These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-23241 is a Linux kernel audit coverage issue. The audit "read" class was missing the "at" variants of getxattr() and listxattr(), so reads of extended attributes through getxattrat() or listxattrat() could avoid audit rules that should have logged those accesses. NVD rates the issue 5.5 (Medium) and maps it to local, low-privilege abuse with high availability impact. Kernel fixes are referenced i [truncated]
CVE-2025-71239 is a Linux kernel audit coverage issue where fchmodat2() was not included in the audit change-attributes class. As described in the CVE record, that omission meant a file attribute change performed with fchmodat2() could evade audit rules that would otherwise apply to chmod() or fchmodat(). The issue was publicly recorded on 2026-03-17 and later updated on 2026-05-20, with stable-kernel pat [truncated]
CVE-2026-23240 is a critical Linux kernel race condition in the TLS work-cancellation path. The bug can allow tx_work_handler() to be scheduled again after close-time cancellation, creating a use-after-free risk against freed TLS state.
CVE-2026-23239 was published on 2026-03-10 and describes a Linux kernel espintcp race condition found during code audit. After espintcp_close() calls cancel_work_sync(), espintcp_tx_work() can still be scheduled from delayed ACK handling or ksoftirqd, which can lead to dereferencing a freed espintcp context or socket. NVD rates the issue HIGH (CVSS 7.8) with local access, low privileges, and no user inter [truncated]
CVE-2024-14027 is a Linux kernel vulnerability caused by a missing fdput() call in the fremovexattr() syscall error path. This vulnerability allows an unprivileged local user to cause kernel memory exhaustion by permanently leaking one file reference per call. The issue was inadvertently fixed by commit a71874379ec8 (“xattr: switch to CLASS(fd)”). The vulnerability has a CVSS score of 5.5 and a severity o [truncated]
A NULL pointer dereference vulnerability was found in the Linux kernel's qla2xxx driver. The issue occurs when the driver attempts to free memory associated with a sp (session) pointer without checking if the pointer is NULL. This can lead to a system crash with a NULL pointer dereference error. The vulnerability has been addressed by adding a check for the sp pointer before freeing associated memory, ens [truncated]
The Linux kernel vulnerability CVE-2025-71234 is caused by the driver not setting hw->sta_data_size, leading to insufficient space allocation for driver private station data in __sta_info_alloc(). This results in a slab-out-of-bounds write when rtl8xxxu_sta_add() accesses members of struct rtl8xxxu_sta_info through sta->drv_priv. The fix involves setting hw->sta_data_size to sizeof(struct rtl8xxxu_sta_inf [truncated]
A Linux kernel vulnerability can cause a kernel oops when reading ceph snapshot directories. This issue arises from an invalid pointer being passed to kfree() in the parse_longname() function. The vulnerability can be triggered by listing snapshot directories, such as with the command `ls /mnt/my_ceph/.snap`. To address this, Linux system administrators should assess exposure and apply patches to prevent [truncated]
A use-after-free vulnerability exists in the Linux kernel's ALSA aloop driver. The vulnerability is due to a race condition between the PCM trigger callback and the stream stopping operation. This can lead to a use-after-free condition when a program attempts to trigger frequently while opening or closing the tied stream. The vulnerability has been resolved by modifying the PCM trigger callback of the alo [truncated]
CVE-2026-23185 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The vulnerability is related to the wifi: iwlwifi: mld component, where the mlo_scan_start_wk work is not canceled on disconnection, leading to potential init-after-queue and use-after-free issues. This vulnerability was published on 2026-02-14T17:15:56.273Z and modified on 2026-06-30T03:17:30.557Z. The CVE reco [truncated]
A high-severity vulnerability, CVE-2025-71204, has been resolved in the Linux kernel's smb/server component. This vulnerability could lead to a refcount leak in the parse_durable_handle_context() function during replay operations when -ENOEXEC is returned, necessitating the release of the ksmbd_file refcount. The vulnerability has been patched through several kernel commits. Linux kernel maintainers, admi [truncated]
CVE-2026-23171 is a Linux kernel bonding vulnerability that can trigger a use-after-free during enslave handling. According to the CVE description, the problem occurs when a new slave is added to the slave array before all enslave error paths are finished; if enslave then fails, cleanup can free the slave memory while it may still be used for transmit path decisions. The fix moves the slave-array update l [truncated]
A deadlock vulnerability in the Linux kernel's Btrfs filesystem can cause system hangs when memory cgroup dirty limits interact with Btrfs's internal metadata writeback threshold. Affected kernels from 2.6.29 through 6.18.8 (and 6.19-rc1 through rc7) may experience this condition when a cgroup with a small dirty limit (e.g., 16 MB) accumulates dirty Btrfs btree pages that exceed the cgroup limit but remai [truncated]
CVE-2026-23151 is a Linux kernel Bluetooth MGMT bug where pending command objects were not freed after completion, creating a memory leak on each affected SSP or advertising command. The issue is listed as medium severity and primarily threatens availability through memory exhaustion.
