These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A regression in the Linux kernel's netfilter nfnetlink_queue subsystem causes packet drops for nfqueue applications that do not set the F_GSO capability flag. When a GSO (Generic Segmentation Offload) packet with an unconfirmed conntrack entry is received, the check for shared-unconfirmed state incorrectly occurs after skb_gso_segment() clones the packet. This elevated reference count triggers false-posit [truncated]
A logic error in the Linux kernel's ext4 filesystem can expose stale data when splitting unwritten extents. When ext4_split_extent() fails to split an extent at point B due to temporary space constraints, it incorrectly marks the entire extent as written after zeroing, leaving stale data in the range 0 to A. A subsequent successful split at A then preserves this stale data as a written extent. The fix pas [truncated]
A null pointer dereference vulnerability exists in the Linux kernel's Chelsio FCoE driver (csiostor). The flaw occurs in an error exit path where a NULL pointer `rn` is dereferenced via the `CSIO_INC_STATS` macro. The vulnerability was resolved by introducing a separate error return path label after the macro's use, preventing the null dereference. Multiple stable kernel branches received backported fixes.
CVE-2026-45856 is a vulnerability in the Linux kernel's RDMA/uverbs subsystem where `ib_uverbs_post_send()` fails to validate the `wqe_size` parameter from userspace before using it for memory allocation and subsequent structure access. An attacker providing a small `wqe_size` value causes out-of-bounds reads from kernel heap memory when accessing fields like `user_wr->opcode` and `user_wr->num_sge`, pote [truncated]
A logic error in the Inside Secure EIP93 cryptographic driver for the Linux kernel causes system panics on hardware platforms where not all cryptographic algorithms are implemented in silicon. The driver registers only the algorithms indicated by the hardware options register, but during cleanup it unconditionally unregisters all possible algorithms—including those never registered. This mismatch triggers [truncated]
A memory corruption vulnerability in the Linux kernel's AMDGPU DRM driver has been resolved. The issue occurred in `amdgpu_gmc_get_nps_memranges()` where memory allocated via `kvcalloc()` (which may use `vmalloc()` for large allocations) was incorrectly freed using `kfree()` instead of `kvfree()`. This mismatch leads to memory corruption when `vmalloc()` is used internally. The fix replaces `kfree()` with [truncated]
A double-free vulnerability exists in the Linux kernel's RDMA/rxe subsystem. In `rxe_srq_from_init()`, the queue pointer `q` is assigned to `srq->rq.queue` before `copy_to_user()` is invoked. If `copy_to_user()` fails, `rxe_queue_cleanup()` frees the queue, but the stale pointer remains in `srq->rq.queue`. When the caller `rxe_create_srq()` subsequently invokes `rxe_srq_cleanup()` upon error, a second `rx [truncated]
A vulnerability in the Linux kernel's EFI subsystem could cause kernel panics on Intel TDX virtual machines with large memory configurations. The `reserve_unaccepted()` function miscalculates the memblock reservation size for the unaccepted memory table when the table's starting physical address is not page-aligned. This leaves the end of the table unreserved, potentially causing it to be overwritten and [truncated]
A vulnerability in the Linux kernel's IP Virtual Server (IPVS) subsystem causes protocol checksum validation to fail for IPv6 packets when extension headers are present before the protocol header. The issue stems from incorrect offset calculation during checksum verification. The fix utilizes the existing iph->len field, which already contains the correct offset, to properly skip IPv6 extension headers. T [truncated]
A missing lock protection vulnerability in the Linux kernel's MSCC Ocelot network driver could lead to race conditions during frame injection operations. The `ocelot_port_xmit_inj()` function calls `ocelot_can_inject()` and `ocelot_port_inject_frame()` without holding the required injection group lock, violating lockdep assertions present in both called functions. The correct caller `felix_port_deferred_x [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's AppArmor security module, specifically within the `aa_sock_file_perm` function. The flaw occurs during socket setup or teardown when either `sock` or `sock->sk` can be NULL, potentially leading to a kernel oops (crash). This affects af_unix sockets and potentially other socket types. The vulnerability represents a fallback path for olde [truncated]
A vulnerability in the Linux kernel's networking stack has been resolved. The issue involved a WARN_ON_ONCE assertion that could be triggered when accessing the forward path array. Recent support for IPIP tunnels increased the likelihood of reaching this warning if userspace constructed a sufficiently long forward path. The fix removes this WARN_ON_ONCE to prevent unnecessary kernel warnings under legitim [truncated]
A memory leak vulnerability exists in the Linux kernel's NTFS3 filesystem driver. In the ntfs_fill_super() function, the fc->fs_private pointer is set to NULL without first freeing the allocated ntfs_mount_options structure. This causes ntfs_fs_free() to skip the cleanup, resulting in a kmemleak-detectable memory leak when mounting NTFS filesystems. The issue was resolved by removing the unnecessary NULL [truncated]
A vulnerability in the Linux kernel's NTFS3 filesystem driver allows uninitialized memory to be used during compressed write operations. When new folios (memory pages) are allocated without being marked as up-to-date, and the ni_read_frame() function is skipped because the caller expects the frame to be completely overwritten, reserved folios may remain only partially filled. This leaves portions of memor [truncated]
