These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-43429 is a Linux kernel USB usbtmc issue where user-specified ioctl timeout values could be passed into usb_bulk_msg() calls that used unkillable waits. The fix changes those paths to usb_bulk_msg_killable(), reducing the risk that a local user can keep a kernel thread waiting indefinitely or for an excessively long time.
CVE-2026-43428 is a Linux kernel USB core availability issue affecting synchronous message APIs. Before the fix, usb_control_msg(), usb_bulk_msg(), and usb_interrupt_msg() could accept unlimited timeouts while waiting uninterruptibly, which could leave a task hung indefinitely unless the device was unplugged. The resolved change caps these unkillable timeouts at 60 seconds and treats negative timeout valu [truncated]
CVE-2026-43427 is a Linux kernel vulnerability in the USB class cdc-wdm read path. According to the published description, a reordering issue can let desc->length be updated before the associated memmove completes, so wdm_read() may observe the new length and copy uninitialized memory to user space. NVD rates the issue HIGH with a 7.1 CVSS score and marks it as analyzed. The supplied record also points to [truncated]
CVE-2026-43426 is a Linux kernel use-after-free in the Renesas USBHS driver’s interrupt handling during device removal. The public record says usbhs_remove() freed driver resources, including the pipe array, while usbhs_interrupt() was still registered. If an interrupt arrived after usbhs_pipe_remove() but before unbind completed, the ISR could dereference freed memory. The fix moves devm_free_irq() earli [truncated]
CVE-2026-43425 is a Linux kernel USB driver issue in the mdc800 path. If mdc800_device_read() times out while waiting for download_urb completion, it can return without killing the URB, so a later read() may resubmit an URB that is still active and trigger the warning “URB submitted while active.” NVD rates this as medium severity with local, low-privilege access and high availability impact.
CVE-2026-43423 is a Linux kernel issue in the usb: gadget: f_ncm path where ncm_set_alt held a mutex while running in an atomic context. The reported result is the classic "sleeping function called from invalid context" warning seen in the call trace. The upstream fix removes the struct net_device pointer from f_ncm_opts to eliminate the locking contention, and switches connection-state handling to a bool [truncated]
CVE-2026-43422 covers a Linux kernel USB legacy NCM issue where gncm_bind() could hit a NULL pointer dereference after a lifecycle change deferred net_device allocation. The fix preserves qmult, host_addr, and dev_addr in ncm_opts->net_opts during bind so they can be applied later, after the net_device exists.
CVE-2026-43421 is a Linux kernel USB gadget bug in f_ncm where the network device could outlive its parent gadget device during disconnect. According to the NVD record and kernel fix description, this created dangling sysfs links and null pointer dereference risk, and also caused a regression affecting USB reconnection and DHCP behavior on pmOS. The fix reworks net_device lifetime management using device_ [truncated]
CVE-2026-43420 describes a race in the Linux kernel Ceph client during asynchronous unlink handling. The issue can cause the inode link count (`i_nlink`) to be decremented after it has already been updated to zero by a concurrent completion or capability update, which can trigger a kernel WARNING in `drop_nlink()`. The source description ties the problem to the async unlink path in `ceph_unlink()`, where [truncated]
CVE-2026-43419 is a Linux kernel Ceph client bug that can leak memory in ceph_mdsc_build_path() when error paths fail to release a path buffer allocated with __getname(). The upstream fix adds the missing __putname() cleanup before returning when ownership is not transferred to the caller. This is primarily a stability and resource-consumption issue rather than a direct code-execution flaw.
CVE-2026-43418 describes a Linux kernel concurrency bug in the sched/mmcid path. A newly forked task could be counted as an MMCID user before it became visible in the thread and task lists. Under concurrent fork activity, this race could prevent already allocated CIDs from being fixed up, and a later schedule-in could fail to obtain a transitional CID, stalling the machine. The fix reorders the fork handl [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's PowerPC performance monitoring subsystem. When collecting user-space callchains via perf, the kernel fails to verify that `current->mm` (the current process's memory descriptor) is still valid. If the process's memory context has already been released—such as during process exit while BPF profiling programs are still executing—subsequen [truncated]
CVE-2026-43415 is a Linux kernel availability issue in the UFS core suspend path. The NVD record and kernel fix description indicate a race in __ufshcd_wl_suspend(): cancel_delayed_work_sync() was called too late, allowing ufshcd_rtc_work() to overlap with ufshcd_vops_suspend(). On systems without UFSHCD_CAP_CLK_GATING, that overlap can lead to ufshcd_update_rtc() running while suspend-time clock gating i [truncated]
CVE-2026-43413 is a Linux kernel vulnerability in the hisi_sas SCSI driver that can crash the system during a user-initiated scan. The issue stems from the updated sas_user_scan() path iterating over channel 1 on hardware that supports only one channel, leading to a NULL pointer dereference and kernel Oops. NVD rates the issue as medium severity with local attack requirements and high availability impact.
