These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-31511 is a Linux kernel Bluetooth MGMT memory-safety issue where an incorrect status check could let mgmt_pending_free() free a command object without first unlinking it from the pending list. That leaves a dangling pointer behind, and later list walks can dereference freed memory. NVD rates the issue HIGH (CVSS 3.1: 7.8) with local, low-privilege conditions and high impact to confidentiality, in [truncated]
The Linux kernel has a vulnerability, CVE-2026-31502, which is a type confusion issue in the team module. This vulnerability can cause a crash when the team device calls dev_hard_header() or dev_parse_header() with the wrong private type. The issue arises from the team module's incorrect handling of header_ops for non-Ethernet ports. The fix introduces team header_ops wrappers for create/parse, selecting [truncated]
CVE-2026-31489 is a Linux kernel vulnerability in the spi: meson-spicc driver’s teardown path. According to the published description, meson_spicc_probe() registers the controller with devm_spi_register_controller(), so device-managed cleanup already drops the controller reference. A second spi_controller_put() in meson_spicc_remove() creates a double-put condition, which is the basis for the CWE-415 clas [truncated]
CVE-2026-31488 is a Linux kernel AMDGPU DRM display flaw in DSC validation. When DSC pre-validation decides a stream has no timing change, it can incorrectly clear the CRTC mode_changed flag even if another unrelated mode change is happening in the same KMS commit. That can leave the old stream unreleased and the new stream unreferenced, which the kernel report describes as a memory leak followed by a pot [truncated]
A race condition in the Linux kernel's PMBus hardware monitoring subsystem could allow local attackers to cause integrity and availability impacts. The vulnerability exists because PMBus regulator operations accessed shared registers and data without mutex protection. The fix introduces mutex protection for voltage operations while avoiding deadlock through a deferred notification worker that processes ev [truncated]
A denial-of-service vulnerability in the Linux kernel's ksmbd SMB server allows remote attackers to invalidate arbitrary active sessions by sending a multichannel session binding request with an incorrect password. The error path unconditionally sets the target session state to SMB2_SESSION_EXPIRED, even though the session belongs to another connection's user. The fix skips session expiration when the fai [truncated]
CVE-2026-31474 is a high-severity vulnerability in the Linux kernel, with a CVSS score of 7.8. This use-after-free vulnerability affects the CAN isotp subsystem, specifically in the isotp_sendmsg() function. The vulnerability occurs when a signal interrupts the wait_event_interruptible() function inside the close() system call, causing the kfree() of the tx.buf to be executed while the sendmsg() function [truncated]
A vulnerability was found in the Linux kernel, specifically in the DAMON (Data Access Monitoring) subsystem. The issue arises from a missing check for the 'nr' field in the 'contexts' structure, which can lead to a NULL pointer dereference when certain functions are called. This vulnerability can be exploited by setting 'nr_contexts' to 0 via sysfs while DAMON is running, causing the functions to derefere [truncated]
A race condition vulnerability was discovered in the Linux kernel, specifically in the `walk_pud_range()` function. This vulnerability occurs when a PUD entry is being split concurrently with a refault operation on the PUD leaf entry. This can lead to a kernel BUG and potentially allow an attacker to crash the system. The vulnerability has a CVSS score of 4.7 and is classified as MEDIUM severity.
A vulnerability has been resolved in the Linux kernel, specifically in the xfs module. The vulnerability is related to the unmount sequence in xfs_unmount_flush_inodes(), where the AIL (Active Inode List) is pushed while background reclaim and inodegc are still running. This can cause issues as inodegc can dirty and insert inodes into the AIL during the flush, and background reclaim can race to abort and [truncated]
CVE-2026-31449 is a Linux kernel ext4 flaw in extent index correction logic. A missing bounds check on an extent-tree index pointer can let corrupted on-disk metadata drive an out-of-bounds read, which NVD rates as CVSS 7.8 HIGH.
CVE-2026-31440 is a Linux kernel availability issue in the dmaengine idxd driver. NVD describes a memory leak in event log handling during device removal: if the device is reset first, configuration registers return to default zero values, and the driver's pre-free check can fail, leaving event log memory undeallocated. The published fix removes that fragile support check and relies on the event-log alloc [truncated]
A logic error in the Linux kernel's Intel Data Streaming Accelerator (IDXD) DMA engine driver can cause NULL pointer dereferences, double completion, or descriptor leaks during descriptor abort operations. The vulnerability exists in the `llist_abort_desc()` function where the traversal cursor `d` is used for iteration, but the wrong variable `found` is passed to the completion routine. This affects kerne [truncated]
CVE-2026-31434 is a Linux kernel Btrfs issue where cleanup for sub-group space_info objects can skip the matching sysfs removal path, leaking kobject name memory. The flaw is a memory leak rather than a direct integrity issue, but it can still matter on systems that repeatedly exercise the affected Btrfs path. NVD rates it medium severity (CVSS 5.5) and the record maps it to a local-privileged attack scen [truncated]
CVE-2026-31433 is a Linux kernel ksmbd issue in FILE_ALL_INFORMATION handling for compound SMB requests. According to the published description, a QUERY_DIRECTORY followed by QUERY_INFO can leave too little room in the response buffer, yet get_file_all_info() still attempted to convert and copy the filename as if PATH_MAX space were available. That can lead to an out-of-bounds write and potential memory c [truncated]
CVE-2026-31432 is a Linux kernel ksmbd memory-safety issue in QUERY_INFO handling for compound SMB requests. If READ consumes most of the response buffer, ksmbd could overrun the allocated space while building a security descriptor. The published fix tightens size calculation and buffer checks before allocation and pinning.
