PatchSiren

Linux CVE debriefs · Page 113

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-02-14

CVE-2025-71201

A vulnerability in the Linux kernel has been identified and resolved. The issue relates to the netfs subsystem, specifically with the unlocking of pages during buffered reads. In certain scenarios, the collection of read results appears to proceed ahead of the completion of subrequests, potentially leading to the premature unlocking of folios. This can cause issues when the file size does not align with a [truncated]

HIGH Linux CVE published 2026-02-04

CVE-2026-23066

A use-after-free (UAF) and reference-count underrun vulnerability exists in the Linux kernel's rxrpc subsystem. The flaw resides in rxrpc_recvmsg(), which unconditionally requeues a call to the recvmsg queue when MSG_DONTWAIT is specified and the call's mutex is locked. Because the call may already be on the queue—either because MSG_PEEK prevented dequeuing or because the I/O thread requeued it—this uncon [truncated]

CRITICAL Linux CVE published 2026-01-31

CVE-2025-71183

A flaw was found in the Linux kernel's btrfs module. This issue occurs when logging inode references during a rename operation, particularly when exchanging two directories. The log tree may end up with only one of the inodes, leading to incorrect deletion attempts after a power failure. This can result in a filesystem mount failure and a stack trace. The issue arises from the btrfs module's handling of i [truncated]

Known exploited Linux CVE published 2026-01-26

CVE-2018-14634

CVE-2018-14634 is a Linux Kernel integer overflow vulnerability that CISA has listed in the Known Exploited Vulnerabilities (KEV) catalog. Based on the supplied source corpus, the key defensive takeaway is that affected Linux Kernel deployments should be reviewed promptly against vendor guidance and patched or mitigated as directed. The source set does not provide a CVSS score or additional technical expl [truncated]

HIGH Linux CVE published 2026-01-25

CVE-2026-22998

The Linux kernel was vulnerable to a high-severity issue, CVE-2026-22998, which involved NULL pointer dereferences in the nvmet_tcp_build_pdu_iov function. This vulnerability was caused by inadequate validation of command data structures before processing H2C_DATA PDUs. Attackers could exploit this by sending H2C_DATA PDUs in specific sequences, such as before a CONNECT command or with uninitialized comma [truncated]

HIGH Linux CVE published 2026-01-25

CVE-2026-22997

A high-severity vulnerability (CVSS 7.5) exists in the Linux kernel's CAN J1939 protocol implementation. The vulnerability, tracked as CVE-2026-22997, is caused by a use-after-free condition that can occur when receiving a second RTS (Request to Send) message for an active session. This can lead to a reference count leak for the j1939_session, which may cause issues with network device unregistration. The [truncated]

HIGH Linux CVE published 2026-01-23

CVE-2026-22990

The Linux kernel has been updated to address a HIGH-severity vulnerability, CVE-2026-22990, in the libceph component. This vulnerability, with a CVSS score of 7.5, could allow an attacker to cause a denial of service (DoS) by providing a maliciously corrupted osdmap. The issue arises from the overzealous use of BUG_ON in the osdmap_apply_incremental() function, which could trigger unexpectedly and lead to [truncated]

HIGH Linux CVE published 2026-01-23

CVE-2025-71158

A vulnerability in the Linux kernel's gpio: mpsse driver has been resolved. The issue allowed for a crash when an IRQ worker was running and the device was unplugged. This was due to inadequate protection of a list of workers. The fix involves using a spinlock to protect the list and tearing it down on disconnect. The gpio: mpsse driver in the Linux kernel did not properly protect its worker list, leading [truncated]

HIGH Linux CVE published 2026-01-23

CVE-2025-71146

The Linux kernel vulnerability CVE-2025-71146 has been resolved. The issue was related to a potential leak of the ct object in error paths within the netfilter: nf_conncount component. The problem arose because certain error paths skipped the refcounted check and returned immediately without properly handling the ct object. To address this, modifications were made to ensure that the check is always called [truncated]

HIGH Linux CVE published 2026-01-23

CVE-2025-71145

A use-after-free vulnerability was found in the Linux kernel's USB PHY isp1301 driver. The issue arises from a recent change that fixed a device reference leak in a UDC driver, which introduced a potential use-after-free in the non-OF case. The isp1301_get_client() helper only increases the reference count for the returned I2C device in the OF case, leading to a potential use-after-free when the caller de [truncated]