A vulnerability in the Linux kernel's Btrfs filesystem send functionality could allow invalid memory access when processing inline extents. The issue occurs in range_is_hole_in_parent() where the disk_bytenr field of a file extent item is accessed without first verifying whether the extent is inline. For inline extents, data begins at the offset of the disk_bytenr field, meaning accessing this field reads [truncated]
A memory leak vulnerability was found in the Linux kernel's unittest_data_add() function. If of_resolve_phandles() fails, the allocated unittest_data is not freed, leading to a memory leak. This issue has been resolved by using a scope-based cleanup helper __free(kfree) for automatic resource cleanup. The vulnerability affects Linux kernel versions 3.18 to 6.18.6 and 6.19-rc1 to 6.19-rc4. Linux kernel dev [truncated]
A vulnerability in the Linux kernel has been identified and resolved. The issue relates to the netfs subsystem, specifically with the unlocking of pages during buffered reads. In certain scenarios, the collection of read results appears to proceed ahead of the completion of subrequests, potentially leading to the premature unlocking of folios. This can cause issues when the file size does not align with a [truncated]
A use-after-free (UAF) and reference-count underrun vulnerability exists in the Linux kernel's rxrpc subsystem. The flaw resides in rxrpc_recvmsg(), which unconditionally requeues a call to the recvmsg queue when MSG_DONTWAIT is specified and the call's mutex is locked. Because the call may already be on the queue—either because MSG_PEEK prevented dequeuing or because the I/O thread requeued it—this uncon [truncated]
A flaw was found in the Linux kernel's btrfs module. This issue occurs when logging inode references during a rename operation, particularly when exchanging two directories. The log tree may end up with only one of the inodes, leading to incorrect deletion attempts after a power failure. This can result in a filesystem mount failure and a stack trace. The issue arises from the btrfs module's handling of i [truncated]
CVE-2018-14634 is a Linux Kernel integer overflow vulnerability that CISA has listed in the Known Exploited Vulnerabilities (KEV) catalog. Based on the supplied source corpus, the key defensive takeaway is that affected Linux Kernel deployments should be reviewed promptly against vendor guidance and patched or mitigated as directed. The source set does not provide a CVSS score or additional technical expl [truncated]
The Linux kernel was vulnerable to a high-severity issue, CVE-2026-22998, which involved NULL pointer dereferences in the nvmet_tcp_build_pdu_iov function. This vulnerability was caused by inadequate validation of command data structures before processing H2C_DATA PDUs. Attackers could exploit this by sending H2C_DATA PDUs in specific sequences, such as before a CONNECT command or with uninitialized comma [truncated]
A high-severity vulnerability (CVSS 7.5) exists in the Linux kernel's CAN J1939 protocol implementation. The vulnerability, tracked as CVE-2026-22997, is caused by a use-after-free condition that can occur when receiving a second RTS (Request to Send) message for an active session. This can lead to a reference count leak for the j1939_session, which may cause issues with network device unregistration. The [truncated]
The Linux kernel has been updated to address a HIGH-severity vulnerability, CVE-2026-22990, in the libceph component. This vulnerability, with a CVSS score of 7.5, could allow an attacker to cause a denial of service (DoS) by providing a maliciously corrupted osdmap. The issue arises from the overzealous use of BUG_ON in the osdmap_apply_incremental() function, which could trigger unexpectedly and lead to [truncated]
A vulnerability in the Linux kernel's gpio: mpsse driver has been resolved. The issue allowed for a crash when an IRQ worker was running and the device was unplugged. This was due to inadequate protection of a list of workers. The fix involves using a spinlock to protect the list and tearing it down on disconnect. The gpio: mpsse driver in the Linux kernel did not properly protect its worker list, leading [truncated]
The Linux kernel vulnerability CVE-2025-71146 has been resolved. The issue was related to a potential leak of the ct object in error paths within the netfilter: nf_conncount component. The problem arose because certain error paths skipped the refcounted check and returned immediately without properly handling the ct object. To address this, modifications were made to ensure that the check is always called [truncated]
A use-after-free vulnerability was found in the Linux kernel's USB PHY isp1301 driver. The issue arises from a recent change that fixed a device reference leak in a UDC driver, which introduced a potential use-after-free in the non-OF case. The isp1301_get_client() helper only increases the reference count for the returned I2C device in the OF case, leading to a potential use-after-free when the caller de [truncated]
A Linux kernel vulnerability triggers a warning when disabling a remote partition due to ineffective CPU management. This issue arises when a CPU is offlined, causing subpartitions_cpus to be cleared. Consequently, partitions are forced to share CPUs with the top_cpuset, leading to a warning about effective_xcpus not being a subset of subpartitions_cpus. The fix involves emitting the warning only if subpa [truncated]
The Linux kernel was vulnerable to possible out-of-bounds array accesses in the `adv7842_cp_log_status()` function due to unchecked return values from `cp_read()` and `hdmi_read()`. This could lead to system crashes or potentially code execution if exploited. The issue has been resolved by adding necessary checks for these return values. Linux kernel maintainers and users should review and apply the provi [truncated]
A NULL pointer dereference vulnerability was found in the Linux kernel's drm/i915/gem module. The vulnerability occurs during the execution of the eb_lookup_vmas() function, which is used to look up virtual memory areas (VMAs) for a given buffer. If the eb_add_vma() function fails, it does not set the vma pointer to NULL, leading to a NULL pointer dereference when trying to clean up the mess. The vulnerab [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-14T15:16:02.547Z and has not been modified since then. The NVD entry is currently Modified. The Linux kernel vulnerability CVE-2025-71128 involves a buffer overflow issue in the erspan code. The problem arises from the incorrect handling of the options_len field in the struct ip_tunnel_info, which h [truncated]