These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A race condition vulnerability was found in the Linux kernel's ipvlan implementation. The addrs_lock, which protects the ipvlan address list, was incorrectly shared among all ipvlan devices instead of being per-port. This could lead to false negatives in ipvlan_addr_busy() and races when adding or removing addresses. The vulnerability is considered minor but could potentially cause issues. The issue has b [truncated]
A MEDIUM severity vulnerability was resolved in the Linux kernel, affecting the hugetlb_pmd_shared() functionality. This patch series includes one functional fix, one performance regression fix, and two related comment fixes. The vulnerability allows for incorrect detection of shared PMD tables, potentially leading to issues with page migration and accounting. The fixes include using ptdesc_pmd_is_shared( [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel, specifically in the scsiback_remove() function, which could lead to a potential memory leak. Memory allocated for struct vscsiblk_info in scsiback_probe() was not freed in scsiback_remove(), leading to potential memory leaks on remove, as well as in the scsiback_probe() error paths. The vulnerability has been resolved by freeing the memory in [truncated]
The Linux kernel was vulnerable to a buffer size manipulation issue in the vsock/virtio component. A malicious guest could advertise a large buffer size, causing the host to allocate excessive memory. This issue has been resolved by introducing a helper function, virtio_transport_tx_buf_size(), which ensures the effective TX window is bounded by both the peer's advertised buffer and the host's own buffer allocation.
A NULL pointer dereference vulnerability was found in the Linux kernel's be2net driver. The be_cmd_get_mac_from_list function may dereference a NULL pointer when the pmac_id_valid argument is set to false and the pmac_id argument is NULL. This issue can lead to a system crash or potential code execution if exploited. Linux kernel users and administrators should be aware of this vulnerability and take step [truncated]
A HIGH severity vulnerability was found in the Linux kernel, affecting the FOU_ATTR_IPPROTO. This issue has been resolved through a series of patches. The vulnerability allows an attacker to potentially cause a denial of service or execute arbitrary code. Users are advised to update to the latest kernel version to mitigate this vulnerability. The Common Vulnerabilities and Exposures (CVE) score for this v [truncated]
A vulnerability was found in the Linux kernel's authencesn component. The vulnerability occurs when the AAD (associated data) length is less than 8, causing a NULL pointer dereference and potentially leading to a kernel panic (DoS). This issue arises because authencesn assumes an ESP/ESN-formatted AAD. When assoclen is shorter than the minimum expected length, crypto_authenc_esn_decrypt() can advance past [truncated]
The Linux kernel was vulnerable to a hang condition when RSS hash key programming was attempted without a valid RX indirection table. This issue was resolved by gating netvsc_set_rxfh() on ndc->rx_table_sz and returning -EOPNOTSUPP when the table is absent. The vulnerability affects the net: hv_netvsc module. The issue arises when the device reports a single receive queue and rndis_filter_device_add() doe [truncated]
A NULL pointer dereference vulnerability was found in the Linux kernel's Marvell Prestera driver. The vulnerability occurs when the devlink_alloc() function returns NULL, but the prestera_devlink_alloc() function unconditionally calls devlink_priv() on the returned pointer, leading to a NULL pointer dereference. This vulnerability affects Linux kernel versions 5.10.1 to 5.15.198, 5.16 to 6.1.161, 6.2 to 6 [truncated]
A vulnerability has been resolved in the Linux kernel, specifically in the ipv4: ip_gre module. The issue arises from the ability of team or bonding drivers to dynamically change their dev->needed_headroom and/or dev->hard_header_len, which can lead to a crash in the ipgre_header() function. This vulnerability affects users of the Linux kernel, particularly those using versions 3.10.1 to 6.19. The vulnera [truncated]
A use-after-free vulnerability was found in the Linux kernel's inet6_addr_del() function. The vulnerability occurs when ipv6_del_addr() is called before reading the ifp->flags for temporary addresses. This can lead to a use-after-free error, allowing an attacker to potentially execute arbitrary code. The issue was introduced by the accidental movement of ipv6_del_addr() for mngtmpaddr before reading its i [truncated]
A vulnerability in the Linux kernel's x86/fpu component could allow a local attacker to cause a denial of service. The vulnerability is due to the failure to clear XSTATE_BV[i] in guest XSAVE state when XFD[i]=1. This could cause the kernel to attempt to load state for features that are disabled via the guest's XFD, resulting in a panic. The vulnerability is addressed in kernel versions 5.17.1, 6.1.162, 6 [truncated]
A HIGH severity vulnerability was found in the Linux kernel, specifically in the ip6_tunnel module. The vulnerability is caused by the improper handling of VLAN encapsulations. An attacker could potentially exploit this vulnerability to cause a denial of service or execute arbitrary code. This issue was resolved by using skb_vlan_inet_prepare() instead of pskb_inet_may_pull(). Linux kernel developers, Lin [truncated]
A reference count leak vulnerability was found in the Linux kernel's bpf_prog_test_run_xdp() function. The vulnerability is caused by a missing call to xdp_convert_buff_to_md() in the error handling path, which can lead to a reference count leak. This issue was reported by syzbot and has been resolved by the Linux kernel maintainers. The vulnerability affects Linux kernel developers and users who rely on [truncated]
A Linux kernel vulnerability was resolved, affecting the ocelot driver. The vulnerability could cause a crash when adding an interface under a lag. This issue specifically affects the ocelot_vsc7514.c frontend, which leaves unused ports as NULL pointers. The felix_vsc9959.c frontend is unaffected as it uses the DSA framework which registers all ports. Linux kernel users and administrators should review th [truncated]