MEDIUM Linux CVE published 2026-01-14

CVE-2025-71142

A Linux kernel vulnerability triggers a warning when disabling a remote partition due to ineffective CPU management. This issue arises when a CPU is offlined, causing subpartitions_cpus to be cleared. Consequently, partitions are forced to share CPUs with the top_cpuset, leading to a warning about effective_xcpus not being a subset of subpartitions_cpus. The fix involves emitting the warning only if subpa [truncated]

HIGH Linux CVE published 2026-01-14

CVE-2025-71136

The Linux kernel was vulnerable to possible out-of-bounds array accesses in the `adv7842_cp_log_status()` function due to unchecked return values from `cp_read()` and `hdmi_read()`. This could lead to system crashes or potentially code execution if exploited. The issue has been resolved by adding necessary checks for these return values. Linux kernel maintainers and users should review and apply the provi [truncated]

HIGH Linux CVE published 2026-01-14

CVE-2025-71130

A NULL pointer dereference vulnerability was found in the Linux kernel's drm/i915/gem module. The vulnerability occurs during the execution of the eb_lookup_vmas() function, which is used to look up virtual memory areas (VMAs) for a given buffer. If the eb_add_vma() function fails, it does not set the vma pointer to NULL, leading to a NULL pointer dereference when trying to clean up the mess. The vulnerab [truncated]

HIGH Linux CVE published 2026-01-14

CVE-2025-71128

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-14T15:16:02.547Z and has not been modified since then. The NVD entry is currently Modified. The Linux kernel vulnerability CVE-2025-71128 involves a buffer overflow issue in the erspan code. The problem arises from the incorrect handling of the options_len field in the struct ip_tunnel_info, which h [truncated]

HIGH Linux CVE published 2026-01-14

CVE-2025-71127

The Linux kernel vulnerability CVE-2025-71127 is related to the mac80211 module. It allows an attacker to send a unicast Beacon frame to an associated STA to potentially get it to do something, such as moving to another channel. This vulnerability has a high CVSS score of 7.1 and affects Linux kernel versions 5.7.1 to 6.19. The NVD entry is currently Modified. AI-assisted PatchSiren debrief based on the s [truncated]

HIGH Linux CVE published 2026-01-14

CVE-2025-71126

A deadlock vulnerability was found in the Linux kernel's MPTCP implementation. The issue occurs when the packet scheduler attempts to reinject a packet after receiving an MP_FAIL and before the infinite map has been transmitted, causing a deadlock. This vulnerability affects Linux kernel developers and maintainers, network administrators, and users of Linux-based systems. The issue is caused by a missing [truncated]

CRITICAL Linux CVE published 2026-01-14

CVE-2025-71116

A critical vulnerability has been identified in the Linux kernel, specifically in the libceph component. The vulnerability is related to the decode_pool function, which has been found to be susceptible to out-of-bounds reads when dealing with corrupted osdmaps. This could potentially lead to security issues if exploited. The issue has been addressed through a series of patches provided by the Linux kernel [truncated]

HIGH Linux CVE published 2026-01-13

CVE-2025-71100

The Linux kernel vulnerability CVE-2025-71100 is caused by a potential array-index-out-of-bounds error in the rtlwifi driver. The issue arises from the TID value obtained from ieee80211_get_tid() which may exceed the array size of sta_entry->tids[]. To fix this, a check is added to ensure that the TID is less than MAX_TID_COUNT. Users of the Linux kernel, especially those using versions 6.9.1 to 6.12.64, [truncated]

CRITICAL Linux CVE published 2026-01-13

CVE-2025-71093

The Linux kernel was vulnerable to an out-of-bounds (OOB) read issue in the e1000 driver, specifically in the e1000_tbi_should_accept function. This could occur when the descriptor-reported length of a frame is zero or larger than the actual RX buffer size, leading to a read that goes out of bounds and potentially hits unrelated slab objects. The issue was observed from the NAPI receive path (e1000_clean_ [truncated]

HIGH Linux CVE published 2026-01-13

CVE-2025-71090

A vulnerability in the Linux kernel's nfsd subsystem has been identified. The nfsd4_add_rdaccess_to_wrdeleg() function was found to leak a reference to a nfsd_file object, potentially leading to open conflicts on files and causing the __nfsd_file_cache_purge() function to encounter files with elevated reference counts that cannot be cleaned up. This issue arises when a client already has a SHARE_ACCESS_RE [truncated]

