PatchSiren

Linux CVE debriefs · Page 103

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-05-08

CVE-2026-43464

CVE-2026-43464 is a Linux kernel vulnerability in the mlx5e receive path that affects XDP multi-buffer handling on legacy RQ. The bug can cause fragment accounting to go out of sync after XDP actions that change buffer layout, which may lead to a negative page-pool reference count and a kernel warning during page release. The issue is documented by NVD as a high-severity availability problem, and the offi [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43463

CVE-2026-43463 is a Linux kernel vulnerability in the rxrpc/AFS path where a helper could return an error pointer, but callers only checked for NULL. The fix updates the helper to return -ENOMEM on allocation failure and changes AFS callers to use IS_ERR() and PTR_ERR(). NVD rates the issue Medium with high availability impact, consistent with a local kernel fault/denial-of-service scenario rather than a [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43462

CVE-2026-43462 is a Linux kernel vulnerability in the Spacemit network driver path. The published fix addresses error handling in emac_tx_mem_map(), where DMA mappings were not being freed when mapping failed. The issue was corrected by reusing the existing emac_free_tx_buf() cleanup path. NVD rates the issue HIGH with a 7.5 CVSS score, reflecting an availability impact.

HIGH Linux CVE published 2026-05-08

CVE-2026-43461

CVE-2026-43461 affects the Linux kernel’s Amlogic SPI flash controller driver path and was published on 2026-05-08, with the record updated on 2026-05-20. The issue is in DMA buffer setup error handling: a failed first mapping returned through an unnecessary cleanup path, a failed info mapping could double-unmap the data mapping, and one unmap used the wrong buffer length. NVD rates the issue as high seve [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43460

CVE-2026-43460 is a Linux kernel double-free issue in the Rockchip SFC SPI controller driver. The problem comes from calling spi_unregister_controller() in remove() after registration was already handled by devm_spi_register_controller(), which can trigger a second free during device removal. The referenced fix changes probe() to use spi_register_controller() so controller teardown happens in the intended [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43459

CVE-2026-43459 is a Linux kernel use-after-free in the ASoC soc-core path that can occur during sound card unbind when a PCM stream is still open. The issue is reached through delayed work in the PCM close path and is rated HIGH by NVD with local access, low privileges, and user interaction required. The CVE was published on 2026-05-08 and later modified on 2026-05-21.

HIGH Linux CVE published 2026-05-08

CVE-2026-43458

CVE-2026-43458 is a Linux kernel use-after-free in the CAIF serial line discipline. A missing lifetime hold on tty->link can let the TX path reach tty_write_room() after the pointed object is freed, producing a slab-use-after-free in pty_write_room() and corrupting tty->link->port access. The published fix adds reference management in ldisc_open() and ser_release(), including cleanup on the error path.

HIGH Linux CVE published 2026-05-08

CVE-2026-43456

CVE-2026-43456 is a Linux kernel bonding flaw where bond_setup_by_slave() copies a slave device’s header_ops directly onto the bond device. When a non-Ethernet slave such as a GRE tunnel is enslaved, later header processing can invoke tunnel-specific helpers with the bond’s private-data layout instead of the slave’s, causing type confusion and crashes. The supplied report shows a kernel BUG reached throug [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43455

CVE-2026-43455 is a Linux kernel MCTP routing bug where a missing lock around a check-and-set sequence can race and leak a device reference. The issue is published in NVD with CVSS 5.5 (MEDIUM) and affects multiple kernel release lines until the fixed stable versions. NVD published the record on 2026-05-08 and last modified it on 2026-05-20.

