stable/c/c9000c93078e5c0a5a651b077c0ec92a4bc7d580"
},
{
"url": "https://git.kernel.org/stable/c/1f6c9d255bdda41216b6e34c96aa2b1abee0bb84"
},
{
"url": "https://git.kernel.org/stable/c/3e44a7665f3abd320a80d9c64ee4a93317041b8b"
},
{
"url": "https://git.kernel.org/stable/c/64ec4192d9c10e96922245d4a6747304cc76b19d"
},
{
"url": "https://git.kernel.org/stable/c/d90b9f39f375c9826ef145605dfe97765d0ecb91"
},
{
"url": "https://git.kernel.org/stable/c/a1fc19d61f661d47204f095b593de507884849f7"
}
],
"title": "staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64445",
"datePublished": "2026-07-25T08:51:16.670Z",
"dateReserved": "2026-07-19T15:36:31.788Z",
"dateUpdated": "2026-08-17T04:55:47.787Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74496 (GCVE-0-2026-74496)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-17 05:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fou: Fix use-after-free in fou_create()
fou_create() publishes struct fou through sk_user_data before adding the
new FOU port to the per-netns list. If fou_add_to_port_list() fails,
the error path frees fou while it is still reachable through
sk_user_data. A concurrent receive can then dereference the freed
object in fou_from_sock().
This ordering issue was previously noted in the linked discussion.
The failure is reachable when local port 0 is requested. Each socket
binds to a different ephemeral port, but fou_cfg_cmp() compares the
requested port 0 and reports -EALREADY once an entry already exists.
Release the tunnel socket before freeing fou so sk_user_data is cleared
first, and defer reclamation with kfree_rcu() to protect concurrent RCU
readers. This matches the lifetime handling in fou_release().
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/fou_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a28d8903bfe76089ea4bbdbff9976965f9ef8107",
"status": "affected",
"version": "23461551c00628c3f3fe9cf837bf53cf8f212b63",
"versionType": "git"
},
{
"lessThan": "b14361aca6350ff7907b0e9903c7b94dc7d5d4a0",
"status": "affected",
"version": "23461551c00628c3f3fe9cf837bf53cf8f212b63",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/fou_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"lessThan": "3.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfou: Fix use-after-free in fou_create()\n\nfou_create() publishes struct fou through sk_user_data before adding the\nnew FOU port to the per-netns list. If fou_add_to_port_list() fails,\nthe error path frees fou while it is still reachable through\nsk_user_data. A concurrent receive can then dereference the freed\nobject in fou_from_sock().\n\nThis ordering issue was previously noted in the linked discussion.\n\nThe failure is reachable when local port 0 is requested. Each socket\nbinds to a different ephemeral port, but fou_cfg_cmp() compares the\nrequested port 0 and reports -EALREADY once an entry already exists.\n\nRelease the tunnel socket before freeing fou so sk_user_data is cleared\nfirst, and defer reclamation with kfree_rcu() to protect concurrent RCU\nreaders. This matches the lifetime handling in fou_release()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is opened only via local FOU_CMD_ADD genetlink into fou_create(); remote UDP can race the dangling sk_user_data read in fou_udp_recv/gue_udp_recv but cannot alone reach the erroneous teardown path.\nAC:L - An attacker with CAP_NET_ADMIN controls both sides: issue a second FOU_CMD_ADD with port 0 to force -EALREADY on fou_add_to_port_list while concurrently sending UDP/GRO traffic to the just-bound ephemeral socket during the kfree window.\nPR:L - FOU_CMD_ADD is gated by GENL_ADMIN_PERM (CAP_NET_ADMIN); the fou genl family is netnsok, so a user with CAP_NET_ADMIN inside unshare -Urn can configure FOU and trigger the failing add path without init-namespace root.\nUI:N - Exploitation is fully programmatic via concurrent netlink FOU_CMD_ADD requests and attacker-controlled UDP packets; no victim mount, file open, or other interactive action is required.\nS:U - Impact is kernel heap corruption and privilege escalation within the same security authority; this is not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - Concurrent readers call fou_from_sock() and dereference freed struct fou fields (family, protocol, flags); reclaimed slab contents give attacker-controlled reads and kernel pointer disclosure primitives typical of UAF.\nI:H - Freed struct fou is attacker-reclaimable kmalloc memory; fou_gro_receive indexes inet_offloads[fou-\u003eprotocol] from the dangling pointer, enabling heap grooming for arbitrary writes and control-flow hijack.\nA:H - Use-after-free in UDP receive/GRO softirq reliably causes KASAN violations and, on production kernels, invalid pointer dereferences or panics when accessing the freed fou object during packet processing."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:47:51.722Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a28d8903bfe76089ea4bbdbff9976965f9ef8107"
},
{
"url": "https://git.kernel.org/stable/c/b14361aca6350ff7907b0e9903c7b94dc7d5d4a0"
}
],
"title": "fou: Fix use-after-free in fou_create()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74496",
"datePublished": "2026-08-15T12:27:23.854Z",
"dateReserved": "2026-08-15T05:44:03.906Z",
"dateUpdated": "2026-08-17T05:47:51.722Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64406 (GCVE-0-2026-64406)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: fix UAF in bt_accept_dequeue()
bt_accept_get() takes a temporary reference before dropping the accept
queue lock. bt_accept_dequeue() currently drops that reference before
bt_accept_unlink(), leaving only the queue reference.
bt_accept_unlink() drops the queue reference. The subsequent
sock_hold() therefore accesses freed memory if it was the final
reference, as observed by KASAN during listening L2CAP socket cleanup.
Retain the temporary queue-walk reference through unlink and hand it to
the caller on success. Drop it explicitly on the closed and
not-yet-connected paths.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 751de6ec671fe75ad9cf65a0638d2a06b6a5984d Version: 407217734835d21d4e0105ebf347860dc1806f88 Version: 7eebd4c2c86f573af87ff165d08a83432eb0b919 Version: 5d86d2f1b4d9a508c441d3e45277ae1a73cfed57 Version: 87c543e2f78d0871f271df92dab98901bbd5b6f5 Version: added1213395071470a900cc845a042fb51882a6 Version: ab1513597c6cf17cd1ad2a21e3b045421b48e022 Version: ab1513597c6cf17cd1ad2a21e3b045421b48e022 Version: a5ca86a6097a8b030ca3226cd300b17ed330f966 Version: 5.10.259 ≤ Version: 5.15.210 ≤ Version: 6.1.175 ≤ Version: 6.6.142 ≤ Version: 6.12.92 ≤ Version: 6.18.34 ≤ Version: 7.0.11 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/af_bluetooth.c",
"net/bluetooth/l2cap_sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c0577c55219be42b6ea2ea8db11e85bfab6f4e8d",
"status": "affected",
"version": "751de6ec671fe75ad9cf65a0638d2a06b6a5984d",
"versionType": "git"
},
{
"lessThan": "96ad400d5132eb333f28f6f1e2d58f0728ca9547",
"status": "affected",
"version": "407217734835d21d4e0105ebf347860dc1806f88",
"versionType": "git"
},
{
"lessThan": "0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0",
"status": "affected",
"version": "7eebd4c2c86f573af87ff165d08a83432eb0b919",
"versionType": "git"
},
{
"lessThan": "c66a95e60b65d876a927123b0ed36bd6177d9ca6",
"status": "affected",
"version": "5d86d2f1b4d9a508c441d3e45277ae1a73cfed57",
"versionType": "git"
},
{
"lessThan": "6303ed4bbe0095f4cc195225479bf506e010d1db",
"status": "affected",
"version": "87c543e2f78d0871f271df92dab98901bbd5b6f5",
"versionType": "git"
},
{
"lessThan": "26168db1ce5a9766cde021b18e590a101c056614",
"status": "affected",
"version": "added1213395071470a900cc845a042fb51882a6",
"versionType": "git"
},
{
"lessThan": "50c662bdcd51b03033a0abed6716bfd377ba1049",
"status": "affected",
"version": "ab1513597c6cf17cd1ad2a21e3b045421b48e022",
"versionType": "git"
},
{
"lessThan": "4bd0b274054f2679f28b70222b607bb0afc3ab9a",
"status": "affected",
"version": "ab1513597c6cf17cd1ad2a21e3b045421b48e022",
"versionType": "git"
},
{
"status": "affected",
"version": "a5ca86a6097a8b030ca3226cd300b17ed330f966",
"versionType": "git"
},
{
"lessThan": "5.10.261",
"status": "affected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThan": "5.15.212",
"status": "affected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThan": "6.12.96",
"status": "affected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThan": "6.18.39",
"status": "affected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThan": "7.1",
"status": "affected",
"version": "7.0.11",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/af_bluetooth.c",
"net/bluetooth/l2cap_sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"lessThan": "7.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.10.259",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.15.210",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.175",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.142",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.12.92",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.18.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7.0.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: fix UAF in bt_accept_dequeue()\n\nbt_accept_get() takes a temporary reference before dropping the accept\nqueue lock. bt_accept_dequeue() currently drops that reference before\nbt_accept_unlink(), leaving only the queue reference.\n\nbt_accept_unlink() drops the queue reference. The subsequent\nsock_hold() therefore accesses freed memory if it was the final\nreference, as observed by KASAN during listening L2CAP socket cleanup.\n\nRetain the temporary queue-walk reference through unlink and hand it to\nthe caller on success. Drop it explicitly on the closed and\nnot-yet-connected paths."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable child is created through an incoming Bluetooth link, with its teardown driven by connection and disconnection events from a nearby peer. Bluetooth radio reachability is adjacent rather than routable network access.\nAC:L - The attacker can control listener cleanup and use an adjacent peer to connect and disconnect before the fixed channel becomes ready, producing the final queue-only reference state. The trigger is repeatable and Bluetooth BR/EDR support is a common default configuration.\nPR:L - Unprivileged SOCK_STREAM or SOCK_SEQPACKET L2CAP sockets and dynamic or fixed-CID binds require no capability; only raw sockets and reserved PSM binds are privileged. Although AF_BLUETOOTH requires init_net, an ordinary host user or user namespace without a new network namespace can reach it.\nUI:N - The attacker can close their own listener while controlling the peer connection lifecycle, requiring no action from another user.\nS:U - Exploitation compromises the vulnerable host kernel but does not inherently cross a VM, IOMMU, or other security-authority boundary.\nC:H - The freed struct sock comes from the general kmalloc-2k cache and can be reclaimed with attacker-controlled data. Subsequent socket and channel dereferences can be developed into arbitrary kernel-memory disclosure.\nI:H - The UAF causes an atomic write to freed memory followed by further operations on the freed socket and channel, enabling heap-spray-based corruption and potential control-flow hijacking.\nA:H - The confirmed post-free write can cause a kernel oops or panic, and the attacker can repeat the connection, disconnection, and cleanup sequence."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:04.583Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c0577c55219be42b6ea2ea8db11e85bfab6f4e8d"
},
{
"url": "https://git.kernel.org/stable/c/96ad400d5132eb333f28f6f1e2d58f0728ca9547"
},
{
"url": "https://git.kernel.org/stable/c/0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0"
},
{
"url": "https://git.kernel.org/stable/c/c66a95e60b65d876a927123b0ed36bd6177d9ca6"
},
{
"url": "https://git.kernel.org/stable/c/6303ed4bbe0095f4cc195225479bf506e010d1db"
},
{
"url": "https://git.kernel.org/stable/c/26168db1ce5a9766cde021b18e590a101c056614"
},
{
"url": "https://git.kernel.org/stable/c/50c662bdcd51b03033a0abed6716bfd377ba1049"
},
{
"url": "https://git.kernel.org/stable/c/4bd0b274054f2679f28b70222b607bb0afc3ab9a"
}
],
"title": "Bluetooth: fix UAF in bt_accept_dequeue()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64406",
"datePublished": "2026-07-25T08:50:47.978Z",
"dateReserved": "2026-07-19T15:36:31.786Z",
"dateUpdated": "2026-08-17T04:55:04.583Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64479 (GCVE-0-2026-64479)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
snd_seq_event_dup() copies an incoming event into a pool cell and, in
the UMP-enabled build, clears the trailing cell->ump.raw.extra word that
the memcpy() did not cover. The guard deciding whether to clear it
compares the copied size against sizeof(cell->event):
memcpy(&cell->ump, event, size);
if (size < sizeof(cell->event))
cell->ump.raw.extra = 0;
For a legacy (non-UMP) event, size == sizeof(struct snd_seq_event) ==
sizeof(cell->event), so the condition is false and the extra word keeps
stale data. The cell pool is allocated with kvmalloc() (not zeroed) and
cells are reused via a free list, so that word holds uninitialised heap
or leftover event data.
When such a cell is delivered to a UMP client (client->midi_version > 0)
that set SNDRV_SEQ_FILTER_NO_CONVERT -- so the legacy event reaches it
unconverted -- snd_seq_read() reads it out as the larger struct
snd_seq_ump_event and copies the stale word to user space, a 4-byte
kernel heap infoleak to an unprivileged /dev/snd/seq client.
Compare against sizeof(cell->ump) instead, so the trailing word is zeroed
for every event shorter than the UMP cell.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6389f2c135311c4ce7c08c3b29145c8f95aacf1f Version: d7e2ce72833bb23a82b4201fbed7214cc04a4a8c Version: 46397622a3fa8372b8fda0f04b33d16923b03b1b Version: 46397622a3fa8372b8fda0f04b33d16923b03b1b Version: 46397622a3fa8372b8fda0f04b33d16923b03b1b Version: 46397622a3fa8372b8fda0f04b33d16923b03b1b Version: 46397622a3fa8372b8fda0f04b33d16923b03b1b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/core/seq/seq_memory.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d7649aa11089a93ea2285c210397aa67e5800766",
"status": "affected",
"version": "6389f2c135311c4ce7c08c3b29145c8f95aacf1f",
"versionType": "git"
},
{
"lessThan": "a224c84e5d3d35708c082c84ad12d81d90762195",
"status": "affected",
"version": "d7e2ce72833bb23a82b4201fbed7214cc04a4a8c",
"versionType": "git"
},
{
"lessThan": "ea672a9f6cc38f06fe69dd2c257ef8a3d4db179a",
"status": "affected",
"version": "46397622a3fa8372b8fda0f04b33d16923b03b1b",
"versionType": "git"
},
{
"lessThan": "fb1aa5082847b98f44f9c6272aee9d0dca9244f0",
"status": "affected",
"version": "46397622a3fa8372b8fda0f04b33d16923b03b1b",
"versionType": "git"
},
{
"lessThan": "651ba82fe2a144bc7356d940bfd235c3810b0549",
"status": "affected",
"version": "46397622a3fa8372b8fda0f04b33d16923b03b1b",
"versionType": "git"
},
{
"lessThan": "6ded42615fa1f4949925afd0a8a9e1ab3bf96202",
"status": "affected",
"version": "46397622a3fa8372b8fda0f04b33d16923b03b1b",
"versionType": "git"
},
{
"lessThan": "435990e25bf1f4af3e6df12a6fbfd1f7ba4a97d4",
"status": "affected",
"version": "46397622a3fa8372b8fda0f04b33d16923b03b1b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/core/seq/seq_memory.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()\n\nsnd_seq_event_dup() copies an incoming event into a pool cell and, in\nthe UMP-enabled build, clears the trailing cell-\u003eump.raw.extra word that\nthe memcpy() did not cover. The guard deciding whether to clear it\ncompares the copied size against sizeof(cell-\u003eevent):\n\n\tmemcpy(\u0026cell-\u003eump, event, size);\n\tif (size \u003c sizeof(cell-\u003eevent))\n\t\tcell-\u003eump.raw.extra = 0;\n\nFor a legacy (non-UMP) event, size == sizeof(struct snd_seq_event) ==\nsizeof(cell-\u003eevent), so the condition is false and the extra word keeps\nstale data. The cell pool is allocated with kvmalloc() (not zeroed) and\ncells are reused via a free list, so that word holds uninitialised heap\nor leftover event data.\n\nWhen such a cell is delivered to a UMP client (client-\u003emidi_version \u003e 0)\nthat set SNDRV_SEQ_FILTER_NO_CONVERT -- so the legacy event reaches it\nunconverted -- snd_seq_read() reads it out as the larger struct\nsnd_seq_ump_event and copies the stale word to user space, a 4-byte\nkernel heap infoleak to an unprivileged /dev/snd/seq client.\n\nCompare against sizeof(cell-\u003eump) instead, so the trailing word is zeroed\nfor every event shorter than the UMP cell."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:25.868Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d7649aa11089a93ea2285c210397aa67e5800766"
},
{
"url": "https://git.kernel.org/stable/c/a224c84e5d3d35708c082c84ad12d81d90762195"
},
{
"url": "https://git.kernel.org/stable/c/ea672a9f6cc38f06fe69dd2c257ef8a3d4db179a"
},
{
"url": "https://git.kernel.org/stable/c/fb1aa5082847b98f44f9c6272aee9d0dca9244f0"
},
{
"url": "https://git.kernel.org/stable/c/651ba82fe2a144bc7356d940bfd235c3810b0549"
},
{
"url": "https://git.kernel.org/stable/c/6ded42615fa1f4949925afd0a8a9e1ab3bf96202"
},
{
"url": "https://git.kernel.org/stable/c/435990e25bf1f4af3e6df12a6fbfd1f7ba4a97d4"
}
],
"title": "ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64479",
"datePublished": "2026-07-25T08:51:41.006Z",
"dateReserved": "2026-07-19T15:36:31.791Z",
"dateUpdated": "2026-08-17T04:56:25.868Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68343 (GCVE-0-2026-68343)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: validate DFS referral PathConsumed
parse_dfs_referrals() validates that the response contains the fixed
referral entry array and, on for-next, the per-referral string offsets.
However, the response also contains a PathConsumed value that is later
used for DFS path parsing.
If a malformed response provides a PathConsumed value larger than the
search name, later DFS parsing can advance beyond the end of the path.
Validate PathConsumed against the search name length before storing it in
the parsed referral.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bfebe5110fd135d86d65a0a346e14c106b02028b",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "5b439f39f33ec15d319ced3b025e122346fba987",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "285bd4a5f3f156aa5869843b47a1b1380b774241",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "2fdd6d196c656b376cc251e1e9ff110b3ed522e1",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "9f88a99ed511651b2dc2177d6854b2d1b8322e75",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "f6f5ee2aa33b350c671721b965251c42cebb962e",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate DFS referral PathConsumed\n\nparse_dfs_referrals() validates that the response contains the fixed\nreferral entry array and, on for-next, the per-referral string offsets.\nHowever, the response also contains a PathConsumed value that is later\nused for DFS path parsing.\n\nIf a malformed response provides a PathConsumed value larger than the\nsearch name, later DFS parsing can advance beyond the end of the path.\n\nValidate PathConsumed against the search name length before storing it in\nthe parsed referral."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The tainted PathConsumed value comes directly from a GET_DFS_REFERRAL response received over TCP/445 from the SMB server, so a malicious or MITM-positioned server on the network fully controls the input to the vulnerable code.\nAC:L - The server simply sets an oversized PathConsumed (up to 65535, and it can also clear the SMB1 UNICODE flag to select the completely unvalidated branch); the resulting out-of-bounds walk past the path buffer is deterministic and needs no race or memory-layout luck.\nPR:N - The attacker is the remote server (or a MITM on an unsigned connection) and needs no account or privilege on the victim client; the client parses the referral response as part of establishing the connection.\nUI:N - DFS referral walks are performed automatically by autofs/systemd automounts, fstab mounts at boot and reconnect-driven remounts, so a forged referral can be delivered without any user action.\nS:U - The out-of-bounds access stays within the kernel\u0027s own memory and mount context on the client; no VM, IOMMU or sandbox boundary is crossed.\nC:H - prepath = full_path + path_consumed points past the end of the heap path string, and cifs_build_devname() strlen()s and copies from there, splicing adjacent kernel heap contents (up to ~64KB away) into the constructed UNC/prefixpath that is then observable via the mount source and /proc/mounts.\nI:N - The defect is purely an out-of-bounds read; all subsequent allocations and copies are sized from the same over-read string, so no kernel memory is written or corrupted.\nA:H - With PathConsumed up to 65535 the pointer can run far past a small slab object into an unmapped or guarded page, so strlen() on it oopses the mounting task (and panics on panic_on_oops systems)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:43.025Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bfebe5110fd135d86d65a0a346e14c106b02028b"
},
{
"url": "https://git.kernel.org/stable/c/5b439f39f33ec15d319ced3b025e122346fba987"
},
{
"url": "https://git.kernel.org/stable/c/285bd4a5f3f156aa5869843b47a1b1380b774241"
},
{
"url": "https://git.kernel.org/stable/c/2fdd6d196c656b376cc251e1e9ff110b3ed522e1"
},
{
"url": "https://git.kernel.org/stable/c/9f88a99ed511651b2dc2177d6854b2d1b8322e75"
},
{
"url": "https://git.kernel.org/stable/c/f6f5ee2aa33b350c671721b965251c42cebb962e"
}
],
"title": "smb: client: validate DFS referral PathConsumed",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68343",
"datePublished": "2026-08-10T12:03:19.939Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:43.025Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53353 (GCVE-0-2026-53353)
Vulnerability from cvelistv5
Published
2026-07-01 13:32
Modified
2026-07-01 13:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hsr: Remove WARN_ONCE() in hsr_addr_is_self().
syzbot reported the warning [0] in hsr_addr_is_self(),
whose assumption is simply wrong.
hsr->self_node is cleared in hsr_del_self_node(), which
is called from hsr_dellink().
Since dev->rtnl_link_ops->dellink() is called before
unregister_netdevice_many(), there is a window when
user can find the device but without hsr->self_node.
Let's remove WARN_ONCE() in hsr_addr_is_self().
[0]:
HSR: No self node
WARNING: net/hsr/hsr_framereg.c:39 at hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39, CPU#0: syz.4.16848/17220
Modules linked in:
CPU: 0 UID: 0 PID: 17220 Comm: syz.4.16848 Tainted: G L syzkaller #0 PREEMPT_{RT,(full)}
Tainted: [L]=SOFTLOCKUP
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026
RIP: 0010:hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39
Code: 33 2f 41 0f b7 dd 89 ee 09 de 31 ff e8 c8 b4 c6 f6 09 dd 74 54 e8 0f b0 c6 f6 31 ed eb 53 e8 06 b0 c6 f6 48 8d 3d 2f 50 9c 04 <67> 48 0f b9 3a 31 ed eb 42 e8 c1 13 1f 00 89 c5 31 ff 89 c6 e8 96
RSP: 0018:ffffc900041c70e0 EFLAGS: 00010283
RAX: ffffffff8afdc6ca RBX: ffffffff8afdc4e6 RCX: 0000000000080000
RDX: ffffc90010493000 RSI: 0000000000000948 RDI: ffffffff8f9a1700
RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000
R10: ffffc900041c71e8 R11: fffff52000838e3f R12: dffffc0000000000
R13: ffff888041f9e3c0 R14: ffff888086ee3802 R15: 0000000000000000
FS: 00007f6fe985d6c0(0000) GS:ffff888126176000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f80bd437dac CR3: 0000000025096000 CR4: 00000000003526f0
DR0: ffffffffffffffff DR1: 00000000000001f8 DR2: 0000000000000002
DR3: ffffffffefffff15 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
check_local_dest net/hsr/hsr_forward.c:592 [inline]
fill_frame_info net/hsr/hsr_forward.c:728 [inline]
hsr_forward_skb+0xa11/0x2a80 net/hsr/hsr_forward.c:739
hsr_dev_xmit+0x253/0x370 net/hsr/hsr_device.c:236
__netdev_start_xmit include/linux/netdevice.h:5368 [inline]
netdev_start_xmit include/linux/netdevice.h:5377 [inline]
xmit_one net/core/dev.c:3888 [inline]
dev_hard_start_xmit+0x2df/0x860 net/core/dev.c:3904
__dev_queue_xmit+0x1428/0x3900 net/core/dev.c:4870
neigh_output include/net/neighbour.h:556 [inline]
ip_finish_output2+0xcec/0x10b0 net/ipv4/ip_output.c:237
ip_send_skb net/ipv4/ip_output.c:1510 [inline]
ip_push_pending_frames+0x8b/0x110 net/ipv4/ip_output.c:1530
raw_sendmsg+0x1547/0x1a50 net/ipv4/raw.c:659
sock_sendmsg_nosec net/socket.c:787 [inline]
__sock_sendmsg net/socket.c:802 [inline]
____sys_sendmsg+0x7da/0x9c0 net/socket.c:2698
___sys_sendmsg+0x2a5/0x360 net/socket.c:2752
__sys_sendmsg net/socket.c:2784 [inline]
__do_sys_sendmsg net/socket.c:2789 [inline]
__se_sys_sendmsg net/socket.c:2787 [inline]
__x64_sys_sendmsg+0x1c3/0x2a0 net/socket.c:2787
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f6feb62ce59
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f6fe985d028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f6feb8a6090 RCX: 00007f6feb62ce59
RDX: 0000000000000000 RSI: 0000200000000000 RDI: 0000000000000004
RBP: 00007f6feb6c2d6f R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f6feb8a6128 R14: 00007f6feb8a6090 R15: 00007ffcf01cc488
</TASK>
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/hsr/hsr_framereg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "271355c2ef6171dbc815e7ae653eed63444bbd58",
"status": "affected",
"version": "f266a683a4804dc499efc6c2206ef68efed029d0",
"versionType": "git"
},
{
"lessThan": "0232b6fcb7615fb7fecfe0727a23065a53e228b8",
"status": "affected",
"version": "f266a683a4804dc499efc6c2206ef68efed029d0",
"versionType": "git"
},
{
"lessThan": "66a46e22396fd5d09606f37f73643eb20e99aa42",
"status": "affected",
"version": "f266a683a4804dc499efc6c2206ef68efed029d0",
"versionType": "git"
},
{
"lessThan": "d71bb171661ec0225bf4babdd4d296d744982fb3",
"status": "affected",
"version": "f266a683a4804dc499efc6c2206ef68efed029d0",
"versionType": "git"
},
{
"lessThan": "afd0f17ca46258cec3a5cc48b8df9327fe772490",
"status": "affected",
"version": "f266a683a4804dc499efc6c2206ef68efed029d0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/hsr/hsr_framereg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhsr: Remove WARN_ONCE() in hsr_addr_is_self().\n\nsyzbot reported the warning [0] in hsr_addr_is_self(),\nwhose assumption is simply wrong.\n\nhsr-\u003eself_node is cleared in hsr_del_self_node(), which\nis called from hsr_dellink().\n\nSince dev-\u003ertnl_link_ops-\u003edellink() is called before\nunregister_netdevice_many(), there is a window when\nuser can find the device but without hsr-\u003eself_node.\n\nLet\u0027s remove WARN_ONCE() in hsr_addr_is_self().\n\n[0]:\nHSR: No self node\nWARNING: net/hsr/hsr_framereg.c:39 at hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39, CPU#0: syz.4.16848/17220\nModules linked in:\nCPU: 0 UID: 0 PID: 17220 Comm: syz.4.16848 Tainted: G L syzkaller #0 PREEMPT_{RT,(full)}\nTainted: [L]=SOFTLOCKUP\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026\nRIP: 0010:hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39\nCode: 33 2f 41 0f b7 dd 89 ee 09 de 31 ff e8 c8 b4 c6 f6 09 dd 74 54 e8 0f b0 c6 f6 31 ed eb 53 e8 06 b0 c6 f6 48 8d 3d 2f 50 9c 04 \u003c67\u003e 48 0f b9 3a 31 ed eb 42 e8 c1 13 1f 00 89 c5 31 ff 89 c6 e8 96\nRSP: 0018:ffffc900041c70e0 EFLAGS: 00010283\nRAX: ffffffff8afdc6ca RBX: ffffffff8afdc4e6 RCX: 0000000000080000\nRDX: ffffc90010493000 RSI: 0000000000000948 RDI: ffffffff8f9a1700\nRBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000\nR10: ffffc900041c71e8 R11: fffff52000838e3f R12: dffffc0000000000\nR13: ffff888041f9e3c0 R14: ffff888086ee3802 R15: 0000000000000000\nFS: 00007f6fe985d6c0(0000) GS:ffff888126176000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f80bd437dac CR3: 0000000025096000 CR4: 00000000003526f0\nDR0: ffffffffffffffff DR1: 00000000000001f8 DR2: 0000000000000002\nDR3: ffffffffefffff15 DR6: 00000000ffff0ff0 DR7: 0000000000000400\nCall Trace:\n \u003cTASK\u003e\n check_local_dest net/hsr/hsr_forward.c:592 [inline]\n fill_frame_info net/hsr/hsr_forward.c:728 [inline]\n hsr_forward_skb+0xa11/0x2a80 net/hsr/hsr_forward.c:739\n hsr_dev_xmit+0x253/0x370 net/hsr/hsr_device.c:236\n __netdev_start_xmit include/linux/netdevice.h:5368 [inline]\n netdev_start_xmit include/linux/netdevice.h:5377 [inline]\n xmit_one net/core/dev.c:3888 [inline]\n dev_hard_start_xmit+0x2df/0x860 net/core/dev.c:3904\n __dev_queue_xmit+0x1428/0x3900 net/core/dev.c:4870\n neigh_output include/net/neighbour.h:556 [inline]\n ip_finish_output2+0xcec/0x10b0 net/ipv4/ip_output.c:237\n ip_send_skb net/ipv4/ip_output.c:1510 [inline]\n ip_push_pending_frames+0x8b/0x110 net/ipv4/ip_output.c:1530\n raw_sendmsg+0x1547/0x1a50 net/ipv4/raw.c:659\n sock_sendmsg_nosec net/socket.c:787 [inline]\n __sock_sendmsg net/socket.c:802 [inline]\n ____sys_sendmsg+0x7da/0x9c0 net/socket.c:2698\n ___sys_sendmsg+0x2a5/0x360 net/socket.c:2752\n __sys_sendmsg net/socket.c:2784 [inline]\n __do_sys_sendmsg net/socket.c:2789 [inline]\n __se_sys_sendmsg net/socket.c:2787 [inline]\n __x64_sys_sendmsg+0x1c3/0x2a0 net/socket.c:2787\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f6feb62ce59\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f6fe985d028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007f6feb8a6090 RCX: 00007f6feb62ce59\nRDX: 0000000000000000 RSI: 0000200000000000 RDI: 0000000000000004\nRBP: 00007f6feb6c2d6f R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007f6feb8a6128 R14: 00007f6feb8a6090 R15: 00007ffcf01cc488\n \u003c/TASK\u003e"
}
],
"providerMetadata": {
"dateUpdated": "2026-07-01T13:32:29.699Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/271355c2ef6171dbc815e7ae653eed63444bbd58"
},
{
"url": "https://git.kernel.org/stable/c/0232b6fcb7615fb7fecfe0727a23065a53e228b8"
},
{
"url": "https://git.kernel.org/stable/c/66a46e22396fd5d09606f37f73643eb20e99aa42"
},
{
"url": "https://git.kernel.org/stable/c/d71bb171661ec0225bf4babdd4d296d744982fb3"
},
{
"url": "https://git.kernel.org/stable/c/afd0f17ca46258cec3a5cc48b8df9327fe772490"
}
],
"title": "hsr: Remove WARN_ONCE() in hsr_addr_is_self().",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53353",
"datePublished": "2026-07-01T13:32:29.699Z",
"dateReserved": "2026-06-09T07:44:35.400Z",
"dateUpdated": "2026-07-01T13:32:29.699Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64109 (GCVE-0-2026-64109)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
af_unix: Fix UAF read of tail->len in unix_stream_data_wait()
unix_stream_data_wait() does skb_peek_tail(&sk->sk_receive_queue) without
holding any lock that prevents SKBs on that queue from being dequeued and
freed.
This has been the case since commit 79f632c71bea ("unix/stream: fix
peeking with an offset larger than data in queue").
The first consequence of this is that the pointer comparison
`tail != last` can be false even if `last` semantically refers to an
already-freed SKB while `tail` is a new SKB allocated at the same address;
which can cause unix_stream_data_wait() to wrongly keep blocking after new
data has arrived, but only in a weird scenario where a peeking recv() and
a normal recv() on the same socket are racing, which is probably not a
real problem.
But since commit 2b514574f7e8 ("net: af_unix: implement splice for stream
af_unix sockets"), `tail` is actually dereferenced, which can cause UAF in
the following race scenario (where test_setup() runs single-threaded,
and afterwards, test_thread1() and test_thread2() run concurrently in
two threads:
```
static int socks[2];
void test_setup(void) {
socketpair(AF_UNIX, SOCK_STREAM, 0, socks);
send(socks[1], "A", 1, 0);
int peekoff = 1;
setsockopt(socks[0], SOL_SOCKET, SO_PEEK_OFF, &peekoff, sizeof(peekoff));
}
void test_thread1(void) {
char dummy;
recv(socks[0], &dummy, 1, MSG_PEEK);
}
void test_thread2(void) {
char dummy;
recv(socks[0], &dummy, 1, 0);
shutdown(socks[1], SHUT_WR);
}
```
when racing like this:
```
thread1 thread2
unix_stream_read_generic
mutex_lock(&u->iolock)
skb_peek(&sk->sk_receive_queue)
skb_peek_next(skb, &sk->sk_receive_queue)
mutex_unlock(&u->iolock)
unix_stream_read_generic
unix_state_lock(sk)
skb_peek(&sk->sk_receive_queue)
unix_state_unlock(sk)
unix_stream_data_wait
unix_state_lock(sk)
tail = skb_peek_tail(&sk->sk_receive_queue)
spin_lock(&sk->sk_receive_queue.lock)
__skb_unlink(skb, &sk->sk_receive_queue)
spin_unlock(&sk->sk_receive_queue.lock)
consume_skb(skb) [frees the SKB]
`tail != last`: false
`tail`: true
`tail->len != last_len` ***UAF***
```
Fix the UAF by removing the read of tail->len; checking tail->len would
only make sense if SKBs in the receive queue of a UNIX socket could grow,
which can no longer happen.
Kuniyuki explained:
> When commit 869e7c62486e ("net: af_unix: implement stream sendpage
> support") added sendpage() support, data could be appended to the last
> skb in the receiver's queue.
>
> That's why we needed to check if the length of the last skb was changed
> while waiting for new data in unix_stream_data_wait().
>
> However, commit a0dbf5f818f9 ("af_unix: Support MSG_SPLICE_PAGES") and
> commit 57d44a354a43 ("unix: Convert unix_stream_sendpage() to use
> MSG_SPLICE_PAGES") refactored sendmsg(), and now data is always added
> to a new skb.
That means this fix is not suitable for kernels before 6.5.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/unix/af_unix.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "26342087fac93b3932e6af61dc91ec029cb8a623",
"status": "affected",
"version": "2b514574f7e88c8498027ee366fd6e7aae5aa4b5",
"versionType": "git"
},
{
"lessThan": "38bccb927d83d7d52e5b20015a172a0b6101d11e",
"status": "affected",
"version": "2b514574f7e88c8498027ee366fd6e7aae5aa4b5",
"versionType": "git"
},
{
"lessThan": "acdff9907478e82208475b1151700d0b71dcdc63",
"status": "affected",
"version": "2b514574f7e88c8498027ee366fd6e7aae5aa4b5",
"versionType": "git"
},
{
"lessThan": "5f162f95a95834f06a8ec6140889272ad12e842f",
"status": "affected",
"version": "2b514574f7e88c8498027ee366fd6e7aae5aa4b5",
"versionType": "git"
},
{
"lessThan": "be309f8eae8b474a4a617eaae01324da996fc719",
"status": "affected",
"version": "2b514574f7e88c8498027ee366fd6e7aae5aa4b5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/unix/af_unix.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Fix UAF read of tail-\u003elen in unix_stream_data_wait()\n\nunix_stream_data_wait() does skb_peek_tail(\u0026sk-\u003esk_receive_queue) without\nholding any lock that prevents SKBs on that queue from being dequeued and\nfreed.\nThis has been the case since commit 79f632c71bea (\"unix/stream: fix\npeeking with an offset larger than data in queue\").\nThe first consequence of this is that the pointer comparison\n`tail != last` can be false even if `last` semantically refers to an\nalready-freed SKB while `tail` is a new SKB allocated at the same address;\nwhich can cause unix_stream_data_wait() to wrongly keep blocking after new\ndata has arrived, but only in a weird scenario where a peeking recv() and\na normal recv() on the same socket are racing, which is probably not a\nreal problem.\n\nBut since commit 2b514574f7e8 (\"net: af_unix: implement splice for stream\naf_unix sockets\"), `tail` is actually dereferenced, which can cause UAF in\nthe following race scenario (where test_setup() runs single-threaded,\nand afterwards, test_thread1() and test_thread2() run concurrently in\ntwo threads:\n```\nstatic int socks[2];\nvoid test_setup(void) {\n socketpair(AF_UNIX, SOCK_STREAM, 0, socks);\n send(socks[1], \"A\", 1, 0);\n int peekoff = 1;\n setsockopt(socks[0], SOL_SOCKET, SO_PEEK_OFF, \u0026peekoff, sizeof(peekoff));\n}\nvoid test_thread1(void) {\n char dummy;\n recv(socks[0], \u0026dummy, 1, MSG_PEEK);\n}\nvoid test_thread2(void) {\n char dummy;\n recv(socks[0], \u0026dummy, 1, 0);\n shutdown(socks[1], SHUT_WR);\n}\n```\n\nwhen racing like this:\n```\nthread1 thread2\nunix_stream_read_generic\n mutex_lock(\u0026u-\u003eiolock)\n skb_peek(\u0026sk-\u003esk_receive_queue)\n skb_peek_next(skb, \u0026sk-\u003esk_receive_queue)\n mutex_unlock(\u0026u-\u003eiolock)\n unix_stream_read_generic\n unix_state_lock(sk)\n skb_peek(\u0026sk-\u003esk_receive_queue)\n unix_state_unlock(sk)\n unix_stream_data_wait\n unix_state_lock(sk)\n tail = skb_peek_tail(\u0026sk-\u003esk_receive_queue)\n spin_lock(\u0026sk-\u003esk_receive_queue.lock)\n __skb_unlink(skb, \u0026sk-\u003esk_receive_queue)\n spin_unlock(\u0026sk-\u003esk_receive_queue.lock)\n consume_skb(skb) [frees the SKB]\n `tail != last`: false\n `tail`: true\n `tail-\u003elen != last_len` ***UAF***\n```\n\nFix the UAF by removing the read of tail-\u003elen; checking tail-\u003elen would\nonly make sense if SKBs in the receive queue of a UNIX socket could grow,\nwhich can no longer happen.\n\nKuniyuki explained:\n\n\u003e When commit 869e7c62486e (\"net: af_unix: implement stream sendpage\n\u003e support\") added sendpage() support, data could be appended to the last\n\u003e skb in the receiver\u0027s queue.\n\u003e\n\u003e That\u0027s why we needed to check if the length of the last skb was changed\n\u003e while waiting for new data in unix_stream_data_wait().\n\u003e\n\u003e However, commit a0dbf5f818f9 (\"af_unix: Support MSG_SPLICE_PAGES\") and\n\u003e commit 57d44a354a43 (\"unix: Convert unix_stream_sendpage() to use\n\u003e MSG_SPLICE_PAGES\") refactored sendmsg(), and now data is always added\n\u003e to a new skb.\n\nThat means this fix is not suitable for kernels before 6.5."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local syscalls on AF_UNIX SOCK_STREAM sockets (recvmsg, splice_read, setsockopt SO_PEEK_OFF), not via any network protocol handler.\nAC:L - The attacker controls both racing threads on the same socket fd and can retry the peek/normal-recv interleaving; this is a self-induced race, not one dependent on uncontrollable kernel state.\nPR:L - Any unprivileged local user can create AF_UNIX socketpairs, set SO_PEEK_OFF, and run concurrent recv operations without capabilities, including from within user namespaces.\nUI:N - Exploitation requires no victim interaction; the attacker sets up and races their own socket endpoints programmatically.\nS:C - Successful kernel heap UAF exploitation from an unprivileged container, Android app sandbox, or user-namespace tenant crosses the sandbox boundary to compromise the host kernel.\nC:H - This is a slab use-after-free read of sk_buff-\u003elen on freed memory, which per UAF guidance enables arbitrary kernel memory disclosure and heap layout leaks.\nI:H - UAF on sk_buff objects in the kernel heap can be leveraged through heap grooming and spraying to obtain arbitrary write and kernel code execution primitives.\nA:H - The UAF read can trigger KASAN slab-use-after-free faults, kernel oops, or panic during the dereference, and repeated triggering causes denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:18.983Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/26342087fac93b3932e6af61dc91ec029cb8a623"
},
{
"url": "https://git.kernel.org/stable/c/38bccb927d83d7d52e5b20015a172a0b6101d11e"
},
{
"url": "https://git.kernel.org/stable/c/acdff9907478e82208475b1151700d0b71dcdc63"
},
{
"url": "https://git.kernel.org/stable/c/5f162f95a95834f06a8ec6140889272ad12e842f"
},
{
"url": "https://git.kernel.org/stable/c/be309f8eae8b474a4a617eaae01324da996fc719"
}
],
"title": "af_unix: Fix UAF read of tail-\u003elen in unix_stream_data_wait()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64109",
"datePublished": "2026-07-19T15:40:11.510Z",
"dateReserved": "2026-07-19T07:54:57.034Z",
"dateUpdated": "2026-08-05T12:39:18.983Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68408 (GCVE-0-2026-68408)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
When a netlink socket that owns a PMSR session is closed,
cfg80211_release_pmsr() clears the request's nl_portid and queues
pmsr_free_wk to call cfg80211_pmsr_process_abort() asynchronously.
If the interface tears down concurrently, cfg80211_pmsr_wdev_down()
is called under wiphy_lock and calls cancel_work_sync(&pmsr_free_wk)
to wait for any running work. The work function acquires wiphy_lock
via guard(wiphy) before calling process_abort.
This is a deadlock: wdev_down holds wiphy_lock and blocks inside
cancel_work_sync(); pmsr_free_wk blocks trying to acquire that same
wiphy_lock. Neither thread can proceed.
The same deadlock is reachable from cfg80211_leave_locked(), which
calls cfg80211_pmsr_wdev_down() for all interface types under
wiphy_lock.
Fix this by converting pmsr_free_wk from a plain work_struct to a
wiphy_work. The wiphy_work dispatcher holds wiphy_lock when running
work items, so the explicit guard(wiphy) in the work function is no
longer needed. wiphy_work_cancel() can be called safely while holding
wiphy_lock - since wiphy_lock prevents the work from running
concurrently, wiphy_work_cancel() never blocks, eliminating the
deadlock.
Remove the cancel_work_sync() for pmsr_free_wk from the
NETDEV_GOING_DOWN handler. cfg80211_leave(), called unconditionally
just before it, already cancels any pending work under wiphy_lock
via wiphy_work_cancel() inside cfg80211_pmsr_wdev_down().
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d32c07ef1880fe20cf4ab223dbfedc9c0b2816aa Version: a1b7a843f12a0c3e9d3a2ca607ce451916ef42cf Version: 6dccbc9f3e1d38565dff7730d2b7d1e8b16c9b09 Version: 6dccbc9f3e1d38565dff7730d2b7d1e8b16c9b09 Version: 28d3551f8d8cb3aec7497894d94150fe84d20e5e Version: 37e776e2e0a523731e2470dce6d563f0e8632a40 Version: 72b7ea786b8e570ae11149e9089859a4a8634a13 Version: 6.12.78 ≤ Version: 6.18.20 ≤ Version: 6.1.167 ≤ Version: 6.6.130 ≤ Version: 6.19.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/cfg80211.h",
"net/wireless/core.c",
"net/wireless/core.h",
"net/wireless/pmsr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "21512b5f7a74fd18c996c22e6854efe57d570816",
"status": "affected",
"version": "d32c07ef1880fe20cf4ab223dbfedc9c0b2816aa",
"versionType": "git"
},
{
"lessThan": "133684982dd0c24359fcc641d19d89cc17d6e5ef",
"status": "affected",
"version": "a1b7a843f12a0c3e9d3a2ca607ce451916ef42cf",
"versionType": "git"
},
{
"lessThan": "0a77d9fb4d5c0e01306cd406ffdee8f1fe955c0e",
"status": "affected",
"version": "6dccbc9f3e1d38565dff7730d2b7d1e8b16c9b09",
"versionType": "git"
},
{
"lessThan": "2b0eab425e1f658d8fe1df7590e3b9af5959505e",
"status": "affected",
"version": "6dccbc9f3e1d38565dff7730d2b7d1e8b16c9b09",
"versionType": "git"
},
{
"status": "affected",
"version": "28d3551f8d8cb3aec7497894d94150fe84d20e5e",
"versionType": "git"
},
{
"status": "affected",
"version": "37e776e2e0a523731e2470dce6d563f0e8632a40",
"versionType": "git"
},
{
"status": "affected",
"version": "72b7ea786b8e570ae11149e9089859a4a8634a13",
"versionType": "git"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.78",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.20",
"versionType": "semver"
},
{
"lessThan": "6.2",
"status": "affected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThan": "6.7",
"status": "affected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThan": "6.20",
"status": "affected",
"version": "6.19.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/cfg80211.h",
"net/wireless/core.c",
"net/wireless/core.h",
"net/wireless/pmsr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.0"
},
{
"lessThan": "7.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.78",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.1.167",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.6.130",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.19.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock\n\nWhen a netlink socket that owns a PMSR session is closed,\ncfg80211_release_pmsr() clears the request\u0027s nl_portid and queues\npmsr_free_wk to call cfg80211_pmsr_process_abort() asynchronously.\n\nIf the interface tears down concurrently, cfg80211_pmsr_wdev_down()\nis called under wiphy_lock and calls cancel_work_sync(\u0026pmsr_free_wk)\nto wait for any running work. The work function acquires wiphy_lock\nvia guard(wiphy) before calling process_abort.\n\nThis is a deadlock: wdev_down holds wiphy_lock and blocks inside\ncancel_work_sync(); pmsr_free_wk blocks trying to acquire that same\nwiphy_lock. Neither thread can proceed.\n\nThe same deadlock is reachable from cfg80211_leave_locked(), which\ncalls cfg80211_pmsr_wdev_down() for all interface types under\nwiphy_lock.\n\nFix this by converting pmsr_free_wk from a plain work_struct to a\nwiphy_work. The wiphy_work dispatcher holds wiphy_lock when running\nwork items, so the explicit guard(wiphy) in the work function is no\nlonger needed. wiphy_work_cancel() can be called safely while holding\nwiphy_lock - since wiphy_lock prevents the work from running\nconcurrently, wiphy_work_cancel() never blocks, eliminating the\ndeadlock.\n\nRemove the cancel_work_sync() for pmsr_free_wk from the\nNETDEV_GOING_DOWN handler. cfg80211_leave(), called unconditionally\njust before it, already cancels any pending work under wiphy_lock\nvia wiphy_work_cancel() inside cfg80211_pmsr_wdev_down()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:58.708Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/21512b5f7a74fd18c996c22e6854efe57d570816"
},
{
"url": "https://git.kernel.org/stable/c/133684982dd0c24359fcc641d19d89cc17d6e5ef"
},
{
"url": "https://git.kernel.org/stable/c/0a77d9fb4d5c0e01306cd406ffdee8f1fe955c0e"
},
{
"url": "https://git.kernel.org/stable/c/2b0eab425e1f658d8fe1df7590e3b9af5959505e"
}
],
"title": "wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68408",
"datePublished": "2026-08-10T12:04:28.172Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-17T05:04:58.708Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74297 (GCVE-0-2026-74297)
Vulnerability from cvelistv5
Published
2026-08-15 05:58
Modified
2026-08-17 05:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mlx5: Fix undefined shift of user RQ WQE size
set_rq_size() computes the RQ WQE size as "1 << rq_wqe_shift" based on
the user-provided rq_wqe_shift, which is only checked to be greater than
32, so shifts of 32 are still accepted. A shift of 31 also overflows a
signed integer, leading to undefined behavior.
Use check_shl_overflow() to compute the RQ WQE size and reject any
invalid values.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c Version: e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c Version: e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c Version: e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c Version: e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c Version: e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c Version: e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c Version: e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/mlx5/qp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9fff54929cc00849d738faa99f06c32399aeb026",
"status": "affected",
"version": "e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c",
"versionType": "git"
},
{
"lessThan": "b746f949c2ac2b041102836095d6d4a2ef21fa75",
"status": "affected",
"version": "e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c",
"versionType": "git"
},
{
"lessThan": "c1dbf52d24a8cb1aa56780ba51b72e7d495f258c",
"status": "affected",
"version": "e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c",
"versionType": "git"
},
{
"lessThan": "6fc874fdfb366bfb11c62e6af9a831c8be59ddda",
"status": "affected",
"version": "e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c",
"versionType": "git"
},
{
"lessThan": "42f3d2c8c18b92ea33e506a38b64f1a8986c2823",
"status": "affected",
"version": "e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c",
"versionType": "git"
},
{
"lessThan": "4b87a2497276a72fd63028e7419abf0fb7ed837b",
"status": "affected",
"version": "e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c",
"versionType": "git"
},
{
"lessThan": "b732db02a2b04cde393638df19de6251ce62a74e",
"status": "affected",
"version": "e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c",
"versionType": "git"
},
{
"lessThan": "d881d60223aac8fdc12b227d89c76e131e92a9cd",
"status": "affected",
"version": "e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/mlx5/qp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.11"
},
{
"lessThan": "3.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix undefined shift of user RQ WQE size\n\nset_rq_size() computes the RQ WQE size as \"1 \u003c\u003c rq_wqe_shift\" based on\nthe user-provided rq_wqe_shift, which is only checked to be greater than\n32, so shifts of 32 are still accepted. A shift of 31 also overflows a\nsigned integer, leading to undefined behavior.\n\nUse check_shl_overflow() to compute the RQ WQE size and reject any\ninvalid values."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local ioctl on /dev/infiniband/uverbs to IB_USER_VERBS_CMD_CREATE_QP; malicious rq_wqe_shift is supplied in mlx5_ib_create_qp userspace data, not from remote RDMA/InfiniBand wire traffic.\nAC:L - An attacker with uverbs access can deterministically pass rq_wqe_shift values 31 or 32 in create_qp driver udata; no races or victim state beyond opening the device and issuing the ioctl are required.\nPR:L - Only local access to the RDMA character device is required (typically rdma group membership on HPC/AI cloud GPU nodes), not init-namespace root; this matches basic local user capability rather than administrator privilege.\nUI:N - No victim interaction is needed; the attacker triggers the flaw entirely through their own create_qp ioctl with crafted mlx5_ib_create_qp fields.\nS:U - Impact stays within the kernel and RDMA context of the attacking process/tenant; it is not a VM-hypervisor or cross-security-authority boundary escape despite using a network-capable NIC.\nC:H - Integer overflow/undefined shift can undersize ib_umem registration while hardware is programmed with a huge RQ stride, enabling out-of-bounds DMA reads and kernel/user memory disclosure beyond the registered queue buffer.\nI:H - Corrupted max_gs (e.g. negative from shift 31) bypasses scatter/gather limits in post_recv, and undersized buffers with oversized hardware stride allow out-of-bounds writes and exploitable memory corruption.\nA:H - Undefined signed shifts and inconsistent queue sizing can cause kernel oops/panic during QP setup or later queue operations, and misprogrammed hardware can hang or crash the host under active RDMA use."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:45:36.087Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9fff54929cc00849d738faa99f06c32399aeb026"
},
{
"url": "https://git.kernel.org/stable/c/b746f949c2ac2b041102836095d6d4a2ef21fa75"
},
{
"url": "https://git.kernel.org/stable/c/c1dbf52d24a8cb1aa56780ba51b72e7d495f258c"
},
{
"url": "https://git.kernel.org/stable/c/6fc874fdfb366bfb11c62e6af9a831c8be59ddda"
},
{
"url": "https://git.kernel.org/stable/c/42f3d2c8c18b92ea33e506a38b64f1a8986c2823"
},
{
"url": "https://git.kernel.org/stable/c/4b87a2497276a72fd63028e7419abf0fb7ed837b"
},
{
"url": "https://git.kernel.org/stable/c/b732db02a2b04cde393638df19de6251ce62a74e"
},
{
"url": "https://git.kernel.org/stable/c/d881d60223aac8fdc12b227d89c76e131e92a9cd"
}
],
"title": "RDMA/mlx5: Fix undefined shift of user RQ WQE size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74297",
"datePublished": "2026-08-15T05:58:01.414Z",
"dateReserved": "2026-08-15T05:44:03.882Z",
"dateUpdated": "2026-08-17T05:45:36.087Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64168 (GCVE-0-2026-64168)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-07-19 15:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
spi: sprd: fix error pointer deref after DMA setup failure
The driver falls back to PIO mode if DMA setup fails during probe.
Make sure to check the dma.enabled flag before trying to release the DMA
channels also on late probe errors to avoid dereferencing an error
pointer (or attempting to release a channel a second time).
This issue was flagged by Sashiko when reviewing a devres allocation
conversion patch.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 386119bc7be9fa5114ced0274a22a943df890b4b Version: 386119bc7be9fa5114ced0274a22a943df890b4b Version: 386119bc7be9fa5114ced0274a22a943df890b4b Version: 386119bc7be9fa5114ced0274a22a943df890b4b Version: 386119bc7be9fa5114ced0274a22a943df890b4b Version: 386119bc7be9fa5114ced0274a22a943df890b4b Version: 386119bc7be9fa5114ced0274a22a943df890b4b Version: 386119bc7be9fa5114ced0274a22a943df890b4b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/spi/spi-sprd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "be74e276111f3c23b8e040c8c5e308f67a573add",
"status": "affected",
"version": "386119bc7be9fa5114ced0274a22a943df890b4b",
"versionType": "git"
},
{
"lessThan": "a8f233fb0c7be29b97cd249f64120bf35ce72805",
"status": "affected",
"version": "386119bc7be9fa5114ced0274a22a943df890b4b",
"versionType": "git"
},
{
"lessThan": "0cdea166c1a07c200caf9d0b722224fca43b23ae",
"status": "affected",
"version": "386119bc7be9fa5114ced0274a22a943df890b4b",
"versionType": "git"
},
{
"lessThan": "450c319dd04d0eeff4184889768f7ada826a2e35",
"status": "affected",
"version": "386119bc7be9fa5114ced0274a22a943df890b4b",
"versionType": "git"
},
{
"lessThan": "b6f1acf4e57ccf708cdc0cb70f5bb5b65162963b",
"status": "affected",
"version": "386119bc7be9fa5114ced0274a22a943df890b4b",
"versionType": "git"
},
{
"lessThan": "be409d2bbe9ca7da7b05cc7dde7499bc481f0766",
"status": "affected",
"version": "386119bc7be9fa5114ced0274a22a943df890b4b",
"versionType": "git"
},
{
"lessThan": "c33b4496e95d04722055446c0a31213639438536",
"status": "affected",
"version": "386119bc7be9fa5114ced0274a22a943df890b4b",
"versionType": "git"
},
{
"lessThan": "3d67fffb74267772d461c02c67f1eff893ad547d",
"status": "affected",
"version": "386119bc7be9fa5114ced0274a22a943df890b4b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/spi/spi-sprd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: sprd: fix error pointer deref after DMA setup failure\n\nThe driver falls back to PIO mode if DMA setup fails during probe.\n\nMake sure to check the dma.enabled flag before trying to release the DMA\nchannels also on late probe errors to avoid dereferencing an error\npointer (or attempting to release a channel a second time).\n\nThis issue was flagged by Sashiko when reviewing a devres allocation\nconversion patch."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:40:52.741Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/be74e276111f3c23b8e040c8c5e308f67a573add"
},
{
"url": "https://git.kernel.org/stable/c/a8f233fb0c7be29b97cd249f64120bf35ce72805"
},
{
"url": "https://git.kernel.org/stable/c/0cdea166c1a07c200caf9d0b722224fca43b23ae"
},
{
"url": "https://git.kernel.org/stable/c/450c319dd04d0eeff4184889768f7ada826a2e35"
},
{
"url": "https://git.kernel.org/stable/c/b6f1acf4e57ccf708cdc0cb70f5bb5b65162963b"
},
{
"url": "https://git.kernel.org/stable/c/be409d2bbe9ca7da7b05cc7dde7499bc481f0766"
},
{
"url": "https://git.kernel.org/stable/c/c33b4496e95d04722055446c0a31213639438536"
},
{
"url": "https://git.kernel.org/stable/c/3d67fffb74267772d461c02c67f1eff893ad547d"
}
],
"title": "spi: sprd: fix error pointer deref after DMA setup failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64168",
"datePublished": "2026-07-19T15:40:52.741Z",
"dateReserved": "2026-07-19T07:54:57.038Z",
"dateUpdated": "2026-07-19T15:40:52.741Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64112 (GCVE-0-2026-64112)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rbd: eliminate a race in lock_dwork draining on unmap
Given how rbd_lock_add_request() and rbd_img_exclusive_lock() are
written, lock_dwork may be (re)queued more than it's actually needed:
for example in case a new I/O request comes in while we are in the
middle of rbd_acquire_lock() on behalf of another I/O request. This is
expected and with rbd_release_lock() preemptively canceling lock_dwork
is benign under normal operation.
A more problematic example is maybe_kick_acquire():
if (have_requests || delayed_work_pending(&rbd_dev->lock_dwork)) {
dout("%s rbd_dev %p kicking lock_dwork\n", __func__, rbd_dev);
mod_delayed_work(rbd_dev->task_wq, &rbd_dev->lock_dwork, 0);
}
It's not unrealistic for lock_dwork to get canceled right after
delayed_work_pending() returns true and for mod_delayed_work() to
requeue it right there anyway. This is a classic TOCTOU race.
When it comes to unmapping the image, there is an implicit assumption
of no self-initiated exclusive lock activity past the point of return
from rbd_dev_image_unlock() which unlocks the lock if it happens to be
held. This unlock is assumed to be final and lock_dwork (as well as
all other exclusive lock tasks, really) isn't expected to get queued
again. However, lock_dwork is canceled only in cancel_tasks_sync()
(i.e. later in the unmap sequence) and on top of that the cancellation
can get in effect nullified by maybe_kick_acquire(). This may result
in rbd_acquire_lock() executing after rbd_dev_device_release() and
rbd_dev_image_release() run and free and/or reset a bunch of things.
One of the possible failure modes then is a violated
rbd_assert(rbd_image_format_valid(rbd_dev->image_format));
in rbd_dev_header_info() which is called via rbd_dev_refresh() from
rbd_post_acquire_action().
Redo exclusive lock task draining to provide saner semantics and try
to meet the assumptions around rbd_dev_image_unlock().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/block/rbd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3427d7ae38337066ce88b68302e285d344ab756b",
"status": "affected",
"version": "fd22aef8b47cfc068448df65c1183698b0abd815",
"versionType": "git"
},
{
"lessThan": "9dcd4f5c99b491c37be90b0bd9988db48225fb75",
"status": "affected",
"version": "fd22aef8b47cfc068448df65c1183698b0abd815",
"versionType": "git"
},
{
"lessThan": "9400efc76b42c751211974a25c91d2c19c65b01b",
"status": "affected",
"version": "fd22aef8b47cfc068448df65c1183698b0abd815",
"versionType": "git"
},
{
"lessThan": "9fc75b71fdd38465c76c6f6a884cdd4ae3c72d90",
"status": "affected",
"version": "fd22aef8b47cfc068448df65c1183698b0abd815",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/block/rbd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrbd: eliminate a race in lock_dwork draining on unmap\n\nGiven how rbd_lock_add_request() and rbd_img_exclusive_lock() are\nwritten, lock_dwork may be (re)queued more than it\u0027s actually needed:\nfor example in case a new I/O request comes in while we are in the\nmiddle of rbd_acquire_lock() on behalf of another I/O request. This is\nexpected and with rbd_release_lock() preemptively canceling lock_dwork\nis benign under normal operation.\n\nA more problematic example is maybe_kick_acquire():\n\n if (have_requests || delayed_work_pending(\u0026rbd_dev-\u003elock_dwork)) {\n dout(\"%s rbd_dev %p kicking lock_dwork\\n\", __func__, rbd_dev);\n mod_delayed_work(rbd_dev-\u003etask_wq, \u0026rbd_dev-\u003elock_dwork, 0);\n }\n\nIt\u0027s not unrealistic for lock_dwork to get canceled right after\ndelayed_work_pending() returns true and for mod_delayed_work() to\nrequeue it right there anyway. This is a classic TOCTOU race.\n\nWhen it comes to unmapping the image, there is an implicit assumption\nof no self-initiated exclusive lock activity past the point of return\nfrom rbd_dev_image_unlock() which unlocks the lock if it happens to be\nheld. This unlock is assumed to be final and lock_dwork (as well as\nall other exclusive lock tasks, really) isn\u0027t expected to get queued\nagain. However, lock_dwork is canceled only in cancel_tasks_sync()\n(i.e. later in the unmap sequence) and on top of that the cancellation\ncan get in effect nullified by maybe_kick_acquire(). This may result\nin rbd_acquire_lock() executing after rbd_dev_device_release() and\nrbd_dev_image_release() run and free and/or reset a bunch of things.\nOne of the possible failure modes then is a violated\n\n rbd_assert(rbd_image_format_valid(rbd_dev-\u003eimage_format));\n\nin rbd_dev_header_info() which is called via rbd_dev_refresh() from\nrbd_post_acquire_action().\n\nRedo exclusive lock task draining to provide saner semantics and try\nto meet the assumptions around rbd_dev_image_unlock()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires writing to /sys/bus/rbd/remove (or the equivalent error-path teardown during map), which is a local sysfs syscall path; network-delivered Ceph lock notifications can assist the race but cannot complete exploitation without this local unmap action.\nAC:L - The attacker controls both sides of the TOCTOU race by concurrently unmapping the device (sysfs remove) while driving lock activity through block I/O or lock-notification handling, making the race winnable with repeated attempts.\nPR:L - Both map and unmap operations require CAP_SYS_ADMIN, which is obtainable by an unprivileged user via user namespaces (unshare -Urn); per kernel CNA guidance this is PR:L rather than PR:H.\nUI:N - No victim interaction is required; the attacker can trigger the race programmatically through concurrent sysfs unmap and I/O or lock-notification activity.\nS:U - Impact is confined to kernel memory corruption and crash on the host running the RBD client; it does not cross a VM, container, or IOMMU security boundary.\nC:H - The bug allows rbd_acquire_lock() to operate on an rbd_device after rbd_dev_image_release() has freed and reset fields, constituting a use-after-free that can expose or dereference freed kernel heap data.\nI:H - Use-after-free on rbd_device and associated header structures provides memory corruption primitives that could be leveraged for arbitrary kernel writes or control-flow hijacking, not merely a clean crash.\nA:H - A confirmed failure mode is rbd_assert() triggering BUG() (kernel panic), and the underlying UAF can also cause oops or hang during post-teardown lock acquisition."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:21.112Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3427d7ae38337066ce88b68302e285d344ab756b"
},
{
"url": "https://git.kernel.org/stable/c/9dcd4f5c99b491c37be90b0bd9988db48225fb75"
},
{
"url": "https://git.kernel.org/stable/c/9400efc76b42c751211974a25c91d2c19c65b01b"
},
{
"url": "https://git.kernel.org/stable/c/9fc75b71fdd38465c76c6f6a884cdd4ae3c72d90"
}
],
"title": "rbd: eliminate a race in lock_dwork draining on unmap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64112",
"datePublished": "2026-07-19T15:40:13.652Z",
"dateReserved": "2026-07-19T07:54:57.035Z",
"dateUpdated": "2026-08-05T12:39:21.112Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74537 (GCVE-0-2026-74537)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-17 05:48
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: hold sk properly in iso_conn_ready
sk deref in iso_conn_ready must be done either under conn->lock, or
holding a refcount, to avoid concurrent close. conn->sk is currently
accessed without either:
[Task 1] [Task 2]
iso_sock_release
iso_conn_ready
sk = conn->sk
lock_sock(sk)
conn->sk = NULL
lock_sock(sk)
release_sock(sk)
iso_sock_kill(sk)
UAF on sk deref
Fix possible UAF by holding sk refcount in iso_conn_ready(). Also
recheck after lock_sock that the socket is still valid. Adjust locking
so conn->sk is cleared only under lock_sock.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/iso.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4e9b5e8669b3602a4e01b6d1e9539b72e42c84d5",
"status": "affected",
"version": "27c24fda62b601d6f9ca5e992502578c4310876f",
"versionType": "git"
},
{
"lessThan": "1308d72903d792d10b82bc4ef08b8a4452308b04",
"status": "affected",
"version": "27c24fda62b601d6f9ca5e992502578c4310876f",
"versionType": "git"
},
{
"lessThan": "0d255e63fcf3f13a570d7ac11678fa1164ac015c",
"status": "affected",
"version": "27c24fda62b601d6f9ca5e992502578c4310876f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/iso.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: hold sk properly in iso_conn_ready\n\nsk deref in iso_conn_ready must be done either under conn-\u003elock, or\nholding a refcount, to avoid concurrent close. conn-\u003esk is currently\naccessed without either:\n\n [Task 1] [Task 2]\n iso_sock_release\n iso_conn_ready\n sk = conn-\u003esk\n lock_sock(sk)\n conn-\u003esk = NULL\n lock_sock(sk)\n release_sock(sk)\n iso_sock_kill(sk)\n UAF on sk deref\n\nFix possible UAF by holding sk refcount in iso_conn_ready(). Also\nrecheck after lock_sock that the socket is still valid. Adjust locking\nso conn-\u003esk is cleared only under lock_sock."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is in the Bluetooth ISO stack; iso_conn_ready runs from HCI connection-confirmation events (CIS/BIS/PA sync) driven by LE isochronous traffic from Bluetooth peers within radio range, which is an adjacent attack surface (phones, earbuds, automotive, embedded).\nAC:L - This is a use-after-free race between iso_conn_ready and iso_sock_release/iso_sock_kill; an attacker who controls both an ISO socket close and concurrent HCI completion (e.g., dual-thread connect/close or rapid adjacent CIS/BIS establish-teardown) can reliably trigger it without uncontrollable conditions.\nPR:N - Exploitation requires no elevated credentials on the victim: HCI events are processed for any Bluetooth-enabled device in range, and the racing socket close can occur from automatic stack/daemon teardown during connection setup without the victim performing privileged local actions.\nUI:N - No victim interaction is required when the OS Bluetooth stack (e.g., LE Audio on Android phones or bluetoothd on Linux) automatically manages ISO sockets during pairing, reconnection, or broadcast sync while processing peer-initiated CIS/BIS traffic.\nS:U - The UAF corrupts kernel socket memory and can enable local privilege escalation within the kernel; it does not cross a VM, container, or IOMMU security boundary, so scope remains unchanged.\nC:H - Use-after-free on struct sock after iso_sock_kill frees the socket lets an attacker dereference attacker-influenced freed heap memory, enabling arbitrary kernel memory disclosure via heap grooming and reuse of the sock object.\nI:H - The UAF touches sk-\u003esk_state and sk-\u003esk_state_change during iso_sock_ready on a freed sock, providing a standard kernel heap corruption primitive that can be leveraged for arbitrary write and control-flow hijack.\nA:H - Concurrent iso_sock_kill and iso_conn_ready can dereference freed socket memory, causing kernel oops/panic from invalid lock_sock/sk_state access; UAF in the Bluetooth ISO path is inherently a high-availability risk even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:48:25.530Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4e9b5e8669b3602a4e01b6d1e9539b72e42c84d5"
},
{
"url": "https://git.kernel.org/stable/c/1308d72903d792d10b82bc4ef08b8a4452308b04"
},
{
"url": "https://git.kernel.org/stable/c/0d255e63fcf3f13a570d7ac11678fa1164ac015c"
}
],
"title": "Bluetooth: ISO: hold sk properly in iso_conn_ready",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74537",
"datePublished": "2026-08-15T12:27:49.668Z",
"dateReserved": "2026-08-15T05:44:03.913Z",
"dateUpdated": "2026-08-17T05:48:25.530Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-45968 (GCVE-0-2026-45968)
Vulnerability from cvelistv5
Published
2026-05-27 12:18
Modified
2026-05-27 12:18
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
cpuidle: Skip governor when only one idle state is available
On certain platforms (PowerNV systems without a power-mgt DT node),
cpuidle may register only a single idle state. In cases where that
single state is a polling state (state 0), the ladder governor may
incorrectly treat state 1 as the first usable state and pass an
out-of-bounds index. This can lead to a NULL enter callback being
invoked, ultimately resulting in a system crash.
