These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2022-2586 is a Linux Kernel use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2024-06-26, with remediation due by 2024-07-17. Because it is on the KEV list, defenders should treat it as a priority patching item and follow vendor guidance promptly. CISA’s notes also indicate this affects a common open-source component used by different products, so dow [truncated]
A vulnerability in the F2FS (Flash-Friendly File System) compression implementation affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control devices. The flaw involves filesystem metadata corruption—including block addresses in dnodes, inode fields, and the total_valid_block_count field—following a Sudden Power Off (SPO) event. This can lead to filesystem integrity issues and p [truncated]
A vulnerability in the F2FS (Flash-Friendly File System) compression implementation affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial controllers. The flaw occurs during partial truncation of compressed inodes, where valid block counts may change without corresponding updates to .i_blocks and .total_valid_block_count metadata fields, leading to potential filesystem corruption. T [truncated]
CVE-2024-1086 is a Linux Kernel use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2024-05-30. CISA also flags known ransomware campaign use as "Known," which makes this a high-priority issue for defenders running Linux kernel-based systems or products that embed the kernel. The KEV entry sets a remediation due date of 2024-06-20 and directs organizations [truncated]
A use-after-free vulnerability exists in the Linux kernel's mac80211 Wi-Fi subsystem when handling station VLAN changes. The issue occurs when moving a station out of a VLAN and subsequently deleting that VLAN—the fast_rx entry retains a pointer to the freed VLAN's network device, leading to potential memory corruption. This vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control systems t [truncated]
A race condition vulnerability exists in the Linux kernel's netfilter nf_tables subsystem. The commit mutex was incorrectly released during a critical section between nft_gc_seq_begin() and nft_gc_seq_end(), allowing an asynchronous garbage collection worker to potentially collect expired objects and acquire the released commit lock within the same GC sequence. This occurs specifically in the abort path w [truncated]
CVE-2024-26880 is a Linux kernel device-mapper flaw that can lead to a kernel crash during suspend/resume handling. The underlying issue was an incorrect pairing of postsuspend and resume callbacks: two consecutive postsuspend calls could attempt to remove the same list entry twice, corrupting kernel list state. The fix updates __dm_internal_resume to invoke the table targets’ preresume and resume methods [truncated]
CVE-2024-26877 is a Linux kernel issue in the Xilinx crypto driver finalize path. According to the kernel fix note, crypto_finalize_request must be called with bottom halves disabled; otherwise the crypto engine can trigger a kernel WARNING and call trace during AEAD request completion. The NVD record rates the issue as medium severity, with availability impact only.
CVE-2024-26872 is a Linux kernel RDMA/srpt use-after-free issue that can occur when an event handler is registered before the srpt device is fully initialized. According to the NVD record and linked kernel patches, a rare error-path race can leave a partially set up event handler in place and later lead to a KASAN-reported use-after-free write in srpt_refresh_port(). The corrective change is to defer even [truncated]
CVE-2024-26870 describes a Linux kernel NFSv4.2 bug in listxattr() handling that can reach a kernel BUG in mm/usercopy.c when buffer sizing is mishandled. The published fix adds an ERANGE return when nfs4_listxattr() is called with size > 0 and the required length is greater than the supplied buffer. NVD rates the issue CVSS 5.5/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, reflecting a local availability impact r [truncated]
CVE-2024-26851 is a Linux kernel issue in netfilter’s nf_conntrack_h323 decoder where malformed input could make the extension bitmap length grow beyond 32 and drive an invalid shift operation. The result is undefined behavior detected by UBSAN, and the fix adds a bounds check so decoding stops with an out-of-range error instead of continuing with unsafe bitmap lengths.
This CVE addresses an incorrect length field in USB MIDI Streaming descriptors within the Linux kernel's USB gadget subsystem. The vulnerability exists in the f_midi driver, which is responsible for implementing USB MIDI functionality when a Linux system operates as a USB device (gadget mode). The descriptor length miscalculation could lead to out-of-bounds memory access or parsing errors when a host syst [truncated]
CVE-2024-42114 is a medium-severity vulnerability (CVSS 3.1: 4.4) in the Linux kernel's cfg80211 wireless configuration subsystem. The flaw involves improper restriction of NL80211_ATTR_TXQ_QUANTUM values, which can lead to denial of service conditions. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. [truncated]
A deadlock vulnerability exists in the Linux kernel's pinctrl subsystem within the create_pinctrl() function. The issue arises from improper mutex handling when add_setting() returns -EPROBE_DEFER, causing create_pinctrl() to call pinctrl_free() while still holding pinctrl_maps_mutex. Since pinctrl_free() attempts to acquire the same mutex, this creates a classic lock-order violation resulting in potentia [truncated]
A denial-of-service vulnerability exists in the Linux kernel's Device Mapper (dm) snapshot subsystem. When a snapshot with many exceptions is exited, the kernel can lock up due to a tight loop in dm_exception_table_exit that lacks scheduling points. The fix adds cond_resched() to yield the CPU during exception cleanup. Siemens has confirmed this affects the GNU/Linux subsystem in SIMATIC S7-1500 TM MFP in [truncated]
CVE-2024-27437 is a Linux kernel VFIO/pci issue in exclusive INTx interrupt handling. On devices that need masking at the irqchip and do not support DisINTx, the kernel could enable the IRQ during request_irq() and then disable it afterward to match the masked state. That brief window created a race: if the interrupt fired in between, the disable depth could be incremented twice and become unrecoverable f [truncated]
A vulnerability in the Linux kernel's ALSA USB audio driver could allow a local attacker to cause a denial of service. The flaw occurs when parsing channel bits from USB audio devices that set more bits than the declared number of channels, potentially causing an out-of-bounds write to the channel map array. This affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that include a GNU/Linux su [truncated]
A null pointer dereference vulnerability exists in the Linux kernel's Bluetooth RFCOMM subsystem, specifically within the rfcomm_check_security function. This flaw can lead to a local denial-of-service condition when exploited by an authenticated attacker with low privileges. The vulnerability affects Siemens SIMATIC S7-1500 TM MFP industrial control systems that utilize the GNU/Linux subsystem, where Blu [truncated]
CVE-2024-26875 is a Linux kernel use-after-free in the pvrusb2 USB media driver. The reported KASAN trace shows pvr2_context_set_notify() dereferencing freed memory during disconnect handling, and the fix moves the disconnect_flag assignment to the end of pvr2_context_disconnect() so another thread cannot free the shared object too early.
