PatchSiren

Linux CVE debriefs · Page 102

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-05-21

CVE-2026-43496

CVE-2026-43496 is a Linux kernel networking bug in sch_red that can trigger a kernel panic when red is used with certain child qdiscs, including ones whose peek callback is qdisc_peek_dequeued(). The supplied record describes a failing parent/child dequeue sequence and includes a KASAN null-pointer dereference trace. The fix changes sch_red to use qdisc_dequeue_peeked() after peeking, instead of directly [truncated]

HIGH Linux CVE published 2026-05-21

CVE-2026-43495

CVE-2026-43495 is a Linux kernel memory-safety issue in the WWAN t7xx path. NVD’s description says the driver trusted modem-supplied length and count fields without checking that the backing buffer was large enough, which could lead to slab-out-of-bounds reads during port enumeration and host runtime-data parsing. The published fix adds size validation before header access and before iterating over port d [truncated]

CRITICAL Linux CVE published 2026-05-19

CVE-2026-43493

CVE-2026-43493 is a Linux kernel issue in the pcrypt crypto path. According to the published CVE description, MAY_BACKLOG requests can return EBUSY, and the fix updates pcrypt to handle that case and filter out EINPROGRESS notifications. This reads as a request-handling correctness problem in the kernel crypto subsystem rather than a user-facing application bug.

MEDIUM Linux CVE published 2026-05-19

CVE-2026-43492

CVE-2026-43492 is a Linux kernel denial-of-service issue in the lib/crypto MPI code path. An integer underflow in mpi_read_raw_from_sgl() can occur when the function subtracts a count of leading zero bytes from an unsigned length value. Under the conditions described in the CVE record, the kernel can spin indefinitely and trigger soft lockup splats. The issue is fixed in kernel updates referenced by the o [truncated]

MEDIUM Linux CVE published 2026-05-19

CVE-2026-43491

CVE-2026-43491 is a Linux kernel qrtr namespace issue where unbounded NEW_SERVER handling could let a malicious client consume memory by repeatedly adding servers for a node. The kernel fix adds a 256-per-node registration limit, preserves replacement of existing ports, and rate-limits related error messages.

HIGH Linux CVE published 2026-05-15

CVE-2026-43490

CVE-2026-43490 affects Linux kernel ksmbd inheritance handling for SMB ACLs. The issue was published on 2026-05-15 and later modified on 2026-05-20. A malformed inheritable ACE can advertise more SID subauthorities than are actually present, which can let the kernel read past the ACE during SID comparison and miscompute inherited ACE size during DACL construction. The supplied record rates the issue 8.8 H [truncated]

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43489

CVE-2026-43489 covers a Linux kernel liveupdate flaw in LUO file handling where failed retrieve() attempts were not recorded. That meant userspace could reissue a retrieve operation after an earlier error, and the cleanup path on session close could also behave as if retrieval had never happened. The result is a state-tracking bug in a sensitive kernel code path, with risk of invalid accesses or double-ha [truncated]

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43488

CVE-2026-43488 describes a Linux kernel xHCI error-handling flaw where a Host Controller Error (HCE) may continue generating interrupts instead of stopping cleanly. In the reported UAS storage plug/unplug scenario on Android devices, that can lead to an interrupt storm and severe system-level faults. The fix adds xhci_halt() to the HCE path in xhci_irq(), matching the existing handling used for fatal erro [truncated]

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43487

CVE-2026-43487 is a Linux kernel stability issue in libata-core affecting a specific Seagate BarraCuda drive model. According to the CVE description, the ST1000DM010-2EP102 can experience random system freezes when Link Power Management (LPM) is enabled, and the kernel fix disables LPM for that model. The description also notes the drive is in the same BarraCuda family as ST2000DM008-2FR102, which had the same issue.

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43486

CVE-2026-43486 is a Linux kernel arm64 contpte bug in access-flag handling. The issue can make a sub-PTE appear updated when only a sibling entry changed, which can stop the kernel from applying the needed read/write state to the actual faulting descriptor and lead to repeated faults.

