These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-23278 is a Linux kernel netfilter/nf_tables vulnerability in transaction processing for catchall elements. According to the CVE description, if a set map is being removed while both a live catchall element and a pending catchall element exist, the abort path may toggle only the first viable element instead of all pending catchall elements. The documented result is a kernel warning in nft_data_rel [truncated]
CVE-2026-23276 describes a Linux kernel networking flaw where tunnel transmit paths did not enforce an adequate recursion limit of their own. In the affected topology, a bond device in broadcast mode with GRE tap interfaces as slaves can loop multicast or broadcast traffic back through the bond, causing repeated recursion between `bond_xmit_broadcast()` and `ip_tunnel_xmit()`/`ip6_tnl_xmit()` until the ke [truncated]
CVE-2026-23275 describes a Linux kernel io_uring race condition during ring resizing. When DEFER_TASKRUN and SETUP_TASKRUN are used, task work added at the same time a ring is being resized can race with the swap to the new rings object and the freeing of the old one. The result is a narrow window where task-run flag manipulation can occur against a rings object that is no longer stable. The fix introduce [truncated]
CVE-2026-23272 is a Linux kernel netfilter/nf_tables issue in set insertion handling. According to the published fix description, when a set is already full, a newly added element could be published and then removed without waiting for the RCU grace period, while an RCU reader may already be traversing it. The upstream fix changes the transaction flow so the element is accounted for even when the set is f [truncated]
A slab-out-of-bounds read vulnerability exists in the Linux kernel's AppArmor security module. During policy unpacking, the `unpack_pdb()` function reads DFA (Deterministic Finite Automaton) start states from untrusted policy data and uses them as indexes into DFA state tables without validation. When `aa_dfa_next()` is subsequently called, it accesses `dfa->tables[YYTD_ID_BASE][start]`, which can result [truncated]
A confused-deputy vulnerability in the Linux kernel's AppArmor security module allows an unprivileged local user to perform privileged policy management operations. The apparmorfs interfaces for loading, replacing, and removing security profiles were accessible with permissions that permitted file descriptor passing attacks. An unprivileged attacker could open these interfaces and pass the resulting file [truncated]
A race condition in the F2FS (Flash-Friendly File System) atomic commit path can cause checkpoint metadata inconsistency, leading to mount failures after sudden power-off (SPO). The vulnerability stems from inadequate synchronization between atomic write commits and checkpoint operations on the `IS_CHECKPOINTED` NAT entry flag. When Thread A performs an atomic commit while Thread B executes a checkpoint, [truncated]
A divide-by-zero vulnerability in the Linux kernel's RIVA framebuffer driver (rivafb) allows a local attacker to crash the kernel. The flaw exists in nv3_arb() within drivers/video/fbdev/riva/riva_hw.c, where state->mclk_khz is used as a divisor without validation. An attacker with access to a malicious or emulated PCI device can supply a zero value for this clock parameter via a crafted PRAMDAC MCLK PLL [truncated]
A vulnerability in the Linux kernel's F2FS (Flash-Friendly File System) allows a corrupted filesystem image to trigger a kernel BUG() panic during node page I/O completion. The issue occurs when a fuzzed or maliciously crafted F2FS image contains a node page whose footer.nid field does not match the page's expected node ID (nid). Under normal read paths, sanity checks catch this inconsistency, but asynchr [truncated]
A logic error in the Linux kernel's AMD GPU ASPM (Active State Power Management) handling can cause system crashes on multi-GPU configurations. The vulnerability stems from an erroneously re-applied commit that checks ASPM enablement from the PCIe subsystem globally, rather than per-device. When a system contains two AMD GPUs and only one supports ASPM, this global check leads to inconsistent power manage [truncated]
CVE-2026-23263 is a Linux kernel issue in the io_uring/zcrx path. The published fix notes that an earlier change stopped a page leak on scatter-gather init failure, but did not release the page array itself. This CVE closes that gap by freeing the page array as well.
CVE-2026-23262 describes a Linux kernel driver bug in gve stats reporting. When the number of queues changes, the driver resizes a shared stats region used by the driver and NIC. If queues are increased, the NIC may write beyond the allocated region, creating a memory corruption condition. If queues are decreased, stats can become misaligned and reported incorrectly. The published fix avoids resizing into [truncated]
CVE-2026-23261 describes a Linux kernel NVMe/FC initialization bug that can leak admin queue/tagset resources if controller setup fails after `nvme_add_ctrl()` succeeds. The issue is in the failure path of `nvme_fc_init_ctrl()`: controller references are torn down, but the admin blk-mq allocation is not freed unless `ctrl->ctrl.admin_tagset` is explicitly checked and removed. The supplied description ties [truncated]
A memory leak vulnerability in the Linux kernel's regmap maple cache implementation allows uncontrolled memory consumption when mas_store_gfp() fails. The flaw exists in regcache_maple_write(), which allocates a new block ('entry') to merge adjacent ranges but fails to free it when mas_store_gfp() returns an error. On the success path, the function correctly frees replaced neighbor blocks ('lower', 'upper [truncated]
A memory leak vulnerability in the Linux kernel's io_uring subsystem could allow a local attacker to cause a denial of service condition. The flaw occurs in the read/write path when a request with an allocated iovec fails to be placed into the rw_cache during cleanup, leaving the iovec pointer unaccounted for and resulting in a memory leak. The fix introduces a return value from io_rw_recycle() to indicat [truncated]
A memory leak vulnerability exists in the Linux kernel's LiquidIO network driver. In setup_nic_devices(), a netdev structure is allocated via alloc_etherdev_mq(), but the pointer is stored in oct->props[i].netdev only after calls to netif_set_real_num_rx_queues() and netif_set_real_num_tx_queues(). If either queue setup function fails, the error return path does not free the allocated netdev because oct-> [truncated]
CVE-2026-23256 is a Linux kernel bug in the liquidio VF setup path where a cleanup loop can miss the failing index after initialization aborts, leaving allocated memory unreleased. The issue is categorized as CWE-193 (off-by-one) and carries a medium severity rating with local, low-privilege impact focused on availability.
