PatchSiren

Linux CVE debriefs · Page 20

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-09-09

CVE-2026-80914

A use-after-free vulnerability exists in the Linux kernel's Bluetooth ISO subsystem, specifically in the `iso_conn_ready` function. This function attempts to create a child socket from a listener socket that has been concurrently closed, leading to a potential use-after-free error when the child socket is later disconnected. The issue affects Linux kernel versions and could allow for system crashes or pot [truncated]

Review Linux CVE published 2026-09-04

CVE-2026-80912

The Linux kernel vulnerability in selinux security_get_classes() allows for NULL pointer dereference. This vulnerability was published on 2026-09-04T18:18:01.047Z and was last modified on 2026-09-14T13:18:48.763Z. The vulnerability exists in the selinux security_get_classes() function, which can lead to a NULL pointer dereference. The vulnerability has been resolved by rejecting unclaimed class values. Li [truncated]

Review Linux CVE published 2026-09-04

CVE-2026-80909

The Linux kernel has a vulnerability in the drm/amdgpu module that has been resolved. The fix involves rejecting UVD messages with an invalid number of h265 references to avoid overflow when calculating the minimum dpb size. This vulnerability requires attention from Linux kernel developers and administrators responsible for maintaining systems with the drm/amdgpu module to verify system exposure and appl [truncated]

Review Linux CVE published 2026-09-04

CVE-2026-80908

The Linux kernel has a vulnerability, tracked as CVE-2026-80908, that could lead to a potential overflow in DPB size calculations. This issue was resolved by rejecting UVD messages with dimensions above 4096. The vulnerability affects Linux kernel deployments, particularly those using AMD GPUs. Administrators should verify affected product deployments, review official advisories, and plan vendor-supported [truncated]

Review Linux CVE published 2026-09-04

CVE-2026-80907

A vulnerability in the Linux kernel has been resolved, affecting the drm/amdgpu component. The issue is related to the UVD dpb min size calculation for H264. This should use the actual number of references from the decode message, instead of the maximum derived from level. Linux kernel developers and maintainers, as well as users and administrators who rely on the Linux kernel in their systems, should ver [truncated]

Review Linux CVE published 2026-09-04

CVE-2026-80899

The Linux kernel has removed the EROFS over fscache feature due to its deprecation and newly found implementation issues. This feature was introduced for image lazy pulling functionality but has been replaced by EROFS file-backed mounts and fanotify pre-content hooks. The main application of this feature, Nydus, plans to move to using fanotify pre-content hooks.

Review Linux CVE published 2026-09-04

CVE-2026-80888

A vulnerability in the Linux kernel's drm/vmwgfx component can cause a reference leak when handling prime imports of foreign file descriptors, potentially leading to resource pinning. This issue was resolved by ensuring the dma_buf reference is always dropped in the error path. The vulnerability allows unprivileged renderD clients to leak one dma_buf reference per call, indefinitely pinning the foreign ex [truncated]

Review Linux CVE published 2026-09-04

CVE-2026-80883

A vulnerability in the Linux kernel's drm/tegra component has been addressed. The host1x_client_register() function was called before initializing the address register map, potentially allowing userspace to submit jobs prematurely. The fix involves moving register initialization before host1x client registration. This change ensures that the register map is fully initialized before the device is made avai [truncated]

Review Linux CVE published 2026-09-04

CVE-2026-80878

A Linux kernel vulnerability has been resolved, involving a fix for a leak of an ungot volume in the afs_lookup_volume_rcu() function. This issue affects Linux kernel deployments and requires verification of kernel version and potential patch application to prevent issues. The vulnerability has been publicly disclosed and requires immediate attention from Linux kernel administrators and developers to ensu [truncated]

Review Linux CVE published 2026-09-03

CVE-2026-80756

A vulnerability in the Linux kernel has been resolved, related to SELinux policy loading. The issue arises when selinux_policy_cancel() is called without an outgoing policy, leading to a NULL dereference. This occurs on the first policy load if it fails while building the selinuxfs tree. The vulnerability is caused by a NULL dereference in selinux_policy_cancel() when there is no outgoing policy. The issu [truncated]

