These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A HIGH severity vulnerability was found in the Linux kernel's nfnetlink_osf component. The vulnerability is caused by a lack of validation of individual option lengths in fingerprints, which can lead to a general protection fault and potential null-pointer dereference. This issue allows attackers to trigger a denial-of-service condition or potentially execute arbitrary code with elevated privileges.
A high-severity vulnerability, CVE-2026-23392, was found in the Linux kernel. This vulnerability is caused by a use-after-free error in the netfilter subsystem, specifically in the nf_tables component. The vulnerability occurs when the flowtable is released after an RCU grace period on error, allowing a hook that already refers to this flowtable to be registered, exposing the flowtable to the packet path [truncated]
A vulnerability has been resolved in the Linux kernel related to netfilter: xt_CT. Templates refer to objects that can go away while packets are sitting in nfqueue. This can cause issues on module removal or timeout policy removal. The use of templates with zone and event cache filter are safe, since this just copies values. However, to prevent potential issues, enqueued packets should be flushed in case [truncated]
A NULL pointer dereference vulnerability was found in the Linux kernel when IPv6 is disabled. The issue occurs when the 'ipv6.disable=1' parameter is used during boot, preventing the initialization of nd_tbl. When neigh_suppress is enabled and an ICMPv6 Neighbor Discovery packet reaches the bridge, the br_do_suppress_nd() function will dereference ipv6_stub->nd_tbl, which is NULL, causing a kernel NULL po [truncated]
A divide by zero vulnerability was found in the Linux kernel's net/sched: ets offload path. This vulnerability can cause a kernel panic. The issue arises from using unsigned integers for 'q_sum' and 'q_psum', which can overflow and cause division by zero. Affected systems include those running Linux kernel versions 5.6.1 to 5.10.253, 5.11 to 5.15.203, 5.16 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.77, 6.13 [truncated]
The Linux kernel was vulnerable to an out-of-bounds error due to improper update behavior of the metalist in the ife action replace. This issue has been resolved by fixing the replace behavior. The vulnerability affected the Linux kernel, particularly in versions 4.15.1 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.77, 6.13 to 6.18.17, 6.19 to 6.19.7, and 7.0 rc1 to rc7. Users of the Linux kernel should review [truncated]
CVE-2026-23370 is a MEDIUM-severity vulnerability in the Linux kernel, specifically in the platform/x86: dell-wmi-sysman component. The vulnerability was resolved by removing the hex dump of plaintext password data in the set_new_password() function, which previously leaked credentials. Linux kernel maintainers, Linux distribution vendors, and users of affected Linux kernel versions should review and appl [truncated]
A Linux kernel vulnerability has been resolved, addressing an AB-BA deadlock issue when both LEDS_TRIGGER_NETDEV and LED_TRIGGER_PHY are enabled. The issue arises in the phy_led_triggers_register function during probe, which can cause a deadlock with LEDS_TRIGGER_NETDEV. Users of Linux kernel versions 4.16.1 to 6.18.17, and 7.0 rc1 to rc7, should review and apply patches. The vulnerability has a CVSS scor [truncated]
The Linux kernel has a vulnerability in the net: usb: kalmia module. The kalmia driver does not validate the USB endpoints of a device before binding to it, which can cause a crash if a malicious device is used. This vulnerability has been resolved by adding endpoint validation. Affected users should validate their systems and apply patches if necessary. The vulnerability requires a malicious device to be [truncated]
A stack-out-of-bounds write vulnerability was discovered in the devmap component of the Linux kernel. The issue arises from the get_upper_ifindexes() function, which iterates over all upper devices and writes their indices into an array without checking bounds. This can lead to a stack-out-of-bounds write when there are more upper devices than expected. The vulnerability was resolved by adding a max param [truncated]
A use-after-free vulnerability was found in the Linux kernel's netfilter: nft_set_pipapo. This vulnerability could lead to a local denial of service due to soft lockup warnings and RCU stall reports under a large number of expired elements. The issue arises from the garbage collection (GC) in the pipapo set type running for a long time in a non-preemptible context. To address this, the GC was split into a [truncated]
A high-severity vulnerability, CVE-2026-23343, was found in the Linux kernel. This issue arises from incorrect XDP Rx queue frag size reporting by some ethernet drivers, leading to negative tailroom calculations. Such miscalculation can cause memory corruption under certain conditions. The vulnerability has been resolved with a patch that produces a warning when a negative tailroom is calculated.
A use-after-free vulnerability was found in the Linux kernel's network scheduler. When shrinking the number of real tx queues, the qdisc_reset_all_tx_gt() function is called to flush qdiscs for queues that will no longer be used. However, for lockless qdiscs, the dequeue path is serialized by qdisc_run_begin/end() using qdisc->seqlock instead of qdisc_lock(). This can lead to a use-after-free vulnerabilit [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel's RDMA/irdma. The vulnerability is caused by a kernel stack leak in the irdma_create_user_ah() function. The reserved members of the structure were not zeroed, resulting in 4 bytes of stack memory being leaked unconditionally. This vulnerability can potentially be used to leak sensitive information from the kernel stack. Linux kernel users and [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel, with a CVSS score of 5.5. The vulnerability is related to the MPTCP (Multipath TCP) protocol and can be triggered by a series of actions that cause a warning to be generated. The actions that can trigger the warning are: setting the MPTCP subflows limit to 0, creating an MPTCP endpoint with both the 'signal' and 'subflow' flags, creating a new [truncated]
CVE-2026-23319 is a use-after-free vulnerability in the Linux kernel, specifically in the bpf_trampoline_link_cgroup_shim function. The vulnerability arises when the refcount of 'shim_link->link.link' is reduced to zero, but the resource is still referenced via 'tr->progs_hlist' in 'cgroup_shim_find'. This can lead to a use-after-free condition when another process accesses the resource during the window [truncated]
A vulnerability in the Linux kernel's SiFive PLIC (Platform-Level Interrupt Controller) irqchip driver could cause interrupts to become permanently frozen when interrupt affinity is changed while a hart (hardware thread) is still handling that interrupt. The root cause is that the existing fix for a prior interrupt-completion issue relied on irqd_irq_disabled() to determine whether to temporarily re-enabl [truncated]
CVE-2026-23284 is a Linux kernel bug in the mtk_eth_soc Ethernet driver’s XDP setup error path. According to the fixed description, if mtk_open fails during mtk_xdp_setup(), the code should restore the previous eBPF program pointer and avoid dropping its reference count. The published record ties the issue to multiple upstream/stable kernel fixes and rates it MEDIUM severity with primary availability impact.