CVE-2024-26861 is a Linux kernel WireGuard issue in the receive path where KCSAN reported a data race involving receiving_counter.counter. The upstream fix uses READ_ONCE() and WRITE_ONCE() annotations to mark the concurrent access as intentional. NVD rates the issue as medium severity, with local access required and availability impact as the primary concern.
CVE-2024-26859 describes a race condition in the Linux kernel's bnx2x network driver that can surface during EEH error recovery and reset handling. In affected paths, transmit-timeout recovery and EEH slot reset logic can overlap while SGEs/page-pool pages are being freed, which can lead to access to freed memory and a system crash. NVD rates the issue as medium severity with local attack requirements and [truncated]
CVE-2024-26855 is a Linux kernel availability issue in the ice network driver path. The bug can lead to a NULL pointer dereference in ice_bridge_setlink() when nlmsg_find_attr() returns NULL and the code later iterates nested attributes. The fix adds a NULL check before entering the nested-attribute loop. NVD rates the issue medium severity (CVSS 5.5).
CVE-2024-26852 is a Linux kernel IPv6 use-after-free in the multipath route notification path. The issue was found by syzbot and confirmed by KASAN, with the supplied record showing a slab-use-after-free in rt6_fill_node reached through ip6_route_mpath_notify().
CVE-2024-26820 affects the Linux kernel’s hv_netvsc driver and can cause virtual function registration to be missed when the driver is unloaded and reloaded. The result is a networking disruption issue rather than a confidentiality or integrity flaw. NVD rates it as a medium-severity local problem with high availability impact.
CVE-2024-26816 is a Linux kernel hardening issue in x86 relocation handling for the .notes section. On kernels built with CONFIG_XEN_PV=y, symbols are emitted into .notes so Xen can find the startup_xen entry point. The flaw is that applying relocations there can expose KASLR-related address information through the world-readable /sys/kernel/notes interface. The fix is to skip relocations in .notes so the [truncated]
CVE-2024-26787 is a Linux kernel issue in the mmci/stm32 MMC DMA path where an error-handling branch could leave scatter-gather DMA mappings unbalanced. In affected builds, CONFIG_DMA_API_DEBUG_SG can report overlapping mappings and cacheline tracking warnings because dma_map_sg and dma_unmap_sg are not correctly paired on certain error paths. The issue was fixed in upstream/stable kernel patches referenc [truncated]
CVE-2024-26651 is a Linux kernel issue in the sr9800 USB network driver where failure from usbnet_get_endpoints() was not properly checked and propagated. The published fix adds error handling so the driver stops on endpoint setup failure instead of continuing with invalid state. NVD rates the issue as medium severity with local, low-privileged, no-user-interaction conditions and high availability impact.
CVE-2024-26629 affects the Linux kernel NFS server (nfsd) handling of NFSv4 RELEASE_LOCKOWNER. According to the supplied record, the original so_count-based test could return a false NFS4ERR_LOCKS_HELD even when no locks were actually held, creating a protocol violation and incorrect client behavior. The issue was published on 2024-03-13 and is rated medium severity in the supplied NVD data.
CVE-2024-25739 affects the Linux kernel’s UBI code path in drivers/mtd/ubi/vtbl.c. The issue is a missing check for ubi->leb_size in create_empty_lvol, which can lead to an attempt to allocate zero bytes and crash the kernel. The CVE was published on 2024-02-12 and the record was later modified on 2026-05-12.
CVE-2024-24859 describes a race condition in the Linux kernel's Bluetooth networking code, specifically in sniff_{min,max}_interval_set(). According to NVD, the issue can trigger a Bluetooth sniffing exception and may lead to denial of service. The CVE is publicly disclosed and mapped by NVD to CWE-362 (race condition).