PatchSiren

Linux CVE debriefs · Page 111

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-03-20

CVE-2026-23278

CVE-2026-23278 is a Linux kernel netfilter/nf_tables vulnerability in transaction processing for catchall elements. According to the CVE description, if a set map is being removed while both a live catchall element and a pending catchall element exist, the abort path may toggle only the first viable element instead of all pending catchall elements. The documented result is a kernel warning in nft_data_rel [truncated]

Review Linux CVE published 2026-03-20

CVE-2026-23276

CVE-2026-23276 describes a Linux kernel networking flaw where tunnel transmit paths did not enforce an adequate recursion limit of their own. In the affected topology, a bond device in broadcast mode with GRE tap interfaces as slaves can loop multicast or broadcast traffic back through the bond, causing repeated recursion between `bond_xmit_broadcast()` and `ip_tunnel_xmit()`/`ip6_tnl_xmit()` until the ke [truncated]

HIGH Linux CVE published 2026-03-20

CVE-2026-23275

CVE-2026-23275 describes a Linux kernel io_uring race condition during ring resizing. When DEFER_TASKRUN and SETUP_TASKRUN are used, task work added at the same time a ring is being resized can race with the swap to the new rings object and the freeing of the old one. The result is a narrow window where task-run flag manipulation can occur against a rings object that is no longer stable. The fix introduce [truncated]

HIGH Linux CVE published 2026-03-20

CVE-2026-23272

CVE-2026-23272 is a Linux kernel netfilter/nf_tables issue in set insertion handling. According to the published fix description, when a set is already full, a newly added element could be published and then removed without waiting for the RCU grace period, while an RCU reader may already be traversing it. The upstream fix changes the transaction flow so the element is accounted for even when the set is f [truncated]

HIGH Linux CVE published 2026-03-18

CVE-2026-23269

A slab-out-of-bounds read vulnerability exists in the Linux kernel's AppArmor security module. During policy unpacking, the `unpack_pdb()` function reads DFA (Deterministic Finite Automaton) start states from untrusted policy data and uses them as indexes into DFA state tables without validation. When `aa_dfa_next()` is subsequently called, it accesses `dfa->tables[YYTD_ID_BASE][start]`, which can result [truncated]

HIGH Linux CVE published 2026-03-18

CVE-2026-23268

A confused-deputy vulnerability in the Linux kernel's AppArmor security module allows an unprivileged local user to perform privileged policy management operations. The apparmorfs interfaces for loading, replacing, and removing security profiles were accessible with permissions that permitted file descriptor passing attacks. An unprivileged attacker could open these interfaces and pass the resulting file [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23267

A race condition in the F2FS (Flash-Friendly File System) atomic commit path can cause checkpoint metadata inconsistency, leading to mount failures after sudden power-off (SPO). The vulnerability stems from inadequate synchronization between atomic write commits and checkpoint operations on the `IS_CHECKPOINTED` NAT entry flag. When Thread A performs an atomic commit while Thread B executes a checkpoint, [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23266

A divide-by-zero vulnerability in the Linux kernel's RIVA framebuffer driver (rivafb) allows a local attacker to crash the kernel. The flaw exists in nv3_arb() within drivers/video/fbdev/riva/riva_hw.c, where state->mclk_khz is used as a divisor without validation. An attacker with access to a malicious or emulated PCI device can supply a zero value for this clock parameter via a crafted PRAMDAC MCLK PLL [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23265

A vulnerability in the Linux kernel's F2FS (Flash-Friendly File System) allows a corrupted filesystem image to trigger a kernel BUG() panic during node page I/O completion. The issue occurs when a fuzzed or maliciously crafted F2FS image contains a node page whose footer.nid field does not match the page's expected node ID (nid). Under normal read paths, sanity checks catch this inconsistency, but asynchr [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23264

A logic error in the Linux kernel's AMD GPU ASPM (Active State Power Management) handling can cause system crashes on multi-GPU configurations. The vulnerability stems from an erroneously re-applied commit that checks ASPM enablement from the PCIe subsystem globally, rather than per-device. When a system contains two AMD GPUs and only one supports ASPM, this global check leads to inconsistent power manage [truncated]

Review Linux CVE published 2026-03-18

CVE-2026-23263

CVE-2026-23263 is a Linux kernel issue in the io_uring/zcrx path. The published fix notes that an earlier change stopped a page leak on scatter-gather init failure, but did not release the page array itself. This CVE closes that gap by freeing the page array as well.