[ 13.342636] cpuidle-powernv : Only Snooze is available
[ 13.351854] Faulting instruction address: 0x00000000
[ 13.376489] NIP [0000000000000000] 0x0
[ 13.378351] LR [c000000001e01974] cpuidle_enter_state+0x2c4/0x668
Fix this by adding a bail-out in cpuidle_select() that returns state 0
directly when state_count <= 1, bypassing the governor and keeping the
tick running.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: dc2251bf98c66db3f4e055b751968f0871037ae4 Version: dc2251bf98c66db3f4e055b751968f0871037ae4 Version: dc2251bf98c66db3f4e055b751968f0871037ae4 Version: dc2251bf98c66db3f4e055b751968f0871037ae4 Version: dc2251bf98c66db3f4e055b751968f0871037ae4 Version: dc2251bf98c66db3f4e055b751968f0871037ae4 Version: dc2251bf98c66db3f4e055b751968f0871037ae4 Version: dc2251bf98c66db3f4e055b751968f0871037ae4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/cpuidle/cpuidle.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a0f7e804edc82e513d1ccb7c95ed8b351522ec81",
"status": "affected",
"version": "dc2251bf98c66db3f4e055b751968f0871037ae4",
"versionType": "git"
},
{
"lessThan": "5d103a38e2ae96eca57fd17161bcd29bd4622d1c",
"status": "affected",
"version": "dc2251bf98c66db3f4e055b751968f0871037ae4",
"versionType": "git"
},
{
"lessThan": "4da2b897283c39980d6ae09dc1560fcd937879e5",
"status": "affected",
"version": "dc2251bf98c66db3f4e055b751968f0871037ae4",
"versionType": "git"
},
{
"lessThan": "5c577ac939bca486cb02069505cfe47a5312ce02",
"status": "affected",
"version": "dc2251bf98c66db3f4e055b751968f0871037ae4",
"versionType": "git"
},
{
"lessThan": "8f6833d919bae915ead6c599a53e81e19b32da52",
"status": "affected",
"version": "dc2251bf98c66db3f4e055b751968f0871037ae4",
"versionType": "git"
},
{
"lessThan": "63ae78336f40bcd9a44952a7c6bafb9c88a8effd",
"status": "affected",
"version": "dc2251bf98c66db3f4e055b751968f0871037ae4",
"versionType": "git"
},
{
"lessThan": "a0724e40a58a0e323c59707edeae5b71d15800dc",
"status": "affected",
"version": "dc2251bf98c66db3f4e055b751968f0871037ae4",
"versionType": "git"
},
{
"lessThan": "e5c9ffc6ae1bcdb1062527d611043681ac301aca",
"status": "affected",
"version": "dc2251bf98c66db3f4e055b751968f0871037ae4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/cpuidle/cpuidle.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.252",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.202",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.252",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.202",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.14",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpuidle: Skip governor when only one idle state is available\n\nOn certain platforms (PowerNV systems without a power-mgt DT node),\ncpuidle may register only a single idle state. In cases where that\nsingle state is a polling state (state 0), the ladder governor may\nincorrectly treat state 1 as the first usable state and pass an\nout-of-bounds index. This can lead to a NULL enter callback being\ninvoked, ultimately resulting in a system crash.\n\n[ 13.342636] cpuidle-powernv : Only Snooze is available\n[ 13.351854] Faulting instruction address: 0x00000000\n[ 13.376489] NIP [0000000000000000] 0x0\n[ 13.378351] LR [c000000001e01974] cpuidle_enter_state+0x2c4/0x668\n\nFix this by adding a bail-out in cpuidle_select() that returns state 0\ndirectly when state_count \u003c= 1, bypassing the governor and keeping the\ntick running."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-27T12:18:27.247Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a0f7e804edc82e513d1ccb7c95ed8b351522ec81"
},
{
"url": "https://git.kernel.org/stable/c/5d103a38e2ae96eca57fd17161bcd29bd4622d1c"
},
{
"url": "https://git.kernel.org/stable/c/4da2b897283c39980d6ae09dc1560fcd937879e5"
},
{
"url": "https://git.kernel.org/stable/c/5c577ac939bca486cb02069505cfe47a5312ce02"
},
{
"url": "https://git.kernel.org/stable/c/8f6833d919bae915ead6c599a53e81e19b32da52"
},
{
"url": "https://git.kernel.org/stable/c/63ae78336f40bcd9a44952a7c6bafb9c88a8effd"
},
{
"url": "https://git.kernel.org/stable/c/a0724e40a58a0e323c59707edeae5b71d15800dc"
},
{
"url": "https://git.kernel.org/stable/c/e5c9ffc6ae1bcdb1062527d611043681ac301aca"
}
],
"title": "cpuidle: Skip governor when only one idle state is available",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-45968",
"datePublished": "2026-05-27T12:18:27.247Z",
"dateReserved": "2026-05-13T15:03:33.089Z",
"dateUpdated": "2026-05-27T12:18:27.247Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64018 (GCVE-0-2026-64018)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-08-05 12:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mana: validate rx_req_idx to prevent out-of-bounds array access
In mana_hwc_rx_event_handler(), rx_req_idx is derived from
sge->address in DMA-coherent memory. In Confidential VMs
(SEV-SNP/TDX), this memory is shared unencrypted and HW can modify
WQE contents at any time. No bounds check exists on rx_req_idx,
which can lead to an out-of-bounds access into reqs[].
Add bounds check on rx_req_idx in mana_hwc_rx_event_handler() before
using it to index the reqs[] array.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/hw_channel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5ddc715324badd7f2641bc177db1d027b402adae",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "ff1d5af207bcea857d45fe81505f1bc4b29eaef0",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "01f7f893d5e1baae995beeb86cd0f3e6bb2a3b01",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "763a372d344fb12fae566d36ddb46e92454ad58c",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "fa627a5eaa83fc0261f44ef3769693b886ca6e27",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "355e9f2b2a7887ca38100127989af3e422ba71d0",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "b809d0409991b75a6cff846a5ac27c3062953f84",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/hw_channel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: validate rx_req_idx to prevent out-of-bounds array access\n\nIn mana_hwc_rx_event_handler(), rx_req_idx is derived from\nsge-\u003eaddress in DMA-coherent memory. In Confidential VMs\n(SEV-SNP/TDX), this memory is shared unencrypted and HW can modify\nWQE contents at any time. No bounds check exists on rx_req_idx,\nwhich can lead to an out-of-bounds access into reqs[].\n\nAdd bounds check on rx_req_idx in mana_hwc_rx_event_handler() before\nusing it to index the reqs[] array."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached via MSI-driven hardware completion processing in the MANA HWC control path (not netdev packet receive), triggered when the Azure hypervisor/host tampers with guest-visible DMA-coherent WQE memory on the same physical compute node.\nAC:L - A malicious host or NIC firmware that can modify shared unencrypted DMA buffers controls both the forged sge-\u003eaddress and the timing of HWC RX completions, allowing reliable out-of-bounds indexing without winning a race or depending on guest state.\nPR:N - Exploitation requires no privileges on the victim guest VM; the attacker operates from the Azure hypervisor/host side by modifying DMA-coherent memory that the guest kernel trusts during HWC response handling.\nUI:N - No victim user action is required; exploitation occurs automatically when the driver processes a hardware completion event on the HWC receive queue.\nS:C - In Confidential VMs the guest relies on host isolation guarantees, but shared unencrypted DMA memory lets a hostile hypervisor cross that CVM security boundary to corrupt guest kernel memory and confidentiality.\nC:H - An out-of-bounds rx_req_idx yields a corrupted hwc_work_request whose buf_va is dereferenced and copied via memcpy in mana_hwc_handle_resp(), enabling arbitrary kernel memory disclosure.\nI:H - The out-of-bounds hwc_work_request supplies attacker-controlled pointers and SGE fields used to repost RX WQEs via mana_hwc_post_rx_wqe(), enabling kernel heap corruption and exploitable memory writes.\nA:H - Indexing reqs[] out of bounds with attacker-controlled values can dereference invalid kernel pointers and corrupt adjacent heap objects, causing kernel oops/panic and denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:38:15.556Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5ddc715324badd7f2641bc177db1d027b402adae"
},
{
"url": "https://git.kernel.org/stable/c/ff1d5af207bcea857d45fe81505f1bc4b29eaef0"
},
{
"url": "https://git.kernel.org/stable/c/01f7f893d5e1baae995beeb86cd0f3e6bb2a3b01"
},
{
"url": "https://git.kernel.org/stable/c/763a372d344fb12fae566d36ddb46e92454ad58c"
},
{
"url": "https://git.kernel.org/stable/c/fa627a5eaa83fc0261f44ef3769693b886ca6e27"
},
{
"url": "https://git.kernel.org/stable/c/355e9f2b2a7887ca38100127989af3e422ba71d0"
},
{
"url": "https://git.kernel.org/stable/c/b809d0409991b75a6cff846a5ac27c3062953f84"
}
],
"title": "net: mana: validate rx_req_idx to prevent out-of-bounds array access",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64018",
"datePublished": "2026-07-19T15:39:12.704Z",
"dateReserved": "2026-07-19T07:54:57.027Z",
"dateUpdated": "2026-08-05T12:38:15.556Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64455 (GCVE-0-2026-64455)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
The chaoskey driver has a use-after-free bug in its release routine.
If the user closes the device file after the USB device has been
unplugged, a debugging log statement will try to access the
usb_interface structure after it has been deallocated:
BUG: KASAN: slab-use-after-free in dev_driver_string (drivers/base/core.c:2406)
Read of size 8 at addr ffff888168e8a0b8 by task chaoskey_raw_re/10106
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)
print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)
kasan_report (mm/kasan/report.c:595)
dev_driver_string (drivers/base/core.c:2406)
__dynamic_dev_dbg (lib/dynamic_debug.c:906)
chaoskey_release (drivers/usb/misc/chaoskey.c:323)
__fput (fs/file_table.c:510)
fput_close_sync (fs/file_table.c:615)
__x64_sys_close (fs/open.c:1507 fs/open.c:1492 fs/open.c:1492)
do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
The driver's last reference to the interface structure is dropped in
the chaoskey_free() routine, so the code must not use the interface --
even in a debugging statement -- after that routine returns.
(Exception: If we know that another reference is held by someone else,
such as the device core while the disconnect routine runs, there's no
problem. Thanks to Johan Hovold for pointing this out.)
Since the bad access is part of an unimportant debugging statement,
we can fix the problem simply by removing the whole statement.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 66e3e591891da9899a8990792da080432531ffd4 Version: 66e3e591891da9899a8990792da080432531ffd4 Version: 66e3e591891da9899a8990792da080432531ffd4 Version: 66e3e591891da9899a8990792da080432531ffd4 Version: 66e3e591891da9899a8990792da080432531ffd4 Version: 66e3e591891da9899a8990792da080432531ffd4 Version: 66e3e591891da9899a8990792da080432531ffd4 Version: 66e3e591891da9899a8990792da080432531ffd4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/chaoskey.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fe7a0f4be283b40dd592540027279735120d0d6f",
"status": "affected",
"version": "66e3e591891da9899a8990792da080432531ffd4",
"versionType": "git"
},
{
"lessThan": "5ec61fbef9ec5635c492ae63dfb5d13f2bdf1023",
"status": "affected",
"version": "66e3e591891da9899a8990792da080432531ffd4",
"versionType": "git"
},
{
"lessThan": "f3e409476ad0703c54c14f245e4e143c8124e1bd",
"status": "affected",
"version": "66e3e591891da9899a8990792da080432531ffd4",
"versionType": "git"
},
{
"lessThan": "6c82f88bc7a8458d5c60f9b354c4d32d233f0cac",
"status": "affected",
"version": "66e3e591891da9899a8990792da080432531ffd4",
"versionType": "git"
},
{
"lessThan": "3ad5fbcced4e9c2b0fee3c1b76289a147fc35b89",
"status": "affected",
"version": "66e3e591891da9899a8990792da080432531ffd4",
"versionType": "git"
},
{
"lessThan": "2a52d55c86a429dac47886b8424e67f90b001e67",
"status": "affected",
"version": "66e3e591891da9899a8990792da080432531ffd4",
"versionType": "git"
},
{
"lessThan": "8f50613bff228272577893aa10a346a2f3063e49",
"status": "affected",
"version": "66e3e591891da9899a8990792da080432531ffd4",
"versionType": "git"
},
{
"lessThan": "abf76d3239dee97b66e7241ad04811f1ce562e28",
"status": "affected",
"version": "66e3e591891da9899a8990792da080432531ffd4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/misc/chaoskey.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: chaoskey: Fix slab-use-after-free in chaoskey_release()\n\nThe chaoskey driver has a use-after-free bug in its release routine.\nIf the user closes the device file after the USB device has been\nunplugged, a debugging log statement will try to access the\nusb_interface structure after it has been deallocated:\n\n\tBUG: KASAN: slab-use-after-free in dev_driver_string (drivers/base/core.c:2406)\n\tRead of size 8 at addr ffff888168e8a0b8 by task chaoskey_raw_re/10106\n\n\tHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n\tCall Trace:\n\t \u003cTASK\u003e\n\t dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n\t print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)\n\t kasan_report (mm/kasan/report.c:595)\n\t dev_driver_string (drivers/base/core.c:2406)\n\t __dynamic_dev_dbg (lib/dynamic_debug.c:906)\n\t chaoskey_release (drivers/usb/misc/chaoskey.c:323)\n\t __fput (fs/file_table.c:510)\n\t fput_close_sync (fs/file_table.c:615)\n\t __x64_sys_close (fs/open.c:1507 fs/open.c:1492 fs/open.c:1492)\n\t do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n\t entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nThe driver\u0027s last reference to the interface structure is dropped in\nthe chaoskey_free() routine, so the code must not use the interface --\neven in a debugging statement -- after that routine returns.\n(Exception: If we know that another reference is held by someone else,\nsuch as the device core while the disconnect routine runs, there\u0027s no\nproblem. Thanks to Johan Hovold for pointing this out.)\n\nSince the bad access is part of an unimportant debugging statement,\nwe can fix the problem simply by removing the whole statement."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:59.518Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fe7a0f4be283b40dd592540027279735120d0d6f"
},
{
"url": "https://git.kernel.org/stable/c/5ec61fbef9ec5635c492ae63dfb5d13f2bdf1023"
},
{
"url": "https://git.kernel.org/stable/c/f3e409476ad0703c54c14f245e4e143c8124e1bd"
},
{
"url": "https://git.kernel.org/stable/c/6c82f88bc7a8458d5c60f9b354c4d32d233f0cac"
},
{
"url": "https://git.kernel.org/stable/c/3ad5fbcced4e9c2b0fee3c1b76289a147fc35b89"
},
{
"url": "https://git.kernel.org/stable/c/2a52d55c86a429dac47886b8424e67f90b001e67"
},
{
"url": "https://git.kernel.org/stable/c/8f50613bff228272577893aa10a346a2f3063e49"
},
{
"url": "https://git.kernel.org/stable/c/abf76d3239dee97b66e7241ad04811f1ce562e28"
}
],
"title": "USB: chaoskey: Fix slab-use-after-free in chaoskey_release()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64455",
"datePublished": "2026-07-25T08:51:23.952Z",
"dateReserved": "2026-07-19T15:36:31.789Z",
"dateUpdated": "2026-08-17T04:55:59.518Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64483 (GCVE-0-2026-64483)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire: isight: bound the sample count to the packet payload
isight_packet() takes the frame count from the device iso packet and
checks it only against the device claimed iso length.
count = be32_to_cpu(payload->sample_count);
if (likely(count <= (length - 16) / 4))
isight_samples(isight, payload->samples, count);
length is the iso header data_length. It can be up to 0xffff. So the
gate allows a count up to about 16379. isight_samples() then copies
count frames out of payload->samples into the PCM DMA buffer.
payload->samples holds only 2 * MAX_FRAMES_PER_PACKET values. The
device multiplexes two samples per frame. A count past
MAX_FRAMES_PER_PACKET reads past the payload. A count past the buffer
size writes past runtime->dma_area. The smallest PCM buffer is larger
than MAX_FRAMES_PER_PACKET. Bounding the count to MAX_FRAMES_PER_PACKET
keeps both the read and the write in range.
A malicious or faulty Apple iSight on the FireWire bus reaches this
during a normal capture.
Add the MAX_FRAMES_PER_PACKET bound to the gate.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3a691b28a0ca3cf4d9010c6158318159e0275d2c Version: 3a691b28a0ca3cf4d9010c6158318159e0275d2c Version: 3a691b28a0ca3cf4d9010c6158318159e0275d2c Version: 3a691b28a0ca3cf4d9010c6158318159e0275d2c Version: 3a691b28a0ca3cf4d9010c6158318159e0275d2c Version: 3a691b28a0ca3cf4d9010c6158318159e0275d2c Version: 3a691b28a0ca3cf4d9010c6158318159e0275d2c Version: 3a691b28a0ca3cf4d9010c6158318159e0275d2c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/firewire/isight.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "24423e0a9251d348c3f1fb0bb0e61b879e1e976c",
"status": "affected",
"version": "3a691b28a0ca3cf4d9010c6158318159e0275d2c",
"versionType": "git"
},
{
"lessThan": "ebbffacda6733dcbcef601b5b523460f8d8b671e",
"status": "affected",
"version": "3a691b28a0ca3cf4d9010c6158318159e0275d2c",
"versionType": "git"
},
{
"lessThan": "57e4d9043afc1eaddee8f50d11def6e65415d273",
"status": "affected",
"version": "3a691b28a0ca3cf4d9010c6158318159e0275d2c",
"versionType": "git"
},
{
"lessThan": "3ed2fa1ed8cc65f910b8bbc0be3cc366b30f8478",
"status": "affected",
"version": "3a691b28a0ca3cf4d9010c6158318159e0275d2c",
"versionType": "git"
},
{
"lessThan": "31da82b9676c6b112e7c72c7529e6812b919742a",
"status": "affected",
"version": "3a691b28a0ca3cf4d9010c6158318159e0275d2c",
"versionType": "git"
},
{
"lessThan": "8e48a29813df8dd71503800b7acf69c12c035045",
"status": "affected",
"version": "3a691b28a0ca3cf4d9010c6158318159e0275d2c",
"versionType": "git"
},
{
"lessThan": "31a01b70bb90e3ef3147f308e2ea899e1d2485ca",
"status": "affected",
"version": "3a691b28a0ca3cf4d9010c6158318159e0275d2c",
"versionType": "git"
},
{
"lessThan": "29b9667982e4df2ed7744f86b1144f8bb58eb698",
"status": "affected",
"version": "3a691b28a0ca3cf4d9010c6158318159e0275d2c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/firewire/isight.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.0"
},
{
"lessThan": "3.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: firewire: isight: bound the sample count to the packet payload\n\nisight_packet() takes the frame count from the device iso packet and\nchecks it only against the device claimed iso length.\n\n\tcount = be32_to_cpu(payload-\u003esample_count);\n\tif (likely(count \u003c= (length - 16) / 4))\n\t\tisight_samples(isight, payload-\u003esamples, count);\n\nlength is the iso header data_length. It can be up to 0xffff. So the\ngate allows a count up to about 16379. isight_samples() then copies\ncount frames out of payload-\u003esamples into the PCM DMA buffer.\n\npayload-\u003esamples holds only 2 * MAX_FRAMES_PER_PACKET values. The\ndevice multiplexes two samples per frame. A count past\nMAX_FRAMES_PER_PACKET reads past the payload. A count past the buffer\nsize writes past runtime-\u003edma_area. The smallest PCM buffer is larger\nthan MAX_FRAMES_PER_PACKET. Bounding the count to MAX_FRAMES_PER_PACKET\nkeeps both the read and the write in range.\n\nA malicious or faulty Apple iSight on the FireWire bus reaches this\nduring a normal capture.\n\nAdd the MAX_FRAMES_PER_PACKET bound to the gate."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:30.281Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/24423e0a9251d348c3f1fb0bb0e61b879e1e976c"
},
{
"url": "https://git.kernel.org/stable/c/ebbffacda6733dcbcef601b5b523460f8d8b671e"
},
{
"url": "https://git.kernel.org/stable/c/57e4d9043afc1eaddee8f50d11def6e65415d273"
},
{
"url": "https://git.kernel.org/stable/c/3ed2fa1ed8cc65f910b8bbc0be3cc366b30f8478"
},
{
"url": "https://git.kernel.org/stable/c/31da82b9676c6b112e7c72c7529e6812b919742a"
},
{
"url": "https://git.kernel.org/stable/c/8e48a29813df8dd71503800b7acf69c12c035045"
},
{
"url": "https://git.kernel.org/stable/c/31a01b70bb90e3ef3147f308e2ea899e1d2485ca"
},
{
"url": "https://git.kernel.org/stable/c/29b9667982e4df2ed7744f86b1144f8bb58eb698"
}
],
"title": "ALSA: firewire: isight: bound the sample count to the packet payload",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64483",
"datePublished": "2026-07-25T08:51:43.851Z",
"dateReserved": "2026-07-19T15:36:31.791Z",
"dateUpdated": "2026-08-17T04:56:30.281Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68137 (GCVE-0-2026-68137)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/x25: fix use-after-free in x25_kill_by_neigh()
x25_kill_by_neigh() walks the global X.25 socket list looking for sockets
attached to a terminating neighbour. x25_list_lock protects list membership
while the lookup is in progress, but it does not pin a socket's lifetime
after the lock is dropped.
The function currently drops x25_list_lock before calling lock_sock(s). A
concurrent close can run x25_release(), remove the same socket from
x25_list, and drop the last socket reference in that window. The neighbour
teardown path can then lock or inspect a freed struct sock/struct x25_sock.
Take sock_hold(s) while x25_list_lock still proves that the list entry is
live, then drop the temporary reference after the socket has been locked,
rechecked, and released. Recheck x25_sk(s)->neighbour after lock_sock(),
because another path may have disconnected the socket before this path
acquired the socket lock. Restart the list walk after each disconnect
because the list lock was dropped and the previous iterator state may no
longer be valid.
A QEMU/KASAN run against origin/master reproduced a slab-use-after-free in
x25_kill_by_neigh().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5c94b6205e87411dbe9dc1ca088eb36b8837fb47 Version: 409570a619c1cda2e0fde6018a256b9e3d3ba0ee Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: dffc859d1d9560da594e4282091781b8d2715f00 Version: 858642789ada1b48630f322e59416ca9fca3e6b7 Version: 4c240c5a105557e4546d0836e694868f22fd09b0 Version: 9acf05b4e7b55fdb712ef7b331dbce5bcd391d0f Version: 4a279d7ee1c65411b4055ecd428b8aa2b1711c1f Version: 671529db75e6be777bb1c76aa07c2bdd2992be6d Version: 5.10.110 ≤ Version: 5.15.33 ≤ Version: 4.9.311 ≤ Version: 4.14.276 ≤ Version: 4.19.238 ≤ Version: 5.4.189 ≤ Version: 5.16.19 ≤ Version: 5.17.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/x25/af_x25.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "db6b04f6d65549bb1c7bc8e64a92e7b7d03be676",
"status": "affected",
"version": "5c94b6205e87411dbe9dc1ca088eb36b8837fb47",
"versionType": "git"
},
{
"lessThan": "5e8a754ac2009a88a7b99ab61eab6296eed360f3",
"status": "affected",
"version": "409570a619c1cda2e0fde6018a256b9e3d3ba0ee",
"versionType": "git"
},
{
"lessThan": "c98a454d1a9e1bd09d5fd55a7aa589b199340b88",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "3f4fe26c20c30bd5a2e2583e80685def0b27858c",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "610678d4be94b619c751572e8a58de705592cd07",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "ec6d91a1bf2ebd767d3d43f6d249ee0ed3f4558a",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "9aabda553184346f74810e2ee1d96920b4612e3f",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "5499e0602d2faafd42c580d25f615903c3fbe11b",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"status": "affected",
"version": "dffc859d1d9560da594e4282091781b8d2715f00",
"versionType": "git"
},
{
"status": "affected",
"version": "858642789ada1b48630f322e59416ca9fca3e6b7",
"versionType": "git"
},
{
"status": "affected",
"version": "4c240c5a105557e4546d0836e694868f22fd09b0",
"versionType": "git"
},
{
"status": "affected",
"version": "9acf05b4e7b55fdb712ef7b331dbce5bcd391d0f",
"versionType": "git"
},
{
"status": "affected",
"version": "4a279d7ee1c65411b4055ecd428b8aa2b1711c1f",
"versionType": "git"
},
{
"status": "affected",
"version": "671529db75e6be777bb1c76aa07c2bdd2992be6d",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.110",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.33",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.311",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.276",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.238",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.189",
"versionType": "semver"
},
{
"lessThan": "5.17",
"status": "affected",
"version": "5.16.19",
"versionType": "semver"
},
{
"lessThan": "5.18",
"status": "affected",
"version": "5.17.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/x25/af_x25.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.110",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.311",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.276",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.238",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.189",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.16.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.17.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/x25: fix use-after-free in x25_kill_by_neigh()\n\nx25_kill_by_neigh() walks the global X.25 socket list looking for sockets\nattached to a terminating neighbour. x25_list_lock protects list membership\nwhile the lookup is in progress, but it does not pin a socket\u0027s lifetime\nafter the lock is dropped.\n\nThe function currently drops x25_list_lock before calling lock_sock(s). A\nconcurrent close can run x25_release(), remove the same socket from\nx25_list, and drop the last socket reference in that window. The neighbour\nteardown path can then lock or inspect a freed struct sock/struct x25_sock.\n\nTake sock_hold(s) while x25_list_lock still proves that the list entry is\nlive, then drop the temporary reference after the socket has been locked,\nrechecked, and released. Recheck x25_sk(s)-\u003eneighbour after lock_sock(),\nbecause another path may have disconnected the socket before this path\nacquired the socket lock. Restart the list walk after each disconnect\nbecause the list lock was dropped and the previous iterator state may no\nlonger be valid.\n\nA QEMU/KASAN run against origin/master reproduced a slab-use-after-free in\nx25_kill_by_neigh()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - x25_kill_by_neigh() is invoked from the net stack when inbound X.25 link-control frames (RESTART_REQUEST/CONFIRMATION with LCI 0, or IFACE_DISCONNECT) are processed on ARPHRD_X25 interfaces via the ETH_P_X25 packet handler, the normal WAN-facing path in telecom/banking/industrial X.25 deployments.\nAC:L - This is a use-after-free race between neighbour teardown and socket close(); an attacker controls both sides by racing close() on an AF_X25 socket against RESTART/terminate frames they send, and KASAN reproduced the slab-UAF under controlled testing.\nPR:N - A remote X.25 peer on the WAN needs no Linux credentials to deliver RESTART/terminate frames that reach x25_kill_by_neigh(); exploitation races that path against any local X.25 consumer closing sockets, without the attacker holding privileges on the victim host.\nUI:N - No victim user interaction is required beyond normal automated X.25 service operation (accepting calls, reconnecting, or closing sessions) that can be timed against remotely injected link-control frames.\nS:U - The vulnerability corrupts kernel heap memory within the host kernel security boundary; it does not cross VM, container, or IOMMU isolation boundaries.\nC:H - Use-after-free on struct sock/x25_sock lets an attacker influence reuse of freed slab objects, enabling arbitrary kernel memory disclosure per CNA guidance for kernel UAF bugs.\nI:H - Use-after-free on socket structures can be leveraged through heap shaping into arbitrary kernel writes, privilege escalation, or code execution per CNA guidance for kernel UAF bugs.\nA:H - The bug is a confirmed slab use-after-free in kernel context (KASAN-reproduced) that can oops or panic the kernel during lock_sock()/x25_disconnect() even before full exploit development."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:54.672Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/db6b04f6d65549bb1c7bc8e64a92e7b7d03be676"
},
{
"url": "https://git.kernel.org/stable/c/5e8a754ac2009a88a7b99ab61eab6296eed360f3"
},
{
"url": "https://git.kernel.org/stable/c/c98a454d1a9e1bd09d5fd55a7aa589b199340b88"
},
{
"url": "https://git.kernel.org/stable/c/3f4fe26c20c30bd5a2e2583e80685def0b27858c"
},
{
"url": "https://git.kernel.org/stable/c/610678d4be94b619c751572e8a58de705592cd07"
},
{
"url": "https://git.kernel.org/stable/c/ec6d91a1bf2ebd767d3d43f6d249ee0ed3f4558a"
},
{
"url": "https://git.kernel.org/stable/c/9aabda553184346f74810e2ee1d96920b4612e3f"
},
{
"url": "https://git.kernel.org/stable/c/5499e0602d2faafd42c580d25f615903c3fbe11b"
}
],
"title": "net/x25: fix use-after-free in x25_kill_by_neigh()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68137",
"datePublished": "2026-08-10T11:59:00.740Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:54.672Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53220 (GCVE-0-2026-53220)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-06-25 08:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: revalidate bridge ports
ebt_redirect_tg() dereferences br_port_get_rcu() return without a
NULL check, causing a kernel panic when the bridge port has been
removed between the original hook invocation and an NFQUEUE
reinject.
A mere NULL check isn't sufficient, however. As sashiko review
points out userspace can not only remove the port from the bridge,
it could also place the device in a different virtual device, e.g.
macvlan.
If this happens, we must drop the packet, there is no way for us to
reinject it into the bridge path.
Switch to _upper API, we don't need the bridge port structure.
Also, this fix keeps another bug intact:
Both nfnetlink_log and nfnetlink_queue use CONFIG_BRIDGE_NETFILTER
too aggressive, which prevents certain logging features when queueing
in bridge family: NETFILTER_FAMILY_BRIDGE can be enabled while the old
CONFIG_BRIDGE_NETFILTER cruft is off.
Fixes tag is a common ancestor, this was always broken.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bridge/netfilter/ebt_dnat.c",
"net/bridge/netfilter/ebt_redirect.c",
"net/netfilter/nfnetlink_log.c",
"net/netfilter/nfnetlink_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "43330a1e8aace6b5a8de9aba127e9e394ab49b0f",
"status": "affected",
"version": "f350a0a87374418635689471606454abc7beaa3a",
"versionType": "git"
},
{
"lessThan": "4beffcd726e2a731cea4dc18e1fbc55c8d76f1a0",
"status": "affected",
"version": "f350a0a87374418635689471606454abc7beaa3a",
"versionType": "git"
},
{
"lessThan": "d4b1301fd3c9e5e105fd3767c68bc4ba558bb228",
"status": "affected",
"version": "f350a0a87374418635689471606454abc7beaa3a",
"versionType": "git"
},
{
"lessThan": "ccb9fd4b87538ccf19ccff78ee26700526d94867",
"status": "affected",
"version": "f350a0a87374418635689471606454abc7beaa3a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bridge/netfilter/ebt_dnat.c",
"net/bridge/netfilter/ebt_redirect.c",
"net/netfilter/nfnetlink_log.c",
"net/netfilter/nfnetlink_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.36"
},
{
"lessThan": "2.6.36",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.36",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: revalidate bridge ports\n\nebt_redirect_tg() dereferences br_port_get_rcu() return without a\nNULL check, causing a kernel panic when the bridge port has been\nremoved between the original hook invocation and an NFQUEUE\nreinject.\n\nA mere NULL check isn\u0027t sufficient, however. As sashiko review\npoints out userspace can not only remove the port from the bridge,\nit could also place the device in a different virtual device, e.g.\nmacvlan.\n\nIf this happens, we must drop the packet, there is no way for us to\nreinject it into the bridge path.\n\nSwitch to _upper API, we don\u0027t need the bridge port structure.\nAlso, this fix keeps another bug intact:\n\nBoth nfnetlink_log and nfnetlink_queue use CONFIG_BRIDGE_NETFILTER\ntoo aggressive, which prevents certain logging features when queueing\nin bridge family: NETFILTER_FAMILY_BRIDGE can be enabled while the old\nCONFIG_BRIDGE_NETFILTER cruft is off.\n\nFixes tag is a common ancestor, this was always broken."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-25T08:39:22.394Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/43330a1e8aace6b5a8de9aba127e9e394ab49b0f"
},
{
"url": "https://git.kernel.org/stable/c/4beffcd726e2a731cea4dc18e1fbc55c8d76f1a0"
},
{
"url": "https://git.kernel.org/stable/c/d4b1301fd3c9e5e105fd3767c68bc4ba558bb228"
},
{
"url": "https://git.kernel.org/stable/c/ccb9fd4b87538ccf19ccff78ee26700526d94867"
}
],
"title": "netfilter: revalidate bridge ports",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53220",
"datePublished": "2026-06-25T08:39:22.394Z",
"dateReserved": "2026-06-09T07:44:35.392Z",
"dateUpdated": "2026-06-25T08:39:22.394Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46037 (GCVE-0-2026-46037)
Vulnerability from cvelistv5
Published
2026-05-27 12:56
Modified
2026-09-08 08:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: icmp: validate reply type before using icmp_pointers
Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type.
That value is outside the range covered by icmp_pointers[], which only
describes the traditional ICMP types up to NR_ICMP_TYPES.
Avoid consulting icmp_pointers[] for reply types outside that range, and
use array_index_nospec() for the remaining in-range lookup. Normal ICMP
replies keep their existing behavior unchanged.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d329ea5bd8845f0b196bf41b18b6173340d6e0e4 Version: d329ea5bd8845f0b196bf41b18b6173340d6e0e4 Version: d329ea5bd8845f0b196bf41b18b6173340d6e0e4 Version: d329ea5bd8845f0b196bf41b18b6173340d6e0e4 Version: d329ea5bd8845f0b196bf41b18b6173340d6e0e4 Version: d329ea5bd8845f0b196bf41b18b6173340d6e0e4 Version: d329ea5bd8845f0b196bf41b18b6173340d6e0e4 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:49:09.678Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/icmp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b3a88fc5ae024d43c5ecf653f3bbe837e4a6dc99",
"status": "affected",
"version": "d329ea5bd8845f0b196bf41b18b6173340d6e0e4",
"versionType": "git"
},
{
"lessThan": "93df2af4f491de33827550b9d420f01808c0706b",
"status": "affected",
"version": "d329ea5bd8845f0b196bf41b18b6173340d6e0e4",
"versionType": "git"
},
{
"lessThan": "92e7c209036dcc0e8ffdf806fdfd3645b263bea5",
"status": "affected",
"version": "d329ea5bd8845f0b196bf41b18b6173340d6e0e4",
"versionType": "git"
},
{
"lessThan": "bc64a66e0b9ad937d3d49934242ee62b01ba9a94",
"status": "affected",
"version": "d329ea5bd8845f0b196bf41b18b6173340d6e0e4",
"versionType": "git"
},
{
"lessThan": "c2178ff1c70ebfc2ab9651b230c58a34683db759",
"status": "affected",
"version": "d329ea5bd8845f0b196bf41b18b6173340d6e0e4",
"versionType": "git"
},
{
"lessThan": "d700c34a5d186b9ba0715bcb19e0ff80ffbfbfc1",
"status": "affected",
"version": "d329ea5bd8845f0b196bf41b18b6173340d6e0e4",
"versionType": "git"
},
{
"lessThan": "67bf002a2d7387a6312138210d0bd06e3cf4879b",
"status": "affected",
"version": "d329ea5bd8845f0b196bf41b18b6173340d6e0e4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/icmp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.86",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.27",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.86",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.27",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.4",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: icmp: validate reply type before using icmp_pointers\n\nExtended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type.\nThat value is outside the range covered by icmp_pointers[], which only\ndescribes the traditional ICMP types up to NR_ICMP_TYPES.\n\nAvoid consulting icmp_pointers[] for reply types outside that range, and\nuse array_index_nospec() for the remaining in-range lookup. Normal ICMP\nreplies keep their existing behavior unchanged."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code is reached by processing an inbound ICMP Extended Echo Request packet in the IPv4 ICMP receive path (icmp_rcv \u2192 icmp_echo \u2192 icmp_reply \u2192 icmp_glue_bits), so any remote host on the network can trigger it.\nAC:L - In the assumed worst-case deployment (RFC 8335 probe responses enabled), a single crafted ICMP Extended Echo Request with the L-bit set deterministically drives the reply type to 43 and triggers the fixed out-of-bounds read; no race or attacker-uncontrollable condition is involved.\nPR:N - Sending an ICMP packet requires no authentication or privileges on the target; the path runs entirely in packet receive before any credential check.\nUI:N - The target only needs to receive the attacker\u0027s packet; no victim action is required.\nS:U - The out-of-bounds access stays within the kernel\u0027s own memory and security authority, with no crossing of a VM/IOMMU/sandbox boundary.\nC:L - An out-of-bounds read of kernel .rodata occurs, but it is strictly bounded to a fixed 2-byte field at a constant offset and is not disclosed to the attacker, fitting a small bounded read rather than arbitrary disclosure.\nI:N - The bug performs only a read; there is no out-of-bounds write or attacker-meaningful modification of kernel data.\nA:H - The out-of-bounds array access can crash the kernel (e.g., KASAN/panic_on_warn configurations) via a single unauthenticated, repeatable remote packet, yielding a denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:29:16.933Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b3a88fc5ae024d43c5ecf653f3bbe837e4a6dc99"
},
{
"url": "https://git.kernel.org/stable/c/93df2af4f491de33827550b9d420f01808c0706b"
},
{
"url": "https://git.kernel.org/stable/c/92e7c209036dcc0e8ffdf806fdfd3645b263bea5"
},
{
"url": "https://git.kernel.org/stable/c/bc64a66e0b9ad937d3d49934242ee62b01ba9a94"
},
{
"url": "https://git.kernel.org/stable/c/c2178ff1c70ebfc2ab9651b230c58a34683db759"
},
{
"url": "https://git.kernel.org/stable/c/d700c34a5d186b9ba0715bcb19e0ff80ffbfbfc1"
},
{
"url": "https://git.kernel.org/stable/c/67bf002a2d7387a6312138210d0bd06e3cf4879b"
}
],
"title": "ipv4: icmp: validate reply type before using icmp_pointers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46037",
"datePublished": "2026-05-27T12:56:47.795Z",
"dateReserved": "2026-05-13T15:03:33.093Z",
"dateUpdated": "2026-09-08T08:49:09.678Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68256 (GCVE-0-2026-68256)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
prev_sink is unconditionally retained via dc_sink_retain at function
entry, but the DP alt mode timeout path inside SIGNAL_TYPE_DISPLAY_PORT
returns false without releasing prev_sink. All other return paths in the
function correctly call dc_sink_release(prev_sink), making this the only
missing cleanup.
(cherry picked from commit 45510cf662dcf46b5d8926d454f338809f107b9d)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/link/link_detection.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f9922828a4ebd26286fbe0286cc61695e7d9b07b",
"status": "affected",
"version": "54618888d1ea7a26f8bccfb89e3c2420350c8047",
"versionType": "git"
},
{
"lessThan": "a59e493567d18ef3858be9368acd132a01ebfa09",
"status": "affected",
"version": "54618888d1ea7a26f8bccfb89e3c2420350c8047",
"versionType": "git"
},
{
"lessThan": "4ee77643e6194f2deb62fe62f04396f9825e27d8",
"status": "affected",
"version": "54618888d1ea7a26f8bccfb89e3c2420350c8047",
"versionType": "git"
},
{
"lessThan": "58ea24dd96848626039296e9e8510270ec8dc4bf",
"status": "affected",
"version": "54618888d1ea7a26f8bccfb89e3c2420350c8047",
"versionType": "git"
},
{
"lessThan": "a6e14b976be48eebd8769cb5b883a6af7fc5ade1",
"status": "affected",
"version": "54618888d1ea7a26f8bccfb89e3c2420350c8047",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/link/link_detection.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference\n\nprev_sink is unconditionally retained via dc_sink_retain at function\n entry, but the DP alt mode timeout path inside SIGNAL_TYPE_DISPLAY_PORT\n returns false without releasing prev_sink. All other return paths in the\n function correctly call dc_sink_release(prev_sink), making this the only\n missing cleanup.\n\n(cherry picked from commit 45510cf662dcf46b5d8926d454f338809f107b9d)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:47.968Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f9922828a4ebd26286fbe0286cc61695e7d9b07b"
},
{
"url": "https://git.kernel.org/stable/c/a59e493567d18ef3858be9368acd132a01ebfa09"
},
{
"url": "https://git.kernel.org/stable/c/4ee77643e6194f2deb62fe62f04396f9825e27d8"
},
{
"url": "https://git.kernel.org/stable/c/58ea24dd96848626039296e9e8510270ec8dc4bf"
},
{
"url": "https://git.kernel.org/stable/c/a6e14b976be48eebd8769cb5b883a6af7fc5ade1"
}
],
"title": "drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68256",
"datePublished": "2026-08-10T12:01:26.406Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:01:47.968Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74584 (GCVE-0-2026-74584)
Vulnerability from cvelistv5
Published
2026-08-22 14:28
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: zero shared page before exposing to userspace
bnxt_re_alloc_ucontext() allocates uctx->shpg via
__get_free_page(GFP_KERNEL). The buddy allocator does not zero pages
without __GFP_ZERO, so the page contains stale kernel data from
whatever object most recently freed it.
The page is then mapped into userspace via vm_insert_page() under
BNXT_RE_MMAP_SH_PAGE in bnxt_re_mmap(). The driver only ever writes
4 bytes (a u32 AVID) at offset BNXT_RE_AVID_OFFT (0x10) inside
bnxt_re_create_ah(); the remaining 4092 bytes of the page are exposed
to userspace unsanitised, leaking kernel memory contents.
Any user with access to /dev/infiniband/uverbsX on a host with a
bnxt_re device (typically rdma group membership) can read this data
via a single mmap() at pgoff 0 after IB_USER_VERBS_CMD_GET_CONTEXT.
Other shared pages in the same file already use get_zeroed_page()
correctly:
drivers/infiniband/hw/bnxt_re/ib_verbs.c
srq->uctx_srq_page = (void *)get_zeroed_page(GFP_KERNEL);
cq->uctx_cq_page = (void *)get_zeroed_page(GFP_KERNEL);
uctx->shpg is the only outlier. Bring it in line with the existing
convention by switching to get_zeroed_page().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 Version: 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 Version: 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 Version: 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 Version: 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 Version: 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 Version: 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 Version: 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/ib_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "53c97e9882f4e747b4ac31b211317c2eba541af9",
"status": "affected",
"version": "1ac5a404797523cedaf424a3aaa3cf8f9548dff8",
"versionType": "git"
},
{
"lessThan": "9896bdfd21d918e9f26a52bc6109cc77970ee0b1",
"status": "affected",
"version": "1ac5a404797523cedaf424a3aaa3cf8f9548dff8",
"versionType": "git"
},
{
"lessThan": "9128c2411b83a64c0a69d2ff059c741bde25a9cc",
"status": "affected",
"version": "1ac5a404797523cedaf424a3aaa3cf8f9548dff8",
"versionType": "git"
},
{
"lessThan": "c19b360fa10c521c0b681875cdaa51545d45a491",
"status": "affected",
"version": "1ac5a404797523cedaf424a3aaa3cf8f9548dff8",
"versionType": "git"
},
{
"lessThan": "a3ed2daab02b2a706e882ad31b5c3c4f33cb5bb1",
"status": "affected",
"version": "1ac5a404797523cedaf424a3aaa3cf8f9548dff8",
"versionType": "git"
},
{
"lessThan": "e2b143df29003d2704b51f62e9297006953dbacb",
"status": "affected",
"version": "1ac5a404797523cedaf424a3aaa3cf8f9548dff8",
"versionType": "git"
},
{
"lessThan": "c75f8ce4baa29ae57fe615c6a2c5101f59b8b89a",
"status": "affected",
"version": "1ac5a404797523cedaf424a3aaa3cf8f9548dff8",
"versionType": "git"
},
{
"lessThan": "f6b079629becfa977f9c51fe53ad2e6dcc55ef44",
"status": "affected",
"version": "1ac5a404797523cedaf424a3aaa3cf8f9548dff8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/bnxt_re/ib_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.260",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.37",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.260",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.37",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.14",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: zero shared page before exposing to userspace\n\nbnxt_re_alloc_ucontext() allocates uctx-\u003eshpg via\n__get_free_page(GFP_KERNEL). The buddy allocator does not zero pages\nwithout __GFP_ZERO, so the page contains stale kernel data from\nwhatever object most recently freed it.\n\nThe page is then mapped into userspace via vm_insert_page() under\nBNXT_RE_MMAP_SH_PAGE in bnxt_re_mmap(). The driver only ever writes\n4 bytes (a u32 AVID) at offset BNXT_RE_AVID_OFFT (0x10) inside\nbnxt_re_create_ah(); the remaining 4092 bytes of the page are exposed\nto userspace unsanitised, leaking kernel memory contents.\n\nAny user with access to /dev/infiniband/uverbsX on a host with a\nbnxt_re device (typically rdma group membership) can read this data\nvia a single mmap() at pgoff 0 after IB_USER_VERBS_CMD_GET_CONTEXT.\n\nOther shared pages in the same file already use get_zeroed_page()\ncorrectly:\n\n drivers/infiniband/hw/bnxt_re/ib_verbs.c\n srq-\u003euctx_srq_page = (void *)get_zeroed_page(GFP_KERNEL);\n cq-\u003euctx_cq_page = (void *)get_zeroed_page(GFP_KERNEL);\n\nuctx-\u003eshpg is the only outlier. Bring it in line with the existing\nconvention by switching to get_zeroed_page()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The leak is triggered only through local access to /dev/infiniband/uverbs* via ioctl GET_CONTEXT and mmap(pgoff 0); bnxt_re_mmap maps the shared page with vm_insert_page, and remote RoCE/IB packet handling never reaches this uverbs allocation path.\nAC:L - On a host with bnxt_re loaded, opening uverbs, issuing GET_CONTEXT, and mmap at offset 0 deterministically exposes the unstale page; the attacker controls all syscall parameters and needs no race, special memory layout, or victim-specific state.\nPR:N - Kernel uverbs character devices are created world-accessible (mode 0666) via uverbs_devnode, and ib_uverbs_open performs no capability or root check beyond netns access, so any local process can open the device and allocate a bnxt_re ucontext.\nUI:N - Exploitation requires only attacker-driven open/ioctl/mmap/read syscalls on their own uverbs file descriptor; no cooperative victim action such as mounting filesystems, opening files, or clicking links is needed.\nS:C - On HPC/cloud hosts exposing bnxt_re to tenant containers or shared RDMA workloads, mmap of unstale host-kernel buddy pages leaks host kernel memory across the container/tenant security boundary into an unprivileged workload\u0027s address space.\nC:H - __get_free_page without __GFP_ZERO leaves up to 4092 bytes of stale kernel heap/slack data readable per ucontext; repeated opens yield additional pages, disclosing kernel pointers, structures, and other sensitive material beyond a few-byte bounded leak.\nI:N - The flaw only exposes existing kernel memory contents to userspace via mmap; it does not corrupt, overwrite, or modify kernel objects, grant write primitives, or enable code execution through the shared page mapping.\nA:N - Reading the unstale mapped page does not trigger kernel oops, panic, hang, or resource exhaustion; the vulnerable path completes normally and availability is unaffected aside from normal per-context page allocation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:11.315Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/53c97e9882f4e747b4ac31b211317c2eba541af9"
},
{
"url": "https://git.kernel.org/stable/c/9896bdfd21d918e9f26a52bc6109cc77970ee0b1"
},
{
"url": "https://git.kernel.org/stable/c/9128c2411b83a64c0a69d2ff059c741bde25a9cc"
},
{
"url": "https://git.kernel.org/stable/c/c19b360fa10c521c0b681875cdaa51545d45a491"
},
{
"url": "https://git.kernel.org/stable/c/a3ed2daab02b2a706e882ad31b5c3c4f33cb5bb1"
},
{
"url": "https://git.kernel.org/stable/c/e2b143df29003d2704b51f62e9297006953dbacb"
},
{
"url": "https://git.kernel.org/stable/c/c75f8ce4baa29ae57fe615c6a2c5101f59b8b89a"
},
{
"url": "https://git.kernel.org/stable/c/f6b079629becfa977f9c51fe53ad2e6dcc55ef44"
}
],
"title": "RDMA/bnxt_re: zero shared page before exposing to userspace",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74584",
"datePublished": "2026-08-22T14:28:07.988Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-25T05:40:11.315Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-71104 (GCVE-0-2025-71104)
Vulnerability from cvelistv5
Published
2026-01-14 15:05
Modified
2026-09-08 08:43
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer
When advancing the target expiration for the guest's APIC timer in periodic
mode, set the expiration to "now" if the target expiration is in the past
(similar to what is done in update_target_expiration()). Blindly adding
the period to the previous target expiration can result in KVM generating
a practically unbounded number of hrtimer IRQs due to programming an
expired timer over and over. In extreme scenarios, e.g. if userspace
pauses/suspends a VM for an extended duration, this can even cause hard
lockups in the host.
Currently, the bug only affects Intel CPUs when using the hypervisor timer
(HV timer), a.k.a. the VMX preemption timer. Unlike the software timer,
a.k.a. hrtimer, which KVM keeps running even on exits to userspace, the
HV timer only runs while the guest is active. As a result, if the vCPU
does not run for an extended duration, there will be a huge gap between
the target expiration and the current time the vCPU resumes running.
Because the target expiration is incremented by only one period on each
timer expiration, this leads to a series of timer expirations occurring
rapidly after the vCPU/VM resumes.
More critically, when the vCPU first triggers a periodic HV timer
expiration after resuming, advancing the expiration by only one period
will result in a target expiration in the past. As a result, the delta
may be calculated as a negative value. When the delta is converted into
an absolute value (tscdeadline is an unsigned u64), the resulting value
can overflow what the HV timer is capable of programming. I.e. the large
value will exceed the VMX Preemption Timer's maximum bit width of
cpu_preemption_timer_multi + 32, and thus cause KVM to switch from the
HV timer to the software timer (hrtimers).
After switching to the software timer, periodic timer expiration callbacks
may be executed consecutively within a single clock interrupt handler,
because hrtimers honors KVM's request for an expiration in the past and
immediately re-invokes KVM's callback after reprogramming. And because
the interrupt handler runs with IRQs disabled, restarting KVM's hrtimer
over and over until the target expiration is advanced to "now" can result
in a hard lockup.
E.g. the following hard lockup was triggered in the host when running a
Windows VM (only relevant because it used the APIC timer in periodic mode)
after resuming the VM from a long suspend (in the host).
NMI watchdog: Watchdog detected hard LOCKUP on cpu 45
...
RIP: 0010:advance_periodic_target_expiration+0x4d/0x80 [kvm]
...
RSP: 0018:ff4f88f5d98d8ef0 EFLAGS: 00000046
RAX: fff0103f91be678e RBX: fff0103f91be678e RCX: 00843a7d9e127bcc
RDX: 0000000000000002 RSI: 0052ca4003697505 RDI: ff440d5bfbdbd500
RBP: ff440d5956f99200 R08: ff2ff2a42deb6a84 R09: 000000000002a6c0
R10: 0122d794016332b3 R11: 0000000000000000 R12: ff440db1af39cfc0
R13: ff440db1af39cfc0 R14: ffffffffc0d4a560 R15: ff440db1af39d0f8
FS: 00007f04a6ffd700(0000) GS:ff440db1af380000(0000) knlGS:000000e38a3b8000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000d5651feff8 CR3: 000000684e038002 CR4: 0000000000773ee0
PKRU: 55555554
Call Trace:
<IRQ>
apic_timer_fn+0x31/0x50 [kvm]
__hrtimer_run_queues+0x100/0x280
hrtimer_interrupt+0x100/0x210
? ttwu_do_wakeup+0x19/0x160
smp_apic_timer_interrupt+0x6a/0x130
apic_timer_interrupt+0xf/0x20
</IRQ>
Moreover, if the suspend duration of the virtual machine is not long enough
to trigger a hard lockup in this scenario, since commit 98c25ead5eda
("KVM: VMX: Move preemption timer <=> hrtimer dance to common x86"), KVM
will continue using the software timer until the guest reprograms the APIC
timer in some way. Since the periodic timer does not require frequent APIC
timer register programming, the guest may continue to use the software
timer in
---truncated---
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc Version: d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc Version: d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc Version: d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc Version: d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc Version: d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc Version: d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc Version: 421e1fadb0b0a648cc75afd5b3c826fa7daeaffc Version: 5a69b7b69beae9bb86e7e1b095685087976cba47 Version: 4.14.45 ≤ Version: 4.16.13 ≤ |
||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-71104",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-10T20:40:39.879856Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-11T18:44:04.010Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:43:53.419Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/lapic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "786ed625c125c5cd180d6aaa37e653e3e4ffb8d9",
"status": "affected",
"version": "d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc",
"versionType": "git"
},
{
"lessThan": "d2da0df7bbc4fb4fd7d0a1da704f81a09c72fe73",
"status": "affected",
"version": "d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc",
"versionType": "git"
},
{
"lessThan": "807dbe8f3862fa7c164155857550ce94b36a11b9",
"status": "affected",
"version": "d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc",
"versionType": "git"
},
{
"lessThan": "7b54ccef865e0aa62e4871d4ada2ba4b9dcb8bed",
"status": "affected",
"version": "d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc",
"versionType": "git"
},
{
"lessThan": "e746e51947053a02af2ea964593dc4887108d379",
"status": "affected",
"version": "d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc",
"versionType": "git"
},
{
"lessThan": "e23f46f1a971c73dad2fd63e1408696114ddebe2",
"status": "affected",
"version": "d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc",
"versionType": "git"
},
{
"lessThan": "18ab3fc8e880791aa9f7c000261320fc812b5465",
"status": "affected",
"version": "d8f2f498d9ed0c5010bc1bbc1146f94c8bf9f8cc",
"versionType": "git"
},
{
"status": "affected",
"version": "421e1fadb0b0a648cc75afd5b3c826fa7daeaffc",
"versionType": "git"
},
{
"status": "affected",
"version": "5a69b7b69beae9bb86e7e1b095685087976cba47",
"versionType": "git"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.45",
"versionType": "semver"
},
{
"lessThan": "4.17",
"status": "affected",
"version": "4.16.13",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/lapic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.248",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.198",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.160",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.120",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.64",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.248",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.198",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.160",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.120",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.64",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.3",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.45",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.16.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer\n\nWhen advancing the target expiration for the guest\u0027s APIC timer in periodic\nmode, set the expiration to \"now\" if the target expiration is in the past\n(similar to what is done in update_target_expiration()). Blindly adding\nthe period to the previous target expiration can result in KVM generating\na practically unbounded number of hrtimer IRQs due to programming an\nexpired timer over and over. In extreme scenarios, e.g. if userspace\npauses/suspends a VM for an extended duration, this can even cause hard\nlockups in the host.\n\nCurrently, the bug only affects Intel CPUs when using the hypervisor timer\n(HV timer), a.k.a. the VMX preemption timer. Unlike the software timer,\na.k.a. hrtimer, which KVM keeps running even on exits to userspace, the\nHV timer only runs while the guest is active. As a result, if the vCPU\ndoes not run for an extended duration, there will be a huge gap between\nthe target expiration and the current time the vCPU resumes running.\nBecause the target expiration is incremented by only one period on each\ntimer expiration, this leads to a series of timer expirations occurring\nrapidly after the vCPU/VM resumes.\n\nMore critically, when the vCPU first triggers a periodic HV timer\nexpiration after resuming, advancing the expiration by only one period\nwill result in a target expiration in the past. As a result, the delta\nmay be calculated as a negative value. When the delta is converted into\nan absolute value (tscdeadline is an unsigned u64), the resulting value\ncan overflow what the HV timer is capable of programming. I.e. the large\nvalue will exceed the VMX Preemption Timer\u0027s maximum bit width of\ncpu_preemption_timer_multi + 32, and thus cause KVM to switch from the\nHV timer to the software timer (hrtimers).\n\nAfter switching to the software timer, periodic timer expiration callbacks\nmay be executed consecutively within a single clock interrupt handler,\nbecause hrtimers honors KVM\u0027s request for an expiration in the past and\nimmediately re-invokes KVM\u0027s callback after reprogramming. And because\nthe interrupt handler runs with IRQs disabled, restarting KVM\u0027s hrtimer\nover and over until the target expiration is advanced to \"now\" can result\nin a hard lockup.\n\nE.g. the following hard lockup was triggered in the host when running a\nWindows VM (only relevant because it used the APIC timer in periodic mode)\nafter resuming the VM from a long suspend (in the host).\n\n NMI watchdog: Watchdog detected hard LOCKUP on cpu 45\n ...\n RIP: 0010:advance_periodic_target_expiration+0x4d/0x80 [kvm]\n ...\n RSP: 0018:ff4f88f5d98d8ef0 EFLAGS: 00000046\n RAX: fff0103f91be678e RBX: fff0103f91be678e RCX: 00843a7d9e127bcc\n RDX: 0000000000000002 RSI: 0052ca4003697505 RDI: ff440d5bfbdbd500\n RBP: ff440d5956f99200 R08: ff2ff2a42deb6a84 R09: 000000000002a6c0\n R10: 0122d794016332b3 R11: 0000000000000000 R12: ff440db1af39cfc0\n R13: ff440db1af39cfc0 R14: ffffffffc0d4a560 R15: ff440db1af39d0f8\n FS: 00007f04a6ffd700(0000) GS:ff440db1af380000(0000) knlGS:000000e38a3b8000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000d5651feff8 CR3: 000000684e038002 CR4: 0000000000773ee0\n PKRU: 55555554\n Call Trace:\n \u003cIRQ\u003e\n apic_timer_fn+0x31/0x50 [kvm]\n __hrtimer_run_queues+0x100/0x280\n hrtimer_interrupt+0x100/0x210\n ? ttwu_do_wakeup+0x19/0x160\n smp_apic_timer_interrupt+0x6a/0x130\n apic_timer_interrupt+0xf/0x20\n \u003c/IRQ\u003e\n\nMoreover, if the suspend duration of the virtual machine is not long enough\nto trigger a hard lockup in this scenario, since commit 98c25ead5eda\n(\"KVM: VMX: Move preemption timer \u003c=\u003e hrtimer dance to common x86\"), KVM\nwill continue using the software timer until the guest reprograms the APIC\ntimer in some way. Since the periodic timer does not require frequent APIC\ntimer register programming, the guest may continue to use the software\ntimer in \n---truncated---"
}
],
"providerMetadata": {
"dateUpdated": "2026-05-23T16:03:11.920Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/786ed625c125c5cd180d6aaa37e653e3e4ffb8d9"
},
{
"url": "https://git.kernel.org/stable/c/d2da0df7bbc4fb4fd7d0a1da704f81a09c72fe73"
},
{
"url": "https://git.kernel.org/stable/c/807dbe8f3862fa7c164155857550ce94b36a11b9"
},
{
"url": "https://git.kernel.org/stable/c/7b54ccef865e0aa62e4871d4ada2ba4b9dcb8bed"
},
{
"url": "https://git.kernel.org/stable/c/e746e51947053a02af2ea964593dc4887108d379"
},
{
"url": "https://git.kernel.org/stable/c/e23f46f1a971c73dad2fd63e1408696114ddebe2"
},
{
"url": "https://git.kernel.org/stable/c/18ab3fc8e880791aa9f7c000261320fc812b5465"
}
],
"title": "KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-71104",
"datePublished": "2026-01-14T15:05:53.802Z",
"dateReserved": "2026-01-13T15:30:19.651Z",
"dateUpdated": "2026-09-08T08:43:53.419Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68360 (GCVE-0-2026-68360)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-cpro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3df2b67793babbea7951b5f601d6df891c63b5d8",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "5e07f292ab5591bf4f588aa7abd22ec86c25d076",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "6c5f31fdf28455a7fd573bda452c80b7b6700247",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "0975c42ed2a3bf32125a920e5d19194289126210",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "c7757db58957ac20cdec6ce575dbd44a6375664e",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "56d2deb6448378118dbe68c4fbb3fbae5f65b18c",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "1a634f464d6153dfa4d7e73a3d78236b65a64ee9",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "94c87871b051d7ad758828a805215a2ec194512a",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-cpro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop\n\nCalling hid_hw_stop() does not stop the device IO.\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\nthe driver probe function. If the probe operation fails after \"io start\"\nhas been initiated, this race condition will result in a UAF vulnerability.\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:10.569Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3df2b67793babbea7951b5f601d6df891c63b5d8"
},
{
"url": "https://git.kernel.org/stable/c/5e07f292ab5591bf4f588aa7abd22ec86c25d076"
},
{
"url": "https://git.kernel.org/stable/c/6c5f31fdf28455a7fd573bda452c80b7b6700247"
},
{
"url": "https://git.kernel.org/stable/c/0975c42ed2a3bf32125a920e5d19194289126210"
},
{
"url": "https://git.kernel.org/stable/c/c7757db58957ac20cdec6ce575dbd44a6375664e"
},
{
"url": "https://git.kernel.org/stable/c/56d2deb6448378118dbe68c4fbb3fbae5f65b18c"
},
{
"url": "https://git.kernel.org/stable/c/1a634f464d6153dfa4d7e73a3d78236b65a64ee9"
},
{
"url": "https://git.kernel.org/stable/c/94c87871b051d7ad758828a805215a2ec194512a"
}
],
"title": "hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68360",
"datePublished": "2026-08-10T12:03:37.298Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:10.569Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72317 (GCVE-0-2026-72317)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-17 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: pin upper rpc_clnt across the TLS connect_worker
The TLS connect path has a use-after-free: nothing pins the
upper rpc_clnt across the delayed connect_worker. xs_connect()
stores task->tk_client in sock_xprt::clnt as a raw pointer
and queues the worker; for TLS-secured transports that worker
is xs_tcp_tls_setup_socket(), which reads several fields out
of the saved pointer (cl_timeout, cl_program, cl_prog,
cl_vers, cl_cred, cl_stats) to construct the args for the
inner handshake rpc_clnt.
The xprt does not reference the rpc_clnt; the rpc_clnt
references the xprt. xs_destroy() does cancel the
connect_worker, but it runs only when the xprt's refcount
drops to zero, which cannot happen until the rpc_clnt
releases its cl_xprt reference in rpc_free_client_work().
When a TLS handshake fails fatally (for example, an mTLS
mount whose client cert does not match the server), the
connecting task is woken with -EACCES and exits, the mount
caller invokes rpc_shutdown_client(), and the upper rpc_clnt
is freed before the queued connect_worker fires.
xs_tcp_tls_setup_socket() then dereferences the freed clnt,
producing the refcount_t underflow Michael Nemanov reported.
Take a reference on the upper rpc_clnt in xs_connect() for
TLS transports via a new rpc_hold_client() helper, and drop
it in the connect_worker's exit path with rpc_release_client().
The xprt_lock_connect() / xprt_unlock_connect() pairing
already serialises xs_connect() with xs_tcp_tls_setup_socket(),
so the take and release are balanced one-for-one.
The non-TLS connect worker (xs_tcp_setup_socket) never reads
sock_xprt::clnt, so leave that path alone and avoid the
clnt-holds-xprt-holds-clnt cycle that would otherwise prevent
xprt destruction.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/sunrpc/clnt.h",
"net/sunrpc/clnt.c",
"net/sunrpc/xprtsock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "79cd550f8c884523b604fbfa43eb02def74d6224",
"status": "affected",
"version": "75eb6af7acdf566c68d61e98e67ee2f235201c02",
"versionType": "git"
},
{
"lessThan": "7a65b41b657b71d5a77861f47dd13eb4bc8e10d0",
"status": "affected",
"version": "75eb6af7acdf566c68d61e98e67ee2f235201c02",
"versionType": "git"
},
{
"lessThan": "5b0427ba582d143a364301f825f4e32272f06d2d",
"status": "affected",
"version": "75eb6af7acdf566c68d61e98e67ee2f235201c02",
"versionType": "git"
},
{
"lessThan": "d49f6d098ed48775b9d27a9f9c5c220fdf76f102",
"status": "affected",
"version": "75eb6af7acdf566c68d61e98e67ee2f235201c02",
"versionType": "git"
},
{
"lessThan": "46bc86c833956219bbfd246c1ffd832a479c5199",
"status": "affected",
"version": "75eb6af7acdf566c68d61e98e67ee2f235201c02",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/sunrpc/clnt.h",
"net/sunrpc/clnt.c",
"net/sunrpc/xprtsock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: pin upper rpc_clnt across the TLS connect_worker\n\nThe TLS connect path has a use-after-free: nothing pins the\nupper rpc_clnt across the delayed connect_worker. xs_connect()\nstores task-\u003etk_client in sock_xprt::clnt as a raw pointer\nand queues the worker; for TLS-secured transports that worker\nis xs_tcp_tls_setup_socket(), which reads several fields out\nof the saved pointer (cl_timeout, cl_program, cl_prog,\ncl_vers, cl_cred, cl_stats) to construct the args for the\ninner handshake rpc_clnt.\n\nThe xprt does not reference the rpc_clnt; the rpc_clnt\nreferences the xprt. xs_destroy() does cancel the\nconnect_worker, but it runs only when the xprt\u0027s refcount\ndrops to zero, which cannot happen until the rpc_clnt\nreleases its cl_xprt reference in rpc_free_client_work().\nWhen a TLS handshake fails fatally (for example, an mTLS\nmount whose client cert does not match the server), the\nconnecting task is woken with -EACCES and exits, the mount\ncaller invokes rpc_shutdown_client(), and the upper rpc_clnt\nis freed before the queued connect_worker fires.\nxs_tcp_tls_setup_socket() then dereferences the freed clnt,\nproducing the refcount_t underflow Michael Nemanov reported.\n\nTake a reference on the upper rpc_clnt in xs_connect() for\nTLS transports via a new rpc_hold_client() helper, and drop\nit in the connect_worker\u0027s exit path with rpc_release_client().\nThe xprt_lock_connect() / xprt_unlock_connect() pairing\nalready serialises xs_connect() with xs_tcp_tls_setup_socket(),\nso the take and release are balanced one-for-one.\n\nThe non-TLS connect worker (xs_tcp_setup_socket) never reads\nsock_xprt::clnt, so leave that path alone and avoid the\nclnt-holds-xprt-holds-clnt cycle that would otherwise prevent\nxprt destruction."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in the SUNRPC TCP-with-TLS client connect_worker processing a remote NFS server\u0027s TLS handshake; a malicious or misconfigured server can induce fatal handshake failure over the network before the delayed worker runs, matching network-reachable kTLS/RPC-with-TLS client paths.\nAC:L - An attacker operating a reachable NFS endpoint can reliably cause fatal TLS handshake failure (e.g., reject mTLS client certificates or send TLS alerts) and influence reconnect timing/backoff so client teardown frees rpc_clnt before the queued connect_worker executes.\nPR:N - Exploitation requires no privileges on the victim host; a remote peer only needs the client kernel to initiate or re-establish an NFS RPC-with-TLS connection, and TLS handshake processing occurs before NFS authentication completes.\nUI:N - No further victim action is needed once an NFS xprtsec=tls/mtls mount exists because automatic reconnect after server-induced disconnect or handshake failure can trigger the race without additional user interaction.\nS:U - Impact is confined to kernel memory corruption and privilege boundaries within the same host; this is standard local kernel compromise rather than crossing VM, container, or IOMMU security scopes.\nC:H - This is a kernel heap use-after-free where xs_tcp_tls_setup_socket reads multiple fields from a freed rpc_clnt (including cl_cred and cl_program), enabling information disclosure and further exploitation beyond a simple crash.\nI:H - Use-after-free of rpc_clnt permits corrupting allocator metadata and adjacent kernel objects; freed-object reuse can yield arbitrary write or control-flow hijack primitives, not merely authenticated data alteration.\nA:H - Accessing the freed rpc_clnt produces a refcount_t underflow and kernel oops/panic; even unsuccessful exploitation typically crashes or hangs the system, and repeated reconnect attempts can deny availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:42:43.024Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/79cd550f8c884523b604fbfa43eb02def74d6224"
},
{
"url": "https://git.kernel.org/stable/c/7a65b41b657b71d5a77861f47dd13eb4bc8e10d0"
},
{
"url": "https://git.kernel.org/stable/c/5b0427ba582d143a364301f825f4e32272f06d2d"
},
{
"url": "https://git.kernel.org/stable/c/d49f6d098ed48775b9d27a9f9c5c220fdf76f102"
},
{
"url": "https://git.kernel.org/stable/c/46bc86c833956219bbfd246c1ffd832a479c5199"
}
],
"title": "SUNRPC: pin upper rpc_clnt across the TLS connect_worker",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72317",
"datePublished": "2026-08-15T05:55:31.022Z",
"dateReserved": "2026-08-09T03:40:39.919Z",
"dateUpdated": "2026-08-17T05:42:43.024Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68245 (GCVE-0-2026-68245)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
The vm pointer returned from amdgpu_vm_get_vm_from_pasid() is only
valid while the lock is still being held. Once xa_unlock_irqrestore is
called and returned, the pointer is no longer under lock and is subject
to modification. Since, the caller still dereferences vm->task_info in
amdgpu_vm_get_task_info_vm() after the lock is removed, this causes a
use after unlock problem.
Remove the lifetime issue present in amdgpu_vm_get_task_info_pasid()
through removing the amdgpu_vm_get_vm_from_pasid() function from
amdgpu_vm.c and making the relevant code inline to hold the lock while
it is still in use.
