PatchSiren

Linux CVE debriefs · Page 109

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-04-03

CVE-2026-31397

CVE-2026-31397 affects the Linux kernel’s huge-page migration path. The bug is in move_pages_huge_pmd(), where handling of huge zero pages could either pass a NULL folio into PMD construction or rebuild a destination PMD in a way that drops special PMD state. Depending on memory configuration, this can result in a NULL dereference or a bogus PMD entry that points at non-existent physical memory and can co [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-31395

CVE-2026-31395 is a Linux kernel vulnerability in the bnxt_en driver’s async event handling path. A firmware-supplied trace type is used as an array index without bounds checking, which can lead to out-of-bounds kernel memory access, corruption, or a crash. NVD rates the issue HIGH (7.1) and lists affected Linux kernel ranges including 6.13 through 6.18.20, 6.19 through 6.19.10, and early 7.0 release candidates.

MEDIUM Linux CVE published 2026-04-03

CVE-2026-31394

CVE-2026-31394 is a Linux kernel mac80211 vulnerability that can crash the system during channel bandwidth changes. The bug affects AP_VLAN stations because ieee80211_chan_bw_change() follows sta->sdata->link[...] even when the VLAN sdata does not participate in chanctx reservations, leaving a NULL chan pointer that can be dereferenced in __ieee80211_sta_cap_rx_bw(). The result is a denial-of-service cond [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-31393

A vulnerability in the Linux kernel's Bluetooth L2CAP subsystem allows out-of-bounds reads when processing malformed L2CAP_INFO_RSP packets. The l2cap_information_rsp() function validates that the command length covers the fixed 4-byte header but fails to verify payload presence before accessing rsp->data. For L2CAP_IT_FEAT_MASK, this results in a 4-byte overread; for L2CAP_IT_FIXED_CHAN, a 1-byte overrea [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-31392

A session reuse flaw in the Linux kernel SMB client (CIFS) allows Kerberos-authenticated mounts to incorrectly reuse SMB sessions from prior mounts, even when a different username= option is specified. This can cause unauthorized access to shares using credentials from a previous mount, or cause mount failures when the wrong principal is used. The vulnerability exists because match_session() did not consi [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-31390

A memory leak vulnerability exists in the Linux kernel's Intel Xe graphics driver (drm/xe). The flaw occurs in the xe_vm_madvise_ioctl function, where allocated resources are not properly freed when the check_bo_args_are_sane() validation fails. This leads to resource exhaustion over time, potentially causing denial of service conditions on affected systems. The vulnerability is classified as CWE-401 (Mis [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23472

A vulnerability in the Linux kernel's serial core subsystem could cause system hangs via infinite loops when drivers interact with improperly initialized serial ports. The issue stems from inconsistent behavior between uart_write_room() and uart_write() when the transmit buffer (xmit_buf) is NULL—a condition occurring with PORT_UNKNOWN ports that were never properly initialized. Specifically, uart_write_r [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23470

A deadlock vulnerability exists in the Linux kernel's drm/imagination driver soft reset sequence. The issue occurs because the soft reset is executed from a threaded IRQ handler, which calls disable_irq()—this internally waits for IRQ handlers to complete, causing the handler to wait for itself. The fix replaces disable_irq() with disable_irq_nosync() to prevent this self-deadlock condition. This is a loc [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23469

A race condition in the Linux kernel's Imagination DRM driver can cause kernel panics when the GPU enters runtime power management suspend while an interrupt handler is active on another CPU core. The vulnerability stems from the runtime PM suspend callback failing to synchronize with in-progress IRQ handlers before powering down the GPU. When this race occurs, the IRQ handler may attempt to access GPU re [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23467

A NULL pointer dereference vulnerability exists in the Linux kernel's Intel i915 graphics driver, specifically within the Display Micro-Controller (DMC) subsystem. The flaw occurs in `intel_dmc_update_dc6_allowed_count()` when called before DMC initialization completes, causing a kernel oops. The vulnerable code path is triggered during probe when `intel_power_domains_init_hw()` executes prior to `intel_d [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23466