CVE-2026-23277 is a Linux kernel networking bug in the TEQL transmit path. When TEQL forwards traffic to a slave device, it fails to update skb->dev before calling netdev_start_xmit(). If the slave is a gretap tunnel, the tunnel transmit path later uses the stale master device pointer, reaches iptunnel_xmit_stats(), and dereferences dev->tstats even though teql0 does not have the per-CPU tstats allocation [truncated]
CVE-2026-23274 is a Linux kernel netfilter xt_IDLETIMER issue where revision 0 rules can reuse an existing timer by label even when that timer was first created by revision 1 with XT_IDLETIMER_ALARM. In that case, the reused object follows alarm-timer semantics and timer->timer is never initialized, yet rev0 still calls mod_timer() on it. The result can be debugobjects warnings and, if panic_on_warn=1 is [truncated]
CVE-2026-23273 describes a Linux kernel macvlan race condition in error handling that can leave a device visible long enough for a concurrent packet path to hit freed memory. The reported impact is a kernel use-after-free in macvlan_forward_source after macvlan_common_newlink() encounters an error and its caller frees the netdev too early without an RCU grace period. The CVSS vector indicates a local, low [truncated]
CVE-2026-23271 is a high-severity Linux kernel vulnerability in perf event handling. The issue is a race between __perf_event_overflow() and perf_remove_from_context()/perf_event_exit_event() cleanup paths, where the overflow path may run after objects it expects have already been freed. The description specifically calls out the BPF program as one example of state that may no longer be present. Because t [truncated]
CVE-2026-23270 is a Linux kernel networking issue in net/sched affecting act_ct. The kernel fix restricts act_ct so it can bind only to clsact/ingress qdiscs and shared blocks, while still allowing clsact-based egress use. The underlying concern is a use-after-free scenario where classify can return TC_ACT_CONSUMED while the skb is still held by the defragmentation engine, and the packet may later be touched again.
CVE-2026-23245 is a high-severity Linux kernel vulnerability in the traffic-control act_gate path. The issue was recorded by CVE/NVD on 2026-03-18 and later updated on 2026-05-21. The kernel fix description says the gate action could be replaced while the hrtimer callback or dump path was walking the schedule list, creating a concurrency hazard. The remediation converts the parameters to an RCU-protected [truncated]
CVE-2026-23243 is a Linux kernel memory-corruption issue in the RDMA/umad path. A user-controlled length calculation in ib_umad_write() can become negative when the MAD header size and RMPP header length do not match. That negative data_len can then reach ib_create_send_mad(), where padding calculations may exceed the segment size and trigger an out-of-bounds memset in alloc_send_rmpp_list(). The fix is s [truncated]
CVE-2026-23242 is a Linux kernel denial-of-service issue in RDMA/siw header processing. NVD rates it HIGH (CVSS 7.5) and the supplied kernel fix notes say a NULL pointer dereference can occur when siw_get_hdr() returns -EINVAL before set_rx_fpdu_context(), leaving qp->rx_fpdu unset and then dereferenced in siw_tcp_rx_data(). The result is a kernel crash rather than a confidentiality or integrity issue.
A slab-out-of-bounds read vulnerability exists in the Linux kernel's `cls_u32` network traffic classifier. The `u32_classify()` function in `net/sched/cls_u32.c` uses `skb_header_pointer()`, which does not fully validate negative offset values. An attacker with local access can supply a crafted packet with a negative offset that bypasses validation, triggering a KASAN-detected out-of-bounds read in kernel [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-14T16:15:55.550Z and has not been modified since then. The NVD entry is currently Modified. This vulnerability affects the Linux kernel, specifically in the handling of GSO segmentation for GRO packets containing a frag_list. The patch enhances GSO segment handling by properly checking the SKB_GSO_D [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel's io_uring/io-wq component. The issue arises from the lack of a check for IO_WQ_BIT_EXIT inside the work run loop, which can lead to a situation where the system appears to hang or become unresponsive for an extended period. The fix involves adding a check for IO_WQ_BIT_EXIT inside the io_worker_handle_work() loop to speed up the exit process. [truncated]
A MEDIUM severity vulnerability, CVE-2026-23110, was found in the Linux kernel. This issue involves a race condition in the SCSI layer that can cause I/O through the SCSI host to become stuck, as the error state cannot advance. The vulnerability arises from a fragile ordering between marking commands completed or failed and waking the error handler. There are two primary race conditions: one within scsi_d [truncated]