(cherry picked from commit 9d01579f3f868b333acc901815972685989092c7)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fe16a7e5336ae888751984e30c451fbf7cfa5df7",
"status": "affected",
"version": "b8f67b9ddf4f8fe6dd536590712b5912ad78f99c",
"versionType": "git"
},
{
"lessThan": "1173190412fb9d12e7efce76734118d9712ff970",
"status": "affected",
"version": "b8f67b9ddf4f8fe6dd536590712b5912ad78f99c",
"versionType": "git"
},
{
"lessThan": "5d5fb9124a2bba96a7807086d8fe0f7ce810d546",
"status": "affected",
"version": "b8f67b9ddf4f8fe6dd536590712b5912ad78f99c",
"versionType": "git"
},
{
"lessThan": "04cc4aa3617b0ed67e859f91f09de5d896a46f3a",
"status": "affected",
"version": "b8f67b9ddf4f8fe6dd536590712b5912ad78f99c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()\n\nThe vm pointer returned from amdgpu_vm_get_vm_from_pasid() is only\nvalid while the lock is still being held. Once xa_unlock_irqrestore is\ncalled and returned, the pointer is no longer under lock and is subject\nto modification. Since, the caller still dereferences vm-\u003etask_info in\namdgpu_vm_get_task_info_vm() after the lock is removed, this causes a\nuse after unlock problem.\n\nRemove the lifetime issue present in amdgpu_vm_get_task_info_pasid()\nthrough removing the amdgpu_vm_get_vm_from_pasid() function from\namdgpu_vm.c and making the relevant code inline to hold the lock while\nit is still in use.\n\n(cherry picked from commit 9d01579f3f868b333acc901815972685989092c7)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached through the amdgpu DRM device (render node) via command submission causing a GPU VM page fault or a ring timeout; this requires local access to /dev/dri/renderD*, with no network exposure.\nAC:L - The attacker controls both sides of the race: it can generate GPU page faults or job timeouts at will while concurrently closing DRM file descriptors to free the amdgpu_vm/fpriv, and can retry the race arbitrarily many times until it wins.\nPR:L - Only an unprivileged local account with access to the AMD GPU render node is needed; render nodes are world/group accessible by default on desktop, Android and container workloads, and no capability is checked on the CS/fault path.\nUI:N - The attacker\u0027s own processes generate the GPU faults and the concurrent VM teardown; no action by any other user is required.\nS:U - The corruption stays within the kernel\u0027s own security authority \u2014 the freed amdgpu_vm/amdgpu_task_info are kernel heap objects, with no crossing of a VM or IOMMU boundary.\nC:H - The stale vm pointer is dereferenced after free, reading vm-\u003etask_info out of reallocated kernel heap memory, and the resulting task_info contents (process name, pid, tgid) are then printed/exported, allowing disclosure of attacker-groomed or unrelated kernel data.\nI:H - kref_get() is performed on memory that may already be freed and reallocated, writing an increment into another object\u0027s fields, and the paired kref_put() can drop a foreign refcount to zero \u2014 a classic use-after-free/refcount-corruption primitive leveraged for arbitrary write and privilege escalation.\nA:H - The use-after-free occurs in a GPU interrupt handler and the reset/timeout path; dereferencing freed memory or corrupting a reused slab object readily oopses or panics the kernel, and it can be retriggered repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:46.886Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fe16a7e5336ae888751984e30c451fbf7cfa5df7"
},
{
"url": "https://git.kernel.org/stable/c/1173190412fb9d12e7efce76734118d9712ff970"
},
{
"url": "https://git.kernel.org/stable/c/5d5fb9124a2bba96a7807086d8fe0f7ce810d546"
},
{
"url": "https://git.kernel.org/stable/c/04cc4aa3617b0ed67e859f91f09de5d896a46f3a"
}
],
"title": "drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68245",
"datePublished": "2026-08-10T12:01:11.501Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-18T06:55:46.886Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64355 (GCVE-0-2026-64355)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject fragmented frames in devmap
Devmap broadcast redirects clone the packet for all but the last
destination.
For native XDP, that clone path copies only the linear xdp_frame data,
while fragmented frames keep skb_shared_info in tailroom outside the
linear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but
without valid frag metadata, and the later free path can interpret
uninitialized tail data as skb_shared_info, leading to an out-of-bounds
access during frame return.
Reject fragmented native XDP frames in dev_map_enqueue_clone().
Add the same restriction to the generic XDP clone path in
dev_map_redirect_clone(). Generic XDP represents fragmented packets as
nonlinear skbs, and rejecting them here keeps clone-based broadcast
support aligned between native and generic XDP.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/bpf/devmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "47baddc856ae7e93a565dd9deeb797999b179466",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "07a4c11ee8ef4abcb39d922e9e410ae269671cdf",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "bccbab36ff228e0825eb85d9b0f9b8434cd0a399",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "c5b4f5efcb55c1af3fe44ff712d31b7fb098a831",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "a9bb2d9c798cb62a4050a991c27b752770c33afe",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "51d07c12ca411e692c424ecdabf077f1e61a61be",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "aa496720618f1a6054f1c870bf10b4f6c99bf656",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/bpf/devmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject fragmented frames in devmap\n\nDevmap broadcast redirects clone the packet for all but the last\ndestination.\n\nFor native XDP, that clone path copies only the linear xdp_frame data,\nwhile fragmented frames keep skb_shared_info in tailroom outside the\nlinear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but\nwithout valid frag metadata, and the later free path can interpret\nuninitialized tail data as skb_shared_info, leading to an out-of-bounds\naccess during frame return.\n\nReject fragmented native XDP frames in dev_map_enqueue_clone().\n\nAdd the same restriction to the generic XDP clone path in\ndev_map_redirect_clone(). Generic XDP represents fragmented packets as\nnonlinear skbs, and rejecting them here keeps clone-based broadcast\nsupport aligned between native and generic XDP."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A remote peer can send an oversized packet that a fragment-capable NIC represents as a multi-buffer XDP frame, reaching the vulnerable devmap broadcast clone path on a configured forwarding host.\nAC:L - No race or uncontrollable timing condition is required; fragmented packets reliably enter the faulty clone path and can be sent repeatedly.\nPR:N - Although initial-namespace CAP_BPF and CAP_NET_ADMIN are needed to configure the XDP deployment, the attacker sending packets through the already-configured unauthenticated data path needs no privileges.\nUI:N - Packet reception and XDP processing occur automatically without victim action.\nS:U - The corruption compromises resources governed by the same host-kernel security authority and does not inherently cross a VM, IOMMU, or other distinct boundary.\nC:H - Uninitialized fragment descriptors are consumed as page references and can be used by scatter-gather transmitters for unintended DMA mappings, potentially exposing arbitrary kernel memory.\nI:H - An uninitialized fragment count can overrun fixed-size driver arrays, while bogus page references can cause invalid refcount decrements, premature frees, and exploitable kernel memory corruption.\nA:H - Invalid fragment metadata can fault during DMA mapping, transmission, or frame return and cause a kernel oops or panic; an attacker can trigger this repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:01.161Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/47baddc856ae7e93a565dd9deeb797999b179466"
},
{
"url": "https://git.kernel.org/stable/c/07a4c11ee8ef4abcb39d922e9e410ae269671cdf"
},
{
"url": "https://git.kernel.org/stable/c/bccbab36ff228e0825eb85d9b0f9b8434cd0a399"
},
{
"url": "https://git.kernel.org/stable/c/c5b4f5efcb55c1af3fe44ff712d31b7fb098a831"
},
{
"url": "https://git.kernel.org/stable/c/a9bb2d9c798cb62a4050a991c27b752770c33afe"
},
{
"url": "https://git.kernel.org/stable/c/51d07c12ca411e692c424ecdabf077f1e61a61be"
},
{
"url": "https://git.kernel.org/stable/c/aa496720618f1a6054f1c870bf10b4f6c99bf656"
}
],
"title": "bpf: Reject fragmented frames in devmap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64355",
"datePublished": "2026-07-25T08:50:13.410Z",
"dateReserved": "2026-07-19T15:36:31.782Z",
"dateUpdated": "2026-08-17T04:54:01.161Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72046 (GCVE-0-2026-72046)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-17 05:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gve: fix header buffer corruption with header-split and HW-GRO
The DQO RX datapath programs a per-buffer-queue-descriptor
header_buf_addr at post time and reads the split header back at
completion time. Both the post and the read currently index the
header buffer by queue position rather than by the buffer's identity:
- post (gve_rx_post_buffers_dqo): header_buf_addr is computed from
bufq->tail
- read (gve_rx_dqo): the header is read from desc_idx (the completion
queue head index)
This relies on the buffer-queue index and the completion-queue index
being equal for the start of every packet, i.e. on the device consuming
posted buffers and returning completions in the exact same order. That
assumption does not hold once HW-GRO is enabled with multiple
flows: coalesced segments are accepted and completed in an order that
may differ from the order buffers were posted, and segments from
different flows may interleave.
That results in two problems:
1. Wrong header slot on read. Because the read offset is derived from
the completion index (desc_idx) while the device wrote the header to
the address programmed for the buffer's buf_id, the driver can copy
a header belonging to a different packet. This shows up as
throughput drop (about 30% drop and large numbers of TCP
retransmissions) with header-split and HW-GRO both enabled and many
streams.
2. Header buffer reused while still owned by the device. The driver
advances bufq->head by one per completion and re-posts buffers based
on that. Arrival of N RX completions only guarantees that at least N
RX buffer descriptors have been read by the device. It does not
guarantee that the device has relinquished the ownership of all the
buffers corresponding to those N descriptors. With out-of-order
completions (e.g. the completion for a packet copied into buffer N
arrives before the completion for a packet copied into buffer N-1),
the driver can re-post and overwrite a header buffer that the device
is still going to write into, corrupting the header of a packet
whose completion has not yet been processed.
Fix both issues by indexing the header buffer by buf_id on both the post
and read paths. Reading from buf_id's slot is therefore always correct
regardless of completion ordering (fixes problem 1).
Indexing by buf_id also ties each header slot to the lifetime of its
buffer state. A buffer state is only returned to the free/recycle lists
when its own completion (buf_id) is processed, so its header slot can
only be re-posted after the device is done with it. This makes header
slot reuse safe under out-of-order completions (fixes problem 2).
Allocate (gve_rx_alloc_hdr_bufs) and free (gve_rx_free_hdr_bufs) the
header buffers based on num_buf_states to match the buf_id indexing.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/google/gve/gve_rx_dqo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "84d3753d4bf284ef770ead6dee2270aaabb3ef41",
"status": "affected",
"version": "5e37d8254e7f551dda62e7590e819d69c7491845",
"versionType": "git"
},
{
"lessThan": "35267819b25074084130b6a7be18bbaf44d3ae74",
"status": "affected",
"version": "5e37d8254e7f551dda62e7590e819d69c7491845",
"versionType": "git"
},
{
"lessThan": "9f8e7f59b0c2f466be74bd923726b0f5496c27ad",
"status": "affected",
"version": "5e37d8254e7f551dda62e7590e819d69c7491845",
"versionType": "git"
},
{
"lessThan": "d676c9a73bdcd8237425dbb826f2bd1a25c36e40",
"status": "affected",
"version": "5e37d8254e7f551dda62e7590e819d69c7491845",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/google/gve/gve_rx_dqo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngve: fix header buffer corruption with header-split and HW-GRO\n\nThe DQO RX datapath programs a per-buffer-queue-descriptor\nheader_buf_addr at post time and reads the split header back at\ncompletion time. Both the post and the read currently index the\nheader buffer by queue position rather than by the buffer\u0027s identity:\n\n - post (gve_rx_post_buffers_dqo): header_buf_addr is computed from\n bufq-\u003etail\n - read (gve_rx_dqo): the header is read from desc_idx (the completion\n queue head index)\n\nThis relies on the buffer-queue index and the completion-queue index\nbeing equal for the start of every packet, i.e. on the device consuming\nposted buffers and returning completions in the exact same order. That\nassumption does not hold once HW-GRO is enabled with multiple\nflows: coalesced segments are accepted and completed in an order that\nmay differ from the order buffers were posted, and segments from\ndifferent flows may interleave.\n\nThat results in two problems:\n\n1. Wrong header slot on read. Because the read offset is derived from\n the completion index (desc_idx) while the device wrote the header to\n the address programmed for the buffer\u0027s buf_id, the driver can copy\n a header belonging to a different packet. This shows up as\n throughput drop (about 30% drop and large numbers of TCP\n retransmissions) with header-split and HW-GRO both enabled and many\n streams.\n\n2. Header buffer reused while still owned by the device. The driver\n advances bufq-\u003ehead by one per completion and re-posts buffers based\n on that. Arrival of N RX completions only guarantees that at least N\n RX buffer descriptors have been read by the device. It does not\n guarantee that the device has relinquished the ownership of all the\n buffers corresponding to those N descriptors. With out-of-order\n completions (e.g. the completion for a packet copied into buffer N\n arrives before the completion for a packet copied into buffer N-1),\n the driver can re-post and overwrite a header buffer that the device\n is still going to write into, corrupting the header of a packet\n whose completion has not yet been processed.\n\nFix both issues by indexing the header buffer by buf_id on both the post\nand read paths. Reading from buf_id\u0027s slot is therefore always correct\nregardless of completion ordering (fixes problem 1).\n\nIndexing by buf_id also ties each header slot to the lifetime of its\nbuffer state. A buffer state is only returned to the free/recycle lists\nwhen its own completion (buf_id) is processed, so its header slot can\nonly be re-posted after the device is done with it. This makes header\nslot reuse safe under out-of-order completions (fixes problem 2).\n\nAllocate (gve_rx_alloc_hdr_bufs) and free (gve_rx_free_hdr_bufs) the\nheader buffers based on num_buf_states to match the buf_id indexing."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in the GVE driver RX NAPI path triggered by incoming network frames; a remote peer can reach gve_rx_dqo()/gve_rx_post_buffers_dqo() by sending TCP traffic to an internet-facing GVE interface (e.g., GCP VM) without local access.\nAC:L - Once header-split and HW-GRO are enabled, an attacker can reliably trigger out-of-order HW-GRO completions by opening many concurrent TCP flows to the target; no race against uncontrollable victim state is required beyond normal multi-stream traffic patterns.\nPR:N - Exploitation requires only the ability to send network packets to the host; no local account, capabilities, or authentication on the victim is needed. Header-split being enabled is victim configuration, not attacker privilege.\nUI:N - No victim user action is required during exploitation beyond the host already receiving network traffic on its GVE interface; the attacker does not depend on the user mounting filesystems or opening files.\nS:U - Impact is confined to the guest kernel network stack and driver DMA header buffers on the affected VM; it does not cross a VM/host or IOMMU security boundary to affect the hypervisor or other tenants.\nC:H - Out-of-order completions cause the driver to read the wrong header slot, mixing headers between packets/flows and disclosing other connections\u0027 L3/L4 header bytes; premature header-buffer reuse also corrupts DMA data the driver later copies into skbs.\nI:H - The driver can repost and overwrite header DMA buffers while the device is still writing them, corrupting packet headers fed into the stack; wrong headers paired with payloads can break protocol parsing and constitutes exploitable kernel memory corruption.\nA:H - The bug causes severe TCP throughput collapse, massive retransmissions, and dropped/corrupted packets; header-buffer corruption and malformed skbs can also destabilize the kernel RX path and cause oopses or loss of network availability on the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:39:45.577Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/84d3753d4bf284ef770ead6dee2270aaabb3ef41"
},
{
"url": "https://git.kernel.org/stable/c/35267819b25074084130b6a7be18bbaf44d3ae74"
},
{
"url": "https://git.kernel.org/stable/c/9f8e7f59b0c2f466be74bd923726b0f5496c27ad"
},
{
"url": "https://git.kernel.org/stable/c/d676c9a73bdcd8237425dbb826f2bd1a25c36e40"
}
],
"title": "gve: fix header buffer corruption with header-split and HW-GRO",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72046",
"datePublished": "2026-08-15T05:52:04.769Z",
"dateReserved": "2026-08-09T03:40:39.902Z",
"dateUpdated": "2026-08-17T05:39:45.577Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-57841 (GCVE-0-2024-57841)
Vulnerability from cvelistv5
Published
2025-01-15 13:10
Modified
2026-05-23 15:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: fix memory leak in tcp_conn_request()
If inet_csk_reqsk_queue_hash_add() return false, tcp_conn_request() will
return without free the dst memory, which allocated in af_ops->route_req.
Here is the kmemleak stack:
unreferenced object 0xffff8881198631c0 (size 240):
comm "softirq", pid 0, jiffies 4299266571 (age 1802.392s)
hex dump (first 32 bytes):
00 10 9b 03 81 88 ff ff 80 98 da bc ff ff ff ff ................
81 55 18 bb ff ff ff ff 00 00 00 00 00 00 00 00 .U..............
backtrace:
[<ffffffffb93e8d4c>] kmem_cache_alloc+0x60c/0xa80
[<ffffffffba11b4c5>] dst_alloc+0x55/0x250
[<ffffffffba227bf6>] rt_dst_alloc+0x46/0x1d0
[<ffffffffba23050a>] __mkroute_output+0x29a/0xa50
[<ffffffffba23456b>] ip_route_output_key_hash+0x10b/0x240
[<ffffffffba2346bd>] ip_route_output_flow+0x1d/0x90
[<ffffffffba254855>] inet_csk_route_req+0x2c5/0x500
[<ffffffffba26b331>] tcp_conn_request+0x691/0x12c0
[<ffffffffba27bd08>] tcp_rcv_state_process+0x3c8/0x11b0
[<ffffffffba2965c6>] tcp_v4_do_rcv+0x156/0x3b0
[<ffffffffba299c98>] tcp_v4_rcv+0x1cf8/0x1d80
[<ffffffffba239656>] ip_protocol_deliver_rcu+0xf6/0x360
[<ffffffffba2399a6>] ip_local_deliver_finish+0xe6/0x1e0
[<ffffffffba239b8e>] ip_local_deliver+0xee/0x360
[<ffffffffba239ead>] ip_rcv+0xad/0x2f0
[<ffffffffba110943>] __netif_receive_skb_one_core+0x123/0x140
Call dst_release() to free the dst memory when
inet_csk_reqsk_queue_hash_add() return false in tcp_conn_request().
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 527bec1f56ac7a2fceb8eb77eb0fc2678ecba394 Version: c14f3c3793f7a785763e353df7fc40426187f832 Version: fdae4d139f4778b20a40c60705c53f5f146459b5 Version: ff46e3b4421923937b7f6e44ffcd3549a074f321 Version: ff46e3b4421923937b7f6e44ffcd3549a074f321 Version: 360892e60710427229fc1f7bb2218cf4d578229b Version: 5.15.162 ≤ Version: 6.1.97 ≤ Version: 6.6.37 ≤ Version: 6.9.8 ≤ |
||
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2024-57841",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-10-01T19:54:23.329434Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-401",
"description": "CWE-401 Missing Release of Memory after Effective Lifetime",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-10-01T19:57:18.572Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2025-11-03T20:54:41.406Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_input.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9d38959677291552d1b0ed2689a540af279b5bf8",
"status": "affected",
"version": "527bec1f56ac7a2fceb8eb77eb0fc2678ecba394",
"versionType": "git"
},
{
"lessThan": "de3f999bf8aee16e9da1c1224191abdc69e97c9d",
"status": "affected",
"version": "c14f3c3793f7a785763e353df7fc40426187f832",
"versionType": "git"
},
{
"lessThan": "2af69905180b3fea12f9c1db374b153a06977021",
"status": "affected",
"version": "fdae4d139f4778b20a40c60705c53f5f146459b5",
"versionType": "git"
},
{
"lessThan": "b0b190218c78d8aeecfba36ea3a90063b3ede52d",
"status": "affected",
"version": "ff46e3b4421923937b7f6e44ffcd3549a074f321",
"versionType": "git"
},
{
"lessThan": "4f4aa4aa28142d53f8b06585c478476cfe325cfc",
"status": "affected",
"version": "ff46e3b4421923937b7f6e44ffcd3549a074f321",
"versionType": "git"
},
{
"status": "affected",
"version": "360892e60710427229fc1f7bb2218cf4d578229b",
"versionType": "git"
},
{
"lessThan": "5.15.176",
"status": "affected",
"version": "5.15.162",
"versionType": "semver"
},
{
"lessThan": "6.1.124",
"status": "affected",
"version": "6.1.97",
"versionType": "semver"
},
{
"lessThan": "6.6.70",
"status": "affected",
"version": "6.6.37",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.9.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_input.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"lessThan": "6.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.124",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.70",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.13",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.176",
"versionStartIncluding": "5.15.162",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.124",
"versionStartIncluding": "6.1.97",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.70",
"versionStartIncluding": "6.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.9",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.13",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.9.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix memory leak in tcp_conn_request()\n\nIf inet_csk_reqsk_queue_hash_add() return false, tcp_conn_request() will\nreturn without free the dst memory, which allocated in af_ops-\u003eroute_req.\n\nHere is the kmemleak stack:\n\nunreferenced object 0xffff8881198631c0 (size 240):\n comm \"softirq\", pid 0, jiffies 4299266571 (age 1802.392s)\n hex dump (first 32 bytes):\n 00 10 9b 03 81 88 ff ff 80 98 da bc ff ff ff ff ................\n 81 55 18 bb ff ff ff ff 00 00 00 00 00 00 00 00 .U..............\n backtrace:\n [\u003cffffffffb93e8d4c\u003e] kmem_cache_alloc+0x60c/0xa80\n [\u003cffffffffba11b4c5\u003e] dst_alloc+0x55/0x250\n [\u003cffffffffba227bf6\u003e] rt_dst_alloc+0x46/0x1d0\n [\u003cffffffffba23050a\u003e] __mkroute_output+0x29a/0xa50\n [\u003cffffffffba23456b\u003e] ip_route_output_key_hash+0x10b/0x240\n [\u003cffffffffba2346bd\u003e] ip_route_output_flow+0x1d/0x90\n [\u003cffffffffba254855\u003e] inet_csk_route_req+0x2c5/0x500\n [\u003cffffffffba26b331\u003e] tcp_conn_request+0x691/0x12c0\n [\u003cffffffffba27bd08\u003e] tcp_rcv_state_process+0x3c8/0x11b0\n [\u003cffffffffba2965c6\u003e] tcp_v4_do_rcv+0x156/0x3b0\n [\u003cffffffffba299c98\u003e] tcp_v4_rcv+0x1cf8/0x1d80\n [\u003cffffffffba239656\u003e] ip_protocol_deliver_rcu+0xf6/0x360\n [\u003cffffffffba2399a6\u003e] ip_local_deliver_finish+0xe6/0x1e0\n [\u003cffffffffba239b8e\u003e] ip_local_deliver+0xee/0x360\n [\u003cffffffffba239ead\u003e] ip_rcv+0xad/0x2f0\n [\u003cffffffffba110943\u003e] __netif_receive_skb_one_core+0x123/0x140\n\nCall dst_release() to free the dst memory when\ninet_csk_reqsk_queue_hash_add() return false in tcp_conn_request()."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-23T15:56:09.585Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9d38959677291552d1b0ed2689a540af279b5bf8"
},
{
"url": "https://git.kernel.org/stable/c/de3f999bf8aee16e9da1c1224191abdc69e97c9d"
},
{
"url": "https://git.kernel.org/stable/c/2af69905180b3fea12f9c1db374b153a06977021"
},
{
"url": "https://git.kernel.org/stable/c/b0b190218c78d8aeecfba36ea3a90063b3ede52d"
},
{
"url": "https://git.kernel.org/stable/c/4f4aa4aa28142d53f8b06585c478476cfe325cfc"
}
],
"title": "net: fix memory leak in tcp_conn_request()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2024-57841",
"datePublished": "2025-01-15T13:10:26.842Z",
"dateReserved": "2025-01-15T13:08:59.716Z",
"dateUpdated": "2026-05-23T15:56:09.585Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64583 (GCVE-0-2026-64583)
Vulnerability from cvelistv5
Published
2026-08-06 07:06
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
The Broadcom BDC UDC driver registers its IRQ handler with
devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm
only after bdc_remove() returns. devm releases resources in reverse
LIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() ->
bdc_mem_free() manually before returning: bdc_udc_exit() tears down
individual endpoint objects via bdc_free_ep(), while bdc_hw_exit() ->
bdc_mem_free() frees and NULLs the DMA-coherent status-report ring
(bdc->srr.sr_bds) and kfree()s bdc->bdc_ep_array. Both happen while
the IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED)
remains deliverable in the window up to the post-remove devm
free_irq().
On receipt of a shared interrupt in that window, bdc_udc_interrupt()
dereferences bdc->srr.sr_bds[bdc->srr.dqp_index] (NULL or freed DMA)
and dispatches sr_handler callbacks that index into bdc_ep_array,
causing a NULL-deref or use-after-free.
The same window affects the delayed_work bdc->func_wake_notify, which is
armed from the IRQ handler via bdc_sr_uspc() -> handle_link_state_change()
-> schedule_delayed_work() and may self-rearm from its own callback
bdc_func_wake_timer(). No cancel exists anywhere in the driver, so a
queued work item that fires after bdc_remove() returns and the bdc
structure is devm-freed dereferences freed memory.
Replace devm_request_irq() with request_irq() and add an explicit
free_irq(bdc->irq, bdc) in bdc_remove(). Clear BDC_GIE before
free_irq() to stop the device from asserting interrupts, then
free_irq() drains any in-flight handler, then cancel_delayed_work_sync()
drains the func_wake_notify delayed work. This ordering ensures the
IRQ handler and delayed work cannot interfere with the subsequent
endpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit(). Wire the
matching free_irq() into the bdc_udc_init() error path so the IRQ is
released on probe failure, and route the bdc_init_ep() failure through
err0 instead of returning directly.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/bdc/bdc_core.c",
"drivers/usb/gadget/udc/bdc/bdc_udc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eac1107e54679db2df2c36d8bba3b66d3ab6cbcd",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "0b0b76e31b3991a899ae724eb97d359de0c0f1b1",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "3fe181952b8a1aeb167d4503c794c0f5050f08ed",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "f6fc21ec7ccd83726ba766d73d0b8cc03e726475",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "dcf3e2f164435b5844706cb8eefef29ebee0eedb",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "d4964a74717107697999f48bcb4e80a9c0679a27",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/bdc/bdc_core.c",
"drivers/usb/gadget/udc/bdc/bdc_udc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown\n\nThe Broadcom BDC UDC driver registers its IRQ handler with\ndevm_request_irq() in bdc_udc_init(), so the IRQ is released by devm\nonly after bdc_remove() returns. devm releases resources in reverse\nLIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() -\u003e\nbdc_mem_free() manually before returning: bdc_udc_exit() tears down\nindividual endpoint objects via bdc_free_ep(), while bdc_hw_exit() -\u003e\nbdc_mem_free() frees and NULLs the DMA-coherent status-report ring\n(bdc-\u003esrr.sr_bds) and kfree()s bdc-\u003ebdc_ep_array. Both happen while\nthe IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED)\nremains deliverable in the window up to the post-remove devm\nfree_irq().\n\nOn receipt of a shared interrupt in that window, bdc_udc_interrupt()\ndereferences bdc-\u003esrr.sr_bds[bdc-\u003esrr.dqp_index] (NULL or freed DMA)\nand dispatches sr_handler callbacks that index into bdc_ep_array,\ncausing a NULL-deref or use-after-free.\n\nThe same window affects the delayed_work bdc-\u003efunc_wake_notify, which is\narmed from the IRQ handler via bdc_sr_uspc() -\u003e handle_link_state_change()\n-\u003e schedule_delayed_work() and may self-rearm from its own callback\nbdc_func_wake_timer(). No cancel exists anywhere in the driver, so a\nqueued work item that fires after bdc_remove() returns and the bdc\nstructure is devm-freed dereferences freed memory.\n\nReplace devm_request_irq() with request_irq() and add an explicit\nfree_irq(bdc-\u003eirq, bdc) in bdc_remove(). Clear BDC_GIE before\nfree_irq() to stop the device from asserting interrupts, then\nfree_irq() drains any in-flight handler, then cancel_delayed_work_sync()\ndrains the func_wake_notify delayed work. This ordering ensures the\nIRQ handler and delayed work cannot interfere with the subsequent\nendpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit(). Wire the\nmatching free_irq() into the bdc_udc_init() error path so the IRQ is\nreleased on probe failure, and route the bdc_init_ep() failure through\nerr0 instead of returning directly.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable window opens on local BDC platform-driver teardown (sysfs unbind/rmmod \u2192 bdc_remove), not on parsing USB host packets; that matches other USB gadget/UDC teardown UAFs scored AV:L and is higher severity than Physical.\nAC:L - The attacker controls remove/bind retries; a pending func_wake_notify (never cancelled before the fix) runs deterministically on the post-remove freed bdc, and IRQF_SHARED plus USB activity can also hit the IRQ window during teardown.\nPR:L - Highest reasonable exposure is a local account managing the gadget/UDC on Android or Broadcom STB systems where platform unbind is delegated beyond init-namespace root; uncertain Low vs High, so Low per the overestimate rule.\nUI:N - The attacker performs driver remove and any prior link-state activity that arms func_wake_notify themselves; no separate victim mount, open, or other interaction is required.\nS:U - NULL-deref/use-after-free of sr_bds, bdc_ep_array, and the delayed-work bdc object stays inside the host kernel authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - Use-after-free of the DMA status-report ring, endpoint array, and the bdc object via IRQ/work handlers allows reclaim/spray and disclosure of kernel memory, which per UAF guidance is High.\nI:H - The same UAF paths write through freed endpoint/status structures and run delayed work on a freed bdc, enabling heap corruption and control-flow hijack suitable for privilege escalation.\nA:H - Dereferencing NULL/freed sr_bds in hard-IRQ context or executing bdc_func_wake_timer on a post-remove freed bdc causes kernel oops/panic, so availability impact is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:42.500Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eac1107e54679db2df2c36d8bba3b66d3ab6cbcd"
},
{
"url": "https://git.kernel.org/stable/c/0b0b76e31b3991a899ae724eb97d359de0c0f1b1"
},
{
"url": "https://git.kernel.org/stable/c/3fe181952b8a1aeb167d4503c794c0f5050f08ed"
},
{
"url": "https://git.kernel.org/stable/c/1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8"
},
{
"url": "https://git.kernel.org/stable/c/f6fc21ec7ccd83726ba766d73d0b8cc03e726475"
},
{
"url": "https://git.kernel.org/stable/c/dcf3e2f164435b5844706cb8eefef29ebee0eedb"
},
{
"url": "https://git.kernel.org/stable/c/d4964a74717107697999f48bcb4e80a9c0679a27"
},
{
"url": "https://git.kernel.org/stable/c/0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb"
}
],
"title": "usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64583",
"datePublished": "2026-08-06T07:06:25.335Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-23T12:45:42.500Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68288 (GCVE-0-2026-68288)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code
the NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload
before overwriting it with skb_copy_bits().
skb_put() reserves nla_total_size(payload_len), i.e. the header plus the
NLA_ALIGN() padding, but only payload_len bytes are copied in. When
payload_len is not a multiple of 4 the 1-3 padding bytes are never
initialized and are leaked to user space inside the netlink message.
KMSAN confirms the leak for the software path when the packet payload
length is not 4-byte aligned:
BUG: KMSAN: kernel-infoleak in _copy_to_iter
_copy_to_iter
__skb_datagram_iter
skb_copy_datagram_iter
netlink_recvmsg
sock_recvmsg
__sys_recvfrom
Uninit was created at:
kmem_cache_alloc_node_noprof
__alloc_skb
net_dm_packet_work
Bytes 173-175 of 176 are uninitialized
Use __nla_reserve(), which sets up the attribute header and zeroes the
padding, instead of open coding the attribute construction.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/drop_monitor.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8fd6975d2aecc36b25ee82b6aef88e62a3527ccb",
"status": "affected",
"version": "ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f",
"versionType": "git"
},
{
"lessThan": "5e9c8baee0329fbefe7c67aea945e2a07f15e98b",
"status": "affected",
"version": "ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/drop_monitor.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD\n\nnet_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code\nthe NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload\nbefore overwriting it with skb_copy_bits().\n\nskb_put() reserves nla_total_size(payload_len), i.e. the header plus the\nNLA_ALIGN() padding, but only payload_len bytes are copied in. When\npayload_len is not a multiple of 4 the 1-3 padding bytes are never\ninitialized and are leaked to user space inside the netlink message.\n\nKMSAN confirms the leak for the software path when the packet payload\nlength is not 4-byte aligned:\n\n BUG: KMSAN: kernel-infoleak in _copy_to_iter\n _copy_to_iter\n __skb_datagram_iter\n skb_copy_datagram_iter\n netlink_recvmsg\n sock_recvmsg\n __sys_recvfrom\n Uninit was created at:\n kmem_cache_alloc_node_noprof\n __alloc_skb\n net_dm_packet_work\n Bytes 173-175 of 176 are uninitialized\n\nUse __nla_reserve(), which sets up the attribute header and zeroes the\npadding, instead of open coding the attribute construction."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:23.619Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8fd6975d2aecc36b25ee82b6aef88e62a3527ccb"
},
{
"url": "https://git.kernel.org/stable/c/5e9c8baee0329fbefe7c67aea945e2a07f15e98b"
}
],
"title": "net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68288",
"datePublished": "2026-08-10T12:02:21.097Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-17T05:02:23.619Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64454 (GCVE-0-2026-64454)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: dwc3: run gadget disconnect from sleepable suspend context
dwc3_gadget_suspend() takes dwc->lock with IRQs disabled and then calls
dwc3_disconnect_gadget(). For async callbacks that helper only uses
plain spin_unlock()/spin_lock(), so the gadget ->disconnect() callback
still runs with IRQs disabled and any sleepable callback trips Lockdep.
This issue was found by our static analysis tool and then manually
reviewed against the current tree.
The grounded PoC kept the dwc3_gadget_suspend() ->
dwc3_disconnect_gadget() -> gadget_driver->disconnect() chain, and
Lockdep reported:
BUG: sleeping function called from invalid context
gadget_disconnect+0x21/0x39 [vuln_msv]
dwc3_gadget_suspend.constprop.0+0x2b/0x42 [vuln_msv]
Keep the disconnect callback selection in one common helper, but add a
sleepable suspend-side wrapper which snapshots the callback under
dwc->lock and then runs it after spin_unlock_irqrestore(). The regular
event path still uses the existing spin_unlock()/spin_lock() window.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 20351ddb1f41cfb3ae20e105425ef43a28393d76 Version: ad43004fd5326bec4466ecc8a07fe0e570b553ca Version: c8540870af4ce6ddeb27a7bb5498b75fb29b643c Version: c8540870af4ce6ddeb27a7bb5498b75fb29b643c Version: c8540870af4ce6ddeb27a7bb5498b75fb29b643c Version: c8540870af4ce6ddeb27a7bb5498b75fb29b643c Version: c8540870af4ce6ddeb27a7bb5498b75fb29b643c Version: 06684c72b6b153dc434bb6ccebbb49f4cd812b5e Version: 5.15.128 ≤ Version: 6.1.30 ≤ Version: 6.3.4 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/dwc3/gadget.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b399be2958456efe1b64b19c55a54a24e9035769",
"status": "affected",
"version": "20351ddb1f41cfb3ae20e105425ef43a28393d76",
"versionType": "git"
},
{
"lessThan": "48958478cb8dbc429a5b19f36e866b63d6297d1d",
"status": "affected",
"version": "ad43004fd5326bec4466ecc8a07fe0e570b553ca",
"versionType": "git"
},
{
"lessThan": "5e5798880eb1533a7de6fb68eb14b2d8202ebf76",
"status": "affected",
"version": "c8540870af4ce6ddeb27a7bb5498b75fb29b643c",
"versionType": "git"
},
{
"lessThan": "e0e4f15d4225fb7156cc0e3c21eb8953114f9b89",
"status": "affected",
"version": "c8540870af4ce6ddeb27a7bb5498b75fb29b643c",
"versionType": "git"
},
{
"lessThan": "c4e232bd07fe2b69a6e5c380db41dd36b95e0524",
"status": "affected",
"version": "c8540870af4ce6ddeb27a7bb5498b75fb29b643c",
"versionType": "git"
},
{
"lessThan": "642e04f5c292d04070ae6e4374fbf14cc40a2465",
"status": "affected",
"version": "c8540870af4ce6ddeb27a7bb5498b75fb29b643c",
"versionType": "git"
},
{
"lessThan": "010382937fb69892b3469ac4d30af072262f59e8",
"status": "affected",
"version": "c8540870af4ce6ddeb27a7bb5498b75fb29b643c",
"versionType": "git"
},
{
"status": "affected",
"version": "06684c72b6b153dc434bb6ccebbb49f4cd812b5e",
"versionType": "git"
},
{
"lessThan": "5.15.212",
"status": "affected",
"version": "5.15.128",
"versionType": "semver"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.30",
"versionType": "semver"
},
{
"lessThan": "6.4",
"status": "affected",
"version": "6.3.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/dwc3/gadget.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.15.128",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.3.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: run gadget disconnect from sleepable suspend context\n\ndwc3_gadget_suspend() takes dwc-\u003elock with IRQs disabled and then calls\ndwc3_disconnect_gadget(). For async callbacks that helper only uses\nplain spin_unlock()/spin_lock(), so the gadget -\u003edisconnect() callback\nstill runs with IRQs disabled and any sleepable callback trips Lockdep.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the dwc3_gadget_suspend() -\u003e\ndwc3_disconnect_gadget() -\u003e gadget_driver-\u003edisconnect() chain, and\nLockdep reported:\n\n BUG: sleeping function called from invalid context\n gadget_disconnect+0x21/0x39 [vuln_msv]\n dwc3_gadget_suspend.constprop.0+0x2b/0x42 [vuln_msv]\n\nKeep the disconnect callback selection in one common helper, but add a\nsleepable suspend-side wrapper which snapshots the callback under\ndwc-\u003elock and then runs it after spin_unlock_irqrestore(). The regular\nevent path still uses the existing spin_unlock()/spin_lock() window."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:55:58.408Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b399be2958456efe1b64b19c55a54a24e9035769"
},
{
"url": "https://git.kernel.org/stable/c/48958478cb8dbc429a5b19f36e866b63d6297d1d"
},
{
"url": "https://git.kernel.org/stable/c/5e5798880eb1533a7de6fb68eb14b2d8202ebf76"
},
{
"url": "https://git.kernel.org/stable/c/e0e4f15d4225fb7156cc0e3c21eb8953114f9b89"
},
{
"url": "https://git.kernel.org/stable/c/c4e232bd07fe2b69a6e5c380db41dd36b95e0524"
},
{
"url": "https://git.kernel.org/stable/c/642e04f5c292d04070ae6e4374fbf14cc40a2465"
},
{
"url": "https://git.kernel.org/stable/c/010382937fb69892b3469ac4d30af072262f59e8"
}
],
"title": "usb: dwc3: run gadget disconnect from sleepable suspend context",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64454",
"datePublished": "2026-07-25T08:51:23.212Z",
"dateReserved": "2026-07-19T15:36:31.789Z",
"dateUpdated": "2026-08-17T04:55:58.408Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64505 (GCVE-0-2026-64505)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: function: rndis: add length check for header
Add a length check for the rndis header in rndis_rm_hdr, to ensure that
MessageType, MessageLength, DataOffset, and DataLength fields are
present before they are accessed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6cdee106e7571751ecc0e9f96606322f88b64a8d Version: 6cdee106e7571751ecc0e9f96606322f88b64a8d Version: 6cdee106e7571751ecc0e9f96606322f88b64a8d Version: 6cdee106e7571751ecc0e9f96606322f88b64a8d Version: 6cdee106e7571751ecc0e9f96606322f88b64a8d Version: 6cdee106e7571751ecc0e9f96606322f88b64a8d Version: 6cdee106e7571751ecc0e9f96606322f88b64a8d Version: 6cdee106e7571751ecc0e9f96606322f88b64a8d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/rndis.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "200dd5092296ad4d5ae47f8445a2fb1edd1da973",
"status": "affected",
"version": "6cdee106e7571751ecc0e9f96606322f88b64a8d",
"versionType": "git"
},
{
"lessThan": "9ffd567d7bf269824dfac06f8ab9a32fef72699b",
"status": "affected",
"version": "6cdee106e7571751ecc0e9f96606322f88b64a8d",
"versionType": "git"
},
{
"lessThan": "b73c0142e3acdc063b50c33afb7be19cdb2cd410",
"status": "affected",
"version": "6cdee106e7571751ecc0e9f96606322f88b64a8d",
"versionType": "git"
},
{
"lessThan": "d6ef5af7d0fe1ac31e5653a77e6d775dd36bc433",
"status": "affected",
"version": "6cdee106e7571751ecc0e9f96606322f88b64a8d",
"versionType": "git"
},
{
"lessThan": "ba2cc601e59fe68716646199a33303493513e2e3",
"status": "affected",
"version": "6cdee106e7571751ecc0e9f96606322f88b64a8d",
"versionType": "git"
},
{
"lessThan": "7515a6d4a9e9e4838b833825882efa00e85f8901",
"status": "affected",
"version": "6cdee106e7571751ecc0e9f96606322f88b64a8d",
"versionType": "git"
},
{
"lessThan": "9facd79028a7807879eb441d12f0e00720980aa3",
"status": "affected",
"version": "6cdee106e7571751ecc0e9f96606322f88b64a8d",
"versionType": "git"
},
{
"lessThan": "21b5bf155435008e0fb0736795289788e63d426f",
"status": "affected",
"version": "6cdee106e7571751ecc0e9f96606322f88b64a8d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/rndis.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: function: rndis: add length check for header\n\nAdd a length check for the rndis header in rndis_rm_hdr, to ensure that\nMessageType, MessageLength, DataOffset, and DataLength fields are\npresent before they are accessed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:55.519Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/200dd5092296ad4d5ae47f8445a2fb1edd1da973"
},
{
"url": "https://git.kernel.org/stable/c/9ffd567d7bf269824dfac06f8ab9a32fef72699b"
},
{
"url": "https://git.kernel.org/stable/c/b73c0142e3acdc063b50c33afb7be19cdb2cd410"
},
{
"url": "https://git.kernel.org/stable/c/d6ef5af7d0fe1ac31e5653a77e6d775dd36bc433"
},
{
"url": "https://git.kernel.org/stable/c/ba2cc601e59fe68716646199a33303493513e2e3"
},
{
"url": "https://git.kernel.org/stable/c/7515a6d4a9e9e4838b833825882efa00e85f8901"
},
{
"url": "https://git.kernel.org/stable/c/9facd79028a7807879eb441d12f0e00720980aa3"
},
{
"url": "https://git.kernel.org/stable/c/21b5bf155435008e0fb0736795289788e63d426f"
}
],
"title": "usb: gadget: function: rndis: add length check for header",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64505",
"datePublished": "2026-07-25T08:51:59.618Z",
"dateReserved": "2026-07-19T15:36:31.793Z",
"dateUpdated": "2026-08-17T04:56:55.519Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68181 (GCVE-0-2026-68181)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mei: bus: access mei_device under device_lock on cleanup
Fix couple of problems in mei_cl_bus_dev_release():
mei_cl_flush_queues() is running without lock.
bus->file_list access after mei_dev_bus_put(bus) can become a
use-after-free if this was the last reference to bus.
Protect queues cleanup and WARN traversal by device lock there
to avoid the concurrent access problems.
Move WARN traversal before mei_dev_bus_put(bus).
This file uses bus variable name for mei_device, adjust
code of mei_cl_bus_dev_release() to use bus variable too.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6f2a6ef86b23a30b92ad57981de537bce67bfa45 Version: 24f4ceeaeee7983c07590149556a0e33efe2ec90 Version: 612c8d21ce6e37b73f3106aec7ffa35959d40261 Version: 35e8a426b16adbecae7a4e0e3c00fc8d0273db53 Version: 35e8a426b16adbecae7a4e0e3c00fc8d0273db53 Version: 35e8a426b16adbecae7a4e0e3c00fc8d0273db53 Version: 2f29dce5a5ae06a7db32e4491d72269329a86eeb Version: 28de6ca5276a94b0589ae1bf026b89fa0eaf14c0 Version: 6.1.149 ≤ Version: 6.6.103 ≤ Version: 6.12.43 ≤ Version: 6.15.11 ≤ Version: 6.16.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/misc/mei/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "02e3a755086db847d795f2593ebc45e8ee4f1755",
"status": "affected",
"version": "6f2a6ef86b23a30b92ad57981de537bce67bfa45",
"versionType": "git"
},
{
"lessThan": "441559d4c595f839b39f0ab6a4ae628427c2fd9e",
"status": "affected",
"version": "24f4ceeaeee7983c07590149556a0e33efe2ec90",
"versionType": "git"
},
{
"lessThan": "c88c030a324c9018b77894a19b2564eb66862020",
"status": "affected",
"version": "612c8d21ce6e37b73f3106aec7ffa35959d40261",
"versionType": "git"
},
{
"lessThan": "59dd34854202d9a3faaa87a85205e553fe7150e1",
"status": "affected",
"version": "35e8a426b16adbecae7a4e0e3c00fc8d0273db53",
"versionType": "git"
},
{
"lessThan": "7cf79e8d682fe93777268f029668ce5e214237fd",
"status": "affected",
"version": "35e8a426b16adbecae7a4e0e3c00fc8d0273db53",
"versionType": "git"
},
{
"lessThan": "f112ea910e554d58b4b39a4492b7d302f0f4204f",
"status": "affected",
"version": "35e8a426b16adbecae7a4e0e3c00fc8d0273db53",
"versionType": "git"
},
{
"status": "affected",
"version": "2f29dce5a5ae06a7db32e4491d72269329a86eeb",
"versionType": "git"
},
{
"status": "affected",
"version": "28de6ca5276a94b0589ae1bf026b89fa0eaf14c0",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.149",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.103",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.43",
"versionType": "semver"
},
{
"lessThan": "6.16",
"status": "affected",
"version": "6.15.11",
"versionType": "semver"
},
{
"lessThan": "6.17",
"status": "affected",
"version": "6.16.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/misc/mei/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"lessThan": "6.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.149",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.103",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.43",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.15.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.16.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmei: bus: access mei_device under device_lock on cleanup\n\nFix couple of problems in mei_cl_bus_dev_release():\n\nmei_cl_flush_queues() is running without lock.\nbus-\u003efile_list access after mei_dev_bus_put(bus) can become a\nuse-after-free if this was the last reference to bus.\n\nProtect queues cleanup and WARN traversal by device lock there\nto avoid the concurrent access problems.\nMove WARN traversal before mei_dev_bus_put(bus).\n\nThis file uses bus variable name for mei_device, adjust\ncode of mei_cl_bus_dev_release() to use bus variable too."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:04.934Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/02e3a755086db847d795f2593ebc45e8ee4f1755"
},
{
"url": "https://git.kernel.org/stable/c/441559d4c595f839b39f0ab6a4ae628427c2fd9e"
},
{
"url": "https://git.kernel.org/stable/c/c88c030a324c9018b77894a19b2564eb66862020"
},
{
"url": "https://git.kernel.org/stable/c/59dd34854202d9a3faaa87a85205e553fe7150e1"
},
{
"url": "https://git.kernel.org/stable/c/7cf79e8d682fe93777268f029668ce5e214237fd"
},
{
"url": "https://git.kernel.org/stable/c/f112ea910e554d58b4b39a4492b7d302f0f4204f"
}
],
"title": "mei: bus: access mei_device under device_lock on cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68181",
"datePublished": "2026-08-10T11:59:52.724Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-23T12:46:04.934Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74395 (GCVE-0-2026-74395)
Vulnerability from cvelistv5
Published
2026-08-15 05:59
Modified
2026-08-17 05:18
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
MLX5_IB_METHOD_DEVX_SUBSCRIBE_EVENT() links event_sub into sub_list
before initializing the fields used by the shared error path.
If eventfd_ctx_fdget() then fails, the unwind path dereferences
event_sub->ev_file in uverbs_uobject_put() and calls
subscribe_event_xa_dealloc() with an unset xa_key_level1.
subscribe_event_xa_alloc() creates the XA entry exactly once for a given
key_level1, on the first occurrence of that key. The unwind path must
therefore call subscribe_event_xa_dealloc() exactly once for it as well.
Enforce that by adding devx_key_in_sub_list() and calling
subscribe_event_xa_dealloc() only when the last matching pending entry is
being cleaned up.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7597385371425febdaa8c6a1da3625d4ffff16f5 Version: 7597385371425febdaa8c6a1da3625d4ffff16f5 Version: 7597385371425febdaa8c6a1da3625d4ffff16f5 Version: 7597385371425febdaa8c6a1da3625d4ffff16f5 Version: 7597385371425febdaa8c6a1da3625d4ffff16f5 Version: 7597385371425febdaa8c6a1da3625d4ffff16f5 Version: 7597385371425febdaa8c6a1da3625d4ffff16f5 Version: 7597385371425febdaa8c6a1da3625d4ffff16f5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/mlx5/devx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6e15b770461eeaa0ff73934922cb670a6a9db04e",
"status": "affected",
"version": "7597385371425febdaa8c6a1da3625d4ffff16f5",
"versionType": "git"
},
{
"lessThan": "9be9aca28424228586fe9211c373ebdb826ebb6c",
"status": "affected",
"version": "7597385371425febdaa8c6a1da3625d4ffff16f5",
"versionType": "git"
},
{
"lessThan": "f345e744b6b087188cde2377da5cbe9713b61353",
"status": "affected",
"version": "7597385371425febdaa8c6a1da3625d4ffff16f5",
"versionType": "git"
},
{
"lessThan": "1025dc2f7ba29b04b8687790fa91f9cd1a53141e",
"status": "affected",
"version": "7597385371425febdaa8c6a1da3625d4ffff16f5",
"versionType": "git"
},
{
"lessThan": "7921821fc2b19c01588311f6e7468ae5b68b1f61",
"status": "affected",
"version": "7597385371425febdaa8c6a1da3625d4ffff16f5",
"versionType": "git"
},
{
"lessThan": "5100febf8e9d6c8c5ba8dc6534c6a5e3376e5989",
"status": "affected",
"version": "7597385371425febdaa8c6a1da3625d4ffff16f5",
"versionType": "git"
},
{
"lessThan": "78b9589fda266c71f0f9d0c858d4fa7381a890a5",
"status": "affected",
"version": "7597385371425febdaa8c6a1da3625d4ffff16f5",
"versionType": "git"
},
{
"lessThan": "43f8f7946814c8e5f464518246fdbc69b6e32326",
"status": "affected",
"version": "7597385371425febdaa8c6a1da3625d4ffff16f5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/mlx5/devx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix devx subscribe-event unwind NULL dereference\n\nMLX5_IB_METHOD_DEVX_SUBSCRIBE_EVENT() links event_sub into sub_list\nbefore initializing the fields used by the shared error path.\n\nIf eventfd_ctx_fdget() then fails, the unwind path dereferences\nevent_sub-\u003eev_file in uverbs_uobject_put() and calls\nsubscribe_event_xa_dealloc() with an unset xa_key_level1.\n\nsubscribe_event_xa_alloc() creates the XA entry exactly once for a given\nkey_level1, on the first occurrence of that key. The unwind path must\ntherefore call subscribe_event_xa_dealloc() exactly once for it as well.\n\nEnforce that by adding devx_key_in_sub_list() and calling\nsubscribe_event_xa_dealloc() only when the last matching pending entry is\nbeing cleaned up."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:18:34.634Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6e15b770461eeaa0ff73934922cb670a6a9db04e"
},
{
"url": "https://git.kernel.org/stable/c/9be9aca28424228586fe9211c373ebdb826ebb6c"
},
{
"url": "https://git.kernel.org/stable/c/f345e744b6b087188cde2377da5cbe9713b61353"
},
{
"url": "https://git.kernel.org/stable/c/1025dc2f7ba29b04b8687790fa91f9cd1a53141e"
},
{
"url": "https://git.kernel.org/stable/c/7921821fc2b19c01588311f6e7468ae5b68b1f61"
},
{
"url": "https://git.kernel.org/stable/c/5100febf8e9d6c8c5ba8dc6534c6a5e3376e5989"
},
{
"url": "https://git.kernel.org/stable/c/78b9589fda266c71f0f9d0c858d4fa7381a890a5"
},
{
"url": "https://git.kernel.org/stable/c/43f8f7946814c8e5f464518246fdbc69b6e32326"
}
],
"title": "RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74395",
"datePublished": "2026-08-15T05:59:07.798Z",
"dateReserved": "2026-08-15T05:44:03.891Z",
"dateUpdated": "2026-08-17T05:18:34.634Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64350 (GCVE-0-2026-64350)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
cdnsp_alloc_stream_info() allocates stream_info->stream_ctx_array with
cdnsp_alloc_stream_ctx(). If a later stream ring allocation or stream
mapping update fails, the error path frees the allocated stream rings
and stream_rings array, but leaves stream_ctx_array allocated.
Free the stream context array before falling through to the stream_rings
cleanup path.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3d82904559f4f5a2622db1b21de3edf2eded7664 Version: 3d82904559f4f5a2622db1b21de3edf2eded7664 Version: 3d82904559f4f5a2622db1b21de3edf2eded7664 Version: 3d82904559f4f5a2622db1b21de3edf2eded7664 Version: 3d82904559f4f5a2622db1b21de3edf2eded7664 Version: 3d82904559f4f5a2622db1b21de3edf2eded7664 Version: 3d82904559f4f5a2622db1b21de3edf2eded7664 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/cdns3/cdnsp-mem.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "37283f5a47127fbdea567749a2110766af53d18d",
"status": "affected",
"version": "3d82904559f4f5a2622db1b21de3edf2eded7664",
"versionType": "git"
},
{
"lessThan": "cb8e9391b7f4f77d112c51910cd7c355a337ef76",
"status": "affected",
"version": "3d82904559f4f5a2622db1b21de3edf2eded7664",
"versionType": "git"
},
{
"lessThan": "fde3c095e1d48e0ac3ab8bc32905da42fe58a36a",
"status": "affected",
"version": "3d82904559f4f5a2622db1b21de3edf2eded7664",
"versionType": "git"
},
{
"lessThan": "d9643bbe93a6aee24edee1a86e0303aa74bcd320",
"status": "affected",
"version": "3d82904559f4f5a2622db1b21de3edf2eded7664",
"versionType": "git"
},
{
"lessThan": "c00826e87bb75e14e0381b05da5f18ffd0241ab6",
"status": "affected",
"version": "3d82904559f4f5a2622db1b21de3edf2eded7664",
"versionType": "git"
},
{
"lessThan": "963075c4da0cd43b3d17b107c355e1eb0ee64a58",
"status": "affected",
"version": "3d82904559f4f5a2622db1b21de3edf2eded7664",
"versionType": "git"
},
{
"lessThan": "3348f444a4ce43dd5c2d1aa41634cb6eff33aa64",
"status": "affected",
"version": "3d82904559f4f5a2622db1b21de3edf2eded7664",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/cdns3/cdnsp-mem.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()\n\ncdnsp_alloc_stream_info() allocates stream_info-\u003estream_ctx_array with\ncdnsp_alloc_stream_ctx(). If a later stream ring allocation or stream\nmapping update fails, the error path frees the allocated stream rings\nand stream_rings array, but leaves stream_ctx_array allocated.\n\nFree the stream context array before falling through to the stream_rings\ncleanup path."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:55.657Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/37283f5a47127fbdea567749a2110766af53d18d"
},
{
"url": "https://git.kernel.org/stable/c/cb8e9391b7f4f77d112c51910cd7c355a337ef76"
},
{
"url": "https://git.kernel.org/stable/c/fde3c095e1d48e0ac3ab8bc32905da42fe58a36a"
},
{
"url": "https://git.kernel.org/stable/c/d9643bbe93a6aee24edee1a86e0303aa74bcd320"
},
{
"url": "https://git.kernel.org/stable/c/c00826e87bb75e14e0381b05da5f18ffd0241ab6"
},
{
"url": "https://git.kernel.org/stable/c/963075c4da0cd43b3d17b107c355e1eb0ee64a58"
},
{
"url": "https://git.kernel.org/stable/c/3348f444a4ce43dd5c2d1aa41634cb6eff33aa64"
}
],
"title": "usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64350",
"datePublished": "2026-07-25T08:50:10.270Z",
"dateReserved": "2026-07-19T15:36:31.782Z",
"dateUpdated": "2026-08-17T04:53:55.657Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52920 (GCVE-0-2026-52920)
Vulnerability from cvelistv5
Published
2026-06-24 07:14
Modified
2026-08-05 12:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_policy: fix strict mode inbound policy matching
match_policy_in() walks sec_path entries from the last transform to the
first one, but strict policy matching needs to consume info->pol[] in
the same forward order as the rule layout.
Derive the strict-match policy position from the number of transforms
already consumed so that multi-element inbound rules are matched
consistently.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c4b885139203d37f76662c37ae645fe8e0f4e4e5 Version: c4b885139203d37f76662c37ae645fe8e0f4e4e5 Version: c4b885139203d37f76662c37ae645fe8e0f4e4e5 Version: c4b885139203d37f76662c37ae645fe8e0f4e4e5 Version: c4b885139203d37f76662c37ae645fe8e0f4e4e5 Version: c4b885139203d37f76662c37ae645fe8e0f4e4e5 Version: c4b885139203d37f76662c37ae645fe8e0f4e4e5 Version: c4b885139203d37f76662c37ae645fe8e0f4e4e5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/xt_policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eb323f7b82d2e2f638de0cc2a177803eb20e0707",
"status": "affected",
"version": "c4b885139203d37f76662c37ae645fe8e0f4e4e5",
"versionType": "git"
},
{
"lessThan": "fc1c518bb1f054831ecabb32da9b8e1dff9699c6",
"status": "affected",
"version": "c4b885139203d37f76662c37ae645fe8e0f4e4e5",
"versionType": "git"
},
{
"lessThan": "f98b7f85e04b40e28b08c461ded0cc79f14f5509",
"status": "affected",
"version": "c4b885139203d37f76662c37ae645fe8e0f4e4e5",
"versionType": "git"
},
{
"lessThan": "82664d0f1ba25e4f9a71994954abae24c60f4067",
"status": "affected",
"version": "c4b885139203d37f76662c37ae645fe8e0f4e4e5",
"versionType": "git"
},
{
"lessThan": "b130a6eefa02bd4d475f2f059da8bcfb3e7d18d9",
"status": "affected",
"version": "c4b885139203d37f76662c37ae645fe8e0f4e4e5",
"versionType": "git"
},
{
"lessThan": "938867e870fb5471bb16f442aeac81326e05bf65",
"status": "affected",
"version": "c4b885139203d37f76662c37ae645fe8e0f4e4e5",
"versionType": "git"
},
{
"lessThan": "392cc1d8408b5665215c1e9290bbf0f92339b043",
"status": "affected",
"version": "c4b885139203d37f76662c37ae645fe8e0f4e4e5",
"versionType": "git"
},
{
"lessThan": "4b2b4d7d4e203c92db8966b163edfacb1f0e1e29",
"status": "affected",
"version": "c4b885139203d37f76662c37ae645fe8e0f4e4e5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/xt_policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.17"
},
{
"lessThan": "2.6.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_policy: fix strict mode inbound policy matching\n\nmatch_policy_in() walks sec_path entries from the last transform to the\nfirst one, but strict policy matching needs to consume info-\u003epol[] in\nthe same forward order as the rule layout.\n\nDerive the strict-match policy position from the number of transforms\nalready consumed so that multi-element inbound rules are matched\nconsistently."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable matcher is executed while processing inbound IPv4/IPv6 packets through x_tables after XFRM/IPsec has populated the packet sec_path. A remote IPsec peer can trigger the affected strict inbound policy rule by sending network packets in a realistic VPN/gateway deployment.\nAC:L - Exploitation requires a strict inbound xt_policy rule with multiple policy elements and a packet with the same number of transforms, but those are normal affected configurations rather than attacker-uncontrolled races. Once present, triggering is repeatable by sending matching packets.\nPR:L - Unauthenticated packets generally fail XFRM state/authentication before reaching this sec_path-based match, so the network scenario requires an authorized IPsec peer or equivalent low privilege. Locally, the rule/XFRM setup is gated by CAP_NET_ADMIN in the network namespace, which is reachable through user namespaces.\nUI:N - No victim user action is needed after the vulnerable rule/state configuration exists. Packet delivery or local namespace traffic is sufficient to invoke the matcher.\nS:U - The bug is in kernel netfilter/XFRM policy evaluation and impacts the same kernel/network security authority. It does not cross a VM, IOMMU, or separate sandbox security scope.\nC:H - The old strict inbound index calculation can make pos negative and read before info-\u003epol[], including x_tables rule metadata or adjacent kernel allocation contents. Although exposed through match behavior rather than a direct copy_to_user, this is an out-of-bounds kernel read larger than a few bytes, so the higher confidentiality impact is warranted.\nI:L - The bug does not provide a direct write primitive or code execution path, but it can make strict IPsec policy matching produce incorrect firewall decisions. That can bypass or misapply intended packet filtering for affected multi-element inbound rules.\nA:H - The negative-index read can reach outside the intended match data and, for larger strict transform counts or unlucky layout, may fault/oops in kernel packet processing. The condition can be triggered repeatedly with packets once the affected rule path is reachable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:31:42.384Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eb323f7b82d2e2f638de0cc2a177803eb20e0707"
},
{
"url": "https://git.kernel.org/stable/c/fc1c518bb1f054831ecabb32da9b8e1dff9699c6"
},
{
"url": "https://git.kernel.org/stable/c/f98b7f85e04b40e28b08c461ded0cc79f14f5509"
},
{
"url": "https://git.kernel.org/stable/c/82664d0f1ba25e4f9a71994954abae24c60f4067"
},
{
"url": "https://git.kernel.org/stable/c/b130a6eefa02bd4d475f2f059da8bcfb3e7d18d9"
},
{
"url": "https://git.kernel.org/stable/c/938867e870fb5471bb16f442aeac81326e05bf65"
},
{
"url": "https://git.kernel.org/stable/c/392cc1d8408b5665215c1e9290bbf0f92339b043"
},
{
"url": "https://git.kernel.org/stable/c/4b2b4d7d4e203c92db8966b163edfacb1f0e1e29"
}
],
"title": "netfilter: xt_policy: fix strict mode inbound policy matching",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52920",
"datePublished": "2026-06-24T07:14:15.866Z",
"dateReserved": "2026-06-09T07:44:35.367Z",
"dateUpdated": "2026-08-05T12:31:42.384Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68405 (GCVE-0-2026-68405)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
ieee80211_do_stop() removes AP_VLAN packets from the parent AP
ps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then
calls ieee80211_free_txskb() before dropping the lock.
ieee80211_free_txskb() is not just a passive SKB release. For SKBs with
TX status state it can report a dropped frame through cfg80211/nl80211,
and that path can reach netlink tap transmit. This is the same reason
the pending queue cleanup in ieee80211_do_stop() already unlinks SKBs
under the queue lock and frees them after IRQ state is restored.
The buggy scenario involves two paths, with each column showing the
order within that path:
AP_VLAN management TX: AP_VLAN stop:
1. attach ACK-status state 1. clear the running state
2. queue a multicast SKB on 2. take ps->bc_buf.lock with IRQs
parent ps->bc_buf disabled
3. unlink the AP_VLAN SKB
4. call ieee80211_free_txskb()
Unlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock,
but move them to a local free queue. Drop the lock and restore IRQ state
before calling ieee80211_free_txskb().
WARNING: kernel/softirq.c:430 at __local_bh_enable_ip
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/iface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0d2619e708e2ef02ba1c91642ea261d3f19d8f9a",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "659a81b62a61440b85e02c09903be861ae7679e5",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "aa01ef0ebbc3289154229ef58e65baf289eb9789",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "962f755a47d7ec3bbf6c709697d7f4c5f798441d",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "a424985c3ef2a87ce6057a853e18d0c441a86be8",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "4b8abf43bf34791c99d99dc3be13f897adefc461",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "f3858d5b1432098c1936e03d6e03dd0e33facf60",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/iface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"lessThan": "3.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock\n\nieee80211_do_stop() removes AP_VLAN packets from the parent AP\nps-\u003ebc_buf while holding ps-\u003ebc_buf.lock with IRQs disabled. It then\ncalls ieee80211_free_txskb() before dropping the lock.\n\nieee80211_free_txskb() is not just a passive SKB release. For SKBs with\nTX status state it can report a dropped frame through cfg80211/nl80211,\nand that path can reach netlink tap transmit. This is the same reason\nthe pending queue cleanup in ieee80211_do_stop() already unlinks SKBs\nunder the queue lock and frees them after IRQ state is restored.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nAP_VLAN management TX: AP_VLAN stop:\n1. attach ACK-status state 1. clear the running state\n2. queue a multicast SKB on 2. take ps-\u003ebc_buf.lock with IRQs\n parent ps-\u003ebc_buf disabled\n 3. unlink the AP_VLAN SKB\n 4. call ieee80211_free_txskb()\n\nUnlink matching AP_VLAN SKBs from ps-\u003ebc_buf under the existing lock,\nbut move them to a local free queue. Drop the lock and restore IRQ state\nbefore calling ieee80211_free_txskb().\n\nWARNING: kernel/softirq.c:430 at __local_bh_enable_ip"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:57.265Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0d2619e708e2ef02ba1c91642ea261d3f19d8f9a"
},
{
"url": "https://git.kernel.org/stable/c/659a81b62a61440b85e02c09903be861ae7679e5"
},
{
"url": "https://git.kernel.org/stable/c/aa01ef0ebbc3289154229ef58e65baf289eb9789"
},
{
"url": "https://git.kernel.org/stable/c/be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef"
},
{
"url": "https://git.kernel.org/stable/c/962f755a47d7ec3bbf6c709697d7f4c5f798441d"
},
{
"url": "https://git.kernel.org/stable/c/a424985c3ef2a87ce6057a853e18d0c441a86be8"
},
{
"url": "https://git.kernel.org/stable/c/4b8abf43bf34791c99d99dc3be13f897adefc461"
},
{
"url": "https://git.kernel.org/stable/c/f3858d5b1432098c1936e03d6e03dd0e33facf60"
}
],
"title": "wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68405",
"datePublished": "2026-08-10T12:04:25.241Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:34:57.265Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68329 (GCVE-0-2026-68329)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()
need_sync is a per-IOMMU flag shared by all domains and devices behind
that IOMMU. It is set whenever a command is queued with sync == true and
cleared when a completion-wait (CWAIT) command is queued. However, a
cleared need_sync only means that a covering CWAIT has been queued, not
that all previously queued commands have actually completed in hardware.
iommu_completion_wait() read need_sync locklessly and returned early
when it was false. This breaks the "block until all previously queued
commands have completed" contract in a multi-CPU scenario:
CPU2: queue inv-B => need_sync = true
CPU1: queue CWAIT(N); need_sync = false; then wait_on_sem(N)
CPU2: read need_sync == false => return 0 (no wait!)
CPU2 returns without waiting for any sequence number even though its
inv-B may not have completed yet (CWAIT(N), queued after inv-B, has not
been signaled). CPU2 then proceeds to, for example, free page-table
pages while the IOMMU can still walk stale translations, opening a
use-after-free window. This is a logical race in the meaning of the
flag, not a memory-visibility issue, so barriers alone do not help.
Fix it without losing the optimization of avoiding redundant CWAIT
commands: take iommu->lock before testing need_sync, and when it is
false do not return early but wait for the last allocated sequence
number (cmd_sem_val). Since need_sync == false implies no sync command
was queued after the last CWAIT, that CWAIT is FIFO-ordered after every
not-yet-completed command, so waiting for its sequence number guarantees
all prior commands (possibly queued by another CPU) have completed. The
common path with pending work is unchanged and no extra hardware command
is issued.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iommu/amd/iommu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ab7faf5a172ebfdc423ebb3eea4d472740de82f9",
"status": "affected",
"version": "815b33fdc279d34ab40a8bfe1866623a4cc5669b",
"versionType": "git"
},
{
"lessThan": "93494bd446396c257fb589f59894577e96e406e2",
"status": "affected",
"version": "815b33fdc279d34ab40a8bfe1866623a4cc5669b",
"versionType": "git"
},
{
"lessThan": "d053eb7e09e10cbdca3fca8b35c1017d438091b2",
"status": "affected",
"version": "815b33fdc279d34ab40a8bfe1866623a4cc5669b",
"versionType": "git"
},
{
"lessThan": "02f8cefa2ad95ea3754f0cfd6fbae7f866202ccb",
"status": "affected",
"version": "815b33fdc279d34ab40a8bfe1866623a4cc5669b",
"versionType": "git"
},
{
"lessThan": "1e75a8255f11c81fb07e81e5029cfd75804350a0",
"status": "affected",
"version": "815b33fdc279d34ab40a8bfe1866623a4cc5669b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iommu/amd/iommu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.0"
},
{
"lessThan": "3.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Wait for completion instead of returning early in iommu_completion_wait()\n\nneed_sync is a per-IOMMU flag shared by all domains and devices behind\nthat IOMMU. It is set whenever a command is queued with sync == true and\ncleared when a completion-wait (CWAIT) command is queued. However, a\ncleared need_sync only means that a covering CWAIT has been queued, not\nthat all previously queued commands have actually completed in hardware.\n\niommu_completion_wait() read need_sync locklessly and returned early\nwhen it was false. This breaks the \"block until all previously queued\ncommands have completed\" contract in a multi-CPU scenario:\n\n CPU2: queue inv-B =\u003e need_sync = true\n CPU1: queue CWAIT(N); need_sync = false; then wait_on_sem(N)\n CPU2: read need_sync == false =\u003e return 0 (no wait!)\n\nCPU2 returns without waiting for any sequence number even though its\ninv-B may not have completed yet (CWAIT(N), queued after inv-B, has not\nbeen signaled). CPU2 then proceeds to, for example, free page-table\npages while the IOMMU can still walk stale translations, opening a\nuse-after-free window. This is a logical race in the meaning of the\nflag, not a memory-visibility issue, so barriers alone do not help.\n\nFix it without losing the optimization of avoiding redundant CWAIT\ncommands: take iommu-\u003elock before testing need_sync, and when it is\nfalse do not return early but wait for the last allocated sequence\nnumber (cmd_sem_val). Since need_sync == false implies no sync command\nwas queued after the last CWAIT, that CWAIT is FIFO-ordered after every\nnot-yet-completed command, so waiting for its sequence number guarantees\nall prior commands (possibly queued by another CPU) have completed. The\ncommon path with pending work is unchanged and no extra hardware command\nis issued."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The racy `iommu_completion_wait()` is reached through local DMA map/unmap activity \u2014 iommu-dma unmap paths, VFIO/IOMMUFD unmap ioctls, and domain attach/detach \u2014 all driven from the local system rather than from network input.\nAC:L - The attacker drives both sides of the race by issuing concurrent unmap/flush operations on multiple CPUs against the same IOMMU, and can retry indefinitely; each hit frees page-table pages while translations are still live, so no condition outside the attacker\u0027s influence is required.\nPR:L - An unprivileged local user can generate the concurrent IOMMU invalidation traffic needed via ordinary parallel I/O through DMA-API device paths; no root or capability in the init namespace is required, and privileged VFIO users are only one of several entry points.\nUI:N - The race is triggered purely by the attacker\u0027s own concurrent unmap/flush workload; no victim action such as mounting a filesystem or opening a file is needed.\nS:C - The failure defeats IOMMU isolation itself: page-table pages are freed and reused while the IOMMU can still walk them and stale IOTLB entries persist, so a device (including one assigned to a guest or an external peripheral) retains DMA access to host memory outside its domain, crossing the DMA/IOMMU security boundary.\nC:H - Stale translations and use-after-free page tables let a device read host memory that was unmapped, freed, and reallocated to unrelated kernel or user data, yielding effectively arbitrary memory disclosure across the IOMMU boundary.\nI:H - The same stale translations permit device DMA writes into freed and reallocated pages, including page-table pages the IOMMU still walks, giving an arbitrary kernel-memory write primitive usable for control-flow hijacking and privilege escalation.\nA:H - Use-after-free of page-table pages and DMA into reallocated memory corrupt kernel structures and generate IOMMU I/O page faults, leading to oops or panic and full loss of availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:27.689Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ab7faf5a172ebfdc423ebb3eea4d472740de82f9"
},
{
"url": "https://git.kernel.org/stable/c/93494bd446396c257fb589f59894577e96e406e2"
},
{
"url": "https://git.kernel.org/stable/c/d053eb7e09e10cbdca3fca8b35c1017d438091b2"
},
{
"url": "https://git.kernel.org/stable/c/02f8cefa2ad95ea3754f0cfd6fbae7f866202ccb"
},
{
"url": "https://git.kernel.org/stable/c/1e75a8255f11c81fb07e81e5029cfd75804350a0"
}
],
"title": "iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68329",
"datePublished": "2026-08-10T12:03:05.526Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-17T05:03:27.689Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64126 (GCVE-0-2026-64126)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: validate Add Extended Advertising Data length
MGMT_OP_ADD_EXT_ADV_DATA is registered as a variable-length command,
with MGMT_ADD_EXT_ADV_DATA_SIZE as the fixed header size. The handler
then uses cp->adv_data_len and cp->scan_rsp_len to validate and copy
cp->data, but it never checks that those bytes are part of the mgmt
command payload.
