These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in the Linux kernel's ext4 filesystem could allow a local attacker to cause a denial of service condition. The issue occurs when an ext4 filesystem is mounted with the `discard` option, files are deleted (populating the discard work queue), then remounted with `nodiscard`, and subsequently unmounted before queued discard work completes. In this scenario, `ext4_mb_release()` fails to drain [truncated]
A workqueue leak in the Linux kernel's Intel Data Streaming Accelerator (DSA)/Intel Analytics Accelerator (IAA) driver (dmaengine/idxd) can lead to resource exhaustion and local denial of service. When an idxd device is released, its associated workqueue is not freed, causing the leaked workqueue to persist. This flaw affects multiple stable kernel branches and 7.0 release candidates. The vulnerability re [truncated]
A use-after-free vulnerability in the Linux kernel's XFS filesystem recovery code could allow local attackers to cause memory corruption. The flaw exists in xfs_attri_recover_work where an inode reference (irele) is attempted after a failed iget operation, despite xlog_recovery_iget* functions never setting the inode pointer to a valid value on error paths. This results in dereferencing a dangling pointer [truncated]
A type confusion vulnerability in the Linux kernel's Bluetooth L2CAP subsystem causes incorrect handling of Enhanced Credit-Based Flow Control (ECRED) reconfiguration response packets. The `l2cap_ecred_reconf_rsp()` function incorrectly casts incoming data to `struct l2cap_ecred_conn_rsp` (8 bytes) instead of `struct l2cap_ecred_reconf_rsp` (2 bytes). This results in two defects: valid reconfiguration res [truncated]
A DMA TX deadlock vulnerability in the Linux kernel's 8250 serial driver can cause permanent loss of serial transmit functionality. When `dmaengine_terminate_async` cancels a DMA transaction without invoking the `__dma_tx_complete` callback, the `dma->tx_running` flag is never cleared. This prevents scheduling of new TX DMA transactions, effectively halting serial output. The fix clears `dma->tx_running` [truncated]
CVE-2026-43060 is a Linux kernel netfilter issue in nft_ct handling where packets already queued in nfqueue can retain references to objects that may be removed underneath them. The supplied record says the kernel fix is to drop pending enqueued packets on removal so they do not hold stale references to conntrack zone templates, timeout policies, or helper objects.
CVE-2026-43059 is a Linux kernel Bluetooth MGMT memory-safety issue in command completion handling. The flaw can corrupt kernel lists or free pending commands incorrectly, creating a risk of kernel panic and use-after-free conditions.
CVE-2026-43058 is a Linux kernel media/vidtv issue resolved by changing two helper functions to accept const pointers instead of pass-by-value structs. The source says the previous calling convention copied struct contents, including MemorySanitizer shadow and origin metadata, which could trigger uninitialized-value warnings. The published CVE record is dated 2026-05-02 and was modified on 2026-05-06.
CVE-2026-43019 is a HIGH-severity vulnerability in the Linux kernel, specifically affecting the Bluetooth HCI connection handling. The vulnerability has a CVSS score of 7.8 and was published on May 1, 2026. It involves a potential Use-After-Free (UAF) issue in the `set_cig_params_sync` function, which can lead to concurrent deletion or modification of `hci_conn` objects. This vulnerability requires local [truncated]
CVE-2026-31779 is a Linux kernel vulnerability in the iwlwifi mvm path where insufficient length validation around a memcpy can let results->matches pick up unwanted data. NVD classifies it as CWE-125 and rates it 8.1 High, with adjacent-network attack conditions and no privileges or user interaction required. The issue was found by the Linux Verification Center (linuxtesting.org) with SVACE, and NVD list [truncated]
CVE-2026-31778 is a Linux kernel ALSA caiaq bug that can turn a shortname copy into a stack out-of-bounds read. The flaw comes from a bounds check that allowed a 16-byte local buffer to be filled without room for the terminating NUL, so later string handling in snd_card_set_id() can read past the stack buffer. NVD rates the issue HIGH, with local attack requirements and potential for information disclosur [truncated]
CVE-2026-31771 is a Linux kernel Bluetooth vulnerability in HCI event processing. The issue was published on 2026-05-01 and updated on 2026-05-11, with fixes referenced in the NVD record and Linux kernel stable patches. The bug allowed wake-reason storage to run before per-event length validation, so a short HCI event frame could reach a memory-copy path before bounds checks completed. The fix moves wake- [truncated]
CVE-2026-31770 is a Linux kernel availability issue in the hwmon occ driver. A missing zero-check in occ_show_power_1() can divide by update_tag before any samples have been collected, which can trigger a kernel crash during early boot or similar zero-sample states. The issue is rated medium severity and affects supported kernel release lines until the fixed stable releases noted by NVD.
CVE-2026-31769 is a Linux kernel use-after-free in the GPIB ioctl path. A low-privileged local attacker can race IBRD, IBWRT, IBCMD, or IBWAIT against IBCLOSEDEV so that a gpib_descriptor is freed after big_gpib_mutex is released but before the handler finishes using it. NVD rates the issue HIGH, with high confidentiality, integrity, and availability impact, and kernel fixes add a descriptor_busy referenc [truncated]
CVE-2026-31767 is a Linux kernel DRM/i915 issue in DSI command mode where DSC-related horizontal timing adjustments could shrink timing values enough to trigger a division-by-zero while calculating vtotal. NVD rates it CVSS 5.5 (MEDIUM) with a local, low-privilege availability impact. The fix stops applying those horizontal timing adjustments in command mode and is referenced by multiple stable kernel patch links.