Review Linux CVE published 2026-03-18

CVE-2026-23262

CVE-2026-23262 describes a Linux kernel driver bug in gve stats reporting. When the number of queues changes, the driver resizes a shared stats region used by the driver and NIC. If queues are increased, the NIC may write beyond the allocated region, creating a memory corruption condition. If queues are decreased, stats can become misaligned and reported incorrectly. The published fix avoids resizing into [truncated]

Review Linux CVE published 2026-03-18

CVE-2026-23261

CVE-2026-23261 describes a Linux kernel NVMe/FC initialization bug that can leak admin queue/tagset resources if controller setup fails after `nvme_add_ctrl()` succeeds. The issue is in the failure path of `nvme_fc_init_ctrl()`: controller references are torn down, but the admin blk-mq allocation is not freed unless `ctrl->ctrl.admin_tagset` is explicitly checked and removed. The supplied description ties [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23260

A memory leak vulnerability in the Linux kernel's regmap maple cache implementation allows uncontrolled memory consumption when mas_store_gfp() fails. The flaw exists in regcache_maple_write(), which allocates a new block ('entry') to merge adjacent ranges but fails to free it when mas_store_gfp() returns an error. On the success path, the function correctly frees replaced neighbor blocks ('lower', 'upper [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23259

A memory leak vulnerability in the Linux kernel's io_uring subsystem could allow a local attacker to cause a denial of service condition. The flaw occurs in the read/write path when a request with an allocated iovec fails to be placed into the rw_cache during cleanup, leaving the iovec pointer unaccounted for and resulting in a memory leak. The fix introduces a return value from io_rw_recycle() to indicat [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23258

A memory leak vulnerability exists in the Linux kernel's LiquidIO network driver. In setup_nic_devices(), a netdev structure is allocated via alloc_etherdev_mq(), but the pointer is stored in oct->props[i].netdev only after calls to netif_set_real_num_rx_queues() and netif_set_real_num_tx_queues(). If either queue setup function fails, the error return path does not free the allocated netdev because oct-> [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23256

CVE-2026-23256 is a Linux kernel bug in the liquidio VF setup path where a cleanup loop can miss the failing index after initialization aborts, leaving allocated memory unreleased. The issue is categorized as CWE-193 (off-by-one) and carries a medium severity rating with local, low-privilege impact focused on availability.

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23255

CVE-2026-23255 is an RCU synchronization flaw in the Linux kernel’s /proc/net/ptype path. According to the CVE description, ptype_seq_show() and ptype_seq_next() can observe packet_type state without sufficient RCU protection while concurrent writers remove packet_type entries and clear pt->dev. The result is an RCU stall and a high-availability denial-of-service condition on affected systems.

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23254

## Summary CVE-2026-23254 is a MEDIUM-severity vulnerability in the Linux kernel's Generic Receive Offload (GRO) networking path. The flaw causes `udp4_gro_complete()` to compute the outer UDP header pseudo-checksum using the wrong (inner) network offset when the `encapsulation` flag is unexpectedly set on incoming packets. This leads to checksum validation errors during subsequent packet processing, resu [truncated]

HIGH Linux CVE published 2026-03-18

CVE-2026-23253

A use-after-free vulnerability exists in the Linux kernel's DVB (Digital Video Broadcasting) core subsystem, specifically in the DVR (Digital Video Recorder) device open path. When a new reader opens the DVR device via `dvb_dvr_open()`, the function incorrectly calls `dvb_ringbuffer_init()`, which reinitializes a shared waitqueue list head to empty. This waitqueue is shared across all open instances of th [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23252