A short command can therefore make add_ext_adv_data() pass an
out-of-bounds pointer into tlv_data_is_valid(). If the bytes beyond
the command buffer are addressable, they can also be copied into the
advertising instance as scan response data, where the caller can read
them back via MGMT_OP_GET_ADV_INSTANCE. The trigger requires
CAP_NET_ADMIN in the initial user namespace; KASAN reports an 8-byte
slab-out-of-bounds read.
Reject commands whose length does not match the fixed header plus both
advertising data lengths before parsing cp->data.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 12410572833a283ce92fcf9679ca8a2f372097ee Version: 12410572833a283ce92fcf9679ca8a2f372097ee Version: 12410572833a283ce92fcf9679ca8a2f372097ee Version: 12410572833a283ce92fcf9679ca8a2f372097ee Version: 12410572833a283ce92fcf9679ca8a2f372097ee Version: 12410572833a283ce92fcf9679ca8a2f372097ee Version: 12410572833a283ce92fcf9679ca8a2f372097ee |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0d5104390b445e7bd664ad583837e4c04d892c9d",
"status": "affected",
"version": "12410572833a283ce92fcf9679ca8a2f372097ee",
"versionType": "git"
},
{
"lessThan": "14b01b9cba04e6ce82825f68fc4c4322fa4ffa43",
"status": "affected",
"version": "12410572833a283ce92fcf9679ca8a2f372097ee",
"versionType": "git"
},
{
"lessThan": "a143ce77a5292f2c9285137433d879ce71d190a7",
"status": "affected",
"version": "12410572833a283ce92fcf9679ca8a2f372097ee",
"versionType": "git"
},
{
"lessThan": "a6c75a3fad226ccbd8ef9110dee87c92c299f2ab",
"status": "affected",
"version": "12410572833a283ce92fcf9679ca8a2f372097ee",
"versionType": "git"
},
{
"lessThan": "f1febe93ef075314615f970a87681d9ab86691d1",
"status": "affected",
"version": "12410572833a283ce92fcf9679ca8a2f372097ee",
"versionType": "git"
},
{
"lessThan": "0bc1a5a69f541859293d79db72bd7854ac48df51",
"status": "affected",
"version": "12410572833a283ce92fcf9679ca8a2f372097ee",
"versionType": "git"
},
{
"lessThan": "d3f7d17960ed50df3a6709c5158caff989c8c905",
"status": "affected",
"version": "12410572833a283ce92fcf9679ca8a2f372097ee",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: validate Add Extended Advertising Data length\n\nMGMT_OP_ADD_EXT_ADV_DATA is registered as a variable-length command,\nwith MGMT_ADD_EXT_ADV_DATA_SIZE as the fixed header size. The handler\nthen uses cp-\u003eadv_data_len and cp-\u003escan_rsp_len to validate and copy\ncp-\u003edata, but it never checks that those bytes are part of the mgmt\ncommand payload.\n\nA short command can therefore make add_ext_adv_data() pass an\nout-of-bounds pointer into tlv_data_is_valid(). If the bytes beyond\nthe command buffer are addressable, they can also be copied into the\nadvertising instance as scan response data, where the caller can read\nthem back via MGMT_OP_GET_ADV_INSTANCE. The trigger requires\nCAP_NET_ADMIN in the initial user namespace; KASAN reports an 8-byte\nslab-out-of-bounds read.\n\nReject commands whose length does not match the fixed header plus both\nadvertising data lengths before parsing cp-\u003edata."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through a local Bluetooth MGMT socket (AF_BLUETOOTH, HCI_CHANNEL_CONTROL) via sendmsg(), not from remote Bluetooth air traffic or network protocols.\nAC:L - An attacker fully controls the malformed MGMT command and length fields and can retry reliably; no race or victim-dependent timing is required to trigger the out-of-bounds read and copy.\nPR:L - Exploitation requires CAP_NET_ADMIN to obtain an HCI_SOCK_TRUSTED MGMT socket, which is reachable by an unprivileged user via user namespaces (e.g. unshare with CAP_NET_ADMIN) on the CONTROL-channel bind path.\nUI:N - No victim interaction is required; the attacker triggers the flaw directly by sending a crafted MGMT_OP_ADD_EXT_ADV_DATA command.\nS:U - Impact is confined to kernel memory disclosure and modification of Bluetooth advertising state within the same kernel security boundary, with no VM escape or cross-authority boundary crossing.\nC:H - A short command causes slab out-of-bounds reads (KASAN-reported) via tlv_data_is_valid(), and addressable bytes beyond the command buffer can be copied into scan response data and potentially exfiltrated over BLE advertising.\nI:H - The out-of-bounds pointer is used in memcpy() into kernel advertising structures, constituting kernel memory corruption with attacker-influenced content that can alter system-controlled Bluetooth data.\nA:L - While the primary impact is information disclosure, out-of-bounds kernel memory access can cause oopses or instability on some layouts; when uncertain, availability impact is rated above none."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:32.975Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0d5104390b445e7bd664ad583837e4c04d892c9d"
},
{
"url": "https://git.kernel.org/stable/c/14b01b9cba04e6ce82825f68fc4c4322fa4ffa43"
},
{
"url": "https://git.kernel.org/stable/c/a143ce77a5292f2c9285137433d879ce71d190a7"
},
{
"url": "https://git.kernel.org/stable/c/a6c75a3fad226ccbd8ef9110dee87c92c299f2ab"
},
{
"url": "https://git.kernel.org/stable/c/f1febe93ef075314615f970a87681d9ab86691d1"
},
{
"url": "https://git.kernel.org/stable/c/0bc1a5a69f541859293d79db72bd7854ac48df51"
},
{
"url": "https://git.kernel.org/stable/c/d3f7d17960ed50df3a6709c5158caff989c8c905"
}
],
"title": "Bluetooth: MGMT: validate Add Extended Advertising Data length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64126",
"datePublished": "2026-07-19T15:40:23.276Z",
"dateReserved": "2026-07-19T07:54:57.036Z",
"dateUpdated": "2026-08-05T12:39:32.975Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68302 (GCVE-0-2026-68302)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
amt: re-read skb header pointers after every pull
Several AMT receive and transmit paths cache a pointer into the skb head
(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call
a helper that can reallocate that head before the cached pointer is used
again. pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),
iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all
free the old head and move the data, so a pointer taken before the call
dangles afterwards and the later access is a use-after-free of the freed
head.
The affected sites are:
amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads
iph->saddr.
amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/
ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.
amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),
then writes the L2 header.
amt_membership_query_handler() caches the AMT header, the outer and
inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several
pulls, then reads and writes them.
amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache
ip_hdr()/ipv6_hdr() and the current group record and read the record
count from the report header inside the record loop, across the
*_mc_may_pull() calls.
amt_update_handler() caches ip_hdr() and the AMT membership-update
header before pskb_may_pull(), iptunnel_pull_header(),
ip_mc_check_igmp() and the report handler, then reads iph->daddr and
amtmu->nonce / amtmu->response_mac.
Fix each site by either snapshotting the scalar that is used after the
pull before the first pull runs, or re-deriving the header pointer from
the skb after the last pull that can move the head. Values that are
stable across the pull (source and group address, the response MAC and
nonce, the record count, the outer source MAC) are snapshotted; pointers
that are written through or read repeatedly are re-derived.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/amt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "37ff890f9c18dfbcf57e17199901d4fd1e4c174e",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "9005b221cb1f9c3c1a2ef656fb0e8fa80c0a187e",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "7746d588d42a4ac0117b68ed8e9b22a9da53dfb7",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "ca0e8b661957f777591efe874cd9d9a63619cd99",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "7f48e3ddad8e97545b25788b8203b3a539df1621",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "3656a79f94c471827a08f2cacce5f94ad5e52c24",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/amt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\namt: re-read skb header pointers after every pull\n\nSeveral AMT receive and transmit paths cache a pointer into the skb head\n(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call\na helper that can reallocate that head before the cached pointer is used\nagain. pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),\niptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all\nfree the old head and move the data, so a pointer taken before the call\ndangles afterwards and the later access is a use-after-free of the freed\nhead.\n\nThe affected sites are:\n\n amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads\n iph-\u003esaddr.\n\n amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/\n ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.\n\n amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),\n then writes the L2 header.\n\n amt_membership_query_handler() caches the AMT header, the outer and\n inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several\n pulls, then reads and writes them.\n\n amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache\n ip_hdr()/ipv6_hdr() and the current group record and read the record\n count from the report header inside the record loop, across the\n *_mc_may_pull() calls.\n\n amt_update_handler() caches ip_hdr() and the AMT membership-update\n header before pskb_may_pull(), iptunnel_pull_header(),\n ip_mc_check_igmp() and the report handler, then reads iph-\u003edaddr and\n amtmu-\u003enonce / amtmu-\u003eresponse_mac.\n\nFix each site by either snapshotting the scalar that is used after the\npull before the first pull runs, or re-deriving the header pointer from\nthe skb after the last pull that can move the head. Values that are\nstable across the pull (source and group address, the response MAC and\nnonce, the record count, the outer source MAC) are snapshotted; pointers\nthat are written through or read repeatedly are re-derived."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - AMT is a routable UDP tunnel (port 2268); all affected handlers run from amt_rcv(), the UDP encap receive callback, on packets from arbitrary remote hosts across the internet. No same-segment requirement exists.\nAC:L - The attacker chooses the packet sizes and fragmentation that make the skb non-linear or cloned, so the pskb_may_pull()/iptunnel_pull_header()/ip_mc_check_igmp() calls deterministically reallocate the skb head and strand the cached pointers; no race or uncontrollable state is involved.\nPR:N - AMT has no authentication: amt_request_handler() creates a tunnel for any source IP and returns the nonce/response MAC to the sender, so an unauthenticated remote host can complete the handshake and then reach the vulnerable update/report paths; gateway paths need only a spoofed relay source address.\nUI:N - Exploitation is entirely driven by inbound UDP packets processed in softirq context; no local user action or interaction is required on the target relay or gateway.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Stale header pointers are read after the head is freed, so freed heap contents are consumed as source/group addresses and record counts, and are copied into the destination MAC of frames delivered up the stack, leaking reallocated kernel memory to the attacker; UAF reads generally enable broader disclosure.\nI:H - amt_multicast_data_handler() and amt_membership_query_handler() write through the dangling pointers (eth-\u003eh_proto, ip_eth_mc_map()/ipv6_eth_mc_map() into eth-\u003eh_dest, ether_addr_copy of h_source), giving an attacker-influenced heap write into freed and likely reallocated memory, a classic control-flow hijack primitive.\nA:H - Use-after-free reads and writes on a freed skb head corrupt the slab and readily cause KASAN splats, oopses, or kernel panic, and the packets triggering it can be sent repeatedly by an unauthenticated remote attacker."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:55.916Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/37ff890f9c18dfbcf57e17199901d4fd1e4c174e"
},
{
"url": "https://git.kernel.org/stable/c/9005b221cb1f9c3c1a2ef656fb0e8fa80c0a187e"
},
{
"url": "https://git.kernel.org/stable/c/7746d588d42a4ac0117b68ed8e9b22a9da53dfb7"
},
{
"url": "https://git.kernel.org/stable/c/ca0e8b661957f777591efe874cd9d9a63619cd99"
},
{
"url": "https://git.kernel.org/stable/c/7f48e3ddad8e97545b25788b8203b3a539df1621"
},
{
"url": "https://git.kernel.org/stable/c/3656a79f94c471827a08f2cacce5f94ad5e52c24"
}
],
"title": "amt: re-read skb header pointers after every pull",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68302",
"datePublished": "2026-08-10T12:02:36.313Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:32:55.916Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64118 (GCVE-0-2026-64118)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
qed: fix double free in qed_cxt_tables_alloc()
If one of the later PF or VF CID bitmap allocations fails,
qed_cid_map_alloc() jumps to cid_map_fail and frees the previously
allocated CID bitmaps before returning an error. qed_cxt_tables_alloc()
then calls qed_cxt_mngr_free(), which invokes qed_cid_map_free()
again.
Fix this by setting each CID bitmap pointer to NULL after bitmap_free()
to avoid double free.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1-rc3.
Runtime reproduction was not attempted because exercising the failing
allocation path requires device-specific setup.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fe56b9e6a8d957d6a20729d626027f800c17a2da Version: fe56b9e6a8d957d6a20729d626027f800c17a2da Version: fe56b9e6a8d957d6a20729d626027f800c17a2da Version: fe56b9e6a8d957d6a20729d626027f800c17a2da Version: fe56b9e6a8d957d6a20729d626027f800c17a2da Version: fe56b9e6a8d957d6a20729d626027f800c17a2da Version: fe56b9e6a8d957d6a20729d626027f800c17a2da Version: fe56b9e6a8d957d6a20729d626027f800c17a2da |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/qlogic/qed/qed_cxt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9fe030719bd083b766602692ee96c8c985798e3c",
"status": "affected",
"version": "fe56b9e6a8d957d6a20729d626027f800c17a2da",
"versionType": "git"
},
{
"lessThan": "06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227",
"status": "affected",
"version": "fe56b9e6a8d957d6a20729d626027f800c17a2da",
"versionType": "git"
},
{
"lessThan": "8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb",
"status": "affected",
"version": "fe56b9e6a8d957d6a20729d626027f800c17a2da",
"versionType": "git"
},
{
"lessThan": "3904b993cc17ec5d7c5d3b57dbd0b775dafb9684",
"status": "affected",
"version": "fe56b9e6a8d957d6a20729d626027f800c17a2da",
"versionType": "git"
},
{
"lessThan": "bdf678a273cadbccc347f331ae2e93ff4d14834c",
"status": "affected",
"version": "fe56b9e6a8d957d6a20729d626027f800c17a2da",
"versionType": "git"
},
{
"lessThan": "0e47fc1c9181ae029e0e35a865cbf2adcbae626c",
"status": "affected",
"version": "fe56b9e6a8d957d6a20729d626027f800c17a2da",
"versionType": "git"
},
{
"lessThan": "a04c207f0801abdd23a169b5f902a9845059a65a",
"status": "affected",
"version": "fe56b9e6a8d957d6a20729d626027f800c17a2da",
"versionType": "git"
},
{
"lessThan": "2bccfb8476ca5f3548afbd623dc7a6980d4e77de",
"status": "affected",
"version": "fe56b9e6a8d957d6a20729d626027f800c17a2da",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/qlogic/qed/qed_cxt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.4"
},
{
"lessThan": "4.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nqed: fix double free in qed_cxt_tables_alloc()\n\nIf one of the later PF or VF CID bitmap allocations fails,\nqed_cid_map_alloc() jumps to cid_map_fail and frees the previously\nallocated CID bitmaps before returning an error. qed_cxt_tables_alloc()\nthen calls qed_cxt_mngr_free(), which invokes qed_cid_map_free()\nagain.\n\nFix this by setting each CID bitmap pointer to NULL after bitmap_free()\nto avoid double free.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc3.\n\nRuntime reproduction was not attempted because exercising the failing\nallocation path requires device-specific setup."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code runs only during PF driver resource initialization (probe or firmware-initiated recovery), reached via local kernel driver bring-up paths rather than network packet processing or remote protocol handlers.\nAC:L - An attacker who can influence system memory pressure (e.g., via local memory exhaustion) can reliably force `bitmap_zalloc()` failures during the multi-step CID bitmap allocation loop, and can also time this with firmware recovery reprobes that re-enter `qed_resc_alloc()`.\nPR:N - No local account or capability is strictly required if a remote attacker can induce firmware process-kill recovery on an internet-facing QED host, causing automatic re-execution of `qed_resc_alloc()` where post-incident memory pressure can trigger the failing allocation path.\nUI:N - Exploitation does not require any victim user action such as opening files or mounting filesystems; driver recovery and re-allocation occur automatically in kernel context once the error/recovery conditions are met.\nS:U - Impact is confined to kernel heap corruption and potential privilege escalation within the same kernel security boundary, not a cross-authority escape such as VM breakout or IOMMU bypass.\nC:H - A double-free of kmalloc-allocated CID bitmap objects corrupts the kernel slab allocator state, which is classically leverageable for arbitrary kernel memory disclosure through heap manipulation primitives.\nI:H - Slab double-free is a standard heap corruption primitive that can be developed into arbitrary kernel writes and control-flow hijacking, not merely a bounded or cosmetic modification.\nA:H - Double-free during driver initialization can cause immediate kernel oops/panic from allocator corruption, and repeated recovery attempts on production QED hardware can produce sustained denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:27.598Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9fe030719bd083b766602692ee96c8c985798e3c"
},
{
"url": "https://git.kernel.org/stable/c/06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227"
},
{
"url": "https://git.kernel.org/stable/c/8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb"
},
{
"url": "https://git.kernel.org/stable/c/3904b993cc17ec5d7c5d3b57dbd0b775dafb9684"
},
{
"url": "https://git.kernel.org/stable/c/bdf678a273cadbccc347f331ae2e93ff4d14834c"
},
{
"url": "https://git.kernel.org/stable/c/0e47fc1c9181ae029e0e35a865cbf2adcbae626c"
},
{
"url": "https://git.kernel.org/stable/c/a04c207f0801abdd23a169b5f902a9845059a65a"
},
{
"url": "https://git.kernel.org/stable/c/2bccfb8476ca5f3548afbd623dc7a6980d4e77de"
}
],
"title": "qed: fix double free in qed_cxt_tables_alloc()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64118",
"datePublished": "2026-07-19T15:40:17.643Z",
"dateReserved": "2026-07-19T07:54:57.035Z",
"dateUpdated": "2026-08-05T12:39:27.598Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74345 (GCVE-0-2026-74345)
Vulnerability from cvelistv5
Published
2026-08-15 05:58
Modified
2026-08-17 05:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Fix endpoint/socket association handling
Disassociating a socket from an endpoint via siw_socket_disassoc() may
release the last reference on that endpoint and free it. Therefore, don't
clear the endpoints socket pointer after calling that function, but
within.
This fixes a:
BUG: KASAN: slab-use-after-free in siw_cm_work_handler (drivers/infiniband/sw/siw/siw_cm.c:1053 drivers/infiniband/sw/siw/siw_cm.c:1075)
which occurred after processing a malformed MPA request during connection
establishment, causing the new endpoint to be closed.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_cm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b28d513393f81e2de00f82970487a9d001557e4e",
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"versionType": "git"
},
{
"lessThan": "f6183983ce1ff254d629a333739082b39d7c5eb6",
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"versionType": "git"
},
{
"lessThan": "b6cf763eee0a932792bef64ceaca568d324192fc",
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"versionType": "git"
},
{
"lessThan": "ea4f6f6c53577fb3f05dbd78b15e586772d49831",
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_cm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Fix endpoint/socket association handling\n\nDisassociating a socket from an endpoint via siw_socket_disassoc() may\nrelease the last reference on that endpoint and free it. Therefore, don\u0027t\nclear the endpoints socket pointer after calling that function, but\nwithin.\n\nThis fixes a:\n\n BUG: KASAN: slab-use-after-free in siw_cm_work_handler (drivers/infiniband/sw/siw/siw_cm.c:1053 drivers/infiniband/sw/siw/siw_cm.c:1075)\n\nwhich occurred after processing a malformed MPA request during connection\nestablishment, causing the new endpoint to be closed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit while processing attacker-supplied MPA/TCP data on an inbound SIW listener socket during connection establishment, which is a standard network protocol path analogous to other in-kernel TCP service handlers.\nAC:L - An attacker fully controls the TCP connection and malformed MPA request bytes that deterministically fail parsing and drive the endpoint teardown path where the refcount bug frees the cep before it is accessed again.\nPR:N - Exploitation requires only the ability to open a TCP connection to a host running an SIW RDMA listener; the MPA handshake is unauthenticated and occurs before any RDMA credentials or local privileges are established.\nUI:N - No end-user action is required at exploit time; the kernel processes the malicious inbound connection automatically once an administrator has started an RDMA listener service.\nS:U - Impact is confined to kernel memory corruption and potential host privilege escalation within the same kernel security authority, not a VM escape or cross-authority boundary such as guest-to-hypervisor.\nC:H - The vulnerability is a slab use-after-free on a freed siw_cep object; UAF on attacker-influenced connection teardown enables heap grooming and arbitrary kernel memory read primitives beyond a simple crash.\nI:H - Use-after-free of the connection endpoint structure in kernel heap can be leveraged for controlled writes and code execution via object reuse and function pointer/callback corruption, not merely data integrity of a single field.\nA:H - The bug was reproduced as a KASAN slab-use-after-free in siw_cm_work_handler during malformed MPA processing, which can cause kernel oops/panic and denial of service on the target host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:46:10.583Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b28d513393f81e2de00f82970487a9d001557e4e"
},
{
"url": "https://git.kernel.org/stable/c/f6183983ce1ff254d629a333739082b39d7c5eb6"
},
{
"url": "https://git.kernel.org/stable/c/b6cf763eee0a932792bef64ceaca568d324192fc"
},
{
"url": "https://git.kernel.org/stable/c/ea4f6f6c53577fb3f05dbd78b15e586772d49831"
}
],
"title": "RDMA/siw: Fix endpoint/socket association handling",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74345",
"datePublished": "2026-08-15T05:58:33.906Z",
"dateReserved": "2026-08-15T05:44:03.886Z",
"dateUpdated": "2026-08-17T05:46:10.583Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68093 (GCVE-0-2026-68093)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
If a vCPU stays scheduled out (or blocked) while the last pCPU it ran
on goes through a hotplug cycle (online->offline->online), and the vCPU
then resumes execution on the same pCPU, then it is possible for it to
run with an ASID that has now been assigned to a different vCPU,
resulting in stale TLB translations being used.
svm_enable_virtualization_cpu() resets asid_generation to 1 and sets
next_asid to max_asid + 1 on every CPU online event, including hotplug
cycles. Because next_asid starts beyond the pool boundary, the first
call to new_asid() after an online event always wraps the pool,
incrementing asid_generation to 2 and assigning ASIDs starting from
min_asid.
Consider two vCPUs from different VMs, vCPU-A pinned to CPU-X holding
asid_generation=2 and ASID=N from before the hotplug event:
1. CPU-X goes offline and back online: asid_generation resets to 1,
next_asid = max_asid + 1.
2. One or more vCPUs migrate to CPU-X and call new_asid(), wrapping
the pool and consuming ASIDs starting from min_asid. Eventually
vCPU-B from a different VM is assigned asid_generation=2, ASID=N
— the same ASID that vCPU-A held before the hotplug.
3. vCPU-A enters pre_svm_run() on CPU-X: current_vmcb->cpu is
unchanged so the migration branch is skipped. Its saved
asid_generation=2 matches sd->asid_generation=2, so the generation
check silently passes and vCPU-A continues running with ASID=N —
the same ASID just freshly assigned to vCPU-B.
Both vCPUs from different VMs now run on CPU-X with the same ASID,
causing them to share NPT TLB entries and producing stale translations.
The collision manifests as a KVM internal error (Suberror: 1, emulation
failure). The NPT page fault reports a faulting GPA far outside the
VM's physical memory range — a sign of stale TLB translations being
used. KVM falls back to instruction emulation, which fails on
FPU/XSave instructions (XRSTOR, STMXCSR) that the emulator does not
implement.
Fix this by incrementing asid_generation instead of resetting it to 1
in svm_enable_virtualization_cpu(). On module load, asid_generation
starts at 0 (memset) and the increment produces 1, identical to the
old behaviour. On subsequent hotplug cycles the generation advances
beyond any value a vCPU previously observed on this CPU, so the
generation check in pre_svm_run() reliably forces new_asid() on every
vCPU after every hotplug cycle.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/svm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2028b81321dc757b6875b99c10d908e349c141e2",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "60283726f2845bd78b95efbd0e50b93944780477",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "7508916b4b55d6f5ecc68cd09774dabd3a6b4440",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "0f33b1c457c2199ed130b92cc2ff363a3f7b9415",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "6b542d116acecb83a1ca34e8eace304cff6a4ec9",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "25f744ffa0c8e799e06250ce2e618367b166b0d4",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/svm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.21"
},
{
"lessThan": "2.6.21",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.21",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug\n\nIf a vCPU stays scheduled out (or blocked) while the last pCPU it ran\non goes through a hotplug cycle (online-\u003eoffline-\u003eonline), and the vCPU\nthen resumes execution on the same pCPU, then it is possible for it to\nrun with an ASID that has now been assigned to a different vCPU,\nresulting in stale TLB translations being used.\n\nsvm_enable_virtualization_cpu() resets asid_generation to 1 and sets\nnext_asid to max_asid + 1 on every CPU online event, including hotplug\ncycles. Because next_asid starts beyond the pool boundary, the first\ncall to new_asid() after an online event always wraps the pool,\nincrementing asid_generation to 2 and assigning ASIDs starting from\nmin_asid.\n\nConsider two vCPUs from different VMs, vCPU-A pinned to CPU-X holding\nasid_generation=2 and ASID=N from before the hotplug event:\n\n 1. CPU-X goes offline and back online: asid_generation resets to 1,\n next_asid = max_asid + 1.\n\n 2. One or more vCPUs migrate to CPU-X and call new_asid(), wrapping\n the pool and consuming ASIDs starting from min_asid. Eventually\n vCPU-B from a different VM is assigned asid_generation=2, ASID=N\n \u2014 the same ASID that vCPU-A held before the hotplug.\n\n 3. vCPU-A enters pre_svm_run() on CPU-X: current_vmcb-\u003ecpu is\n unchanged so the migration branch is skipped. Its saved\n asid_generation=2 matches sd-\u003easid_generation=2, so the generation\n check silently passes and vCPU-A continues running with ASID=N \u2014\n the same ASID just freshly assigned to vCPU-B.\n\nBoth vCPUs from different VMs now run on CPU-X with the same ASID,\ncausing them to share NPT TLB entries and producing stale translations.\n\nThe collision manifests as a KVM internal error (Suberror: 1, emulation\nfailure). The NPT page fault reports a faulting GPA far outside the\nVM\u0027s physical memory range \u2014 a sign of stale TLB translations being\nused. KVM falls back to instruction emulation, which fails on\nFPU/XSave instructions (XRSTOR, STMXCSR) that the emulator does not\nimplement.\n\nFix this by incrementing asid_generation instead of resetting it to 1\nin svm_enable_virtualization_cpu(). On module load, asid_generation\nstarts at 0 (memset) and the increment produces 1, identical to the\nold behaviour. On subsequent hotplug cycles the generation advances\nbeyond any value a vCPU previously observed on this CPU, so the\ngeneration check in pre_svm_run() reliably forces new_asid() on every\nvCPU after every hotplug cycle."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:15.060Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2028b81321dc757b6875b99c10d908e349c141e2"
},
{
"url": "https://git.kernel.org/stable/c/60283726f2845bd78b95efbd0e50b93944780477"
},
{
"url": "https://git.kernel.org/stable/c/7508916b4b55d6f5ecc68cd09774dabd3a6b4440"
},
{
"url": "https://git.kernel.org/stable/c/0f33b1c457c2199ed130b92cc2ff363a3f7b9415"
},
{
"url": "https://git.kernel.org/stable/c/6b542d116acecb83a1ca34e8eace304cff6a4ec9"
},
{
"url": "https://git.kernel.org/stable/c/25f744ffa0c8e799e06250ce2e618367b166b0d4"
}
],
"title": "KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68093",
"datePublished": "2026-08-10T11:58:05.933Z",
"dateReserved": "2026-07-30T09:28:09.367Z",
"dateUpdated": "2026-08-19T16:29:15.060Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68132 (GCVE-0-2026-68132)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
super: fix emergency thaw deadlock on frozen block devices
do_thaw_all_callback() calls bdev_thaw() while holding sb->s_umount
exclusively. If the block device was frozen via bdev_freeze() dropping
the last block layer freeze reference calls fs_bdev_thaw() which
reacquires s_umount:
do_thaw_all_callback(sb)
super_lock_excl(sb) # holds sb->s_umount
bdev_thaw(sb->s_bdev)
mutex_lock(&bdev->bd_fsfreeze_mutex)
# bd_fsfreeze_count drops 1 -> 0
bd_holder_ops->thaw == fs_bdev_thaw
get_bdev_super(bdev)
bdev_super_lock(bdev, true)
super_lock(sb, true)
down_write(&sb->s_umount) # same task: deadlock
The emergency thaw worker deadlocks against itself holding both
s_umount and bd_fsfreeze_mutex. That fscks any subsequent unmount,
freeze, or thaw of that filesystem and block device.
[ 81.878470] sysrq: Show Blocked State
[ 81.880140] task:kworker/0:1 state:D stack:0 pid:11 tgid:11 ppid:2 task_flags:0x4208060 flags:0x00080000
[ 81.884876] Workqueue: events do_thaw_all
[ 81.886656] Call Trace:
[ 81.887759] <TASK>
[ 81.888763] __schedule+0x579/0x1420
[ 81.890372] schedule+0x3a/0x100
[ 81.891794] schedule_preempt_disabled+0x15/0x30
[ 81.893848] rwsem_down_write_slowpath+0x1ea/0x900
[ 81.895191] ? __pfx_do_thaw_all_callback+0x10/0x10
[ 81.896528] down_write+0xbd/0xc0
[ 81.897505] super_lock+0x91/0x180
[ 81.898457] ? __mutex_lock+0xa99/0x1140
[ 81.900748] ? __mutex_unlock_slowpath+0x1f/0x400
[ 81.902069] bdev_super_lock+0x5b/0x150
[ 81.903132] get_bdev_super+0x10/0x60
[ 81.904042] fs_bdev_thaw+0x23/0xf0
[ 81.904755] bdev_thaw+0x82/0x100
[ 81.905484] do_thaw_all_callback+0x2c/0x50
[ 81.906298] __iterate_supers+0x5d/0x130
[ 81.907067] do_thaw_all+0x20/0x40
[ 81.907739] process_one_work+0x206/0x5e0
[ 81.908545] worker_thread+0x1e2/0x3c0
[ 81.909339] ? __pfx_worker_thread+0x10/0x10
[ 81.910171] kthread+0xf4/0x130
[ 81.910799] ? __pfx_kthread+0x10/0x10
[ 81.911528] ret_from_fork+0x2e2/0x3b0
[ 81.912259] ? __pfx_kthread+0x10/0x10
[ 81.913010] ret_from_fork_asm+0x1a/0x30
[ 81.913806] </TASK>
bdev_super_lock() even documents the violated requirement with
lockdep_assert_not_held(&sb->s_umount).
Acquiring bd_fsfreeze_mutex under s_umount also inverts the
bd_fsfreeze_mutex vs. s_umount ordering established by
bdev_{freeze,thaw}() and can thus ABBA against a concurrent block-layer
freeze even when the recursive path isn't hit.
Fix this by not holding s_umount around the bdev_thaw() loop at all. Pin
the superblock with an active reference instead as
filesystems_freeze_callback() does. The active reference keeps the
superblock from being shut down and so ->s_bdev stays valid without
holding s_umount. The block-layer-held freeze is dropped by
fs_bdev_thaw() with FREEZE_MAY_NEST | FREEZE_HOLDER_USERSPACE exactly as
a regular unfreeze would and thaw_super_locked() handles
filesystem-level freezes as before.
The emergency thaw path has deadlocked like this in one form or
another for a long long time but the current exclusively-held
shape dates back to commit [1] where thaw_bdev() already ended in
thaw_super() with s_umount held by do_thaw_all_callback().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/super.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "96248aeddde794227a49af1a332a1e21b3c15d56",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "c202aa03388fd1889b7aa4f7d677c49e22cd9700",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "2a1127c1c58b4f15a93f2fd56ff7c2c3d611d5c5",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "05536cad35f27b520d4b6f0e57c8cc5bfb6b0502",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "99719b5da9320ed344daee87d9c73d321a98f252",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "63d78b546eefc38ad9898dc839bfc94811ede547",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "4c483644d1a7709efe7d1be7dbf88cf4008a7864",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "749d7aa0377aae32af8c0a4ad43371e7bf830ab5",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/super.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsuper: fix emergency thaw deadlock on frozen block devices\n\ndo_thaw_all_callback() calls bdev_thaw() while holding sb-\u003es_umount\nexclusively. If the block device was frozen via bdev_freeze() dropping\nthe last block layer freeze reference calls fs_bdev_thaw() which\nreacquires s_umount:\n\n do_thaw_all_callback(sb)\n super_lock_excl(sb) # holds sb-\u003es_umount\n bdev_thaw(sb-\u003es_bdev)\n mutex_lock(\u0026bdev-\u003ebd_fsfreeze_mutex)\n # bd_fsfreeze_count drops 1 -\u003e 0\n bd_holder_ops-\u003ethaw == fs_bdev_thaw\n get_bdev_super(bdev)\n bdev_super_lock(bdev, true)\n super_lock(sb, true)\n down_write(\u0026sb-\u003es_umount) # same task: deadlock\n\nThe emergency thaw worker deadlocks against itself holding both\ns_umount and bd_fsfreeze_mutex. That fscks any subsequent unmount,\nfreeze, or thaw of that filesystem and block device.\n\n [ 81.878470] sysrq: Show Blocked State\n [ 81.880140] task:kworker/0:1 state:D stack:0 pid:11 tgid:11 ppid:2 task_flags:0x4208060 flags:0x00080000\n [ 81.884876] Workqueue: events do_thaw_all\n [ 81.886656] Call Trace:\n [ 81.887759] \u003cTASK\u003e\n [ 81.888763] __schedule+0x579/0x1420\n [ 81.890372] schedule+0x3a/0x100\n [ 81.891794] schedule_preempt_disabled+0x15/0x30\n [ 81.893848] rwsem_down_write_slowpath+0x1ea/0x900\n [ 81.895191] ? __pfx_do_thaw_all_callback+0x10/0x10\n [ 81.896528] down_write+0xbd/0xc0\n [ 81.897505] super_lock+0x91/0x180\n [ 81.898457] ? __mutex_lock+0xa99/0x1140\n [ 81.900748] ? __mutex_unlock_slowpath+0x1f/0x400\n [ 81.902069] bdev_super_lock+0x5b/0x150\n [ 81.903132] get_bdev_super+0x10/0x60\n [ 81.904042] fs_bdev_thaw+0x23/0xf0\n [ 81.904755] bdev_thaw+0x82/0x100\n [ 81.905484] do_thaw_all_callback+0x2c/0x50\n [ 81.906298] __iterate_supers+0x5d/0x130\n [ 81.907067] do_thaw_all+0x20/0x40\n [ 81.907739] process_one_work+0x206/0x5e0\n [ 81.908545] worker_thread+0x1e2/0x3c0\n [ 81.909339] ? __pfx_worker_thread+0x10/0x10\n [ 81.910171] kthread+0xf4/0x130\n [ 81.910799] ? __pfx_kthread+0x10/0x10\n [ 81.911528] ret_from_fork+0x2e2/0x3b0\n [ 81.912259] ? __pfx_kthread+0x10/0x10\n [ 81.913010] ret_from_fork_asm+0x1a/0x30\n [ 81.913806] \u003c/TASK\u003e\n\nbdev_super_lock() even documents the violated requirement with\nlockdep_assert_not_held(\u0026sb-\u003es_umount).\n\nAcquiring bd_fsfreeze_mutex under s_umount also inverts the\nbd_fsfreeze_mutex vs. s_umount ordering established by\nbdev_{freeze,thaw}() and can thus ABBA against a concurrent block-layer\nfreeze even when the recursive path isn\u0027t hit.\n\nFix this by not holding s_umount around the bdev_thaw() loop at all. Pin\nthe superblock with an active reference instead as\nfilesystems_freeze_callback() does. The active reference keeps the\nsuperblock from being shut down and so -\u003es_bdev stays valid without\nholding s_umount. The block-layer-held freeze is dropped by\nfs_bdev_thaw() with FREEZE_MAY_NEST | FREEZE_HOLDER_USERSPACE exactly as\na regular unfreeze would and thaw_super_locked() handles\nfilesystem-level freezes as before.\n\nThe emergency thaw path has deadlocked like this in one form or\nanother for a long long time but the current exclusively-held\nshape dates back to commit [1] where thaw_bdev() already ended in\nthaw_super() with s_umount held by do_thaw_all_callback()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:53.613Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/96248aeddde794227a49af1a332a1e21b3c15d56"
},
{
"url": "https://git.kernel.org/stable/c/c202aa03388fd1889b7aa4f7d677c49e22cd9700"
},
{
"url": "https://git.kernel.org/stable/c/2a1127c1c58b4f15a93f2fd56ff7c2c3d611d5c5"
},
{
"url": "https://git.kernel.org/stable/c/05536cad35f27b520d4b6f0e57c8cc5bfb6b0502"
},
{
"url": "https://git.kernel.org/stable/c/99719b5da9320ed344daee87d9c73d321a98f252"
},
{
"url": "https://git.kernel.org/stable/c/63d78b546eefc38ad9898dc839bfc94811ede547"
},
{
"url": "https://git.kernel.org/stable/c/4c483644d1a7709efe7d1be7dbf88cf4008a7864"
},
{
"url": "https://git.kernel.org/stable/c/749d7aa0377aae32af8c0a4ad43371e7bf830ab5"
}
],
"title": "super: fix emergency thaw deadlock on frozen block devices",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68132",
"datePublished": "2026-08-10T11:58:55.196Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-23T12:45:53.613Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-31629 (GCVE-0-2026-31629)
Vulnerability from cvelistv5
Published
2026-04-24 14:42
Modified
2026-08-05 12:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: add missing return after LLCP_CLOSED checks
In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket
state is LLCP_CLOSED, the code correctly calls release_sock() and
nfc_llcp_sock_put() but fails to return. Execution falls through to
the remainder of the function, which calls release_sock() and
nfc_llcp_sock_put() again. This results in a double release_sock()
and a refcount underflow via double nfc_llcp_sock_put(), leading to
a use-after-free.
Add the missing return statements after the LLCP_CLOSED branches
in both functions to prevent the fall-through.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b2a23529593d011fb433a3d711fc597ed6a6bd2f",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "665315df9c3486cb213fc44d83cc8bcd47fe0d26",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "0eb1263a3b8c36418c9ba295c9ab3abed664edbf",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "796e0cac058252d0ad34ebe288e6f7979b5fc9b2",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "8977fad2b3c6eefd414131168d597c5d1d5e1abf",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "ff3d9e8f7244293e303f7b6ef70774291c7c27e9",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "aba4712e8f0381cd5d196534ce2ad082626a5ab6",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "2b5dd4632966c39da6ba74dbc8689b309065e82c",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.3"
},
{
"lessThan": "3.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.136",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.83",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.24",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.136",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.83",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.24",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.14",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.1",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: add missing return after LLCP_CLOSED checks\n\nIn nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket\nstate is LLCP_CLOSED, the code correctly calls release_sock() and\nnfc_llcp_sock_put() but fails to return. Execution falls through to\nthe remainder of the function, which calls release_sock() and\nnfc_llcp_sock_put() again. This results in a double release_sock()\nand a refcount underflow via double nfc_llcp_sock_put(), leading to\na use-after-free.\n\nAdd the missing return statements after the LLCP_CLOSED branches\nin both functions to prevent the fall-through."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable LLCP receive handlers process NFC DEP/LLCP PDUs supplied by a nearby NFC peer over the NFC radio link. The attacker must be in NFC range, so this is adjacent rather than local or internet-routable network access.\nAC:L - The attacker can drive the required LLCP packet sequence, for example closing a matched LLCP socket with a remote control PDU and then sending DISC or I/RR/RNR for the same SAP pair. No uncontrollable race or special memory layout condition is required to trigger the double put/unlock path.\nPR:N - The triggering input is unauthenticated NFC LLCP traffic from the peer and does not require an account or privileges on the victim. Any local NFC setup or listening service is an environmental prerequisite, not a privilege held by the attacker.\nUI:N - After the victim NFC subsystem/link is active and the attacker is in range, malicious LLCP frames are processed by the kernel receive path without further victim action. Proximity is already captured by AV:A.\nS:U - The vulnerability corrupts kernel socket lifetime state within the same kernel security authority. It does not cross a VM, hypervisor, IOMMU, or separate authorization boundary.\nC:H - The bug causes a refcount imbalance and use-after-free of an NFC LLCP socket object. Kernel UAFs are defensibly treated as enabling memory disclosure primitives under the required high-severity guidance.\nI:H - The freed socket object can potentially be reclaimed and controlled, turning the UAF into kernel memory corruption or control-flow/data-structure modification. Under the required guidance, UAF impact is high for integrity.\nA:H - The double release and double sock_put can produce refcount underflow, use-after-free, warnings, oopses, or crashes in kernel socket handling. A kernel crash or panic is high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:23:55.426Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b2a23529593d011fb433a3d711fc597ed6a6bd2f"
},
{
"url": "https://git.kernel.org/stable/c/665315df9c3486cb213fc44d83cc8bcd47fe0d26"
},
{
"url": "https://git.kernel.org/stable/c/9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6"
},
{
"url": "https://git.kernel.org/stable/c/0eb1263a3b8c36418c9ba295c9ab3abed664edbf"
},
{
"url": "https://git.kernel.org/stable/c/796e0cac058252d0ad34ebe288e6f7979b5fc9b2"
},
{
"url": "https://git.kernel.org/stable/c/8977fad2b3c6eefd414131168d597c5d1d5e1abf"
},
{
"url": "https://git.kernel.org/stable/c/ff3d9e8f7244293e303f7b6ef70774291c7c27e9"
},
{
"url": "https://git.kernel.org/stable/c/aba4712e8f0381cd5d196534ce2ad082626a5ab6"
},
{
"url": "https://git.kernel.org/stable/c/2b5dd4632966c39da6ba74dbc8689b309065e82c"
}
],
"title": "nfc: llcp: add missing return after LLCP_CLOSED checks",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-31629",
"datePublished": "2026-04-24T14:42:49.849Z",
"dateReserved": "2026-03-09T15:48:24.124Z",
"dateUpdated": "2026-08-05T12:23:55.426Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74495 (GCVE-0-2026-74495)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
igbvf: Fix leak in TX DMA error cleanup
If an error is encountered while mapping TX buffers, the driver should
unmap any buffers already mapped for that skb.
Because count is incremented before each frag mapping, it will always
match the correct number of unmappings needed when dma_error is reached.
Decrementing count before the while loop in dma_error causes an
off-by-one error. If any mapping was successful before an unsuccessful
mapping, exactly one DMA mapping (the head) would leak.
This bug was introduced by a 2010 fix for an endless loop in dma_error.
All other affected drivers have already been fixed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/igbvf/netdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e42b7225c45f57b42306b80cdd3bda202bae7293",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "e3ed89c257f6361f13df23023cd10ace830330ad",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "56726ff12cb6759ab90d6f5332c2377aeca7d249",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "31089f4eab42e0fc248ec80c26f9b0bad59ba4cc",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "bc25d56c03e41c10bc4b40e99ca5d7b941675c04",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "845a9cdd9b03b7b6fa8de3ee80579780350a7f65",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "df07003b5a6c6c9fce60d765d6a3da815a74c41c",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "0565052b7e2f436b7f1541f4849da96dc0aa7a0e",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/igbvf/netdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.33"
},
{
"lessThan": "2.6.33",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.33",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nigbvf: Fix leak in TX DMA error cleanup\n\nIf an error is encountered while mapping TX buffers, the driver should\nunmap any buffers already mapped for that skb.\n\nBecause count is incremented before each frag mapping, it will always\nmatch the correct number of unmappings needed when dma_error is reached.\nDecrementing count before the while loop in dma_error causes an\noff-by-one error. If any mapping was successful before an unsuccessful\nmapping, exactly one DMA mapping (the head) would leak.\n\nThis bug was introduced by a 2010 fix for an endless loop in dma_error.\nAll other affected drivers have already been fixed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in the igbvf VF transmit path reached whenever egress skbs are queued, including fragmented replies or forwarded traffic from remote peers on SR-IOV cloud/tenant networks with internet-facing VFs.\nAC:L - No race is required; an attacker can repeatedly drive fragmented TX skbs and SWIOTLB/DMA-mapping pressure until skb_frag_dma_map fails after a successful head map, deterministically hitting the off-by-one dma_error cleanup.\nPR:N - Reaching ndo_start_xmit via normal sockets on the VF requires no kernel capabilities; co-tenant or internet-facing traffic can induce the leaky dma_error path without local credentials on the victim.\nUI:N - No victim interaction is needed beyond the VF carrying traffic; the leak occurs automatically in dma_error cleanup during transmit once mapping failure conditions are met.\nS:U - Impact is confined to the kernel/DMA resources of the guest or host running igbvf and does not by itself cross a hypervisor, IOMMU isolation, or separate security authority boundary.\nC:H - The error path frees the skb while its head DMA/IOMMU mapping remains in buffer_info, so freed pages can be reallocated while still mapped, enabling plausible kernel memory disclosure via stale DMA state.\nI:H - Reusing the descriptor slot without unmapping the leaked head mapping corrupts driver/IOMMU metadata and accumulates orphan mappings, a defensible path to driver heap corruption or write primitives.\nA:H - Each leaked TX DMA/IOMMU mapping consumes finite SWIOTLB/IOMMU resources; repeated triggering can exhaust mappings and break transmit or disable the VF entirely."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:53.097Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e42b7225c45f57b42306b80cdd3bda202bae7293"
},
{
"url": "https://git.kernel.org/stable/c/e3ed89c257f6361f13df23023cd10ace830330ad"
},
{
"url": "https://git.kernel.org/stable/c/56726ff12cb6759ab90d6f5332c2377aeca7d249"
},
{
"url": "https://git.kernel.org/stable/c/31089f4eab42e0fc248ec80c26f9b0bad59ba4cc"
},
{
"url": "https://git.kernel.org/stable/c/bc25d56c03e41c10bc4b40e99ca5d7b941675c04"
},
{
"url": "https://git.kernel.org/stable/c/845a9cdd9b03b7b6fa8de3ee80579780350a7f65"
},
{
"url": "https://git.kernel.org/stable/c/df07003b5a6c6c9fce60d765d6a3da815a74c41c"
},
{
"url": "https://git.kernel.org/stable/c/0565052b7e2f436b7f1541f4849da96dc0aa7a0e"
}
],
"title": "igbvf: Fix leak in TX DMA error cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74495",
"datePublished": "2026-08-15T12:27:23.229Z",
"dateReserved": "2026-08-15T05:44:03.906Z",
"dateUpdated": "2026-08-19T16:37:53.097Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68399 (GCVE-0-2026-68399)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix UAF in sock clone early bailouts
Similar to recent commit 9b51a6155d14 ("bpf,fork: wipe ->bpf_storage
before bailouts that access it"), sk_clone() performs an initial
shallow copy of the socket field ->sk_bpf_storage via sock_copy()
for the cloned socket newsk.
If sk_clone() bails out early (e.g. if sk_filter_charge() fails) prior
to calling bpf_sk_storage_clone(), newsk->sk_bpf_storage still points
to the parent socket's BPF local storage. When newsk is subsequently
freed via sk_free(), the deallocation path (__sk_destruct() ->
bpf_sk_storage_free()) destroys the parent socket's BPF local storage,
leading to a use-after-free (UAF) on the parent socket.
Fix this by resetting newsk->sk_bpf_storage to NULL immediately after
sock_copy() in sk_clone(), and remove the now redundant initialization
from bpf_sk_storage_clone().
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/bpf_sk_storage.c",
"net/core/sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "14b49b5ab29979552c219a09e569b424fbbf4a6e",
"status": "affected",
"version": "6ac99e8f23d4b10258406ca0dd7bffca5f31da9d",
"versionType": "git"
},
{
"lessThan": "7cbd0c4cebe4c9f678d15e6b9ba975e1155a107f",
"status": "affected",
"version": "6ac99e8f23d4b10258406ca0dd7bffca5f31da9d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/bpf_sk_storage.c",
"net/core/sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix UAF in sock clone early bailouts\n\nSimilar to recent commit 9b51a6155d14 (\"bpf,fork: wipe -\u003ebpf_storage\nbefore bailouts that access it\"), sk_clone() performs an initial\nshallow copy of the socket field -\u003esk_bpf_storage via sock_copy()\nfor the cloned socket newsk.\n\nIf sk_clone() bails out early (e.g. if sk_filter_charge() fails) prior\nto calling bpf_sk_storage_clone(), newsk-\u003esk_bpf_storage still points\nto the parent socket\u0027s BPF local storage. When newsk is subsequently\nfreed via sk_free(), the deallocation path (__sk_destruct() -\u003e\nbpf_sk_storage_free()) destroys the parent socket\u0027s BPF local storage,\nleading to a use-after-free (UAF) on the parent socket.\n\nFix this by resetting newsk-\u003esk_bpf_storage to NULL immediately after\nsock_copy() in sk_clone(), and remove the now redundant initialization\nfrom bpf_sk_storage_clone()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable clone path and its early-bailout condition are driven through the BPF sk_storage subsystem and local socket setup (attaching sk_storage, attaching a socket filter, adjusting optmem_max). Per kernel guidance BPF is Local; a remote peer cannot control the bailout conditions.\nAC:L - An attacker who controls the local setup can deterministically force the early bailout by attaching a filter and lowering net.core.optmem_max below the filter size, exactly the sysctl-change scenario the code documents, making sk_filter_charge fail on every clone.\nPR:L - Reaching the bug requires attaching BPF sk_storage and manipulating socket/net settings; these capabilities (CAP_BPF/CAP_NET_ADMIN) can be reachable via user namespaces in some configurations, so the lower-privilege value is chosen per the higher-severity rule.\nUI:N - The clone is triggered by connection acceptance or association creation with no victim action; no user interaction is needed.\nS:U - The UAF corrupts kernel socket/BPF-storage objects within the kernel\u0027s own security authority; no crossing into a separate security scope (no VM/IOMMU boundary).\nC:H - The use-after-free lets the attacker reclaim the freed bpf_local_storage object with controlled contents, enabling disclosure of kernel memory; per guidance UAF is High.\nI:H - UAF on a live socket\u0027s BPF storage enables heap grooming and arbitrary-write primitives, giving control-flow hijack potential; per guidance UAF is High.\nA:H - Destroying the parent socket\u0027s still-referenced BPF local storage reliably causes memory corruption, oops, and kernel panic; per guidance any UAF/crash is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:47.842Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/14b49b5ab29979552c219a09e569b424fbbf4a6e"
},
{
"url": "https://git.kernel.org/stable/c/7cbd0c4cebe4c9f678d15e6b9ba975e1155a107f"
}
],
"title": "bpf: Fix UAF in sock clone early bailouts",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68399",
"datePublished": "2026-08-10T12:04:18.837Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-17T05:04:47.842Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43386 (GCVE-0-2026-43386)
Vulnerability from cvelistv5
Published
2026-05-08 14:21
Modified
2026-05-11 22:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie
The current code checks 'i + 5 < in_len' at the end of the if statement.
However, it accesses 'in_ie[i + 5]' before that check, which can lead
to an out-of-bounds read. Move the length check to the beginning of the
conditional to ensure the index is within bounds before accessing the
array.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_mlme.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6ff2243d5e05a5239e39d4ba61d96b0ea3bf7259",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "12cc6e8f8d4245b7b5a408c6fc8ab1d098d67020",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "209644e25757c499e1c1f08c071ea0386d4448b6",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "768f25613a9fe6766d15a4a72979657adfc1c6d8",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "e14a1148f02e8cf1ca380d57e4b95ca36c97f45d",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "4dd2d9cf563c54e09d5f7eacf95c5b8f538b513b",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "d97fc1b29513010b60fde874c7f0ba816744e18c",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "a75281626fc8fa6dc6c9cc314ee423e8bc45203b",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_mlme.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.253",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.19",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.253",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.167",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.19",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.9",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie\n\nThe current code checks \u0027i + 5 \u003c in_len\u0027 at the end of the if statement.\nHowever, it accesses \u0027in_ie[i + 5]\u0027 before that check, which can lead\nto an out-of-bounds read. Move the length check to the beginning of the\nconditional to ensure the index is within bounds before accessing the\narray."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:23:35.007Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6ff2243d5e05a5239e39d4ba61d96b0ea3bf7259"
},
{
"url": "https://git.kernel.org/stable/c/12cc6e8f8d4245b7b5a408c6fc8ab1d098d67020"
},
{
"url": "https://git.kernel.org/stable/c/209644e25757c499e1c1f08c071ea0386d4448b6"
},
{
"url": "https://git.kernel.org/stable/c/768f25613a9fe6766d15a4a72979657adfc1c6d8"
},
{
"url": "https://git.kernel.org/stable/c/e14a1148f02e8cf1ca380d57e4b95ca36c97f45d"
},
{
"url": "https://git.kernel.org/stable/c/4dd2d9cf563c54e09d5f7eacf95c5b8f538b513b"
},
{
"url": "https://git.kernel.org/stable/c/d97fc1b29513010b60fde874c7f0ba816744e18c"
},
{
"url": "https://git.kernel.org/stable/c/a75281626fc8fa6dc6c9cc314ee423e8bc45203b"
}
],
"title": "staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43386",
"datePublished": "2026-05-08T14:21:32.646Z",
"dateReserved": "2026-05-01T14:12:56.006Z",
"dateUpdated": "2026-05-11T22:23:35.007Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64133 (GCVE-0-2026-64133)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: asihpi: Fix potential OOB array access at reading cache
find_control() to retrieve a cached info accesses the array with the
given index blindly, which may lead to an OOB array access.
Add a sanity check for avoiding it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 719f82d3987aad4cc9f46d19c35f362672545cad Version: 719f82d3987aad4cc9f46d19c35f362672545cad Version: 719f82d3987aad4cc9f46d19c35f362672545cad Version: 719f82d3987aad4cc9f46d19c35f362672545cad Version: 719f82d3987aad4cc9f46d19c35f362672545cad Version: 719f82d3987aad4cc9f46d19c35f362672545cad Version: 719f82d3987aad4cc9f46d19c35f362672545cad Version: 719f82d3987aad4cc9f46d19c35f362672545cad |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/pci/asihpi/hpicmn.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e060e21fe9cca1e5eafd8a1c597026577771e8d9",
"status": "affected",
"version": "719f82d3987aad4cc9f46d19c35f362672545cad",
"versionType": "git"
},
{
"lessThan": "34d0d492a2812b9289af14bca3573a89275965b2",
"status": "affected",
"version": "719f82d3987aad4cc9f46d19c35f362672545cad",
"versionType": "git"
},
{
"lessThan": "ffa29cea7bf9a4ef2ea8084967f142e0301ac670",
"status": "affected",
"version": "719f82d3987aad4cc9f46d19c35f362672545cad",
"versionType": "git"
},
{
"lessThan": "7b6f8c8eb93f02a74b1de8e521c0952af10d1f43",
"status": "affected",
"version": "719f82d3987aad4cc9f46d19c35f362672545cad",
"versionType": "git"
},
{
"lessThan": "8778386e4387b28f2bf8425d7ffc667c6294457f",
"status": "affected",
"version": "719f82d3987aad4cc9f46d19c35f362672545cad",
"versionType": "git"
},
{
"lessThan": "61c5017c64e2ac9e10b70b14b17a079dbc0a805f",
"status": "affected",
"version": "719f82d3987aad4cc9f46d19c35f362672545cad",
"versionType": "git"
},
{
"lessThan": "7d107239935793995bdc6cf29bb99e180bde4c28",
"status": "affected",
"version": "719f82d3987aad4cc9f46d19c35f362672545cad",
"versionType": "git"
},
{
"lessThan": "7b7d6572145c1dab2dd9bfb550b188e5f0ff3c3f",
"status": "affected",
"version": "719f82d3987aad4cc9f46d19c35f362672545cad",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/pci/asihpi/hpicmn.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.35"
},
{
"lessThan": "2.6.35",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.35",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: asihpi: Fix potential OOB array access at reading cache\n\nfind_control() to retrieve a cached info accesses the array with the\ngiven index blindly, which may lead to an OOB array access.\nAdd a sanity check for avoiding it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local ALSA hwdep ioctl (`HPI_IOCTL_LINUX` on `/dev/snd/hwC*D0`) or equivalent in-kernel `hpi_send_recv()` calls; there is no network, Bluetooth, or physical-device attack surface for this PCI audio driver path.\nAC:L - On systems with an AudioScience adapter and control cache enabled, an attacker fully controls `obj_index` in the HPI control message and can reliably trigger the out-of-bounds access with a single crafted ioctl without races or victim-dependent timing.\nPR:L - Exploitation requires only local access to the ALSA sound/hwdep device nodes (typically any unprivileged user in the `audio` group), not real root or capabilities that cannot be obtained through user namespaces.\nUI:N - No victim interaction is required; the attacker opens the hwdep device and issues crafted HPI control messages directly without needing another user to perform any action.\nS:U - Impact is confined to kernel memory within the same security authority (local privilege escalation / kernel crash); it does not cross VM, IOMMU, or sandbox boundaries.\nC:H - The out-of-bounds read of `p_cache-\u003ep_info[control_index]` returns adjacent kernel heap pointers/data, and `hpi_check_control_cache_single()` dereferences the corrupted pointer and copies interpreted fields into the ioctl response buffer, enabling kernel information disclosure.\nI:H - After the out-of-bounds pointer load, follow-on cache handling dereferences attacker-influenced kernel addresses for reads and, on SET_STATE or PAD control paths, performs writes (e.g., null-termination), providing exploitable kernel memory corruption beyond a simple crash.\nA:H - A large out-of-bounds `obj_index` can read unmapped memory and cause a kernel oops/panic, and invalid pointer dereferences in the cache-handling path can crash or hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:39:35.138Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e060e21fe9cca1e5eafd8a1c597026577771e8d9"
},
{
"url": "https://git.kernel.org/stable/c/34d0d492a2812b9289af14bca3573a89275965b2"
},
{
"url": "https://git.kernel.org/stable/c/ffa29cea7bf9a4ef2ea8084967f142e0301ac670"
},
{
"url": "https://git.kernel.org/stable/c/7b6f8c8eb93f02a74b1de8e521c0952af10d1f43"
},
{
"url": "https://git.kernel.org/stable/c/8778386e4387b28f2bf8425d7ffc667c6294457f"
},
{
"url": "https://git.kernel.org/stable/c/61c5017c64e2ac9e10b70b14b17a079dbc0a805f"
},
{
"url": "https://git.kernel.org/stable/c/7d107239935793995bdc6cf29bb99e180bde4c28"
},
{
"url": "https://git.kernel.org/stable/c/7b7d6572145c1dab2dd9bfb550b188e5f0ff3c3f"
}
],
"title": "ALSA: asihpi: Fix potential OOB array access at reading cache",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64133",
"datePublished": "2026-07-19T15:40:28.277Z",
"dateReserved": "2026-07-19T07:54:57.036Z",
"dateUpdated": "2026-08-05T12:39:35.138Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68196 (GCVE-0-2026-68196)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: validate assoc response length before subtracting header
wilc_parse_assoc_resp_info() computes the trailing IE length as
ies_len = buffer_len - sizeof(*res);
without first checking that buffer_len is at least sizeof(struct
wilc_assoc_resp) (6 bytes). buffer_len is the length reported for a
received association response (host_int_parse_assoc_resp_info() passes
hif_drv->assoc_resp / assoc_resp_info_len straight in) and must be
validated before the driver accesses the fixed header.
For a frame shorter than the 6-byte fixed header, the subtraction wraps.
For a four-byte response the result is truncated to a u16 ies_len of
65534, so kmemdup() then attempts to copy 65534 bytes starting at
buffer + sizeof(*res), beyond the valid association-response data
(CWE-125). A response shorter than four bytes can also cause an
out-of-bounds read of res->status_code at offsets 2 and 3.
Reject frames too short to hold the fixed header before touching the
header or computing ies_len. Also set the connection status to a failure
on this path: the caller falls through to a
"conn_info->status == WLAN_STATUS_SUCCESS" check after the parser
returns, so leaving the status untouched could let a malformed short
response be treated as a successful association.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/microchip/wilc1000/hif.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d79b92417f33424ff23dad76716ed8f2cefb1083",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "b81d0ea9e1daa215b3da68c1f4f6fb07940c2f6a",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "8d50acf5420de0c4da99c2d634731c9d3164a755",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "584c8954ad55f8b09b475be6db710fe40ceb988c",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "4d410320e8ae5933e651660c9fadc1d380309e23",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "e511e93abd6eeedcd5b3c55516241f414fbde64a",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "8ccdf8c8de87a9580df37c3c1ec53ba88cedef65",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "4c4c97b60a5e978121d9ee8cb0ab3916e5d6a8de",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/microchip/wilc1000/hif.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: validate assoc response length before subtracting header\n\nwilc_parse_assoc_resp_info() computes the trailing IE length as\n\n\ties_len = buffer_len - sizeof(*res);\n\nwithout first checking that buffer_len is at least sizeof(struct\nwilc_assoc_resp) (6 bytes). buffer_len is the length reported for a\nreceived association response (host_int_parse_assoc_resp_info() passes\nhif_drv-\u003eassoc_resp / assoc_resp_info_len straight in) and must be\nvalidated before the driver accesses the fixed header.\n\nFor a frame shorter than the 6-byte fixed header, the subtraction wraps.\nFor a four-byte response the result is truncated to a u16 ies_len of\n65534, so kmemdup() then attempts to copy 65534 bytes starting at\nbuffer + sizeof(*res), beyond the valid association-response data\n(CWE-125). A response shorter than four bytes can also cause an\nout-of-bounds read of res-\u003estatus_code at offsets 2 and 3.\n\nReject frames too short to hold the fixed header before touching the\nheader or computing ies_len. Also set the connection status to a failure\non this path: the caller falls through to a\n\"conn_info-\u003estatus == WLAN_STATUS_SUCCESS\" check after the parser\nreturns, so leaving the status untouched could let a malformed short\nresponse be treated as a successful association."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Exploitation requires a rogue WiFi AP to send a malformed 802.11 Association Response over the air during STA join; per kernel guidance WiFi frame injection is Adjacent, not routable Network.\nAC:L - The attacker fully controls the rogue AP and can craft sub-6-byte association responses with SUCCESS status; once the victim initiates or auto-rejoins association, the malformed frame reliably reaches the parser.\nPR:N - No privileges on the victim are required; a remote attacker operating a rogue AP triggers the bug during the standard pre-authentication WiFi association handshake without local access or credentials.\nUI:N - Exploitation does not require per-attempt user action when devices auto-reconnect to a saved SSID or join an evil-twin AP broadcasting a known network name, which is common on embedded/IoT WILC1000 deployments.\nS:U - The vulnerability is confined to kernel memory and driver state on the affected host; impact does not cross a security boundary such as VM escape, sandbox escape, or IOMMU/DMA isolation bypass.\nC:H - Integer underflow drives kmemdup() to copy up to ~65534 bytes past the 512-byte assoc_resp buffer, leaking adjacent kernel heap data that is forwarded to userspace via cfg80211_connect_bss() response IEs.\nI:L - Beyond the OOB read, a malformed short response can leave conn_info-\u003estatus as WLAN_STATUS_SUCCESS and report a bogus successful association, corrupting the device\u0027s connection integrity without granting arbitrary kernel write.\nA:H - The oversized kmemdup() memcpy reads far beyond the kmalloc-backed assoc_resp array, which can fault on unmapped memory and cause a kernel oops or panic; repeated triggers also impose severe memory pressure."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:13.791Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d79b92417f33424ff23dad76716ed8f2cefb1083"
},
{
"url": "https://git.kernel.org/stable/c/b81d0ea9e1daa215b3da68c1f4f6fb07940c2f6a"
},
{
"url": "https://git.kernel.org/stable/c/8d50acf5420de0c4da99c2d634731c9d3164a755"
},
{
"url": "https://git.kernel.org/stable/c/584c8954ad55f8b09b475be6db710fe40ceb988c"
},
{
"url": "https://git.kernel.org/stable/c/4d410320e8ae5933e651660c9fadc1d380309e23"
},
{
"url": "https://git.kernel.org/stable/c/e511e93abd6eeedcd5b3c55516241f414fbde64a"
},
{
"url": "https://git.kernel.org/stable/c/8ccdf8c8de87a9580df37c3c1ec53ba88cedef65"
},
{
"url": "https://git.kernel.org/stable/c/4c4c97b60a5e978121d9ee8cb0ab3916e5d6a8de"
}
],
"title": "wifi: wilc1000: validate assoc response length before subtracting header",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68196",
"datePublished": "2026-08-10T12:00:14.686Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:13.791Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53238 (GCVE-0-2026-53238)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-06-25 08:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netlabel: validate unlabeled address and mask attribute lengths
netlbl_unlabel_addrinfo_get() used the address attribute length to
determine whether the attribute data could be read as an IPv4 or IPv6
address, but did not independently validate the corresponding mask
attribute length. A crafted Generic Netlink request could therefore
provide a valid IPv4/IPv6 address attribute with a shorter mask
attribute, which would later be read as a full struct in_addr or
struct in6_addr.
NLA_BINARY policy lengths are maximum lengths by default, so use
NLA_POLICY_EXACT_LEN() for the unlabeled IPv4/IPv6 address and mask
attributes. This rejects short attributes during policy validation and
also exposes the exact length requirements through policy introspection.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd Version: 8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd Version: 8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd Version: 8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd Version: 8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd Version: 8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd Version: 8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd Version: 8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netlabel/netlabel_unlabeled.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "975a84fd741440853380d37465b6e226cf47254c",
"status": "affected",
"version": "8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd",
"versionType": "git"
},
{
"lessThan": "672f0f3b8f875ffe6525a37847eafa7648c4c0c6",
"status": "affected",
"version": "8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd",
"versionType": "git"
},
{
"lessThan": "95bda3eac0b1454c2cee98d58d9ba6dd8391e843",
"status": "affected",
"version": "8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd",
"versionType": "git"
},
{
"lessThan": "07a18f5c90dd3d586b73242f5a5bbf0a72f2fdc6",
"status": "affected",
"version": "8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd",
"versionType": "git"
},
{
"lessThan": "71c52da13c3737493b42d20d9f33de34e03b3156",
"status": "affected",
"version": "8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd",
"versionType": "git"
},
{
"lessThan": "0c4bb32ad7fdc2dc6a8050f41eb04d4bda56b6c8",
"status": "affected",
"version": "8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd",
"versionType": "git"
},
{
"lessThan": "ccfe292a966079c61ea68a2da303b2a336170993",
"status": "affected",
"version": "8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd",
"versionType": "git"
},
{
"lessThan": "9772589b57e44aedc240211c5c3f7a684a034d3a",
"status": "affected",
"version": "8cc44579d1bd77ba3a32f2cb76fd9669c229c5fd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netlabel/netlabel_unlabeled.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlabel: validate unlabeled address and mask attribute lengths\n\nnetlbl_unlabel_addrinfo_get() used the address attribute length to\ndetermine whether the attribute data could be read as an IPv4 or IPv6\naddress, but did not independently validate the corresponding mask\nattribute length. A crafted Generic Netlink request could therefore\nprovide a valid IPv4/IPv6 address attribute with a shorter mask\nattribute, which would later be read as a full struct in_addr or\nstruct in6_addr.\n\nNLA_BINARY policy lengths are maximum lengths by default, so use\nNLA_POLICY_EXACT_LEN() for the unlabeled IPv4/IPv6 address and mask\nattributes. This rejects short attributes during policy validation and\nalso exposes the exact length requirements through policy introspection."
}
],
"providerMetadata": {
"dateUpdated": "2026-06-25T08:39:34.492Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/975a84fd741440853380d37465b6e226cf47254c"
},
{
"url": "https://git.kernel.org/stable/c/672f0f3b8f875ffe6525a37847eafa7648c4c0c6"
},
{
"url": "https://git.kernel.org/stable/c/95bda3eac0b1454c2cee98d58d9ba6dd8391e843"
},
{
"url": "https://git.kernel.org/stable/c/07a18f5c90dd3d586b73242f5a5bbf0a72f2fdc6"
},
{
"url": "https://git.kernel.org/stable/c/71c52da13c3737493b42d20d9f33de34e03b3156"
},
{
"url": "https://git.kernel.org/stable/c/0c4bb32ad7fdc2dc6a8050f41eb04d4bda56b6c8"
},
{
"url": "https://git.kernel.org/stable/c/ccfe292a966079c61ea68a2da303b2a336170993"
},
{
"url": "https://git.kernel.org/stable/c/9772589b57e44aedc240211c5c3f7a684a034d3a"
}
],
"title": "netlabel: validate unlabeled address and mask attribute lengths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53238",
"datePublished": "2026-06-25T08:39:34.492Z",
"dateReserved": "2026-06-09T07:44:35.393Z",
"dateUpdated": "2026-06-25T08:39:34.492Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40199 (GCVE-0-2025-40199)
Vulnerability from cvelistv5
Published
2025-11-12 21:56
Modified
2026-08-05 12:08
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches
Helge reported that the introduction of PP_MAGIC_MASK let to crashes on
boot on his 32-bit parisc machine. The cause of this is the mask is set
too wide, so the page_pool_page_is_pp() incurs false positives which
crashes the machine.
