PatchSiren

Linux CVE debriefs · Page 110

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-04-03

CVE-2026-23429

A use-after-free vulnerability was found in the Linux kernel's IOMMU subsystem. The bug occurs when the iommu_sva_unbind_device function accesses the domain->mm->iommu_mm after it has been freed by iommu_domain_free, leading to a potential crash. This vulnerability has a high CVSS score of 7.8, indicating a high severity. The issue was resolved by moving the code that accesses domain->mm->iommu_mm to befo [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23426

The Linux kernel was vulnerable to a device node reference leak in the drm/logicvc component. The issue was resolved with a series of patches. Users should update to a fixed version. This vulnerability affects Linux kernel versions 6.0.1 to 7.0 (rc1 to rc7) and specific releases in between. Administrators and users should apply patches or mitigations as recommended.

HIGH Linux CVE published 2026-04-03

CVE-2026-23425

The Linux kernel was vulnerable to a HIGH severity issue, CVE-2026-23425, affecting KVM on arm64 architecture. The vulnerability arises from improper ID register initialization for non-protected pKVM guests, potentially leading to state corruption. The issue has been resolved through targeted patches. This vulnerability impacts system administrators and security teams managing Linux kernel-based systems, [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23424

A HIGH severity vulnerability was found in the Linux kernel, specifically in the accel/amdxdna component. The vulnerability is related to the validation of command buffer payload counts. The CVE record was published on 2026-04-03T14:16:28.623Z and was last modified on 2026-07-24T21:10:00.143Z. This vulnerability could allow an attacker with local access and low privileges to potentially exploit this vulne [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23423

A MEDIUM severity vulnerability was found in the Linux kernel, specifically in the btrfs_uring_read_extent() function. The vulnerability occurs when the 'pages' object is not freed in case of an error, potentially leading to memory leaks. This issue can cause system crashes or other problems if not addressed. Linux kernel users and administrators should be aware of this vulnerability and take necessary ac [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23421

A memory leak vulnerability was found in the Linux kernel's drm/xe/configfs component. The ctx_restore_mid_bb memory, allocated in wa_bb_store(), was not being freed in xe_config_device_release(), leading to a potential memory leak when the configfs device is removed. This issue has been resolved by adding a call to free ctx_restore_mid_bb[0].cs. The vulnerability affects Linux kernel versions 6.18.1 to 6 [truncated]

HIGH Linux CVE published 2026-04-03

CVE-2026-23419

A circular locking dependency vulnerability was found in the Linux kernel's rds_tcp_tune function. The issue arises when sk_net_refcnt_upgrade() is called while holding the socket lock, creating a dependency with fs_reclaim. This vulnerability has been resolved by moving sk_net_refcnt_upgrade() outside the socket lock critical section. The fix ensures that the fields modified by sk_net_refcnt_upgrade() ar [truncated]

MEDIUM Linux CVE published 2026-04-03

CVE-2026-23418

A memory leak vulnerability was found in the Linux kernel's drm/xe/reg_sr module. The vulnerability occurs when the xa_store() function fails, causing a memory leak on the error path. The vulnerability has been patched. Linux kernel users and administrators should be aware of this vulnerability and take steps to apply the patch. The vulnerability can be exploited by a local attacker with low privileges.

MEDIUM Linux CVE published 2026-04-01

CVE-2026-23401

A medium-severity vulnerability, CVE-2026-23401, was found in the Linux kernel's KVM component. The issue arises during the installation of emulated MMIO SPTEs, where an existing shadow-present SPTE is not properly dropped or zapped. This can lead to unexpected behavior when a guest hits a page fault. The vulnerability has a CVSS score of 5.5 and is considered a local attack vector with low attack complex [truncated]

MEDIUM Linux CVE published 2026-03-28

CVE-2026-23399

A memory leak vulnerability exists in the Linux kernel's nf_tables subsystem, specifically within the nft_dynset module. When cloning stateful expressions for dynamic set elements, if the second stateful expression clone fails due to GFP_ATOMIC allocation failure, the first successfully cloned stateful expression is not released, resulting in a memory leak of per-CPU objects. The leaked object trace indic [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23394

