PatchSiren

Linux CVE debriefs · Page 75

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-07-14

CVE-2026-31427

CVE-2026-31427 is a Linux kernel netfilter bug in nf_conntrack_sip. When SDP media parsing does not establish a valid RTP address, process_sdp() can still pass an uninitialized stack value into the nf_nat_sip sdp_session hook. That can lead to incorrect rewriting of SDP session-level owner and connection lines, including 0.0.0.0 on zero-initialized stacks or stale stack data on others. The published fix i [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-31424

CVE-2026-31424 is a Linux kernel availability vulnerability in netfilter's x_tables/nft_compat handling for ARP. A hook-validation mismatch can let xt_match/xt_target extensions with NFPROTO_UNSPEC run in ARP chains even when their .hooks masks were written for NF_INET_* layouts, which can lead to a NULL pointer dereference and kernel panic.

MEDIUM Linux CVE published 2026-07-14

CVE-2026-31423

CVE-2026-31423 is a Linux kernel availability issue in the sch_hfsc traffic scheduler. Under specific large-input conditions, a 64-bit difference is truncated into a 32-bit divisor in rtsc_min(), which can become zero and trigger a divide-by-zero kernel oops in the concave-curve intersection path. The CVE is rated medium severity (CVSS 5.5) and is primarily a denial-of-service concern for systems using th [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-31421

CVE-2026-31421 is a Linux kernel net/sched cls_fw bug that can trigger a NULL pointer dereference in fw_classify() when the old-method path is used on a shared block. The issue is reached when an empty cls_fw filter is attached to a shared block and a packet with a nonzero major skb mark is classified, which can crash the kernel and affect availability. The fix rejects that configuration in fw_change() fo [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-31418

CVE-2026-31418 is a Linux kernel netfilter/ipset issue in mtype_del() where logically empty buckets were not always released. NVD rates the issue medium severity with a local attack vector and high availability impact. Official kernel stable patches are available for the affected branches.

MEDIUM Linux CVE published 2026-07-14

CVE-2026-31416

CVE-2026-31416 covers a Linux kernel netfilter bug in nfnetlink_log where NLMSG_DONE failed to account for the netlink header size. The CVE description says this can trigger a WARN splat and cause the netlink message to be dropped. NVD rates the issue as local, low-privilege, no-interaction, with high availability impact and no confidentiality or integrity impact.

MEDIUM Linux CVE published 2026-07-14

CVE-2026-31415

CVE-2026-31415 is a Linux kernel IPv6 sendmsg flaw that can lead to a local denial of service. Repeated IPv6 destination-options control messages can cause a 16-bit length field to wrap while the kernel still retains a pointer to a large destination-options header, resulting in an skb headroom underestimation and a potential kernel panic.

CRITICAL Linux CVE published 2026-07-14

CVE-2026-31414

CVE-2026-31414 is a critical Linux kernel netfilter/conntrack issue involving unsafe helper-name handling in nf_conntrack_expect. NVD says the bug can be reached over the network with no privileges or user interaction, and the published fix switches ctnetlink and /proc dumping to use expect->helper and related reference-safe paths.

HIGH Linux CVE published 2026-07-14

CVE-2026-31411

CVE-2026-31411 is a Linux kernel availability issue in the ATM signaling send path. According to the supplied CVE/NVD material, sigd_send() used a vcc pointer taken from msg->vcc without validating that it referred to a real VCC object. A local attacker who can reach the ATM signaling daemon path could supply a forged pointer value and trigger a kernel crash. The kernel fix adds validation by searching th [truncated]

CRITICAL Linux CVE published 2026-07-14

CVE-2026-31402

CVE-2026-31402 is a critical Linux kernel vulnerability in nfsd’s NFSv4.0 LOCK replay cache. A denial response for a conflicting LOCK can include a large, variable-length lock owner field that may overflow the fixed inline replay buffer, leading to a heap out-of-bounds write. Because the issue is reachable over the network without authentication, exposed NFSv4.0 servers should be treated as urgent patchin [truncated]

