PatchSiren

Linux CVE debriefs · Page 100

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45890

A vulnerability in the Linux kernel's Xen network backend (xen-netback) allowed malicious or buggy Xen guests to trigger a kernel warning by setting the multi-queue configuration to zero. The connect() function validated only the upper bound of requested queue counts, permitting a zero-queue configuration to reach vzalloc() with a zero size argument. This triggered WARN_ON_ONCE(!size) in __vmalloc_node_ra [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45889

A vulnerability in the Linux kernel's Multipath TCP (MPTCP) implementation could lead to a divide-by-zero kernel oops under specific race conditions. The issue stems from improper accounting of out-of-order (OoO) packets in the `mptcp_rcvbuf_grow()` function. MPTCP-level OoO packets are normal when multiple subflows are active and do not indicate packet loss or require retransmissions. However, accounting [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45888

A memory leak vulnerability exists in the Linux kernel's RAID1 (md/raid1) implementation. The flaw occurs in raid1_run() when setup_conf() successfully registers a thread via md_register_thread(), but a subsequent call to raid1_set_limits() fails. In this error path, the previously registered thread is not unregistered, resulting in a memory leak of both the md_thread structure and the associated thread r [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45887

A memory leak vulnerability exists in the Linux kernel's AF_UNIX socket implementation. Specifically, in the `unix_stream_connect()` function, when `prepare_peercred()` fails, the newly created socket (`newsk`) is not properly released via `unix_release_sock()`, resulting in a memory leak. The fix reorders operations to call `prepare_peercred()` before `unix_create1()`, ensuring that credential preparatio [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45886

A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem has been resolved. The issue was an incorrect function prototype for `bpf_xdp_store_bytes` that used `ARG_PTR_TO_UNINIT_MEM` for its third argument, which incorrectly included the `MEM_WRITE` flag. This caused the BPF verifier to reject legitimate programs attempting to use `bpf_xdp_store_bytes` with read-only map values, as the [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45885

A use-after-free vulnerability exists in the Linux kernel's CPCAP battery driver (cpcap-battery). The issue stems from incorrect ordering of devm-managed resource allocations: the IRQ is requested via devm_request_irq() before the power_supply handle is registered via devm_power_supply_register(). Because devm-managed resources are deallocated in reverse order of allocation, during driver removal the powe [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45884

A vulnerability in the Linux kernel's AppArmor security module could cause memory pressure and performance degradation under specific conditions. The flaw exists in the per-CPU buffer cache management code where an unsigned integer underflow prevents proper buffer recycling between CPUs. When triggered, this causes buffers to remain stranded on individual CPUs rather than being returned to the global pool [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45883

A resource leak vulnerability in the Linux kernel's SCA3000 industrial I/O (IIO) driver has been resolved. The issue occurred in the `sca3000_probe()` function where `spi->irq` allocated via `request_threaded_irq()` was not released if `iio_device_register()` subsequently failed. The fix adds proper return value checking and error handling to ensure cleanup occurs on registration failure.

HIGH Linux CVE published 2026-05-27

CVE-2026-45882

A use-after-free vulnerability in the Linux kernel's Qualcomm PM8916 Battery Management System (BMS) driver could allow system crashes or memory corruption. The flaw stems from incorrect devm_ resource ordering where the IRQ handler could execute with a freed or uninitialized power_supply handle during driver probe or removal.

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45881

A memory leak vulnerability exists in the Linux kernel's MediaTek SVS (Smart Voltage Scaling) driver. The flaw occurs in the svs_enable_debug_write() function where memory allocated via memdup_user_nul() is not freed if kstrtoint() fails during integer parsing. The fix implements automatic memory cleanup using the __free(kfree) attribute, eliminating manual kfree() calls and preventing resource leaks. Thi [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45880

A resource leak vulnerability in the Linux kernel's PCI Peer-to-Peer DMA (P2PDMA) subsystem can cause system hangs during PCI device removal. When vm_insert_page() fails in p2pmem_alloc_mmap(), the per-CPU reference count for the page map (pgmap) is not decremented, leading to memunmap_pages() hanging indefinitely when the PCI device is later removed. The vulnerability stems from a missing percpu_ref_put( [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45879

A use-after-free vulnerability exists in the Linux kernel's BQ25980 power supply driver. The issue stems from incorrect ordering of devm-managed resource allocations: the IRQ is requested via devm_request_irq() before the power_supply handle is registered via devm_power_supply_register(). Because devm-managed resources are deallocated in reverse order of allocation, during driver removal the power_supply [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45878

A bounds-checking flaw in the Linux kernel's AMD GPU driver (drm/amdkfd) could allow local attackers to trigger memory corruption or undefined behavior. The vulnerability exists in the debug address watch functionality where a user-supplied watch_id value, received as unsigned 32-bit integer, was processed through signed integer operations without proper validation. When a watch_id exceeding INT_MAX (2,14 [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45877

A NULL pointer dereference vulnerability exists in the Linux kernel's Intel ISH (Integrated Sensor Hub) HID driver. During warm reset flows, the `cl->device` pointer may be NULL if a reset occurs while clients are still being enumerated. The `ishtp_bus_remove_all_clients` function accesses `cl->device->reference_count` without validating the pointer, leading to a kernel panic. This was identified during m [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45876

A vulnerability in the Linux kernel's arm64 Guarded Control Stack (GCS) implementation has been resolved. The flaw existed in `arch_set_shadow_stack_status()` where error handling for `alloc_gcs()` was incorrect. The function returns an error-encoded pointer on failure (from `do_mmap()`), not NULL. The original NULL check failed to detect these errors, potentially leading to use of an invalid GCS address. [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45875

