PatchSiren

Linux CVE debriefs · Page 39

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Linux CVE published 2026-08-15

CVE-2026-72384

The Linux kernel vulnerability CVE-2026-72384 was resolved. The irqchip/ts4800 driver had a missing chained handler cleanup on remove. The driver installed a chained handler for the parent interrupt during probe but did not clear this handler during removal, potentially causing a kernel crash by accessing freed memory when the parent interrupt fires.

Review Linux CVE published 2026-08-15

CVE-2026-72383

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T06:22:11.813Z and has not been modified since then. The vulnerability is a use-after-free issue in the Linux kernel's sctp_free_addr_wq function, caused by a race condition with the sctp_addr_wq_timeout_handler function. This vulnerability may allow attackers to access freed memory, potentially l [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72382

A vulnerability in the Linux kernel has been resolved, where ksmbd rejects undersized DACLs before parsing ACEs. The vulnerability is caused by the parse_dacl() function not properly checking the DACL size, allowing an attacker to bypass the ACE count check and drive large temporary ACL state and pointer-array allocations. This issue can be exploited by a malicious client through SMB2_SET_INFO (InfoType=S [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72381

A use-after-free vulnerability was found in the Linux kernel's ksmbd module. The vulnerability occurs when two concurrent SMB2 durable reconnects race against the kfree() in ksmbd_reopen_durable_fd()'s reopen-success path, leading to a potential use-after-free of fp->owner.name in ksmbd_vfs_compare_durable_owner(). This issue arises from the lack of proper synchronization between the compare-read operatio [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72380

The Linux kernel vulnerability, CVE-2026-72380, allows for an out-of-bounds write due to a lack of range checking on req_id in pvcalls_front_event_handler(). This vulnerability has been resolved by declaring req_id as u32 to cover both ends. A backend that sends an out-of-range req_id has violated the wire protocol. Users of the Linux kernel, particularly those with confidential and disaggregated deployme [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72379

The Linux kernel had a vulnerability where the creation of temporary files with unmapped fsuid or fsgid on idmapped mounts could lead to files being owned by an invalid user or group. This has been resolved by adding a check in vfs_tmpfile(). The change ensures that file systems supporting idmapping and implementing ->tmpfile() now refuse O_TMPFILE creation with an unmapped fsuid or fsgid, maintaining own [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72377

The Linux kernel has a vulnerability that has been resolved, related to the handling of symlinks and mountpoints in the AFS file system. The AFS file system sets AS_RELEASE_ALWAYS for regular files, but not for symlinks and mountpoints, which can cause a pointer dereference when trying to release folios. This vulnerability has been resolved by removing the setting of AS_RELEASE_ALWAYS for symlinks and mou [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72376

The Linux kernel has a vulnerability in the afs component, tracked as CVE-2026-72376. This issue arises from the incorrect increment of the net->cells_outstanding counter before checking for failure of idr_alloc_cyclic(), potentially leading to incorrect counts on error. Linux kernel users and administrators should review their systems and ensure they are updated with the latest security patches to mitiga [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72375

The CVE-2026-72375 vulnerability is related to the Andrew File System (afs) module in the Linux kernel. The issue arises from the insufficient initialization of work_structs in the slab's init function, specifically with the afs_vnode::lock_work. This leads to a warning from the DEBUG_OBJECTS debugging mechanism when running tests like generic/131 xfstest. The fix involves reinitializing ->lock_work after [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72374

The Linux kernel's AFS filesystem client has a vulnerability in its callback service message parsers. This issue arises from the incorrect handling of the -EAGAIN return value, which could lead to improper parsing of incoming request streams. The vulnerability has been resolved through a patch that ensures the correct pass-through of -EAGAIN. Linux kernel users, system administrators, and security teams s [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72370

The Linux kernel had an issue with iomap where pages were not released on atomic dio size mismatch. This could potentially lead to resource leaks. The issue has been resolved by releasing or unbouncing the pages before falling through to out_put_bio on the error path. This vulnerability affects Linux kernel developers and users who rely on the iomap functionality. The issue was reported by sashiko and is [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72369

The Linux kernel vulnerability, CVE-2026-72369, allows mounting a crafted Minix v3 image to cause a kernel panic due to a zero bitmap-block count. This issue arises from an overflow in the bitmap block count calculation in minix_check_superblock(). Affected are Linux kernel maintainers and users of Minix filesystem. The vulnerability has a significant impact as it can lead to a kernel panic, potentially c [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72368

The Linux kernel vulnerability, CVE-2026-72368, is caused by a double unlock in the nomem_d_alloc error path of cachefiles_get_directory(). This vulnerability affects Linux kernel users and could potentially lead to a denial-of-service or privilege escalation if exploited. The CVE record was published on 2026-08-15T06:22:10.227Z and has not been modified since then. Users should verify their kernel versio [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72367

The Linux kernel vulnerability, CVE-2026-72367, relates to the handling of io_size and EOF (end of file) in the iomap_writeback_handle_eof function. A concurrent truncate operation can cause an underflow when calculating io_size, leading to a huge value due to unsigned integer wrapping. This can mislead append detection and corrupt completion-time size handling. Linux kernel users and administrators shoul [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72366

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T06:22:10.017Z and has not been modified since then. The vulnerability is in the netfs_create_write_req() function of the Linux kernel's netfs module. The function could potentially skip caching if the fscache cookie is disabled, even if async cache object creation is still in progress. This could [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72364

A vulnerability was found in the Linux kernel's netfs, which could lead to writeback error handling issues. The error handling in the writeback_iter() loop was not properly implemented, causing problems when an error occurred. The issue has been resolved by fixing the error handling in writeback_iter() to properly clean up iteration state and unlock and redirty the current folio.