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43485

CVE-2026-43485 covers a Linux kernel change in the nouveau/gsp path that removes WARN_ON checks from ACPI probe code. The supplied description says these warnings were triggering frequently and were judged most likely harmless, so the fix is to drop the warnings rather than treat them as a known security boundary failure. The record currently has no CVSS score, no weakness classification, and no KEV listi [truncated]

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43484

CVE-2026-43484 describes a Linux kernel MMC core race where claim and retune control flags shared a bitfield word. Concurrent writes from asynchronous paths could overwrite unrelated bits, leading to incorrect host state and spurious WARN_ON(!host->claimed) events. The fix separates the flags into bool fields to remove the shared-word read/modify/write coupling.

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43483

CVE-2026-43483 is a Linux kernel KVM issue in the SVM/AVIC path. If AVIC is activated or deactivated at the wrong time, KVM can leave CR8 write interception enabled when it should not be, which is described as a lingering performance problem on its own. The CVE notes that, when combined with an earlier TPR synchronization bug fixed by commit d02e48830e3f, the mismatch between hardware-visible TPR state an [truncated]

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43482

CVE-2026-43482 describes a Linux kernel sched_ext bug where a task can be preempted after scx_claim_exit() sets the exit state but before the helper work is kicked. In that gap, error handling is intentionally disabled, so the task may not be scheduled back to queue the helper work. If that happens, bypass mode never activates, teardown does not proceed, tasks stop being dispatched, and the system can wed [truncated]

HIGH Linux CVE published 2026-05-13

CVE-2026-43481

CVE-2026-43481 describes a Linux kernel net-shapers bug where reply skb handling could lead to a double free. The issue is in two netlink handlers that may free the same skb after genlmsg_reply() has already handed it off for consumption. The published fix returns the genlmsg_reply() error directly and limits nlmsg_free() to failures that occur before the reply is handed off.

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43480

CVE-2026-43480 covers a Linux kernel ASoC bug in the AMD ACP3x RT5682/MAX9836 audio path. The driver failed to check whether clock acquisition succeeded, which could let an error pointer reach later clock-enable logic. The fix switches to managed clock acquisition and adds proper error handling.

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43479

CVE-2026-43479 is a Linux kernel issue in the lan78xx USB network driver where disconnecting a device can trigger a WARN in __netif_napi_del_locked(). The source description says the disconnect path called netif_napi_del() while NAPI was still enabled, even though unregister_netdev() already handles NAPI teardown safely. The fix removes the redundant call to avoid the warning during USB device disconnect.

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43478

CVE-2026-43478 is a Linux kernel vulnerability in the ASoC rt1011 codec control path. According to the supplied record, the issue was resolved by changing rt1011_recv_spk_mode_put() to obtain the DAPM context from the component with snd_soc_component_to_dapm(), because the kcontrol path can yield a NULL pointer. In practical defensive terms, this is a kernel stability bug in audio codec handling that coul [truncated]

MEDIUM Linux CVE published 2026-05-13

CVE-2026-43477

CVE-2026-43477 describes a Linux kernel i915 graphics driver issue where Variable Refresh Rate (VRR) timing registers could be programmed before enabling TRANS_DDI_FUNC_CTL. According to the source description, that ordering can cause a hang and, on affected systems, may surface as an MCE-like failure. The upstream fix reorders the steps so VRR timings are configured only after the DDI function control is enabled.