A resource leak vulnerability exists in the Linux kernel's MFD Arizona driver. The wm5102_clear_write_sequencer() function may return an error and exit directly, bypassing the cleanup sequence and leaving regulators enabled. This results in a resource leak where regulators remain powered on when they should be released. The fix changes the direct return to jump to the err_reset label, ensuring proper reso [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45874

A NULL pointer dereference vulnerability exists in the Linux kernel's Freescale i.MX8QM HSIO PHY driver. The issue occurs when the 'fsl,refclk-pad-mode' device tree property is absent, causing the refclk_pad pointer to remain NULL. The function imx_hsio_configure_clk_pad() subsequently dereferences this pointer without validation, leading to a potential kernel crash. The vulnerability was resolved by addi [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45873

A logic flaw in the Linux kernel's netfilter nft_set_rbtree implementation allowed partial interval overlaps to go undetected in anonymous sets. The existing overlap detection skipped checks on start elements when intervals were adjacent (an optimization where end elements are omitted). However, this permitted scenarios where two start elements could share the same starting point with different endpoints [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45872

A memory leak vulnerability exists in the Linux kernel's smartpqi SCSI driver. The function pqi_report_phys_luns() fails to release the rpl_list buffer when encountering an unsupported data format or when allocation for rpl_16byte_wwid_list fails. These early return paths bypass cleanup logic, causing memory leaks. The fix consolidates error handling by adding an out_free_rpl_list label and using goto sta [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45871

A resource leak vulnerability exists in the Linux kernel's TPM ST33ZP24 driver. When the `get_burstcount()` function returns `-EBUSY` due to a timeout condition, the `st33zp24_send()` function exits directly without releasing the TPM locality that was previously acquired. This failure to properly clean up resources could lead to resource exhaustion or denial of service conditions affecting TPM operations. [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45869

A race condition in the Linux kernel's WM97xx battery power supply driver could allow a NULL pointer dereference during device probe. The vulnerability exists because `request_irq()` was called before `power_supply_register()`, creating a window where an interrupt could fire and access an uninitialized power supply handle. The fix reorders initialization to register the power supply before requesting the [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45868

A reference-count leak vulnerability exists in the Linux kernel's pinctrl-single driver. The function `pcs_add_gpio_func()` in `drivers/pinctrl/pinctrl-single.c` calls `of_parse_phandle_with_args()`, which returns a `device_node` pointer with an incremented reference count in `gpiospec.np`. The code iterates through all GPIO phandles but fails to release these references, causing a reference-count leak on [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45867

A use-after-free vulnerability exists in the Linux kernel's ACT8945A power supply driver. The issue stems from incorrect ordering of devm-managed resource allocations: the IRQ is requested before the power_supply handle is registered, causing the power_supply to be freed before the IRQ handler is unregistered during driver removal. This creates a race condition where a late interrupt can invoke power_supp [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45866

A use-after-free vulnerability in the Linux kernel's CAIF serial line discipline (ldisc) driver allows local attackers to trigger memory corruption. The race condition occurs between ldisc_close() and packet transmission paths, where the TTY structure may be freed while still being accessed by handle_tx(). The vulnerability was resolved by moving tty_kref_put() from ldisc_close() to ser_release(), ensurin [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45865

A vulnerability in the Linux kernel's MCTP (Management Component Transport Protocol) over I2C driver could expose uninitialized stack memory to userspace. The mctp-i2c driver failed to initialize the read buffer before performing I2C operations, causing reads to return whatever value happened to be in the 'val' variable from the I2C bus driver. For i2c-aspeed and i2c-npcm7xx drivers specifically, this was [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45864

A vulnerability in the Linux kernel's NTFS3 filesystem driver could allow an attacker to trigger an infinite loop, leading to a denial of service (system hang). The issue occurs when processing valid values within a specific range; if the retrieved valid value remains unchanged, the loop never terminates. This was reported by syzbot, which observed a task blocked for over 143 seconds. The fix adds a check [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45863

A memory leak vulnerability exists in the Linux kernel's DesignWare I3C master driver. The dw_i3c_master_i2c_xfers() function allocates memory for an xfer structure using dw_i3c_master_alloc_xfer(), but if pm_runtime_resume_and_get() fails, the function returns without freeing the allocated memory. This results in a memory leak on the error path. The fix adds a dw_i3c_master_free_xfer() call to properly r [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45862

A cache coherency vulnerability in the Linux kernel's Intel VT-d IOMMU driver could allow non-coherent IOMMU hardware to access uninitialized PASID table memory, potentially leading to memory corruption or privilege escalation. The issue stems from a race condition where the PASID directory entry was updated before the CPU cache flush completed, creating a window where hardware could read stale data. Patc [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45861

A use-after-free vulnerability in the Linux kernel's GFS2 (Global File System 2) quota data management code allows memory corruption during filesystem shutdown. The flaw stems from incomplete synchronization between quota data object freeing and LRU list management, introduced in commit a475c5dd16e5. When GFS2 shuts down, quota data objects are freed synchronously but remain on the LRU list; subsequent sh [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45860

A vulnerability in the Linux kernel's netfilter nf_conncount subsystem could cause premature connection limit enforcement under high connection rates. The issue stems from an optimization that limited garbage collection (GC) to once per jiffy. When more than 8 new connections are tracked per jiffy, the cleanup cannot keep pace, potentially causing legitimate connections to be rejected when limits are reac [truncated]