CVE-2026-31766 is a Linux kernel AMDGPU flaw in user queue creation where a user-controlled doorbell_offset could be used without bounds checking. The kernel patch validates that the offset stays within the allocated doorbell buffer object before computing the BAR doorbell index, using u64 arithmetic to avoid overflow. This reduces the risk of out-of-range doorbell indexing and potential corruption of ker [truncated]
CVE-2026-31765 is a Linux kernel amdgpu/KFD availability issue that can crash affected systems, especially on 64KB page-size configurations. The problem is a size mismatch between the reserved GPU trap area and the KFD CWSR TBA/TMA allocation: the reserved space was hardcoded at 8KB while the allocation could grow to 128KB on 64KB-page systems. NVD rates the issue as local, low-complexity, low-privilege, [truncated]
The Linux kernel has a vulnerability in the gpiochip_add_data_with_key() function, which can cause resource leaks on errors. This issue was introduced by a commit that unset the release function for the device. As a result, the reference count to the device isn't dropped on error handling paths, leading to potential resource leaks. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. Linux [truncated]
CVE-2026-31718 is a critical Linux kernel vulnerability in ksmbd, the SMB server component. The issue is a use-after-free in durable file handle cleanup: when a durable handle survives disconnect, the file pointer’s connection reference can be cleared while associated lock-list state is left behind. Later cleanup in the durable scavenger can dereference the freed connection object, causing memory corrupti [truncated]
CVE-2026-31715 is a Linux kernel F2FS bug where concurrent writeback completion and unmount can race in a way that leaves sbi->node_inode NULL before f2fs_in_warm_node_list() checks it. The result is a NULL pointer dereference / panic and a use-after-free class flaw mapped by NVD to CWE-416. NVD rates the issue 7.8 HIGH and describes it as locally reachable with low privileges and no user interaction. The [truncated]
CVE-2026-31712 is a Linux kernel ksmbd issue where permission checking of stored DACL entries accepted ACEs that were too small for the fields later read. An authenticated SMB client with the ability to set an ACL on a file could trigger the bug on a later CREATE against that file, leading to an out-of-bounds read and possible KASAN reports or kernel state corruption.
A vulnerability in the Linux kernel has been resolved, affecting SMB1 UNIX mounts. The issue arises from the incorrect dir separator used in paths due to the missing CIFS_MOUNT_POSIX_PATHS bit in cifs_sb_info::mnt_cifs_flags. This could lead to unexpected behavior when handling directory paths. The vulnerability was introduced due to the incorrect handling of cifs_sb->mnt_cifs_flags in cifs_mount_get_tcon [truncated]
CVE-2026-31709 is a Linux kernel SMB/CIFS client vulnerability involving incomplete validation of server-supplied DACL data before chmod/chown security-descriptor rewriting. NVD rates it 8.8 HIGH, and the published record indicates Linux kernel versions from 5.12 through before 7.0.2 are affected.
Integer overflow vulnerabilities in ksmbd's IPC message validation allow local attackers to bypass size checks and trigger out-of-bounds memory operations. The ksmbd kernel module computes expected message sizes using attacker-controlled fields from daemon responses without proper overflow detection. Three code paths are affected: RPC request handling adds payload_sz to struct size; share config request h [truncated]
CVE-2026-31431 is a Linux Kernel vulnerability described as an incorrect resource transfer between spheres. It carries a CVSS score of 7.8 (HIGH) and was added to CISA’s Known Exploited Vulnerabilities catalog on 2026-05-01, which raises its defensive priority. The supplied corpus does not provide deeper technical root-cause detail, so the safest response is to rely on vendor guidance and the official CVE [truncated]
A high-severity vulnerability has been resolved in the Linux kernel, affecting various versions. The issue relates to the xfrm component, where a device reference is incorrectly released, potentially leading to a use-after-free condition. This could allow attackers to access sensitive information or execute arbitrary code. Linux kernel maintainers and users should prioritize patching affected systems, esp [truncated]
The Linux kernel has a vulnerability in the rxrpc module, specifically in the rxrpc_preparse_xdr_yfs_rxgk() function. This function is responsible for loading RxGK tokens. The vulnerability occurs when the function reads raw key and ticket lengths from the XDR token as u32 values and passes them through round_up(x, 4) before validation and allocation. If the raw length is >= 0xfffffffd, round_up() wraps t [truncated]
CVE-2026-31635 is a Linux kernel rxrpc issue in which RESPONSE authenticator length validation is inverted. According to the supplied CVE text, oversized authenticators can be accepted by rxgk_verify_response(), passed into rxgk_decrypt_skb(), and eventually reach skb_to_sgvec() with an impossible length, triggering BUG_ON(len) and a kernel crash. NVD records the issue as HIGH severity (CVSS 7.5) with net [truncated]
A memory leak vulnerability was found in the Linux kernel's ksmbd component. The vulnerability occurs when the SPNEGO decode fails after token allocation, causing a memory leak. This could allow an untrusted client to cause a slow memory leak on a server without proper authentication. The vulnerability is caused by the ksmbd component not properly freeing the memory allocated for the mechToken when the SP [truncated]
A vulnerability in the Linux kernel's clock events subsystem could cause system stalls due to timer interrupt starvation. The issue stems from the `next_event_forced` flag not being reset in three specific scenarios: when the clock event state changes (potentially leaving the flag stale across shutdown/startup sequences), when a non-forced event is armed (preventing rearming and causing missed interrupts [truncated]