These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A slab-use-after-free vulnerability was found in the Linux kernel's __inet_lookup_established function. This issue arises from MPTCP's mptcp_subflow_init() function copying tcpv6_prot into tcpv6_prot_override before inet6_init() has called proto_register(&tcpv6_prot), leading to MPTCP v6 subflow child sockets being allocated via kmalloc instead of the TCPv6 slab cache. This causes a slab-use-after-free wh [truncated]
A use-after-free vulnerability was found in the Linux kernel's netfilter component. The nft_ct_timeout_obj_destroy function was freeing the timeout object immediately after nf_ct_untimeout, without waiting for an RCU grace period. This could allow concurrent packet processing on other CPUs to still hold RCU-protected references to the timeout object, leading to a potential crash or code execution. The fix [truncated]
A memory leak vulnerability was found in the Linux kernel's altera-tse driver. When dma_map_single() fails in tse_start_xmit(), the function returns NETDEV_TX_OK without freeing the skb, leading to a memory leak on every DMA mapping failure. This vulnerability has a medium severity and could potentially lead to memory exhaustion through repeated exploitation attempts. Linux kernel maintainers, Linux distr [truncated]
A MEDIUM severity vulnerability was resolved in the Linux kernel, specifically in the mmc: vub300 driver. The vulnerability could lead to NULL-pointer dereferences or use-after-free issues on disconnect. The issue has been patched. Linux kernel maintainers, Linux distribution vendors, and users should be aware of this vulnerability and take necessary actions to patch their systems.
The Linux kernel was vulnerable to an integer underflow issue in the stmmac network driver. The vulnerability occurred in the jumbo_frm() implementation, which unconditionally computed a length value that could wrap around as an unsigned integer when a packet had a small linear portion but a large total length due to page fragments. This led to a potential kernel memory disclosure and memory corruption fr [truncated]
A medium-severity vulnerability was patched in the Linux kernel. The vulnerability, CVE-2026-31628, affects various Linux kernel versions and could allow an attacker to leak partial results from previous operations. The vulnerability was resolved with a patch. Linux kernel users and administrators should review and apply patches as necessary. The vulnerability has a medium severity score of 5.5.
A deadlock vulnerability was found in the Linux kernel's RDMA/irdma component. The issue occurs when a netdev reset is executed while RDMA applications are active, causing a circular dependency and indefinite wait in iWARP mode. This deadlock can potentially impact system availability and performance. Linux kernel maintainers, RDMA/irdma users, and administrators of systems using affected kernel versions [truncated]
A HIGH severity vulnerability was found in the Linux kernel, with a CVSS score of 7.5. The vulnerability is related to the macb driver, which is used for Ethernet networking. The issue arises from the improper use of napi_consume_skb() in an IRQ-disabled context, leading to a potential system crash or denial of service. This vulnerability can impact system availability and may allow attackers to cause a d [truncated]
A use-after-free vulnerability was found in the Linux kernel's futex subsystem. When futex_lock_pi_atomic() sees the owner is exiting, it returns -EBUSY and stores a refcounted task pointer in 'exiting'. After wait_for_owner_exiting() consumes that reference, the local pointer is never reset to nil. Upon a retry, if futex_lock_pi_atomic() returns a different error, the bogus pointer is passed to wait_for_ [truncated]
A NULL pointer dereference vulnerability was found in the Linux kernel's bonding module. The vulnerability occurs in the `bond_debug_rlb_hash_show` function, which does not check if the `slave` pointer is NULL before accessing it. This can cause a kernel crash when trying to access the `slave` pointer. The vulnerability can be triggered by running the `cat` command on the `/proc/net/bonding/bond0` file, w [truncated]
A use-after-free vulnerability was discovered in the Linux kernel's TLS encryption handling. The vulnerability occurs when the -EBUSY error path in tls_do_encryption() is triggered, leading to double cleanup of encrypt_pending and the scatterlist entry. This can cause a use-after-free when a cryptd callback is still pending, resulting in a potential system crash or code execution.