HIGH Linux CVE published 2026-01-13

CVE-2025-71080

A race condition vulnerability was found in the Linux kernel's IPv6 implementation. The issue occurs in the rt6_get_pcpu_route() function under PREEMPT_RT kernels. When rt6_get_pcpu_route() returns NULL, the current task can be preempted, allowing another task to execute rt6_make_pcpu_route() and install a pcpu_rt entry. When the first task resumes, its cmpxchg() in rt6_make_pcpu_route() fails due to rt6i [truncated]

HIGH Linux CVE published 2026-01-13

CVE-2025-71078

The Linux kernel's software SLB preload cache can become inconsistent with the hardware SLB when the kernel skips switch_mmu_context() in switch_mm_irqs_off(). This inconsistency can lead to stale SLB entries being retained in the hardware SLB, causing a multihit error when the kernel attempts to reload those entries. The affected product is Linux kernel versions from 4.20.1 to 5.10.248, 5.11 to 5.15.198, [truncated]

HIGH Linux CVE published 2026-01-13

CVE-2025-71074

The Linux kernel's functionfs has a use-after-free vulnerability due to a race condition between opening and removing files. This can lead to UAF on subsequent read or write operations. The fix involves serializing openers, using atomic_inc_not_zero() for dynamic files, marking inodes on removal, and verifying file state during open operations. Affected Linux kernel users and maintainers should be aware o [truncated]

HIGH Linux CVE published 2026-01-13

CVE-2025-71072

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-13T16:16:06.633Z and has not been modified since then. The NVD entry is currently Modified. The Linux kernel vulnerability CVE-2025-71072 relates to shmem recovery on rename failures. Maple_tree insertions can fail under serious memory shortage; simple_offset_rename() and simple_offset_rename_exchan [truncated]

HIGH Linux CVE published 2026-01-13

CVE-2025-71070

A vulnerability in the Linux kernel has been resolved, related to the ublk server exit and user copy references. The issue arises when a ublk server process releases a ublk char device file, but requests dispatched to the ublk server but not yet completed retain a reference value. This leaked reference count allows user copy and zero copy operations on the completed ublk request and triggers warnings in u [truncated]

CRITICAL Linux CVE published 2026-01-13

CVE-2025-71068

A critical vulnerability has been identified in the Linux kernel, specifically in the svcrdma component. The vulnerability is caused by a lack of bounds checking on the rq_pages index in the inline path, which could allow an attacker to access sensitive information or execute arbitrary code. The vulnerability has been assigned a CVSS score of 9.8 and is considered CRITICAL.

HIGH Linux CVE published 2026-01-13

CVE-2025-71066

CVE-2025-71066 is a Linux kernel net/sched ETS qdisc race condition that can leave a class on the active list after its qdisc has been freed, creating a use-after-free in struct Qdisc. The supplied source says an attacker needs the ability to create new user and network namespaces to trigger the bug. The referenced fix removes the class from the active list before deleting and freeing the associated qdisc.

MEDIUM Linux CVE published 2026-01-13

CVE-2025-68823

A local deadlock vulnerability in the Linux kernel's ublk (userspace block device) subsystem can cause system hangs when processes attempt to read partition tables from ublk block devices. The deadlock occurs when bdev_open() acquires disk->open_mutex, issues I/O to the ublk backend, and completion handling triggers a deferred fput() that attempts to reacquire the same mutex via blkdev_release(). The fix [truncated]

HIGH Linux CVE published 2026-01-13

CVE-2025-68822

A use-after-free vulnerability was found in the Linux kernel's ALPS touchpad driver. The dev3_register_work delayed work item was not properly canceled during device detachment, allowing it to be scheduled after the alps_data structure had been deallocated. This can cause a use-after-free vulnerability in the Linux kernel's ALPS touchpad driver. The vulnerability can be mitigated by applying the patches p [truncated]

HIGH Linux CVE published 2026-01-13

CVE-2025-68819

An out-of-bounds vulnerability exists in the Linux kernel's media dvb-usb module, specifically in the dtv5100_i2c_msg() function. The rlen value, which is user-controlled, is not checked for size, potentially leading to an out-of-bounds vulnerability for st->data. To mitigate this, proper range checking should be added to prevent such vulnerabilities.