Just disabling the check in page_pool_is_pp() will lead to the page_pool
code itself malfunctioning; so instead of doing this, this patch changes
the define for PP_DMA_INDEX_BITS to avoid mistaking arbitrary kernel
pointers for page_pool-tagged pages.
The fix relies on the kernel pointers that alias with the pp_magic field
always being above PAGE_OFFSET. With this assumption, we can use the
lowest bit of the value of PAGE_OFFSET as the upper bound of the
PP_DMA_INDEX_MASK, which should avoid the false positives.
Because we cannot rely on PAGE_OFFSET always being a compile-time
constant, nor on it always being >0, we fall back to disabling the
dma_index storage when there are not enough bits available. This leaves
us in the situation we were in before the patch in the Fixes tag, but
only on a subset of architecture configurations. This seems to be the
best we can do until the transition to page types in complete for
page_pool pages.
v2:
- Make sure there's at least 8 bits available and that the PAGE_OFFSET
bit calculation doesn't wrap
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/mm.h",
"net/core/page_pool.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "15b8a5b4cdc16e9a8bb2a548e12a0fd92997605a",
"status": "affected",
"version": "4f51fb0d257ff4d406ec27966902de075e3b118e",
"versionType": "git"
},
{
"lessThan": "f62934cea32c8f7b11b747975d69bf5afe4264cf",
"status": "affected",
"version": "ee62ce7a1d909ccba0399680a03c2dee83bcae95",
"versionType": "git"
},
{
"lessThan": "95920c2ed02bde551ab654e9749c2ca7bc3100e0",
"status": "affected",
"version": "ee62ce7a1d909ccba0399680a03c2dee83bcae95",
"versionType": "git"
},
{
"status": "affected",
"version": "c30ae60f41f9edd6e1b5cad41cf28ce04dae39e4",
"versionType": "git"
},
{
"lessThan": "6.12.54",
"status": "affected",
"version": "6.12.34",
"versionType": "semver"
},
{
"lessThan": "6.16",
"status": "affected",
"version": "6.15.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/mm.h",
"net/core/page_pool.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.16"
},
{
"lessThan": "6.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.54",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.54",
"versionStartIncluding": "6.12.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.4",
"versionStartIncluding": "6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.15.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npage_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches\n\nHelge reported that the introduction of PP_MAGIC_MASK let to crashes on\nboot on his 32-bit parisc machine. The cause of this is the mask is set\ntoo wide, so the page_pool_page_is_pp() incurs false positives which\ncrashes the machine.\n\nJust disabling the check in page_pool_is_pp() will lead to the page_pool\ncode itself malfunctioning; so instead of doing this, this patch changes\nthe define for PP_DMA_INDEX_BITS to avoid mistaking arbitrary kernel\npointers for page_pool-tagged pages.\n\nThe fix relies on the kernel pointers that alias with the pp_magic field\nalways being above PAGE_OFFSET. With this assumption, we can use the\nlowest bit of the value of PAGE_OFFSET as the upper bound of the\nPP_DMA_INDEX_MASK, which should avoid the false positives.\n\nBecause we cannot rely on PAGE_OFFSET always being a compile-time\nconstant, nor on it always being \u003e0, we fall back to disabling the\ndma_index storage when there are not enough bits available. This leaves\nus in the situation we were in before the patch in the Fixes tag, but\nonly on a subset of architecture configurations. This seems to be the\nbest we can do until the transition to page types in complete for\npage_pool pages.\n\nv2:\n- Make sure there\u0027s at least 8 bits available and that the PAGE_OFFSET\n bit calculation doesn\u0027t wrap"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The broken `PP_MAGIC_MASK` is evaluated on every page free/alloc check and on every page_pool skb recycle, driven by ordinary local memory and I/O activity rather than by attacker-supplied packet content; an unprivileged local process reliably reaches `free_page_is_bad()`/`napi_pp_put_page()` through normal slab and socket buffer churn. No remote input influences the aliased pointer values, so Local is the accurate vector.\nAC:L - On an affected architecture (32-bit parisc/m68k/nommu targets whose default `PAGE_OFFSET \u003c 0x40000000`) the false positive is deterministic and occurs with no special setup \u2014 it fires during boot on stock configuration, and any page-allocation churn reproduces it. No condition beyond the attacker\u0027s control is required.\nPR:L - Any unprivileged local user can drive slab page frees and network buffer recycling that funnel pages through `page_pool_page_is_pp()`/`netmem_is_pp()`; no capability, namespace privilege, or root is needed. The condition even manifests spontaneously under the init process during boot.\nUI:N - No victim action is required \u2014 the misidentification happens inside the page allocator and skb free paths during normal kernel operation.\nS:U - Both the flawed check and its consequences (page allocator state, page_pool/skb handling) live entirely within the kernel\u0027s own security authority, with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - A false positive in `netmem_is_pp()` causes `page-\u003emapping` to be reinterpreted as a `struct page_pool *` and dereferenced throughout `page_pool_put_unrefed_netmem()`, giving a type-confusion read primitive over arbitrary kernel memory; `bad_page()` additionally dumps raw `struct page` contents and kernel pointers to the log.\nI:H - The same type confusion lets `page_pool_recycle_in_cache()`/`page_pool_recycle_in_ring()` write netmem values and update counters at offsets from an uncontrolled kernel pointer, and `skb_pp_frag_ref()` performs `atomic_long_inc()` on the `page-\u003eprivate`-aliased `pp_ref_count`, corrupting page-cache metadata \u2014 memory corruption leverageable for control-flow hijack.\nA:H - The reported symptom is a machine crash on boot: every affected slab page free triggers a \"BUG: Bad page state ... page_pool leak\" splat and permanently leaks the page, exhausting memory, while the network path oopses on a wild `page_pool` pointer dereference."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:08:28.841Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/15b8a5b4cdc16e9a8bb2a548e12a0fd92997605a"
},
{
"url": "https://git.kernel.org/stable/c/f62934cea32c8f7b11b747975d69bf5afe4264cf"
},
{
"url": "https://git.kernel.org/stable/c/95920c2ed02bde551ab654e9749c2ca7bc3100e0"
}
],
"title": "page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40199",
"datePublished": "2025-11-12T21:56:33.510Z",
"dateReserved": "2025-04-16T07:20:57.178Z",
"dateUpdated": "2026-08-05T12:08:28.841Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68155 (GCVE-0-2026-68155)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: Reject monmaps advertising zero monitors
A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a
monitor to the client. This monmap contains information about the
existing monitors in the cluster. Currently, a monmap indicating that
there are zero monitors in the cluster is treated as valid. However, it
is impossible to have zero monitors in the cluster and still receive a
valid monmap from a monitor. Therefore, such a monmap must be corrupted
and should be treated as invalid. Furthermore, a monmap with a monitor
count of zero can subsequently crash the client when attempting to open
a session with a monitor in __open_session(). This happens because the
"BUG_ON(monc->monmap->num_mon < 1)" assertion in pick_new_mon() is
triggered.
This patch extends a check in ceph_monmap_decode() to also reject
arriving mon_maps with num_mon == 0 rather than only with
num_mon > CEPH_MAX_MON.
[ idryomov: drop "log output for unusual values of num_mon" part ]
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "caf082ef8609a6ac26159ce115f55ab7d00231a3",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "e3ccd4ecab09b22f507f49cb7ed9990c7158ceab",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "0591a15815b498be628a937146e44487d599ba33",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "cd0d41bc569632eaaeccde9d2a6bc919ec00c407",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "e67e8b694872c9bc66996040f9de9242f6236ed9",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "3b249546f59c3d6d3592c10657f82bc3f1faa07c",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "40480eee361ed9676b3f844d532ac28b47251634",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Reject monmaps advertising zero monitors\n\nA message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a\nmonitor to the client. This monmap contains information about the\nexisting monitors in the cluster. Currently, a monmap indicating that\nthere are zero monitors in the cluster is treated as valid. However, it\nis impossible to have zero monitors in the cluster and still receive a\nvalid monmap from a monitor. Therefore, such a monmap must be corrupted\nand should be treated as invalid. Furthermore, a monmap with a monitor\ncount of zero can subsequently crash the client when attempting to open\na session with a monitor in __open_session(). This happens because the\n\"BUG_ON(monc-\u003emonmap-\u003enum_mon \u003c 1)\" assertion in pick_new_mon() is\ntriggered.\n\nThis patch extends a check in ceph_monmap_decode() to also reject\narriving mon_maps with num_mon == 0 rather than only with\nnum_mon \u003e CEPH_MAX_MON.\n\n[ idryomov: drop \"log output for unusual values of num_mon\" part ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached when libceph decodes CEPH_MSG_MON_MAP from a remote Ceph monitor over the kernel client\u0027s established TCP/msgr2 session (mon_dispatch -\u003e ceph_monc_handle_map -\u003e ceph_monmap_decode), which is a network protocol attack surface on CephFS/RBD/cloud nodes.\nAC:L - An attacker who can send monitor protocol messages only needs to set num_mon=0 in the monmap; once accepted, any later session reopen (keepalive timeout, hunt, or connection fault) deterministically hits BUG_ON in pick_new_mon without races or special memory layout.\nPR:N - In the highest-impact scenario a malicious or compromised Ceph monitor (or equivalent authenticated cluster peer) sends the malformed monmap to already-connected kernel clients; the attacker needs no local privileges on the victim host.\nUI:N - After a Ceph client session exists, monmap updates are delivered and processed automatically by the kernel monitor client; no further mount, open, or other victim interaction is required to accept the bad map and later crash on reconnect.\nS:U - Exploitation causes a kernel BUG/panic within the same kernel security domain and does not cross VM, container, IOMMU, or other security boundaries.\nC:N - The failure mode is a BUG_ON assertion in pick_new_mon when num_mon is zero; there is no memory corruption, out-of-bounds access, or other information disclosure primitive on the vulnerable path.\nI:N - Accepting num_mon==0 only stores an empty monmap and later triggers a deliberate kernel BUG; attacker input does not corrupt or modify arbitrary kernel memory or enable code execution.\nA:H - BUG_ON(monc-\u003emonmap-\u003enum_mon \u003c 1) in pick_new_mon during __open_session causes a kernel oops/panic, fully denying availability of the affected host until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:22.933Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/caf082ef8609a6ac26159ce115f55ab7d00231a3"
},
{
"url": "https://git.kernel.org/stable/c/e3ccd4ecab09b22f507f49cb7ed9990c7158ceab"
},
{
"url": "https://git.kernel.org/stable/c/0591a15815b498be628a937146e44487d599ba33"
},
{
"url": "https://git.kernel.org/stable/c/cd0d41bc569632eaaeccde9d2a6bc919ec00c407"
},
{
"url": "https://git.kernel.org/stable/c/e67e8b694872c9bc66996040f9de9242f6236ed9"
},
{
"url": "https://git.kernel.org/stable/c/3b249546f59c3d6d3592c10657f82bc3f1faa07c"
},
{
"url": "https://git.kernel.org/stable/c/40480eee361ed9676b3f844d532ac28b47251634"
}
],
"title": "libceph: Reject monmaps advertising zero monitors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68155",
"datePublished": "2026-08-10T11:59:21.200Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:22.933Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68446 (GCVE-0-2026-68446)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Validate vmw_surface_metadata::array_size
This field comes from userspace and should be validated against specific
limits depending on which Shader Model (SM) is available.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/vmwgfx_surface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e949adf2d42678fb391a41db277e2fcb12090566",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "0403cec2aff8037bc246cf9a0831eb169ddcd9df",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "aded8463466ede7a7fbd1bbf821756c67c83e89b",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "5ff94e1279176b539d451e3e754fdcbd1a8d520a",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "71779fe8bf403a9b3e28dc59229fa556db32d35d",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "6910ccaf41678f7761ba2e57d72b77d056320b4d",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "a4f55260f7f7d4dc4d0ee55063dfb0c457b77991",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/vmwgfx_surface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Validate vmw_surface_metadata::array_size\n\nThis field comes from userspace and should be validated against specific\nlimits depending on which Shader Model (SM) is available."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the DRM_IOCTL_VMW_GB_SURFACE_CREATE/_EXT ioctls on the vmwgfx render node (/dev/dri/renderD128), i.e. local access to the device file on a VMware guest; no network or physical access is involved.\nAC:L - The attacker directly supplies array_size, mip_levels and base_size in a single ioctl and can deterministically choose values that wrap the 32-bit size/subresource computations; no race or uncontrolled precondition is required.\nPR:L - Both ioctls are registered DRM_RENDER_ALLOW, so an unprivileged local user (or containerized workload) holding the normal render-node permissions can call them without DRM master, root, or any capability.\nUI:N - Exploitation is entirely attacker-driven via ioctl calls on an already-open render node; no action by another user or administrator is needed.\nS:U - The unvalidated value corrupts guest kernel memory and device-command state within the same kernel security authority; no VM/IOMMU or sandbox boundary is crossed by the flaw itself.\nC:H - The wrapped res-\u003eguest_memory_size makes the backing buffer far smaller than the surface the host device is told to service, and the undersized dirty-\u003eboxes array is indexed out of bounds, giving out-of-bounds reads of adjacent kernel heap data that can be leaked back through surface contents.\nI:H - The u32 overflows in vmw_surface_get_serialized_size() and num_layers*num_mip yield an undersized backing BO and dirty-tracking array, producing controlled out-of-bounds heap writes (SVGA3dBox data and device DMA past the buffer) usable for heap corruption and privilege escalation.\nA:H - Out-of-bounds writes past kvzalloc\u0027d dirty trackers and BO-sized mismatches reliably corrupt kernel heap metadata, causing oopses/panics; huge array_size values also drive enormous allocations, so a local user can crash the guest kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:40.576Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e949adf2d42678fb391a41db277e2fcb12090566"
},
{
"url": "https://git.kernel.org/stable/c/0403cec2aff8037bc246cf9a0831eb169ddcd9df"
},
{
"url": "https://git.kernel.org/stable/c/aded8463466ede7a7fbd1bbf821756c67c83e89b"
},
{
"url": "https://git.kernel.org/stable/c/5ff94e1279176b539d451e3e754fdcbd1a8d520a"
},
{
"url": "https://git.kernel.org/stable/c/71779fe8bf403a9b3e28dc59229fa556db32d35d"
},
{
"url": "https://git.kernel.org/stable/c/b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8"
},
{
"url": "https://git.kernel.org/stable/c/6910ccaf41678f7761ba2e57d72b77d056320b4d"
},
{
"url": "https://git.kernel.org/stable/c/a4f55260f7f7d4dc4d0ee55063dfb0c457b77991"
}
],
"title": "drm/vmwgfx: Validate vmw_surface_metadata::array_size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68446",
"datePublished": "2026-08-12T00:07:37.385Z",
"dateReserved": "2026-07-30T09:28:09.395Z",
"dateUpdated": "2026-08-19T16:35:40.576Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64021 (GCVE-0-2026-64021)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-07-19 15:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/oa: Fix exec_queue leak on width check in stream open
In xe_oa_stream_open_ioctl(), when param.exec_q->width > 1 the
function returns -EOPNOTSUPP directly, skipping the existing
err_exec_q cleanup path. The exec_queue reference obtained by
xe_exec_queue_lookup() is leaked.
The exec queue holds a reference on the xe_file, which is only
dropped during queue teardown. The leaked lookup ref is not on
the file's exec_queue xarray, so file close cannot release it.
This keeps both the exec queue and the file private state pinned
indefinitely.
Jump to err_exec_q instead of returning directly so the reference
is released.
(cherry picked from commit 339fa0be9e4a5d69fa47e91f4a36574224fb478f)
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/xe/xe_oa.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "04ef7592eaadd9ca8f8f66e76452f73525cff819",
"status": "affected",
"version": "f0ed39830e6064d62f9c5393505677a26569bb56",
"versionType": "git"
},
{
"lessThan": "4b0c4f0c1b133d4bfa31c167200bcda646873328",
"status": "affected",
"version": "f0ed39830e6064d62f9c5393505677a26569bb56",
"versionType": "git"
},
{
"lessThan": "4d25342543c01310fc4e0cba7cb17c775e2421e2",
"status": "affected",
"version": "f0ed39830e6064d62f9c5393505677a26569bb56",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/xe/xe_oa.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/oa: Fix exec_queue leak on width check in stream open\n\nIn xe_oa_stream_open_ioctl(), when param.exec_q-\u003ewidth \u003e 1 the\nfunction returns -EOPNOTSUPP directly, skipping the existing\nerr_exec_q cleanup path. The exec_queue reference obtained by\nxe_exec_queue_lookup() is leaked.\n\nThe exec queue holds a reference on the xe_file, which is only\ndropped during queue teardown. The leaked lookup ref is not on\nthe file\u0027s exec_queue xarray, so file close cannot release it.\nThis keeps both the exec queue and the file private state pinned\nindefinitely.\n\nJump to err_exec_q instead of returning directly so the reference\nis released.\n\n(cherry picked from commit 339fa0be9e4a5d69fa47e91f4a36574224fb478f)"
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T15:39:14.741Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/04ef7592eaadd9ca8f8f66e76452f73525cff819"
},
{
"url": "https://git.kernel.org/stable/c/4b0c4f0c1b133d4bfa31c167200bcda646873328"
},
{
"url": "https://git.kernel.org/stable/c/4d25342543c01310fc4e0cba7cb17c775e2421e2"
}
],
"title": "drm/xe/oa: Fix exec_queue leak on width check in stream open",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64021",
"datePublished": "2026-07-19T15:39:14.741Z",
"dateReserved": "2026-07-19T07:54:57.027Z",
"dateUpdated": "2026-07-19T15:39:14.741Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64489 (GCVE-0-2026-64489)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ymfpci: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails.
snd_ymfpci_create_spdif_controls() does not check the return value
before dereferencing kctl->id.device, which can lead to a NULL pointer
dereference.
Add NULL checks after snd_ctl_new1() calls and return -ENOMEM if any
fails.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1f6c520932bca5be9e8dec137fccb2fc094a80fe Version: c9b83ae4a1609b1914ba7fc70826a3f3a8b234db Version: c9b83ae4a1609b1914ba7fc70826a3f3a8b234db Version: c9b83ae4a1609b1914ba7fc70826a3f3a8b234db Version: c9b83ae4a1609b1914ba7fc70826a3f3a8b234db Version: c9b83ae4a1609b1914ba7fc70826a3f3a8b234db Version: cf671d2462d9af50c328bcc185d2c7b9726f8093 Version: 6.1.34 ≤ Version: 6.3.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/pci/ymfpci/ymfpci_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d7c71dfd4b80f0eacac2c157a8a3a4c6e8b2e0d1",
"status": "affected",
"version": "1f6c520932bca5be9e8dec137fccb2fc094a80fe",
"versionType": "git"
},
{
"lessThan": "91095474eea29b95c9a8bceb9b501a2702b6c55f",
"status": "affected",
"version": "c9b83ae4a1609b1914ba7fc70826a3f3a8b234db",
"versionType": "git"
},
{
"lessThan": "02f33c2062c75e28abc7ad58ce86451cf3140455",
"status": "affected",
"version": "c9b83ae4a1609b1914ba7fc70826a3f3a8b234db",
"versionType": "git"
},
{
"lessThan": "f6538a318947b627710b08a268bc80a48c23bde7",
"status": "affected",
"version": "c9b83ae4a1609b1914ba7fc70826a3f3a8b234db",
"versionType": "git"
},
{
"lessThan": "18ec7d7785be7a4ee8ea11e355122282caad4267",
"status": "affected",
"version": "c9b83ae4a1609b1914ba7fc70826a3f3a8b234db",
"versionType": "git"
},
{
"lessThan": "e64d170346d00b580c0043de3e5ccb3e331c47d4",
"status": "affected",
"version": "c9b83ae4a1609b1914ba7fc70826a3f3a8b234db",
"versionType": "git"
},
{
"status": "affected",
"version": "cf671d2462d9af50c328bcc185d2c7b9726f8093",
"versionType": "git"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.34",
"versionType": "semver"
},
{
"lessThan": "6.4",
"status": "affected",
"version": "6.3.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/pci/ymfpci/ymfpci_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ymfpci: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_ymfpci_create_spdif_controls() does not check the return value\nbefore dereferencing kctl-\u003eid.device, which can lead to a NULL pointer\ndereference.\n\nAdd NULL checks after snd_ctl_new1() calls and return -ENOMEM if any\nfails."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:37.102Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d7c71dfd4b80f0eacac2c157a8a3a4c6e8b2e0d1"
},
{
"url": "https://git.kernel.org/stable/c/91095474eea29b95c9a8bceb9b501a2702b6c55f"
},
{
"url": "https://git.kernel.org/stable/c/02f33c2062c75e28abc7ad58ce86451cf3140455"
},
{
"url": "https://git.kernel.org/stable/c/f6538a318947b627710b08a268bc80a48c23bde7"
},
{
"url": "https://git.kernel.org/stable/c/18ec7d7785be7a4ee8ea11e355122282caad4267"
},
{
"url": "https://git.kernel.org/stable/c/e64d170346d00b580c0043de3e5ccb3e331c47d4"
}
],
"title": "ALSA: ymfpci: check snd_ctl_new1() return value",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64489",
"datePublished": "2026-07-25T08:51:48.161Z",
"dateReserved": "2026-07-19T15:36:31.792Z",
"dateUpdated": "2026-08-17T04:56:37.102Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64237 (GCVE-0-2026-64237)
Vulnerability from cvelistv5
Published
2026-07-24 15:27
Modified
2026-07-27 04:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: elan_i2c - validate firmware size before use
Ensure that the firmware file is large enough to contain the expected
number of pages and the signature (which resides at the end of the
firmware blob) before accessing them to prevent potential out-of-bounds
reads.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bb03bf3f8427a38112819061fc8688999ba02f67 Version: bb03bf3f8427a38112819061fc8688999ba02f67 Version: bb03bf3f8427a38112819061fc8688999ba02f67 Version: bb03bf3f8427a38112819061fc8688999ba02f67 Version: bb03bf3f8427a38112819061fc8688999ba02f67 Version: bb03bf3f8427a38112819061fc8688999ba02f67 Version: bb03bf3f8427a38112819061fc8688999ba02f67 Version: bb03bf3f8427a38112819061fc8688999ba02f67 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/mouse/elan_i2c_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "47b52b98edfe34d0249e72f815215ef24311c3a3",
"status": "affected",
"version": "bb03bf3f8427a38112819061fc8688999ba02f67",
"versionType": "git"
},
{
"lessThan": "c2c3b33b3c0bf2c9427c0926817ef5ffac50de6f",
"status": "affected",
"version": "bb03bf3f8427a38112819061fc8688999ba02f67",
"versionType": "git"
},
{
"lessThan": "331d49b4e1c9efe4479bbd22922dfcdd8c64be7b",
"status": "affected",
"version": "bb03bf3f8427a38112819061fc8688999ba02f67",
"versionType": "git"
},
{
"lessThan": "48b0aa9c08a3ac8e0c0345b7ca581f552324e460",
"status": "affected",
"version": "bb03bf3f8427a38112819061fc8688999ba02f67",
"versionType": "git"
},
{
"lessThan": "3b37190ad3ded3a15fb1dbfc4f26df520a3e59bb",
"status": "affected",
"version": "bb03bf3f8427a38112819061fc8688999ba02f67",
"versionType": "git"
},
{
"lessThan": "bf769358419e00344c1b16fa034d058f563d46a1",
"status": "affected",
"version": "bb03bf3f8427a38112819061fc8688999ba02f67",
"versionType": "git"
},
{
"lessThan": "d97baee9590edf303b3eca432e61de9320834fe1",
"status": "affected",
"version": "bb03bf3f8427a38112819061fc8688999ba02f67",
"versionType": "git"
},
{
"lessThan": "76b0d0baa9ae9c60e726bbe1b6ff0bec2c993634",
"status": "affected",
"version": "bb03bf3f8427a38112819061fc8688999ba02f67",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/mouse/elan_i2c_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.0"
},
{
"lessThan": "4.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: elan_i2c - validate firmware size before use\n\nEnsure that the firmware file is large enough to contain the expected\nnumber of pages and the signature (which resides at the end of the\nfirmware blob) before accessing them to prevent potential out-of-bounds\nreads."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-27T04:37:26.944Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/47b52b98edfe34d0249e72f815215ef24311c3a3"
},
{
"url": "https://git.kernel.org/stable/c/c2c3b33b3c0bf2c9427c0926817ef5ffac50de6f"
},
{
"url": "https://git.kernel.org/stable/c/331d49b4e1c9efe4479bbd22922dfcdd8c64be7b"
},
{
"url": "https://git.kernel.org/stable/c/48b0aa9c08a3ac8e0c0345b7ca581f552324e460"
},
{
"url": "https://git.kernel.org/stable/c/3b37190ad3ded3a15fb1dbfc4f26df520a3e59bb"
},
{
"url": "https://git.kernel.org/stable/c/bf769358419e00344c1b16fa034d058f563d46a1"
},
{
"url": "https://git.kernel.org/stable/c/d97baee9590edf303b3eca432e61de9320834fe1"
},
{
"url": "https://git.kernel.org/stable/c/76b0d0baa9ae9c60e726bbe1b6ff0bec2c993634"
}
],
"title": "Input: elan_i2c - validate firmware size before use",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64237",
"datePublished": "2026-07-24T15:27:41.937Z",
"dateReserved": "2026-07-19T15:36:31.771Z",
"dateUpdated": "2026-07-27T04:37:26.944Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64190 (GCVE-0-2026-64190)
Vulnerability from cvelistv5
Published
2026-07-20 16:27
Modified
2026-07-20 16:27
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: team: fix NULL pointer dereference in team_xmit during mode change
__team_change_mode() clears team->ops with memset() before restoring
safe dummy handlers via team_adjust_ops(). A concurrent team_xmit()
running under RCU on another CPU can read team->ops.transmit during
this window and call a NULL function pointer, crashing the kernel.
The race requires a mode change (CAP_NET_ADMIN) concurrent with
transmit on the team device.
BUG: kernel NULL pointer dereference, address: 0000000000000000
Oops: 0010 [#1] SMP KASAN NOPTI
RIP: 0010:0x0
Call Trace:
team_xmit (drivers/net/team/team_core.c:1853)
dev_hard_start_xmit (net/core/dev.c:3904)
__dev_queue_xmit (net/core/dev.c:4871)
packet_sendmsg (net/packet/af_packet.c:3109)
__sys_sendto (net/socket.c:2265)
The original code assumed that no ports means no traffic, so mode
changes could freely memset()/memcpy() the ops. AF_PACKET with
forced carrier breaks that assumption.
Prevent the race instead of making it safe: replace memset()/memcpy()
with per-field updates that never touch transmit or receive. Those
two handlers are managed solely by team_adjust_ops(), which already
installs dummies when tx_en_port_count == 0 (always true during mode
change since no ports are present). WRITE_ONCE/READ_ONCE prevent
store/load tearing on the handler pointers.
synchronize_net() before exit_op() drains in-flight readers that may
still reference old mode state from before port removal switched the
handlers to dummies.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/team/team_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "03e9405c518c4d61f28079492f252d6d4e2bac5c",
"status": "affected",
"version": "3d249d4ca7d0ed6629a135ea1ea21c72286c0d80",
"versionType": "git"
},
{
"lessThan": "25fe708bbc59289d3d1ea4b126fbc1b460a072a5",
"status": "affected",
"version": "3d249d4ca7d0ed6629a135ea1ea21c72286c0d80",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/team/team_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.3"
},
{
"lessThan": "3.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: team: fix NULL pointer dereference in team_xmit during mode change\n\n__team_change_mode() clears team-\u003eops with memset() before restoring\nsafe dummy handlers via team_adjust_ops(). A concurrent team_xmit()\nrunning under RCU on another CPU can read team-\u003eops.transmit during\nthis window and call a NULL function pointer, crashing the kernel.\n\nThe race requires a mode change (CAP_NET_ADMIN) concurrent with\ntransmit on the team device.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n Oops: 0010 [#1] SMP KASAN NOPTI\n RIP: 0010:0x0\n Call Trace:\n team_xmit (drivers/net/team/team_core.c:1853)\n dev_hard_start_xmit (net/core/dev.c:3904)\n __dev_queue_xmit (net/core/dev.c:4871)\n packet_sendmsg (net/packet/af_packet.c:3109)\n __sys_sendto (net/socket.c:2265)\n\nThe original code assumed that no ports means no traffic, so mode\nchanges could freely memset()/memcpy() the ops. AF_PACKET with\nforced carrier breaks that assumption.\n\nPrevent the race instead of making it safe: replace memset()/memcpy()\nwith per-field updates that never touch transmit or receive. Those\ntwo handlers are managed solely by team_adjust_ops(), which already\ninstalls dummies when tx_en_port_count == 0 (always true during mode\nchange since no ports are present). WRITE_ONCE/READ_ONCE prevent\nstore/load tearing on the handler pointers.\n\nsynchronize_net() before exit_op() drains in-flight readers that may\nstill reference old mode state from before port removal switched the\nhandlers to dummies."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-20T16:27:48.314Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/03e9405c518c4d61f28079492f252d6d4e2bac5c"
},
{
"url": "https://git.kernel.org/stable/c/25fe708bbc59289d3d1ea4b126fbc1b460a072a5"
}
],
"title": "net: team: fix NULL pointer dereference in team_xmit during mode change",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64190",
"datePublished": "2026-07-20T16:27:48.314Z",
"dateReserved": "2026-07-19T07:54:57.040Z",
"dateUpdated": "2026-07-20T16:27:48.314Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64315 (GCVE-0-2026-64315)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: caam - use print_hex_dump_devel to guard key hex dumps
Use print_hex_dump_devel() for dumping sensitive key material in
*_setkey() to avoid leaking secrets at runtime when CONFIG_DYNAMIC_DEBUG
is enabled.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8d818c1055013d355d36188f21c7535687374f6c Version: 8d818c1055013d355d36188f21c7535687374f6c Version: 8d818c1055013d355d36188f21c7535687374f6c Version: 8d818c1055013d355d36188f21c7535687374f6c Version: 8d818c1055013d355d36188f21c7535687374f6c Version: 8d818c1055013d355d36188f21c7535687374f6c Version: 8d818c1055013d355d36188f21c7535687374f6c Version: 8d818c1055013d355d36188f21c7535687374f6c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/crypto/caam/caamalg_qi2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1ec775f6a124cce6278ae58b7d1c78a3bc6eef23",
"status": "affected",
"version": "8d818c1055013d355d36188f21c7535687374f6c",
"versionType": "git"
},
{
"lessThan": "bcf3cf74dfb6981e18b22cbf561f859a0f7faa26",
"status": "affected",
"version": "8d818c1055013d355d36188f21c7535687374f6c",
"versionType": "git"
},
{
"lessThan": "6407dc85d0a4306681cf6c9be7f05e05dcb67a37",
"status": "affected",
"version": "8d818c1055013d355d36188f21c7535687374f6c",
"versionType": "git"
},
{
"lessThan": "c8cfe11e48b2a4646fa662fcaa92e14810a28d46",
"status": "affected",
"version": "8d818c1055013d355d36188f21c7535687374f6c",
"versionType": "git"
},
{
"lessThan": "8904b425cfcafe6a820c94b9bdf4b10f7d70f9d7",
"status": "affected",
"version": "8d818c1055013d355d36188f21c7535687374f6c",
"versionType": "git"
},
{
"lessThan": "d0b8cafd529b4ec759190c6081f7a76efb563a8f",
"status": "affected",
"version": "8d818c1055013d355d36188f21c7535687374f6c",
"versionType": "git"
},
{
"lessThan": "59057f5d4e9a195c6dd61695ad3bc4481ddf4f14",
"status": "affected",
"version": "8d818c1055013d355d36188f21c7535687374f6c",
"versionType": "git"
},
{
"lessThan": "8005dc808bcce7d6cc2ae015a3cde1683bee602d",
"status": "affected",
"version": "8d818c1055013d355d36188f21c7535687374f6c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/crypto/caam/caamalg_qi2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: caam - use print_hex_dump_devel to guard key hex dumps\n\nUse print_hex_dump_devel() for dumping sensitive key material in\n*_setkey() to avoid leaking secrets at runtime when CONFIG_DYNAMIC_DEBUG\nis enabled."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The exposed keys are obtained through local kernel-log interfaces such as /dev/kmsg or syslog; network consumers can cause key installation, but the secret is not returned remotely.\nAC:H - The DPAA2 CAAM implementation must be selected and its normally disabled dynamic-debug callsite must have been enabled by boot configuration or an administrator, a condition an unprivileged attacker cannot create.\nPR:L - On systems with dmesg_restrict disabled, an ordinary local user can read the global kernel log and can invoke the affected callbacks through AF_ALG without capabilities.\nUI:N - No victim action is required after the vulnerable logging configuration is active; services and protocol stacks install keys during normal operation.\nS:U - The disclosure and resulting compromise of kernel-protected cryptographic sessions remain within the host kernel\u0027s security authority.\nC:H - The dumps contain complete encryption and authentication keys, including RFC4106/RFC4543 salt material, enabling decryption of protected IPsec, SMB, or other traffic.\nI:H - Disclosed AEAD or authentication keys permit valid ciphertexts and authentication tags to be forged, enabling unauthorized modification of protected communications.\nA:H - An AF_ALG caller can trigger the unratelimited dumps continuously, potentially stalling systems using slow debug consoles, while stolen authentication keys can also sustain disruption of protected IPsec or SMB sessions."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:15.471Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1ec775f6a124cce6278ae58b7d1c78a3bc6eef23"
},
{
"url": "https://git.kernel.org/stable/c/bcf3cf74dfb6981e18b22cbf561f859a0f7faa26"
},
{
"url": "https://git.kernel.org/stable/c/6407dc85d0a4306681cf6c9be7f05e05dcb67a37"
},
{
"url": "https://git.kernel.org/stable/c/c8cfe11e48b2a4646fa662fcaa92e14810a28d46"
},
{
"url": "https://git.kernel.org/stable/c/8904b425cfcafe6a820c94b9bdf4b10f7d70f9d7"
},
{
"url": "https://git.kernel.org/stable/c/d0b8cafd529b4ec759190c6081f7a76efb563a8f"
},
{
"url": "https://git.kernel.org/stable/c/59057f5d4e9a195c6dd61695ad3bc4481ddf4f14"
},
{
"url": "https://git.kernel.org/stable/c/8005dc808bcce7d6cc2ae015a3cde1683bee602d"
}
],
"title": "crypto: caam - use print_hex_dump_devel to guard key hex dumps",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64315",
"datePublished": "2026-07-25T08:49:45.787Z",
"dateReserved": "2026-07-19T15:36:31.779Z",
"dateUpdated": "2026-08-17T04:53:15.471Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68206 (GCVE-0-2026-68206)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: v4l2-ctrls: validate HEVC active reference counts
HEVC slice parameters are shared stateless V4L2 controls, but the common
validation path does not verify the active L0/L1 reference counts before
driver-specific code consumes them.
The original report came from Cedrus, but the active count bounds are
not Cedrus-specific. Validate them in the common HEVC slice control path
so stateless HEVC drivers get the same basic guarantees as soon as the
control is queued.
Do not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may
use out-of-range sentinel values such as 0xff for missing references, and
some hardware can use that information for concealment. Keep this common
check limited to the active reference counts.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-ctrls-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3299c3905f3fb439ebd892658b87bc76c93ae116",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "9a998cc1c348769262d433acb7d238c5fac4b2e0",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "dbaf0e0023e2f9332c5164822def7f80b7d2c5ef",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "3068ab802fc98b121dcb451e1f7f4d338ffc7a19",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "b01df98a6669d2b67d8aed816021b327fd905998",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "afbe4bc252d90a6f8fad869b06d5430f615f22f9",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-ctrls-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-ctrls: validate HEVC active reference counts\n\nHEVC slice parameters are shared stateless V4L2 controls, but the common\nvalidation path does not verify the active L0/L1 reference counts before\ndriver-specific code consumes them.\n\nThe original report came from Cedrus, but the active count bounds are\nnot Cedrus-specific. Validate them in the common HEVC slice control path\nso stateless HEVC drivers get the same basic guarantees as soon as the\ncontrol is queued.\n\nDo not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may\nuse out-of-range sentinel values such as 0xff for missing references, and\nsome hardware can use that information for concealment. Keep this common\ncheck limited to the active reference counts."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The control is only settable through VIDIOC_S_EXT_CTRLS on the local V4L2 stateless decoder node (/dev/videoN), followed by QBUF/STREAMON on the same fd. There is no network or remote path into the HEVC slice-params control.\nAC:L - The attacker supplies num_ref_idx_l0/l1_active_minus1 verbatim as a u8; any value in 16..254 deterministically drives the loops in cedrus_h265_is_low_delay() and rkvdec_hevc set_ps_field() out of bounds on the very next decode run. No race, timing window, or uncontrollable memory layout is involved.\nPR:L - Only an unprivileged local account holding the video device node is required (typically the \u0027video\u0027 group, or the media/codec service reachable from sandboxed apps on Android and embedded Allwinner/Rockchip devices). cedrus_try_ctrl() checks only SPS chroma format and bit depth; no capability or root check exists on the path.\nUI:N - The attacking process performs the whole sequence itself: open the decoder, set the crafted HEVC slice-params control, queue buffers and start streaming. No victim action, media file, or mount is needed.\nS:U - The out-of-bounds accesses stay inside the kernel\u0027s own slab and DMA memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - decode_params-\u003edpb[] holds 16 16-byte entries at the tail of a ~336-byte control allocation, so an index up to 255 reads roughly 3.8 KB of adjacent kernel heap; the pred-weight loops likewise read 240 bytes past slice_params. Those OOB bytes are fed into decoder SRAM and steer the low-delay decision, giving an attacker-steerable oracle over unrelated kernel memory.\nI:H - In rkvdec-hevc, REF_PIC_IDX_L0(i)/REF_PIC_LONG_TERM_L1(i) with i up to 255 resolve to bit offset ~1276 in an 8-word rkvdec_rps_packet, so set_ps_field() performs an out-of-bounds write of attacker-chosen bits at an attacker-chosen offset into (and past the end of) the coherent DMA priv_tbl, corrupting hardware descriptor state and adjacent memory.\nA:H - Reading several kilobytes past a slab object can walk into an unmapped or poisoned region and trips KASAN/hardening checks, while the rkvdec out-of-bounds write corrupts the DMA table handed to the decoder; either yields a kernel oops or wedged hardware, repeatable at will from an unprivileged process."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:26.837Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3299c3905f3fb439ebd892658b87bc76c93ae116"
},
{
"url": "https://git.kernel.org/stable/c/9a998cc1c348769262d433acb7d238c5fac4b2e0"
},
{
"url": "https://git.kernel.org/stable/c/dbaf0e0023e2f9332c5164822def7f80b7d2c5ef"
},
{
"url": "https://git.kernel.org/stable/c/3068ab802fc98b121dcb451e1f7f4d338ffc7a19"
},
{
"url": "https://git.kernel.org/stable/c/b01df98a6669d2b67d8aed816021b327fd905998"
},
{
"url": "https://git.kernel.org/stable/c/afbe4bc252d90a6f8fad869b06d5430f615f22f9"
}
],
"title": "media: v4l2-ctrls: validate HEVC active reference counts",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68206",
"datePublished": "2026-08-10T12:00:25.309Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:26.837Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43206 (GCVE-0-2026-43206)
Vulnerability from cvelistv5
Published
2026-05-06 11:28
Modified
2026-08-05 12:26
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()
The kfd_event_page_set() function writes KFD_SIGNAL_EVENT_LIMIT * 8
bytes via memset without checking the buffer size parameter. This allows
unprivileged userspace to trigger an out-of bounds kernel memory write
by passing a small buffer, leading to potential privilege
escalation.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0fc8011f89feb8b2c3008583b777d097e1974660 Version: 0fc8011f89feb8b2c3008583b777d097e1974660 Version: 0fc8011f89feb8b2c3008583b777d097e1974660 Version: 0fc8011f89feb8b2c3008583b777d097e1974660 Version: 0fc8011f89feb8b2c3008583b777d097e1974660 Version: 0fc8011f89feb8b2c3008583b777d097e1974660 Version: 0fc8011f89feb8b2c3008583b777d097e1974660 Version: 0fc8011f89feb8b2c3008583b777d097e1974660 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3e04bc310d80b46eaf481f1fefcbcb37a187412d",
"status": "affected",
"version": "0fc8011f89feb8b2c3008583b777d097e1974660",
"versionType": "git"
},
{
"lessThan": "de8d7a25cd2eb5875b1d8d4fbc7fe4b4138b781f",
"status": "affected",
"version": "0fc8011f89feb8b2c3008583b777d097e1974660",
"versionType": "git"
},
{
"lessThan": "b4034442cb090e4a980bdcc1540948606cbc951b",
"status": "affected",
"version": "0fc8011f89feb8b2c3008583b777d097e1974660",
"versionType": "git"
},
{
"lessThan": "4857c37c7ba9aa38b9a4c694e8bd8d0091c87940",
"status": "affected",
"version": "0fc8011f89feb8b2c3008583b777d097e1974660",
"versionType": "git"
},
{
"lessThan": "75fb57efdd7863fffbc39db23e9cad7aafda26ed",
"status": "affected",
"version": "0fc8011f89feb8b2c3008583b777d097e1974660",
"versionType": "git"
},
{
"lessThan": "bfcd6b53e1f4feb182952f4ff9a137c36ceaf20b",
"status": "affected",
"version": "0fc8011f89feb8b2c3008583b777d097e1974660",
"versionType": "git"
},
{
"lessThan": "4e72f419e4ed44cb3b60506752d8688c20a60a9b",
"status": "affected",
"version": "0fc8011f89feb8b2c3008583b777d097e1974660",
"versionType": "git"
},
{
"lessThan": "8a70a26c9f34baea6c3199a9862ddaff4554a96d",
"status": "affected",
"version": "0fc8011f89feb8b2c3008583b777d097e1974660",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.252",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.202",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.252",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.202",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()\n\nThe kfd_event_page_set() function writes KFD_SIGNAL_EVENT_LIMIT * 8\nbytes via memset without checking the buffer size parameter. This allows\nunprivileged userspace to trigger an out-of bounds kernel memory write\nby passing a small buffer, leading to potential privilege\nescalation."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached through local `/dev/kfd` ioctls, specifically allocating a KFD GPU memory object and passing its handle as `event_page_offset` to `AMDKFD_IOC_CREATE_EVENT`. There is no network, adjacent, or physical packet/device-input path.\nAC:L - The attacker controls the supplied event-page handle and can allocate a buffer smaller than `KFD_SIGNAL_EVENT_LIMIT * 8`, making the fixed-size `memset` out-of-bounds deterministic. No race or external condition is required.\nPR:L - The path is available to unprivileged userspace with access to KFD/AMDGPU device nodes, and the relevant ioctls have no capability flag or `capable()` gate. This is low privilege, not real administrator privilege.\nUI:N - Once a local attacker can execute code and open the device, exploitation only requires issuing ioctls. No victim user action is needed.\nS:U - The corruption occurs inside the kernel driver and impacts the same kernel security authority. This is standard local kernel compromise/DoS, not a cross-scope escape such as guest-to-host or IOMMU boundary bypass.\nC:H - The bug is an out-of-bounds kernel write into memory adjacent to a kernel-mapped GPU buffer, and kernel memory corruption can reasonably be leveraged to disclose sensitive kernel memory. Following the higher-severity rule for memory corruption, confidentiality impact is High.\nI:H - The vulnerable `memset` writes attacker-triggered data beyond the allocated object, giving a kernel memory corruption primitive. Out-of-bounds writes are scored as High integrity impact because they can plausibly be developed into privilege escalation or control-flow/data corruption.\nA:H - The out-of-bounds kernel write can corrupt adjacent kernel memory and readily crash or destabilize the kernel even without full exploitation. Kernel oops, panic, or persistent GPU/kernel failure is a High availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:26:33.242Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3e04bc310d80b46eaf481f1fefcbcb37a187412d"
},
{
"url": "https://git.kernel.org/stable/c/de8d7a25cd2eb5875b1d8d4fbc7fe4b4138b781f"
},
{
"url": "https://git.kernel.org/stable/c/b4034442cb090e4a980bdcc1540948606cbc951b"
},
{
"url": "https://git.kernel.org/stable/c/4857c37c7ba9aa38b9a4c694e8bd8d0091c87940"
},
{
"url": "https://git.kernel.org/stable/c/75fb57efdd7863fffbc39db23e9cad7aafda26ed"
},
{
"url": "https://git.kernel.org/stable/c/bfcd6b53e1f4feb182952f4ff9a137c36ceaf20b"
},
{
"url": "https://git.kernel.org/stable/c/4e72f419e4ed44cb3b60506752d8688c20a60a9b"
},
{
"url": "https://git.kernel.org/stable/c/8a70a26c9f34baea6c3199a9862ddaff4554a96d"
}
],
"title": "drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43206",
"datePublished": "2026-05-06T11:28:10.937Z",
"dateReserved": "2026-05-01T14:12:55.993Z",
"dateUpdated": "2026-08-05T12:26:33.242Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64192 (GCVE-0-2026-64192)
Vulnerability from cvelistv5
Published
2026-07-20 16:27
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
When CONFIG_BPF_LSM=y is set, BPF inode storage maps
(BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However,
if the BPF LSM is not explicitly enabled at boot time (e.g. omitted
from the "lsm=" boot parameter), lsm_prepare() is never executed for
the BPF LSM.
Consequently, the BPF inode security blob offset
(bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains at
its default compiled size of 8 bytes instead of being updated to a
valid offset past the reserved struct rcu_head (typically 16 bytes
or more).
When a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGE
map, bpf_inode() evaluates inode->i_security + 8. This erroneously
aliases the struct rcu_head.func callback pointer at the beginning
of the inode->i_security blob. During subsequent map element cleanup
or inode destruction, writing NULL to owner_storage clears the queued
RCU callback pointer. When rcu_do_batch() later executes the queued
callback, it attempts an instruction fetch at address 0x0, triggering
an immediate kernel panic.
Fix this by introducing a global bpf_lsm_initialized boolean flag
marked with __ro_after_init. Set this flag to true inside bpf_lsm_init()
when the LSM framework successfully registers the BPF LSM. Gate map
allocation in inode_storage_map_alloc() on this flag, returning
-EOPNOTSUPP if the BPF LSM is in turn uninitialized.
This fail-fast approach prevents userspace from allocating inode
storage maps when the supporting BPF LSM infrastructure is absent,
avoiding zombie map states.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/bpf_lsm.h",
"kernel/bpf/bpf_inode_storage.c",
"security/bpf/hooks.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "413b14b9623a2e6ee131c2b2152b304aeb04e378",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "a6d634f794c808a261eac7d5af023a7e06b9ecd8",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "721f669853bdbf46b475a81bb5d05d610f8c19de",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "5337eebdf8c5d4810b1913047f078d2815d5645f",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "de984ea883405420fdc416ae8964b752df586970",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "267fdd9b6530c399dfd996e1a0a7628b45baf9f0",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "c76b8abce575e0c6e4096957220b4515ed847d89",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "a6f0643e4f63cfaa0d5d4a69de4f132eac4b8fe4",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/bpf_lsm.h",
"kernel/bpf/bpf_inode_storage.c",
"security/bpf/hooks.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized\n\nWhen CONFIG_BPF_LSM=y is set, BPF inode storage maps\n(BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However,\nif the BPF LSM is not explicitly enabled at boot time (e.g. omitted\nfrom the \"lsm=\" boot parameter), lsm_prepare() is never executed for\nthe BPF LSM.\n\nConsequently, the BPF inode security blob offset\n(bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains at\nits default compiled size of 8 bytes instead of being updated to a\nvalid offset past the reserved struct rcu_head (typically 16 bytes\nor more).\n\nWhen a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGE\nmap, bpf_inode() evaluates inode-\u003ei_security + 8. This erroneously\naliases the struct rcu_head.func callback pointer at the beginning\nof the inode-\u003ei_security blob. During subsequent map element cleanup\nor inode destruction, writing NULL to owner_storage clears the queued\nRCU callback pointer. When rcu_do_batch() later executes the queued\ncallback, it attempts an instruction fetch at address 0x0, triggering\nan immediate kernel panic.\n\nFix this by introducing a global bpf_lsm_initialized boolean flag\nmarked with __ro_after_init. Set this flag to true inside bpf_lsm_init()\nwhen the LSM framework successfully registers the BPF LSM. Gate map\nallocation in inode_storage_map_alloc() on this flag, returning\n-EOPNOTSUPP if the BPF LSM is in turn uninitialized.\n\nThis fail-fast approach prevents userspace from allocating inode\nstorage maps when the supporting BPF LSM infrastructure is absent,\navoiding zombie map states."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:34.754Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/413b14b9623a2e6ee131c2b2152b304aeb04e378"
},
{
"url": "https://git.kernel.org/stable/c/a6d634f794c808a261eac7d5af023a7e06b9ecd8"
},
{
"url": "https://git.kernel.org/stable/c/721f669853bdbf46b475a81bb5d05d610f8c19de"
},
{
"url": "https://git.kernel.org/stable/c/5337eebdf8c5d4810b1913047f078d2815d5645f"
},
{
"url": "https://git.kernel.org/stable/c/de984ea883405420fdc416ae8964b752df586970"
},
{
"url": "https://git.kernel.org/stable/c/267fdd9b6530c399dfd996e1a0a7628b45baf9f0"
},
{
"url": "https://git.kernel.org/stable/c/c76b8abce575e0c6e4096957220b4515ed847d89"
},
{
"url": "https://git.kernel.org/stable/c/a6f0643e4f63cfaa0d5d4a69de4f132eac4b8fe4"
}
],
"title": "bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64192",
"datePublished": "2026-07-20T16:27:51.720Z",
"dateReserved": "2026-07-19T07:54:57.040Z",
"dateUpdated": "2026-08-23T12:45:34.754Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68269 (GCVE-0-2026-68269)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Add missing nospec on parallel submit slot
Add missing Spectre mitigation for userspace controlled parallel
submission slot.
Discovered using AI-assisted static analysis confirmed by Intel
Product Security.
(cherry picked from commit 15b9353deff3cf72331c387780de3cf9c316b643)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0ac3bab10c62997727a0a90f819a27d337347f93",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "4a27275d275971c9ea29d3d240ea4a224ad368a2",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "be393175306694de5da1d1a23a8ea4149baa09f1",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "45db277b2e1e34bcc99a0852026791108339ec3e",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "c41a54619e95f860bf2950dd679ab353380ecd2b",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "914a76a9f08366434bf595700f62026b7a19a9cc",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Add missing nospec on parallel submit slot\n\nAdd missing Spectre mitigation for userspace controlled parallel\nsubmission slot.\n\nDiscovered using AI-assisted static analysis confirmed by Intel\nProduct Security.\n\n(cherry picked from commit 15b9353deff3cf72331c387780de3cf9c316b643)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:30.915Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0ac3bab10c62997727a0a90f819a27d337347f93"
},
{
"url": "https://git.kernel.org/stable/c/4a27275d275971c9ea29d3d240ea4a224ad368a2"
},
{
"url": "https://git.kernel.org/stable/c/be393175306694de5da1d1a23a8ea4149baa09f1"
},
{
"url": "https://git.kernel.org/stable/c/45db277b2e1e34bcc99a0852026791108339ec3e"
},
{
"url": "https://git.kernel.org/stable/c/c41a54619e95f860bf2950dd679ab353380ecd2b"
},
{
"url": "https://git.kernel.org/stable/c/914a76a9f08366434bf595700f62026b7a19a9cc"
}
],
"title": "drm/i915/gem: Add missing nospec on parallel submit slot",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68269",
"datePublished": "2026-08-10T12:01:44.575Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-19T16:32:30.915Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68182 (GCVE-0-2026-68182)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
comedi: comedi_parport: deal with premature interrupt
Syzbot reported a general protection fault in
`comedi_get_is_subdevice_running()`, which was called from the interrupt
handler `parport_interrupt()` in the "comedi_parport" driver, but it
does not currently have a C reproducer for the problem. It's
probably due to a premature interrupt for one of two reasons:
1. The driver sets up the interrupt handler before the comedi subdevices
used by the interrupt handler have been allocated, but does not
disable the interrupt in the parallel port's CTRL register first.
2. The driver uses a user-supplied I/O port base address which Syzbot
would have supplied, but it might not be backed by real parallel port
hardware.
Change the initialization order in the driver's comedi "attach" handler
(`parport_attach()`) so that the hardware registers are initialized
before the interrupt handler is requested. This should prevent
premature interrupts occurring for real hardware.
Also add a test to the interrupt handler to ensure the comedi device is
fully attached and return early if it isn't.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/comedi/drivers/comedi_parport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6ed34611e569fc1a1169905c5228fd0eb2806c1b",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "48ef18e5eb6b8a9c546038b2ab89a841fcd97fe7",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "a88b25db815ff6edace81b0bb0f4a201133bd215",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "b061bb4dca49fd93063359d3805387235818778c",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "086a9ae3c5df63ec11033a8c0b3f6a1fd295ddd1",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "cf26dd2d841583c54a87005c4934b92fddb930c3",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "5d059ce0e6a2f6f8b97273499d47b8f917097b48",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "17221216ae8ce6a24e8a4e787382e3ebc81b88a8",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/comedi/drivers/comedi_parport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.29"
},
{
"lessThan": "2.6.29",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.29",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: comedi_parport: deal with premature interrupt\n\nSyzbot reported a general protection fault in\n`comedi_get_is_subdevice_running()`, which was called from the interrupt\nhandler `parport_interrupt()` in the \"comedi_parport\" driver, but it\ndoes not currently have a C reproducer for the problem. It\u0027s\nprobably due to a premature interrupt for one of two reasons:\n\n1. The driver sets up the interrupt handler before the comedi subdevices\n used by the interrupt handler have been allocated, but does not\n disable the interrupt in the parallel port\u0027s CTRL register first.\n2. The driver uses a user-supplied I/O port base address which Syzbot\n would have supplied, but it might not be backed by real parallel port\n hardware.\n\nChange the initialization order in the driver\u0027s comedi \"attach\" handler\n(`parport_attach()`) so that the hardware registers are initialized\nbefore the interrupt handler is requested. This should prevent\npremature interrupts occurring for real hardware.\n\nAlso add a test to the interrupt handler to ensure the comedi device is\nfully attached and return early if it isn\u0027t."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:47.491Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6ed34611e569fc1a1169905c5228fd0eb2806c1b"
},
{
"url": "https://git.kernel.org/stable/c/48ef18e5eb6b8a9c546038b2ab89a841fcd97fe7"
},
{
"url": "https://git.kernel.org/stable/c/a88b25db815ff6edace81b0bb0f4a201133bd215"
},
{
"url": "https://git.kernel.org/stable/c/b061bb4dca49fd93063359d3805387235818778c"
},
{
"url": "https://git.kernel.org/stable/c/086a9ae3c5df63ec11033a8c0b3f6a1fd295ddd1"
},
{
"url": "https://git.kernel.org/stable/c/cf26dd2d841583c54a87005c4934b92fddb930c3"
},
{
"url": "https://git.kernel.org/stable/c/5d059ce0e6a2f6f8b97273499d47b8f917097b48"
},
{
"url": "https://git.kernel.org/stable/c/17221216ae8ce6a24e8a4e787382e3ebc81b88a8"
}
],
"title": "comedi: comedi_parport: deal with premature interrupt",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68182",
"datePublished": "2026-08-10T11:59:53.793Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:47.491Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64375 (GCVE-0-2026-64375)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-09-08 08:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
proc: protect ptrace_may_access() with exec_update_lock (FD links)
proc_pid_get_link() and proc_pid_readlink() currently look up the task from
the pid once, then do the ptrace access check on that task, then look up
the task from the pid a second time to do the actual access.
That's racy in several ways.
To fix it, pass the task to the ->proc_get_link() handler, and instead of
proc_fd_access_allowed(), introduce a new helper call_proc_get_link() that
looks up and locks the task, does the access check, and calls
->proc_get_link().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 778c1144771f0064b6f51bee865cceb0d996f2f9 Version: 778c1144771f0064b6f51bee865cceb0d996f2f9 Version: 778c1144771f0064b6f51bee865cceb0d996f2f9 Version: 778c1144771f0064b6f51bee865cceb0d996f2f9 Version: 778c1144771f0064b6f51bee865cceb0d996f2f9 Version: 778c1144771f0064b6f51bee865cceb0d996f2f9 Version: 778c1144771f0064b6f51bee865cceb0d996f2f9 Version: 778c1144771f0064b6f51bee865cceb0d996f2f9 |
||
{
"containers": {
"adp": [
{
"affected": [
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.6",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T08:50:27.618Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/proc/base.c",
"fs/proc/fd.c",
"fs/proc/internal.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6253dfee5afba536bb54fc6fe6c091c3758fafe1",
"status": "affected",
"version": "778c1144771f0064b6f51bee865cceb0d996f2f9",
"versionType": "git"
},
{
"lessThan": "65bf0d2b6e914f1448d6a2fde193dcf60936a651",
"status": "affected",
"version": "778c1144771f0064b6f51bee865cceb0d996f2f9",
"versionType": "git"
},
{
"lessThan": "de497d7aa2fae453a7e7c8f7d3e8682e565e3aaf",
"status": "affected",
"version": "778c1144771f0064b6f51bee865cceb0d996f2f9",
"versionType": "git"
},
{
"lessThan": "138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2",
"status": "affected",
"version": "778c1144771f0064b6f51bee865cceb0d996f2f9",
"versionType": "git"
},
{
"lessThan": "83b17872e3166c295c599279fc9562ac3840c638",
"status": "affected",
"version": "778c1144771f0064b6f51bee865cceb0d996f2f9",
"versionType": "git"
},
{
"lessThan": "497c6bae5167428596575f20af6613ff5671f383",
"status": "affected",
"version": "778c1144771f0064b6f51bee865cceb0d996f2f9",
"versionType": "git"
},
{
"lessThan": "dfd1894cb64cbd8758b461ed713800fe73db4f82",
"status": "affected",
"version": "778c1144771f0064b6f51bee865cceb0d996f2f9",
"versionType": "git"
},
{
"lessThan": "6255da28d4bb5349fe18e84cb043ccd394eba75d",
"status": "affected",
"version": "778c1144771f0064b6f51bee865cceb0d996f2f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/proc/base.c",
"fs/proc/fd.c",
"fs/proc/internal.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.18"
},
{
"lessThan": "2.6.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nproc: protect ptrace_may_access() with exec_update_lock (FD links)\n\nproc_pid_get_link() and proc_pid_readlink() currently look up the task from\nthe pid once, then do the ptrace access check on that task, then look up\nthe task from the pid a second time to do the actual access.\nThat\u0027s racy in several ways.\n\nTo fix it, pass the task to the -\u003eproc_get_link() handler, and instead of\nproc_fd_access_allowed(), introduce a new helper call_proc_get_link() that\nlooks up and locks the task, does the access check, and calls\n-\u003eproc_get_link()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation uses local open/openat or readlink syscalls against /proc/$pid symlinks; no network or physical access path reaches the flaw.\nAC:L - The attacker can launch the setuid target process and race concurrent procfs accesses repeatedly, thereby controlling both sides of the race.\nPR:L - A basic unprivileged user can pass the initial ptrace check against a same-UID dumpable child before it performs privileged exec; no capability is required.\nUI:N - The attacker can create and race the target by launching the setuid program directly, without action from another user.\nS:U - The procfs authorization bypass compromises privileged resources on the same host and constitutes ordinary local privilege escalation rather than crossing a VM or hardware isolation boundary.\nC:H - The race can redirect an authorized pre-exec lookup to a private post-setuid memfd whose permissive shmem inode allows the attacker to read all privileged contents, including secrets.\nI:H - The attacker can obtain write and truncation access to the privileged memfd; corruption of trusted data or executable content consumed by the setuid process can yield root-level code execution.\nA:H - Tampering with a privileged process\u0027s trusted memfd can crash or disable critical privileged services, and resulting root-level execution permits complete system availability loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:54:26.202Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6253dfee5afba536bb54fc6fe6c091c3758fafe1"
},
{
"url": "https://git.kernel.org/stable/c/65bf0d2b6e914f1448d6a2fde193dcf60936a651"
},
{
"url": "https://git.kernel.org/stable/c/de497d7aa2fae453a7e7c8f7d3e8682e565e3aaf"
},
{
"url": "https://git.kernel.org/stable/c/138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2"
},
{
"url": "https://git.kernel.org/stable/c/83b17872e3166c295c599279fc9562ac3840c638"
},
{
"url": "https://git.kernel.org/stable/c/497c6bae5167428596575f20af6613ff5671f383"
},
{
"url": "https://git.kernel.org/stable/c/dfd1894cb64cbd8758b461ed713800fe73db4f82"
},
{
"url": "https://git.kernel.org/stable/c/6255da28d4bb5349fe18e84cb043ccd394eba75d"
}
],
"title": "proc: protect ptrace_may_access() with exec_update_lock (FD links)",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64375",
"datePublished": "2026-07-25T08:50:26.869Z",
"dateReserved": "2026-07-19T15:36:31.784Z",
"dateUpdated": "2026-09-08T08:50:27.618Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43163 (GCVE-0-2026-43163)
Vulnerability from cvelistv5
Published
2026-05-06 11:27
Modified
2026-05-11 22:18
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
md/bitmap: fix GPF in write_page caused by resize race
A General Protection Fault occurs in write_page() during array resize:
RIP: 0010:write_page+0x22b/0x3c0 [md_mod]
This is a use-after-free race between bitmap_daemon_work() and
__bitmap_resize(). The daemon iterates over `bitmap->storage.filemap`
without locking, while the resize path frees that storage via
md_bitmap_file_unmap(). `quiesce()` does not stop the md thread,
allowing concurrent access to freed pages.
Fix by holding `mddev->bitmap_info.mutex` during the bitmap update.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d60b479d177a5735b6b4db6ee5280ef6653f50e7 Version: d60b479d177a5735b6b4db6ee5280ef6653f50e7 Version: d60b479d177a5735b6b4db6ee5280ef6653f50e7 Version: d60b479d177a5735b6b4db6ee5280ef6653f50e7 Version: d60b479d177a5735b6b4db6ee5280ef6653f50e7 Version: d60b479d177a5735b6b4db6ee5280ef6653f50e7 Version: d60b479d177a5735b6b4db6ee5280ef6653f50e7 Version: d60b479d177a5735b6b4db6ee5280ef6653f50e7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/md-bitmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "140cc839fbeb1ddb33a8da8811b716d88d3905b7",
"status": "affected",
"version": "d60b479d177a5735b6b4db6ee5280ef6653f50e7",
"versionType": "git"
},
{
"lessThan": "ebcacc7ca22d5e8a03a970f0621ae1d1356b9ae8",
"status": "affected",
"version": "d60b479d177a5735b6b4db6ee5280ef6653f50e7",
"versionType": "git"
},
{
"lessThan": "d3af62411e19752c663fe4f424dbf49d95a4cc7c",
"status": "affected",
"version": "d60b479d177a5735b6b4db6ee5280ef6653f50e7",
"versionType": "git"
},
{
"lessThan": "d92b8fac294b5f915c50e65ce4ae2262e53614ec",
"status": "affected",
"version": "d60b479d177a5735b6b4db6ee5280ef6653f50e7",
"versionType": "git"
},
{
"lessThan": "a437e3bf30e32846079e470c1ba5ee790bccdf89",
"status": "affected",
"version": "d60b479d177a5735b6b4db6ee5280ef6653f50e7",
"versionType": "git"
},
{
"lessThan": "9a6f8cd28bb9bb6ed86a6df19331fb08016dee7f",
"status": "affected",
"version": "d60b479d177a5735b6b4db6ee5280ef6653f50e7",
"versionType": "git"
},
{
"lessThan": "5f73c8b33df9a605a591eab72d43a969600c1f8c",
"status": "affected",
"version": "d60b479d177a5735b6b4db6ee5280ef6653f50e7",
"versionType": "git"
},
{
"lessThan": "46ef85f854dfa9d5226b3c1c46493d79556c9589",
"status": "affected",
"version": "d60b479d177a5735b6b4db6ee5280ef6653f50e7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/md-bitmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.252",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.202",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.252",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.202",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/bitmap: fix GPF in write_page caused by resize race\n\nA General Protection Fault occurs in write_page() during array resize:\nRIP: 0010:write_page+0x22b/0x3c0 [md_mod]\n\nThis is a use-after-free race between bitmap_daemon_work() and\n__bitmap_resize(). The daemon iterates over `bitmap-\u003estorage.filemap`\nwithout locking, while the resize path frees that storage via\nmd_bitmap_file_unmap(). `quiesce()` does not stop the md thread,\nallowing concurrent access to freed pages.\n\nFix by holding `mddev-\u003ebitmap_info.mutex` during the bitmap update."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:18:58.873Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/140cc839fbeb1ddb33a8da8811b716d88d3905b7"
},
{
"url": "https://git.kernel.org/stable/c/ebcacc7ca22d5e8a03a970f0621ae1d1356b9ae8"
},
{
"url": "https://git.kernel.org/stable/c/d3af62411e19752c663fe4f424dbf49d95a4cc7c"
},
{
"url": "https://git.kernel.org/stable/c/d92b8fac294b5f915c50e65ce4ae2262e53614ec"
},
{
"url": "https://git.kernel.org/stable/c/a437e3bf30e32846079e470c1ba5ee790bccdf89"
},
{
"url": "https://git.kernel.org/stable/c/9a6f8cd28bb9bb6ed86a6df19331fb08016dee7f"
},
{
"url": "https://git.kernel.org/stable/c/5f73c8b33df9a605a591eab72d43a969600c1f8c"
},
{
"url": "https://git.kernel.org/stable/c/46ef85f854dfa9d5226b3c1c46493d79556c9589"
}
],
"title": "md/bitmap: fix GPF in write_page caused by resize race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43163",
"datePublished": "2026-05-06T11:27:41.265Z",
"dateReserved": "2026-05-01T14:12:55.990Z",
"dateUpdated": "2026-05-11T22:18:58.873Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64478 (GCVE-0-2026-64478)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-17 04:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: avoid kobject path lookup in DualSense match
The DualSense jack-detection input handler verifies that a matching input
device belongs to the same physical controller by building kobject path
strings for both the input device and the USB audio device, then comparing
the path prefix.