CVE-2026-23466 affects the Linux kernel's drm/xe path for GGTT MMIO access protection. The issue is that hotplug-based protection can be insufficient when driver load fails, and teardown can race with asynchronously freed buffer objects, leaving MMIO access enabled longer than intended. The supplied kernel fix introduces an explicit flag, protected by the GGTT lock, and clears it during dev_fini_ggtt so M [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23462

CVE-2026-23462 is a Linux kernel Bluetooth HIDP use-after-free issue. The NVD record says the bug was fixed after a missing l2cap_conn reference drop when the user->remove callback is invoked, which can leave a stale connection object reachable during Bluetooth teardown. NVD rates the issue HIGH with CVSS 8.8 and lists broad kernel version coverage across multiple stable branches and early 7.0 release candidates.

HIGH Linux CVE published 2026-04-03

CVE-2026-23461

CVE-2026-23461 is a Linux kernel Bluetooth L2CAP concurrency flaw that can trigger use-after-free and list corruption in conn->users / hchan handling. NVD rates the issue HIGH (CVSS 8.8) with adjacent-network attack conditions, and the record ties it to CWE-416. The published fix moves l2cap_register_user() and l2cap_unregister_user() to conn->lock for consistent synchronization with l2cap_conn_del().

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23460

A NULL pointer dereference vulnerability exists in the Linux kernel's ROSE (Radio Amateur Packet X.25 PLP) protocol implementation. The flaw occurs in `rose_connect()` when a second connection attempt is made while a previous connection is still in progress (TCP_SYN_SENT state). Under these conditions, the function overwrites `rose->neighbour` without checking if the new neighbor lookup returns NULL, leav [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23459

A vulnerability in the Linux kernel's IP tunneling subsystem could cause system instability or corruption on 32-bit architectures. The `iptunnel_xmit_stats()` function incorrectly assumed all tunnels use `NETDEV_PCPU_STAT_TSTATS`, but VXLAN and GENEVE tunnels use `NETDEV_PCPU_STAT_DSTATS`. The `@syncp` offset differs between `pcpu_sw_netstats` and `pcpu_dstats` structures. On 32-bit kernels, this offset m [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23453

A memory leak vulnerability exists in the Texas Instruments ICSSG PRU Ethernet driver (icssg-prueth) within the Linux kernel. The flaw occurs in the XDP_DROP path when operating in non-zero-copy mode (standard page pool mode). A previous change removed page recycling from emac_run_xdp() to avoid conflicts with AF_XDP zero-copy mode, which uses xsk_buff_free() for cleanup. However, this removal inadvertent [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23451

CVE-2026-23451 is a Linux kernel bonding bug that could trigger an infinite loop in bond_header_parse() when two bonding devices are stacked. The issue is an availability problem: the parser can recurse without a bounded leaf device context because skb->dev points at the top of the hierarchy. The kernel fix adds a const struct net_device *dev parameter to the header_ops->parse() path so recursion is bound [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23448

CVE-2026-23448 is a Linux kernel bug in the usb:cdc_ncm receive path. The NDP16 verifier correctly checked the NDP header against the skb length using ndpoffset, but it did not include ndpoffset when validating the DPE array size. As a result, when the NDP is positioned near the end of the NTB, the DPE entries can extend past the skb buffer and cdc_ncm_rx_fixup() may read out of bounds while iterating the [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23447

Linux kernel vulnerability in net: usb: cdc_ncm allows out-of-bounds reads due to improper bounds checking, patched in multiple commits. The vulnerability has been resolved with additional checks and validation to prevent potential exploitation. This patch addresses the issue by adding ndpoffset to NDP32 nframes bounds check and expressing the NDP-plus-DPE-array size more clearly with struct_size_t(). The [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23445

