These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2024-24858 is a race condition in the Linux kernel Bluetooth stack that can disrupt I2CAP connection or broadcast behavior and may lead to denial of service. NVD rates it Medium severity (CVSS 4.6) and identifies affected Linux kernel ranges across multiple release lines.
CVE-2024-24857 is a Linux kernel Bluetooth issue involving a race condition in conn_info_{min,max}_age_set(). According to the CVE record, the flaw can lead to an integrity overflow and may cause Bluetooth connection abnormality or denial of service. The issue is rated medium severity, but it still matters for systems that rely on Bluetooth connectivity or run affected kernel builds.
CVE-2024-23848 is a Linux kernel use-after-free in the CEC message handling path, specifically cec_queue_msg_fh in the drivers/media/cec/core code. NVD lists the issue as affecting Linux kernel versions through 6.7.1 and scores it 5.5 (MEDIUM) with local, low-privilege access and high availability impact. For defenders, this is primarily a kernel-stability and availability concern, with the usual urgency [truncated]
CVE-2024-23307 is a Linux kernel vulnerability classified by NVD as a CWE-190 integer overflow/wraparound issue. The CVSS 3.1 score is 4.4 (AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H), so the main concern is availability rather than data compromise. NVD’s affected-version criteria show multiple vulnerable release bands, making kernel update hygiene the key mitigation.
CVE-2024-22099 describes a NULL pointer dereference in the Linux kernel Bluetooth RFCOMM path, specifically in net/bluetooth/rfcomm/core.C. The supplied record assigns CVSS 3.1 6.3 (MEDIUM) with network attack vector, low privileges required, no user interaction, and high availability impact. The source record was published on 2024-01-25 and later modified on 2026-05-12; the modification date should not b [truncated]
CVE-2023-52458 is a Linux kernel block-layer bug in partition handling. When a partition is added or resized without checking alignment to the disk’s logical block size, reads of the final sector can be truncated into an I/O error on systems with logical block sizes larger than 512 bytes. If integrity data is enabled, the same condition can also lead to a NULL pointer dereference. NVD rates the issue CVSS [truncated]
CVE-2023-47233 affects the Linux kernel’s brcm80211/brcmfmac code path handling device unplugging. NVD rates it 4.3 (medium) and describes it as a use-after-free that may be exploitable by a physically proximate attacker with local access. The issue was published on 2023-11-03 and later modified on 2026-05-12; no KEV entry is present in the supplied data.
CVE-2023-1652 is a use-after-free flaw in Linux kernel NFS server code that can let a local attacker crash the system or potentially expose kernel information. NVD lists it as high severity, with low attack complexity but requiring local privileges. The issue affects specific Linux kernel version ranges and is tracked by vendor and third-party advisories.
CVE-2022-38096 is a Linux kernel vmwgfx NULL pointer dereference issue. The NVD record identifies affected Linux kernel versions starting at 4.20 and rates the issue CVSS 3.1 6.3 MEDIUM (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H). In practical terms, a local attacker with an account and user interaction could trigger a kernel fault that may lead to denial of service, with the record also noting low integrity impact.
CVE-2021-47002 is a Linux kernel SUNRPC issue that can trigger a null pointer dereference in svc_rqst_free(). According to the CVE description, if alloc_pages_node() returns null in svc_rqst_alloc(), the resulting rq_scratch_page can later be passed to put_page() without a null check. The result is a crash condition rather than a confidentiality or integrity compromise.
CVE-2024-26812 is a Linux kernel VFIO/PCI issue in INTx interrupt handling. The supplied NVD record describes a path where the INTx eventfd could be deconfigured, unregistering the IRQ handler while later irqfd or SET_IRQS paths could still signal an eventfd with a NULL context. The published fix changes how the INTx handler is managed and adds synchronization so the trigger can be updated safely while in [truncated]
CVE-2024-26810 is a Linux kernel VFIO PCI race condition involving INTx masking and interrupt-configuration changes. The flaw occurs when mask operations through config-space changes to DisINTx can race ioctl-driven INTx configuration changes. The result is an unsafe interrupt state transition path that can affect availability.
CVE-2024-26659 is a Linux kernel xHCI bug in isochronous transfer error handling. According to the public record, the driver could incorrectly assume ownership of a multi-TRB transfer descriptor after early error events, which could lead to freed or overwritten descriptors and incorrect completion handling. The issue is rated medium severity and primarily affects availability, with the NVD vector indicati [truncated]
CVE-2024-26643 is a Linux kernel netfilter/nf_tables race condition affecting anonymous sets with timeouts. NVD rates it Medium (CVSS 5.5), and the issue is described as an asynchronous garbage-collection race that can interfere with set teardown and lead to denial of service on vulnerable kernels. The fix marks the set dead so async GC skips it during release and abort handling.
CVE-2024-26642 is a Linux kernel nf_tables issue that was fixed by rejecting anonymous sets with the timeout flag, except where NFT_SET_EVAL is needed for legacy meter support. The CVE is rated medium severity and is primarily a defensive maintenance concern for systems running affected kernel branches.