This was observed when a weak physical connection caused the controller
to rapidly disconnect and reconnect. During that repeated hotplug,
snd_dualsense_ih_match() can run while the controller's USB device is
being disconnected. kobject_get_path() walks ancestor kobjects and
dereferences their names; if the USB device kobject name is no longer
valid, this can fault in strlen():
RIP: 0010:strlen+0x10/0x30
Call Trace:
kobject_get_path+0x34/0x150
snd_dualsense_ih_match+0x49/0xd0 [snd_usb_audio]
input_register_device+0x566/0x6a0
ps_probe+0xb89/0x1590 [hid_playstation]
The same ownership check can be done without building kobject path
strings. The input device is parented below the HID device, USB interface
and USB device, so walking the input device parent chain and comparing
against the mixer USB device preserves the check without dereferencing
kobject names during disconnect.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0b0264009596c07a77d82808b0dae72bc04ac5c Version: b4b94f092f193d7a2db8e82af5e51519ae89963c Version: c2d5b0a6c688ffb32c35627e337fbbcc65bc275f Version: d04d301614630724feb4048bf17432fc7964fe74 Version: a705899ec6085b12a33aa0fd94a58e82e9e90502 Version: 79d561c4ec0497669f19a9550cfb74812f60938b Version: 79d561c4ec0497669f19a9550cfb74812f60938b Version: 79d561c4ec0497669f19a9550cfb74812f60938b Version: 104ad9bae11ee450fb7d0595ff7876cfb6527838 Version: 0105cfc41abeb428d4405951a20e1e239bea5e1d Version: 5.10.245 ≤ Version: 5.15.194 ≤ Version: 6.1.155 ≤ Version: 6.6.109 ≤ Version: 6.12.50 ≤ Version: 5.4.300 ≤ Version: 6.16.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/usb/mixer_quirks.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e4c66a149c408e44e60bfec3fabf08b6b7abbc60",
"status": "affected",
"version": "d0b0264009596c07a77d82808b0dae72bc04ac5c",
"versionType": "git"
},
{
"lessThan": "4566bf8ae9dbfe81bdc2ff1702d59db8a233b06e",
"status": "affected",
"version": "b4b94f092f193d7a2db8e82af5e51519ae89963c",
"versionType": "git"
},
{
"lessThan": "662a1d7b5affc424ea4f4bc20dd99be29e687886",
"status": "affected",
"version": "c2d5b0a6c688ffb32c35627e337fbbcc65bc275f",
"versionType": "git"
},
{
"lessThan": "a47ecd904c51ae6a42957feb3cf2f4266adee2e5",
"status": "affected",
"version": "d04d301614630724feb4048bf17432fc7964fe74",
"versionType": "git"
},
{
"lessThan": "c1da6d3f45036fa63672ee04ad97cb526b40b987",
"status": "affected",
"version": "a705899ec6085b12a33aa0fd94a58e82e9e90502",
"versionType": "git"
},
{
"lessThan": "a263eb12cbe2e208e6e637df0f9b0be9a484158e",
"status": "affected",
"version": "79d561c4ec0497669f19a9550cfb74812f60938b",
"versionType": "git"
},
{
"lessThan": "4246dd043b7a4f8e3bc1d2896e81d11220610eda",
"status": "affected",
"version": "79d561c4ec0497669f19a9550cfb74812f60938b",
"versionType": "git"
},
{
"lessThan": "7693c0cc415f3a16a7a3355f245474a5e661be4e",
"status": "affected",
"version": "79d561c4ec0497669f19a9550cfb74812f60938b",
"versionType": "git"
},
{
"status": "affected",
"version": "104ad9bae11ee450fb7d0595ff7876cfb6527838",
"versionType": "git"
},
{
"status": "affected",
"version": "0105cfc41abeb428d4405951a20e1e239bea5e1d",
"versionType": "git"
},
{
"lessThan": "5.10.261",
"status": "affected",
"version": "5.10.245",
"versionType": "semver"
},
{
"lessThan": "5.15.212",
"status": "affected",
"version": "5.15.194",
"versionType": "semver"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.155",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.109",
"versionType": "semver"
},
{
"lessThan": "6.12.96",
"status": "affected",
"version": "6.12.50",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.300",
"versionType": "semver"
},
{
"lessThan": "6.17",
"status": "affected",
"version": "6.16.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/usb/mixer_quirks.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"lessThan": "6.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.10.245",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.15.194",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.155",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.109",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.12.50",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.300",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.16.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: avoid kobject path lookup in DualSense match\n\nThe DualSense jack-detection input handler verifies that a matching input\ndevice belongs to the same physical controller by building kobject path\nstrings for both the input device and the USB audio device, then comparing\nthe path prefix.\n\nThis was observed when a weak physical connection caused the controller\nto rapidly disconnect and reconnect. During that repeated hotplug,\nsnd_dualsense_ih_match() can run while the controller\u0027s USB device is\nbeing disconnected. kobject_get_path() walks ancestor kobjects and\ndereferences their names; if the USB device kobject name is no longer\nvalid, this can fault in strlen():\n\n RIP: 0010:strlen+0x10/0x30\n Call Trace:\n kobject_get_path+0x34/0x150\n snd_dualsense_ih_match+0x49/0xd0 [snd_usb_audio]\n input_register_device+0x566/0x6a0\n ps_probe+0xb89/0x1590 [hid_playstation]\n\nThe same ownership check can be done without building kobject path\nstrings. The input device is parented below the HID device, USB interface\nand USB device, so walking the input device parent chain and comparing\nagainst the mixer USB device preserves the check without dereferencing\nkobject names during disconnect."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:56:24.788Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e4c66a149c408e44e60bfec3fabf08b6b7abbc60"
},
{
"url": "https://git.kernel.org/stable/c/4566bf8ae9dbfe81bdc2ff1702d59db8a233b06e"
},
{
"url": "https://git.kernel.org/stable/c/662a1d7b5affc424ea4f4bc20dd99be29e687886"
},
{
"url": "https://git.kernel.org/stable/c/a47ecd904c51ae6a42957feb3cf2f4266adee2e5"
},
{
"url": "https://git.kernel.org/stable/c/c1da6d3f45036fa63672ee04ad97cb526b40b987"
},
{
"url": "https://git.kernel.org/stable/c/a263eb12cbe2e208e6e637df0f9b0be9a484158e"
},
{
"url": "https://git.kernel.org/stable/c/4246dd043b7a4f8e3bc1d2896e81d11220610eda"
},
{
"url": "https://git.kernel.org/stable/c/7693c0cc415f3a16a7a3355f245474a5e661be4e"
}
],
"title": "ALSA: usb-audio: avoid kobject path lookup in DualSense match",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64478",
"datePublished": "2026-07-25T08:51:40.299Z",
"dateReserved": "2026-07-19T15:36:31.791Z",
"dateUpdated": "2026-08-17T04:56:24.788Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68246 (GCVE-0-2026-68246)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit daa62107452d2451787c4248ca38fa2d1a0cbefd)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cac8002c675eda7d0d567871287201932857576c",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "96b6d68f2b5a208e4d8f1e4a932ec424655e1267",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "7aeef42b657d930f3b639220e62120ac1bf058a1",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "dfd9bf09fd8fe81f113a5c7e88bfd99f2499542f",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "625f301e01bf89694466fdaa1f9904e2c62eb8f2",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "0eebcab1ea2a77f086a04108f386f82ee3496022",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit daa62107452d2451787c4248ca38fa2d1a0cbefd)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:13.526Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cac8002c675eda7d0d567871287201932857576c"
},
{
"url": "https://git.kernel.org/stable/c/96b6d68f2b5a208e4d8f1e4a932ec424655e1267"
},
{
"url": "https://git.kernel.org/stable/c/7aeef42b657d930f3b639220e62120ac1bf058a1"
},
{
"url": "https://git.kernel.org/stable/c/dfd9bf09fd8fe81f113a5c7e88bfd99f2499542f"
},
{
"url": "https://git.kernel.org/stable/c/625f301e01bf89694466fdaa1f9904e2c62eb8f2"
},
{
"url": "https://git.kernel.org/stable/c/0eebcab1ea2a77f086a04108f386f82ee3496022"
}
],
"title": "drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68246",
"datePublished": "2026-08-10T12:01:12.489Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:13.526Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68335 (GCVE-0-2026-68335)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rds: drop incoming messages that cross network namespace boundaries
rds_find_bound() looks up the destination socket using a global
rhashtable keyed solely on (addr, port, scope_id). Network namespaces
are not part of the key, so a sender in netns A can deliver an incoming
message (inc) to a socket that lives in a different netns B.
When this happens, inc->i_conn points to an rds_connection whose c_net
is netns A, but the receiving rs lives in netns B. Once the child
process that created netns A exits, cleanup_net() calls
rds_loop_exit_net() -> rds_loop_kill_conns() -> rds_conn_destroy(),
freeing that connection. If the survivor socket in netns B still holds
the inc, any subsequent dereference of inc->i_conn is a use-after-free.
There are two dangerous sites in rds_clear_recv_queue():
1. inc->i_conn->c_lcong (offset 88 of freed rds_connection, size 200)
read via rds_recv_rcvbuf_delta() -- confirmed by KASAN.
2. inc->i_conn->c_trans->inc_free(inc) (function pointer at offset 80)
called via rds_inc_put() when the inc refcount reaches zero -- same
race window, potential call-through-freed-object primitive.
The bug is reachable from unprivileged user namespaces
(CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8.
Fix this by rejecting the delivery in rds_recv_incoming() when the
socket returned by rds_find_bound() belongs to a different network
namespace than the connection that carried the message. Use the
existing rds_conn_net() / sock_net() helpers and net_eq() for the
comparison.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c827073c95fde388bc65fe5227f944eaf859b9f0 Version: 4.17.19 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rds/recv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "742ff6f02545212e991cd8b45011e40d2c2ef25a",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "abff41fd928328bbf3dda1140beb2e61fa424ccd",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "03c574112e5d066df0ddce36d7438e850bcf3050",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "1e2e2d9806944fe485824d617c8b7c78116c22db",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "cfb3ce07b705e486e022a2f2b1242b48f13981ff",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "9591042533140dfe6608d9344806d567dcd39d02",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "0f8690e3869109cd5803ccb400889d20a0b54e0e",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "5521ae71e32a8069ed4ca6e792179dc57bc43ab2",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"status": "affected",
"version": "c827073c95fde388bc65fe5227f944eaf859b9f0",
"versionType": "git"
},
{
"lessThan": "4.18",
"status": "affected",
"version": "4.17.19",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rds/recv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.17.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrds: drop incoming messages that cross network namespace boundaries\n\nrds_find_bound() looks up the destination socket using a global\nrhashtable keyed solely on (addr, port, scope_id). Network namespaces\nare not part of the key, so a sender in netns A can deliver an incoming\nmessage (inc) to a socket that lives in a different netns B.\n\nWhen this happens, inc-\u003ei_conn points to an rds_connection whose c_net\nis netns A, but the receiving rs lives in netns B. Once the child\nprocess that created netns A exits, cleanup_net() calls\nrds_loop_exit_net() -\u003e rds_loop_kill_conns() -\u003e rds_conn_destroy(),\nfreeing that connection. If the survivor socket in netns B still holds\nthe inc, any subsequent dereference of inc-\u003ei_conn is a use-after-free.\n\nThere are two dangerous sites in rds_clear_recv_queue():\n 1. inc-\u003ei_conn-\u003ec_lcong (offset 88 of freed rds_connection, size 200)\n read via rds_recv_rcvbuf_delta() -- confirmed by KASAN.\n 2. inc-\u003ei_conn-\u003ec_trans-\u003einc_free(inc) (function pointer at offset 80)\n called via rds_inc_put() when the inc refcount reaches zero -- same\n race window, potential call-through-freed-object primitive.\n\nThe bug is reachable from unprivileged user namespaces\n(CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8.\n\nFix this by rejecting the delivery in rds_recv_incoming() when the\nsocket returned by rds_find_bound() belongs to a different network\nnamespace than the connection that carried the message. Use the\nexisting rds_conn_net() / sock_net() helpers and net_eq() for the\ncomparison."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscall access: the attacker must create RDS sockets and a network namespace (CLONE_NEWUSER|CLONE_NEWNET), then trigger namespace teardown to free the connection. A remote RDS peer cannot drive the netns-destruction half of the sequence, so the vulnerability is reachable only locally.\nAC:L - The attacker controls the entire sequence deterministically \u2014 bind a socket in one netns, send a loopback RDS message from a second netns so the inc is queued cross-netns, then exit that netns to free inc-\u003ei_conn. No race must be won and no uncontrollable precondition exists; the UAF is confirmed reproducible under KASAN.\nPR:L - Only an unprivileged local user account is required; the needed CAP_NET_ADMIN for creating and configuring the second network namespace is obtained inside a user namespace the attacker owns, as the commit explicitly notes (\"reachable from unprivileged user namespaces\").\nUI:N - The attacker performs every step \u2014 socket creation, cross-netns send, namespace teardown, and the subsequent read/close that dereferences the freed connection \u2014 with no action from any other user or administrator.\nS:U - The use-after-free corrupts kernel memory within the same kernel security authority; there is no crossing of a hypervisor, IOMMU, or comparable trust boundary.\nC:H - The stale inc-\u003ei_conn is dereferenced to read c_lcong from a freed 200-byte rds_connection, and the freed slot can be reclaimed with attacker-groomed data, giving a use-after-free read primitive usable to disclose kernel memory contents.\nI:H - rds_inc_put() calls inc-\u003ei_conn-\u003ec_trans-\u003einc_free(inc) through a function pointer at offset 80 of the freed object \u2014 an indirect call through freed memory that the commit calls a \"call-through-freed-object primitive\", which after heap reclamation is a control-flow hijack path leading to arbitrary kernel modification.\nA:H - Dereferencing the freed rds_connection in rds_clear_recv_queue() and calling through its freed transport vtable reliably corrupts kernel state and panics the machine (KASAN-confirmed use-after-free), causing a full denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:33.100Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/742ff6f02545212e991cd8b45011e40d2c2ef25a"
},
{
"url": "https://git.kernel.org/stable/c/abff41fd928328bbf3dda1140beb2e61fa424ccd"
},
{
"url": "https://git.kernel.org/stable/c/03c574112e5d066df0ddce36d7438e850bcf3050"
},
{
"url": "https://git.kernel.org/stable/c/1e2e2d9806944fe485824d617c8b7c78116c22db"
},
{
"url": "https://git.kernel.org/stable/c/cfb3ce07b705e486e022a2f2b1242b48f13981ff"
},
{
"url": "https://git.kernel.org/stable/c/9591042533140dfe6608d9344806d567dcd39d02"
},
{
"url": "https://git.kernel.org/stable/c/0f8690e3869109cd5803ccb400889d20a0b54e0e"
},
{
"url": "https://git.kernel.org/stable/c/5521ae71e32a8069ed4ca6e792179dc57bc43ab2"
}
],
"title": "rds: drop incoming messages that cross network namespace boundaries",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68335",
"datePublished": "2026-08-10T12:03:11.547Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:33.100Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74577 (GCVE-0-2026-74577)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mpls: initialize rtm_tos in mpls_getroute()
mpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE
request by filling a struct rtmsg allocated from an skb whose data
area is not zeroed (alloc_skb(NLMSG_GOODSIZE, ...)). It sets every
field of the header except rtm_tos:
r = nlmsg_data(nlh);
r->rtm_family = AF_MPLS;
r->rtm_dst_len = 20;
r->rtm_src_len = 0;
r->rtm_table = RT_TABLE_MAIN;
r->rtm_type = RTN_UNICAST;
r->rtm_scope = RT_SCOPE_UNIVERSE;
r->rtm_protocol = rt->rt_protocol;
r->rtm_flags = 0;
struct rtmsg has no padding, so the one uninitialised byte rtm_tos
(offset 3) is copied straight to user space on recvmsg(), leaking a
byte of uninitialised heap memory. This is in contrast to
mpls_dump_route(), which fills the very same header and does set
rtm_tos = 0.
Initialize rtm_tos to 0, matching mpls_dump_route().
Reproduced with KMSAN by adding an MPLS route and issuing a
non-RTM_F_FIB_MATCH RTM_GETROUTE for its label:
BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x36c/0x33f0
_copy_to_iter+0x36c/0x33f0
__skb_datagram_iter+0x196/0x12c0
skb_copy_datagram_iter+0x5b/0x210
netlink_recvmsg+0x37b/0xef0
...
Uninit was created at:
__alloc_skb+0x8ca/0x10e0
mpls_getroute+0x1280/0x3a40
rtnetlink_rcv_msg+0x1138/0x15a0
...
Byte 19 of 64 is uninitialized
(byte 19 = nlmsghdr(16) + rtmsg offset 3 = rtm_tos)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mpls/af_mpls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "248718fd88b146d8bdc7610ecd1eb4cd16e0b5a1",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "466b474a8deb0c93b5280c6d261e5eda6482eca7",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "ba56f88aab18d982f2a21f11390f4d8a8897782a",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "95651461cf77cc6590fa08c87667717e5dcfa55d",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "1fea5ff0eb4aa7e951bb3d380248566c473aa377",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "a5cdd2407dd890f741f59b8367e4c6c101cce154",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "2dc2fffc704a4365cae1aae078ba62223aaeff93",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "295dd295e2137e10e9a5b1891d97e0f08de76f03",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mpls/af_mpls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mpls: initialize rtm_tos in mpls_getroute()\n\nmpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE\nrequest by filling a struct rtmsg allocated from an skb whose data\narea is not zeroed (alloc_skb(NLMSG_GOODSIZE, ...)). It sets every\nfield of the header except rtm_tos:\n\n\tr = nlmsg_data(nlh);\n\tr-\u003ertm_family\t = AF_MPLS;\n\tr-\u003ertm_dst_len\t= 20;\n\tr-\u003ertm_src_len\t= 0;\n\tr-\u003ertm_table\t= RT_TABLE_MAIN;\n\tr-\u003ertm_type\t= RTN_UNICAST;\n\tr-\u003ertm_scope\t= RT_SCOPE_UNIVERSE;\n\tr-\u003ertm_protocol = rt-\u003ert_protocol;\n\tr-\u003ertm_flags\t= 0;\n\nstruct rtmsg has no padding, so the one uninitialised byte rtm_tos\n(offset 3) is copied straight to user space on recvmsg(), leaking a\nbyte of uninitialised heap memory. This is in contrast to\nmpls_dump_route(), which fills the very same header and does set\nrtm_tos = 0.\n\nInitialize rtm_tos to 0, matching mpls_dump_route().\n\nReproduced with KMSAN by adding an MPLS route and issuing a\nnon-RTM_F_FIB_MATCH RTM_GETROUTE for its label:\n\n BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x36c/0x33f0\n _copy_to_iter+0x36c/0x33f0\n __skb_datagram_iter+0x196/0x12c0\n skb_copy_datagram_iter+0x5b/0x210\n netlink_recvmsg+0x37b/0xef0\n ...\n Uninit was created at:\n __alloc_skb+0x8ca/0x10e0\n mpls_getroute+0x1280/0x3a40\n rtnetlink_rcv_msg+0x1138/0x15a0\n ...\n Byte 19 of 64 is uninitialized\n\n(byte 19 = nlmsghdr(16) + rtmsg offset 3 = rtm_tos)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:39:14.107Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/248718fd88b146d8bdc7610ecd1eb4cd16e0b5a1"
},
{
"url": "https://git.kernel.org/stable/c/466b474a8deb0c93b5280c6d261e5eda6482eca7"
},
{
"url": "https://git.kernel.org/stable/c/ba56f88aab18d982f2a21f11390f4d8a8897782a"
},
{
"url": "https://git.kernel.org/stable/c/95651461cf77cc6590fa08c87667717e5dcfa55d"
},
{
"url": "https://git.kernel.org/stable/c/1fea5ff0eb4aa7e951bb3d380248566c473aa377"
},
{
"url": "https://git.kernel.org/stable/c/a5cdd2407dd890f741f59b8367e4c6c101cce154"
},
{
"url": "https://git.kernel.org/stable/c/2dc2fffc704a4365cae1aae078ba62223aaeff93"
},
{
"url": "https://git.kernel.org/stable/c/295dd295e2137e10e9a5b1891d97e0f08de76f03"
}
],
"title": "net: mpls: initialize rtm_tos in mpls_getroute()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74577",
"datePublished": "2026-08-15T12:28:14.408Z",
"dateReserved": "2026-08-15T05:44:03.917Z",
"dateUpdated": "2026-08-19T16:39:14.107Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64333 (GCVE-0-2026-64333)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: digi_acceleport: fix write buffer corruption
The digi_write_inb_command() is supposed to wait for the write urb to
become available or return an error, but instead it updates the transfer
buffer and tries to resubmit the urb on timeout.
To make things worse, for commands like break control where no timeout
is used, the driver would corrupt the urb immediately due to a broken
jiffies comparison (on 32-bit machines this takes five minutes of uptime
to trigger due to INITIAL_JIFFIES).
Fix this by adding the missing return on timeout and waiting
indefinitely when no timeout has been specified as intended.
This issue was (sort of) flagged by Sashiko when reviewing an unrelated
change to the driver.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/digi_acceleport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5d9dc88bdf8897788b0eed57113e9eca7fd42ea9",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2f296974acc279f05f284441bfe3064074958d11",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e60e4873e9178da9f4f2674e4c2ff085d5a84f79",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "699dfb6917503b3cda4d5da6941cf79c3c1b4c8b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a274b3794fe1852c3d9fe6d900b94053c0b03410",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1243f120790042c2ac92e84e797dacc75fff4366",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a3a13fdc53103b07335918e2cdeb465038a71725",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "24ca1fea8f2753bf33e1d458ec1ae5d9b7796a65",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/digi_acceleport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: digi_acceleport: fix write buffer corruption\n\nThe digi_write_inb_command() is supposed to wait for the write urb to\nbecome available or return an error, but instead it updates the transfer\nbuffer and tries to resubmit the urb on timeout.\n\nTo make things worse, for commands like break control where no timeout\nis used, the driver would corrupt the urb immediately due to a broken\njiffies comparison (on 32-bit machines this takes five minutes of uptime\nto trigger due to INITIAL_JIFFIES).\n\nFix this by adding the missing return on timeout and waiting\nindefinitely when no timeout has been specified as intended.\n\nThis issue was (sort of) flagged by Sashiko when reviewing an unrelated\nchange to the driver."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is reached locally through write() followed by ioctl(TIOCCBRK) on an open Digi ttyUSB device; the attached adapter is a platform prerequisite rather than the attack entry point.\nAC:L - The attacker controls both URB submission and the competing break command and can repeat the sequence or stall transmission to widen the window. No uncontrollable race or memory layout is required.\nPR:L - No capability check exists in the ioctl path; the attacker only needs ordinary user-level permission to access the tty device node.\nUI:N - The attacker can open, write to, and issue the ioctl without another user performing any action.\nS:U - Compromise remains within the host kernel\u0027s security authority and is a standard local kernel privilege escalation rather than a VM, IOMMU, or distinct-scope escape.\nC:H - On controller-local-memory HCDs, the changed length can make USB completion restore the transfer-buffer pointer from attacker-controlled payload bytes. The resulting kernel-write and code-execution primitive can expose arbitrary kernel memory.\nI:H - A subsequent tty write dereferences the attacker-selected transfer-buffer pointer, providing an attacker-directed kernel overwrite with largely controlled contents. This can corrupt control data and plausibly achieve kernel code execution.\nA:H - The corrupted kernel pointer can immediately cause an oops or panic, while exploitation of the arbitrary overwrite can crash or hang the entire kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:36.100Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5d9dc88bdf8897788b0eed57113e9eca7fd42ea9"
},
{
"url": "https://git.kernel.org/stable/c/2f296974acc279f05f284441bfe3064074958d11"
},
{
"url": "https://git.kernel.org/stable/c/e60e4873e9178da9f4f2674e4c2ff085d5a84f79"
},
{
"url": "https://git.kernel.org/stable/c/699dfb6917503b3cda4d5da6941cf79c3c1b4c8b"
},
{
"url": "https://git.kernel.org/stable/c/a274b3794fe1852c3d9fe6d900b94053c0b03410"
},
{
"url": "https://git.kernel.org/stable/c/1243f120790042c2ac92e84e797dacc75fff4366"
},
{
"url": "https://git.kernel.org/stable/c/a3a13fdc53103b07335918e2cdeb465038a71725"
},
{
"url": "https://git.kernel.org/stable/c/24ca1fea8f2753bf33e1d458ec1ae5d9b7796a65"
}
],
"title": "USB: serial: digi_acceleport: fix write buffer corruption",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64333",
"datePublished": "2026-07-25T08:49:59.616Z",
"dateReserved": "2026-07-19T15:36:31.781Z",
"dateUpdated": "2026-08-17T04:53:36.100Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68194 (GCVE-0-2026-68194)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and
mt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus.
mt7921_mac_tx_free() cleans the DMA tx queues with
mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the
mmio queue ops implement that callback; on USB and SDIO it is NULL, so
a TXRX_NOTIFY there calls a NULL pointer in the RX worker:
BUG: kernel NULL pointer dereference, address: 0000000000000000
RIP: 0010:0x0
Call Trace:
mt7921_mac_tx_free+0x64/0x310 [mt7921_common]
mt7921_rx_check+0x5f/0xf0 [mt7921_common]
mt76u_rx_worker+0x1b9/0x620 [mt76_usb]
Drop the event on non-mmio buses via mt76_is_mmio(), as in
commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for
non-mmio devices").
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7921/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7003a2cbddd7917933c1f169c7874cfa6ab852c3",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "ef2ee5f820c3ef87643b51e960c20b4a14d8336b",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "ecf995b828191829ba4a87169bccabcbeb5c9c32",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "263816e92e8d66c81c98ccab2b5d2191ed08ec71",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "24475d2ddc8d8dfd82f4d2be0d951401f86911a6",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "da4082e91acabc1498611ed8ccc53f0610baefc6",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7921/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses\n\nPKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and\nmt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus.\nmt7921_mac_tx_free() cleans the DMA tx queues with\nmt76_queue_tx_cleanup(), which calls queue_ops-\u003etx_cleanup(). Only the\nmmio queue ops implement that callback; on USB and SDIO it is NULL, so\na TXRX_NOTIFY there calls a NULL pointer in the RX worker:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n RIP: 0010:0x0\n Call Trace:\n mt7921_mac_tx_free+0x64/0x310 [mt7921_common]\n mt7921_rx_check+0x5f/0xf0 [mt7921_common]\n mt76u_rx_worker+0x1b9/0x620 [mt76_usb]\n\nDrop the event on non-mmio buses via mt76_is_mmio(), as in\ncommit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for\nnon-mmio devices\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:09.017Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7003a2cbddd7917933c1f169c7874cfa6ab852c3"
},
{
"url": "https://git.kernel.org/stable/c/ef2ee5f820c3ef87643b51e960c20b4a14d8336b"
},
{
"url": "https://git.kernel.org/stable/c/ecf995b828191829ba4a87169bccabcbeb5c9c32"
},
{
"url": "https://git.kernel.org/stable/c/263816e92e8d66c81c98ccab2b5d2191ed08ec71"
},
{
"url": "https://git.kernel.org/stable/c/24475d2ddc8d8dfd82f4d2be0d951401f86911a6"
},
{
"url": "https://git.kernel.org/stable/c/da4082e91acabc1498611ed8ccc53f0610baefc6"
}
],
"title": "wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68194",
"datePublished": "2026-08-10T12:00:12.245Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:09.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68227 (GCVE-0-2026-68227)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: cx231xx: fix devres lifetime
USB drivers bind to USB interfaces and any device managed resources
should have their lifetime tied to the interface rather than parent USB
device. This avoids issues like memory leaks when drivers are unbound
without their devices being physically disconnected (e.g. on probe
deferral or configuration changes).
Fix the driver state lifetime so that it is released on driver unbind.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/cx231xx/cx231xx-cards.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1770fc4e2b47b1185e6f688d4012bc91f7543854",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "c07f535bcdd3f956d4c32085535368f46ba99ba0",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "0ea4b6fd49f7bed3a7e2b8734c15d9699dabe26f",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "a373f1a5137e96549a795e7fb9efb5de0ae1d065",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "c5ccb01eb1107acb6aab8ce8fe5a523f215c837e",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "f468b7ee5d6332b01e6c538179a4c720e6dae93b",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "e797e252bfb3d0d4b3d38e4faef817e05869c240",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "7d6358ab02866e5b7ed8d3a00805297617bbb0ec",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/cx231xx/cx231xx-cards.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx231xx: fix devres lifetime\n\nUSB drivers bind to USB interfaces and any device managed resources\nshould have their lifetime tied to the interface rather than parent USB\ndevice. This avoids issues like memory leaks when drivers are unbound\nwithout their devices being physically disconnected (e.g. on probe\ndeferral or configuration changes).\n\nFix the driver state lifetime so that it is released on driver unbind."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:59.091Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1770fc4e2b47b1185e6f688d4012bc91f7543854"
},
{
"url": "https://git.kernel.org/stable/c/c07f535bcdd3f956d4c32085535368f46ba99ba0"
},
{
"url": "https://git.kernel.org/stable/c/0ea4b6fd49f7bed3a7e2b8734c15d9699dabe26f"
},
{
"url": "https://git.kernel.org/stable/c/a373f1a5137e96549a795e7fb9efb5de0ae1d065"
},
{
"url": "https://git.kernel.org/stable/c/c5ccb01eb1107acb6aab8ce8fe5a523f215c837e"
},
{
"url": "https://git.kernel.org/stable/c/f468b7ee5d6332b01e6c538179a4c720e6dae93b"
},
{
"url": "https://git.kernel.org/stable/c/e797e252bfb3d0d4b3d38e4faef817e05869c240"
},
{
"url": "https://git.kernel.org/stable/c/7d6358ab02866e5b7ed8d3a00805297617bbb0ec"
}
],
"title": "media: cx231xx: fix devres lifetime",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68227",
"datePublished": "2026-08-10T12:00:49.821Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:31:59.091Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63980 (GCVE-0-2026-63980)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-08-05 12:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/handshake: Use spin_lock_bh for hn_lock
nvmet_tcp_state_change(), a socket callback that runs in BH context,
can reach handshake_req_cancel() via nvmet_tcp_schedule_release_queue()
and tls_handshake_cancel(). handshake_req_cancel() acquires
hn->hn_lock with plain spin_lock(). If a process-context thread on
the same CPU holds hn->hn_lock when a softirq invokes the cancel path,
the lock attempt deadlocks. This is the only caller that invokes
tls_handshake_cancel() from BH context; every other consumer calls it
from process context.
Deferring the cancel to process context in the NVMe target is not
straightforward: nvmet_tcp_schedule_release_queue() must call
tls_handshake_cancel() atomically with its state transition to
DISCONNECTING. If the cancel were deferred, the handshake completion
callback could fire in the window before the cancel runs, observe the
unexpected state, and return without dropping its kref on the queue.
Reworking that interlock is considerably more invasive than hardening
the handshake lock. Convert all hn->hn_lock acquisitions from
spin_lock/spin_unlock to spin_lock_bh/spin_unlock_bh so the lock is
never taken with softirqs enabled.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/handshake/netlink.c",
"net/handshake/request.c",
"net/handshake/tlshd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "06ab5978866fc2221b910347fd3e510ca8e7b1a4",
"status": "affected",
"version": "675b453e024154dd547921c6e6d5b58747ba7e0e",
"versionType": "git"
},
{
"lessThan": "0866569fc36a56f568acd3900d354e3505932e09",
"status": "affected",
"version": "675b453e024154dd547921c6e6d5b58747ba7e0e",
"versionType": "git"
},
{
"lessThan": "91898de9501a047ba67c6b864dcd403e00bdfbf5",
"status": "affected",
"version": "675b453e024154dd547921c6e6d5b58747ba7e0e",
"versionType": "git"
},
{
"lessThan": "cc993e0927ec8bd98ea33377ada03295fcda0f24",
"status": "affected",
"version": "675b453e024154dd547921c6e6d5b58747ba7e0e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/handshake/netlink.c",
"net/handshake/request.c",
"net/handshake/tlshd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/handshake: Use spin_lock_bh for hn_lock\n\nnvmet_tcp_state_change(), a socket callback that runs in BH context,\ncan reach handshake_req_cancel() via nvmet_tcp_schedule_release_queue()\nand tls_handshake_cancel(). handshake_req_cancel() acquires\nhn-\u003ehn_lock with plain spin_lock(). If a process-context thread on\nthe same CPU holds hn-\u003ehn_lock when a softirq invokes the cancel path,\nthe lock attempt deadlocks. This is the only caller that invokes\ntls_handshake_cancel() from BH context; every other consumer calls it\nfrom process context.\n\nDeferring the cancel to process context in the NVMe target is not\nstraightforward: nvmet_tcp_schedule_release_queue() must call\ntls_handshake_cancel() atomically with its state transition to\nDISCONNECTING. If the cancel were deferred, the handshake completion\ncallback could fire in the window before the cancel runs, observe the\nunexpected state, and return without dropping its kref on the queue.\nReworking that interlock is considerably more invasive than hardening\nthe handshake lock. Convert all hn-\u003ehn_lock acquisitions from\nspin_lock/spin_unlock to spin_lock_bh/spin_unlock_bh so the lock is\nnever taken with softirqs enabled."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable path is reachable through nvmet-tcp, an in-kernel network service that processes remote TCP connections; socket state-change callbacks run in softirq when remote peers disconnect during TLS handshake.\nAC:L - An attacker controls both sides of the race by opening multiple concurrent TLS connections to the NVMe/TCP target and timing abrupt disconnects against in-progress handshake submissions on the same CPU.\nPR:N - Exploitation requires only network access to an NVMe/TCP target port with TLS enabled; the TLS handshake upcall occurs before any NVMe authentication or credentials are verified.\nUI:N - No victim user action is required; the deadlock is triggered entirely by the remote attacker\u0027s connection and disconnection timing against the NVMe/TCP service.\nS:U - The deadlock affects kernel availability on the target host but does not cross a security boundary such as a VM guest-to-host escape or sandbox breakout.\nC:N - This is a spinlock deadlock with no memory corruption, out-of-bounds access, or use-after-free; no information disclosure occurs.\nI:N - The vulnerability causes a CPU hang via lock deadlock but does not modify data or enable arbitrary writes or code execution.\nA:H - A spinlock deadlock between process context and softirq causes CPU soft lockup on the affected processor; watchdog timeout can escalate this to a full kernel panic, denying all system availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:37:51.364Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/06ab5978866fc2221b910347fd3e510ca8e7b1a4"
},
{
"url": "https://git.kernel.org/stable/c/0866569fc36a56f568acd3900d354e3505932e09"
},
{
"url": "https://git.kernel.org/stable/c/91898de9501a047ba67c6b864dcd403e00bdfbf5"
},
{
"url": "https://git.kernel.org/stable/c/cc993e0927ec8bd98ea33377ada03295fcda0f24"
}
],
"title": "net/handshake: Use spin_lock_bh for hn_lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63980",
"datePublished": "2026-07-19T14:56:03.887Z",
"dateReserved": "2026-07-19T07:54:57.025Z",
"dateUpdated": "2026-08-05T12:37:51.364Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64582 (GCVE-0-2026-64582)
Vulnerability from cvelistv5
Published
2026-08-05 11:25
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix a use-after-free problem in rxe_mmap
rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list
and releases pending_lock while the struct's kref is still at 1:
list_del_init(&ip->pending_mmaps);
spin_unlock_bh(&rxe->pending_lock); /* ref == 1, no lock held */
ret = remap_vmalloc_range(vma, ip->obj, 0); /* walks PTEs */
[...]
rxe_vma_open(vma); /* kref_get, ref → 2 */
remap_vmalloc_range_partial() walks PTEs without any lock.
A concurrent DESTROY_CQ ioctl on another CPU calls:
kref_put(&q->ip->ref, rxe_mmap_release) /* ref 1→0 */
vfree(ip->obj) /* clears vmalloc PTEs mid-walk */
kfree(ip) /* frees rxe_mmap_info */
This yields:
1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the
per-PTE race -> vm_insert_page(NULL) → GPF in validate_page_before_insert
2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears
it. User VMA holds a PTE to a free'd page which might eventually get
reallocated later by vmalloc which allows the attacker to get a clean
page-level UAF.
It is worth noting that even though a page-level UAF is possible given
the strong primitive, it is statistically very difficult to achieve
given the very short time window (after the last insert_page and before
the kref_get).
The call trace are as below:
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
RIP: 0010:validate_page_before_insert+0x32/0x300
Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5
RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008
RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00
R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20
FS: 00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0
Call Trace:
<TASK>
insert_page+0x8f/0x190
? __pfx_insert_page+0x10/0x10
? kasan_save_alloc_info+0x38/0x60
vm_insert_page+0x2e7/0x400
remap_vmalloc_range_partial+0x212/0x3e0
remap_vmalloc_range+0x6e/0xb0
? __kasan_check_write+0x14/0x30
rxe_mmap+0x2e9/0x5d0
ib_uverbs_mmap+0x1ad/0x2c0
__mmap_region+0x12c2/0x2ad0
? __pfx___mmap_region+0x10/0x10
? __sanitizer_cov_trace_switch+0x58/0xb0
? mas_prev_slot+0x360/0x39c0
? __sanitizer_cov_trace_switch+0x58/0xb0
? mas_next_slot+0x1e5b/0x2f40
? __sanitizer_cov_trace_cmp8+0x18/0x30
? unmapped_area_topdown+0x4dd/0x610
? kfree+0x1b1/0x440
? free_cpumask_var+0x16/0x30
? __kasan_slab_free+0x7d/0xa0
? __sanitizer_cov_trace_cmp8+0x18/0x30
mmap_region+0x2e6/0x3c0
do_mmap+0xa3e/0x12a0
? __pfx_do_mmap+0x10/0x10
? __kasan_check_write+0x14/0x30
? down_write_killable+0xba/0x160
? __pfx_down_write_killable+0x10/0x10
? __sanitizer_cov_trace_cmp4+0x16/0x30
vm_mmap_pgoff+0x2d4/0x4a0
? __pfx_vm_mmap_pgoff+0x10/0x10
? fget+0x1bf/0x270
ksys_mmap_pgoff+0x40c/0x690
? __sanitizer_cov_trace_const_cmp4+0x16/0x30
? __pfx_ksys_mmap_pgoff+0x10/0x10
? __kasan_check_write+0x14/0x30
? _raw_spin_trylock+0xbb/0x130
? __pfx__raw_spin_trylock+0x10/0x10
__x64_sys_mmap+0x135/0x1e0
x64_sys_c
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/rxe/rxe_mmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b810352d0916796dabe633cdb9adee9863ab4911",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "aef5ea8578f97f2701039600846a8bcf5f21e863",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "3371f2036e0f970166bbb624e25bba46d32fa18e",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "665fb7d22a700c66a78db0cf88c6e6a649aba9d0",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "e038d42cc09ca1da9d3568ce8ae062b2bfb3bc0e",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "e59a6aa89e0fcd1d0707832eb4654fd9ae7d31e6",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "3525987a392536f31a484833af258971af63b24c",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "35744ab3d03c5fca8c1752f53fc8fc674e14c561",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/rxe/rxe_mmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix a use-after-free problem in rxe_mmap\n\nrxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list\nand releases pending_lock while the struct\u0027s kref is still at 1:\n\n list_del_init(\u0026ip-\u003epending_mmaps);\n spin_unlock_bh(\u0026rxe-\u003epending_lock); /* ref == 1, no lock held */\n ret = remap_vmalloc_range(vma, ip-\u003eobj, 0); /* walks PTEs */\n [...]\n rxe_vma_open(vma); /* kref_get, ref \u2192 2 */\n remap_vmalloc_range_partial() walks PTEs without any lock.\n\nA concurrent DESTROY_CQ ioctl on another CPU calls:\n\n kref_put(\u0026q-\u003eip-\u003eref, rxe_mmap_release) /* ref 1\u21920 */\n vfree(ip-\u003eobj) /* clears vmalloc PTEs mid-walk */\n kfree(ip) /* frees rxe_mmap_info */\n\nThis yields:\n\n 1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the\n per-PTE race -\u003e vm_insert_page(NULL) \u2192 GPF in validate_page_before_insert\n\n 2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears\n it. User VMA holds a PTE to a free\u0027d page which might eventually get\n reallocated later by vmalloc which allows the attacker to get a clean\n page-level UAF.\n\n It is worth noting that even though a page-level UAF is possible given\n the strong primitive, it is statistically very difficult to achieve\n given the very short time window (after the last insert_page and before\n the kref_get).\n\nThe call trace are as below:\n\n Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\n KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:validate_page_before_insert+0x32/0x300\n Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 \u003c80\u003e 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5\n RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202\n RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000\n RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008\n RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00\n R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20\n FS: 00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0\n Call Trace:\n \u003cTASK\u003e\n insert_page+0x8f/0x190\n ? __pfx_insert_page+0x10/0x10\n ? kasan_save_alloc_info+0x38/0x60\n vm_insert_page+0x2e7/0x400\n remap_vmalloc_range_partial+0x212/0x3e0\n remap_vmalloc_range+0x6e/0xb0\n ? __kasan_check_write+0x14/0x30\n rxe_mmap+0x2e9/0x5d0\n ib_uverbs_mmap+0x1ad/0x2c0\n __mmap_region+0x12c2/0x2ad0\n ? __pfx___mmap_region+0x10/0x10\n ? __sanitizer_cov_trace_switch+0x58/0xb0\n ? mas_prev_slot+0x360/0x39c0\n ? __sanitizer_cov_trace_switch+0x58/0xb0\n ? mas_next_slot+0x1e5b/0x2f40\n ? __sanitizer_cov_trace_cmp8+0x18/0x30\n ? unmapped_area_topdown+0x4dd/0x610\n ? kfree+0x1b1/0x440\n ? free_cpumask_var+0x16/0x30\n ? __kasan_slab_free+0x7d/0xa0\n ? __sanitizer_cov_trace_cmp8+0x18/0x30\n mmap_region+0x2e6/0x3c0\n do_mmap+0xa3e/0x12a0\n ? __pfx_do_mmap+0x10/0x10\n ? __kasan_check_write+0x14/0x30\n ? down_write_killable+0xba/0x160\n ? __pfx_down_write_killable+0x10/0x10\n ? __sanitizer_cov_trace_cmp4+0x16/0x30\n vm_mmap_pgoff+0x2d4/0x4a0\n ? __pfx_vm_mmap_pgoff+0x10/0x10\n ? fget+0x1bf/0x270\n ksys_mmap_pgoff+0x40c/0x690\n ? __sanitizer_cov_trace_const_cmp4+0x16/0x30\n ? __pfx_ksys_mmap_pgoff+0x10/0x10\n ? __kasan_check_write+0x14/0x30\n ? _raw_spin_trylock+0xbb/0x130\n ? __pfx__raw_spin_trylock+0x10/0x10\n __x64_sys_mmap+0x135/0x1e0\n x64_sys_c\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via local mmap on /dev/infiniband/uverbsN (ib_uverbs_mmap\u2192rxe_mmap) racing DESTROY_CQ/QP/SRQ ioctls; not reachable from RoCE/UDP packet processing.\nAC:L - Attacker controls both sides\u2014mmap of the pending CQ/QP/SRQ queue buffer and concurrent destroy that kref_puts to rxe_mmap_release\u2014and can retry unboundedly; PoC shows reliable crash.\nPR:L - uverbs_devnode() publishes /dev/infiniband/uverbs* as 0666 with no capability checks on create/mmap/destroy; once Soft-RoCE exists (admin setup), any unprivileged user (PoC UID 1000) can exploit.\nUI:N - Attacker opens uverbs, creates a CQ/QP/SRQ, then races mmap with destroy from its own threads; no victim action required.\nS:U - UAF corrupts kernel heap/vmalloc within the host kernel authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Race frees rxe_mmap_info and vfree\u0027s the queue while remap_vmalloc_range still walks it; stale PTEs can leave a user VMA mapped to reallocated pages, enabling page-level UAF reads.\nI:H - Same page-level UAF / freed-object control yields write primitives via remapped freed pages and heap reuse, sufficient for control-flow hijacking per UAF guidance.\nA:H - Concurrent vfree during PTE walk returns NULL to vm_insert_page, causing the documented GPF/oops in validate_page_before_insert; crash is reliably repeatable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:09.006Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b810352d0916796dabe633cdb9adee9863ab4911"
},
{
"url": "https://git.kernel.org/stable/c/aef5ea8578f97f2701039600846a8bcf5f21e863"
},
{
"url": "https://git.kernel.org/stable/c/3371f2036e0f970166bbb624e25bba46d32fa18e"
},
{
"url": "https://git.kernel.org/stable/c/665fb7d22a700c66a78db0cf88c6e6a649aba9d0"
},
{
"url": "https://git.kernel.org/stable/c/e038d42cc09ca1da9d3568ce8ae062b2bfb3bc0e"
},
{
"url": "https://git.kernel.org/stable/c/e59a6aa89e0fcd1d0707832eb4654fd9ae7d31e6"
},
{
"url": "https://git.kernel.org/stable/c/3525987a392536f31a484833af258971af63b24c"
},
{
"url": "https://git.kernel.org/stable/c/35744ab3d03c5fca8c1752f53fc8fc674e14c561"
}
],
"title": "RDMA/rxe: Fix a use-after-free problem in rxe_mmap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64582",
"datePublished": "2026-08-05T11:25:29.082Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:09.006Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53309 (GCVE-0-2026-53309)
Vulnerability from cvelistv5
Published
2026-06-26 19:41
Modified
2026-08-05 12:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
The local-vs-remote region comparison loop uses '<=' instead of '<',
causing it to read one entry past the valid range of qr_regions. The
other loops in the same function correctly use '<'.
Fix the loop condition to use '<' for consistency and correctness.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ea2034416b54700e30371f2ad6517cbb94674083 Version: ea2034416b54700e30371f2ad6517cbb94674083 Version: ea2034416b54700e30371f2ad6517cbb94674083 Version: ea2034416b54700e30371f2ad6517cbb94674083 Version: ea2034416b54700e30371f2ad6517cbb94674083 Version: ea2034416b54700e30371f2ad6517cbb94674083 Version: ea2034416b54700e30371f2ad6517cbb94674083 Version: ea2034416b54700e30371f2ad6517cbb94674083 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ocfs2/dlm/dlmdomain.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "760ab35040aca8399021fdb9ff1db1089feb7194",
"status": "affected",
"version": "ea2034416b54700e30371f2ad6517cbb94674083",
"versionType": "git"
},
{
"lessThan": "c60a2710b73838d250cda57344c049b89abc5d52",
"status": "affected",
"version": "ea2034416b54700e30371f2ad6517cbb94674083",
"versionType": "git"
},
{
"lessThan": "2a0673836f019e7c032acbf48d022d5ccf02a845",
"status": "affected",
"version": "ea2034416b54700e30371f2ad6517cbb94674083",
"versionType": "git"
},
{
"lessThan": "819d8ebad3200a53de99bd7e297bc428e41ced54",
"status": "affected",
"version": "ea2034416b54700e30371f2ad6517cbb94674083",
"versionType": "git"
},
{
"lessThan": "d5403ae28085761d58b555645bc7d5feadb10073",
"status": "affected",
"version": "ea2034416b54700e30371f2ad6517cbb94674083",
"versionType": "git"
},
{
"lessThan": "1fb7f356547d9688822315cd2b205ff0bd5429b4",
"status": "affected",
"version": "ea2034416b54700e30371f2ad6517cbb94674083",
"versionType": "git"
},
{
"lessThan": "426cd8eedac89b86148d4478990eeef16e8a2520",
"status": "affected",
"version": "ea2034416b54700e30371f2ad6517cbb94674083",
"versionType": "git"
},
{
"lessThan": "01b61e8dda9b0fdb0d4cda43de25f4e390554d7b",
"status": "affected",
"version": "ea2034416b54700e30371f2ad6517cbb94674083",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ocfs2/dlm/dlmdomain.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison\n\nThe local-vs-remote region comparison loop uses \u0027\u003c=\u0027 instead of \u0027\u003c\u0027,\ncausing it to read one entry past the valid range of qr_regions. The\nother loops in the same function correctly use \u0027\u003c\u0027.\n\nFix the loop condition to use \u0027\u003c\u0027 for consistency and correctness."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - DLM_QUERY_REGION is received and dispatched by the ocfs2 o2net TCP cluster transport, so the vulnerable comparison is reached through network messages from a peer node.\nAC:L - A peer that can reach the OCFS2 cluster transport can deterministically drive the join sequence and send a crafted region list; the off-by-one comparison is not a race and needs no unusual timing.\nPR:N - The receive path does not require credentials or a local account on the target; it relies on cluster node/IP/heartbeat state rather than authenticated target privileges.\nUI:N - Once the OCFS2/DLM cluster service is running, exploitation is driven entirely by network protocol messages and requires no victim user action.\nS:U - The vulnerable component and resulting kernel/cluster filesystem effects remain within the same kernel and OCFS2 cluster security authority.\nC:H - The bug is an out-of-bounds read of a region-sized entry beyond the valid qr_regions range, driven by attacker-supplied network state; under the required kernel scoring guidance, non-trivial out-of-bounds reads are treated as high confidentiality impact.\nI:H - The off-by-one can let a joining node pass heartbeat-region validation with an inconsistent region set, undermining DLM cluster membership safety and enabling severe shared-filesystem integrity corruption in a plausible OCFS2 deployment.\nA:H - Accepting inconsistent heartbeat regions can lead to cluster miscoordination, fencing, hangs, or filesystem disruption, and the malformed query can be sent without user interaction once the join path is reachable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:34:59.157Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/760ab35040aca8399021fdb9ff1db1089feb7194"
},
{
"url": "https://git.kernel.org/stable/c/c60a2710b73838d250cda57344c049b89abc5d52"
},
{
"url": "https://git.kernel.org/stable/c/2a0673836f019e7c032acbf48d022d5ccf02a845"
},
{
"url": "https://git.kernel.org/stable/c/819d8ebad3200a53de99bd7e297bc428e41ced54"
},
{
"url": "https://git.kernel.org/stable/c/d5403ae28085761d58b555645bc7d5feadb10073"
},
{
"url": "https://git.kernel.org/stable/c/1fb7f356547d9688822315cd2b205ff0bd5429b4"
},
{
"url": "https://git.kernel.org/stable/c/426cd8eedac89b86148d4478990eeef16e8a2520"
},
{
"url": "https://git.kernel.org/stable/c/01b61e8dda9b0fdb0d4cda43de25f4e390554d7b"
}
],
"title": "ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53309",
"datePublished": "2026-06-26T19:41:03.505Z",
"dateReserved": "2026-06-09T07:44:35.397Z",
"dateUpdated": "2026-08-05T12:34:59.157Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68348 (GCVE-0-2026-68348)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: tas2781: bound firmware description string parsing
The TAS2781 firmware parser reads several variable-length description
strings with strlen() before checking that the string terminator is
present inside the firmware blob. A malformed firmware image without a
NUL terminator can therefore make the parser walk past the end of the
firmware buffer before the later size checks run.
Add a small bounded string-length helper and use it for all description
fields that are parsed from the firmware buffer. Keep the existing size
checks for the fixed bytes that follow each string.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/tas2781-fmwlib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3ddb0d3e36507615e5ef010a879357a54870adf5",
"status": "affected",
"version": "915f5eadebd29ba185ac506766a90120153b7e14",
"versionType": "git"
},
{
"lessThan": "0ec45e80a82785ee147516fdecf5c93707dec119",
"status": "affected",
"version": "915f5eadebd29ba185ac506766a90120153b7e14",
"versionType": "git"
},
{
"lessThan": "41ae2b7d37c3dd82302167496836cca9f0328374",
"status": "affected",
"version": "915f5eadebd29ba185ac506766a90120153b7e14",
"versionType": "git"
},
{
"lessThan": "e75ef37d83c90b09bedb601624b47e168202b226",
"status": "affected",
"version": "915f5eadebd29ba185ac506766a90120153b7e14",
"versionType": "git"
},
{
"lessThan": "bc889dfcea9294a1eae7f8e2f3573a90764ae4d0",
"status": "affected",
"version": "915f5eadebd29ba185ac506766a90120153b7e14",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/tas2781-fmwlib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: tas2781: bound firmware description string parsing\n\nThe TAS2781 firmware parser reads several variable-length description\nstrings with strlen() before checking that the string terminator is\npresent inside the firmware blob. A malformed firmware image without a\nNUL terminator can therefore make the parser walk past the end of the\nfirmware buffer before the later size checks run.\n\nAdd a small bounded string-length helper and use it for all description\nfields that are parsed from the firmware buffer. Keep the existing size\nchecks for the fixed bytes that follow each string."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The malformed blob is consumed by request_firmware() from the local firmware search path during tas2781 codec probe (tasdevice_dsp_parser/tas2781_load_calibration); there is no network, adjacent-network, or peer-supplied data path into the parser, so local presence on the affected system is required.\nAC:L - Simply omitting the NUL terminator at the end of a coef/cal .bin file makes strlen() run past fmw-\u003esize deterministically on every load \u2014 no race, no timing window, and no memory-layout precondition the attacker cannot influence.\nPR:L - The parsing path contains no capability, credential, or privilege check whatsoever, and the firmware search path on many embedded/Android/appliance deployments lives on a vendor or data partition writable by non-root system accounts; a low-privileged local account is therefore sufficient to be positioned to place the blob.\nUI:N - Parsing runs from the asynchronous request_firmware_nowait() completion callback during device probe/bind; once the file is in place it is consumed automatically at the next boot or driver bind with no victim action required.\nS:U - The out-of-bounds read occurs in kernel memory belonging to the same kernel that hosts the vulnerable codec driver, with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - strlen() is unbounded \u2014 it walks from the description offset through arbitrary kernel memory adjacent to the firmware buffer until a zero byte is found, so the read is not confined to a few bytes and touches heap/vmalloc contents outside the intended allocation.\nI:N - The defect is purely a read: the computed length is re-validated against fmw-\u003esize afterwards (and int/size_t promotion makes overflowed sums fail the check), so no out-of-bounds write or corrupted parse offset results from the OOB strlen.\nA:H - Firmware buffers are vmalloc/kmalloc allocations, so a strlen() walk past the end readily crosses into an unmapped page or guard page and produces a kernel oops/panic, which is High availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:50.265Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3ddb0d3e36507615e5ef010a879357a54870adf5"
},
{
"url": "https://git.kernel.org/stable/c/0ec45e80a82785ee147516fdecf5c93707dec119"
},
{
"url": "https://git.kernel.org/stable/c/41ae2b7d37c3dd82302167496836cca9f0328374"
},
{
"url": "https://git.kernel.org/stable/c/e75ef37d83c90b09bedb601624b47e168202b226"
},
{
"url": "https://git.kernel.org/stable/c/bc889dfcea9294a1eae7f8e2f3573a90764ae4d0"
}
],
"title": "ASoC: tas2781: bound firmware description string parsing",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68348",
"datePublished": "2026-08-10T12:03:25.193Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-17T05:03:50.265Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68377 (GCVE-0-2026-68377)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_tunnel_key: Defer dst_release to RCU callback
Fix a race-condition use-after-free in tunnel_key_release_params().
The function releases the metadata_dst of the old params synchronously
via dst_release() while deferring the params struct free with
kfree_rcu(). A concurrent tunnel_key_act() reader on the datapath may
still hold the old params pointer (under rcu_read_lock_bh) and proceed
to call dst_clone(¶ms->tcft_enc_metadata->dst) after the writer's
dst_release has already pushed the dst's rcuref to RCUREF_DEAD.
zdi-disclosures@trendmicro.com produced a poc which i (and Victor) verified
that KASAN reports:
==================================================================
BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112
BUG: KASAN: slab-use-after-free in atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326
BUG: KASAN: slab-use-after-free in __rcuref_put include/linux/rcuref.h:109
BUG: KASAN: slab-use-after-free in rcuref_put include/linux/rcuref.h:173
BUG: KASAN: slab-use-after-free in dst_release+0x5b/0x370 net/core/dst.c:168
Write of size 4 at addr ffff88806158de40 by task poc/9388
CPU: 0 UID: 0 PID: 9388 Comm: poc Tainted: G W 7.1.0-rc7 #7 PREEMPT(lazy)
Tainted: [W]=WARN
Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94
dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378
print_report+0x139/0x4ad mm/kasan/report.c:482
kasan_report+0xe4/0x1d0 mm/kasan/report.c:595
check_region_inline mm/kasan/generic.c:186
kasan_check_range+0x125/0x200 mm/kasan/generic.c:200
instrument_atomic_read_write include/linux/instrumented.h:112
atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326
__rcuref_put include/linux/rcuref.h:109
rcuref_put include/linux/rcuref.h:173
dst_release+0x5b/0x370 net/core/dst.c:168
refdst_drop include/net/dst.h:272
skb_dst_drop include/net/dst.h:284
skb_release_head_state+0x293/0x400 net/core/skbuff.c:1163
skb_release_all net/core/skbuff.c:1187
[..]
Allocated by task 9391:
kasan_save_stack+0x30/0x50 mm/kasan/common.c:57
kasan_save_track+0x14/0x30 mm/kasan/common.c:78
poison_kmalloc_redzone mm/kasan/common.c:398
__kasan_kmalloc+0x9a/0xb0 mm/kasan/common.c:415
kasan_kmalloc include/linux/kasan.h:263
__do_kmalloc_node mm/slub.c:5296
__kmalloc_noprof+0x2f1/0x830 mm/slub.c:5308
kmalloc_noprof include/linux/slab.h:954
kzalloc_noprof include/linux/slab.h:1188
offload_action_alloc+0x2f/0x130 net/core/flow_offload.c:35
tcf_action_offload_add_ex+0x1ba/0x880 net/sched/act_api.c:258
tcf_action_offload_add net/sched/act_api.c:293
tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547
tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101
[..]
Freed by task 9391:
kasan_save_stack+0x30/0x50 mm/kasan/common.c:57
kasan_save_track+0x14/0x30 mm/kasan/common.c:78
kasan_save_free_info+0x3b/0x70 mm/kasan/generic.c:584
poison_slab_object mm/kasan/common.c:253
__kasan_slab_free+0x6b/0x90 mm/kasan/common.c:285
kasan_slab_free include/linux/kasan.h:235
slab_free_hook mm/slub.c:2689
slab_free mm/slub.c:6251
kfree+0x21f/0x6b0 mm/slub.c:6566
tcf_action_offload_add_ex+0x4ad/0x880 net/sched/act_api.c:284
tcf_action_offload_add net/sched/act_api.c:293
tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547
tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101
The buggy address belongs to the object at ffff88806158de00
which belongs to the cache kmalloc-256 of size 256
The buggy address is located 64 bytes inside of
freed 256-byte region [ffff88806158de00, ffff88806158df00)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88806158d600 pfn:0x6158c
head: order:1 mapcount:0 entire_map
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 02239e797ac75f89a05622a27d04695f08c1ca89 Version: ca9b7a65a2c97579fcdd509d454d48e3a5c49af8 Version: 4.19.19 ≤ Version: 4.20.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/act_tunnel_key.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b5931f020b681fdcb9378262d89b61cb3c7ebbf8",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "389d03992dabb80488228e8119b9dd6d0f58e1a6",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "676ad6aa7cec89a08d2a5ce3cd5959e313f29733",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "531dbb5bb98e52ad26be7e90f9f8bec707c5bd0e",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "2200a00ff247f70f5dcdb4e6f14b0d48ddac5467",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "fed1b1ddab41a0e7a462ac690a0c8af6ff793624",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "2791a501da508b704a617b4dba29db54a65bc9f7",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "f1f5c8a3955f8fda3f84ed883ac8daa1847e724c",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"status": "affected",
"version": "02239e797ac75f89a05622a27d04695f08c1ca89",
"versionType": "git"
},
{
"status": "affected",
"version": "ca9b7a65a2c97579fcdd509d454d48e3a5c49af8",
"versionType": "git"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.19",
"versionType": "semver"
},
{
"lessThan": "4.21",
"status": "affected",
"version": "4.20.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/act_tunnel_key.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.20.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_tunnel_key: Defer dst_release to RCU callback\n\nFix a race-condition use-after-free in tunnel_key_release_params().\n\nThe function releases the metadata_dst of the old params synchronously\nvia dst_release() while deferring the params struct free with\nkfree_rcu(). A concurrent tunnel_key_act() reader on the datapath may\nstill hold the old params pointer (under rcu_read_lock_bh) and proceed\nto call dst_clone(\u0026params-\u003etcft_enc_metadata-\u003edst) after the writer\u0027s\ndst_release has already pushed the dst\u0027s rcuref to RCUREF_DEAD.\n\nzdi-disclosures@trendmicro.com produced a poc which i (and Victor) verified\nthat KASAN reports:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112\nBUG: KASAN: slab-use-after-free in atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326\nBUG: KASAN: slab-use-after-free in __rcuref_put include/linux/rcuref.h:109\nBUG: KASAN: slab-use-after-free in rcuref_put include/linux/rcuref.h:173\nBUG: KASAN: slab-use-after-free in dst_release+0x5b/0x370 net/core/dst.c:168\nWrite of size 4 at addr ffff88806158de40 by task poc/9388\n\nCPU: 0 UID: 0 PID: 9388 Comm: poc Tainted: G W 7.1.0-rc7 #7 PREEMPT(lazy)\nTainted: [W]=WARN\nHardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n __dump_stack lib/dump_stack.c:94\n dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378\n print_report+0x139/0x4ad mm/kasan/report.c:482\n kasan_report+0xe4/0x1d0 mm/kasan/report.c:595\n check_region_inline mm/kasan/generic.c:186\n kasan_check_range+0x125/0x200 mm/kasan/generic.c:200\n instrument_atomic_read_write include/linux/instrumented.h:112\n atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326\n __rcuref_put include/linux/rcuref.h:109\n rcuref_put include/linux/rcuref.h:173\n dst_release+0x5b/0x370 net/core/dst.c:168\n refdst_drop include/net/dst.h:272\n skb_dst_drop include/net/dst.h:284\n skb_release_head_state+0x293/0x400 net/core/skbuff.c:1163\n skb_release_all net/core/skbuff.c:1187\n[..]\nAllocated by task 9391:\n kasan_save_stack+0x30/0x50 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n poison_kmalloc_redzone mm/kasan/common.c:398\n __kasan_kmalloc+0x9a/0xb0 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263\n __do_kmalloc_node mm/slub.c:5296\n __kmalloc_noprof+0x2f1/0x830 mm/slub.c:5308\n kmalloc_noprof include/linux/slab.h:954\n kzalloc_noprof include/linux/slab.h:1188\n offload_action_alloc+0x2f/0x130 net/core/flow_offload.c:35\n tcf_action_offload_add_ex+0x1ba/0x880 net/sched/act_api.c:258\n tcf_action_offload_add net/sched/act_api.c:293\n tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547\n tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101\n[..]\nFreed by task 9391:\n kasan_save_stack+0x30/0x50 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n kasan_save_free_info+0x3b/0x70 mm/kasan/generic.c:584\n poison_slab_object mm/kasan/common.c:253\n __kasan_slab_free+0x6b/0x90 mm/kasan/common.c:285\n kasan_slab_free include/linux/kasan.h:235\n slab_free_hook mm/slub.c:2689\n slab_free mm/slub.c:6251\n kfree+0x21f/0x6b0 mm/slub.c:6566\n tcf_action_offload_add_ex+0x4ad/0x880 net/sched/act_api.c:284\n tcf_action_offload_add net/sched/act_api.c:293\n tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547\n tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101\n\nThe buggy address belongs to the object at ffff88806158de00\n which belongs to the cache kmalloc-256 of size 256\nThe buggy address is located 64 bytes inside of\n freed 256-byte region [ffff88806158de00, ffff88806158df00)\n\nThe buggy address belongs to the physical page:\npage: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88806158d600 pfn:0x6158c\nhead: order:1 mapcount:0 entire_map\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable window is opened via the tc/rtnetlink RTM_NEWACTION path (`tc action replace ... tunnel_key set`) and closed by locally generated traffic through a clsact/ingress filter, both requiring local system access rather than remote packets.\nAC:L - The attacker controls both sides of the race \u2014 one thread repeatedly replaces the tunnel_key action while another pumps packets through the filter \u2014 and can widen the window with qdisc backlog, so the UAF is reliably reproducible (a ZDI PoC reproduced it under KASAN).\nPR:L - The action-add path is gated only by netlink_capable(skb, CAP_NET_ADMIN), which is namespace-relative and obtainable by any unprivileged user via `unshare -Urn`; the packet side runs in the attacker\u0027s own netns.\nUI:N - Both the netlink action replace and the packet transmission that dereferences the stale params are performed entirely by the attacker\u0027s own processes; no victim action is involved.\nS:U - The corruption is confined to kernel heap memory within the same security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - The freed metadata_dst sits in the general-purpose kmalloc-256 cache and remains attached to an skb, so tx paths read tunnel metadata out of reclaimed memory, giving an attacker who sprays the slab a route to disclose kernel data and defeat KASLR.\nI:H - The stale dst_clone/skb_dst_drop pair performs atomic 4-byte read-modify-write operations on a freed, attacker-reclaimable slab object, yielding a refcount-corruption primitive that is a well-established stepping stone to arbitrary write and privilege escalation.\nA:H - The use-after-free reliably corrupts slab memory and triggers KASAN-reported faults; unmitigated it causes kernel oops or panic, and the race can be repeated at will by an unprivileged user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:38.220Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b5931f020b681fdcb9378262d89b61cb3c7ebbf8"
},
{
"url": "https://git.kernel.org/stable/c/389d03992dabb80488228e8119b9dd6d0f58e1a6"
},
{
"url": "https://git.kernel.org/stable/c/676ad6aa7cec89a08d2a5ce3cd5959e313f29733"
},
{
"url": "https://git.kernel.org/stable/c/531dbb5bb98e52ad26be7e90f9f8bec707c5bd0e"
},
{
"url": "https://git.kernel.org/stable/c/2200a00ff247f70f5dcdb4e6f14b0d48ddac5467"
},
{
"url": "https://git.kernel.org/stable/c/fed1b1ddab41a0e7a462ac690a0c8af6ff793624"
},
{
"url": "https://git.kernel.org/stable/c/2791a501da508b704a617b4dba29db54a65bc9f7"
},
{
"url": "https://git.kernel.org/stable/c/f1f5c8a3955f8fda3f84ed883ac8daa1847e724c"
}
],
"title": "net/sched: act_tunnel_key: Defer dst_release to RCU callback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68377",
"datePublished": "2026-08-10T12:03:55.643Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:38.220Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63990 (GCVE-0-2026-63990)
Vulnerability from cvelistv5
Published
2026-07-19 14:56
Modified
2026-07-19 14:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bonding: refuse to enslave CAN devices
syzbot reported a kernel paging request crash in
can_rx_unregister() inside net/can/af_can.c. The crash occurs
because a virtual CAN device (vxcan) is being enslaved to a
bonding master.
During the enslavement process, the bonding driver mutates
and modifies the network device states to fit an Ethernet-like
aggregation model. However, CAN devices operate on a completely
different Layer 2 architecture, relying on the CAN mid-layer
private data structure (can_ml_priv) instead of standard
Ethernet structures. Since bonding does not initialize or
maintain these CAN structures, subsequent operations on the
half-enslaved interface (such as closing associated sockets
via isotp_release) lead to a null-pointer dereference when
accessing the CAN receiver lists.
Bonding CAN interfaces is architecturally invalid as CAN lacks
MAC addresses, ARP capabilities, and standard Ethernet
link-layer mechanisms. While generic loopback devices are
blocked globally in net/core/dev.c, virtual CAN devices
bypass this check because they do not carry the IFF_LOOPBACK
flag, despite acting as local software-loopbacks.
Fix this by explicitly blocking network devices of type
ARPHRD_CAN from being enslaved at the very beginning of
bond_enslave(). This prevents illegal state mutations,
eliminates the resulting KASAN crashes, and avoids potential
memory leaks from incomplete socket cleanups.
As the CAN support has been added a long time after bonding
the Fixes-tag points to the introduction of ARPHRD_CAN that
would have needed a specific handling in bonding_main.c.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cd05acfe65ed2cf2db683fa9a6adb8d35635263b Version: cd05acfe65ed2cf2db683fa9a6adb8d35635263b Version: cd05acfe65ed2cf2db683fa9a6adb8d35635263b Version: cd05acfe65ed2cf2db683fa9a6adb8d35635263b Version: cd05acfe65ed2cf2db683fa9a6adb8d35635263b Version: cd05acfe65ed2cf2db683fa9a6adb8d35635263b Version: cd05acfe65ed2cf2db683fa9a6adb8d35635263b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "69b78b5f3033272e53a2dc2dad675962654a5b38",
"status": "affected",
"version": "cd05acfe65ed2cf2db683fa9a6adb8d35635263b",
"versionType": "git"
},
{
"lessThan": "41e8478c4cd896d3abbe33d41afc90c84ac66602",
"status": "affected",
"version": "cd05acfe65ed2cf2db683fa9a6adb8d35635263b",
"versionType": "git"
},
{
"lessThan": "f4d78a81f57df82e9d82a2c07471fed1a1235893",
"status": "affected",
"version": "cd05acfe65ed2cf2db683fa9a6adb8d35635263b",
"versionType": "git"
},
{
"lessThan": "02f1c87ded33b43d48b4a1d665da15f2157b30d8",
"status": "affected",
"version": "cd05acfe65ed2cf2db683fa9a6adb8d35635263b",
"versionType": "git"
},
{
"lessThan": "9ea8a648d9120f7652bcde1ce2c4ad66871af707",
"status": "affected",
"version": "cd05acfe65ed2cf2db683fa9a6adb8d35635263b",
"versionType": "git"
},
{
"lessThan": "563090e5d450c665f70d955a39f9587afc7842eb",
"status": "affected",
"version": "cd05acfe65ed2cf2db683fa9a6adb8d35635263b",
"versionType": "git"
},
{
"lessThan": "8ba68464e4787b6a7ec938826e16124df20fd23d",
"status": "affected",
"version": "cd05acfe65ed2cf2db683fa9a6adb8d35635263b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.93",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.35",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.12",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: refuse to enslave CAN devices\n\nsyzbot reported a kernel paging request crash in\ncan_rx_unregister() inside net/can/af_can.c. The crash occurs\nbecause a virtual CAN device (vxcan) is being enslaved to a\nbonding master.\n\nDuring the enslavement process, the bonding driver mutates\nand modifies the network device states to fit an Ethernet-like\naggregation model. However, CAN devices operate on a completely\ndifferent Layer 2 architecture, relying on the CAN mid-layer\nprivate data structure (can_ml_priv) instead of standard\nEthernet structures. Since bonding does not initialize or\nmaintain these CAN structures, subsequent operations on the\nhalf-enslaved interface (such as closing associated sockets\nvia isotp_release) lead to a null-pointer dereference when\naccessing the CAN receiver lists.\n\nBonding CAN interfaces is architecturally invalid as CAN lacks\nMAC addresses, ARP capabilities, and standard Ethernet\nlink-layer mechanisms. While generic loopback devices are\nblocked globally in net/core/dev.c, virtual CAN devices\nbypass this check because they do not carry the IFF_LOOPBACK\nflag, despite acting as local software-loopbacks.\n\nFix this by explicitly blocking network devices of type\nARPHRD_CAN from being enslaved at the very beginning of\nbond_enslave(). This prevents illegal state mutations,\neliminates the resulting KASAN crashes, and avoids potential\nmemory leaks from incomplete socket cleanups.\n\nAs the CAN support has been added a long time after bonding\nthe Fixes-tag points to the introduction of ARPHRD_CAN that\nwould have needed a specific handling in bonding_main.c."
}
],
"providerMetadata": {
"dateUpdated": "2026-07-19T14:56:11.111Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/69b78b5f3033272e53a2dc2dad675962654a5b38"
},
{
"url": "https://git.kernel.org/stable/c/41e8478c4cd896d3abbe33d41afc90c84ac66602"
},
{
"url": "https://git.kernel.org/stable/c/f4d78a81f57df82e9d82a2c07471fed1a1235893"
},
{
"url": "https://git.kernel.org/stable/c/02f1c87ded33b43d48b4a1d665da15f2157b30d8"
},
{
"url": "https://git.kernel.org/stable/c/9ea8a648d9120f7652bcde1ce2c4ad66871af707"
},
{
"url": "https://git.kernel.org/stable/c/563090e5d450c665f70d955a39f9587afc7842eb"
},
{
"url": "https://git.kernel.org/stable/c/8ba68464e4787b6a7ec938826e16124df20fd23d"
}
],
"title": "bonding: refuse to enslave CAN devices",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63990",
"datePublished": "2026-07-19T14:56:11.111Z",
"dateReserved": "2026-07-19T07:54:57.025Z",
"dateUpdated": "2026-07-19T14:56:11.111Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68278 (GCVE-0-2026-68278)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix buffer overflows in sideband chunk accumulation
drm_dp_sideband_append_payload() has three related bugs when processing
device-provided sideband reply data:
1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken
directly from the DP sideband header. If a device sends msg_len=0,
curchunk_len is set to zero. The condition (curchunk_idx >= curchunk_len)
is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow).
drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy()
writes 255 bytes into msg[], both far out of bounds.
