PatchSiren

Linux CVE debriefs · Page 106

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43220

CVE-2026-43220 is a Linux kernel AMD IOMMU availability issue where concurrent TLB invalidations could cause completion waits to time out. The problem was that cmd_sem_val was incremented outside the IOMMU spinlock, which let CMD_COMPL_WAIT commands be queued out of sequence and violate the ordering assumption in wait_on_sem(). The published fix serializes completion-sequence allocation under iommu->lock [truncated]

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43219

A vulnerability was found in the Linux kernel's net: cpsw_new. The issue arises when an error occurs during register_netdev() for the first MAC in cpsw_register_ports(). This can cause cpsw_unregister_ports() to attempt to unregister the second MAC, which has not been registered yet. To fix this, a check for ndev->reg_state before calling unregister_netdev() was added.

CRITICAL Linux CVE published 2026-05-06

CVE-2026-43198

A race condition vulnerability in the Linux kernel's TCP/IP implementation has been addressed. The issue arises in the tcp_v6_syn_recv_sock() function, where code execution after a specific call could lead to unintended behavior due to the child socket being prematurely visible in the TCP ehash table. This could allow other CPUs to use the socket inappropriately. The problem has been mitigated by moving t [truncated]

CRITICAL Linux CVE published 2026-05-06

CVE-2026-43197

A vulnerability was found in the Linux kernel's netconsole functionality. The issue arises because the message passed to netconsole from the console subsystem is not guaranteed to be nul-terminated, leading to out-of-bounds reads. This could potentially allow an attacker to access sensitive information. The vulnerability has been resolved with patches available.

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43137

A NULL pointer dereference vulnerability exists in the Linux kernel's ASoC SOF Intel HDA driver. The issue occurs when there is a mismatch between DAI links in the machine driver and the topology, particularly in loopback capture scenarios using dummy DAI links for echo reference. When the playback/capture widget is not set due to this mismatch, the code fails to check for NULL before dereferencing, leadi [truncated]

HIGH Linux CVE published 2026-05-06

CVE-2026-43133

A Linux kernel vulnerability was resolved, affecting KVM: nSVM, where VMLOAD/VMSAVE emulation mistakenly used vmcb02 instead of vmcb01, potentially leading to unintended behavior. This issue arises from a missed update in the VMLOAD/VMSAVE emulation code, which failed to adopt the always-use-vmcb01 approach for fields controlled by VMSAVE/VMLOAD, as initially implemented in a previous commit. The vulnerab [truncated]

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43129

CVE-2026-43129 is a Linux kernel availability issue in IMA measurement-list restore during kexec boot. According to the official description, if the second-stage kernel starts with a memory-limiting command line such as mem=<size>, the IMA buffer handed over from the previous kernel can fall outside the new kernel’s addressable RAM. Accessing that buffer during early restore can trigger a page fault and c [truncated]

HIGH Linux CVE published 2026-05-06

CVE-2025-71286

The Linux kernel has a vulnerability in the ASoC: SOF: ipc4-topology component. The vulnerability is related to the allocation size for bytes controls. The issue has been resolved with several patches available. Users and administrators of Linux kernel systems, especially those with local access to the system, should be aware of this vulnerability. They need to review their system configurations, apply pa [truncated]

HIGH Linux CVE published 2026-05-06

CVE-2025-71274

A use-after-free vulnerability exists in the Linux kernel's rpmsg driver due to a race condition between the driver_override_show and driver_override_store functions. The show function reads the driver_override string without holding the device_lock, while the store function modifies and frees the string while holding the device_lock. This can lead to a use-after-free condition where the string is freed b [truncated]

MEDIUM Linux CVE published 2026-05-06

CVE-2025-71273

A MEDIUM severity vulnerability was discovered in the Linux kernel, tracked as CVE-2025-71273. The issue was resolved by using device managed memory allocations with devm_kmemdup() in rtw_set_supported_band(). This change also fixes a memory leak in rtw_register_hw(), where supported bands were not freed in the error path. The vulnerability has a CVSS score of 5.5.