A vulnerability in the Linux kernel can cause a kernel panic when a symbol st_shndx is out of bounds. The module loader doesn't check for bounds of the ELF section index in simplify_symbols(). A symbol with an out-of-bounds st_shndx value may cause a kernel panic. This can happen when module ELF is legitimately using SHN_XINDEX or when it is corrupted. Add a bounds check in simplify_symbols() to validate [truncated]
A Linux kernel vulnerability, CVE-2026-31518, has been resolved. The vulnerability is related to the espintcp and async crypto components, which could lead to a skb leak. This issue arises when the TX queue for espintcp is full, and esp_output_tail_tcp returns an error without freeing the skb. With async crypto, the common xfrm output code will not drop the packet, necessitating manual handling. The vulne [truncated]
The Linux kernel was vulnerable to a crash in the pfkey_send_migrate function due to lack of family validation, which could lead to a buffer overfill. This issue has been resolved by adding early family validation. The vulnerability was discovered through fuzzing and has been addressed with multiple patches across various kernel versions. Users of affected Linux kernel versions should apply updates to pre [truncated]
A vulnerability was found in the Linux kernel, specifically in the Open vSwitch (OVS) component. The issue arises from the improper synchronization of netdev destruction and unregistration, leading to a use-after-free vulnerability. This could potentially allow local attackers to escalate their privileges or cause a denial of service. The vulnerability was resolved through a series of patches applied to t [truncated]
A high-severity vulnerability was found in the Linux kernel's SMC (System Management Controller) splice buffer handling. The vulnerability, tracked as CVE-2026-31507, could lead to a double-free of the smc_spd_priv structure when the tee() system call duplicates a pipe buffer. This could result in a use-after-free (UAF) condition, potentially causing a kernel panic. The vulnerability has been resolved thr [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel. The vulnerability is related to a bind conflict check issue in the UDP protocol. When binding a udp_sock to a local address and port, UDP uses two hashes for collision detection. The current code switches to 'hash2' when hslot->count > 10. However, this can lead to a conflict when binding to a wildcard address. The vulnerability can be exploit [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel, with a CVSS score of 5.5. The vulnerability has been resolved in the netfilter component. This issue allows attackers to skip expectations that do not reside in the current network namespace via proc. Users of the Linux kernel, particularly those using versions prior to the patched versions, should be aware of this vulnerability and take steps [truncated]
The Linux kernel was vulnerable to a MEDIUM severity issue, resolved by replacing manual range and mask validations with netlink policy annotations in ctnetlink code paths. This change helps prevent invalid values from being accepted and allows the netlink core to generate extack errors early. The vulnerability affects the netfilter: ctnetlink component and has been addressed to prevent potential exploita [truncated]
A potential mismatch between the memory reserved for statistics and the amount of memory written in the Linux kernel's macb driver can result in an out-of-bounds write. The issue arises from the gem_get_ethtool_stats function, which indiscriminately copies data using the maximum number of queues, leading to a potential out-of-bounds write when the number of active queues is less than the maximum. This vul [truncated]
A use-after-free vulnerability was found in the Linux kernel's spi_fsl_lpspi driver. The vulnerability occurs due to a teardown order issue, where the SPI controller is unregistered after the fsl_lpspi_remove function returns, leading to a NULL pointer dereference when a running SPI transfer triggers a DMA RX error. This issue affects users of the Linux kernel, particularly those using the spi_fsl_lpspi d [truncated]
A use-after-free vulnerability was discovered in the Linux kernel's virtio_net driver. The issue arises when the IFF_XMIT_DST_RELEASE flag is cleared and napi_tx is set to false. This configuration can lead to a situation where the driver fails to hold a reference to the skb->dst, resulting in a use-after-free error when the network namespace is destroyed.
A MEDIUM severity vulnerability was found in the Linux kernel, specifically in the mm/huge_memory module. The vulnerability is related to a missing memory barrier in the softleaf_to_folio() function, which can lead to a race condition between folio split and zap_nonpresent_ptes(). This can cause a folio to be incorrectly modified without a lock being held, triggering a VM_WARN_ON_ONCE() in pfn_swap_entry_ [truncated]
A HIGH severity vulnerability was found in the Linux kernel, with a CVSS score of 7.8. The vulnerability occurs when the file size of an inode with inline data exceeds the inline capacity during a truncate operation, causing the filesystem to enter an inconsistent state. This can lead to potential crashes and data corruption if not addressed. Linux kernel users and administrators should be aware of this v [truncated]
A HIGH severity vulnerability was found in the Linux kernel, with a CVSS score of 8.8. The vulnerability exists in the ext4_inode_attach_jinode() function, where ei->jinode is published to concurrent users before initialization, allowing a reader to observe a non-NULL jinode with i_vfs_inode still unset. This can cause a crash when the fast commit flush path passes this jinode to jbd2_wait_inode_data(). T [truncated]
A vulnerability has been resolved in the Linux kernel, specifically in the ext4 filesystem. The issue arises when mapping logical blocks to physical blocks on the mkdir/mknod path. If inserting a new extent into the extent tree fails, ext4_ext_map_blocks() only calls ext4_free_blocks() to reclaim the physical block without deleting the corresponding data in the extent tree. This can cause subsequent mkdir [truncated]
A vulnerability was found in the Linux kernel, specifically in the ext4 filesystem. The CVE record was published on 2026-04-22T14:16:38.577Z and has not been modified since then. The NVD entry is currently Modified. The vulnerability has a high CVSS score of 7.8 and is classified as HIGH severity. The issue arises from bigalloc with s_first_data_block != 0, which is not supported. Users of Linux kernel ve [truncated]
A use-after-free vulnerability was found in the Linux kernel, specifically in the ext4 filesystem. The vulnerability occurs when racing with umount, leading to a potential use-after-free in update_super_work. This could allow an attacker to execute arbitrary code or cause a denial of service. The fix involves modifying ext4_notify_error_sysfs() to detect if sysfs has already been torn down and skip the sy [truncated]
A memory leak vulnerability was found in the Linux kernel. The vulnerability occurs when a workqueue is reset, and the idxd_wq_disable_cleanup() function sets the workqueue type to NONE before releasing its resources. This can cause a memory leak. The vulnerability has been resolved by setting the workqueue type to NONE only after its resources are released. This issue affects Linux kernel users and admin [truncated]
CVE-2026-31428 is a Linux kernel issue in nfnetlink_log where NFULA_PAYLOAD was built manually and could expose uninitialized padding bytes to userspace. NVD rates the issue MEDIUM, and the reported attack vector is local with low privileges. The fix replaces the manual attribute construction with the standard netlink reservation path so padding is initialized before the payload is copied in.