2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is
only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks
until curchunk_idx reaches curchunk_len, writing up to 15 bytes past
the end of chunk[] into msg[].
3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to
msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256],
so the memcpy can spill into adjacent struct fields.
All three are reachable from any DP MST device that can forge sideband
reply messages on a physical connection.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ef2ecb6cf268debf3890df99fea01b6452dcf78e",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "d4e05dedb252ed3e540a0c9be511e427f098110a",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "4d5109075a787de28c9e89940f9dee45269f91fa",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "53937a2787d29c7a460e984dc4f20ff6ac91dc65",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "ef0dbcc200c3389f1f781ab181932a97e54b51af",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "1e5827839ad0ceb0079d1560c321fa3656b54f21",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "a6366b551079c79bf7bdbadd74c97358bcfe2d58",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "55bd5e685bda455b9b50c835f8c8442d52a344a3",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix buffer overflows in sideband chunk accumulation\n\ndrm_dp_sideband_append_payload() has three related bugs when processing\ndevice-provided sideband reply data:\n\n1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken\n directly from the DP sideband header. If a device sends msg_len=0,\n curchunk_len is set to zero. The condition (curchunk_idx \u003e= curchunk_len)\n is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow).\n drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy()\n writes 255 bytes into msg[], both far out of bounds.\n\n2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is\n only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks\n until curchunk_idx reaches curchunk_len, writing up to 15 bytes past\n the end of chunk[] into msg[].\n\n3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to\n msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256],\n so the memcpy can spill into adjacent struct fields.\n\nAll three are reachable from any DP MST device that can forge sideband\nreply messages on a physical connection."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:15.450Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ef2ecb6cf268debf3890df99fea01b6452dcf78e"
},
{
"url": "https://git.kernel.org/stable/c/d4e05dedb252ed3e540a0c9be511e427f098110a"
},
{
"url": "https://git.kernel.org/stable/c/4d5109075a787de28c9e89940f9dee45269f91fa"
},
{
"url": "https://git.kernel.org/stable/c/53937a2787d29c7a460e984dc4f20ff6ac91dc65"
},
{
"url": "https://git.kernel.org/stable/c/ef0dbcc200c3389f1f781ab181932a97e54b51af"
},
{
"url": "https://git.kernel.org/stable/c/1e5827839ad0ceb0079d1560c321fa3656b54f21"
},
{
"url": "https://git.kernel.org/stable/c/a6366b551079c79bf7bdbadd74c97358bcfe2d58"
},
{
"url": "https://git.kernel.org/stable/c/55bd5e685bda455b9b50c835f8c8442d52a344a3"
}
],
"title": "drm/dp/mst: fix buffer overflows in sideband chunk accumulation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68278",
"datePublished": "2026-08-10T12:01:54.285Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:15.450Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64427 (GCVE-0-2026-64427)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: logitech-dj: Fix maxfield check in DJ short report validation
Commit b6a57912854e ("HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT
related user initiated OOB write") added validation for the DJ short
output report, but the error path dereferences rep->field[0] even when
rep->maxfield is zero.
Commit 8b9a097eb2fc ("HID: logitech-dj: fix wrong detection of bad
DJ_SHORT output report") made the check conditional on rep being present,
but a crafted descriptor can still create report ID 0x20 with only padding
output items. hid-core registers the report, ignores the padding field,
and leaves rep->maxfield as zero.
In that case the validation enters the rep->maxfield < 1 branch and then
dereferences rep->field[0]->report_count while printing the error message,
causing a NULL pointer dereference during probe. This is reproducible with
uhid by emulating a Logitech receiver with a padding-only DJ short output
report:
BUG: KASAN: null-ptr-deref in logi_dj_probe+0xb1/0x754 [hid_logitech_dj]
Read of size 4 at addr 0000000000000028 by task kworker/4:1/129
...
Call Trace:
logi_dj_probe+0xb1/0x754 [hid_logitech_dj]
hid_device_probe+0x329/0x3f0 [hid]
really_probe+0x162/0x570
__device_attach+0x137/0x2c0
bus_probe_device+0x38/0xc0
device_add+0xa56/0xce0
hid_add_device+0x19c/0x280 [hid]
uhid_device_add_worker+0x2c/0xb0 [uhid]
Reject the zero-field report before printing the field report_count.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7754ade02d0fb1caf20392baf4e02937378fd136 Version: 2ed9638cfbf9d49bdef9b0f5ee547236c2c2f500 Version: eeb5ad388595ca2b6624689198a057847f3a3e19 Version: 968e84f5c0dca4960580d174500e4bbf0c45dc15 Version: ce2a731c179df8869e1969a1b2b5b9e4e1c25f8b Version: bc3bba4656ad280267ea78cf845ab6b1d95b9fcd Version: b6a57912854e7ea36f3b270032661140cc4209cd Version: b6a57912854e7ea36f3b270032661140cc4209cd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-logitech-dj.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f3790a6af9c7f47d454225cab9dc145270e48f62",
"status": "affected",
"version": "7754ade02d0fb1caf20392baf4e02937378fd136",
"versionType": "git"
},
{
"lessThan": "1215febd644c3e16f77e0f1799d89544dd57a754",
"status": "affected",
"version": "2ed9638cfbf9d49bdef9b0f5ee547236c2c2f500",
"versionType": "git"
},
{
"lessThan": "6f7f22a8d244c2e586b8eb61c7585784b62aea01",
"status": "affected",
"version": "eeb5ad388595ca2b6624689198a057847f3a3e19",
"versionType": "git"
},
{
"lessThan": "95b3f23d632490b5eb285b9fcf7284f2ac8f9872",
"status": "affected",
"version": "968e84f5c0dca4960580d174500e4bbf0c45dc15",
"versionType": "git"
},
{
"lessThan": "80c1e18473f63fd7c6a2bc9ad6f3d0a6cc4fb500",
"status": "affected",
"version": "ce2a731c179df8869e1969a1b2b5b9e4e1c25f8b",
"versionType": "git"
},
{
"lessThan": "2b70bebc709489d29a31ac2935aeffb8d5228395",
"status": "affected",
"version": "bc3bba4656ad280267ea78cf845ab6b1d95b9fcd",
"versionType": "git"
},
{
"lessThan": "7a89ad762fad53d56b7002d7ffc923a4b7f4006f",
"status": "affected",
"version": "b6a57912854e7ea36f3b270032661140cc4209cd",
"versionType": "git"
},
{
"lessThan": "590cc4d782487632a52f37c2171bee1eeea29627",
"status": "affected",
"version": "b6a57912854e7ea36f3b270032661140cc4209cd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-logitech-dj.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"lessThan": "7.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: logitech-dj: Fix maxfield check in DJ short report validation\n\nCommit b6a57912854e (\"HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT\nrelated user initiated OOB write\") added validation for the DJ short\noutput report, but the error path dereferences rep-\u003efield[0] even when\nrep-\u003emaxfield is zero.\n\nCommit 8b9a097eb2fc (\"HID: logitech-dj: fix wrong detection of bad\nDJ_SHORT output report\") made the check conditional on rep being present,\nbut a crafted descriptor can still create report ID 0x20 with only padding\noutput items. hid-core registers the report, ignores the padding field,\nand leaves rep-\u003emaxfield as zero.\n\nIn that case the validation enters the rep-\u003emaxfield \u003c 1 branch and then\ndereferences rep-\u003efield[0]-\u003ereport_count while printing the error message,\ncausing a NULL pointer dereference during probe. This is reproducible with\nuhid by emulating a Logitech receiver with a padding-only DJ short output\nreport:\n\n BUG: KASAN: null-ptr-deref in logi_dj_probe+0xb1/0x754 [hid_logitech_dj]\n Read of size 4 at addr 0000000000000028 by task kworker/4:1/129\n ...\n Call Trace:\n logi_dj_probe+0xb1/0x754 [hid_logitech_dj]\n hid_device_probe+0x329/0x3f0 [hid]\n really_probe+0x162/0x570\n __device_attach+0x137/0x2c0\n bus_probe_device+0x38/0xc0\n device_add+0xa56/0xce0\n hid_add_device+0x19c/0x280 [hid]\n uhid_device_add_worker+0x2c/0xb0 [uhid]\n\nReject the zero-field report before printing the field report_count."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:13.596Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f3790a6af9c7f47d454225cab9dc145270e48f62"
},
{
"url": "https://git.kernel.org/stable/c/1215febd644c3e16f77e0f1799d89544dd57a754"
},
{
"url": "https://git.kernel.org/stable/c/6f7f22a8d244c2e586b8eb61c7585784b62aea01"
},
{
"url": "https://git.kernel.org/stable/c/95b3f23d632490b5eb285b9fcf7284f2ac8f9872"
},
{
"url": "https://git.kernel.org/stable/c/80c1e18473f63fd7c6a2bc9ad6f3d0a6cc4fb500"
},
{
"url": "https://git.kernel.org/stable/c/2b70bebc709489d29a31ac2935aeffb8d5228395"
},
{
"url": "https://git.kernel.org/stable/c/7a89ad762fad53d56b7002d7ffc923a4b7f4006f"
},
{
"url": "https://git.kernel.org/stable/c/590cc4d782487632a52f37c2171bee1eeea29627"
}
],
"title": "HID: logitech-dj: Fix maxfield check in DJ short report validation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64427",
"datePublished": "2026-07-25T08:51:04.686Z",
"dateReserved": "2026-07-19T15:36:31.787Z",
"dateUpdated": "2026-08-19T16:28:13.596Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68289 (GCVE-0-2026-68289)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
In tipc_recvmsg(), the copy length is computed as:
copy = min_t(int, dlen - offset, buflen);
buflen is size_t but min_t(int, ...) casts it to int. When buflen
exceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it
wraps negative, wins the comparison, and the negative copy length
propagates to simple_copy_to_iter() where int-to-size_t promotion
makes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the
same pattern.
Kernel panic - not syncing: kernel: panic_on_warn set ...
RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521)
Call Trace:
__skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402)
skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534)
tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934)
io_recvmsg+0x47e/0xda0
Fix by changing min_t(int, ...) to min_t(size_t, ...) in both
functions. The result is always <= (dlen - offset), which is bounded
by TIPC maximum message size (0x1ffff bytes), so the implicit
narrowing on assignment to int copy is always safe.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fe9bf32bb18f2d35789d4960fb007d1059bbaa38",
"status": "affected",
"version": "e9f8b10101c6da3ab000a2fb17162374c9bd2c69",
"versionType": "git"
},
{
"lessThan": "47f42ff521b4eeb46e82f9a46a4783a99f7570d7",
"status": "affected",
"version": "e9f8b10101c6da3ab000a2fb17162374c9bd2c69",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()\n\nIn tipc_recvmsg(), the copy length is computed as:\n\n copy = min_t(int, dlen - offset, buflen);\n\nbuflen is size_t but min_t(int, ...) casts it to int. When buflen\nexceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it\nwraps negative, wins the comparison, and the negative copy length\npropagates to simple_copy_to_iter() where int-to-size_t promotion\nmakes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the\nsame pattern.\n\n Kernel panic - not syncing: kernel: panic_on_warn set ...\n RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521)\n Call Trace:\n __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402)\n skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534)\n tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934)\n io_recvmsg+0x47e/0xda0\n\nFix by changing min_t(int, ...) to min_t(size_t, ...) in both\nfunctions. The result is always \u003c= (dlen - offset), which is bounded\nby TIPC maximum message size (0x1ffff bytes), so the implicit\nnarrowing on assignment to int copy is always safe."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:24.704Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fe9bf32bb18f2d35789d4960fb007d1059bbaa38"
},
{
"url": "https://git.kernel.org/stable/c/47f42ff521b4eeb46e82f9a46a4783a99f7570d7"
}
],
"title": "tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68289",
"datePublished": "2026-08-10T12:02:22.101Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-17T05:02:24.704Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68247 (GCVE-0-2026-68247)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/bios: range check LFP Data Block panel_type2
While the panel_type from LFP Data Block is range checked, panel_type2
is not. Add a few helpers for range checking, and use them to not only
check panel_type2, but also improve clarity and correctness in the panel
type selection.
Discovered using AI-assisted static analysis confirmed by Intel Product
Security.
v2:
- Fix commit message typo (Michał)
- Add is_panel_type_pnp() (Ville)
(cherry picked from commit c9ebe5d2f25729d6cfbbb1235d640bf67f9275df)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_bios.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e7b5694645b03e80830dc141b59fc65aac693c70",
"status": "affected",
"version": "6434cf630086eea2d091f122f5802582a05d9d1c",
"versionType": "git"
},
{
"lessThan": "8b2da44446f9dce2ae50fee78bac2734d4277143",
"status": "affected",
"version": "6434cf630086eea2d091f122f5802582a05d9d1c",
"versionType": "git"
},
{
"lessThan": "8887b94d2fc93071bf6ff09c39d474510e6f582f",
"status": "affected",
"version": "6434cf630086eea2d091f122f5802582a05d9d1c",
"versionType": "git"
},
{
"lessThan": "2084503f2d087bf956198e7f6eb25b03a7049cb2",
"status": "affected",
"version": "6434cf630086eea2d091f122f5802582a05d9d1c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_bios.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/bios: range check LFP Data Block panel_type2\n\nWhile the panel_type from LFP Data Block is range checked, panel_type2\nis not. Add a few helpers for range checking, and use them to not only\ncheck panel_type2, but also improve clarity and correctness in the panel\ntype selection.\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\nv2:\n- Fix commit message typo (Micha\u0142)\n- Add is_panel_type_pnp() (Ville)\n\n(cherry picked from commit c9ebe5d2f25729d6cfbbb1235d640bf67f9275df)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:37.262Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e7b5694645b03e80830dc141b59fc65aac693c70"
},
{
"url": "https://git.kernel.org/stable/c/8b2da44446f9dce2ae50fee78bac2734d4277143"
},
{
"url": "https://git.kernel.org/stable/c/8887b94d2fc93071bf6ff09c39d474510e6f582f"
},
{
"url": "https://git.kernel.org/stable/c/2084503f2d087bf956198e7f6eb25b03a7049cb2"
}
],
"title": "drm/i915/bios: range check LFP Data Block panel_type2",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68247",
"datePublished": "2026-08-10T12:01:13.466Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-17T05:01:37.262Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68402 (GCVE-0-2026-68402)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: bound element ID read when checking non-inheritance
cfg80211_is_element_inherited() reads the first data octet of the
candidate element (id = elem->data[0]) to look it up in an extension
non-inheritance list. It does so after testing elem->id, but without
verifying that the element actually has a data octet. A zero-length
extension element (WLAN_EID_EXTENSION with length 0) therefore makes it
read one octet past the end of the element.
_ieee802_11_parse_elems_full() runs this check for every element of a
frame once a non-inheritance context exists -- e.g. while parsing a
per-STA profile of a Multi-Link element in a (re)association response,
or a non-transmitted BSS profile -- so a crafted frame from an AP can
trigger a one-octet slab-out-of-bounds read during element parsing:
BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited
Read of size 1 ... in net/wireless/scan.c
Return early (treat the element as inherited) when an extension element
carries no data, mirroring the existing handling of empty ID lists.
The bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/scan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "521dd5fe6d12b0d3c275f919738dc3a07117f4a5",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "24154c172246ae3f0e69bb17c9111095685ceedc",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "2d31ebb26a14f103c9cdc5287fb20cb2d4bde901",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "20c308d9a57722801961f816395bf825f7bde6bc",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "84bd907361c56fbd5523eceb2682cb39da059bd5",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "11ac7a5e75f5132f1778e0c60981d30dc29fb869",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "ddf2773bcc8e49a43c561f22ec1e7924215d7947",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "cb8afea4655ff004fa7feee825d5c79783525383",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/scan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: bound element ID read when checking non-inheritance\n\ncfg80211_is_element_inherited() reads the first data octet of the\ncandidate element (id = elem-\u003edata[0]) to look it up in an extension\nnon-inheritance list. It does so after testing elem-\u003eid, but without\nverifying that the element actually has a data octet. A zero-length\nextension element (WLAN_EID_EXTENSION with length 0) therefore makes it\nread one octet past the end of the element.\n\n_ieee802_11_parse_elems_full() runs this check for every element of a\nframe once a non-inheritance context exists -- e.g. while parsing a\nper-STA profile of a Multi-Link element in a (re)association response,\nor a non-transmitted BSS profile -- so a crafted frame from an AP can\ntrigger a one-octet slab-out-of-bounds read during element parsing:\n\n BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited\n Read of size 1 ... in net/wireless/scan.c\n\nReturn early (treat the element as inherited) when an extension element\ncarries no data, mirroring the existing handling of empty ID lists.\n\nThe bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The malformed element arrives in an 802.11 management frame (beacon, probe response, ML probe response or (re)association response) processed by mac80211\u0027s element parser, so the attacker must be a rogue/spoofing AP within radio range of the victim station.\nAC:L - The attacker fully controls the frame contents and simply appends a zero-length WLAN_EID_EXTENSION element inside a frame that already establishes a non-inheritance context (multi-BSSID non-transmitted profile or a Multi-Link per-STA profile), which reliably triggers the over-read every time.\nPR:N - Beacons, probe responses and association responses are parsed before or independently of any authentication or key establishment, so an unauthenticated attacker with no credentials on the network can deliver the crafted frame.\nUI:N - Stations parse beacons and probe/association responses automatically as part of scanning, roaming and staying associated; no action by the device owner is needed for the crafted frame to be processed.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no other component or privilege domain is crossed.\nC:L - The read is a single octet past the end of the slab object, and its value is only compared against the non-inheritance ID list, influencing whether an element is parsed \u2014 this leaks at most a narrow side-channel oracle about one adjacent heap byte rather than arbitrary memory.\nI:N - The defect is purely a read; no kernel memory is written or corrupted, and the only consequence is a possibly wrong inherit/skip decision for one element in a frame the attacker already controls.\nA:H - The slab out-of-bounds access is fatal on KASAN, hardened or debug-allocator kernels (the bug was reported as a KASAN slab-out-of-bounds splat), and can be re-triggered at will by an adjacent unauthenticated attacker to repeatedly panic the machine."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:52.049Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/521dd5fe6d12b0d3c275f919738dc3a07117f4a5"
},
{
"url": "https://git.kernel.org/stable/c/24154c172246ae3f0e69bb17c9111095685ceedc"
},
{
"url": "https://git.kernel.org/stable/c/2d31ebb26a14f103c9cdc5287fb20cb2d4bde901"
},
{
"url": "https://git.kernel.org/stable/c/20c308d9a57722801961f816395bf825f7bde6bc"
},
{
"url": "https://git.kernel.org/stable/c/84bd907361c56fbd5523eceb2682cb39da059bd5"
},
{
"url": "https://git.kernel.org/stable/c/11ac7a5e75f5132f1778e0c60981d30dc29fb869"
},
{
"url": "https://git.kernel.org/stable/c/ddf2773bcc8e49a43c561f22ec1e7924215d7947"
},
{
"url": "https://git.kernel.org/stable/c/cb8afea4655ff004fa7feee825d5c79783525383"
}
],
"title": "wifi: cfg80211: bound element ID read when checking non-inheritance",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68402",
"datePublished": "2026-08-10T12:04:22.113Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:52.049Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64537 (GCVE-0-2026-64537)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bridge: cfm: reject invalid CCM interval at configuration time
ccm_tx_work_expired() re-arms itself via queue_delayed_work() using
the configured exp_interval converted by interval_to_us(). When
exp_interval is BR_CFM_CCM_INTERVAL_NONE or out of range,
interval_to_us() returns 0, causing the worker to fire immediately in
a tight loop that allocates skbs until OOM.
Fix this by validating exp_interval at configuration time:
- Constrain IFLA_BRIDGE_CFM_CC_CONFIG_EXP_INTERVAL to the valid range
[BR_CFM_CCM_INTERVAL_3_3_MS, BR_CFM_CCM_INTERVAL_10_MIN] in the
netlink policy so userspace cannot set an invalid value.
- Reject starting CCM TX in br_cfm_cc_ccm_tx() when exp_interval has
not yet been configured (defaults to 0 from kzalloc).
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2be665c3940d367e0a2a8128eb4985ce323f99a3 Version: 2be665c3940d367e0a2a8128eb4985ce323f99a3 Version: 2be665c3940d367e0a2a8128eb4985ce323f99a3 Version: 2be665c3940d367e0a2a8128eb4985ce323f99a3 Version: 2be665c3940d367e0a2a8128eb4985ce323f99a3 Version: 2be665c3940d367e0a2a8128eb4985ce323f99a3 Version: 2be665c3940d367e0a2a8128eb4985ce323f99a3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bridge/br_cfm.c",
"net/bridge/br_cfm_netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2870056a78961e0fecd652362ee9d3fcfd24a8a6",
"status": "affected",
"version": "2be665c3940d367e0a2a8128eb4985ce323f99a3",
"versionType": "git"
},
{
"lessThan": "f0f5eb59a97ece0d85de8cfa95dc18c609302a8b",
"status": "affected",
"version": "2be665c3940d367e0a2a8128eb4985ce323f99a3",
"versionType": "git"
},
{
"lessThan": "53788b134519e995699ea3721969c96a08d64575",
"status": "affected",
"version": "2be665c3940d367e0a2a8128eb4985ce323f99a3",
"versionType": "git"
},
{
"lessThan": "b42aeb58317f12024734759ff745856b53948873",
"status": "affected",
"version": "2be665c3940d367e0a2a8128eb4985ce323f99a3",
"versionType": "git"
},
{
"lessThan": "a090880c1f544589427e5b7050c40fb211ccecb4",
"status": "affected",
"version": "2be665c3940d367e0a2a8128eb4985ce323f99a3",
"versionType": "git"
},
{
"lessThan": "865643640b5b5c4579b32d7a55ac9ad648362eaa",
"status": "affected",
"version": "2be665c3940d367e0a2a8128eb4985ce323f99a3",
"versionType": "git"
},
{
"lessThan": "f3e02edd8322b31b8e6517faa6ba053bf29d1e26",
"status": "affected",
"version": "2be665c3940d367e0a2a8128eb4985ce323f99a3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bridge/br_cfm.c",
"net/bridge/br_cfm_netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: cfm: reject invalid CCM interval at configuration time\n\nccm_tx_work_expired() re-arms itself via queue_delayed_work() using\nthe configured exp_interval converted by interval_to_us(). When\nexp_interval is BR_CFM_CCM_INTERVAL_NONE or out of range,\ninterval_to_us() returns 0, causing the worker to fire immediately in\na tight loop that allocates skbs until OOM.\n\nFix this by validating exp_interval at configuration time:\n\n - Constrain IFLA_BRIDGE_CFM_CC_CONFIG_EXP_INTERVAL to the valid range\n [BR_CFM_CCM_INTERVAL_3_3_MS, BR_CFM_CCM_INTERVAL_10_MIN] in the\n netlink policy so userspace cannot set an invalid value.\n\n - Reject starting CCM TX in br_cfm_cc_ccm_tx() when exp_interval has\n not yet been configured (defaults to 0 from kzalloc)."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:13.368Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2870056a78961e0fecd652362ee9d3fcfd24a8a6"
},
{
"url": "https://git.kernel.org/stable/c/f0f5eb59a97ece0d85de8cfa95dc18c609302a8b"
},
{
"url": "https://git.kernel.org/stable/c/53788b134519e995699ea3721969c96a08d64575"
},
{
"url": "https://git.kernel.org/stable/c/b42aeb58317f12024734759ff745856b53948873"
},
{
"url": "https://git.kernel.org/stable/c/a090880c1f544589427e5b7050c40fb211ccecb4"
},
{
"url": "https://git.kernel.org/stable/c/865643640b5b5c4579b32d7a55ac9ad648362eaa"
},
{
"url": "https://git.kernel.org/stable/c/f3e02edd8322b31b8e6517faa6ba053bf29d1e26"
}
],
"title": "bridge: cfm: reject invalid CCM interval at configuration time",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64537",
"datePublished": "2026-07-27T20:10:32.210Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:13.368Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68160 (GCVE-0-2026-68160)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
ceph_handle_caps() reads snap_trace_len from the wire-format
ceph_mds_caps header and uses it unconditionally to build a fake
end pointer (snaptrace + snaptrace_len) that is later handed to
ceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:
snaptrace = h + 1;
snaptrace_len = le32_to_cpu(h->snap_trace_len);
p = snaptrace + snaptrace_len;
...
case CEPH_CAP_OP_IMPORT:
if (snaptrace_len) {
...
if (ceph_update_snap_trace(mdsc, snaptrace,
snaptrace + snaptrace_len,
false, &realm)) { ... }
ceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm
from snaptrace using ceph_decode_need(&p, e, sizeof(*ri), bad)
with the attacker-supplied fake end e == snaptrace + snaptrace_len.
With snaptrace_len == 0xFFFFFFFF the bound check is trivially
satisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past
the legitimate msg->front buffer, and ri->num_snaps /
ri->num_prior_parent_snaps then drive further out-of-bounds
reads of the encoded snap arrays.
The eleven msg_version >= 2 .. msg_version >= 12 decoder blocks
above the op switch each catch this OOB through their
ceph_decode_*_safe() / ceph_decode_need() helpers, but they sit
behind a hdr.version-gated if, so a malicious or compromised
MDS that sets msg->hdr.version = 1 reaches the IMPORT path with
no version-gated decoder having validated snap_trace_len. The
shape has been present since ceph_handle_caps() was introduced.
Validate snap_trace_len against the message front buffer before
consuming it, using the canonical ceph_decode_need() / ceph_has_room()
helper. The helper bounds the length with subtraction (n <= end - p,
guarded by end >= p) rather than pointer addition, so it is wrap-safe
for the attacker-controlled u32 length on 32-bit builds where
p + snap_trace_len could overflow the address space. This matches the
rest of the ceph decode path (e.g. the pool_ns_len check a few lines
below), and the existing goto bad cleanup already covers this exit
path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ceph/caps.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f913192fc782288e060dafc329b2346934be34cc",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "0c011137194036424e974677e0f1592e22a33d8c",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "cc93f68a31c9b831abf2db8647b5f5b10329d793",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "9081c71796724ffe96cba253f68fbe42363c5295",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "03b417afce19ee6b6e61f1bbbbebac924c9f36d1",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "a4228b93706fb74a484e6ffb271c1cc2af3a2ddb",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "71893c342a26bcff92eaab0b2b75d64aed19308a",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ceph/caps.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()\n\nceph_handle_caps() reads snap_trace_len from the wire-format\nceph_mds_caps header and uses it unconditionally to build a fake\nend pointer (snaptrace + snaptrace_len) that is later handed to\nceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:\n\n snaptrace = h + 1;\n snaptrace_len = le32_to_cpu(h-\u003esnap_trace_len);\n p = snaptrace + snaptrace_len;\n ...\n case CEPH_CAP_OP_IMPORT:\n if (snaptrace_len) {\n ...\n if (ceph_update_snap_trace(mdsc, snaptrace,\n snaptrace + snaptrace_len,\n false, \u0026realm)) { ... }\n\nceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm\nfrom snaptrace using ceph_decode_need(\u0026p, e, sizeof(*ri), bad)\nwith the attacker-supplied fake end e == snaptrace + snaptrace_len.\nWith snaptrace_len == 0xFFFFFFFF the bound check is trivially\nsatisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past\nthe legitimate msg-\u003efront buffer, and ri-\u003enum_snaps /\nri-\u003enum_prior_parent_snaps then drive further out-of-bounds\nreads of the encoded snap arrays.\n\nThe eleven msg_version \u003e= 2 .. msg_version \u003e= 12 decoder blocks\nabove the op switch each catch this OOB through their\nceph_decode_*_safe() / ceph_decode_need() helpers, but they sit\nbehind a hdr.version-gated if, so a malicious or compromised\nMDS that sets msg-\u003ehdr.version = 1 reaches the IMPORT path with\nno version-gated decoder having validated snap_trace_len. The\nshape has been present since ceph_handle_caps() was introduced.\n\nValidate snap_trace_len against the message front buffer before\nconsuming it, using the canonical ceph_decode_need() / ceph_has_room()\nhelper. The helper bounds the length with subtraction (n \u003c= end - p,\nguarded by end \u003e= p) rather than pointer addition, so it is wrap-safe\nfor the attacker-controlled u32 length on 32-bit builds where\np + snap_trace_len could overflow the address space. This matches the\nrest of the ceph decode path (e.g. the pool_ns_len check a few lines\nbelow), and the existing goto bad cleanup already covers this exit\npath."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - CEPH_MSG_CLIENT_CAPS is received over the kernel Ceph messenger TCP connection from an MDS peer; mds_dispatch() passes it directly to ceph_handle_caps(), so a malicious or compromised MDS (or on-path attacker on an unsigned msgr session) reaches the bug with network data alone.\nAC:L - The attacker fully controls msg-\u003ehdr.version and snap_trace_len in the caps header; setting version=1 bypasses all version-gated decoders and snap_trace_len=0xFFFFFFFF yields a fake end pointer that reliably defeats ceph_decode_need(), with no race or memory-layout dependency.\nPR:N - Exploitation requires only the ability to send crafted caps messages as the remote MDS peer on an established session; the attacker needs no account, mount privilege, or other credentials on the victim host beyond the client already being connected to that cluster.\nUI:N - Once CephFS is mounted and the MDS session is open, CEPH_CAP_OP_IMPORT caps messages are delivered and processed automatically during normal cap migration and MDS failover; no additional local user action is needed at exploit time beyond prior cluster connectivity.\nS:U - The out-of-bounds read and resulting snap-realm corruption affect only the kernel CephFS client\u2019s internal state within the same kernel security authority; there is no VM escape, sandbox breakout, or cross-authority boundary crossing.\nC:H - ceph_update_snap_trace() decodes struct ceph_mds_snap_realm and snap arrays using an attacker-supplied fake end pointer, reading sizeof(*ri) and further attacker-influenced extents past the legitimate msg-\u003efront buffer into adjacent kernel memory without copying to userspace.\nI:H - Out-of-bounds kernel memory is interpreted as snap-realm metadata and copied via dup_array() into newly allocated kernel heap structures (realm-\u003esnaps, realm-\u003eprior_parent_snaps), corrupting authoritative snap state and providing a memory-corruption primitive that could be leveraged for further kernel compromise.\nA:H - Out-of-bounds reads can fault on unmapped pages causing a kernel oops; the ceph_update_snap_trace() error path issues WARN(1), fences I/O via CEPH_MOUNT_FENCE_IO, and can close all MDS sessions\u2014effects an attacker can trigger repeatedly at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:32.455Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f913192fc782288e060dafc329b2346934be34cc"
},
{
"url": "https://git.kernel.org/stable/c/0c011137194036424e974677e0f1592e22a33d8c"
},
{
"url": "https://git.kernel.org/stable/c/cc93f68a31c9b831abf2db8647b5f5b10329d793"
},
{
"url": "https://git.kernel.org/stable/c/9081c71796724ffe96cba253f68fbe42363c5295"
},
{
"url": "https://git.kernel.org/stable/c/03b417afce19ee6b6e61f1bbbbebac924c9f36d1"
},
{
"url": "https://git.kernel.org/stable/c/a4228b93706fb74a484e6ffb271c1cc2af3a2ddb"
},
{
"url": "https://git.kernel.org/stable/c/71893c342a26bcff92eaab0b2b75d64aed19308a"
},
{
"url": "https://git.kernel.org/stable/c/4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02"
}
],
"title": "ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68160",
"datePublished": "2026-08-10T11:59:26.741Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:32.455Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-23227 (GCVE-0-2026-23227)
Vulnerability from cvelistv5
Published
2026-02-18 14:53
Modified
2026-08-05 12:20
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free
Exynos Virtual Display driver performs memory alloc/free operations
without lock protection, which easily causes concurrency problem.
For example, use-after-free can occur in race scenario like this:
```
CPU0 CPU1 CPU2
---- ---- ----
vidi_connection_ioctl()
if (vidi->connection) // true
drm_edid = drm_edid_alloc(); // alloc drm_edid
...
ctx->raw_edid = drm_edid;
...
drm_mode_getconnector()
drm_helper_probe_single_connector_modes()
vidi_get_modes()
if (ctx->raw_edid) // true
drm_edid_dup(ctx->raw_edid);
if (!drm_edid) // false
...
vidi_connection_ioctl()
if (vidi->connection) // false
drm_edid_free(ctx->raw_edid); // free drm_edid
...
drm_edid_alloc(drm_edid->edid)
kmemdup(edid); // UAF!!
...
```
To prevent these vulns, at least in vidi_context, member variables related
to memory alloc/free should be protected with ctx->lock.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d3b62dbfc7b9bb013926f56db79b60f6c18c392f Version: d3b62dbfc7b9bb013926f56db79b60f6c18c392f Version: d3b62dbfc7b9bb013926f56db79b60f6c18c392f Version: d3b62dbfc7b9bb013926f56db79b60f6c18c392f Version: d3b62dbfc7b9bb013926f56db79b60f6c18c392f Version: d3b62dbfc7b9bb013926f56db79b60f6c18c392f Version: d3b62dbfc7b9bb013926f56db79b60f6c18c392f Version: d3b62dbfc7b9bb013926f56db79b60f6c18c392f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/exynos/exynos_drm_vidi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "56966a4cfa925ec24edb68ab652a740a7abe2c4d",
"status": "affected",
"version": "d3b62dbfc7b9bb013926f56db79b60f6c18c392f",
"versionType": "git"
},
{
"lessThan": "9e1ef9396a1899925911b1729cb65665420268df",
"status": "affected",
"version": "d3b62dbfc7b9bb013926f56db79b60f6c18c392f",
"versionType": "git"
},
{
"lessThan": "92dd1f38d7db75374dcdaf54f1d79d67bffd54e5",
"status": "affected",
"version": "d3b62dbfc7b9bb013926f56db79b60f6c18c392f",
"versionType": "git"
},
{
"lessThan": "1b24d3e8792bcc050c70e8e0dea6b49c4fc63b13",
"status": "affected",
"version": "d3b62dbfc7b9bb013926f56db79b60f6c18c392f",
"versionType": "git"
},
{
"lessThan": "abfdf449fb3d7b42e85a1ad1c8694b768b1582f4",
"status": "affected",
"version": "d3b62dbfc7b9bb013926f56db79b60f6c18c392f",
"versionType": "git"
},
{
"lessThan": "60b75407c172e1f341a8a5097c5cbc97dbbdd893",
"status": "affected",
"version": "d3b62dbfc7b9bb013926f56db79b60f6c18c392f",
"versionType": "git"
},
{
"lessThan": "0cd2c155740dbd00868ac5a8ae5d14cd6b9ed385",
"status": "affected",
"version": "d3b62dbfc7b9bb013926f56db79b60f6c18c392f",
"versionType": "git"
},
{
"lessThan": "52b330799e2d6f825ae2bb74662ec1b10eb954bb",
"status": "affected",
"version": "d3b62dbfc7b9bb013926f56db79b60f6c18c392f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/exynos/exynos_drm_vidi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.6"
},
{
"lessThan": "3.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.253",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.77",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.253",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.167",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.77",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.11",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.1",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "3.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/exynos: vidi: use ctx-\u003elock to protect struct vidi_context member variables related to memory alloc/free\n\nExynos Virtual Display driver performs memory alloc/free operations\nwithout lock protection, which easily causes concurrency problem.\n\nFor example, use-after-free can occur in race scenario like this:\n```\n\tCPU0\t\t\t\tCPU1\t\t\t\tCPU2\n\t----\t\t\t\t----\t\t\t\t----\n vidi_connection_ioctl()\n if (vidi-\u003econnection) // true\n drm_edid = drm_edid_alloc(); // alloc drm_edid\n ...\n ctx-\u003eraw_edid = drm_edid;\n ...\n\t\t\t\t\t\t\t\tdrm_mode_getconnector()\n\t\t\t\t\t\t\t\t drm_helper_probe_single_connector_modes()\n\t\t\t\t\t\t\t\t vidi_get_modes()\n\t\t\t\t\t\t\t\t if (ctx-\u003eraw_edid) // true\n\t\t\t\t\t\t\t\t drm_edid_dup(ctx-\u003eraw_edid);\n\t\t\t\t\t\t\t\t if (!drm_edid) // false\n\t\t\t\t\t\t\t\t ...\n\t\t\t\tvidi_connection_ioctl()\n\t\t\t\t if (vidi-\u003econnection) // false\n\t\t\t\t drm_edid_free(ctx-\u003eraw_edid); // free drm_edid\n\t\t\t\t ...\n\t\t\t\t\t\t\t\t drm_edid_alloc(drm_edid-\u003eedid)\n\t\t\t\t\t\t\t\t kmemdup(edid); // UAF!!\n\t\t\t\t\t\t\t\t ...\n```\n\nTo prevent these vulns, at least in vidi_context, member variables related\nto memory alloc/free should be protected with ctx-\u003elock."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Requires local access to the DRM device node (/dev/dri/cardN) to issue the vidi_connection_ioctl and drm_mode_getconnector ioctls. Not reachable over network.\nAC:L - The attacker controls both sides of the race by issuing concurrent ioctls from multiple threads \u2014 one calling vidi_connection_ioctl to free raw_edid and another calling drm_mode_getconnector to read it.\nPR:L - The ioctl requires DRM_AUTH, which is granted to any process authenticated by the DRM master (display server). Any local user in a graphical session on an Exynos device has this access.\nUI:N - No victim action required; the attacker triggers the race entirely through their own concurrent ioctl calls.\nS:U - The vulnerability is in the kernel and impacts kernel memory; there is no crossing of a security boundary like VM escape or sandbox escape.\nC:H - The use-after-free allows reading freed memory via kmemdup on the reclaimed object, providing arbitrary memory read primitives when combined with heap spraying.\nI:H - The UAF enables heap spraying to reclaim the freed slot with attacker-controlled data, giving arbitrary write primitives and potential control flow hijacking for code execution.\nA:H - The use-after-free reliably causes kernel crashes (oops/panic) when the freed memory is accessed, providing a denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:20:45.582Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/56966a4cfa925ec24edb68ab652a740a7abe2c4d"
},
{
"url": "https://git.kernel.org/stable/c/9e1ef9396a1899925911b1729cb65665420268df"
},
{
"url": "https://git.kernel.org/stable/c/92dd1f38d7db75374dcdaf54f1d79d67bffd54e5"
},
{
"url": "https://git.kernel.org/stable/c/1b24d3e8792bcc050c70e8e0dea6b49c4fc63b13"
},
{
"url": "https://git.kernel.org/stable/c/abfdf449fb3d7b42e85a1ad1c8694b768b1582f4"
},
{
"url": "https://git.kernel.org/stable/c/60b75407c172e1f341a8a5097c5cbc97dbbdd893"
},
{
"url": "https://git.kernel.org/stable/c/0cd2c155740dbd00868ac5a8ae5d14cd6b9ed385"
},
{
"url": "https://git.kernel.org/stable/c/52b330799e2d6f825ae2bb74662ec1b10eb954bb"
}
],
"title": "drm/exynos: vidi: use ctx-\u003elock to protect struct vidi_context member variables related to memory alloc/free",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-23227",
"datePublished": "2026-02-18T14:53:30.784Z",
"dateReserved": "2026-01-13T15:37:45.987Z",
"dateUpdated": "2026-08-05T12:20:45.582Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-23210 (GCVE-0-2026-23210)
Vulnerability from cvelistv5
Published
2026-02-14 16:27
Modified
2026-06-11 18:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ice: Fix PTP NULL pointer dereference during VSI rebuild
Fix race condition where PTP periodic work runs while VSI is being
rebuilt, accessing NULL vsi->rx_rings.
The sequence was:
1. ice_ptp_prepare_for_reset() cancels PTP work
2. ice_ptp_rebuild() immediately queues PTP work
3. VSI rebuild happens AFTER ice_ptp_rebuild()
4. PTP work runs and accesses NULL vsi->rx_rings
Fix: Keep PTP work cancelled during rebuild, only queue it after
VSI rebuild completes in ice_rebuild().
Added ice_ptp_queue_work() helper function to encapsulate the logic
for queuing PTP work, ensuring it's only queued when PTP is supported
and the state is ICE_PTP_READY.
Error log:
[ 121.392544] ice 0000:60:00.1: PTP reset successful
[ 121.392692] BUG: kernel NULL pointer dereference, address: 0000000000000000
[ 121.392712] #PF: supervisor read access in kernel mode
[ 121.392720] #PF: error_code(0x0000) - not-present page
[ 121.392727] PGD 0
[ 121.392734] Oops: Oops: 0000 [#1] SMP NOPTI
[ 121.392746] CPU: 8 UID: 0 PID: 1005 Comm: ice-ptp-0000:60 Tainted: G S 6.19.0-rc6+ #4 PREEMPT(voluntary)
[ 121.392761] Tainted: [S]=CPU_OUT_OF_SPEC
[ 121.392773] RIP: 0010:ice_ptp_update_cached_phctime+0xbf/0x150 [ice]
[ 121.393042] Call Trace:
[ 121.393047] <TASK>
[ 121.393055] ice_ptp_periodic_work+0x69/0x180 [ice]
[ 121.393202] kthread_worker_fn+0xa2/0x260
[ 121.393216] ? __pfx_ice_ptp_periodic_work+0x10/0x10 [ice]
[ 121.393359] ? __pfx_kthread_worker_fn+0x10/0x10
[ 121.393371] kthread+0x10d/0x230
[ 121.393382] ? __pfx_kthread+0x10/0x10
[ 121.393393] ret_from_fork+0x273/0x2b0
[ 121.393407] ? __pfx_kthread+0x10/0x10
[ 121.393417] ret_from_fork_asm+0x1a/0x30
[ 121.393432] </TASK>
References
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-23210",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-10T20:41:52.270125Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-11T18:44:17.033Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/ice/ice_main.c",
"drivers/net/ethernet/intel/ice/ice_ptp.c",
"drivers/net/ethernet/intel/ice/ice_ptp.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ba0c7fff6616025a7d3a9e887e7ce16b06dc34b9",
"status": "affected",
"version": "803bef817807d2d36c930dada20c96fffae0dd19",
"versionType": "git"
},
{
"lessThan": "7565d4df66b6619b50dc36618d8b8f1787d77e19",
"status": "affected",
"version": "803bef817807d2d36c930dada20c96fffae0dd19",
"versionType": "git"
},
{
"lessThan": "fc6f36eaaedcf4b81af6fe1a568f018ffd530660",
"status": "affected",
"version": "803bef817807d2d36c930dada20c96fffae0dd19",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/ice/ice_main.c",
"drivers/net/ethernet/intel/ice/ice_ptp.c",
"drivers/net/ethernet/intel/ice/ice_ptp.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.80",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.80",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.10",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix PTP NULL pointer dereference during VSI rebuild\n\nFix race condition where PTP periodic work runs while VSI is being\nrebuilt, accessing NULL vsi-\u003erx_rings.\n\nThe sequence was:\n1. ice_ptp_prepare_for_reset() cancels PTP work\n2. ice_ptp_rebuild() immediately queues PTP work\n3. VSI rebuild happens AFTER ice_ptp_rebuild()\n4. PTP work runs and accesses NULL vsi-\u003erx_rings\n\nFix: Keep PTP work cancelled during rebuild, only queue it after\nVSI rebuild completes in ice_rebuild().\n\nAdded ice_ptp_queue_work() helper function to encapsulate the logic\nfor queuing PTP work, ensuring it\u0027s only queued when PTP is supported\nand the state is ICE_PTP_READY.\n\nError log:\n[ 121.392544] ice 0000:60:00.1: PTP reset successful\n[ 121.392692] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 121.392712] #PF: supervisor read access in kernel mode\n[ 121.392720] #PF: error_code(0x0000) - not-present page\n[ 121.392727] PGD 0\n[ 121.392734] Oops: Oops: 0000 [#1] SMP NOPTI\n[ 121.392746] CPU: 8 UID: 0 PID: 1005 Comm: ice-ptp-0000:60 Tainted: G S 6.19.0-rc6+ #4 PREEMPT(voluntary)\n[ 121.392761] Tainted: [S]=CPU_OUT_OF_SPEC\n[ 121.392773] RIP: 0010:ice_ptp_update_cached_phctime+0xbf/0x150 [ice]\n[ 121.393042] Call Trace:\n[ 121.393047] \u003cTASK\u003e\n[ 121.393055] ice_ptp_periodic_work+0x69/0x180 [ice]\n[ 121.393202] kthread_worker_fn+0xa2/0x260\n[ 121.393216] ? __pfx_ice_ptp_periodic_work+0x10/0x10 [ice]\n[ 121.393359] ? __pfx_kthread_worker_fn+0x10/0x10\n[ 121.393371] kthread+0x10d/0x230\n[ 121.393382] ? __pfx_kthread+0x10/0x10\n[ 121.393393] ret_from_fork+0x273/0x2b0\n[ 121.393407] ? __pfx_kthread+0x10/0x10\n[ 121.393417] ret_from_fork_asm+0x1a/0x30\n[ 121.393432] \u003c/TASK\u003e"
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T22:02:27.163Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ba0c7fff6616025a7d3a9e887e7ce16b06dc34b9"
},
{
"url": "https://git.kernel.org/stable/c/7565d4df66b6619b50dc36618d8b8f1787d77e19"
},
{
"url": "https://git.kernel.org/stable/c/fc6f36eaaedcf4b81af6fe1a568f018ffd530660"
}
],
"title": "ice: Fix PTP NULL pointer dereference during VSI rebuild",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-23210",
"datePublished": "2026-02-14T16:27:31.892Z",
"dateReserved": "2026-01-13T15:37:45.986Z",
"dateUpdated": "2026-06-11T18:44:17.033Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64512 (GCVE-0-2026-64512)
Vulnerability from cvelistv5
Published
2026-07-25 08:52
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ACPI: CPPC: Suppress UBSAN warning caused by field misuse
The definition of reg->access_width changes depending on the
reg->space_id type. Type ACPI_ADR_SPACE_PLATFORM_COMM uses
access_width to indicate the PCC region, which can result in a UBSAN
if the value is greater than 4.
For example:
UBSAN: shift-out-of-bounds in drivers/acpi/cppc_acpi.c:1090:9
shift exponent 32 is too large for 32-bit type 'int'
CPU: 61 UID: 0 PID: 1220 Comm: (udev-worker) Not tainted 7.0.10-201.fc44.aarch64 #1 PREEMPT(lazy)
Hardware name: To be filled by O.E.M.
Call trace:
...(trimming)
ubsan_epilogue+0x10/0x48
__ubsan_handle_shift_out_of_bounds+0xdc/0x1e0
cpc_write+0x4d0/0x670
cppc_set_perf+0x18c/0x490
cppc_cpufreq_cpu_init+0x1c8/0x380 [cppc_cpufreq]
... (trimming)
Lets fix this by validating the region type, as well as whether
access_width has a value. Then since we are returning bit_width
directly for ACPI_ADR_SPACE_PLATFORM_COMM, drop the code correcting
the size.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4949affd5288b867cdf115f5b08d6166b2027f87 Version: 01fc53be672acae37e611c80cc0b4f3939584de3 Version: 1b890ae474d19800a6be1696df7fb4d9a41676e4 Version: 2f4a4d63a193be6fd530d180bb13c3592052904c Version: 2f4a4d63a193be6fd530d180bb13c3592052904c Version: 2f4a4d63a193be6fd530d180bb13c3592052904c Version: 2f4a4d63a193be6fd530d180bb13c3592052904c Version: 6cb6b12b78dcd8867a3fdbb1b6d0ed1df2b208d1 Version: 5.15.154 ≤ Version: 6.1.90 ≤ Version: 6.6.30 ≤ Version: 6.8.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/acpi/cppc_acpi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b54c4632946ae42f2b39ed38abd909bbf78cbcc2",
"status": "affected",
"version": "4949affd5288b867cdf115f5b08d6166b2027f87",
"versionType": "git"
},
{
"lessThan": "e904596ba6dd108534ffa15e3e46b2fe245145e2",
"status": "affected",
"version": "01fc53be672acae37e611c80cc0b4f3939584de3",
"versionType": "git"
},
{
"lessThan": "2fb80e962029000959f651665baa4838cc92eb99",
"status": "affected",
"version": "1b890ae474d19800a6be1696df7fb4d9a41676e4",
"versionType": "git"
},
{
"lessThan": "37f28bf8f14672dfa395994e41fd778a63f0bf5c",
"status": "affected",
"version": "2f4a4d63a193be6fd530d180bb13c3592052904c",
"versionType": "git"
},
{
"lessThan": "f29dc6132d4968e39d8fa575d1a12e2c718ce57b",
"status": "affected",
"version": "2f4a4d63a193be6fd530d180bb13c3592052904c",
"versionType": "git"
},
{
"lessThan": "dc066bd13c860bb27d6ace511210e18b8064c1d9",
"status": "affected",
"version": "2f4a4d63a193be6fd530d180bb13c3592052904c",
"versionType": "git"
},
{
"lessThan": "1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1",
"status": "affected",
"version": "2f4a4d63a193be6fd530d180bb13c3592052904c",
"versionType": "git"
},
{
"status": "affected",
"version": "6cb6b12b78dcd8867a3fdbb1b6d0ed1df2b208d1",
"versionType": "git"
},
{
"lessThan": "5.15.155",
"status": "affected",
"version": "5.15.154",
"versionType": "semver"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.90",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.30",
"versionType": "semver"
},
{
"lessThan": "6.9",
"status": "affected",
"version": "6.8.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/acpi/cppc_acpi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.155",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.155",
"versionStartIncluding": "5.15.154",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.90",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.8.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Suppress UBSAN warning caused by field misuse\n\nThe definition of reg-\u003eaccess_width changes depending on the\nreg-\u003espace_id type. Type ACPI_ADR_SPACE_PLATFORM_COMM uses\naccess_width to indicate the PCC region, which can result in a UBSAN\nif the value is greater than 4.\n\nFor example:\n\n UBSAN: shift-out-of-bounds in drivers/acpi/cppc_acpi.c:1090:9\n shift exponent 32 is too large for 32-bit type \u0027int\u0027\n CPU: 61 UID: 0 PID: 1220 Comm: (udev-worker) Not tainted 7.0.10-201.fc44.aarch64 #1 PREEMPT(lazy)\n Hardware name: To be filled by O.E.M.\n Call trace:\n ...(trimming)\n ubsan_epilogue+0x10/0x48\n __ubsan_handle_shift_out_of_bounds+0xdc/0x1e0\n cpc_write+0x4d0/0x670\n cppc_set_perf+0x18c/0x490\n cppc_cpufreq_cpu_init+0x1c8/0x380 [cppc_cpufreq]\n ... (trimming)\n\nLets fix this by validating the region type, as well as whether\naccess_width has a value. Then since we are returning bit_width\ndirectly for ACPI_ADR_SPACE_PLATFORM_COMM, drop the code correcting\nthe size."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:03.207Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2"
},
{
"url": "https://git.kernel.org/stable/c/e904596ba6dd108534ffa15e3e46b2fe245145e2"
},
{
"url": "https://git.kernel.org/stable/c/2fb80e962029000959f651665baa4838cc92eb99"
},
{
"url": "https://git.kernel.org/stable/c/37f28bf8f14672dfa395994e41fd778a63f0bf5c"
},
{
"url": "https://git.kernel.org/stable/c/f29dc6132d4968e39d8fa575d1a12e2c718ce57b"
},
{
"url": "https://git.kernel.org/stable/c/dc066bd13c860bb27d6ace511210e18b8064c1d9"
},
{
"url": "https://git.kernel.org/stable/c/1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1"
}
],
"title": "ACPI: CPPC: Suppress UBSAN warning caused by field misuse",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64512",
"datePublished": "2026-07-25T08:52:04.423Z",
"dateReserved": "2026-07-19T15:36:31.793Z",
"dateUpdated": "2026-08-17T04:57:03.207Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68115 (GCVE-0-2026-68115)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit ac6f00beb658239bced4aaed9efbb04a35348d48)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a5de4c9065db8653a3af8a1d4cf5f3c0024c480a",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "e994f4391b574bd57e7ac183ab93c3d60e8d4d55",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "5c23b018c64f9e8f28e407f313616dccd51b684f",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "793cdf17ddf9dc662a94cae86ce005565ef3c1c2",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "6c8cfdc2321c1284dc4320ac148867ea8f6419bd",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "7e22de67e545d0f72595514d3a66675e9d074adc",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "2929a932b0d70f481dbcb6994181544b07913de0",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "d06c4173a7c38c7a39e98859f839ce714c7af2c9",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit ac6f00beb658239bced4aaed9efbb04a35348d48)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:26.881Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a5de4c9065db8653a3af8a1d4cf5f3c0024c480a"
},
{
"url": "https://git.kernel.org/stable/c/e994f4391b574bd57e7ac183ab93c3d60e8d4d55"
},
{
"url": "https://git.kernel.org/stable/c/5c23b018c64f9e8f28e407f313616dccd51b684f"
},
{
"url": "https://git.kernel.org/stable/c/793cdf17ddf9dc662a94cae86ce005565ef3c1c2"
},
{
"url": "https://git.kernel.org/stable/c/6c8cfdc2321c1284dc4320ac148867ea8f6419bd"
},
{
"url": "https://git.kernel.org/stable/c/7e22de67e545d0f72595514d3a66675e9d074adc"
},
{
"url": "https://git.kernel.org/stable/c/2929a932b0d70f481dbcb6994181544b07913de0"
},
{
"url": "https://git.kernel.org/stable/c/d06c4173a7c38c7a39e98859f839ce714c7af2c9"
}
],
"title": "drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68115",
"datePublished": "2026-08-10T11:58:33.594Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:26.881Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72020 (GCVE-0-2026-72020)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-17 05:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
Commit 9a05475cebdd ("ipvs: avoid kmem_cache_zalloc in
ip_vs_conn_new") changed ip_vs_conn_new() to allocate an ip_vs_conn
object with kmem_cache_alloc(). The function then initializes many
fields explicitly, but only resets in_seq.delta and out_seq.delta in the
two struct ip_vs_seq members.
That leaves init_seq and previous_delta uninitialized. This is normally
harmless while the corresponding IP_VS_CONN_F_IN_SEQ or
IP_VS_CONN_F_OUT_SEQ flag is clear. For connections learned from a sync
message, however, ip_vs_proc_conn() preserves those flags from
IP_VS_CONN_F_BACKUP_MASK and passes opt=NULL when the message omits
IPVS_OPT_SEQ_DATA. In that case the new connection can be hashed with
SEQ flags set but with the rest of in_seq/out_seq still containing stale
slab data.
When a packet for such a connection is later handled by an IPVS
application helper, vs_fix_seq() and vs_fix_ack_seq() use
previous_delta and init_seq to rewrite TCP sequence numbers. A malformed
sync message can therefore make forwarded packets carry stale slab bytes
in their TCP seq/ack numbers, and can also corrupt the forwarded TCP
flow.
Reset both struct ip_vs_seq members completely before publishing the
connection. This matches the existing "reset struct ip_vs_seq" comment
and keeps the sequence-adjustment gates inactive unless valid sequence
data is installed later.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9a05475cebdd6341884b5901e53870be26e65158 Version: 9a05475cebdd6341884b5901e53870be26e65158 Version: 9a05475cebdd6341884b5901e53870be26e65158 Version: 9a05475cebdd6341884b5901e53870be26e65158 Version: 9a05475cebdd6341884b5901e53870be26e65158 Version: 9a05475cebdd6341884b5901e53870be26e65158 Version: 9a05475cebdd6341884b5901e53870be26e65158 Version: 9a05475cebdd6341884b5901e53870be26e65158 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipvs/ip_vs_conn.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3bf9a260188b2a5449cbddc032a749ab433fe328",
"status": "affected",
"version": "9a05475cebdd6341884b5901e53870be26e65158",
"versionType": "git"
},
{
"lessThan": "6378c5cb360eb1750f88839d7c3613ea92ac1816",
"status": "affected",
"version": "9a05475cebdd6341884b5901e53870be26e65158",
"versionType": "git"
},
{
"lessThan": "32c299e28b8eea6cbbd23b97dc61401e9ef9c445",
"status": "affected",
"version": "9a05475cebdd6341884b5901e53870be26e65158",
"versionType": "git"
},
{
"lessThan": "9e36602cbec552286f7e691cfd366525c565ee74",
"status": "affected",
"version": "9a05475cebdd6341884b5901e53870be26e65158",
"versionType": "git"
},
{
"lessThan": "d0eed7177e822cab83141e5c44b2aa345c7fd379",
"status": "affected",
"version": "9a05475cebdd6341884b5901e53870be26e65158",
"versionType": "git"
},
{
"lessThan": "83fb4c2c5344f02eac929f66de3c9d1adfcde04c",
"status": "affected",
"version": "9a05475cebdd6341884b5901e53870be26e65158",
"versionType": "git"
},
{
"lessThan": "6335ab62d5fc9ed875279238233fba3462c168f5",
"status": "affected",
"version": "9a05475cebdd6341884b5901e53870be26e65158",
"versionType": "git"
},
{
"lessThan": "2975324d164c552b028632f107b567302863b7f6",
"status": "affected",
"version": "9a05475cebdd6341884b5901e53870be26e65158",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipvs/ip_vs_conn.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: reset full ip_vs_seq structs in ip_vs_conn_new\n\nCommit 9a05475cebdd (\"ipvs: avoid kmem_cache_zalloc in\nip_vs_conn_new\") changed ip_vs_conn_new() to allocate an ip_vs_conn\nobject with kmem_cache_alloc(). The function then initializes many\nfields explicitly, but only resets in_seq.delta and out_seq.delta in the\ntwo struct ip_vs_seq members.\n\nThat leaves init_seq and previous_delta uninitialized. This is normally\nharmless while the corresponding IP_VS_CONN_F_IN_SEQ or\nIP_VS_CONN_F_OUT_SEQ flag is clear. For connections learned from a sync\nmessage, however, ip_vs_proc_conn() preserves those flags from\nIP_VS_CONN_F_BACKUP_MASK and passes opt=NULL when the message omits\nIPVS_OPT_SEQ_DATA. In that case the new connection can be hashed with\nSEQ flags set but with the rest of in_seq/out_seq still containing stale\nslab data.\n\nWhen a packet for such a connection is later handled by an IPVS\napplication helper, vs_fix_seq() and vs_fix_ack_seq() use\nprevious_delta and init_seq to rewrite TCP sequence numbers. A malformed\nsync message can therefore make forwarded packets carry stale slab bytes\nin their TCP seq/ack numbers, and can also corrupt the forwarded TCP\nflow.\n\nReset both struct ip_vs_seq members completely before publishing the\nconnection. This matches the existing \"reset struct ip_vs_seq\" comment\nand keeps the sequence-adjustment gates inactive unless valid sequence\ndata is installed later."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached when a host running the IPVS backup sync receiver processes forged UDP sync datagrams (default multicast 224.0.0.81:8848) in ip_vs_process_message(), which is a network packet receive path rather than a local-only ioctl/netlink interface.\nAC:L - Once IPVS backup sync is enabled, an attacker can reliably send IPVS v1 messages that set IP_VS_CONN_F_IN_SEQ/OUT_SEQ while omitting IPVS_OPT_SEQ_DATA; no race, heap grooming, or victim-specific state beyond matching syncid (often 0) is required.\nPR:N - The backup sync socket accepts unauthenticated UDP input with no capability checks; only an optional syncid filter (frequently left at 0) may drop messages, so the attacker needs no Linux privileges to inject the malformed sync records.\nUI:N - No end-user or administrator interaction is required at exploit time; the attacker directly delivers crafted sync messages to the listening backup daemon without victims opening files, clicking links, or changing settings.\nS:U - Exploitation stays within the IPVS load balancer kernel/network authority and affects connections it forwards; it does not constitute a VM escape, sandbox breakout, or cross-security-authority boundary such as guest-to-host.\nC:H - Uninitialized ip_vs_seq init_seq and previous_delta fields retain stale slab data that vs_fix_seq()/vs_fix_ack_seq() apply when rewriting forwarded TCP seq/ack numbers, leaking kernel heap bytes onto the network to clients or backend servers.\nI:H - Those same uninitialized sequence-adjustment fields cause incorrect TCP sequence/ack rewriting in NAT/application-helper paths (ip_vs_app_pkt_in/out), corrupting load-balanced TCP flows and enabling attacker-driven manipulation of forwarded traffic integrity.\nA:H - Corrupted TCP sequence handling breaks or resets connections on the virtual service and can be triggered repeatedly via additional forged sync messages, causing sustained denial of service to load-balanced traffic on the affected backup node."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:39:30.496Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3bf9a260188b2a5449cbddc032a749ab433fe328"
},
{
"url": "https://git.kernel.org/stable/c/6378c5cb360eb1750f88839d7c3613ea92ac1816"
},
{
"url": "https://git.kernel.org/stable/c/32c299e28b8eea6cbbd23b97dc61401e9ef9c445"
},
{
"url": "https://git.kernel.org/stable/c/9e36602cbec552286f7e691cfd366525c565ee74"
},
{
"url": "https://git.kernel.org/stable/c/d0eed7177e822cab83141e5c44b2aa345c7fd379"
},
{
"url": "https://git.kernel.org/stable/c/83fb4c2c5344f02eac929f66de3c9d1adfcde04c"
},
{
"url": "https://git.kernel.org/stable/c/6335ab62d5fc9ed875279238233fba3462c168f5"
},
{
"url": "https://git.kernel.org/stable/c/2975324d164c552b028632f107b567302863b7f6"
}
],
"title": "ipvs: reset full ip_vs_seq structs in ip_vs_conn_new",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72020",
"datePublished": "2026-08-15T05:51:46.675Z",
"dateReserved": "2026-08-09T03:40:39.900Z",
"dateUpdated": "2026-08-17T05:39:30.496Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-52975 (GCVE-0-2026-52975)
Vulnerability from cvelistv5
Published
2026-06-24 16:28
Modified
2026-08-05 12:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bonding: 3ad: implement proper RCU rules for port->aggregator
syzbot found a data-race in bond_3ad_get_active_agg_info /
bond_3ad_state_machine_handler [1] which hints at lack of proper
RCU implementation.
Add __rcu qualifier to port->aggregator, and add proper RCU API.