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43119

A medium-severity vulnerability was patched in the Linux kernel in May 2026. CVE-2026-43119 affects Bluetooth HCI synchronization, allowing potential data races around hdev->req_status. The issue was resolved by adding READ_ONCE()/WRITE_ONCE() annotations. Linux kernel maintainers, Linux distribution vendors, and organizations using Linux kernel versions 5.2 through 7.0-rc5 should apply patches to prevent [truncated]

HIGH Linux CVE published 2026-05-06

CVE-2026-43116

CVE-2026-43116 is a HIGH severity vulnerability in the Linux kernel's netfilter component. It allows local attackers to escalate privileges due to unsafe access to master conntrack objects. The vulnerability has been resolved through a series of patches addressing safe access to master conntrack. Affected Linux kernel versions range from 2.6.16 to 6.18.24, 6.19 to 6.19.14, and specific 7.0 release candidates.

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43109

CVE-2026-43109 is a Linux kernel vulnerability in the x86 shadow stack path. The issue is an error-handling oversight: shstk_pop_sigframe() did not check for failures from mmap_read_lock_killable(), and the fix also adds __must_check coverage so similar mistakes are caught earlier. The published CVSS 3.1 vector rates this as a local, low-privilege issue with high availability impact and no confidentiality [truncated]

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43092

A validation flaw in the Linux kernel's AF_XDP socket bind operation allows zero-copy pool configurations that do not accommodate the device MTU within the usable frame space. When tailroom is subtracted from chunk_size, a 2KB chunk may be insufficient for standard 1500-byte MTU frames. The kernel now validates at bind time that the MTU fits within the frame size and that underlying hardware can satisfy t [truncated]

HIGH Linux CVE published 2026-05-06

CVE-2026-43091

A use-after-free vulnerability exists in the Linux kernel's XFRM (IPsec transform) subsystem during network namespace teardown. The xfrm_policy_fini() function frees policy_bydst hash tables without waiting for concurrent RCU readers to exit their critical sections. Since these tables are published via rcu_assign_pointer() and accessed through rcu_dereference_check(), premature freeing allows use-after-fr [truncated]

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43089

CVE-2026-43089 is an information disclosure issue in the Linux kernel’s xfrm_user code path. The published fix says build_mapping() could copy a struct xfrm_usersa_id to userspace without clearing a one-byte padding hole after the proto field, potentially leaking uninitialized kernel memory. The kernel fix zeroes the whole structure before setting fields.

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43088

A vulnerability in the Linux kernel's PF_KEY export paths has been resolved. The issue involves uninitialized aligned sockaddr payloads in certain PF_KEY messages, specifically `SADB_ACQUIRE`, `SADB_X_NAT_T_NEW_MAPPING`, and `SADB_X_MIGRATE`. This could potentially lead to information disclosure or other security issues if exploited. The fix involves clearing only the aligned sockaddr tail after `pfkey_so [truncated]

HIGH Linux CVE published 2026-05-06

CVE-2026-43084

CVE-2026-43084 is a Linux kernel netfilter issue in nfnetlink_queue that can trigger a slab-use-after-free while nfqnl_recv_verdict walks queue entries. The source description says the crash is caused by sharing a global hash table across queues, allowing a freed nf_queue_entry to be encountered by a parallel CPU. NVD rates it HIGH with a local attack vector and lists multiple affected kernel version rang [truncated]

HIGH Linux CVE published 2026-05-06

CVE-2026-43078

CVE-2026-43078 is a high-severity Linux kernel vulnerability in the af_alg crypto subsystem. The issue was resolved by fixing an overflow in af_alg_pull_tsgl: after page reassignment was introduced, the original loop could attempt to reassign one page too many. The kernel patch adds a check to prevent the extra reassignment and updates an outdated comment. Because the CVSS vector requires local access and [truncated]

MEDIUM Linux CVE published 2026-05-06

CVE-2026-43077

CVE-2026-43077 is a Linux kernel issue in the algif_aead decryption path where the minimum receive-buffer size check did not account for the authentication tag length. The published fix adds the missing extra length so the size check matches decryption requirements. NVD rates the issue as medium severity and lists only availability impact.