A race condition in the Linux kernel's AF_UNIX socket garbage collector (GC) can cause premature purging of a live socket's receive queue when MSG_PEEK operations interleave with socket close() calls. The vulnerability reintroduces a previously-fixed issue (commit cbcf01128d0a) that resurfaced after GC algorithm changes removed protective locking in unix_peek_fds(). When MSG_PEEK bumps a file reference co [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23389

A memory leak vulnerability exists in the Intel Ethernet Connection E800 Series (ice) driver within the Linux kernel. The flaw occurs in the `ice_set_ringparam()` function during ring parameter reconfiguration. When `tx_rings` and `xdp_rings` are successfully allocated but subsequent `rx_rings` allocation or individual Rx ring setup fails, the error handling paths fail to properly free all previously allo [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23371

A vulnerability in the Linux kernel's SCHED_DEADLINE scheduler could allow a local attacker to trigger bandwidth accounting corruption, leading to kernel warnings and potential denial of service. The issue occurs when a SCHED_DEADLINE task holding a PI mutex is changed to a lower priority class via sched_setscheduler() without properly inheriting DEADLINE parameters from a donor task. This missing ENQUEUE [truncated]

HIGH Linux CVE published 2026-03-25

CVE-2026-23364

CVE-2026-23364 is a HIGH severity vulnerability in the Linux kernel ksmbd subsystem. The vulnerability allows attackers to exploit timing attacks due to non-constant time MAC comparisons. This issue has been resolved by replacing memcmp() with the constant-time function crypto_memneq(). Affected Linux kernel versions include 5.15.1 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.19, and 6.19 to 6 [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23346

A vulnerability was found in the Linux kernel, specifically affecting the arm64 architecture. The issue arises from the ioremap_prot() function, which is used to create a kernel mapping of a physical address with specific protection flags. The function was incorrectly returning a user mapping, leading to a fault when accessed from the kernel. This could potentially allow a local attacker to access sensiti [truncated]

HIGH Linux CVE published 2026-03-25

CVE-2026-23327

A slab-out-of-bounds read vulnerability exists in the Linux kernel's CXL (Compute Express Link) mailbox subsystem. The function `cxl_payload_from_user_allowed()` in `drivers/cxl/core/mbox.c` casts and dereferences user-supplied payload data without first validating that the payload size is sufficient for the expected structure. When a raw mailbox command is issued with an undersized payload—for example, a [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23313

A preempt count leak vulnerability exists in the Linux kernel's i40e driver, specifically within the NAPI poll tracepoint. The issue stems from using get_cpu() in a tracepoint assignment without a corresponding put_cpu() call, causing the preempt count to increment without decrement. This results in a softirq warning indicating mismatched preempt counts on entry and exit of NET_RX softirq processing. The [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23312

A vulnerability in the Linux kernel's kaweth USB network driver allows a local attacker to cause a denial of service through a malicious USB device. The driver fails to validate USB endpoints during device probing, leading to null pointer dereferences when accessing expected URBs. The issue affects Linux kernel versions from 2.6.12 through 6.19.7, with patches available for all supported stable branches. [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23311

A local privilege context vulnerability exists in the Linux kernel's performance monitoring subsystem (perf/core). The flaw involves an invalid wait context where a wait-queue lock is incorrectly acquired while holding a perf-context lock, leading to a lockdep-detected bug. An attacker with local access could potentially trigger this condition to cause a denial of service. The vulnerability affects Linux [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23310

A logic gap in the Linux kernel's bonding driver allows an incompatible transmit hash policy change while XDP is loaded, leading to a WARN_ON splat during bond teardown. The vulnerability exists because bond_option_xmit_hash_policy_set() lacked the bond_xdp_check() guard present in bond_option_mode_set(). When a user changes xmit_hash_policy to vlan+srcmac after XDP attachment on a bond in 802.3ad or bala [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23309