HIGH Linux CVE published 2026-05-08

CVE-2026-43454

CVE-2026-43454 is a high-severity Linux kernel issue in netfilter's nf_tables netdev hook handling. According to the published record, duplicate device registration must be avoided when processing NETDEV_REGISTER notifications because the device may already have been added during hook allocation. The CVE was published on 2026-05-08 and later modified on 2026-05-20. NVD rates it as local, low-privilege, no [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43453

CVE-2026-43453 is a Linux kernel memory-safety flaw in netfilter's nft_set_pipapo code. The bug occurs in pipapo_drop(), which passes rulemap[i + 1].n to pipapo_unmap() on every loop iteration, including the last one. On that final iteration, the code reads one element past the end of the stack-allocated rulemap array. The issue was confirmed by KASAN as a stack-out-of-bounds read, and the upstream fix re [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43452

CVE-2026-43452 is a Linux kernel netfilter flaw in x_tables option walkers. The issue is a missing end-of-buffer check when the last byte of an option area is not a single-byte option kind, allowing the walker logic in xt_tcpudp and xt_dccp to dereference one byte past the option region. NVD rates the issue HIGH with network attack vector, no privileges, no user interaction, and availability impact in add [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43450

CVE-2026-43450 is a Linux kernel memory-safety issue in the netfilter nfnetlink_cthelper code path. The bug can trigger an 8-byte out-of-bounds read in nfnl_cthelper_dump_table() when table state changes between netlink dump rounds, and it was observed by KASAN as a slab-out-of-bounds read. The issue is rated HIGH (CVSS 7.1) and requires local access with privileges.

HIGH Linux CVE published 2026-05-08

CVE-2026-43449

CVE-2026-43449 is a Linux kernel NVMe PCI driver vulnerability that can cause a slab-out-of-bounds read in nvme_dbbuf_set. NVD assigns it CVSS 7.1 HIGH and classifies the weakness as CWE-125. The kernel fix notes state that dev->online_queues is a count incremented in nvme_init_queue, so valid indices are 0 through dev->online_queues - 1, and the loop condition was corrected to stay within that range whil [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43448

CVE-2026-43448 is a Linux kernel race condition in the NVMe PCI timeout path. If device state changes while nvme_poll_irqdisable() is toggling IRQs, the code can act on different IRQ numbers for disable and enable, triggering an "Unbalanced enable" warning and potential availability impact. The issue was published by NVD on 2026-05-08 and later updated on 2026-05-21.

HIGH Linux CVE published 2026-05-08

CVE-2026-43447

CVE-2026-43447 is a Linux kernel use-after-free in the iavf driver’s PTP handling. A worker added to periodically cache PHC time was not stopped during reset or VF disable, creating a teardown race. If the worker runs while adapter resources are being freed, it can touch invalid memory and cause a crash. The published fix ensures PTP cleanup happens before adapter teardown so the worker is synchronously c [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43446

CVE-2026-43446 is a Linux kernel issue in accel/amdxdna where runtime suspend can deadlock if a job is still executing and calls pm_runtime_resume_and_get() while the suspend path is draining the workqueue. The fix moves the resume call into job submission so the device is resumed before the job is queued, avoiding the deadlock.

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43445

CVE-2026-43445 is a Linux kernel availability issue in the e1000/e1000e TX DMA error cleanup path. When buffer mapping fails after one or more successful mappings, the driver should unmap the buffers already mapped for that skb. The reported bug changes the cleanup count incorrectly, so exactly one DMA mapping can leak when an error is reached. The issue was introduced after a prior infinite-loop fix in t [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43444

CVE-2026-43444 is a Linux kernel flaw in drm/amdkfd error handling. According to the NVD record, if a queue update fails, the code should unreserve the buffer object before returning an error. The bug was corrected in stable kernel patches linked from the NVD entry. NVD rates the issue as medium severity with local attack conditions and high availability impact.

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43443

CVE-2026-43443 is a Linux kernel issue in the ASoC AMD ACP machine-driver code where clock acquisition return values were not checked in acp_card_rt5682_init() and acp_card_rt5682s_init(). If clk_get() returned an invalid pointer and later clock-core code dereferenced it, the kernel could crash. The upstream fix switches to devm_clk_get() and adds immediate IS_ERR() checks.