Review Linux CVE published 2026-09-03

CVE-2026-80755

The Linux kernel's SELinux implementation has a vulnerability, CVE-2026-80755, which allows for an out-of-bounds heap write due to improper bounding of permission values. This issue arises from the perm_read() function not properly checking the number of permissions (nprim) in the owning class or common. As a result, Linux kernel users and administrators, SELinux policy developers, and cybersecurity teams [truncated]

HIGH Linux CVE published 2026-09-03

CVE-2026-80754

A vulnerability was found in the Linux kernel's synaptics-rmi4 module. During F55 sensor detection, a typo led to the incorrect assignment of the transmitter electrode count, which was then used to determine diagnostics report size. This could lead to incorrect report size calculations and potential out-of-bounds buffer accesses. The issue arises from a copy-paste error in the F55 sensor detection code, w [truncated]

HIGH Linux CVE published 2026-09-03

CVE-2026-80751

The Linux kernel vulnerability, CVE-2026-80751, is related to the pmdomain: mediatek: mfg module. The issue arises from the variable prev_o being used before it's initialized in the mtk_mfg_attach_dev function. This could lead to a potential fault or incorrect skipping of the first OPP. Users and administrators of systems running the affected Linux kernel version should take action to update their systems [truncated]

HIGH Linux CVE published 2026-09-03

CVE-2026-80750

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-03T13:06:14.650Z and has not been modified since then. The vulnerability exists in the Linux kernel, specifically in the pmdomain: mediatek component. It has been resolved by fixing the remaining %pOF after of_node_put(). The scpsys_get_bus_protection_legacy() function looks up several legacy bus pr [truncated]

HIGH Linux CVE published 2026-09-03

CVE-2026-80748

The CVE-2026-80748 vulnerability involves a fix for incorrect sg iteration in Loongson2 mmc reorder functions within the Linux kernel. The issue lies in ls2k0500_mmc_reorder_cmd_data() and ls2k2000_mmc_reorder_cmd_data(), where the for_each_sg() macro is used. However, the code incorrectly indexes 'sg' as if it were an array base, leading to access of wrong sg entries or out-of-bounds errors if the list i [truncated]

HIGH Linux CVE published 2026-09-03

CVE-2026-80747

A vulnerability has been identified in the Linux kernel, specifically in the drm/amdkfd component. The CRAT parser does not properly validate the subtype length, leading to potential out-of-bounds reads. This issue has been resolved with the addition of bounds checking. The vulnerability affects the Linux kernel drm/amdkfd component, which is used for managing GPU resources. The CRAT (Component Resource A [truncated]

HIGH Linux CVE published 2026-09-03

CVE-2026-80745

The Linux kernel vulnerability, CVE-2026-80745, relates to the regulator: fp9931 module. The VPOSNEG_table[] mapping does not match the FP9931 datasheet, potentially causing issues with voltage selector tables. The datasheet defines the VPOS/VNEG voltage mapping as: 00h-04h -> 7.04V (-7.04V), 05h -> 7.26V (-7.26V), 06h -> 7.49V (-7.49V), ..., 28h-3Fh -> 15.06V (-15.06V). However, VPOSNEG_table[] has two i [truncated]

Review Linux CVE published 2026-09-03

CVE-2026-80744

The Linux kernel vulnerability CVE-2026-80744 involves a fix for a warning condition in the netfilter subsystem, specifically in the nf_tables_offload module. The warning was incorrectly triggered on memory allocation failures. The fix changes the warning condition to ignore -ENOMEM errors, aligning with common kernel practices. This vulnerability affects systems using nf_tables and could be triggered und [truncated]

Review Linux CVE published 2026-09-03

CVE-2026-80743

A Linux kernel vulnerability was resolved, affecting the ASoC xilinx formatter_pcm driver. The irq handlers were not properly set up, causing a potential crash when an interrupt occurred before the driver data was set. This issue arises because the driver data is only set at the end of probe, after devm_request_irq(). To address this, the private data should be passed directly as the devm_request_irq() ar [truncated]

Review Linux CVE published 2026-09-03

CVE-2026-80742

The Linux kernel has a vulnerability in the af_packet component. When sending 0-byte packets via TPACKET ring buffer on devices with no hard header, tpacket_fill_skb() populates an skb with skb->len == 0 and returns 0. tpacket_snd() then forwards this empty skb to packet_xmit(), causing __dev_queue_xmit() to hit skb_assert_len(skb). This issue can be mitigated by rejecting zero-length packets in tpacket_s [truncated]

