These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-43220 is a Linux kernel AMD IOMMU availability issue where concurrent TLB invalidations could cause completion waits to time out. The problem was that cmd_sem_val was incremented outside the IOMMU spinlock, which let CMD_COMPL_WAIT commands be queued out of sequence and violate the ordering assumption in wait_on_sem(). The published fix serializes completion-sequence allocation under iommu->lock [truncated]
A vulnerability was found in the Linux kernel's net: cpsw_new. The issue arises when an error occurs during register_netdev() for the first MAC in cpsw_register_ports(). This can cause cpsw_unregister_ports() to attempt to unregister the second MAC, which has not been registered yet. To fix this, a check for ndev->reg_state before calling unregister_netdev() was added.
A race condition vulnerability in the Linux kernel's TCP/IP implementation has been addressed. The issue arises in the tcp_v6_syn_recv_sock() function, where code execution after a specific call could lead to unintended behavior due to the child socket being prematurely visible in the TCP ehash table. This could allow other CPUs to use the socket inappropriately. The problem has been mitigated by moving t [truncated]
A vulnerability was found in the Linux kernel's netconsole functionality. The issue arises because the message passed to netconsole from the console subsystem is not guaranteed to be nul-terminated, leading to out-of-bounds reads. This could potentially allow an attacker to access sensitive information. The vulnerability has been resolved with patches available.
A NULL pointer dereference vulnerability exists in the Linux kernel's ASoC SOF Intel HDA driver. The issue occurs when there is a mismatch between DAI links in the machine driver and the topology, particularly in loopback capture scenarios using dummy DAI links for echo reference. When the playback/capture widget is not set due to this mismatch, the code fails to check for NULL before dereferencing, leadi [truncated]
A Linux kernel vulnerability was resolved, affecting KVM: nSVM, where VMLOAD/VMSAVE emulation mistakenly used vmcb02 instead of vmcb01, potentially leading to unintended behavior. This issue arises from a missed update in the VMLOAD/VMSAVE emulation code, which failed to adopt the always-use-vmcb01 approach for fields controlled by VMSAVE/VMLOAD, as initially implemented in a previous commit. The vulnerab [truncated]
CVE-2026-43129 is a Linux kernel availability issue in IMA measurement-list restore during kexec boot. According to the official description, if the second-stage kernel starts with a memory-limiting command line such as mem=<size>, the IMA buffer handed over from the previous kernel can fall outside the new kernel’s addressable RAM. Accessing that buffer during early restore can trigger a page fault and c [truncated]
The Linux kernel has a vulnerability in the ASoC: SOF: ipc4-topology component. The vulnerability is related to the allocation size for bytes controls. The issue has been resolved with several patches available. Users and administrators of Linux kernel systems, especially those with local access to the system, should be aware of this vulnerability. They need to review their system configurations, apply pa [truncated]
A use-after-free vulnerability exists in the Linux kernel's rpmsg driver due to a race condition between the driver_override_show and driver_override_store functions. The show function reads the driver_override string without holding the device_lock, while the store function modifies and frees the string while holding the device_lock. This can lead to a use-after-free condition where the string is freed b [truncated]
A MEDIUM severity vulnerability was discovered in the Linux kernel, tracked as CVE-2025-71273. The issue was resolved by using device managed memory allocations with devm_kmemdup() in rtw_set_supported_band(). This change also fixes a memory leak in rtw_register_hw(), where supported bands were not freed in the error path. The vulnerability has a CVSS score of 5.5.
A medium-severity vulnerability was patched in the Linux kernel in May 2026. CVE-2026-43119 affects Bluetooth HCI synchronization, allowing potential data races around hdev->req_status. The issue was resolved by adding READ_ONCE()/WRITE_ONCE() annotations. Linux kernel maintainers, Linux distribution vendors, and organizations using Linux kernel versions 5.2 through 7.0-rc5 should apply patches to prevent [truncated]
CVE-2026-43116 is a HIGH severity vulnerability in the Linux kernel's netfilter component. It allows local attackers to escalate privileges due to unsafe access to master conntrack objects. The vulnerability has been resolved through a series of patches addressing safe access to master conntrack. Affected Linux kernel versions range from 2.6.16 to 6.18.24, 6.19 to 6.19.14, and specific 7.0 release candidates.
CVE-2026-43109 is a Linux kernel vulnerability in the x86 shadow stack path. The issue is an error-handling oversight: shstk_pop_sigframe() did not check for failures from mmap_read_lock_killable(), and the fix also adds __must_check coverage so similar mistakes are caught earlier. The published CVSS 3.1 vector rates this as a local, low-privilege issue with high availability impact and no confidentiality [truncated]
A validation flaw in the Linux kernel's AF_XDP socket bind operation allows zero-copy pool configurations that do not accommodate the device MTU within the usable frame space. When tailroom is subtracted from chunk_size, a 2KB chunk may be insufficient for standard 1500-byte MTU frames. The kernel now validates at bind time that the MTU fits within the frame size and that underlying hardware can satisfy t [truncated]
A use-after-free vulnerability exists in the Linux kernel's XFRM (IPsec transform) subsystem during network namespace teardown. The xfrm_policy_fini() function frees policy_bydst hash tables without waiting for concurrent RCU readers to exit their critical sections. Since these tables are published via rcu_assign_pointer() and accessed through rcu_dereference_check(), premature freeing allows use-after-fr [truncated]
CVE-2026-43089 is an information disclosure issue in the Linux kernel’s xfrm_user code path. The published fix says build_mapping() could copy a struct xfrm_usersa_id to userspace without clearing a one-byte padding hole after the proto field, potentially leaking uninitialized kernel memory. The kernel fix zeroes the whole structure before setting fields.