CVE-2026-23255 is an RCU synchronization flaw in the Linux kernel’s /proc/net/ptype path. According to the CVE description, ptype_seq_show() and ptype_seq_next() can observe packet_type state without sufficient RCU protection while concurrent writers remove packet_type entries and clear pt->dev. The result is an RCU stall and a high-availability denial-of-service condition on affected systems.
## Summary CVE-2026-23254 is a MEDIUM-severity vulnerability in the Linux kernel's Generic Receive Offload (GRO) networking path. The flaw causes `udp4_gro_complete()` to compute the outer UDP header pseudo-checksum using the wrong (inner) network offset when the `encapsulation` flag is unexpectedly set on incoming packets. This leads to checksum validation errors during subsequent packet processing, resu [truncated]
A use-after-free vulnerability exists in the Linux kernel's DVB (Digital Video Broadcasting) core subsystem, specifically in the DVR (Digital Video Recorder) device open path. When a new reader opens the DVR device via `dvb_dvr_open()`, the function incorrectly calls `dvb_ringbuffer_init()`, which reinitializes a shared waitqueue list head to empty. This waitqueue is shared across all open instances of th [truncated]
A local denial-of-service vulnerability in the Linux kernel's XFS filesystem scrubber (xfs_scrub) where debug description macros could trigger memory allocation failures. The xchk_xfile_*_descr macros used kasprintf for formatting debug strings, which could fail when formatted output exceeded allocation guarantees. A syzbot fuzzing campaign by Jiaming Zhang identified reachable failure paths. The fix repl [truncated]
CVE-2026-23250 was published on 2026-03-18 and concerns a Linux kernel XFS bug in the scrub helper path. The advisory says xchk_scrub_create_subord should return NULL rather than a mangled ENOMEM value, and callers must check for NULL and return ENOMEM. NVD rates the issue Medium with high availability impact and no confidentiality or integrity impact, which points to a local denial-of-service risk rather [truncated]
CVE-2026-23249 is a Linux kernel XFS flaw where revalidating rebuilt allocation or inode btrees can dereference a cursor that was already deleted after a failed cross-reference check. The result is a kernel crash / denial of service during XFS repair evaluation. NVD rates the issue 5.5 (Medium) with local, low-privilege conditions and high availability impact.
CVE-2025-71270 is a Linux kernel flaw in LoongArch exception handling for BPF memory-access probes. The fix enables exception recovery for specific ADE subcodes so BPF_PROBE_MEM* instructions can be safely recovered through the BPF exception table mechanism. On affected LoongArch systems, a local BPF-capable user may be able to trigger unhandled recoverable access exceptions, resulting in kernel instabili [truncated]
CVE-2025-71269 is a Linux kernel Btrfs bug in inline extent handling. When inline extent creation fails with -ENOSPC, the code falls back to the normal COW path, but the reserved qgroup data was being freed as if no data would be used. The published fix changes that cleanup so qgroup data is only freed when the inline path does not fall back.
CVE-2026-23248 is a Linux kernel vulnerability in perf/core where a race during perf_mmap() could expose a ring buffer after mmap() setup fails, leading to a refcount error and potential use-after-free. The issue is fixed by keeping mmap_mutex held across map_range() so buffer setup, mapping, and cleanup behave atomically from other threads’ perspective.
CVE-2026-23247 is a Linux kernel TCP hardening issue where a SYN cookie side-channel could leak TCP source-port information. The upstream fix restores port influence in timestamp offset randomization, reversing an earlier change that reduced timestamp offsets to per-host values. NVD rates the issue Medium (CVSS 5.5) and has linked stable kernel patches for remediation.
CVE-2026-23246 is a high-severity Linux kernel Wi-Fi/mac80211 vulnerability published on 2026-03-18 and last modified on 2026-04-02. The issue is a missing bounds check in ieee80211_ml_reconfiguration: link_id is derived from the ML Reconfiguration element and can range from 0 to 15, but the link_removal_timeout[] stack array has only 15 elements. As described in the source record, accepting link_id == 15 [truncated]
CVE-2026-23244 is a Linux kernel issue in nvme_pr_read_keys() where a user-controlled num_keys value is used to size an allocation via struct_size(). With the existing PR_KEYS_MAX upper bound, a large input can still drive an allocation attempt of up to about 4 MB, which in turn can trigger allocator warnings when the requested order exceeds MAX_PAGE_ORDER. The kernel fix switches the allocation to kvzalloc().
CVE-2026-23241 is a Linux kernel audit coverage issue. The audit "read" class was missing the "at" variants of getxattr() and listxattr(), so reads of extended attributes through getxattrat() or listxattrat() could avoid audit rules that should have logged those accesses. NVD rates the issue 5.5 (Medium) and maps it to local, low-privilege abuse with high availability impact. Kernel fixes are referenced i [truncated]