CVE-2026-22980 is a high-severity use-after-free vulnerability in the Linux kernel. The vulnerability exists in the nfsd subsystem and can be exploited to gain unauthorized access to sensitive data or potentially execute arbitrary code. The vulnerability is caused by a race condition between writing to v4_end_grace and server shutdown, which can result in memory being accessed after it was freed. This vul [truncated]
A memory leak vulnerability was found in the Linux kernel's network stack, specifically in the GRO (Generic Receive Offload) packet handling. The issue arises from incorrect socket memory accounting when handling packets that were aggregated by the GRO engine. This leads to a persistent memory leak, preventing socket destruction and causing sk_wmem_alloc to remain non-zero. The vulnerability affects vario [truncated]
CVE-2025-71266 is a Linux kernel ntfs3 vulnerability in directory lookup handling. A malformed dentry can drive indx_find() into a repeated loop over the same index block, and the missing return-value check on fnd_push() allows processing to continue when the node stack is exceeded. The result is repeated 4 KB allocations, memory exhaustion, and a local denial of service, including a hang or OOM crash. NV [truncated]
CVE-2025-71265 is a Linux kernel ntfs3 flaw that can lead to a denial of service when malformed NTFS metadata is encountered. According to the NVD record, the issue is a local vulnerability with low attack complexity and low privileges required, and it affects multiple Linux kernel release branches. The kernel fix referenced by NVD prevents attr_load_runs_range() from spinning forever when run_lookup_entr [truncated]
A race condition in the Linux kernel's MMP PDMA (Peripheral DMA) engine driver can lead to use-after-free when multiple threads query DMA transaction status while a tasklet frees completed descriptors on another CPU. The vulnerability exists in mmp_pdma_residue(), which iterates the chain_running descriptor list without holding the channel's desc_lock spinlock. An interrupt-driven tasklet can concurrently [truncated]
A buffer overflow vulnerability was found in the Linux kernel's w1: therm: alarms_store function. The issue arises from an off-by-one error when allocating memory for the sysfs buffer, leading to a potential buffer overflow when copying data using strcpy(). This vulnerability affects Linux kernel users and distributors, particularly those using the w1: therm module. The vulnerability has a high defensive [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel's dmaengine: idxd component. The vulnerability has been resolved, and patches are available. It relates to device leaks on compat bind and unbind. Linux kernel users and administrators should be aware of this vulnerability and take steps to ensure their systems are up to date. This includes reviewing system configurations, applying available pa [truncated]
A use-after-free vulnerability exists in the Linux kernel's Tegra ADMA driver when audio streams are terminated, particularly during XRUN conditions. The issue occurs when the DMA buffer is freed by tegra_adma_terminate_all() before the vchan completion tasklet finishes accessing it. This can lead to a race condition where the tasklet attempts to access already-freed memory, resulting in a use-after-free bug.
CVE-2025-71161 is a medium-severity vulnerability in the Linux kernel's dm-verity subsystem, specifically affecting its forward error correction (FEC) mechanism. The flaw was resolved by disabling recursive forward error correction, which presented two distinct problems: a potential denial-of-service condition and functional corruption of recovery data. The vulnerability was published on January 23, 2026, [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel, with a CVSS score of 5.5. The vulnerability exists in the crypto: seqiv component. The CVE record was published on 2026-01-14T15:16:02.843Z and was last modified on 2026-07-14T13:18:04.163Z. The vulnerability is caused by the improper use of req->iv after crypto_aead_encrypt is called, which can lead to a use-after-free error. This vulnerabili [truncated]
A buffer overflow vulnerability was found in the Linux kernel's ext4 filesystem implementation. The vulnerability occurs in the parse_apply_sb_mount_options() function, where a string copying operation using strscpy_pad() can overflow a 64-byte buffer if the user provides a non-NUL-terminated string longer than 63 characters. This can lead to a buffer overflow warning and potential memory corruption.
A MEDIUM severity vulnerability was found in the Linux kernel, specifically in the SUNRPC component. The vulnerability is caused by a NULL dereference on a zero-length gss_token in the gss_read_proxy_verf function. This can lead to a denial-of-service (DoS) attack. The vulnerability has a CVSS score of 5.5 and is considered MEDIUM severity. Affected Linux kernel deployments should be inventoried and patch [truncated]
A vulnerability has been identified in the Linux kernel, specifically in the VIA watchdog driver. The driver uses allocate_resource() to reserve a MMIO region for the watchdog control register, but the allocated resource was not given a name. This causes the kernel resource tree to contain an entry marked as '<BAD>' under /proc/iomem on x86 platforms. During boot, this unnamed resource can lead to a criti [truncated]
The Linux kernel was vulnerable to an out-of-bounds memory access issue due to a lack of VLAN id validation when receiving VLAN configuration mailboxes from VF. This vulnerability has been resolved with the addition of VLAN id validation before using it. Affected users should review their deployments, apply patches, and monitor for potential exploitation attempts.
A medium-severity vulnerability, CVE-2025-71104, was found in the Linux kernel's KVM x86. This issue may cause a VM hard lockup after prolonged inactivity with a periodic HV timer. The vulnerability has been resolved through multiple kernel patches. Affected systems may experience hard lockups if not patched. The vulnerability primarily affects Intel CPUs using the HV timer. System administrators should a [truncated]