CVE-2026-31429 is a Linux kernel vulnerability in the skb head free path. When KFENCE is enabled, exact-size reporting from kfence_ksize() can make skb_kfree_head() misidentify a KMALLOC-allocated skb head as coming from skb_small_head_cache. That can lead to a cross-cache free and slab corruption symptoms. The fix is to always free the head with kfree(), avoiding allocator-specific misclassification.
CVE-2026-31425 is a Linux kernel availability issue in the RDS over InfiniBand path. On a fresh outgoing connection, the code can reach FRMR memory registration before the RDMA connection is fully established, which can lead to a null pointer dereference and kernel crash. NVD rates the issue MEDIUM with local attack requirements and high availability impact. The issue was published on 2026-04-13 and updat [truncated]
CVE-2026-31419 is a Linux kernel bonding flaw in the broadcast transmit path. A race in bond_xmit_broadcast() could cause the original skb to be reused for the wrong slave and then double-consumed, leading to a use-after-free. The supplied record includes a KASAN crash in skb_clone and official patch references that replace the racy last-slave check with a stable index-based comparison.
CVE-2026-31413 is a Linux kernel BPF verifier bug in maybe_fork_scalars() that can fork verifier state incorrectly for BPF_OR when the source operand is constant. The result is a verifier/runtime mismatch that can permit out-of-bounds map access. NVD rates the issue HIGH (CVSS 7.8) and lists patches for affected stable kernel lines.
CVE-2026-31412 is a Linux kernel issue in the USB gadget mass-storage function (`f_mass_storage`). The vulnerable path calculates a command data size by left shifting `common->data_size_from_cmnd` by the logical block size without first checking for overflow. According to the published fix notes, a large SCSI READ or WRITE request can cause the shifted size to wrap, which may truncate boundary calculation [truncated]
CVE-2026-31410 is a Linux kernel ksmbd issue in the way FS_OBJECT_ID_INFORMATION is populated. The fix changes ksmbd to use the filesystem UUID from sb->s_uuid as the primary volume identifier, and to fall back to the statfs filesystem ID only when a UUID is unavailable. NVD rates the issue CVSS 5.5 (MEDIUM) with local attack prerequisites and high availability impact.
CVE-2026-31409 is a Linux kernel ksmbd issue in SMB multichannel session handling. According to the CVE/NVD record, a failed SMB2_SESSION_SETUP request with SMB2_SESSION_REQ_FLAG_BINDING could leave the connection marked as binding, which changes later session lookup behavior until the state is corrected. The published fix clears conn->binding on the error path. NVD lists the vulnerability as analyzed and [truncated]
CVE-2026-31408 is a high-severity Linux kernel memory-safety issue in Bluetooth SCO handling. The bug is a use-after-free in sco_recv_frame(): it reads conn->sk while holding sco_conn_lock(), but then releases the lock without first taking a socket reference. A concurrent close() can free the socket before the later sk->sk_state access. The fix is to hold the socket safely before unlocking and to drop the [truncated]
CVE-2026-31405 is a critical Linux kernel media/dvb-net memory-safety issue. Network-controlled ULE extension data can produce htype values from 0-255, but the handler tables are sized for valid indices 0-254. When htype is 255, the kernel can read past the end of the function-pointer table, and the out-of-bounds value may be invoked as a function pointer. The published fix adds a bounds check and discard [truncated]
CVE-2026-31404 is a Linux kernel NFSD memory-safety issue in export and expkey cleanup. The problem is that svc_export_put() could drop path_put() and auth_domain_put() immediately when the last reference vanished, even though RCU readers in e_show() and c_show() may still be accessing ex_path and ex_client->name. If cache_clean removed the entry at the wrong time, those sub-objects could be freed while s [truncated]
CVE-2026-31401 is a Linux kernel HID-BPF buffer overflow issue in hid_hw_request. Per the CVE description, the code assumes the returned value is always valid, but dispatch_hid_bpf_raw_requests() can return an arbitrarily large value through struct_ops, creating an unchecked size condition that can overflow a buffer. NVD assigns CVSS 7.8 (HIGH) with local, low-complexity, low-privilege impact and lists af [truncated]
CVE-2026-31400 is a Linux kernel sunrpc memory-leak issue in cache_release(). If a reader closes its file descriptor while mid-read, the request can lose a reader without being freed, leaving the cache_request, its buffer, and cache_head reference behind. NVD assigns a medium CVSS score and lists the issue as affecting multiple Linux kernel release lines.
CVE-2026-31399 is a Linux kernel use-after-free in nvdimm/bus asynchronous initialization. According to the supplied record, the bug can occur when device_add() fails during nd_async_device_register(), causing the parent reference handling to reach a freed object. NVD assigns CVSS 7.8 and lists the issue as locally exploitable with high impacts to confidentiality, integrity, and availability.
CVE-2026-31398 is a Linux kernel mm/rmap flaw in lazyfree folio PTE restoration. When anonymous lazyfree folios are unmapped in batches, a mix of writable and non-writable entries can be restored as writable, and soft-dirty state may also be lost. The supplied report shows this can violate anonymous memory/CoW semantics and trigger a page_table_check BUG_ON during reclaim, crashing affected kernels.