HIGH Linux CVE published 2026-05-06

CVE-2026-43076

CVE-2026-43076 is a Linux kernel OCFS2 inode-validation bug. When the kernel reads an inode from disk, ocfs2_validate_inode_block() did not verify that inline data i_size stayed within the actual inline data capacity (id_count). On a corrupted filesystem, that mismatch can let directory iteration walk past the inline buffer and reach freed memory, resulting in a use-after-free in the directory-entry validation path.

HIGH Linux CVE published 2026-05-06

CVE-2026-43075

CVE-2026-43075 is a Linux kernel OCFS2 flaw in inline-data write handling. The issue occurs because the filesystem code trusted the on-disk id_count field too far: on a corrupted OCFS2 filesystem, an oversized id_count can make ocfs2_write_end_inline write past the inode block buffer, which KASAN reports as a use-after-free style write into an adjacent freed page. The referenced fix adds an upper-bound ch [truncated]

HIGH Linux CVE published 2026-05-06

CVE-2026-43074

CVE-2026-43074 is a Linux kernel eventpoll use-after-free in ep_free() where struct eventpoll can be freed while another concurrent thread is still using it. The fix defers the kfree() to an RCU callback to avoid the race. NVD rates the issue HIGH with CVSS 7.8.

MEDIUM Linux CVE published 2026-05-05

CVE-2026-43073

CVE-2026-43073 concerns a Linux kernel x86-64 helper that was misleadingly named and had an awkward interface. The source description says the routine is neither a true user-copy helper nor a non-cached source copy; it is a specialty copy path that uses non-temporal stores for the destination and exception handling for both source and destination accesses. The patch set renames the helper, adjusts its pro [truncated]

MEDIUM Linux CVE published 2026-05-05

CVE-2026-43072

A missing error check in the Linux kernel's DRM VC4 driver allows a negative IRQ error code from platform_get_irq_byname() to be passed directly into devm_request_threaded_irq(), leading to undefined behavior and potential local denial of service. The flaw exists because the return value was treated as valid without verifying it was non-negative. Patches are available for multiple stable kernel branches.

CRITICAL Linux CVE published 2026-05-05

CVE-2026-43071

A critical out-of-bounds (OOB) read vulnerability exists in the Linux kernel's dentry cache (dcache) subsystem, triggered when a user sets the kernel boot parameter `dhash_entries=1`. This configuration causes the dentry hash table to be allocated with only a single bucket. The `d_hash_shift` value is then calculated as 32 by `dcache_init()`. During dentry lookup operations in `__d_lookup()`, the hash ind [truncated]

HIGH Linux CVE published 2026-05-05

CVE-2026-43070

A logic error in the Linux kernel's BPF verifier fails to reset the scalar register ID after BPF_END (byte-swap) operations. When a register that shares a scalar ID with another register undergoes byte-swap mutation, the verifier incorrectly propagates learned bounds to the linked register during conditional jumps. This false confidence in register values can lead to out-of-bounds memory access. The fix e [truncated]

MEDIUM Linux CVE published 2026-05-05

CVE-2026-43069

A missing firmware release call in the Linux kernel's Bluetooth hci_ll driver causes a resource leak when request_firmware() succeeds but returns invalid content. The bug was identified by Smatch static analysis and affects multiple stable kernel branches. Patches have been committed to all supported stable trees.

MEDIUM Linux CVE published 2026-05-05

CVE-2026-43068

CVE-2026-43068 is a Linux kernel ext4 issue where delayed block allocation can fail when the allocator keeps targeting a corrupted block group. The reported symptom is repeated allocation failures followed by ext4 warnings that data may be lost. NVD rates the issue MEDIUM (CVSS 5.5) because it is locally reachable and can disrupt availability.

MEDIUM Linux CVE published 2026-05-05

CVE-2026-43066

CVE-2026-43066 is a medium-severity (CVSS 3.1: 5.5) memory leak vulnerability in the Linux kernel's ext4 filesystem fast-commit replay logic. The flaw exists in ext4_fc_replay_inode(), where ext4_get_fc_inode_loc() acquires a reference to iloc.bh (a buffer head) that must be released via brelse(). Multiple error paths—including failures in ext4_handle_dirty_metadata(), sync_dirty_buffer(), ext4_mark_inode [truncated]