These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in the Linux kernel's drm/amd/display component can lead to a dangling pointer in the CRTC reset function. This occurs when the function frees the old state before allocating a new one, leaving a pointer to already freed memory if the new allocation fails. The issue has been resolved by allocating the new state first. The vulnerability was found by Linux Verification Center (linuxtesting.o [truncated]
The Linux kernel has a vulnerability that has been resolved by replacing the ly instruction with llgf in s390/bpf. This change addresses an issue where the cpu_nr value, a 32-bit value, was loaded into BPF_REG_0, a 64-bit register, without zeroing the upper bits. This vulnerability has been assigned a CVSS score of 7.8 and a severity of HIGH. The vulnerability affects Linux kernel systems, particularly th [truncated]
A vulnerability in the Linux kernel's iSCSI implementation allows for out-of-bounds reads when processing login PDUs. This occurs because the isert_rx_login_req function does not validate the declared length of the login PDU against the actual received data length. An initiator can exploit this by declaring a longer length than it sends, causing the kernel to read beyond the buffer's end. This can lead to [truncated]
The Linux kernel has a vulnerability (CVE-2026-90289) that has been resolved by resizing MST HDCP per-connector arrays to 32. This change addresses an off-by-one issue with DRM core, which supports a maximum of 32 connectors. The vulnerability was fixed by renaming AMDGPU_DM_MAX_DISPLAY_INDEX to AMDGPU_DM_MAX_DISPLAY_COUNT and increasing its size to 32 to match the originally intended size. Defenders shou [truncated]
A vulnerability in the Linux kernel has been resolved, where the ksmbd module did not properly perform lock checks for single-byte ranges. This could potentially allow an attacker to bypass mandatory byte-range lock checks for one-byte reads, writes, copychunk operations, and one-byte truncate ranges. The vulnerability was addressed by removing a shortcut in the check_lock_range() function that previously [truncated]
The Linux kernel vulnerability, CVE-2026-90118, allows for out-of-bounds writes when reading a corrupted compressed $DATA attribute in the ntfs_decompress() function. This occurs due to an off-by-one page overflow, which can lead to potential data corruption or unauthorized access. Linux kernel developers, maintainers, and users of Linux systems with NTFS support should review and apply the kernel patch t [truncated]
The Linux kernel vulnerability (CVE-2026-89570) was caused by registering the MCE notifier per memory device instead of per region. This led to lifetime issues, NULL dereferences, and use-after-free in the MCE handler. The fix involves moving the notifier into 'struct cxl_region' and registering it from cxl_region_probe(). Affected Linux kernel deployments should be verified for exposure, and patches or u [truncated]
A race condition vulnerability in the Linux kernel's sunrpc module allows a local attacker to potentially lock an uninitialized mutex, leading to a denial-of-service or other unspecified impacts. The vulnerability is caused by the create_use_gss_proxy_proc_entry function publishing a proc entry before initializing the gssp_lock mutex. To address this issue, defenders should assess exposure and prioritize [truncated]
A vulnerability in the Linux kernel's svcrdma has been resolved. The issue arises from the order of operations in svc_rdma_free(), where rpcrdma_rn_unregister() is called after rdma_destroy_id(). This can lead to a use-after-free vulnerability if a concurrent ib_unregister_device walk dispatches svc_rdma_xprt_done() against the now-freed sc_cm_id. The vulnerability was addressed by reordering rpcrdma_rn_u [truncated]
A vulnerability in the Linux kernel's mt76 driver has been addressed. The mt7925 device may have pending work running and accessing freed data or sending MCU commands while the firmware is unavailable if reset, suspended, or unregistered within a certain window. The fix involves adding cancel_delayed_work_sync(&dev->mlo_pm_work) in relevant teardown and suspend paths.
A use-after-free vulnerability exists in the Linux kernel's media staging IPu7 when an asynchronous notifier is not properly unregistered during probe error handling. This leads to list corruption and potential crashes when the notifier list is traversed. The issue arises from the isys_probe() function, which jumps to the out_cleanup label upon failure in a subsequent probe step such as isys_fw_log_init() [truncated]
A vulnerability in the Linux kernel's ocfs2 cluster implementation has been addressed. The o2hb_region_pin() function was called with the o2hb_live_lock spinlock held, but it invoked configfs_depend_item(), which sleeps and can trigger a BUG under CONFIG_DEBUG_ATOMIC_SLEEP. This issue, along with two others, has been fixed in a patch series. The patch series reworks o2hb_region_pin() to drop o2hb_live_loc [truncated]
A use-after-free vulnerability was found in the Linux kernel's lp8788-charger power supply driver. The issue occurs when the charger_work is queued after flush_work() has returned, leading to a potential crash when the work runs after devres frees pchg. This vulnerability can cause system crashes if exploited. Linux system administrators and developers should assess their exposure and apply the patch to p [truncated]
A use-after-free vulnerability was found in the Linux kernel's power: supply: twl4030_charger driver. The bci struct is devm-allocated and used by two workers, but it was not properly cleaned up during the remove process, leading to a potential use-after-free issue. This can occur when the USB transceiver comes from devm_usb_get_phy_by_node() and devm unregisters its notifier only after remove() returns. [truncated]
A Linux kernel vulnerability has been resolved, involving iommu/sva where a handle's device pointer was not initialized before being made visible. This leaves a window where a racing bind can return a handle whose dev pointer is still NULL. A subsequent iommu_sva_unbind_device() can then dereference it via handle->dev->iommu_group. The issue arises from the initialization of handle->dev after dropping iom [truncated]
A memory leak vulnerability was found in the Linux kernel's platform/x86 component, specifically in the int1092 driver. The issue arises from the `sar_probe()` function not freeing memory allocated for `device_mode_info` in certain error paths. This vulnerability has been resolved by converting to use device-managed allocations. The fix involves changing the allocation method to prevent memory leaks, whic [truncated]
A race condition vulnerability in the Linux kernel's ALSA pcxhr driver has been identified. The pcxhr_probe() function requests a threaded IRQ before initializing the mgr->lock mutex, which is used by the threaded handler. This could potentially lead to a use-after-free or other synchronization issues if an interrupt occurs before the mutex is initialized.