HIGH Linux CVE published 2026-07-14

CVE-2026-31396

CVE-2026-31396 is a Linux kernel use-after-free in the macb network driver’s PTP clock handling. The issue matters because the PTP clock is created and destroyed with interface open/close activity, but it can still be accessed from the get_ts_info ethtool path while the device remains present in the kernel. The supplied kernel report shows KASAN detecting a use-after-free in ptp_clock_index() reached thro [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-31391

A vulnerability in the Linux kernel's Atmel SHA204A crypto driver could allow a local attacker to cause a denial of service condition. The flaw exists in the driver's error handling path: when memory allocation fails during cryptographic operations, the driver fails to decrement the `tfm_count` reference counter. This leak causes the counter to remain elevated, eventually blocking legitimate read operatio [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-23475

CVE-2026-23475 is a Linux kernel SPI subsystem vulnerability that can trigger a NULL-pointer dereference when sysfs statistics are accessed before per-controller statistics are allocated. NVD rates the issue as medium severity, with local low-privilege access leading to high availability impact. The published fix moves statistics allocation earlier in controller setup and ties its lifetime to the controll [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-23474

A buffer overflow vulnerability exists in the Linux kernel's RedBoot partition table parser within the MTD (Memory Technology Device) subsystem. The flaw occurs when parsing partition names where a memcmp() operation reads beyond the bounds of a dynamically allocated buffer. When CONFIG_FORTIFY_SOURCE is enabled with a recent compiler, this triggers a detected buffer overflow warning and kernel oops durin [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-23463

CVE-2026-23463 is a Linux kernel race condition in the soc:fsl:qbman qman flow-queue management path. When QMAN_FQ_FLAG_DYNAMIC_FQID is set, the ordering between clearing fq_table[fq->idx] and returning the FQID to the pool can allow a concurrent creator to reuse the just-freed ID and hit a WARN_ON in qman_create_fq(). The published fix changes the ordering so the table entry is cleared before gen_pool_fr [truncated]

HIGH Linux CVE published 2026-07-14

CVE-2026-23458

A use-after-free vulnerability in the Linux kernel's netfilter ctnetlink subsystem allows local attackers to escalate privileges or cause denial of service. The flaw exists in ctnetlink_dump_exp_ct(), which stores a conntrack pointer in cb->data for netlink dump callbacks but releases the reference immediately after netlink_dump_start(). When dump operations span multiple rounds, subsequent recvmsg() call [truncated]

HIGH Linux CVE published 2026-07-14

CVE-2026-23457

A vulnerability in the Linux kernel's netfilter SIP connection tracking module (nf_conntrack_sip) allows an attacker to trigger incorrect message boundary parsing in sip_help_tcp(). The root cause is a type mismatch: simple_strtoul() returns unsigned long, but the result is stored in unsigned int clen. On 64-bit systems, Content-Length values exceeding UINT_MAX (e.g., 4294967328) are silently truncated, c [truncated]

HIGH Linux CVE published 2026-07-14

CVE-2026-23456

A slab-out-of-bounds read vulnerability exists in the Linux kernel's netfilter H.323 connection tracking module. The flaw occurs in decode_int() when processing the CONS (constructed) case: after reading a 2-bit length value via get_bits(), the code calls get_uint() to read 1-4 bytes without verifying that sufficient bytes remain in the buffer. A malformed H.323/RAS packet can trigger a 1-4 byte out-of-bo [truncated]

CRITICAL Linux CVE published 2026-07-14

CVE-2026-23455

An integer underflow vulnerability exists in the Linux kernel's netfilter H.323 connection tracking module. In the DecodeQ931() function, a 16-bit length field read from packet data is decremented by 1 to skip the protocol discriminator byte before being passed to DecodeH323_UserInformation(). When the encoded length is 0, this decrement wraps to -1 (interpreted as a large unsigned value), causing an out- [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-23454

A use-after-free vulnerability exists in the Microsoft Azure Network Adapter (MANA) driver within the Linux kernel. The flaw occurs in `mana_hwc_destroy_channel()` where `hwc->caller_ctx` is freed before the Hardware Channel's Completion Queue (CQ) and Event Queue (EQ) are destroyed. This creates a race condition where an in-flight CQ interrupt handler can dereference freed memory when executing `mana_hwc [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-23452

