PatchSiren

Linux CVE debriefs · Page 105

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43393

A memory leak vulnerability exists in the Btrfs filesystem implementation within the Linux kernel. Specifically, the `btrfs_map_block()` function fails to release a chunk map object when an early return with `-EINVAL` occurs after calling `btrfs_chunk_map_num_copies()`. This flaw leads to resource exhaustion over time, potentially causing system instability or denial of service conditions on affected syst [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43392

A vulnerability in the Linux kernel's sched_ext (BPF extensible scheduler) subsystem allows system hangs during scheduler enablement. When scx_enable() executes, it transitions tasks from the fair scheduling class to the ext class. Because fair class tasks have higher priority than ext class tasks, a saturated fair-class workload can indefinitely starve the enable thread, causing a complete system hang. T [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43391

A privilege escalation vulnerability in the Linux kernel's nsfs (namespace filesystem) subsystem allows local attackers to bypass namespace isolation boundaries. The flaw exists in the permission checks for handle opening operations on namespace files, where insufficient validation could permit privileged services to access other privileged services' namespaces, enabling information leakage between isolat [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43390

A vulnerability in the Linux kernel's nstree (namespace tree) subsystem allowed privileged services to enumerate namespaces belonging to other privileged services, potentially enabling cross-service information leakage. The issue stemmed from insufficient permission checks when listing namespaces. The fix introduces the `may_see_all_namespaces()` helper to centralize and tighten access policy enforcement. [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43389

## Summary CVE-2026-43389 is a data-loss vulnerability in the Linux kernel's memfd Live Update (LUO) subsystem. The flaw occurs because clean folios (memory pages) preserved during a live update could be incorrectly reclaimed under memory pressure after retrieval, resulting in loss of user data. The root cause was that the dirty state was captured at preserve() time rather than at freeze(), allowing folio [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43388

A use-after-free vulnerability in the Linux kernel's DAMON (Data Access MONitor) subsystem could allow local attackers to corrupt memory or cause denial of service. The flaw exists in damos_walk() where a stack-allocated walk_control structure pointer is left dangling when the DAMON context is inactive, creating conditions for use-after-free if the context is later started. While the described use-after-f [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43387

This CVE addresses an out-of-bounds read vulnerability in the rtl8723bs staging driver within the Linux kernel. The flaw exists in the `rtw_get_ie_ex()` function, which failed to properly validate length fields in wireless frame data before processing. This vulnerability is conceptually similar to a prior fix in commit 154828bf9559 for the related `rtw_get_ie()` function. The issue affects multiple Linux [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43386

CVE-2026-43386 is a HIGH severity (CVSS 7.1) out-of-bounds read vulnerability in the Linux kernel's staging rtl8723bs Wi-Fi driver. The flaw exists in the `rtw_restruct_wmm_ie` function where the code accesses `in_ie[i + 5]` before verifying that `i + 5 < in_len`, allowing a local attacker with low privileges to trigger an out-of-bounds read. This is classified as CWE-125 (Out-of-bounds Read). The vulnera [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43382

A deadlock vulnerability exists in the Linux kernel's B.A.T.M.A.N. advanced (batman-adv) mesh networking subsystem. The flaw occurs in the ELP (Echo Location Protocol) metric worker when batadv_v_elp_get_throughput() is called while the RTNL (routing/netlink) lock is already held. A previous fix attempted to use rtnl_trylock() to avoid deadlock when retrieving ethtool information, but failed to address th [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43381

A vulnerability in the Linux kernel's nouveau driver for NVIDIA GPUs allows local users to trigger a kernel crash when attempting DisplayPort AUX channel transfers while the GPU is in a runtime-suspended (asleep) state. The issue occurs because the driver fails to check power state before initiating GSP (GPU System Processor) RPC operations, leading to a NULL pointer dereference or use-after-free in the G [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43380

CVE-2026-43380 is a Linux kernel vulnerability in the hwmon/pmbus q54sj108a2 debugfs read path. The bug can overflow a stack buffer when hex output is generated with bin2hex() using the wrong destination/source arguments and insufficient output space. NVD rates the issue HIGH with local, low-privilege access required.

CRITICAL Linux CVE published 2026-05-08

CVE-2026-43378

CVE-2026-43378 is a critical Linux kernel vulnerability in the SMB server path. The kernel fix description says smb2_open() can dereference an opinfo pointer obtained via rcu_dereference(fp->f_opinfo) after rcu_read_unlock(), creating a use-after-free window. NVD rates the issue CVSS 9.8 with network attack vector and no privileges or user interaction required, so affected systems exposed through SMB shou [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43347

CVE-2026-43347 is a Linux kernel arm64 device-tree issue affecting Qualcomm Monaco-based platforms. According to the CVE record, firmware only reserved part of the Gunyah metadata area, leaving the rest available as conventional memory; the kernel could then allocate from hypervisor-owned pages and trigger synchronous external aborts and crashes. The fix reserves the full 512 KiB region and marks it no-ma [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43343

CVE-2026-43343 is a Linux kernel USB gadget bug in the f_subset function where geth_alloc() increments a reference count but geth_free() did not decrement it. According to the supplied record, this left cleanup unbalanced and prevented configuration of attributes via configfs after unlinking the function. The fix is a reference-count decrement in geth_free() to restore proper teardown and post-unlink conf [truncated]

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43342

CVE-2026-43342 affects the Linux kernel’s USB gadget RNDIS function. The issue is a race condition in class, subclass, and protocol option handling when those values are accessed concurrently through configfs. The fix uses an existing mutex to serialize access; the issue was identified during code inspection.