A lock inversion deadlock vulnerability in the Linux kernel's NTFS3 filesystem driver has been resolved. The issue occurred in the compressed folio read path where the inode mutex (ni_lock) and page locks could be acquired in inconsistent order, leading to task hangs. The vulnerability was reported by Syzbot and affects the ni_read_folio_cmpr function (previously ni_readpage_cmpr). The fix restructures lo [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's AMD XDNA AI accelerator driver (accel/amdxdna). During context creation in aie2_create_context(), if mailbox channel creation fails, the context's mailbox channel pointer remains NULL. The error handling path then calls aie_destroy_context(), which assumes this pointer is non-NULL, leading to a NULL pointer dereference. The fix replaces [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's drm/panthor driver during GPU unplug operations. The issue occurs in `panthor_fw_unplug()` when the driver attempts to halt and wait for the Microcontroller Unit (MCU) to stop, but the firmware may not be loaded or initialized. This leads to a NULL pointer dereference because the code assumes valid firmware state that doesn't exist. The [truncated]
A stack-out-of-bounds memory access vulnerability exists in the Linux kernel's Integrity Measurement Architecture (IMA) subsystem. The flaw occurs in `ima_appraise_measurement()` when `is_bprm_creds_for_exec()` incorrectly uses `container_of()` on a `*file` pointer, causing an invalid offset calculation that reads beyond allocated stack memory. KASAN detected this as a 1-byte read at an out-of-bounds stac [truncated]
A vulnerability in the Linux kernel's DisplayPort Multi-Stream Transport (MST) driver could cause undefined behavior when releasing display timeslots. The issue occurs when a DP 2.1 monitor disconnects, causing the Virtual Channel Payload Identifier (VCPI) to become zero. The code then attempts to calculate a payload mask using a negative bit shift (`~BIT(vcpi - 1)`), triggering a UBSAN shift-out-of-bound [truncated]
A logic flaw in the Linux kernel's Smack security module allows non-privileged users to disable networking for non-ambient Smack labels by writing a previously-used DOI value to /smack/doi. The root cause is that Smack retains decommissioned DOI definitions, causing subsequent re-add attempts to fail with -EEXIST (-17). This prevents the default domain map from being re-established, breaking CIPSO-labeled [truncated]
A race condition in the Linux kernel's AMD XDNA accelerator driver (accel/amdxdna) could allow commands to be submitted while the device is in an improper power state. The vulnerability exists in the driver's runtime power management (RPM) logic where the `rpm_on` flag was used to indicate suspend/resume progress. When autosuspend triggers, this flag is set; however, if a userspace application submits a c [truncated]
A null-pointer dereference vulnerability exists in the Linux kernel's Bluetooth L2CAP subsystem. The flaw occurs in `l2cap_sock_get_sndtimeo_cb()` where a missing NULL guard allows dereferencing a potentially NULL pointer. The fix applies the same NULL check pattern already implemented in related callback functions `l2cap_sock_resume_cb()` and `l2cap_sock_ready_cb()`. This vulnerability could lead to kern [truncated]
A null-pointer dereference vulnerability exists in the Linux kernel's Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) subsystem. The flaw occurs in `l2cap_sock_new_connection_cb()` when a NULL pointer is dereferenced without proper validation. The fix applies a NULL guard pattern already implemented in related callback functions `l2cap_sock_resume_cb()` and `l2cap_sock_ready_cb()`. This vul [truncated]
A null-pointer dereference vulnerability in the Linux kernel's Bluetooth L2CAP subsystem has been resolved. The vulnerability existed in the `l2cap_sock_state_change_cb()` function, which lacked a NULL guard present in related callback functions. The fix adds the same NULL check already implemented in `l2cap_sock_resume_cb()` and `l2cap_sock_ready_cb()` to prevent potential crashes.
A vulnerability in the Linux kernel's network stack allows the SKBFL_SHARED_FRAG marker to be lost during socket buffer coalescing in skb_try_coalesce(). When TCP receive coalescing transfers paged fragments from one skb to another, the shared-frag marker indicating externally-owned or page-cache-backed memory is not propagated. This breaks an invariant relied upon by in-place writers, specifically ESP (E [truncated]
This CVE addresses a vulnerability in the Linux kernel's socket buffer (skbuff) subsystem where the SKBFL_SHARED_FRAG flag was not properly propagated through several fragment-transfer helper functions. When fragment descriptors are moved between skbuffs, this flag indicates that the destination buffer references externally-owned or page-cache-backed pages that require copy-on-write handling. The omission [truncated]
A vulnerability in the Linux kernel's RDS (Reliable Datagram Service) subsystem can lead to improper handling of zerocopy send cleanup, potentially causing issues with pinned user pages and message queuing. This issue arises when a zerocopy send fails after user pages have been pinned but before the message is attached to the sending socket. The purge path may incorrectly infer zerocopy state, leading to [truncated]
CVE-2026-43501 is a Linux kernel IPv6 vulnerability in RPL Source Routing Header processing. When ipv6_rpl_srh_rcv() decompresses, swaps the next segment, recompresses, and pushes the rebuilt headers back, the new header can require more space than the received one. If the remaining headroom is smaller than the push size plus skb->mac_len, the MAC header rebuild path can write past skb->head, leading to k [truncated]
CVE-2026-43499 is a Linux kernel synchronization bug in rtmutex handling. The supplied CVE text says remove_waiter() can be reached not only from slowlock paths, but also during proxy-lock rollback from rt_mutex_start_proxy_lock() when invoked by futex_requeue(). In that rollback case, waiter::task is not current, so using current for dequeue-related operations can leave the waiter task’s pi_blocked_on st [truncated]
This CVE covers a Linux kernel ivpu driver issue where imported GEM buffers could be re-exported. That re-export path can strip buffer flag settings, which may lead to incorrect device access and data corruption. The published fix adds a custom prime_handle_to_fd callback that rejects re-export of imported objects with -EOPNOTSUPP.