These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-31397 affects the Linux kernel’s huge-page migration path. The bug is in move_pages_huge_pmd(), where handling of huge zero pages could either pass a NULL folio into PMD construction or rebuild a destination PMD in a way that drops special PMD state. Depending on memory configuration, this can result in a NULL dereference or a bogus PMD entry that points at non-existent physical memory and can co [truncated]
CVE-2026-31395 is a Linux kernel vulnerability in the bnxt_en driver’s async event handling path. A firmware-supplied trace type is used as an array index without bounds checking, which can lead to out-of-bounds kernel memory access, corruption, or a crash. NVD rates the issue HIGH (7.1) and lists affected Linux kernel ranges including 6.13 through 6.18.20, 6.19 through 6.19.10, and early 7.0 release candidates.
CVE-2026-31394 is a Linux kernel mac80211 vulnerability that can crash the system during channel bandwidth changes. The bug affects AP_VLAN stations because ieee80211_chan_bw_change() follows sta->sdata->link[...] even when the VLAN sdata does not participate in chanctx reservations, leaving a NULL chan pointer that can be dereferenced in __ieee80211_sta_cap_rx_bw(). The result is a denial-of-service cond [truncated]
A vulnerability in the Linux kernel's Bluetooth L2CAP subsystem allows out-of-bounds reads when processing malformed L2CAP_INFO_RSP packets. The l2cap_information_rsp() function validates that the command length covers the fixed 4-byte header but fails to verify payload presence before accessing rsp->data. For L2CAP_IT_FEAT_MASK, this results in a 4-byte overread; for L2CAP_IT_FIXED_CHAN, a 1-byte overrea [truncated]
A session reuse flaw in the Linux kernel SMB client (CIFS) allows Kerberos-authenticated mounts to incorrectly reuse SMB sessions from prior mounts, even when a different username= option is specified. This can cause unauthorized access to shares using credentials from a previous mount, or cause mount failures when the wrong principal is used. The vulnerability exists because match_session() did not consi [truncated]
A memory leak vulnerability exists in the Linux kernel's Intel Xe graphics driver (drm/xe). The flaw occurs in the xe_vm_madvise_ioctl function, where allocated resources are not properly freed when the check_bo_args_are_sane() validation fails. This leads to resource exhaustion over time, potentially causing denial of service conditions on affected systems. The vulnerability is classified as CWE-401 (Mis [truncated]
A vulnerability in the Linux kernel's serial core subsystem could cause system hangs via infinite loops when drivers interact with improperly initialized serial ports. The issue stems from inconsistent behavior between uart_write_room() and uart_write() when the transmit buffer (xmit_buf) is NULL—a condition occurring with PORT_UNKNOWN ports that were never properly initialized. Specifically, uart_write_r [truncated]
A deadlock vulnerability exists in the Linux kernel's drm/imagination driver soft reset sequence. The issue occurs because the soft reset is executed from a threaded IRQ handler, which calls disable_irq()—this internally waits for IRQ handlers to complete, causing the handler to wait for itself. The fix replaces disable_irq() with disable_irq_nosync() to prevent this self-deadlock condition. This is a loc [truncated]
A race condition in the Linux kernel's Imagination DRM driver can cause kernel panics when the GPU enters runtime power management suspend while an interrupt handler is active on another CPU core. The vulnerability stems from the runtime PM suspend callback failing to synchronize with in-progress IRQ handlers before powering down the GPU. When this race occurs, the IRQ handler may attempt to access GPU re [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's Intel i915 graphics driver, specifically within the Display Micro-Controller (DMC) subsystem. The flaw occurs in `intel_dmc_update_dc6_allowed_count()` when called before DMC initialization completes, causing a kernel oops. The vulnerable code path is triggered during probe when `intel_power_domains_init_hw()` executes prior to `intel_d [truncated]
CVE-2026-23466 affects the Linux kernel's drm/xe path for GGTT MMIO access protection. The issue is that hotplug-based protection can be insufficient when driver load fails, and teardown can race with asynchronously freed buffer objects, leaving MMIO access enabled longer than intended. The supplied kernel fix introduces an explicit flag, protected by the GGTT lock, and clears it during dev_fini_ggtt so M [truncated]
CVE-2026-23462 is a Linux kernel Bluetooth HIDP use-after-free issue. The NVD record says the bug was fixed after a missing l2cap_conn reference drop when the user->remove callback is invoked, which can leave a stale connection object reachable during Bluetooth teardown. NVD rates the issue HIGH with CVSS 8.8 and lists broad kernel version coverage across multiple stable branches and early 7.0 release candidates.
CVE-2026-23461 is a Linux kernel Bluetooth L2CAP concurrency flaw that can trigger use-after-free and list corruption in conn->users / hchan handling. NVD rates the issue HIGH (CVSS 8.8) with adjacent-network attack conditions, and the record ties it to CWE-416. The published fix moves l2cap_register_user() and l2cap_unregister_user() to conn->lock for consistent synchronization with l2cap_conn_del().
