These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A use-after-free vulnerability was found in the Linux kernel's pNFS implementation. The issue occurs in the pnfs_update_layout() function when it hits the NFS_LAYOUT_RETURN branch. The code calls pnfs_prepare_to_retry_layoutget(lo), and if it succeeds, pnfs_put_layout_hdr(lo) is called before trace_pnfs_update_layout(), which still references 'lo'. This results in a use-after-free when the tracepoint acce [truncated]
The Linux kernel's irqchip/imgpdc driver had a resource leak vulnerability. During probe, it allocated domain generic chips but didn't free them on removal, and didn't remove chained handlers. This could lead to use-after-free and kernel crashes. The fix involves setting IRQ_DOMAIN_FLAG_DESTROY_GC and clearing chained handlers. The vulnerability was introduced due to missing cleanup on driver removal, pot [truncated]
The Linux kernel was vulnerable to a use-after-free issue in the rpmsg character device driver. When rpmsg_chrdev_probe() failed, it could lead to callbacks being dispatched with a stale pointer. This vulnerability affects Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems. The issue arises from rpmsg_chrdev_probe() storing a newly allocated eptdev in the [truncated]
The Linux kernel has been found to have a vulnerability, CVE-2026-63796, which involves a flaw in the ocfs2_validate_gd_parent() function. This function did not properly validate the group bitmap descriptors, allowing for potential out-of-bounds access. The vulnerability was discovered and resolved in the Linux kernel. The fix adds a physical-cap check based on ocfs2_group_bitmap_size() for the parent all [truncated]
A use-after-free vulnerability was found in the Linux kernel's 9p filesystem implementation. When p9_client_walk() is called with clone set to false, fid aliases oldfid. If the walk subsequently fails after the request has been sent, the error path jumps to clunk_fid, which currently calls p9_fid_put(fid) unconditionally. This drops a reference to oldfid even though ownership of oldfid remains with the ca [truncated]
A use-after-free vulnerability was found in the Linux kernel's KVM: SVM sev_dbg_crypt() function. The vulnerability occurs when the per-iteration transfer length is not bounded by the destination page offset, leading to a potential page overflow. This can cause a use-after-free vulnerability, potentially allowing attackers to access sensitive information or execute arbitrary code. The vulnerability was re [truncated]
A use-after-free vulnerability in the Linux kernel's NTFS subsystem has been resolved. The vulnerability occurred when the FS_IOC_SETFSLABEL and FS_IOC_GETTSLABEL operations were executed concurrently, leading to a potential use-after-free issue. The fix involves protecting the vol->volume_label with a mutex and snapshotting the label before copy_to_user. This vulnerability affected the Linux kernel's NTF [truncated]
The Linux kernel vulnerability CVE-2026-53403 was resolved. The vulnerability was related to the fbdev subsystem, specifically in the fb_new_modelist function, which did not check if the current mode info->var still had a matching entry in the new modelist after userspace replaced it. This could lead to a null pointer dereference in fb_videomode_to_var. The issue was resolved by keeping the current mode i [truncated]
A use-after-free vulnerability was discovered in the Linux kernel's fbdev: omap2. The vulnerability occurs in the omapfb_mmap() function, which has a race condition with the OMAPFB_SETUP_PLANE ioctl. This can lead to a use-after-free vulnerability, allowing attackers to access freed physical memory. The vulnerability was introduced due to a lack of proper synchronization between the fb_mmap() entry point [truncated]
A Linux kernel vulnerability has been resolved in the i2c core, addressing an adapter registration race condition. The issue arises from the lookup of adapters based on their ID using i2c_get_adapter(), which takes a reference to the embedded struct device. To prevent accessing uninitialized data, which could lead to NULL-pointer dereferences or use-after-free, the adapter must be fully initialized before [truncated]
A Linux kernel vulnerability, CVE-2026-53399, was resolved by releasing layout stid on setlease failure. The nfsd4_alloc_layout_stateid() function publishes a new stid into cl->cl_stateids via idr_alloc_cyclic() under cl_lock before returning to nfsd4_layout_setlease(). When nfsd4_layout_setlease() fails, the error path frees the layout stateid directly with kmem_cache_free() without calling idr_remove(), [truncated]
The Linux kernel has a vulnerability that has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup. The vulnerability occurs when nfsd4_decode_secinfo_no_name() initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the decoder returns nfserr_bad_xdr before sin_exp is initialized. This can lead to stale union contents from a previous operation being left in sin_exp, causing [truncated]
A vulnerability was found in the Linux kernel's nfsd, which could lead to a posix_acl leak on SETACL decode failure. The issue arises from nfsaclsvc_decode_setaclargs() and nfs3svc_decode_setaclargs() each calling nfs_stream_decode_acl() twice. If the first call succeeds but the second fails, the decoder returns false, leaving argp->acl_access dangling, resulting in a posix_acl leak for the lifetime of th [truncated]
A Linux kernel vulnerability, CVE-2026-53395, was resolved in nfsd4_create(). The issue involves a dead ACL conflict guard, leading to a memory leak of two posix_acl slab objects per request, causing unbounded slab exhaustion. This vulnerability affects Linux kernel users and administrators, who should be aware of the issue and ensure their systems are updated.