A vulnerability in the Linux kernel's igc driver has been identified, which can cause a page fault when handling XDP TX timestamps. This issue arises when an XDP application requesting TX timestamping shuts down while the interface link remains up, leaving behind stale xsk_meta pointers that the IRQ handler attempts to access. The problem has been addressed by cleaning up the stale xsk meta data on TX shu [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23444

A memory leak vulnerability in the Linux kernel's mac80211 wireless subsystem could allow a local attacker to cause resource exhaustion. The flaw exists in ieee80211_tx_prepare_skb() where one of three error paths failed to free an sk_buff (socket buffer), leading to inconsistent memory handling. The fix ensures all error paths uniformly free the skb and removes redundant frees in callers (ath9k, mt76, ma [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23443

A use-after-free vulnerability was found in the Linux kernel. After a previous fix for acpi_processor_errata_piix4(), device pointers may be dereferenced after dropping references to the device objects pointed to by them, which may cause a use-after-free to occur. Moreover, debug messages about enabling the errata may be printed if the errata flags corresponding to them are unset. Address all of these iss [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23442

A NULL pointer dereference vulnerability exists in the Linux kernel's IPv6 Segment Routing (SRv6) implementation. The function `__in6_dev_get()` can return NULL when a network device lacks IPv6 configuration, such as when the MTU is below `IPV6_MIN_MTU` or during `NETDEV_UNREGISTER` processing. Two SRv6 code paths—`seg6_hmac_validate_skb()` and `ipv6_srh_rcv()`—failed to validate the returned `idev` point [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23441

A race condition exists in the Linux kernel's net/mlx5e due to concurrent access to IPSec ASO context. The driver uses a single mlx5e_ipsec_aso struct for each PF, containing a shared DMA-mapped context for all ASO operations. A second operation can overwrite the shared context before the first operation's completion is processed, leading to unexpected behavior. This vulnerability affects Linux kernel ver [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23440

A race condition exists in the Linux kernel's handling of IPSec ESN updates in full offload mode. The device reports an ESN wrap event to the driver, which validates the event and then updates the kernel's xfrm state. However, the driver temporarily releases and re-acquires the xfrm state lock, allowing the event to be processed twice. This causes the ESN high-order bits to be incremented incorrectly, lea [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23437

The Linux kernel was vulnerable to a use-after-free condition in the shaper netdev component. A fix has been applied to the stable kernel branches. This vulnerability could potentially allow attackers to exploit the system, leading to crashes or code execution. Users of affected kernel versions should take immediate action to patch their systems. The vulnerability was introduced due to improper handling o [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23436

The Linux kernel was vulnerable to a race condition in the shaper component, allowing for potential hierarchy leaks. The vulnerability has been resolved through patches. Affected users should apply patches to mitigate this vulnerability. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. The vulnerability was resolved by taking the instance lock in pre-callbacks, preventing the netdev fro [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23435

A Linux kernel vulnerability, CVE-2026-23435, was found in the x86_pmu_enable() function. The flaw occurs when handling perf events, leading to a NULL pointer dereference. This happens because the event pointer is not properly set up before being used. The vulnerability was introduced by a commit that moved the cpuc->events[idx] assignment out of x86_pmu_start() and into step 2 of x86_pmu_enable(), after [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23433

CVE-2026-23433 is a MEDIUM severity vulnerability in the Linux kernel, specifically in the arm_mpam component. The vulnerability occurs when an MSC supporting memory bandwidth monitoring is brought offline and then online, causing a null pointer dereference when restoring bandwidth counters. This issue can lead to a kernel oops with a call trace. The vulnerability is resolved by providing a local variable [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23431

A memory leak vulnerability was found in the Linux kernel's spi: amlogic-spisg component. The vulnerability occurs when the driver fails to call spi_controller_put() in several error paths, leading to a memory leak. This issue has been resolved by converting to use devm_spi_alloc_host()/devm_spi_alloc_target(). Linux kernel users and administrators should be aware of this vulnerability and take steps to e [truncated]