A NULL pointer dereference vulnerability exists in the Linux kernel's ROSE (Radio Amateur Packet X.25 PLP) protocol implementation. The flaw occurs in `rose_connect()` when a second connection attempt is made while a previous connection is still in progress (TCP_SYN_SENT state). Under these conditions, the function overwrites `rose->neighbour` without checking if the new neighbor lookup returns NULL, leav [truncated]
A vulnerability in the Linux kernel's IP tunneling subsystem could cause system instability or corruption on 32-bit architectures. The `iptunnel_xmit_stats()` function incorrectly assumed all tunnels use `NETDEV_PCPU_STAT_TSTATS`, but VXLAN and GENEVE tunnels use `NETDEV_PCPU_STAT_DSTATS`. The `@syncp` offset differs between `pcpu_sw_netstats` and `pcpu_dstats` structures. On 32-bit kernels, this offset m [truncated]
A memory leak vulnerability exists in the Texas Instruments ICSSG PRU Ethernet driver (icssg-prueth) within the Linux kernel. The flaw occurs in the XDP_DROP path when operating in non-zero-copy mode (standard page pool mode). A previous change removed page recycling from emac_run_xdp() to avoid conflicts with AF_XDP zero-copy mode, which uses xsk_buff_free() for cleanup. However, this removal inadvertent [truncated]
CVE-2026-23451 is a Linux kernel bonding bug that could trigger an infinite loop in bond_header_parse() when two bonding devices are stacked. The issue is an availability problem: the parser can recurse without a bounded leaf device context because skb->dev points at the top of the hierarchy. The kernel fix adds a const struct net_device *dev parameter to the header_ops->parse() path so recursion is bound [truncated]
CVE-2026-23448 is a Linux kernel bug in the usb:cdc_ncm receive path. The NDP16 verifier correctly checked the NDP header against the skb length using ndpoffset, but it did not include ndpoffset when validating the DPE array size. As a result, when the NDP is positioned near the end of the NTB, the DPE entries can extend past the skb buffer and cdc_ncm_rx_fixup() may read out of bounds while iterating the [truncated]
Linux kernel vulnerability in net: usb: cdc_ncm allows out-of-bounds reads due to improper bounds checking, patched in multiple commits. The vulnerability has been resolved with additional checks and validation to prevent potential exploitation. This patch addresses the issue by adding ndpoffset to NDP32 nframes bounds check and expressing the NDP-plus-DPE-array size more clearly with struct_size_t(). The [truncated]
A vulnerability in the Linux kernel's igc driver has been identified, which can cause a page fault when handling XDP TX timestamps. This issue arises when an XDP application requesting TX timestamping shuts down while the interface link remains up, leaving behind stale xsk_meta pointers that the IRQ handler attempts to access. The problem has been addressed by cleaning up the stale xsk meta data on TX shu [truncated]
A memory leak vulnerability in the Linux kernel's mac80211 wireless subsystem could allow a local attacker to cause resource exhaustion. The flaw exists in ieee80211_tx_prepare_skb() where one of three error paths failed to free an sk_buff (socket buffer), leading to inconsistent memory handling. The fix ensures all error paths uniformly free the skb and removes redundant frees in callers (ath9k, mt76, ma [truncated]
A use-after-free vulnerability was found in the Linux kernel. After a previous fix for acpi_processor_errata_piix4(), device pointers may be dereferenced after dropping references to the device objects pointed to by them, which may cause a use-after-free to occur. Moreover, debug messages about enabling the errata may be printed if the errata flags corresponding to them are unset. Address all of these iss [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's IPv6 Segment Routing (SRv6) implementation. The function `__in6_dev_get()` can return NULL when a network device lacks IPv6 configuration, such as when the MTU is below `IPV6_MIN_MTU` or during `NETDEV_UNREGISTER` processing. Two SRv6 code paths—`seg6_hmac_validate_skb()` and `ipv6_srh_rcv()`—failed to validate the returned `idev` point [truncated]
A race condition exists in the Linux kernel's net/mlx5e due to concurrent access to IPSec ASO context. The driver uses a single mlx5e_ipsec_aso struct for each PF, containing a shared DMA-mapped context for all ASO operations. A second operation can overwrite the shared context before the first operation's completion is processed, leading to unexpected behavior. This vulnerability affects Linux kernel ver [truncated]
A race condition exists in the Linux kernel's handling of IPSec ESN updates in full offload mode. The device reports an ESN wrap event to the driver, which validates the event and then updates the kernel's xfrm state. However, the driver temporarily releases and re-acquires the xfrm state lock, allowing the event to be processed twice. This causes the ESN high-order bits to be incremented incorrectly, lea [truncated]
The Linux kernel was vulnerable to a use-after-free condition in the shaper netdev component. A fix has been applied to the stable kernel branches. This vulnerability could potentially allow attackers to exploit the system, leading to crashes or code execution. Users of affected kernel versions should take immediate action to patch their systems. The vulnerability was introduced due to improper handling o [truncated]
The Linux kernel was vulnerable to a race condition in the shaper component, allowing for potential hierarchy leaks. The vulnerability has been resolved through patches. Affected users should apply patches to mitigate this vulnerability. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. The vulnerability was resolved by taking the instance lock in pre-callbacks, preventing the netdev fro [truncated]
A Linux kernel vulnerability, CVE-2026-23435, was found in the x86_pmu_enable() function. The flaw occurs when handling perf events, leading to a NULL pointer dereference. This happens because the event pointer is not properly set up before being used. The vulnerability was introduced by a commit that moved the cpuc->events[idx] assignment out of x86_pmu_start() and into step 2 of x86_pmu_enable(), after [truncated]
CVE-2026-23433 is a MEDIUM severity vulnerability in the Linux kernel, specifically in the arm_mpam component. The vulnerability occurs when an MSC supporting memory bandwidth monitoring is brought offline and then online, causing a null pointer dereference when restoring bandwidth counters. This issue can lead to a kernel oops with a call trace. The vulnerability is resolved by providing a local variable [truncated]
A memory leak vulnerability was found in the Linux kernel's spi: amlogic-spisg component. The vulnerability occurs when the driver fails to call spi_controller_put() in several error paths, leading to a memory leak. This issue has been resolved by converting to use devm_spi_alloc_host()/devm_spi_alloc_target(). Linux kernel users and administrators should be aware of this vulnerability and take steps to e [truncated]