A NULL pointer dereference vulnerability exists in the Linux kernel's tracing subsystem. When trigger_data_alloc() fails and returns NULL, the error handling path in event_hist_trigger_parse() calls trigger_data_free(), which does not check for NULL before dereferencing data->cmd_ops->set_filter. This flaw affects multiple stable kernel branches and could lead to a denial of service (system crash) when tr [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23308

A logic error in the Linux kernel's pinctrl equilibrium driver causes spurious warning traces during GPIO initialization. The `eqbr_irq_mask_ack()` callback incorrectly invokes `eqbr_irq_mask()`, which internally calls `gpiochip_disable_irq()`. This triggers a WARN_ON trace for every GPIO at load time because the interrupt is being disabled in a context where it should not be. The issue affects Linux kern [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23307

A vulnerability in the Linux kernel's EMS USB CAN driver (ems_usb) could allow a local attacker to cause a denial of service. The issue exists in the ems_usb_read_bulk_callback() function, which incorrectly uses transfer_buffer_length (the maximum buffer size set by the driver) instead of actual_length (the actual data size received) when parsing USB urb data. This leads to improper bounds checking at bot [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23296

A reference-count leak in the Linux kernel SCSI core subsystem can cause host teardown to hang indefinitely. The flaw resides in tagset_refcnt handling: when a SCSI host is destroyed, the leaked reference prevents completion of scsi_remove_host(), leaving processes such as iscsid unresponsive in __wait_for_common(). Local users with privileges to remove SCSI hosts or iSCSI sessions can trigger the hang, r [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23286

A null-pointer dereference vulnerability exists in the Linux kernel's ATM LANE (LAN Emulation) module, specifically in the `lec_arp_clear_vccs()` function. The issue arises when multiple `lec_arp_table` entries share the same `atm_vcc` structure. During VCC closure, `lec_vcc_close()` iterates over ARP entries and calls `lec_arp_clear_vccs()` for each match. On the first matched entry, the function frees ` [truncated]

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23285

CVE-2026-23285 is a Linux kernel availability issue in DRBD. In drbd_request_endio(), READ_COMPLETED_WITH_ERROR can reach __req_mod() with a NULL peer_device, and the handler then passes that NULL value into drbd_set_out_of_sync(), causing a null-pointer dereference. The supplied NVD record rates the issue CVSS 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23283

CVE-2026-23283 is a Linux kernel issue in the fp9931 regulator/hwmon path where an error return from regmap_read() could bypass pm_runtime_put_autosuspend(), leaking a PM runtime reference. NVD marks the issue as MEDIUM severity with local attack requirements and availability impact. According to the supplied NVD data, the affected range includes Linux kernel 6.19 through 6.19.7, plus 7.0-rc1. NVD also li [truncated]

HIGH Linux CVE published 2026-03-25

CVE-2026-23281

CVE-2026-23281 is a Linux kernel use-after-free in the libertas Wi‑Fi driver cleanup path. The bug affects lbs_free_adapter(), where non-synchronous timer teardown could allow a running timer callback to continue after the adapter structure was freed. That creates a memory safety issue in code that can touch driver state such as locks, command pointers, and device references. The issue is rated CVSS 7.8 ( [truncated]

HIGH Linux CVE published 2026-03-25

CVE-2026-23280

CVE-2026-23280 is a Linux kernel vulnerability in the accel/amdxdna path where a ubuf size calculation can overflow before allocation. That can lead to an undersized allocation and possible memory corruption. NVD marks the issue as HIGH severity with local attack conditions and references upstream kernel patches that add overflow checking.

MEDIUM Linux CVE published 2026-03-25

CVE-2026-23279

CVE-2026-23279 is a Linux kernel mac80211 bug that can crash systems using 802.11s mesh networking. A crafted Spectrum Management / Channel Switch action frame that matches the local Mesh ID and Mesh Configuration but omits the Mesh Channel Switch Parameters IE can trigger a NULL pointer dereference in mesh_rx_csa_frame(). The impact is denial of service through a kernel oops/panic risk, not code executio [truncated]