Review Linux CVE published 2026-08-15

CVE-2026-72362

The Linux kernel's drm/xe/pt module has a NULL pointer dereference vulnerability. The issue arises when the page-table walk framework passes a NULL *child pointer for unpopulated entries to the xe_pt_zap_ptes_entry() function. This can cause a system crash. To mitigate this vulnerability, Linux kernel users should verify their systems are updated with the latest patches. The vulnerability was resolved by [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72361

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T06:22:09.530Z and has not been modified since then. The vulnerability affects the Linux kernel and is related to a double-free of managed BO in the error path of hw_engine_init(). This could potentially lead to a denial-of-service or privilege escalation. Users of the Linux kernel should review t [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72359

A NULL pointer dereference vulnerability was found in the Linux kernel's drm/xe component. The vulnerability occurs when a buffer object's ttm.resource is set to NULL during the TTM pipeline gutting flow, but the BO remains in the client's object list. If memory stats are queried during this time, accessing bo->ttm.resource->mem_type will result in a NULL pointer dereference.

Review Linux CVE published 2026-08-15

CVE-2026-72358

The Linux kernel vulnerability CVE-2026-72358 relates to the drm/xe/pt component, specifically how it handles purged Buffer Objects (BOs) during page table walks. Normally, when a BO is purged, the xe_pt_stage_bind() function skips initializing the xe_res_cursor for it, treating it similarly to NULL VMAs by only setting the cursor size. However, the functions xe_pt_hugepte_possible() and xe_pt_scan_64K() [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72357

The Linux kernel vulnerability CVE-2026-72357 exists in the uprobes/x86 subsystem, specifically in the __in_uprobe_trampoline function. The issue arises from using the wrong mm_struct in the unregister path, leading to incorrect VMA lookup. This vulnerability affects Linux kernel maintainers, Linux distribution vendors, and organizations using Linux systems. The fix involves adding a mm_struct pointer arg [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72354

A use-after-free vulnerability was found in the Linux kernel's NTFS file system implementation. The flaw occurs in the `ntfs_write_mft_block` function, which can lead to a slab-use-after-free error when writing to an MFT block. This happens because the function borrows a `runlist_element` pointer from `ni->runlist.rl` without holding the `ni->runlist.lock` spinlock, allowing for a concurrent MFT allocatio [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72353

A use-after-free vulnerability was found in the Linux kernel's ntfs module. The bug occurs in the ntfs_attr_fallocate function when accessing a runlist element after the read lock is dropped, allowing a writer to replace and free the array. This can lead to a slab-use-after-free error when reading rl->lcn, rl->length, and rl->vcn. The vulnerability requires immediate attention due to its potential for loc [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72351

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T06:22:08.520Z and has not been modified since then. The Linux kernel vulnerability involves GUE private flags indicating remote checksum offload metadata. Limited details are available; verify option length validation. Grounding in source evidence is required to understand affected scope and nece [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72348

The CVE-2026-72348 vulnerability is related to the Linux kernel's netfilter component, specifically with the handling of IPv6 extension headers. This vulnerability could allow malformed packets to bypass intended drop rules. Linux kernel users and administrators should verify their systems are updated with the latest security patches to mitigate potential threats. The CVE record was published on 2026-08-1 [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72347

The Linux kernel vulnerability CVE-2026-72347 has been resolved. The netfilter xt_connmark component did not properly validate user-supplied shift parameters, potentially leading to undefined behavior. This issue has been addressed by rejecting invalid revision-2 shift parameters during rule installation. The vulnerability affects Linux kernel deployments and has been resolved through updates to the netfi [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72346

A NULL pointer dereference vulnerability was found in the Linux kernel's platform/x86: bitland-mifs-wmi driver during suspend/resume operations. The event device handling path returns early before initializing the platform profile device, leaving it NULL. When entering suspend, the event device invokes bitland_mifs_wmi_suspend(), passing the uninitialized data->pp_dev (NULL) into laptop_profile_get(), lea [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72345

CVE-2026-72345 is an off-by-one error vulnerability in the Linux kernel's mlx5_lag_create_single_fdb() function. This issue occurs during the rollback process in case of failure at a certain index, potentially leading to the use of uninitialized state or double-tear-down of a rule that has already been rolled back by the add_one path. Affected Linux kernel users should verify their configurations and appl [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72343

A vulnerability was found in the Linux kernel's net/mlx5e component. The mlx5e_hv_vhca_stats_create() function is called before mlx5e_open(), at which point priv->stats_nch is still zero. This leads to mlx5e_hv_vhca_stats_buf_size() returning 0, and kvzalloc(0, GFP_KERNEL) returns ZERO_SIZE_PTR instead of NULL. The 'if (!buf)' guard does not catch this, and mlx5e_hv_vhca_stats_create() completes 'successf [truncated]

Review Linux CVE published 2026-08-15

CVE-2026-72342

A race condition vulnerability was found in the Linux kernel's net/mlx5e module, specifically in the HV VHCA stats agent registration. The vulnerability occurs when the mlx5e_hv_vhca_stats_create() function registers the stats agent through mlx5_hv_vhca_agent_create(), which publishes the agent and schedules an asynchronous control invalidation. However, the delayed_work and priv->stats_agent.agent are on [truncated]