[1]
BUG: KCSAN: data-race in bond_3ad_get_active_agg_info / bond_3ad_state_machine_handler
write to 0xffff88813cf5c4b0 of 8 bytes by task 36 on cpu 0:
ad_port_selection_logic drivers/net/bonding/bond_3ad.c:1659 [inline]
bond_3ad_state_machine_handler+0x9d5/0x2d60 drivers/net/bonding/bond_3ad.c:2569
process_one_work kernel/workqueue.c:3302 [inline]
process_scheduled_works+0x4f0/0x9c0 kernel/workqueue.c:3385
worker_thread+0x58a/0x780 kernel/workqueue.c:3466
kthread+0x22a/0x280 kernel/kthread.c:436
ret_from_fork+0x146/0x330 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
read to 0xffff88813cf5c4b0 of 8 bytes by task 22063 on cpu 1:
__bond_3ad_get_active_agg_info drivers/net/bonding/bond_3ad.c:2858 [inline]
bond_3ad_get_active_agg_info+0x8c/0x230 drivers/net/bonding/bond_3ad.c:2881
bond_fill_info+0xe0f/0x10f0 drivers/net/bonding/bond_netlink.c:853
rtnl_link_info_fill net/core/rtnetlink.c:906 [inline]
rtnl_link_fill+0x1d7/0x4e0 net/core/rtnetlink.c:927
rtnl_fill_ifinfo+0xf8e/0x1380 net/core/rtnetlink.c:2168
rtmsg_ifinfo_build_skb+0x11c/0x1b0 net/core/rtnetlink.c:4453
rtmsg_ifinfo_event net/core/rtnetlink.c:4486 [inline]
rtmsg_ifinfo+0x6d/0x110 net/core/rtnetlink.c:4495
__dev_notify_flags+0x76/0x390 net/core/dev.c:9790
netif_change_flags+0xac/0xd0 net/core/dev.c:9823
do_setlink+0x905/0x2950 net/core/rtnetlink.c:3180
rtnl_group_changelink net/core/rtnetlink.c:3813 [inline]
__rtnl_newlink net/core/rtnetlink.c:3981 [inline]
rtnl_newlink+0xf55/0x1400 net/core/rtnetlink.c:4109
rtnetlink_rcv_msg+0x64b/0x720 net/core/rtnetlink.c:6995
netlink_rcv_skb+0x123/0x220 net/netlink/af_netlink.c:2550
rtnetlink_rcv+0x1c/0x30 net/core/rtnetlink.c:7022
netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]
netlink_unicast+0x5a8/0x680 net/netlink/af_netlink.c:1344
netlink_sendmsg+0x5c8/0x6f0 net/netlink/af_netlink.c:1894
sock_sendmsg_nosec net/socket.c:787 [inline]
__sock_sendmsg net/socket.c:802 [inline]
____sys_sendmsg+0x563/0x5b0 net/socket.c:2698
___sys_sendmsg+0x195/0x1e0 net/socket.c:2752
__sys_sendmsg net/socket.c:2784 [inline]
__do_sys_sendmsg net/socket.c:2789 [inline]
__se_sys_sendmsg net/socket.c:2787 [inline]
__x64_sys_sendmsg+0xd4/0x160 net/socket.c:2787
x64_sys_call+0x194c/0x3020 arch/x86/include/generated/asm/syscalls_64.h:47
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x12c/0x3b0 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
value changed: 0x0000000000000000 -> 0xffff88813cf5c400
Reported by Kernel Concurrency Sanitizer on:
CPU: 1 UID: 0 PID: 22063 Comm: syz.0.31122 Tainted: G W syzkaller #0 PREEMPT(full)
Tainted: [W]=WARN
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 47e91f56008b43e1365e8d1d4a6813fe8a33b6f6 Version: 47e91f56008b43e1365e8d1d4a6813fe8a33b6f6 Version: 47e91f56008b43e1365e8d1d4a6813fe8a33b6f6 Version: 47e91f56008b43e1365e8d1d4a6813fe8a33b6f6 Version: 47e91f56008b43e1365e8d1d4a6813fe8a33b6f6 Version: 47e91f56008b43e1365e8d1d4a6813fe8a33b6f6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_3ad.c",
"drivers/net/bonding/bond_main.c",
"drivers/net/bonding/bond_netlink.c",
"drivers/net/bonding/bond_procfs.c",
"drivers/net/bonding/bond_sysfs_slave.c",
"include/net/bond_3ad.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ba2272be04f0cb1e74e1e355ff32ef95df280731",
"status": "affected",
"version": "47e91f56008b43e1365e8d1d4a6813fe8a33b6f6",
"versionType": "git"
},
{
"lessThan": "3b7265b3a82f40d2357c4004b26eb794a095b186",
"status": "affected",
"version": "47e91f56008b43e1365e8d1d4a6813fe8a33b6f6",
"versionType": "git"
},
{
"lessThan": "5fb9ea4e8ebf514d92df2b6c9d0db25ba02ac735",
"status": "affected",
"version": "47e91f56008b43e1365e8d1d4a6813fe8a33b6f6",
"versionType": "git"
},
{
"lessThan": "c169c5837525ad842df6a542facf52b6f866a519",
"status": "affected",
"version": "47e91f56008b43e1365e8d1d4a6813fe8a33b6f6",
"versionType": "git"
},
{
"lessThan": "78f409fd34fe9de2b24ad8e9dca1b4608a48ed3d",
"status": "affected",
"version": "47e91f56008b43e1365e8d1d4a6813fe8a33b6f6",
"versionType": "git"
},
{
"lessThan": "c4f050ce06c56cfb5993268af4a5cb66ed1cd04e",
"status": "affected",
"version": "47e91f56008b43e1365e8d1d4a6813fe8a33b6f6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_3ad.c",
"drivers/net/bonding/bond_main.c",
"drivers/net/bonding/bond_netlink.c",
"drivers/net/bonding/bond_procfs.c",
"drivers/net/bonding/bond_sysfs_slave.c",
"include/net/bond_3ad.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.13"
},
{
"lessThan": "3.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: 3ad: implement proper RCU rules for port-\u003eaggregator\n\nsyzbot found a data-race in bond_3ad_get_active_agg_info /\nbond_3ad_state_machine_handler [1] which hints at lack of proper\nRCU implementation.\n\nAdd __rcu qualifier to port-\u003eaggregator, and add proper RCU API.\n\n[1]\n\nBUG: KCSAN: data-race in bond_3ad_get_active_agg_info / bond_3ad_state_machine_handler\n\nwrite to 0xffff88813cf5c4b0 of 8 bytes by task 36 on cpu 0:\n ad_port_selection_logic drivers/net/bonding/bond_3ad.c:1659 [inline]\n bond_3ad_state_machine_handler+0x9d5/0x2d60 drivers/net/bonding/bond_3ad.c:2569\n process_one_work kernel/workqueue.c:3302 [inline]\n process_scheduled_works+0x4f0/0x9c0 kernel/workqueue.c:3385\n worker_thread+0x58a/0x780 kernel/workqueue.c:3466\n kthread+0x22a/0x280 kernel/kthread.c:436\n ret_from_fork+0x146/0x330 arch/x86/kernel/process.c:158\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n\nread to 0xffff88813cf5c4b0 of 8 bytes by task 22063 on cpu 1:\n __bond_3ad_get_active_agg_info drivers/net/bonding/bond_3ad.c:2858 [inline]\n bond_3ad_get_active_agg_info+0x8c/0x230 drivers/net/bonding/bond_3ad.c:2881\n bond_fill_info+0xe0f/0x10f0 drivers/net/bonding/bond_netlink.c:853\n rtnl_link_info_fill net/core/rtnetlink.c:906 [inline]\n rtnl_link_fill+0x1d7/0x4e0 net/core/rtnetlink.c:927\n rtnl_fill_ifinfo+0xf8e/0x1380 net/core/rtnetlink.c:2168\n rtmsg_ifinfo_build_skb+0x11c/0x1b0 net/core/rtnetlink.c:4453\n rtmsg_ifinfo_event net/core/rtnetlink.c:4486 [inline]\n rtmsg_ifinfo+0x6d/0x110 net/core/rtnetlink.c:4495\n __dev_notify_flags+0x76/0x390 net/core/dev.c:9790\n netif_change_flags+0xac/0xd0 net/core/dev.c:9823\n do_setlink+0x905/0x2950 net/core/rtnetlink.c:3180\n rtnl_group_changelink net/core/rtnetlink.c:3813 [inline]\n __rtnl_newlink net/core/rtnetlink.c:3981 [inline]\n rtnl_newlink+0xf55/0x1400 net/core/rtnetlink.c:4109\n rtnetlink_rcv_msg+0x64b/0x720 net/core/rtnetlink.c:6995\n netlink_rcv_skb+0x123/0x220 net/netlink/af_netlink.c:2550\n rtnetlink_rcv+0x1c/0x30 net/core/rtnetlink.c:7022\n netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]\n netlink_unicast+0x5a8/0x680 net/netlink/af_netlink.c:1344\n netlink_sendmsg+0x5c8/0x6f0 net/netlink/af_netlink.c:1894\n sock_sendmsg_nosec net/socket.c:787 [inline]\n __sock_sendmsg net/socket.c:802 [inline]\n ____sys_sendmsg+0x563/0x5b0 net/socket.c:2698\n ___sys_sendmsg+0x195/0x1e0 net/socket.c:2752\n __sys_sendmsg net/socket.c:2784 [inline]\n __do_sys_sendmsg net/socket.c:2789 [inline]\n __se_sys_sendmsg net/socket.c:2787 [inline]\n __x64_sys_sendmsg+0xd4/0x160 net/socket.c:2787\n x64_sys_call+0x194c/0x3020 arch/x86/include/generated/asm/syscalls_64.h:47\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x12c/0x3b0 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nvalue changed: 0x0000000000000000 -\u003e 0xffff88813cf5c400\n\nReported by Kernel Concurrency Sanitizer on:\nCPU: 1 UID: 0 PID: 22063 Comm: syz.0.31122 Tainted: G W syzkaller #0 PREEMPT(full)\nTainted: [W]=WARN\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable paths are local bonding control/information paths such as rtnetlink, sysfs, and procfs racing with the 802.3ad workqueue. A remote packet alone is not sufficient for the complete race; a local attacker can exercise the reader and drive bond state changes.\nAC:L - A local attacker can create/configure an 802.3ad bond in a user/network namespace and repeatedly issue concurrent link queries while the bond workqueue updates port-\u003eaggregator. The race is attacker-influenced and does not depend on rare conditions outside the attacker\u0027s control.\nPR:L - Bond creation and many control operations require CAP_NET_ADMIN, but that is reachable by an unprivileged user inside a user namespace. RTM_GETLINK-style readers are even less restricted, but exploitation still assumes a local unprivileged user context.\nUI:N - No victim action is required once the attacker can run local commands or netlink requests. The attacker can trigger the relevant reader and writer activity directly.\nS:U - The impact remains within the kernel and the host networking subsystem security authority. This is not a VM escape, IOMMU bypass, or cross-scope boundary violation.\nC:H - The bug is an RCU lifetime violation on port-\u003eaggregator, which points into per-slave ad_slave_info memory that can be cleared, freed, or reused. Treating the stale-pointer/UAF condition conservatively, it can expose kernel memory through groomed object reuse.\nI:H - A stale kernel pointer/UAF in attacker-controllable bonding state is a memory-safety issue that can plausibly be heap-groomed beyond a simple crash. Under the required overestimation rule, this supports high integrity impact.\nA:H - At minimum, racing dereferences of port-\u003eaggregator can lead to invalid pointer dereferences, inconsistent list traversal, oops, or panic. The vulnerability is therefore capable of causing a kernel-level denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:32:17.100Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ba2272be04f0cb1e74e1e355ff32ef95df280731"
},
{
"url": "https://git.kernel.org/stable/c/3b7265b3a82f40d2357c4004b26eb794a095b186"
},
{
"url": "https://git.kernel.org/stable/c/5fb9ea4e8ebf514d92df2b6c9d0db25ba02ac735"
},
{
"url": "https://git.kernel.org/stable/c/c169c5837525ad842df6a542facf52b6f866a519"
},
{
"url": "https://git.kernel.org/stable/c/78f409fd34fe9de2b24ad8e9dca1b4608a48ed3d"
},
{
"url": "https://git.kernel.org/stable/c/c4f050ce06c56cfb5993268af4a5cb66ed1cd04e"
}
],
"title": "bonding: 3ad: implement proper RCU rules for port-\u003eaggregator",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-52975",
"datePublished": "2026-06-24T16:28:52.514Z",
"dateReserved": "2026-06-09T07:44:35.376Z",
"dateUpdated": "2026-08-05T12:32:17.100Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53110 (GCVE-0-2026-53110)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-08-05 12:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/bpf: Zero-extend bpf prog return values and kfunc arguments
s390x ABI requires callers to zero-extend unsigned arguments and
sign-extend signed arguments, and callees to zero-extend unsigned
return values and sign-extend signed return values.
s390 BPF JIT currently implements only sign extension. Fix this
omission and implement zero extension too.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/s390/net/bpf_jit_comp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "edc90a12073b9a530064a99945c183dde120cb99",
"status": "affected",
"version": "528eb2cb87bc1353235a6384696b4849bde8b0ba",
"versionType": "git"
},
{
"lessThan": "44c4f999b03f55debb1a0c5ab5c1796895a1adf8",
"status": "affected",
"version": "528eb2cb87bc1353235a6384696b4849bde8b0ba",
"versionType": "git"
},
{
"lessThan": "366b0e05ee24f5ba62bdc7ec1346038258b9a797",
"status": "affected",
"version": "528eb2cb87bc1353235a6384696b4849bde8b0ba",
"versionType": "git"
},
{
"lessThan": "834918a77be51419383bf1dda9f02b81ecf26b34",
"status": "affected",
"version": "528eb2cb87bc1353235a6384696b4849bde8b0ba",
"versionType": "git"
},
{
"lessThan": "202e42e4aa890172366354b233c42c73107a3f59",
"status": "affected",
"version": "528eb2cb87bc1353235a6384696b4849bde8b0ba",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/s390/net/bpf_jit_comp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/bpf: Zero-extend bpf prog return values and kfunc arguments\n\ns390x ABI requires callers to zero-extend unsigned arguments and\nsign-extend signed arguments, and callees to zero-extend unsigned\nreturn values and sign-extend signed return values.\n\ns390 BPF JIT currently implements only sign extension. Fix this\nomission and implement zero extension too."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached by locally loading or attaching BPF programs through the bpf() syscall and then executing the JITed program or generated trampoline. It is not directly reachable from remote network packets without prior local BPF program installation.\nAC:L - An attacker can craft BPF bytecode/attachments that exercise unsigned kfunc arguments or trampoline return values, and there is no race or external timing condition required. The bug is a deterministic ABI/JIT miscompilation on affected s390 systems.\nPR:L - Loading kfunc/tracing BPF normally requires BPF-related capabilities, but BPF token delegation can evaluate these in a non-init user namespace in delegated/containerized deployments. Following the higher-severity rule, this is scored as low privileges rather than requiring real init-namespace root.\nUI:N - No victim action is needed after the attacker can issue the relevant bpf() syscalls. The attacker loads/attaches and triggers the affected BPF program path directly.\nS:U - The vulnerability affects kernel execution in the same security authority as the vulnerable component. It is a local kernel compromise/DoS style issue, not a VM escape or separate security-scope boundary bypass.\nC:H - The missing zero-extension lets attacker-controlled high bits cross the verifier/native ABI boundary for kfunc calls and trampoline returns. This can plausibly turn verifier-assumed bounded values into unsafe kernel values, matching prior BPF JIT verifier-bypass classes with kernel memory disclosure potential.\nI:H - Incorrect unsigned argument or return extension can corrupt kernel control/data flow through kfuncs or BPF modify-return trampolines. Under the required higher-severity assumption, this is treated as exploitable for kernel memory modification or privilege escalation.\nA:H - At minimum, passing ABI-invalid kfunc arguments or malformed trampoline return values can trigger kernel oops/panic paths, as similar BPF JIT argument-extension bugs have done. The attacker can repeatedly load/trigger the crafted BPF program."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:33:23.053Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/edc90a12073b9a530064a99945c183dde120cb99"
},
{
"url": "https://git.kernel.org/stable/c/44c4f999b03f55debb1a0c5ab5c1796895a1adf8"
},
{
"url": "https://git.kernel.org/stable/c/366b0e05ee24f5ba62bdc7ec1346038258b9a797"
},
{
"url": "https://git.kernel.org/stable/c/834918a77be51419383bf1dda9f02b81ecf26b34"
},
{
"url": "https://git.kernel.org/stable/c/202e42e4aa890172366354b233c42c73107a3f59"
}
],
"title": "s390/bpf: Zero-extend bpf prog return values and kfunc arguments",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53110",
"datePublished": "2026-06-24T16:30:44.036Z",
"dateReserved": "2026-06-09T07:44:35.385Z",
"dateUpdated": "2026-08-05T12:33:23.053Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68223 (GCVE-0-2026-68223)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: meson: vdec: Fix memory leak in error path of vdec_open
The vdec_open() function previously jumped directly to
err_m2m_release when vdec_init_ctrls() failed, skipping
release of the m2m context. This caused a resource leak.
Fix it by introducing a proper err_m2m_ctx_release label
that calls v4l2_m2m_ctx_release(sess->m2m_ctx) before
releasing the m2m device.
This was identified via kmemleak:
unreferenced object 0xffff0000205d6878 (size 8):
comm "v4l_id", pid 5289, jiffies 4294938580
hex dump (first 8 bytes):
40 d2 49 18 00 00 ff ff @.I.....
backtrace (crc d3204599):
kmemleak_alloc+0xc8/0xf0
__kvmalloc_node_noprof+0x60c/0x850
v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev]
vdec_open+0x1f4/0x788 [meson_vdec]
v4l2_open+0x144/0x460 [videodev]
chrdev_open+0x1ac/0x500
do_dentry_open+0x3f0/0xfe8
vfs_open+0x68/0x320
do_open+0x2d8/0x9a8
path_openat+0x1d0/0x4f0
do_filp_open+0x190/0x380
do_sys_openat2+0xf8/0x1b0
__arm64_sys_openat+0x13c/0x1e8
invoke_syscall+0xdc/0x268
el0_svc_common.constprop.0+0x178/0x258
do_el0_svc+0x4c/0x70
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/meson/vdec/vdec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5f97120d1a50c9efffe54425fac42bb7ef13ac86",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "fb77d6f4580f316c9148b942af0028ee489d121e",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "d9058a19731036c03a779bfe8c3ca0d9aa198599",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "c6cd08a71a630f19b10c318e76e3c56e1dd10e00",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "2cf0171ad594860e31723c671e37824ce12c01ea",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "1391b75bf0119b5d37f1c1c3078d452a01967f9b",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "99f3527bd1a27ff798d59177ed045b0dd87deaef",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "940f161f734b25f175a95d2684c2021f6323693a",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/meson/vdec/vdec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: meson: vdec: Fix memory leak in error path of vdec_open\n\nThe vdec_open() function previously jumped directly to\nerr_m2m_release when vdec_init_ctrls() failed, skipping\nrelease of the m2m context. This caused a resource leak.\n\nFix it by introducing a proper err_m2m_ctx_release label\nthat calls v4l2_m2m_ctx_release(sess-\u003em2m_ctx) before\nreleasing the m2m device.\n\nThis was identified via kmemleak:\nunreferenced object 0xffff0000205d6878 (size 8):\n comm \"v4l_id\", pid 5289, jiffies 4294938580\n hex dump (first 8 bytes):\n 40 d2 49 18 00 00 ff ff @.I.....\n backtrace (crc d3204599):\n kmemleak_alloc+0xc8/0xf0\n __kvmalloc_node_noprof+0x60c/0x850\n v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev]\n vdec_open+0x1f4/0x788 [meson_vdec]\n v4l2_open+0x144/0x460 [videodev]\n chrdev_open+0x1ac/0x500\n do_dentry_open+0x3f0/0xfe8\n vfs_open+0x68/0x320\n do_open+0x2d8/0x9a8\n path_openat+0x1d0/0x4f0\n do_filp_open+0x190/0x380\n do_sys_openat2+0xf8/0x1b0\n __arm64_sys_openat+0x13c/0x1e8\n invoke_syscall+0xdc/0x268\n el0_svc_common.constprop.0+0x178/0x258\n do_el0_svc+0x4c/0x70"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:54.081Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5f97120d1a50c9efffe54425fac42bb7ef13ac86"
},
{
"url": "https://git.kernel.org/stable/c/fb77d6f4580f316c9148b942af0028ee489d121e"
},
{
"url": "https://git.kernel.org/stable/c/d9058a19731036c03a779bfe8c3ca0d9aa198599"
},
{
"url": "https://git.kernel.org/stable/c/c6cd08a71a630f19b10c318e76e3c56e1dd10e00"
},
{
"url": "https://git.kernel.org/stable/c/2cf0171ad594860e31723c671e37824ce12c01ea"
},
{
"url": "https://git.kernel.org/stable/c/1391b75bf0119b5d37f1c1c3078d452a01967f9b"
},
{
"url": "https://git.kernel.org/stable/c/99f3527bd1a27ff798d59177ed045b0dd87deaef"
},
{
"url": "https://git.kernel.org/stable/c/940f161f734b25f175a95d2684c2021f6323693a"
}
],
"title": "media: meson: vdec: Fix memory leak in error path of vdec_open",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68223",
"datePublished": "2026-08-10T12:00:44.123Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:54.081Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68417 (GCVE-0-2026-68417)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: publish QP after initialization
siw_create_qp() currently calls siw_qp_add() before the queues, CQ
pointers, state, completion, and device list entry are ready. A QPN
lookup can therefore reach a QP that is still being constructed.
Move siw_qp_add() to the end of siw_create_qp(), after QP
initialization and before adding the QP to the siw device list.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3c9d128219964dcea897bf6139b88242e987be8f",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "3ff82e3841ecab1ff38d5817c969a019d266c83c",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "36e91a58397ca8c978e38a0bf389f0c6113fa8ca",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "74912ad168f87d6b2b670a87987bb302d6e64aa1",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "fcc9d50022bcdb1f9f7ed04955c72b4a7355af3d",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "52f9fcb191143448df55fd215ff09c5207fed43e",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "bb27fcc67c429d97f785c92c35a6c5adebb05d7f",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: publish QP after initialization\n\nsiw_create_qp() currently calls siw_qp_add() before the queues, CQ\npointers, state, completion, and device list entry are ready. A QPN\nlookup can therefore reach a QP that is still being constructed.\n\nMove siw_qp_add() to the end of siw_create_qp(), after QP\ninitialization and before adding the QP to the siw device list."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to the RDMA character devices (/dev/infiniband/uverbsN for create_qp and /dev/infiniband/rdma_cm for the QPN lookup); no network packet reaches the racing code path without a local trigger first.\nAC:L - The attacker controls both sides of the race: one thread issues create_qp while another issues rdma_connect/rdma_accept with an attacker-supplied qp_num, and QPNs from xa_alloc(XA_FLAGS_ALLOC1) are predictable. The post-publish failure can be made deterministic by passing a short udata-\u003eoutlen, so the window is wide and repeatable at will.\nPR:L - Any unprivileged local user with access to the siw uverbs and rdma_cm character devices can create QPs and issue rdma_connect/rdma_accept with an arbitrary qp_num; no capability check gates siw_create_qp, siw_connect or siw_accept.\nUI:N - The attacker drives both the QP creation and the concurrent QPN lookup from its own threads; no action by any other user or administrator is needed.\nS:U - The corruption is confined to kernel memory managed by the same kernel security authority; there is no crossing of a VM, IOMMU or sandbox boundary.\nC:H - The siw_qp object can be kfree\u0027d by the ib core error path while the CM thread still holds a reference, giving a use-after-free on a slab object the attacker can groom and read back through QP/CM state, enabling disclosure of arbitrary kernel memory.\nI:H - After the free, siw_free_qp() performs list_del(\u0026qp-\u003edevq), vfree() of four pointer fields and siw_put_tx_cpu(qp-\u003etx_cpu) using values read from reallocated attacker-controlled memory, yielding arbitrary-pointer free, list-unlink writes and out-of-range per-CPU decrements suitable for control-flow hijacking.\nA:H - Even without exploitation the race reliably causes kernel crashes: NULL sendq/recvq/scq/rcq dereferences, list_del on an uninitialized devq head, waits on an uninitialized qp_free completion, and use-after-free oopses."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:15.087Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3c9d128219964dcea897bf6139b88242e987be8f"
},
{
"url": "https://git.kernel.org/stable/c/3ff82e3841ecab1ff38d5817c969a019d266c83c"
},
{
"url": "https://git.kernel.org/stable/c/36e91a58397ca8c978e38a0bf389f0c6113fa8ca"
},
{
"url": "https://git.kernel.org/stable/c/74912ad168f87d6b2b670a87987bb302d6e64aa1"
},
{
"url": "https://git.kernel.org/stable/c/fcc9d50022bcdb1f9f7ed04955c72b4a7355af3d"
},
{
"url": "https://git.kernel.org/stable/c/52f9fcb191143448df55fd215ff09c5207fed43e"
},
{
"url": "https://git.kernel.org/stable/c/bb27fcc67c429d97f785c92c35a6c5adebb05d7f"
}
],
"title": "RDMA/siw: publish QP after initialization",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68417",
"datePublished": "2026-08-10T12:04:37.936Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:15.087Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68450 (GCVE-0-2026-68450)
Vulnerability from cvelistv5
Published
2026-08-12 00:51
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: free mapping node on duplicate reloc root insert
__add_reloc_root() allocates a mapping_node before inserting it into
rc->reloc_root_tree. If rb_simple_insert() finds an existing entry, it
returns the existing rb_node and leaves the newly allocated node unlinked.
The error path then returns -EEXIST without freeing the new node. Since
the node was never inserted into reloc_root_tree, the later cleanup in
put_reloc_control() cannot find it either.
Free the newly allocated node before returning -EEXIST.
The callers currently assert that -EEXIST should not happen, so this is a
defensive cleanup for an unexpected duplicate insert path. If the path is
ever reached, the local allocation should still be released.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "29d9746812d8b7c37d594f484e994fd552c3ec33",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "92bedc0455552b42ada1a1f42b0e3a8593cdfccc",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "14a8be9428435ee17f17fae7991215c246b7fd43",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "797dc567146c7e3c4f8d9680e4fbc76e0a6d9151",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "ae0629ff9ccb836416ada129f4edc7efea6eaaad",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "6a8269b6459ed870a8156c106a0f597383907872",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: free mapping node on duplicate reloc root insert\n\n__add_reloc_root() allocates a mapping_node before inserting it into\nrc-\u003ereloc_root_tree. If rb_simple_insert() finds an existing entry, it\nreturns the existing rb_node and leaves the newly allocated node unlinked.\n\nThe error path then returns -EEXIST without freeing the new node. Since\nthe node was never inserted into reloc_root_tree, the later cleanup in\nput_reloc_control() cannot find it either.\n\nFree the newly allocated node before returning -EEXIST.\n\nThe callers currently assert that -EEXIST should not happen, so this is a\ndefensive cleanup for an unexpected duplicate insert path. If the path is\never reached, the local allocation should still be released."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:45.490Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/29d9746812d8b7c37d594f484e994fd552c3ec33"
},
{
"url": "https://git.kernel.org/stable/c/b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8"
},
{
"url": "https://git.kernel.org/stable/c/92bedc0455552b42ada1a1f42b0e3a8593cdfccc"
},
{
"url": "https://git.kernel.org/stable/c/14a8be9428435ee17f17fae7991215c246b7fd43"
},
{
"url": "https://git.kernel.org/stable/c/797dc567146c7e3c4f8d9680e4fbc76e0a6d9151"
},
{
"url": "https://git.kernel.org/stable/c/ae0629ff9ccb836416ada129f4edc7efea6eaaad"
},
{
"url": "https://git.kernel.org/stable/c/6a8269b6459ed870a8156c106a0f597383907872"
}
],
"title": "btrfs: free mapping node on duplicate reloc root insert",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68450",
"datePublished": "2026-08-12T00:51:48.970Z",
"dateReserved": "2026-07-30T09:28:09.395Z",
"dateUpdated": "2026-08-19T16:35:45.490Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68088 (GCVE-0-2026-68088)
Vulnerability from cvelistv5
Published
2026-08-10 11:51
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: function: rndis: add length check to response query
Add variable representations for BufLength and BufOffset in
rndis_query_response(), and perform a length check on them.
This is identical to how rndis_set_response() handles these parameters.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 340600ab4cf0cc41efd01a65af97ebb7d35a7f85 Version: 340600ab4cf0cc41efd01a65af97ebb7d35a7f85 Version: 340600ab4cf0cc41efd01a65af97ebb7d35a7f85 Version: 340600ab4cf0cc41efd01a65af97ebb7d35a7f85 Version: 340600ab4cf0cc41efd01a65af97ebb7d35a7f85 Version: 340600ab4cf0cc41efd01a65af97ebb7d35a7f85 Version: 340600ab4cf0cc41efd01a65af97ebb7d35a7f85 Version: 340600ab4cf0cc41efd01a65af97ebb7d35a7f85 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/rndis.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "efcf4e4eeea0d69d8da72a7bc5cbd49b6192260e",
"status": "affected",
"version": "340600ab4cf0cc41efd01a65af97ebb7d35a7f85",
"versionType": "git"
},
{
"lessThan": "bb2b4402b4571b0c989b977779f7be01107ca425",
"status": "affected",
"version": "340600ab4cf0cc41efd01a65af97ebb7d35a7f85",
"versionType": "git"
},
{
"lessThan": "585921866d2d7d65d4b0d89927c78f784668cf5f",
"status": "affected",
"version": "340600ab4cf0cc41efd01a65af97ebb7d35a7f85",
"versionType": "git"
},
{
"lessThan": "caea8b120604312bab2bfeb1a972f9cd17019e93",
"status": "affected",
"version": "340600ab4cf0cc41efd01a65af97ebb7d35a7f85",
"versionType": "git"
},
{
"lessThan": "f5870777458d8be65d7cd08bc750a03f17998350",
"status": "affected",
"version": "340600ab4cf0cc41efd01a65af97ebb7d35a7f85",
"versionType": "git"
},
{
"lessThan": "e01e7814b4223560eab0513b7c15b8c82bdc83f3",
"status": "affected",
"version": "340600ab4cf0cc41efd01a65af97ebb7d35a7f85",
"versionType": "git"
},
{
"lessThan": "b09716040f3fa4a252eeda3ceb5295ea0e39c1fb",
"status": "affected",
"version": "340600ab4cf0cc41efd01a65af97ebb7d35a7f85",
"versionType": "git"
},
{
"lessThan": "95f90eea070837f7c72207d5520f805bdefc3bc5",
"status": "affected",
"version": "340600ab4cf0cc41efd01a65af97ebb7d35a7f85",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/rndis.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.13"
},
{
"lessThan": "2.6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: function: rndis: add length check to response query\n\nAdd variable representations for BufLength and BufOffset in\nrndis_query_response(), and perform a length check on them.\n\nThis is identical to how rndis_set_response() handles these parameters."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:35.975Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/efcf4e4eeea0d69d8da72a7bc5cbd49b6192260e"
},
{
"url": "https://git.kernel.org/stable/c/bb2b4402b4571b0c989b977779f7be01107ca425"
},
{
"url": "https://git.kernel.org/stable/c/585921866d2d7d65d4b0d89927c78f784668cf5f"
},
{
"url": "https://git.kernel.org/stable/c/caea8b120604312bab2bfeb1a972f9cd17019e93"
},
{
"url": "https://git.kernel.org/stable/c/f5870777458d8be65d7cd08bc750a03f17998350"
},
{
"url": "https://git.kernel.org/stable/c/e01e7814b4223560eab0513b7c15b8c82bdc83f3"
},
{
"url": "https://git.kernel.org/stable/c/b09716040f3fa4a252eeda3ceb5295ea0e39c1fb"
},
{
"url": "https://git.kernel.org/stable/c/95f90eea070837f7c72207d5520f805bdefc3bc5"
}
],
"title": "usb: gadget: function: rndis: add length check to response query",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68088",
"datePublished": "2026-08-10T11:51:42.647Z",
"dateReserved": "2026-07-30T09:28:09.367Z",
"dateUpdated": "2026-08-17T04:58:35.975Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80534 (GCVE-0-2026-80534)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfs: fix ilock leak on error in xfs_dq_get_next_id
xfs_dq_get_next_id() takes the quota inode ILOCK before calling
xfs_iread_extents(). If xfs_iread_extents() fails, the function returns
immediately without releasing the lock, leaking the quota inode ILOCK.
This can leave the quota inode locked and cause subsequent quota
operations to hang.
Fix this by jumping to a common unlock path on error instead of returning
directly.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_dquot.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e4c05ebd01e910bccd4f7e9517c7353982e27763",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "6401b99a285cd4cfb2949ba44675541b91ad7e4f",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "0865e4fca02e418fd2423fae9a887dee87b778a1",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "ed8bfb43de71213cfdbbe833b2c2817250e18b1a",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "e270d539b8a2e0cb8f617fee47a7b083c0088361",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "514a5d42d4188fc5f1499a8d654c717ebf981193",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "08bed2b67d2ee79d3e138c344d8dcfa4c9b26a38",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "63320a0f70f66f311f4bccff3af0719c2119f46c",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_dquot.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix ilock leak on error in xfs_dq_get_next_id\n\nxfs_dq_get_next_id() takes the quota inode ILOCK before calling\nxfs_iread_extents(). If xfs_iread_extents() fails, the function returns\nimmediately without releasing the lock, leaking the quota inode ILOCK.\nThis can leave the quota inode locked and cause subsequent quota\noperations to hang.\n\nFix this by jumping to a common unlock path on error instead of returning\ndirectly."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:03.205Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e4c05ebd01e910bccd4f7e9517c7353982e27763"
},
{
"url": "https://git.kernel.org/stable/c/6401b99a285cd4cfb2949ba44675541b91ad7e4f"
},
{
"url": "https://git.kernel.org/stable/c/0865e4fca02e418fd2423fae9a887dee87b778a1"
},
{
"url": "https://git.kernel.org/stable/c/ed8bfb43de71213cfdbbe833b2c2817250e18b1a"
},
{
"url": "https://git.kernel.org/stable/c/e270d539b8a2e0cb8f617fee47a7b083c0088361"
},
{
"url": "https://git.kernel.org/stable/c/514a5d42d4188fc5f1499a8d654c717ebf981193"
},
{
"url": "https://git.kernel.org/stable/c/08bed2b67d2ee79d3e138c344d8dcfa4c9b26a38"
},
{
"url": "https://git.kernel.org/stable/c/63320a0f70f66f311f4bccff3af0719c2119f46c"
}
],
"title": "xfs: fix ilock leak on error in xfs_dq_get_next_id",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80534",
"datePublished": "2026-08-26T14:37:10.378Z",
"dateReserved": "2026-08-26T14:34:25.764Z",
"dateUpdated": "2026-08-27T12:40:03.205Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53273 (GCVE-0-2026-53273)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-08-05 12:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tee: optee: prevent use-after-free when the client exits before the supplicant
Commit 70b0d6b0a199 ("tee: optee: Fix supplicant wait loop") made the
client wait as killable so it can be interrupted during shutdown or
after a supplicant crash. This changes the original lifetime expectations:
the client task can now terminate while the supplicant is still processing
its request.
If the client exits first it removes the request from its queue and
kfree()s it, while the request ID remains in supp->idr. A subsequent
lookup on the supplicant path then dereferences freed memory, leading to
a use-after-free.
Serialise access to the request with supp->mutex:
* Hold supp->mutex in optee_supp_recv() and optee_supp_send() while
looking up and touching the request.
* Let optee_supp_thrd_req() notice that the client has terminated and
signal optee_supp_send() accordingly.
With these changes the request cannot be freed while the supplicant still
has a reference, eliminating the race.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0180cf0373f84fff61b16f8c062553a13dd7cfca Version: c0a9a948159153be145f9471435695373904ee6d Version: ec18520f5edc20a00c34a8c9fdd6507c355e880f Version: d61cc1a435e6894bfb0dd3370c6f765d2d12825d Version: fd9d2d6124c293e40797a080adf8a9c237efd8b8 Version: 70b0d6b0a199c5a3ee6c72f5e61681ed6f759612 Version: 70b0d6b0a199c5a3ee6c72f5e61681ed6f759612 Version: 70b0d6b0a199c5a3ee6c72f5e61681ed6f759612 Version: 3eb4911364c764572e9db4ab900a57689a54e8ce Version: 21234efe2a8474a6d2d01ea9573319de7858ce44 Version: 5.10.235 ≤ Version: 5.15.179 ≤ Version: 6.1.130 ≤ Version: 6.6.80 ≤ Version: 6.12.17 ≤ Version: 5.4.291 ≤ Version: 6.13.5 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tee/optee/supp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "416259cb5bffecaaae5f76539deb535a8c1b2c34",
"status": "affected",
"version": "0180cf0373f84fff61b16f8c062553a13dd7cfca",
"versionType": "git"
},
{
"lessThan": "724d0caffd4204b46f78efe22f18f8338031c6e1",
"status": "affected",
"version": "c0a9a948159153be145f9471435695373904ee6d",
"versionType": "git"
},
{
"lessThan": "ae847ab29ded2d7cece4d5970f0edefa4137bf2f",
"status": "affected",
"version": "ec18520f5edc20a00c34a8c9fdd6507c355e880f",
"versionType": "git"
},
{
"lessThan": "9a0dc9279d0907b198f205a693aedf696b08145d",
"status": "affected",
"version": "d61cc1a435e6894bfb0dd3370c6f765d2d12825d",
"versionType": "git"
},
{
"lessThan": "d366a01475f927402c96a3fe78bfc06b924fc87d",
"status": "affected",
"version": "fd9d2d6124c293e40797a080adf8a9c237efd8b8",
"versionType": "git"
},
{
"lessThan": "d5b57bb314d79e99bebb58a53588fa11dd4dbf69",
"status": "affected",
"version": "70b0d6b0a199c5a3ee6c72f5e61681ed6f759612",
"versionType": "git"
},
{
"lessThan": "373152c94e57e9592b68c100e224fbd943cfd608",
"status": "affected",
"version": "70b0d6b0a199c5a3ee6c72f5e61681ed6f759612",
"versionType": "git"
},
{
"lessThan": "387a926ee166814611acecb960207fe2f3c4fd3e",
"status": "affected",
"version": "70b0d6b0a199c5a3ee6c72f5e61681ed6f759612",
"versionType": "git"
},
{
"status": "affected",
"version": "3eb4911364c764572e9db4ab900a57689a54e8ce",
"versionType": "git"
},
{
"status": "affected",
"version": "21234efe2a8474a6d2d01ea9573319de7858ce44",
"versionType": "git"
},
{
"lessThan": "5.10.259",
"status": "affected",
"version": "5.10.235",
"versionType": "semver"
},
{
"lessThan": "5.15.210",
"status": "affected",
"version": "5.15.179",
"versionType": "semver"
},
{
"lessThan": "6.1.176",
"status": "affected",
"version": "6.1.130",
"versionType": "semver"
},
{
"lessThan": "6.6.143",
"status": "affected",
"version": "6.6.80",
"versionType": "semver"
},
{
"lessThan": "6.12.94",
"status": "affected",
"version": "6.12.17",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.291",
"versionType": "semver"
},
{
"lessThan": "6.14",
"status": "affected",
"version": "6.13.5",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/tee/optee/supp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.14"
},
{
"lessThan": "6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.259",
"versionStartIncluding": "5.10.235",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.15.179",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "6.1.130",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "6.6.80",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "6.12.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.291",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.13.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntee: optee: prevent use-after-free when the client exits before the supplicant\n\nCommit 70b0d6b0a199 (\"tee: optee: Fix supplicant wait loop\") made the\nclient wait as killable so it can be interrupted during shutdown or\nafter a supplicant crash. This changes the original lifetime expectations:\nthe client task can now terminate while the supplicant is still processing\nits request.\n\nIf the client exits first it removes the request from its queue and\nkfree()s it, while the request ID remains in supp-\u003eidr. A subsequent\nlookup on the supplicant path then dereferences freed memory, leading to\na use-after-free.\n\nSerialise access to the request with supp-\u003emutex:\n\n * Hold supp-\u003emutex in optee_supp_recv() and optee_supp_send() while\n looking up and touching the request.\n * Let optee_supp_thrd_req() notice that the client has terminated and\n signal optee_supp_send() accordingly.\n\nWith these changes the request cannot be freed while the supplicant still\nhas a reference, eliminating the race."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached through local TEE character device ioctls where a client request enters OP-TEE and is later completed by tee-supplicant via TEE_IOC_SUPPL_SEND. It is not directly reachable from network packets.\nAC:L - The attacker can create supplicant-backed OP-TEE requests and interrupt or terminate the waiting client while the supplicant is processing them. This race is attacker-triggerable and repeatable rather than dependent on rare external conditions.\nPR:L - A basic local user can reach the non-privileged TEE client ioctl path and rely on the legitimate system tee-supplicant to complete the request. The privileged supplicant device exists, but attacker control of it is not required to trigger the UAF.\nUI:N - No victim user action is needed after the attacker runs the local client and triggers the ioctl/race sequence. The supplicant daemon processes queued requests automatically.\nS:U - The memory corruption occurs in the normal-world kernel OP-TEE driver and affects the same kernel security authority. This is a standard local kernel compromise path, not a VM escape or separate security-scope bypass.\nC:H - The stale IDR entry points to a freed optee_supp_req that is later dereferenced by optee_supp_send. As a use-after-free in kernel heap memory, it can plausibly be shaped into disclosure of arbitrary kernel memory.\nI:H - The supplicant completion path writes through fields of the freed request, including the request parameter pointer and completion state. This kernel UAF can plausibly be exploited for controlled memory corruption and privilege escalation.\nA:H - Even without full exploitation, dereferencing and updating a freed kernel object can readily cause an oops, panic, or hang. The bug is repeatedly triggerable from a local client while supplicant requests are in flight."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:34:49.968Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/416259cb5bffecaaae5f76539deb535a8c1b2c34"
},
{
"url": "https://git.kernel.org/stable/c/724d0caffd4204b46f78efe22f18f8338031c6e1"
},
{
"url": "https://git.kernel.org/stable/c/ae847ab29ded2d7cece4d5970f0edefa4137bf2f"
},
{
"url": "https://git.kernel.org/stable/c/9a0dc9279d0907b198f205a693aedf696b08145d"
},
{
"url": "https://git.kernel.org/stable/c/d366a01475f927402c96a3fe78bfc06b924fc87d"
},
{
"url": "https://git.kernel.org/stable/c/d5b57bb314d79e99bebb58a53588fa11dd4dbf69"
},
{
"url": "https://git.kernel.org/stable/c/373152c94e57e9592b68c100e224fbd943cfd608"
},
{
"url": "https://git.kernel.org/stable/c/387a926ee166814611acecb960207fe2f3c4fd3e"
}
],
"title": "tee: optee: prevent use-after-free when the client exits before the supplicant",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53273",
"datePublished": "2026-06-25T08:39:57.811Z",
"dateReserved": "2026-06-09T07:44:35.395Z",
"dateUpdated": "2026-08-05T12:34:49.968Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-31557 (GCVE-0-2026-31557)
Vulnerability from cvelistv5
Published
2026-04-24 14:35
Modified
2026-08-05 12:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvmet: move async event work off nvmet-wq
For target nvmet_ctrl_free() flushes ctrl->async_event_work.
If nvmet_ctrl_free() runs on nvmet-wq, the flush re-enters workqueue
completion for the same worker:-
A. Async event work queued on nvmet-wq (prior to disconnect):
nvmet_execute_async_event()
queue_work(nvmet_wq, &ctrl->async_event_work)
nvmet_add_async_event()
queue_work(nvmet_wq, &ctrl->async_event_work)
B. Full pre-work chain (RDMA CM path):
nvmet_rdma_cm_handler()
nvmet_rdma_queue_disconnect()
__nvmet_rdma_queue_disconnect()
queue_work(nvmet_wq, &queue->release_work)
process_one_work()
lock((wq_completion)nvmet-wq) <--------- 1st
nvmet_rdma_release_queue_work()
C. Recursive path (same worker):
nvmet_rdma_release_queue_work()
nvmet_rdma_free_queue()
nvmet_sq_destroy()
nvmet_ctrl_put()
nvmet_ctrl_free()
flush_work(&ctrl->async_event_work)
__flush_work()
touch_wq_lockdep_map()
lock((wq_completion)nvmet-wq) <--------- 2nd
Lockdep splat:
============================================
WARNING: possible recursive locking detected
6.19.0-rc3nvme+ #14 Tainted: G N
--------------------------------------------
kworker/u192:42/44933 is trying to acquire lock:
ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90
but task is already holding lock:
ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660
3 locks held by kworker/u192:42/44933:
#0: ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660
#1: ffffc9000e6cbe28 ((work_completion)(&queue->release_work)){+.+.}-{0:0}, at: process_one_work+0x1c5/0x660
#2: ffffffff82d4db60 (rcu_read_lock){....}-{1:3}, at: __flush_work+0x62/0x530
Workqueue: nvmet-wq nvmet_rdma_release_queue_work [nvmet_rdma]
Call Trace:
__flush_work+0x268/0x530
nvmet_ctrl_free+0x140/0x310 [nvmet]
nvmet_cq_put+0x74/0x90 [nvmet]
nvmet_rdma_free_queue+0x23/0xe0 [nvmet_rdma]
nvmet_rdma_release_queue_work+0x19/0x50 [nvmet_rdma]
process_one_work+0x206/0x660
worker_thread+0x184/0x320
kthread+0x10c/0x240
ret_from_fork+0x319/0x390
Move async event work to a dedicated nvmet-aen-wq to avoid reentrant
flush on nvmet-wq.
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8832cf922151e9dfa2821736beb0ae2dd3968b6e Version: 8832cf922151e9dfa2821736beb0ae2dd3968b6e Version: 8832cf922151e9dfa2821736beb0ae2dd3968b6e Version: 8832cf922151e9dfa2821736beb0ae2dd3968b6e Version: d44ff3b100b94e9f23b1e8dbe688eee9bb867ac9 Version: 84026f8c9357c62a9d3e4c554ffd10ccab813654 Version: 5.15.42 ≤ Version: 5.17.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/admin-cmd.c",
"drivers/nvme/target/core.c",
"drivers/nvme/target/nvmet.h",
"drivers/nvme/target/rdma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "49c7c50ee6325a084216e94395e067ecde8088fa",
"status": "affected",
"version": "8832cf922151e9dfa2821736beb0ae2dd3968b6e",
"versionType": "git"
},
{
"lessThan": "ca111c9d8d6c9d5735878d933a1716c4be86c2d1",
"status": "affected",
"version": "8832cf922151e9dfa2821736beb0ae2dd3968b6e",
"versionType": "git"
},
{
"lessThan": "25ceffc1dabec3b93f458b437aae26f4da293f87",
"status": "affected",
"version": "8832cf922151e9dfa2821736beb0ae2dd3968b6e",
"versionType": "git"
},
{
"lessThan": "2922e3507f6d5caa7f1d07f145e186fc6f317a4e",
"status": "affected",
"version": "8832cf922151e9dfa2821736beb0ae2dd3968b6e",
"versionType": "git"
},
{
"status": "affected",
"version": "d44ff3b100b94e9f23b1e8dbe688eee9bb867ac9",
"versionType": "git"
},
{
"status": "affected",
"version": "84026f8c9357c62a9d3e4c554ffd10ccab813654",
"versionType": "git"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.42",
"versionType": "semver"
},
{
"lessThan": "5.18",
"status": "affected",
"version": "5.17.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/admin-cmd.c",
"drivers/nvme/target/core.c",
"drivers/nvme/target/nvmet.h",
"drivers/nvme/target/rdma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.80",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.21",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.80",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.21",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.11",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.42",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.17.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: move async event work off nvmet-wq\n\nFor target nvmet_ctrl_free() flushes ctrl-\u003easync_event_work.\nIf nvmet_ctrl_free() runs on nvmet-wq, the flush re-enters workqueue\ncompletion for the same worker:-\n\nA. Async event work queued on nvmet-wq (prior to disconnect):\n nvmet_execute_async_event()\n queue_work(nvmet_wq, \u0026ctrl-\u003easync_event_work)\n\n nvmet_add_async_event()\n queue_work(nvmet_wq, \u0026ctrl-\u003easync_event_work)\n\nB. Full pre-work chain (RDMA CM path):\n nvmet_rdma_cm_handler()\n nvmet_rdma_queue_disconnect()\n __nvmet_rdma_queue_disconnect()\n queue_work(nvmet_wq, \u0026queue-\u003erelease_work)\n process_one_work()\n lock((wq_completion)nvmet-wq) \u003c--------- 1st\n nvmet_rdma_release_queue_work()\n\nC. Recursive path (same worker):\n nvmet_rdma_release_queue_work()\n nvmet_rdma_free_queue()\n nvmet_sq_destroy()\n nvmet_ctrl_put()\n nvmet_ctrl_free()\n flush_work(\u0026ctrl-\u003easync_event_work)\n __flush_work()\n touch_wq_lockdep_map()\n lock((wq_completion)nvmet-wq) \u003c--------- 2nd\n\nLockdep splat:\n\n ============================================\n WARNING: possible recursive locking detected\n 6.19.0-rc3nvme+ #14 Tainted: G N\n --------------------------------------------\n kworker/u192:42/44933 is trying to acquire lock:\n ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90\n\n but task is already holding lock:\n ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660\n\n 3 locks held by kworker/u192:42/44933:\n #0: ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660\n #1: ffffc9000e6cbe28 ((work_completion)(\u0026queue-\u003erelease_work)){+.+.}-{0:0}, at: process_one_work+0x1c5/0x660\n #2: ffffffff82d4db60 (rcu_read_lock){....}-{1:3}, at: __flush_work+0x62/0x530\n\n Workqueue: nvmet-wq nvmet_rdma_release_queue_work [nvmet_rdma]\n Call Trace:\n __flush_work+0x268/0x530\n nvmet_ctrl_free+0x140/0x310 [nvmet]\n nvmet_cq_put+0x74/0x90 [nvmet]\n nvmet_rdma_free_queue+0x23/0xe0 [nvmet_rdma]\n nvmet_rdma_release_queue_work+0x19/0x50 [nvmet_rdma]\n process_one_work+0x206/0x660\n worker_thread+0x184/0x320\n kthread+0x10c/0x240\n ret_from_fork+0x319/0x390\n\nMove async event work to a dedicated nvmet-aen-wq to avoid reentrant\nflush on nvmet-wq."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable async event and teardown path is reachable through NVMe-oF target networking, including nvmet-tcp, by connecting to the target, issuing an admin Async Event Request, and disconnecting.\nAC:L - The attacker controls both relevant actions: queuing async event work and triggering connection teardown. No uncontrollable memory layout or victim timing condition is required beyond repeating the network sequence.\nPR:N - The NVMe discovery controller is reachable with the standard discovery NQN, allows hosts by design, supports async event requests, and skips DH-HMAC-CHAP authentication. In an exposed nvmet-tcp deployment this is reachable without credentials.\nUI:N - No victim user action is needed after the target service is exposed. The remote peer can trigger the sequence by protocol messages and disconnecting.\nS:U - The impact is confined to the kernel/NVMe target host that processes the malicious connection. It does not cross a VM, IOMMU, or separate security authority boundary.\nC:N - The bug is a workqueue/flush recursion issue and does not expose kernel memory or target data. There is no identified read primitive.\nI:N - The issue does not corrupt memory or provide a write/control-flow primitive. It affects teardown/workqueue progress rather than data integrity.\nA:H - The recursive workqueue flush can trigger a kernel lockdep warning and can lead to a panic or teardown hang in hardened/debug configurations. It can be triggered repeatedly over the network, so availability impact is scored high."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:23:29.694Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/49c7c50ee6325a084216e94395e067ecde8088fa"
},
{
"url": "https://git.kernel.org/stable/c/ca111c9d8d6c9d5735878d933a1716c4be86c2d1"
},
{
"url": "https://git.kernel.org/stable/c/25ceffc1dabec3b93f458b437aae26f4da293f87"
},
{
"url": "https://git.kernel.org/stable/c/2922e3507f6d5caa7f1d07f145e186fc6f317a4e"
}
],
"title": "nvmet: move async event work off nvmet-wq",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-31557",
"datePublished": "2026-04-24T14:35:40.544Z",
"dateReserved": "2026-03-09T15:48:24.116Z",
"dateUpdated": "2026-08-05T12:23:29.694Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68480 (GCVE-0-2026-68480)
Vulnerability from cvelistv5
Published
2026-08-06 17:36
Modified
2026-08-18 06:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
x86/bugs: Make Safe-RET robust against interrupt injection
An attacker injecting interrupts while the Safe-RET mitigation executes
on machines affected by SRSO can neutralize the safe return sequence,
potentially leading to data leakage through speculative execution.
Fixup register state as if the Safe-RET sequence executed successfully
by "emulating" it, in a manner of speaking, and avoid executing a RET
instruction after returning from the interrupt.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3f9b7101bea1dcb63410c016ceb266f6e9f733c9 Version: b35087763a44d1eb45857f799579a351332be505 Version: ac41e90d8daa8815d8bee774a1975435fbfe1ae7 Version: fb3bd914b3ec28f5fb697ac55c4846ac2d542855 Version: fb3bd914b3ec28f5fb697ac55c4846ac2d542855 Version: fb3bd914b3ec28f5fb697ac55c4846ac2d542855 Version: fb3bd914b3ec28f5fb697ac55c4846ac2d542855 Version: fb3bd914b3ec28f5fb697ac55c4846ac2d542855 Version: acdc883eb61efbe01b954e782e1124790bd391a8 Version: 5.10.189 ≤ Version: 5.15.125 ≤ Version: 6.1.44 ≤ Version: 6.4.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/entry/entry_64.S",
"arch/x86/include/asm/nospec-branch.h",
"arch/x86/kernel/cpu/bugs.c",
"arch/x86/lib/retpoline.S"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dfefa3c51370f84acb643cddf98bb42c885d0483",
"status": "affected",
"version": "3f9b7101bea1dcb63410c016ceb266f6e9f733c9",
"versionType": "git"
},
{
"lessThan": "52db77a13be224e09eb4ba6b4252ae8ab9085c2c",
"status": "affected",
"version": "b35087763a44d1eb45857f799579a351332be505",
"versionType": "git"
},
{
"lessThan": "d0208e08d64d99383e09852a76cc3038c5a4c3ab",
"status": "affected",
"version": "ac41e90d8daa8815d8bee774a1975435fbfe1ae7",
"versionType": "git"
},
{
"lessThan": "6703dba1d14cbd6647cd1ccfa3a3fa94b64dd096",
"status": "affected",
"version": "fb3bd914b3ec28f5fb697ac55c4846ac2d542855",
"versionType": "git"
},
{
"lessThan": "e262f28a69ae9e0791248f93b0173c1d1f3e1d5d",
"status": "affected",
"version": "fb3bd914b3ec28f5fb697ac55c4846ac2d542855",
"versionType": "git"
},
{
"lessThan": "bfe7f9993467ba431b2731437949ac1e2634e771",
"status": "affected",
"version": "fb3bd914b3ec28f5fb697ac55c4846ac2d542855",
"versionType": "git"
},
{
"lessThan": "61649a2d61cb0dbc673f0f232f0f0c298bf50442",
"status": "affected",
"version": "fb3bd914b3ec28f5fb697ac55c4846ac2d542855",
"versionType": "git"
},
{
"lessThan": "7e7f81cf6f5ca3311e526308f55d7c54d3ba71f9",
"status": "affected",
"version": "fb3bd914b3ec28f5fb697ac55c4846ac2d542855",
"versionType": "git"
},
{
"status": "affected",
"version": "acdc883eb61efbe01b954e782e1124790bd391a8",
"versionType": "git"
},
{
"lessThan": "5.10.264",
"status": "affected",
"version": "5.10.189",
"versionType": "semver"
},
{
"lessThan": "5.15.215",
"status": "affected",
"version": "5.15.125",
"versionType": "semver"
},
{
"lessThan": "6.1.182",
"status": "affected",
"version": "6.1.44",
"versionType": "semver"
},
{
"lessThan": "6.5",
"status": "affected",
"version": "6.4.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/entry/entry_64.S",
"arch/x86/include/asm/nospec-branch.h",
"arch/x86/kernel/cpu/bugs.c",
"arch/x86/lib/retpoline.S"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.264",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.215",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.182",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.150",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.102",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.43",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.264",
"versionStartIncluding": "5.10.189",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.215",
"versionStartIncluding": "5.15.125",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.182",
"versionStartIncluding": "6.1.44",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.150",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.102",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.43",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.7",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Make Safe-RET robust against interrupt injection\n\nAn attacker injecting interrupts while the Safe-RET mitigation executes\non machines affected by SRSO can neutralize the safe return sequence,\npotentially leading to data leakage through speculative execution.\n\nFixup register state as if the Safe-RET sequence executed successfully\nby \"emulating\" it, in a manner of speaking, and avoid executing a RET\ninstruction after returning from the interrupt."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:56:07.999Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dfefa3c51370f84acb643cddf98bb42c885d0483"
},
{
"url": "https://git.kernel.org/stable/c/52db77a13be224e09eb4ba6b4252ae8ab9085c2c"
},
{
"url": "https://git.kernel.org/stable/c/d0208e08d64d99383e09852a76cc3038c5a4c3ab"
},
{
"url": "https://git.kernel.org/stable/c/6703dba1d14cbd6647cd1ccfa3a3fa94b64dd096"
},
{
"url": "https://git.kernel.org/stable/c/e262f28a69ae9e0791248f93b0173c1d1f3e1d5d"
},
{
"url": "https://git.kernel.org/stable/c/bfe7f9993467ba431b2731437949ac1e2634e771"
},
{
"url": "https://git.kernel.org/stable/c/61649a2d61cb0dbc673f0f232f0f0c298bf50442"
},
{
"url": "https://git.kernel.org/stable/c/7e7f81cf6f5ca3311e526308f55d7c54d3ba71f9"
},
{
"url": "https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf"
}
],
"title": "x86/bugs: Make Safe-RET robust against interrupt injection",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68480",
"datePublished": "2026-08-06T17:36:43.654Z",
"dateReserved": "2026-07-30T09:28:09.397Z",
"dateUpdated": "2026-08-18T06:56:07.999Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68257 (GCVE-0-2026-68257)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
total_cwsr_size was computed in 32-bit before being used as a BO/SVM
allocation size.
With large ctx_save_restore_area_size and debug_memory_size
multiplied by the XCC count, the product can wrap,
yielding an undersized CWSR save area that firmware later overruns.
Promote total_cwsr_size to u64 and use check_add_overflow()/
check_mul_overflow() in both kfd_queue_acquire_buffers() and
kfd_queue_release_buffers().
(cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 325aa07165394b8e866ffe9ec1d4c99d9195b2f2 Version: d15deafab5d722afb9e2f83c5edcdef9d9d98bd1 Version: d15deafab5d722afb9e2f83c5edcdef9d9d98bd1 Version: d15deafab5d722afb9e2f83c5edcdef9d9d98bd1 Version: 63600103d2ac5c09fdeec5b931b396e4e0efd5d8 Version: 6.12.59 ≤ Version: 6.17.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b88ffe6593607364a8c06a48c6f29e55437cdf8e",
"status": "affected",
"version": "325aa07165394b8e866ffe9ec1d4c99d9195b2f2",
"versionType": "git"
},
{
"lessThan": "abce3276c57e36c955627307469b9f009057a467",
"status": "affected",
"version": "d15deafab5d722afb9e2f83c5edcdef9d9d98bd1",
"versionType": "git"
},
{
"lessThan": "865532d54eb57b660b1cb1b0e1755776ce21b849",
"status": "affected",
"version": "d15deafab5d722afb9e2f83c5edcdef9d9d98bd1",
"versionType": "git"
},
{
"lessThan": "2b0386d4293920e690c0e017708f999b93cc729b",
"status": "affected",
"version": "d15deafab5d722afb9e2f83c5edcdef9d9d98bd1",
"versionType": "git"
},
{
"status": "affected",
"version": "63600103d2ac5c09fdeec5b931b396e4e0efd5d8",
"versionType": "git"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.59",
"versionType": "semver"
},
{
"lessThan": "6.18",
"status": "affected",
"version": "6.17.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"lessThan": "6.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.59",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.17.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix 32-bit overflow in CWSR total size calculation\n\ntotal_cwsr_size was computed in 32-bit before being used as a BO/SVM\nallocation size.\nWith large ctx_save_restore_area_size and debug_memory_size\nmultiplied by the XCC count, the product can wrap,\nyielding an undersized CWSR save area that firmware later overruns.\n\nPromote total_cwsr_size to u64 and use check_add_overflow()/\ncheck_mul_overflow() in both kfd_queue_acquire_buffers() and\nkfd_queue_release_buffers().\n\n(cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered through the AMDKFD_IOC_CREATE_QUEUE ioctl on the local /dev/kfd character device; the attacker-controlled ctx_save_restore_size field comes straight from the ioctl argument struct with no remote reachability.\nAC:L - The overflow is pure deterministic arithmetic on a value the attacker fully controls \u2014 passing ctx_save_restore_size near 2^32 (or /NUM_XCC on multi-XCC MI300 parts) reliably wraps total_cwsr_size to 0 or a small value on every attempt, with no race or layout dependency.\nPR:L - Requires only an unprivileged local account with access to /dev/kfd, which is granted to the render group and is routinely available to ordinary users on ROCm hosts, GPU compute nodes, containers, Steam Deck/desktop and Chrome OS style systems; no capabilities are checked on this path.\nUI:N - The attacker creates the malicious compute queue entirely from its own process via a single ioctl; no action by any other user or administrator is needed.\nS:U - The undersized CWSR area and the resulting firmware overrun stay within the kernel/GPU driver security authority of the same machine; there is no hypervisor or IOMMU boundary crossed.\nC:H - With validation bypassed, CP firmware save/restore reads span memory adjacent to the tiny validated buffer and load it into wave state the attacker\u0027s shader can read back, and get_wave_state copies per-XCC control-stack contents out of the unvalidated region, giving a broad out-of-bounds disclosure primitive.\nI:H - The queue is programmed with the full unwrapped save size and per-XCC base offsets, so firmware performs large out-of-bounds writes of wave/control-stack data beyond the buffer that was actually validated and reference-counted, and the bypassed queue_refcount lets those buffers be unmapped or freed while the queue is live \u2014 an attacker-influenced memory-corruption primitive.\nA:H - Overrunning the CWSR save area drives the GPU into unmapped VA on preemption, causing VM faults, queue hangs and driver-initiated GPU resets that take down all GPU workloads on the machine, including other tenants on shared compute nodes."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:54.208Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b88ffe6593607364a8c06a48c6f29e55437cdf8e"
},
{
"url": "https://git.kernel.org/stable/c/abce3276c57e36c955627307469b9f009057a467"
},
{
"url": "https://git.kernel.org/stable/c/865532d54eb57b660b1cb1b0e1755776ce21b849"
},
{
"url": "https://git.kernel.org/stable/c/2b0386d4293920e690c0e017708f999b93cc729b"
}
],
"title": "drm/amdkfd: fix 32-bit overflow in CWSR total size calculation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68257",
"datePublished": "2026-08-10T12:01:30.547Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-18T06:55:54.208Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72341 (GCVE-0-2026-72341)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-17 05:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix publication race for priv->channel_stats[]
mlx5e_channel_stats_alloc() publishes a new entry to
priv->channel_stats[] and then increments priv->stats_nch as a
publication token, but neither store carries any memory barrier:
priv->channel_stats[ix] = kvzalloc_node(...);
if (!priv->channel_stats[ix])
return -ENOMEM;
priv->stats_nch++;
Concurrent readers compute the loop bound from priv->stats_nch and
then dereference priv->channel_stats[i] using plain accesses, e.g.
for (i = 0; i < priv->stats_nch; i++) {
struct mlx5e_channel_stats *cs = priv->channel_stats[i];
... cs->rq.packets ...
}
On weakly-ordered architectures (ARM, PowerPC, RISC-V) the writes to
channel_stats[ix] and stats_nch may become visible to other CPUs out
of program order. A reader can observe stats_nch == N while still
seeing channel_stats[N-1] == NULL, leading to a NULL pointer
dereference in the channel_stats loop.
This has been observed in production on BlueField-3 DPUs (arm64),
where ovs-vswitchd queries netdev statistics over netlink during NIC
bringup, racing mlx5e_open_channel() -> mlx5e_channel_stats_alloc()
on another CPU:
Unable to handle kernel NULL pointer dereference at virtual address 0x840
Hardware name: BlueField-3 DPU
pc : mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]
Call trace:
mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]
dev_get_stats+0x50/0xc0
ovs_vport_get_stats+0x38/0xac [openvswitch]
ovs_vport_cmd_fill_info+0x194/0x290 [openvswitch]
ovs_vport_cmd_get+0xbc/0x10c [openvswitch]
genl_family_rcv_msg_doit+0xd0/0x160
genl_rcv_msg+0xec/0x1f0
netlink_rcv_skb+0x64/0x130
genl_rcv+0x40/0x60
netlink_unicast+0x2fc/0x370
netlink_sendmsg+0x1dc/0x454
...
__arm64_sys_sendmsg+0x2c/0x40
Add mlx5e_stats_nch_write() and mlx5e_stats_nch_read() helpers in en.h
that wrap the smp_store_release()/smp_load_acquire() pair on stats_nch.
The release/acquire pair establishes the contract:
stats_nch == N => channel_stats[0..N-1] are visible and non-NULL.
Publish the stats_nch increment via mlx5e_stats_nch_write() in the
writer (mlx5e_channel_stats_alloc()), and read stats_nch via
mlx5e_stats_nch_read() in all readers: mlx5e RX/TX queue stats,
mlx5e_get_base_stats(), ethtool channels stats, IPoIB stats, the
sw_stats fold and the HV VHCA stats agent.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en.h",
"drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/en_main.c",
"drivers/net/ethernet/mellanox/mlx5/core/en_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/ipoib/ipoib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5c7e3755abf663f033de24f917b77685e9543045",
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"versionType": "git"
},
{
"lessThan": "815515ec68f527ca755cb1e2c1ff9148f6b3ea56",
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"versionType": "git"
},
{
"lessThan": "5a799714e8ca0bce9ea40694f49914cf1adbbaa9",
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en.h",
"drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/en_main.c",
"drivers/net/ethernet/mellanox/mlx5/core/en_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/ipoib/ipoib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix publication race for priv-\u003echannel_stats[]\n\nmlx5e_channel_stats_alloc() publishes a new entry to\npriv-\u003echannel_stats[] and then increments priv-\u003estats_nch as a\npublication token, but neither store carries any memory barrier:\n\n\tpriv-\u003echannel_stats[ix] = kvzalloc_node(...);\n\tif (!priv-\u003echannel_stats[ix])\n\t\treturn -ENOMEM;\n\tpriv-\u003estats_nch++;\n\nConcurrent readers compute the loop bound from priv-\u003estats_nch and\nthen dereference priv-\u003echannel_stats[i] using plain accesses, e.g.\n\n\tfor (i = 0; i \u003c priv-\u003estats_nch; i++) {\n\t\tstruct mlx5e_channel_stats *cs = priv-\u003echannel_stats[i];\n\t\t... cs-\u003erq.packets ...\n\t}\n\nOn weakly-ordered architectures (ARM, PowerPC, RISC-V) the writes to\nchannel_stats[ix] and stats_nch may become visible to other CPUs out\nof program order. A reader can observe stats_nch == N while still\nseeing channel_stats[N-1] == NULL, leading to a NULL pointer\ndereference in the channel_stats loop.\n\nThis has been observed in production on BlueField-3 DPUs (arm64),\nwhere ovs-vswitchd queries netdev statistics over netlink during NIC\nbringup, racing mlx5e_open_channel() -\u003e mlx5e_channel_stats_alloc()\non another CPU:\n\n Unable to handle kernel NULL pointer dereference at virtual address 0x840\n Hardware name: BlueField-3 DPU\n pc : mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]\n Call trace:\n mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]\n dev_get_stats+0x50/0xc0\n ovs_vport_get_stats+0x38/0xac [openvswitch]\n ovs_vport_cmd_fill_info+0x194/0x290 [openvswitch]\n ovs_vport_cmd_get+0xbc/0x10c [openvswitch]\n genl_family_rcv_msg_doit+0xd0/0x160\n genl_rcv_msg+0xec/0x1f0\n netlink_rcv_skb+0x64/0x130\n genl_rcv+0x40/0x60\n netlink_unicast+0x2fc/0x370\n netlink_sendmsg+0x1dc/0x454\n ...\n __arm64_sys_sendmsg+0x2c/0x40\n\nAdd mlx5e_stats_nch_write() and mlx5e_stats_nch_read() helpers in en.h\nthat wrap the smp_store_release()/smp_load_acquire() pair on stats_nch.\nThe release/acquire pair establishes the contract:\n\n stats_nch == N =\u003e channel_stats[0..N-1] are visible and non-NULL.\n\nPublish the stats_nch increment via mlx5e_stats_nch_write() in the\nwriter (mlx5e_channel_stats_alloc()), and read stats_nch via\nmlx5e_stats_nch_read() in all readers: mlx5e RX/TX queue stats,\nmlx5e_get_base_stats(), ethtool channels stats, IPoIB stats, the\nsw_stats fold and the HV VHCA stats agent."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:12:50.055Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5c7e3755abf663f033de24f917b77685e9543045"
},
{
"url": "https://git.kernel.org/stable/c/815515ec68f527ca755cb1e2c1ff9148f6b3ea56"
},
{
"url": "https://git.kernel.org/stable/c/5a799714e8ca0bce9ea40694f49914cf1adbbaa9"
}
],
"title": "net/mlx5e: Fix publication race for priv-\u003echannel_stats[]",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72341",
"datePublished": "2026-08-15T05:55:47.764Z",
"dateReserved": "2026-08-09T03:40:39.920Z",
"dateUpdated": "2026-08-17T05:12:50.055Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64585 (GCVE-0-2026-64585)
Vulnerability from cvelistv5
Published
2026-08-06 07:06
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: esd_usb: kill anchored URBs before freeing netdevs
esd_usb_disconnect() frees each CAN netdev with free_candev() inside
its per-netdev loop and only calls unlink_all_urbs(dev) afterwards.
The per-netdev private data (struct esd_usb_net_priv) is embedded in
the net_device allocation returned by alloc_candev(), so once
free_candev() has run, dev->nets[i] points to freed memory.
unlink_all_urbs() then dereferences the freed dev->nets[i] to kill the
per-netdev TX anchor (usb_kill_anchored_urbs(&priv->tx_submitted)),
clear active_tx_jobs, and reset priv->tx_contexts[].
Reorder the teardown so the anchored URBs are killed before the netdevs
are freed, matching other CAN/USB drivers in the same directory such as
ems_usb, usb_8dev and mcba_usb, which unregister, then unlink, then
free: unregister the netdevs first (which stops their TX queues), call
unlink_all_urbs(dev) once, then free the netdevs.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 96d8e90382dc336b5de401164597edfdc2e8d9f1 Version: 96d8e90382dc336b5de401164597edfdc2e8d9f1 Version: 96d8e90382dc336b5de401164597edfdc2e8d9f1 Version: 96d8e90382dc336b5de401164597edfdc2e8d9f1 Version: 96d8e90382dc336b5de401164597edfdc2e8d9f1 Version: 96d8e90382dc336b5de401164597edfdc2e8d9f1 Version: 96d8e90382dc336b5de401164597edfdc2e8d9f1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/esd_usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d12f6add48f2da15c8c8281961d3faad804c76cf",
"status": "affected",
"version": "96d8e90382dc336b5de401164597edfdc2e8d9f1",
"versionType": "git"
},
{
"lessThan": "aa1d005927db38af783c1a4a8a00a39e0229ab2d",
"status": "affected",
"version": "96d8e90382dc336b5de401164597edfdc2e8d9f1",
"versionType": "git"
},
{
"lessThan": "a02e1d8f191324583599544d54e59e6a2b74bb0e",
"status": "affected",
"version": "96d8e90382dc336b5de401164597edfdc2e8d9f1",
"versionType": "git"
},
{
"lessThan": "a3314f10369df70925140f59bbe069718f65a0b9",
"status": "affected",
"version": "96d8e90382dc336b5de401164597edfdc2e8d9f1",
"versionType": "git"
},
{
"lessThan": "765ba1c91823a296447528791b89a6504947fd5c",
"status": "affected",
"version": "96d8e90382dc336b5de401164597edfdc2e8d9f1",
"versionType": "git"
},
{
"lessThan": "5832c55b3c824ba2fe9c36ac3c411baddcce053e",
"status": "affected",
"version": "96d8e90382dc336b5de401164597edfdc2e8d9f1",
"versionType": "git"
},
{
"lessThan": "c43122fef328a70045fe7621c06de6b2b8e19264",
"status": "affected",
"version": "96d8e90382dc336b5de401164597edfdc2e8d9f1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/esd_usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.36"
},
{
"lessThan": "2.6.36",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.36",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: esd_usb: kill anchored URBs before freeing netdevs\n\nesd_usb_disconnect() frees each CAN netdev with free_candev() inside\nits per-netdev loop and only calls unlink_all_urbs(dev) afterwards.\nThe per-netdev private data (struct esd_usb_net_priv) is embedded in\nthe net_device allocation returned by alloc_candev(), so once\nfree_candev() has run, dev-\u003enets[i] points to freed memory.\nunlink_all_urbs() then dereferences the freed dev-\u003enets[i] to kill the\nper-netdev TX anchor (usb_kill_anchored_urbs(\u0026priv-\u003etx_submitted)),\nclear active_tx_jobs, and reset priv-\u003etx_contexts[].\n\nReorder the teardown so the anchored URBs are killed before the netdevs\nare freed, matching other CAN/USB drivers in the same directory such as\nems_usb, usb_8dev and mcba_usb, which unregister, then unlink, then\nfree: unregister the netdevs first (which stops their TX queues), call\nunlink_all_urbs(dev) once, then free the netdevs.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is reached by forcing esd_usb_disconnect() via local usbfs USBDEVFS_DISCONNECT, sysfs unbind, or USB emulation, not by network/CAN traffic; this matches AV:L scoring of analogous USB disconnect UAFs (e.g. CVE-2025-40283).\nAC:L - Once disconnect runs, free_candev() then unlink_all_urbs() deterministically uses freed esd_usb_net_priv in the same teardown path; the attacker fully controls when unbind occurs, with no attacker-uncontrollable race required.\nPR:L - A basic local account with write access to the USB device node (plugdev/uaccess or USB passthrough) can issue USBDEVFS_DISCONNECT; that path has no CAP_SYS_ADMIN check, so init-namespace root is not required.\nUI:N - The attacker issues disconnect/unbind against an already-bound esd CAN-USB interface (or their own matching VID/PID device) without any separate victim action.\nS:U - The freed netdev-private object and subsequent URB teardown run entirely within the host kernel security authority; this is not a VM, IOMMU, or sandbox boundary escape.\nC:H - Use-after-free of struct esd_usb_net_priv (embedded in the freed candev) lets a reclaimed object supply attacker-controlled pointer-rich state read through usb_kill_anchored_urbs() and related teardown, enabling kernel disclosure.\nI:H - unlink_all_urbs() writes through the freed priv (usb_kill_anchored_urbs on tx_submitted, atomic_set of active_tx_jobs, and tx_contexts[] resets), giving a heap UAF write primitive suitable for control-flow hijack.\nA:H - Dereferencing the freed per-netdev private data during disconnect reliably causes kernel oops/panic, and the attacker can repeat unbind/rebind to re-trigger the crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:43.597Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d12f6add48f2da15c8c8281961d3faad804c76cf"
},
{
"url": "https://git.kernel.org/stable/c/aa1d005927db38af783c1a4a8a00a39e0229ab2d"
},
{
"url": "https://git.kernel.org/stable/c/a02e1d8f191324583599544d54e59e6a2b74bb0e"
},
{
"url": "https://git.kernel.org/stable/c/a3314f10369df70925140f59bbe069718f65a0b9"
},
{
"url": "https://git.kernel.org/stable/c/765ba1c91823a296447528791b89a6504947fd5c"
},
{
"url": "https://git.kernel.org/stable/c/5832c55b3c824ba2fe9c36ac3c411baddcce053e"
},
{
"url": "https://git.kernel.org/stable/c/c43122fef328a70045fe7621c06de6b2b8e19264"
}
],
"title": "can: esd_usb: kill anchored URBs before freeing netdevs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64585",
"datePublished": "2026-08-06T07:06:26.556Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-23T12:45:43.597Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…