HIGH Linux CVE published 2026-05-08

CVE-2026-43441

CVE-2026-43441 is a Linux kernel availability issue in bonding. According to the NVD record and the kernel fix description, systems booted with ipv6.disable=1 can leave nd_tbl uninitialized, and bonding ARP/NS validation may then route an IPv6 NS/NA packet into ipv6_chk_addr(), causing a kernel NULL pointer dereference and crash. The published fix adds an ipv6_mod_enabled() check before dispatching IPv6 p [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43440

CVE-2026-43440 is a Linux kernel use-after-free in the net/mana code path. The issue comes from a setup error path in mana_gd_setup() where the workqueue pointer was not cleared after destroy_workqueue(), creating a mismatch with cleanup logic and a risk of double-destroy or stale-pointer use after a failed setup. NVD rates the issue HIGH with local attack requirements and references kernel patches as the fix.

HIGH Linux CVE published 2026-05-08

CVE-2026-43438

CVE-2026-43438 is a Linux kernel sched_ext vulnerability caused by an unbalanced css_put() in scx_cgroup_init(). In the error path, the code could drop a reference that was never acquired, underflowing the cgroup subsystem’s refcount and creating a potential use-after-free condition. NVD rates the issue HIGH (CVSS 7.8) and maps it to CWE-416.

HIGH Linux CVE published 2026-05-08

CVE-2026-43437

CVE-2026-43437 is a Linux kernel ALSA PCM use-after-free affecting snd_pcm_drain(). The issue comes from reusing a linked stream’s runtime pointer after the stream lock is released, while a concurrent close() path can free that runtime. The published fix caches the needed runtime fields before unlocking, removing the stale-pointer dereference window.

Review Linux CVE published 2026-05-08

CVE-2026-43435

CVE-2026-43435 is a Linux kernel rust_binder issue in the oneway spam detection path. The published fix corrects two defensive-control gaps: TreeRange was evaluating spam detection before inserting the current request into the tree, which meant the new request was excluded from the calculation, and ArrayRange did not implement the equivalent low_oneway_space() check at all. The result was that some spammi [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43434

CVE-2026-43434 is a Linux kernel Rust Binder issue where a VMA looked up by address could be replaced before use, allowing Binder to operate on the wrong mapping. The reported fix adds ownership checks using vm_private_data and vm_ops so Rust Binder refuses to interact with an unrelated VMA. Based on the CVE text and CVSS vector, this is a locally reachable kernel issue with high impact potential if the f [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43433

CVE-2026-43433 describes a Linux kernel rust_binder flaw where the kernel copied an offsets array into a target process’s VMA and then read the values back from that memory. The CVE text says this read-back was normally safe because the mapping is read-only, but it could become dangerous if another Binder bug somehow let the target process write to its own mapping. In that worst case, the kernel could mis [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43432

CVE-2026-43432 is a Linux kernel xHCI bug that leaks memory in an error-handling path inside xhci_disable_slot(). According to the supplied record, xhci_alloc_command() can allocate both a command structure and a completion structure, but the buggy path freed only the command with kfree(), leaving the completion object behind. The fix is to use xhci_free_command(), which releases both allocations correctly.

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43431

CVE-2026-43431 is a Linux kernel xhci bug in recently added portli debugfs files. Under certain hardware layout conditions, reading the debugfs entry can hit a NULL pointer dereference and crash the kernel. NVD rates the issue CVSS 5.5 (medium) with local, low-privilege access and no user interaction required.

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43430

CVE-2026-43430 is a Linux kernel race condition in the usb:yurex probe path. The issue is an ordering bug: the descriptor's bbu field must be set to the uninitialized sentinel before the URB is submitted, otherwise probe can race with the URB completion handler and overwrite data that has already been retrieved. NVD rates the issue 4.7/10 (MEDIUM) with a local attack vector, high attack complexity, low pr [truncated]