A vulnerability in the Linux kernel's PF_KEY export paths has been resolved. The issue involves uninitialized aligned sockaddr payloads in certain PF_KEY messages, specifically `SADB_ACQUIRE`, `SADB_X_NAT_T_NEW_MAPPING`, and `SADB_X_MIGRATE`. This could potentially lead to information disclosure or other security issues if exploited. The fix involves clearing only the aligned sockaddr tail after `pfkey_so [truncated]
CVE-2026-43084 is a Linux kernel netfilter issue in nfnetlink_queue that can trigger a slab-use-after-free while nfqnl_recv_verdict walks queue entries. The source description says the crash is caused by sharing a global hash table across queues, allowing a freed nf_queue_entry to be encountered by a parallel CPU. NVD rates it HIGH with a local attack vector and lists multiple affected kernel version rang [truncated]
CVE-2026-43078 is a high-severity Linux kernel vulnerability in the af_alg crypto subsystem. The issue was resolved by fixing an overflow in af_alg_pull_tsgl: after page reassignment was introduced, the original loop could attempt to reassign one page too many. The kernel patch adds a check to prevent the extra reassignment and updates an outdated comment. Because the CVSS vector requires local access and [truncated]
CVE-2026-43077 is a Linux kernel issue in the algif_aead decryption path where the minimum receive-buffer size check did not account for the authentication tag length. The published fix adds the missing extra length so the size check matches decryption requirements. NVD rates the issue as medium severity and lists only availability impact.
CVE-2026-43076 is a Linux kernel OCFS2 inode-validation bug. When the kernel reads an inode from disk, ocfs2_validate_inode_block() did not verify that inline data i_size stayed within the actual inline data capacity (id_count). On a corrupted filesystem, that mismatch can let directory iteration walk past the inline buffer and reach freed memory, resulting in a use-after-free in the directory-entry validation path.
CVE-2026-43075 is a Linux kernel OCFS2 flaw in inline-data write handling. The issue occurs because the filesystem code trusted the on-disk id_count field too far: on a corrupted OCFS2 filesystem, an oversized id_count can make ocfs2_write_end_inline write past the inode block buffer, which KASAN reports as a use-after-free style write into an adjacent freed page. The referenced fix adds an upper-bound ch [truncated]
CVE-2026-43074 is a Linux kernel eventpoll use-after-free in ep_free() where struct eventpoll can be freed while another concurrent thread is still using it. The fix defers the kfree() to an RCU callback to avoid the race. NVD rates the issue HIGH with CVSS 7.8.
CVE-2026-43073 concerns a Linux kernel x86-64 helper that was misleadingly named and had an awkward interface. The source description says the routine is neither a true user-copy helper nor a non-cached source copy; it is a specialty copy path that uses non-temporal stores for the destination and exception handling for both source and destination accesses. The patch set renames the helper, adjusts its pro [truncated]
A missing error check in the Linux kernel's DRM VC4 driver allows a negative IRQ error code from platform_get_irq_byname() to be passed directly into devm_request_threaded_irq(), leading to undefined behavior and potential local denial of service. The flaw exists because the return value was treated as valid without verifying it was non-negative. Patches are available for multiple stable kernel branches.
A critical out-of-bounds (OOB) read vulnerability exists in the Linux kernel's dentry cache (dcache) subsystem, triggered when a user sets the kernel boot parameter `dhash_entries=1`. This configuration causes the dentry hash table to be allocated with only a single bucket. The `d_hash_shift` value is then calculated as 32 by `dcache_init()`. During dentry lookup operations in `__d_lookup()`, the hash ind [truncated]
A logic error in the Linux kernel's BPF verifier fails to reset the scalar register ID after BPF_END (byte-swap) operations. When a register that shares a scalar ID with another register undergoes byte-swap mutation, the verifier incorrectly propagates learned bounds to the linked register during conditional jumps. This false confidence in register values can lead to out-of-bounds memory access. The fix e [truncated]
A missing firmware release call in the Linux kernel's Bluetooth hci_ll driver causes a resource leak when request_firmware() succeeds but returns invalid content. The bug was identified by Smatch static analysis and affects multiple stable kernel branches. Patches have been committed to all supported stable trees.
CVE-2026-43068 is a Linux kernel ext4 issue where delayed block allocation can fail when the allocator keeps targeting a corrupted block group. The reported symptom is repeated allocation failures followed by ext4 warnings that data may be lost. NVD rates the issue MEDIUM (CVSS 5.5) because it is locally reachable and can disrupt availability.
CVE-2026-43066 is a medium-severity (CVSS 3.1: 5.5) memory leak vulnerability in the Linux kernel's ext4 filesystem fast-commit replay logic. The flaw exists in ext4_fc_replay_inode(), where ext4_get_fc_inode_loc() acquires a reference to iloc.bh (a buffer head) that must be released via brelse(). Multiple error paths—including failures in ext4_handle_dirty_metadata(), sync_dirty_buffer(), ext4_mark_inode [truncated]