HIGH Linux CVE published 2026-05-13

CVE-2026-43476

CVE-2026-43476 is a high-severity Linux kernel issue in the IIO chemical SPS30 I2C driver. The supplied record says sps30_i2c_read_meas() used sizeof(num), which resolves to the size of size_t rather than the intended __be32 element size, and the fix changes this to sizeof(*meas). In practice, that is a buffer-size mismatch in kernel-space measurement handling and can lead to incorrect memory access or co [truncated]

HIGH Linux CVE published 2026-05-11

CVE-2026-43500

CVE-2026-43500 is a Linux kernel rxrpc memory-safety bug in packet handling. According to the NVD record and linked kernel fixes, the flaw occurs when DATA or RESPONSE packets carry paged fragments that were not cloned but are still externally shared; the old gate only unshared cloned skbs, which could send shared fragments into in-place decryption. NVD classifies the issue as CWE-787 and rates it HIGH (CVSS 7.8).

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43475

CVE-2026-43475 affects the Linux kernel storvsc path used by Hyper-V guests. On PREEMPT_RT kernels, the issue can trigger a "scheduling while atomic" warning and a lock-up during storage I/O, creating an availability problem rather than a confidentiality or integrity issue. NVD rates the CVE CVSS 5.5/Medium with low-privilege local attack conditions and high availability impact.

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43474

CVE-2026-43474 is a Linux kernel vulnerability in file attribute handling where an uninitialized field was passed into vfs_fileattr_get(). The issue was confirmed by KMSAN as an uninit-value read in fuse_fileattr_get(), and the available fix initializes the relevant flags before the call. NVD rates the issue MEDIUM with a local, low-privilege impact focused on availability.

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43472

CVE-2026-43472 is a Linux kernel bug in unshare(2) namespace setup. When CLONE_NEWNS is used and the current task’s fs_struct was not already shared, the kernel could reuse the existing fs_struct during mount-namespace creation. If a later namespace step failed, the process could be left with pwd and root pointing at detached mounts. The issue is primarily a local availability problem and was rated CVSS 5.5 (MEDIUM).

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43471

CVE-2026-43471 is a Linux kernel availability issue in the UFS core path. NVD describes a possible NULL pointer dereference in ufshcd_add_command_trace() when hwq is NULL, which can crash the kernel. The published fix adds a NULL check before accessing hwq->id.

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43470

CVE-2026-43470 is a Linux kernel NFS flaw that can lead to a kernel oops and denial of service when an NFS create path encounters a directory alias and the error is not handled correctly. The issue was published on 2026-05-08 and updated on 2026-05-21. NVD rates it 5.5 (MEDIUM), and the described impact is availability-only: no confidentiality or integrity impact is identified in the supplied record.

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43468

CVE-2026-43468 is a Linux kernel issue in the mlx5 driver’s eswitch/devlink path where a workqueue handler could deadlock with the devlink lock during eswitch mode changes. The upstream fix removes the problematic workqueue flush, adds a generation counter to ignore stale work, and defers final draining to cleanup. The practical result is a local denial-of-service risk from kernel lockup rather than a con [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43467

CVE-2026-43467 is a Linux kernel availability issue in the mlx5 driver path. According to the CVE description, moving a device into switchdev mode could crash if the hardware does not support IPsec, because the code attempted to clean up IPsec resources anyway. The issue was published on 2026-05-08 and later updated on 2026-05-21, with official kernel patch references listed in NVD.

HIGH Linux CVE published 2026-05-08

CVE-2026-43466

CVE-2026-43466 is a Linux kernel vulnerability in the mlx5e network driver’s TX error recovery path. On affected kernels, recovery reset logic could desynchronize the software DMA FIFO producer and consumer counters, so later TX processing could unmap stale DMA addresses from before recovery. The issue is associated with a kernel warning in iommu_dma_unmap_page() and was assigned CVSS 8.2 (HIGH) with netw [truncated]

CRITICAL Linux CVE published 2026-05-08

CVE-2026-43465

CVE-2026-43465 is a critical Linux kernel issue in the mlx5e RX path. When XDP multi-buffer programs change an XDP buffer’s layout, the driver can fail to count dropped fragments correctly for striding RQ, leading to page fragment reference-counting errors and kernel warnings during RX teardown. The supplied record says the bug affects XDP_TX, XDP_REDIRECT, and XDP_PASS handling and was found by the drive [truncated]