A use-after-free vulnerability was found in the Linux kernel's dm-pcache module. This issue occurs in the kset_replay function when accessing a key's cache segment after it has been freed, potentially leading to invalid memory operations. The vulnerability arises from the function's failure to properly handle stale key generations, allowing for use-after-free and invalid segment operations. This could res [truncated]
A use-after-free vulnerability was found in the Linux kernel's rtl8xxxu driver. The bug occurs when the rx_urb_wq worker is not properly canceled during the stop process, allowing it to run after the device has been disconnected and the private data has been freed. This can lead to a use-after-free error when the worker tries to access the freed private data.
A memory leak vulnerability was found in the Linux kernel's rtlwifi driver, specifically in the rtl92du_init_sw_vars() function. The memory allocated by rtl92du_init_shared_data() was not being freed in case of errors. This issue has been resolved by adding a call to rtl92du_deinit_shared_data() in the error path. The vulnerability was addressed to prevent potential system instability. Linux kernel develo [truncated]
A Linux kernel vulnerability was addressed by moving the 'cad_pid' sysctl entry to a more appropriate table, ensuring only the root user can read or modify it. This change prevents non-root users from unsharing pid/user namespaces and modifying 'cad_pid' from child namespaces. The patch ensures that only GLOBAL_ROOT_UID can read or modify this sysctl, addressing a potential security risk. Linux kernel adm [truncated]
The Linux kernel has removed the crypto_rng interface for the sun8i-ss driver due to its redundancy with hwrng and the actual Linux RNG. This removal is part of a larger effort to phase out the crypto_rng interface for hardware PRNGs, which is unused. The driver had a use-after-free vulnerability and a buffer overread bug, but these issues were not fixed separately as the code was slated for removal.
A vulnerability in the Linux kernel's Bluetooth RFCOMM implementation can cause a general protection fault when a remote device sends a DISC message to a deferred DLC. This occurs because the rfcomm_mutex is not held during the deferred setup accept, allowing an attacker to dereference a NULL session pointer. The issue was resolved by taking the rfcomm_mutex for the deferred setup accept, preventing the N [truncated]
The Linux kernel vulnerability CVE-2026-80753 involves the ovpn module queuing work items on global system workqueues instead of a module-owned workqueue. This could lead to module text being freed while work items are still executing, causing potential use-after-free issues. A patch has been applied to use a module-owned workqueue for ovpn work items. The vulnerability has a high CVSS score of 8.4 and is [truncated]
The Linux kernel vulnerability CVE-2026-80731 allows for an out-of-bounds write due to a race condition in the dev_validate_header function. This function is used to validate the header of a network packet. When the CAP_SYS_RAWIO capability is present, the function performs zero-padding on short link layer headers. However, if the device's hard_header_len is increased after the packet's headroom has been [truncated]
The Linux kernel vulnerability, CVE-2026-80608, involves a use-after-free issue in the accel/amdxdna component. When force_iova mode is enabled, amdxdna_remove() frees xdna->domain. If amdxdna_gem_obj_free() is called after device removal, it may attempt to access xdna->domain, resulting in a use-after-free. This issue can have significant operational impact, particularly for Linux kernel users and admini [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T13:17:58.397Z and has not been modified since then. The vulnerability exists in the Linux kernel Bluetooth hci_conn due to a lack of conn reference hold in abort_conn_sync(). This theoretical UAF vulnerability has been resolved in the Linux kernel. Linux system administrators and users who rely o [truncated]
A use-after-free vulnerability was found in the Linux kernel's KVM subsystem. The issue occurs when the I/O APIC's delayed EOI handling work is not canceled before destroying vCPUs, leading to a use-after-free error when the work is processed after vCPUs are destroyed. This vulnerability can be triggered by a malicious guest, potentially allowing them to execute arbitrary code on the host system. System a [truncated]
The Linux kernel has a vulnerability in the Bluetooth HIDP component. An attacker can send an empty basic-mode SDU to cause the use of an uninitialized byte from the skb tailroom, potentially leading to undefined behavior. This vulnerability, CVE-2026-74508, affects the Linux kernel's Bluetooth HIDP implementation, allowing for potential remote code execution. The issue arises from the HIDP protocol's fai [truncated]
A race condition vulnerability was found in the Linux kernel's net/9p trans_rdma.c file. The rdma->state field is modified without holding req_lock in both recv_done() and p9_cm_event_handler(), while rdma_request() accesses the same field under the req_lock spinlock. This inconsistent locking creates a race condition that can cause lost state transitions, leading to the FLUSHING transition being silently [truncated]