A divide-by-zero vulnerability exists in the Linux kernel's TIPC (Transparent Inter-Process Communication) socket implementation. The flaw occurs in `tipc_sk_filter_connect()` when a user sets `conn_timeout` to a value less than 4 via `setsockopt(TIPC_CONN_TIMEOUT)`. When a SYN packet is rejected with `TIPC_ERR_OVERLOAD`, the retry path executes `delay %= (tsk->conn_timeout / 4)`, which triggers a divide- [truncated]
CVE-2026-43410 is a Linux kernel availability vulnerability in the Stratix10 Remote System Update (RSU) driver. When RSU is not enabled in the First Stage Boot Loader (FSBL), the driver can continue after a failed async message send, later dereference an invalid channel, and panic the kernel. NVD rates the issue as CVSS 3.1 5.5/Medium with local attack requirements and high availability impact only.
CVE-2026-43409 is a Linux kernel vulnerability in kprobes handling that can lead to a crash when a module is removed or inserted after ftrace has already been killed by an earlier error path. NVD rates the issue CVSS 5.5/Medium, with local privileges required and high availability impact. The kernel fix is to check kprobe_ftrace_disabled in __disarm_kprobe_ftrace() and skip ftrace-related operations once [truncated]
CVE-2026-43408 is a Linux kernel Ceph client issue where ceph_mdsc_build_path() expects a zero-initialized ceph_path_info structure. Some callers were missing initializers, so later cleanup via ceph_mdsc_free_path_info() could operate on uninitialized state and trigger kernel crashes. The supplied record includes SLUB warnings and an oops on affected kernels, and NVD rates the issue HIGH with local, low-p [truncated]
CVE-2026-43407 is a critical Linux kernel libceph vulnerability in ceph_handle_auth_reply(). A malformed CEPH_MSG_AUTH_REPLY message can drive an integer overflow in payload_len, turning a length into a negative value and leading to an out-of-bounds read. The issue was published on 2026-05-08 and last modified on 2026-05-21; official stable kernel patch references are listed in the source corpus.
CVE-2026-43406 is a critical Linux kernel issue in libceph where malformed or spoofed message framing can cause out-of-bounds reads during process_message_header(). The published fix adds an explicit bounds check before decoding the message header, reducing the chance that corrupted control-segment sizing or a frame that only appears to be a message frame will drive unsafe parsing.
CVE-2026-43405 is a Linux kernel libceph parsing bug in ceph_monmap_decode(). The issue is not a classic code-execution flaw; it is a validation and type-handling mistake that can turn a large incoming value into a negative signed int, bypass the num_mon > CEPH_MAX_MON check, and drive an attempted oversized allocation for the monmap structure. NVD rates the issue as high severity because it is remotely r [truncated]
CVE-2026-43404 is a Linux kernel availability bug in the memory-management path. According to the kernel fix summary, hmm_range_fault() could spin after a folio_trylock() failure in do_swap_page() while trying to lock a device-private folio for migration to RAM. In a narrow set of conditions, the spinning task can starve the work item needed by the lock holder, creating a livelock/starvation loop that doe [truncated]
CVE-2026-43403 is a Linux kernel vulnerability in nsfs namespace-iteration ioctls. The documented fix tightens permission checks so that even privileged services do not necessarily see other privileged services’ namespaces, reducing the chance of information leakage across privilege boundaries. NVD rates the issue HIGH (CVSS 8.8) and links kernel patches for remediation.
CVE-2026-43402 is a critical Linux kernel use-after-free in kthread teardown. According to the CVE description, a kthread that exits through make_task_dead() could bypass kthread_exit(), skip affinity-node cleanup, and leave a node linked in the global kthread_affinity_list while the struct kthread memory is freed and later reused. That can let a later list_del() write through dangling pointers and corrup [truncated]
CVE-2026-43401 is a Linux kernel availability issue in cpufreq: intel_pstate. On systems booted with the nosmt parameter, update_cpu_qos_request() could dereference a NULL cpudata pointer before validating policy and driver state, leading to a NULL pointer dereference when qos requests are updated. The NVD record rates the impact as medium severity with high availability impact, and the affected ranges in [truncated]
CVE-2026-43400 is a Linux kernel vulnerability in amdgpu_userq_signal_ioctl where excessively large user inputs could trigger an out-of-memory condition and be exploited. NVD lists affected Linux kernel ranges as 6.16 through before 6.18.19, 6.19 through before 6.19.9, and 7.0-rc1, with the issue published on 2026-05-08.
CVE-2026-43397 is a Linux kernel issue in the drm/bridge samsung-dsim driver where an attach failure path could leave the bridge registered and leak memory. The flaw was published on 2026-05-08 and later updated on 2026-05-21. NVD rates it CVSS 5.5 (medium) with a local, low-privilege attack vector and availability impact only.
CVE-2026-43396 is a Linux kernel vulnerability in the drm/xe/sync path where a failed dma_fence_chain_alloc() could leave a user fence reference unreleased. NVD rates it medium severity with a local availability impact, and the issue is tracked as CWE-401 (memory leak).
CVE-2026-43395 is a Linux kernel issue in the Xe DRM sync parsing path. According to the vendor description, error handling in xe_sync_entry_parse() could return after allocating references, leaving partially initialized sync state behind. The fix routes those failures through a common cleanup path so allocated sync objects are released before returning.
A credential reference leak in the Linux kernel's NFS server (nfsd) netlink listener configuration allows local attackers to cause denial of service through memory exhaustion. The vulnerability exists in nfsd_nl_listener_set_doit() which used get_current_cred() without a corresponding put_cred(), causing the credential structure to leak on each invocation. The fix replaces get_current_cred() with current_ [truncated]