CRITICAL Linux CVE published 2026-05-08

CVE-2026-43341

CVE-2026-43341 is a Linux kernel vulnerability in net/ipv6 ioam6 trace filling where a schema-length value could wrap around and defeat a remaining-space check. The resulting cursor miscalculation could allow writes past the trace buffer, and the upstream fix keeps the length in a wider integer type so the size checks and cursor math use the full value.

HIGH Linux CVE published 2026-05-08

CVE-2026-43328

CVE-2026-43328 is a Linux kernel double-free flaw in cpufreq governor initialization. The bug occurs on an error path after kobject_init_and_add(), where cleanup can be performed twice through cpufreq_dbs_data_release() and the surrounding failure handling. NVD rates the issue high severity (CVSS 7.8) and lists multiple affected kernel version ranges.

MEDIUM Linux CVE published 2026-05-08

CVE-2026-43311

CVE-2026-43311 is a medium-severity vulnerability in the Linux kernel, specifically affecting the soc/tegra: pmc component. The vulnerability arises from an unsafe call to generic_handle_irq() in a non-interrupt context, triggering a warning during system resume on Tegra platforms. The issue is resolved by deferring the generic_handle_irq() call to an IRQ work executed in hard IRQ context. This vulnerabil [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2025-71300

A vulnerability in the Linux kernel has been identified and resolved. The issue involves reverting a commit that added an OP-TEE node to the device tree, which caused memory access violations during runtime due to conflicts with OP-TEE's automatic injection of a reserved-memory node. This vulnerability affects Linux kernel versions and could lead to local privilege escalation. Developers, maintainers, and [truncated]

HIGH Linux CVE published 2026-05-08

CVE-2026-43284

CVE-2026-43284 is a Linux kernel flaw in XFRM ESP processing for UDP-encapsulated traffic. When IPv4/IPv6 datagram splice paths failed to mark pipe-backed pages as shared, ESP input could decrypt data in place on skbs that were not privately owned, creating a high-impact memory corruption risk. NVD rates the issue 8.8 High and lists fixed stable kernel branches.

HIGH Linux CVE published 2026-05-06

CVE-2026-43249

CVE-2026-43249 is a Linux kernel memory-safety issue in the Xen 9p front-end path. NVD describes a race where the xenwatch thread can overlap with other back-end change notifications and call xen_9pfs_front_free() more than once, leading to a double-free and a general protection fault. The issue is publicly documented as fixed in kernel patches referenced by NVD, and the advisory dates show the CVE was pu [truncated]

HIGH Linux CVE published 2026-05-06

CVE-2026-43248

CVE-2026-43248 is a Linux kernel memory-safety flaw in the vhost/vDPA path. The kernel fix consolidates vdpa group bound checks into vhost_vdpa to avoid parent drivers missing validation, and also corrects a vdpa_sim bug where a valid ASID could be assigned to a group equal to ngroups, leading to an out-of-bounds write. NVD rates the issue 7.8/High with local, low-privilege attack conditions and high impa [truncated]

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43247

CVE-2026-43247 affects the Linux kernel’s chips-media wave5 media driver and can lead to an asynchronous SError and kernel panic. The issue was observed while testing fluster, where an autosuspend delay timeout could cause the device to enter suspend mode at the wrong time. NVD rates the issue as CVSS 5.5/Medium, with local attack conditions and high availability impact. Patched kernel references are prov [truncated]

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43246

CVE-2026-43246 is a Linux kernel memory-leak issue in the media:i2c/tw9906 driver. In an error path in tw9906_probe(), memory allocated by v4l2_ctrl_handler_init() and v4l2_ctrl_new_std() was not freed. The fix adds v4l2_ctrl_handler_free() on that handler before returning from the failing path. NVD classifies the issue as medium severity and maps it to CWE-401 (Missing Release of Memory after Effective Lifetime).

HIGH Linux CVE published 2026-05-06

CVE-2026-43245

CVE-2026-43245 is a Linux kernel NTFS vulnerability in which d_compare() must not block, but the affected code did. The published fix replaces the problematic allocation path with kmalloc(PATH_MAX, GFP_NOWAIT) and stops relying on names_cachep for uses that are not actually pathname handling. NVD rates the issue CVSS 7.5 HIGH with an availability impact.

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43244

CVE-2026-43244 is a Linux kernel KCM issue where a partial sendmsg() failure can leave an empty skb in a frag_list. In the affected path, that malformed chain can later trigger a kernel warning while messages are processed, creating an availability problem. The kernel fix adds cleanup for the empty skb and reduces repeated warning noise.

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43243

CVE-2026-43243 is a Linux kernel vulnerability in the AMD display code path that can trigger a crash when the driver tries to access link-encoder state on a DPIA link. NVD rates the issue as medium severity with availability impact only, and lists multiple affected kernel release ranges that are fixed in later stable updates.

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43242

CVE-2026-43242 is a Linux kernel availability issue in the TI K3 SoC info driver. According to the CVE description, the mmio regmap allocated during probe was not being freed, which could leave resources unreleased on probe failures such as probe deferral and on driver unbind. NVD rates the issue 5.5 MEDIUM and classifies it as CWE-401 (missing release of memory after effective lifetime).

HIGH Linux CVE published 2026-05-06

CVE-2026-43241

CVE-2026-43241 is a Linux kernel memory-safety issue in ntb_hw_switchtec. The supplied advisory text says the number of MW LUTs depends on NTB configuration and may be set to MAX_MWS, which could lead to an invalid index into mw_sizes. The fix adds bounds protection and reports an invalid configuration when access would go out of range.

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43240

CVE-2026-43240 is a Linux kernel availability issue in x86 kexec handling. If a second-stage kernel is started with a limiting command line such as mem=<size>, the preserved IMA measurement list from the previous kernel can land outside the usable RAM range. When the kernel tries to restore that list, it can fault and panic during boot. The main risk is loss of system availability and disrupted attestatio [truncated]