HIGH Linux CVE published 2026-09-03

CVE-2026-80737

A vulnerability in the Linux kernel has been resolved, involving the amba-pl011 serial driver. The issue arises from the use of dmaengine_terminate_all(), which does not wait for a running callback, potentially allowing the TX callback to access the TX buffer after it has been freed. Additionally, the RX poll timer reads RX buffers without the port lock. The fix involves switching to dmaengine_terminate_s [truncated]

HIGH Linux CVE published 2026-09-03

CVE-2026-80736

The CVE-2026-80736 vulnerability affects the Linux kernel's thunderbolt subsystem, involving a bandwidth group reservation indexing issue. The problem arises from the group_reserved[] array not being properly sized, leading to potential out-of-bounds access. The issue has been resolved by increasing the size of group_reserved[] to MAX_GROUPS + 1, ensuring direct Group ID indexing covers the reserved ID 0 [truncated]

HIGH Linux CVE published 2026-09-03

CVE-2026-80735

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-03T13:06:12.343Z and has not been modified since then. The CVE-2026-80735 vulnerability in the Linux kernel was resolved by adding a validation check to ensure that the socket is owned by ovpn before dereferencing sk_user_data. This prevents potential out-of-bounds reads that could occur when subsys [truncated]

HIGH Linux CVE published 2026-09-03

CVE-2026-80734

A Linux kernel vulnerability allows for a crash when handling a specific file system operation in the btrfs file system. The issue arises from a missing initialization of inode mapping flags for cached inodes, which can lead to an assertion failure. This vulnerability has been resolved with a patch that ensures the proper initialization of these flags. The patch moves the btrfs_update_inode_mapping_flags( [truncated]

Review Linux CVE published 2026-09-03

CVE-2026-80733

The CVE-2026-80733 vulnerability involves a fix for the `sk_mc_loop()` function in the Linux kernel. The function can be called for sockets that are neither AF_INET nor AF_INET6, triggering a warning. The fix removes this warning for non-INET sockets, ensuring that loopback defaults to true without generating a warning. This change impacts Linux kernel users who should ensure their systems are updated wit [truncated]

Review Linux CVE published 2026-09-03

CVE-2026-80730

The Linux kernel vulnerability CVE-2026-80730 was resolved, involving a fix for the ring-buffer to prevent a crash when passing an error pointer to kthread_stop(). The issue arose during the test_ringbuffer() cleanup loop, where a check for NULL entries in rb_threads[] missed error pointer entries. This led to kthread_stop() being called with an erroneous pointer, causing a kernel crash during a late_init [truncated]

Review Linux CVE published 2026-09-03

CVE-2026-80729

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-03T13:06:11.417Z and has not been modified since then. The Linux kernel vulnerability CVE-2026-80729 relates to the mm/huge_memory module, specifically the initialization of the workingset state before folio split. This issue could lead to memory corruption. Affected systems should apply patches and [truncated]

Review Linux CVE published 2026-09-03

CVE-2026-80728

A vulnerability in the Linux kernel has been identified and resolved. The issue involves a revert of a previous commit related to aperture mapping leak in the AMD GPU driver. The problem arises during device probe failure or rollback, leading to a kernel page fault due to invalid memory access. This vulnerability affects Linux kernel users, particularly those utilizing AMD GPU drivers. The revert of the c [truncated]

Review Linux CVE published 2026-09-03

CVE-2026-80727

The Linux kernel vulnerability CVE-2026-80727 relates to the x86/mce and CMCI discovery. The issue arises from the polling timer being set up after CMCI discovery, leading to potential crashes. This vulnerability affects Linux kernel maintainers, users, and administrators. The fix involves setting up the timer before CMCI discovery. It is essential to review and update Linux kernel configurations to ensur [truncated]

CRITICAL Linux CVE published 2026-09-03

CVE-2026-80726

A use-after-free vulnerability was found in the Linux kernel's KVM subsystem. The issue occurs when creating a child shadow page, where the role.invalid flag is not cleared, leading to a potential use-after-free error. This vulnerability has been resolved with a patch that explicitly clears role.invalid when deriving a child shadow page's role from its parent.