A Linux kernel vulnerability, CVE-2026-53394, was resolved to address a race condition in the NFSv4.0 OPEN threads that could lead to a memory leak of pre-allocated openowner objects. This vulnerability requires a race between two NFSv4.0 OPEN threads with the same owner string, where a concurrent thread inserts a new unconfirmed owner into the hash between retry iterations. The vulnerability has been fix [truncated]
A Linux kernel vulnerability, CVE-2026-53393, was resolved by adding calls to commit_reset_write_verifier() in nfsd_vfs_write() and nfsd_commit() to address a durability contract issue with UNSTABLE write data. This vulnerability affects Linux kernel users and administrators who should ensure they are running a patched kernel version to prevent potential data loss or corruption.
The Linux kernel has a vulnerability that has been resolved. The NFSv4/flexfiles: reject zero filehandle version count vulnerability was found in the Linux kernel. The ff_layout_alloc_lseg() function decodes the filehandle-version array count from the flexfiles layout body. A zero count yields ZERO_SIZE_PTR, which can be stored in dss_info->fh_versions even though later flexfiles paths assume that at leas [truncated]
The Linux kernel has a vulnerability that has been resolved. The NFSv4/pNFS implementation did not properly handle zero-length r_addr in nfs4_decode_mp_ds_addr, leading to a potential NULL pointer dereference. This vulnerability affects Linux kernel with NFSv4/pNFS enabled. The vulnerability has been resolved, and users should update to the latest version of the Linux kernel.
A Linux kernel vulnerability, CVE-2026-53390, was resolved to address an out-of-bounds read in the smb_check_perm_dacl() function. This vulnerability arises from the function failing to verify if the size of an Access Control Entry (ACE) is sufficient to contain a certain number of sub-authorities before accessing them. An attacker could exploit this by crafting a malicious ACE that, when processed, leads [truncated]
The Linux kernel was vulnerable to a use-after-free condition in the tcp_ao_delete_key() function. When a key was added with specific settings and then deleted asynchronously, the key could be freed without clearing related pointers, leading to potential crashes or code execution if the socket transitioned to LISTEN state. This vulnerability was particularly concerning because it could be triggered by spe [truncated]
A use-after-free vulnerability was found in the Linux kernel's fuse subsystem. The issue arises from fuse_try_move_folio() unlocking the request on entry but failing to re-lock it on the success path. This allows fuse_chan_abort() to end the request and free the fuse_io_args while the subsequent copy chain logic accesses the fuse_io_args, leading to use-after-free issues. The fix involves calling lock_req [truncated]
A Linux kernel vulnerability was resolved, adding bounds checking to veml6075_it_ms index in iio: light: veml6075. The vulnerability could cause an out-of-bounds array access if VEML6075_CONF_IT yields values 0-7, with 5 elements in veml6075_it_ms. This issue was found in the Linux kernel and has been addressed with a bounds check to prevent out-of-bounds array access. The problem values are reserved and [truncated]
A Linux kernel vulnerability, CVE-2026-53386, was resolved by adding bounds checking to the pga_settings index in the ti-ads1298 iio adc. The ads1298_pga_settings array has 7 elements, but ADS1298_MASK_CH_PGA can yield values 0-7. If it yields a value >= 7, this causes an out-of-bounds array access. A bounds check was added and returns -EINVAL if the index is out of range. The remaining value b111 is rese [truncated]
A null pointer dereference vulnerability was observed in the Linux kernel's vc_screen module. The issue occurs when the console_lock is temporarily dropped during a concurrent vcs_write operation, causing the vc_data pointer to become stale. After re-acquiring the lock, if the vc has been deallocated, vcs_vc() returns NULL, leading to a null pointer dereference in the notifier chain. This vulnerability ha [truncated]
The Linux kernel has a vulnerability, CVE-2026-53384, which has been resolved. The vulnerability occurs in the serial: 8250_dw component. When dw8250_probe() registers the 8250 port and then fails to register a clock notifier, the probe returns an error but leaves the 8250 port registered. This leads to a use-after-free hazard because the devm-allocated driver data is freed while the port still references [truncated]
The Linux kernel vulnerability CVE-2026-53383 was resolved by rejecting non-VALID sessions in compound request branches. The vulnerability allowed for a remote NULL-pointer dereference and a kernel Oops due to a bypass of session validity checks in COMPOUND requests. This vulnerability was found in the ksmbd module of the Linux kernel. It occurred because the smb2_check_user_session() function did not pro [truncated]
A general protection fault in the Linux kernel's media test driver, vidtv, was reported. The issue arises from a NULL pointer dereference in the vidtv_mux_push_si function. This occurs when vidtv_mux_get_pid_ctx returns NULL, and the returned pointer is dereferenced to access the continuity counter. The root cause is that vidtv_mux_pid_ctx_init does not check the return value of vidtv_mux_create_pid_ctx_o [truncated]
A use-after-free (UAF) vulnerability was discovered in the Linux kernel's virtiofs subsystem. The issue arises from the iput() function being called from fuse_release_end(), which can lead to a crash if the super block has already been destroyed. This problem is caused by the wait counter being per connection, not per superblock, making it ineffective for multiple submount instances. The fix involves reve [truncated]
A vulnerability was found in the Linux kernel's media module, specifically in the rzv2h-ivc driver. The bug allows for concurrent access to the buffer list without proper locking, leading to potential data corruption or crashes. This issue is particularly concerning for Linux kernel developers and maintainers, as well as users of Linux-based systems who may be exposed to this vulnerability. The fix involv [truncated]
The Linux kernel was updated to address memory leaks in drm/colorop state blob property handling. Issues included improper state memory freeing and blob reference releasing during duplication, destruction, and reset operations. This update ensures proper reference counting throughout the state lifecycle, matching the well-tested pattern used by drm_crtc since 2016.