CVE-2023-52620 affects the Linux kernel’s netfilter nf_tables path. According to the CVE description, the fix disallows timeout parameters for anonymous sets because those parameters were never intended to be used from userspace. NVD rates the issue as LOW severity with local access, low privileges, high attack complexity, and availability-only impact. The record also links multiple stable-kernel patch re [truncated]
CVE-2023-52614 is a Linux kernel memory-safety issue in PM/devfreq’s trans_stat_show() path. According to the CVE record and referenced kernel patches, the function could overrun its output buffer while building transition statistics. The fix replaces snprintf with scnprintf, stops when PAGE_SIZE would be exceeded, emits a warning that statistics are disabled, and returns -EFBIG when the full table cannot [truncated]
CVE-2021-47107 is a Linux kernel NFSD memory-corruption issue in the READDIR path. According to NVD and the kernel fix notes, a too-small READDIR count can underflow the buffer-size calculation in the new init_dirlist helper, which can then allow XDR reserve/write logic to go past the intended buffer. NVD rates the issue 7.8 HIGH and lists affected Linux kernel builds in the 5.13 to 5.15.12 range, plus 5. [truncated]
CVE-2023-52447 is a Linux kernel BPF use-after-free issue in the handling of inner maps. When an inner map is updated or deleted from an outer map, BPF programs may still access it. The kernel fix defers the final free until after the required RCU and tasks trace RCU grace periods, reducing the risk that a BPF program can touch freed memory.
CVE-2024-42096 is a medium-severity vulnerability (CVSS 5.1) in the Linux kernel affecting Siemens SIMATIC S7-1500 TM MFP industrial control systems with GNU/Linux subsystem. The vulnerability, published April 9, 2024, involves unsafe stack manipulation in the x86 `profile_pc()` function that could lead to out-of-bounds read conditions. The issue was resolved in the upstream Linux kernel by eliminating st [truncated]
CVE-2024-26878 is a Linux kernel vulnerability in quota handling that can lead to a NULL pointer dereference during a race between inode quota teardown and quota-off processing. NVD lists impacted Linux kernel release ranges across multiple stable branches, and the kernel fix replaces the direct pointer use with a temporary reference to avoid the race window. The primary impact is availability, consistent [truncated]
CVE-2024-26863 is a Linux kernel vulnerability in the HSR code path, published on 2024-04-17. A packet with ETH_P_PRP or ETH_P_HSR that is not followed by an HSR tag can cause hsr_get_node() to use an invalid uninitialized sequence number, leading to an availability impact rated CVSS 5.5/MEDIUM.
CVE-2023-6817 is a Linux kernel netfilter:nf_tables use-after-free issue that can be used for local privilege escalation. The flaw is tied to nft_pipapo_walk failing to skip inactive elements during set walking, which can lead to double deactivation of PIPAPO elements and then use-after-free. NVD lists affected Linux kernel version ranges across multiple release lines, and the upstream fix is identified b [truncated]
CVE-2023-45898 is a high-severity Linux kernel flaw in ext4’s extents status handling. NVD describes it as an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent. The vulnerable range is Linux kernel 6.5 up to, but not including, 6.5.4. From a defensive standpoint, the key action is to move affected systems to 6.5.4 or a later kernel that includes the fix and to prioritize hos [truncated]
A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. The vulnerability is caused by a reference counter issue in the tcf_change_indev() and u32_set_parms() functions. If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.
CVE-2014-0196 is a Linux kernel race condition vulnerability that CISA has listed in the Known Exploited Vulnerabilities (KEV) catalog. In the supplied corpus, CISA’s guidance is explicit: if the impacted product is end-of-life and still in use, it should be disconnected. No CVSS score, affected-version range, or patch details are provided in the supplied sources.
CVE-2010-3904 is a Linux Kernel improper input validation issue that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied CISA guidance treats impacted systems as legacy risk: the affected product is end-of-life and should be disconnected if still in use. That makes asset discovery and isolation the main defensive priority where this kernel lineage is still present.
CVE-2023-0266 is a Linux kernel use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-03-30, with remediation due by 2023-04-20. The official guidance is to apply vendor updates, and the kernel stable-queue patch referenced in the source notes indicates a fix in the ALSA PCM area aimed at preventing the UAF.
CVE-2021-3493 is a Linux kernel privilege escalation vulnerability that CISA has placed in the Known Exploited Vulnerabilities catalog. That KEV listing indicates the issue has been observed in active exploitation, so defenders should treat Linux kernel patching and verification as a priority. The supplied official sources do not provide affected versions or deeper technical root-cause details, so remedia [truncated]
CVE-2013-6282 is a Linux Kernel improper input validation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. In the supplied timeline, CISA added it on 2022-09-15 and set a remediation due date of 2022-10-06. Because it is KEV-listed, organizations should treat remediation as urgent and follow vendor update guidance promptly.