A local denial-of-service vulnerability in the Linux kernel's XFS filesystem scrubber (xfs_scrub) where debug description macros could trigger memory allocation failures. The xchk_xfile_*_descr macros used kasprintf for formatting debug strings, which could fail when formatted output exceeded allocation guarantees. A syzbot fuzzing campaign by Jiaming Zhang identified reachable failure paths. The fix repl [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23250

CVE-2026-23250 was published on 2026-03-18 and concerns a Linux kernel XFS bug in the scrub helper path. The advisory says xchk_scrub_create_subord should return NULL rather than a mangled ENOMEM value, and callers must check for NULL and return ENOMEM. NVD rates the issue Medium with high availability impact and no confidentiality or integrity impact, which points to a local denial-of-service risk rather [truncated]

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23249

CVE-2026-23249 is a Linux kernel XFS flaw where revalidating rebuilt allocation or inode btrees can dereference a cursor that was already deleted after a failed cross-reference check. The result is a kernel crash / denial of service during XFS repair evaluation. NVD rates the issue 5.5 (Medium) with local, low-privilege conditions and high availability impact.

MEDIUM Linux CVE published 2026-03-18

CVE-2025-71270

CVE-2025-71270 is a Linux kernel flaw in LoongArch exception handling for BPF memory-access probes. The fix enables exception recovery for specific ADE subcodes so BPF_PROBE_MEM* instructions can be safely recovered through the BPF exception table mechanism. On affected LoongArch systems, a local BPF-capable user may be able to trigger unhandled recoverable access exceptions, resulting in kernel instabili [truncated]

HIGH Linux CVE published 2026-03-18

CVE-2025-71269

CVE-2025-71269 is a Linux kernel Btrfs bug in inline extent handling. When inline extent creation fails with -ENOSPC, the code falls back to the normal COW path, but the reserved qgroup data was being freed as if no data would be used. The published fix changes that cleanup so qgroup data is only freed when the inline path does not fall back.

HIGH Linux CVE published 2026-03-18

CVE-2026-23248

CVE-2026-23248 is a Linux kernel vulnerability in perf/core where a race during perf_mmap() could expose a ring buffer after mmap() setup fails, leading to a refcount error and potential use-after-free. The issue is fixed by keeping mmap_mutex held across map_range() so buffer setup, mapping, and cleanup behave atomically from other threads’ perspective.

MEDIUM Linux CVE published 2026-03-18

CVE-2026-23247

CVE-2026-23247 is a Linux kernel TCP hardening issue where a SYN cookie side-channel could leak TCP source-port information. The upstream fix restores port influence in timestamp offset randomization, reversing an earlier change that reduced timestamp offsets to per-host values. NVD rates the issue Medium (CVSS 5.5) and has linked stable kernel patches for remediation.

HIGH Linux CVE published 2026-03-18

CVE-2026-23246

CVE-2026-23246 is a high-severity Linux kernel Wi-Fi/mac80211 vulnerability published on 2026-03-18 and last modified on 2026-04-02. The issue is a missing bounds check in ieee80211_ml_reconfiguration: link_id is derived from the ML Reconfiguration element and can range from 0 to 15, but the link_removal_timeout[] stack array has only 15 elements. As described in the source record, accepting link_id == 15 [truncated]

HIGH Linux CVE published 2026-03-18

CVE-2026-23244

CVE-2026-23244 is a Linux kernel issue in nvme_pr_read_keys() where a user-controlled num_keys value is used to size an allocation via struct_size(). With the existing PR_KEYS_MAX upper bound, a large input can still drive an allocation attempt of up to about 4 MB, which in turn can trigger allocator warnings when the requested order exceeds MAX_PAGE_ORDER. The kernel fix switches the allocation to kvzalloc().

MEDIUM Linux CVE published 2026-03-17

CVE-2026-23241

CVE-2026-23241 is a Linux kernel audit coverage issue. The audit "read" class was missing the "at" variants of getxattr() and listxattr(), so reads of extended attributes through getxattrat() or listxattrat() could avoid audit rules that should have logged those accesses. NVD rates the issue 5.5 (Medium) and maps it to local, low-privilege abuse with high availability impact. Kernel fixes are referenced i [truncated]