A race condition in the Linux kernel's Power Management (PM) runtime subsystem can lead to a use-after-free when a device is removed while its parent device is being processed by the pm_runtime_work() workqueue. The vulnerability exists because pm_runtime_work() may dereference dev->parent after the parent has been freed, specifically when checking parent->power.ignore_children and subsequently calling rp [truncated]

CRITICAL Linux CVE published 2026-07-14

CVE-2026-23450

CVE-2026-23450 is a critical Linux kernel vulnerability in the SMC/TCP receive path. A race in smc_tcp_syn_recv_sock() can read a stale or cleared sk_user_data pointer while a concurrent close path frees the underlying smc_sock, leading to either a NULL pointer dereference or a use-after-free. The issue is network-facing, requires no privileges or user interaction, and affects multiple stable kernel relea [truncated]

HIGH Linux CVE published 2026-07-14

CVE-2026-23449

CVE-2026-23449 is a Linux kernel double-free in TEQL qdisc handling. NVD rates it HIGH (CVSS 7.8), and the issue is described as a race between TEQL's datapath and qdisc reset logic when a TEQL device has a lockless root qdisc. The reported effect is kernel memory corruption and crashes, including a KASAN double-free report. Fixed kernels are referenced by upstream stable patches and NVD marks multiple Li [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-23446

A MEDIUM severity vulnerability was found in the Linux kernel. The vulnerability is caused by aqc111_suspend calling the PM variant of its write_cmd routine, which can lead to a task hang in rpm_resume. The issue was resolved by replacing the write_cmd calls with their _nopm variants. This vulnerability affects Linux kernel versions 5.0.1 to 6.19.10 and users should be aware of this vulnerability and take [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-23439

A NULL pointer dereference vulnerability was found in the Linux kernel. The udp_sock_create6 function returns 0 without creating a socket when CONFIG_IPV6 is disabled, leading to a NULL pointer dereference in callers like fou_create. This issue can have a significant impact on systems relying on the Linux kernel, particularly those with IPv6 disabled. The vulnerability has been resolved by making udp_sock [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-23438

A NULL pointer dereference vulnerability was found in the Linux kernel's mvpp2 driver. The vulnerability occurs when the CM3 SRAM resource is not present in the device tree, causing the priv->cm3_base to remain NULL and priv->global_tx_fc to be false. This can lead to a crash when the mvpp2_bm_switch_buffers() function is triggered, for example, by an MTU change that crosses the jumbo frame threshold. The [truncated]

HIGH Linux CVE published 2026-07-14

CVE-2026-23434

A HIGH severity vulnerability was found in the Linux kernel, with a CVSS score of 7.1. The vulnerability exists in the mtd: rawnand component, where nand_lock() and nand_unlock() operations can race with concurrent UBI/UBIFS background erase/write operations, resulting in cmd_pending conflicts on the NAND controller. This can lead to potential security risks and impact the stability of the system. Linux k [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-23422

The Linux kernel was vulnerable to an interrupt storm due to improper handling of out-of-bounds if_id values in the dpaa2-switch IRQ handler. This issue was resolved by clearing the interrupt status after detecting an out-of-bounds if_id. The vulnerability was addressed through a range check for if_id and clearing the interrupt status when an out-of-bounds value is detected. Affected users should apply pa [truncated]

HIGH Linux CVE published 2026-07-14

CVE-2026-23414

A HIGH severity vulnerability was found in the Linux kernel, with a CVSS score of 7.5. The vulnerability is related to the tls: Purge async_hold in tls_decrypt_async_wait(). This vulnerability causes a leak when tls_strp_msg_hold() fails part-way through, after having added some cloned skbs to the async_hold queue. The vulnerability affects Linux kernel versions 6.1.158 to 6.1.168, 6.6.114 to 6.6.131, 6.1 [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2026-23398

The Linux kernel was vulnerable to a NULL pointer dereference in the icmp_tag_validation() function. This issue arises when the kernel receives an ICMP Fragmentation Needed error with a quoted inner IP header containing an unregistered protocol number. The vulnerability has been resolved with the addition of a NULL check before accessing icmp_strict_tag_validation. The vulnerability affects Linux kernel v [truncated]