PatchSiren

Linux CVE debriefs · Page 88

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-06-08

CVE-2026-46283

CVE-2026-46283 is an information disclosure vulnerability in the Linux kernel. The tpm_dev_release() function uses kfree() to free sensitive data, potentially leaving sensitive cryptographic material in freed slab memory. This issue has been resolved by using kfree_sensitive() to ensure session keys are scrubbed during device teardown.

MEDIUM Linux CVE published 2026-06-08

CVE-2026-46282

A NULL pointer dereference vulnerability was found in the Linux kernel's iio: frequency: admv1013 driver. When device_property_read_string() fails, the code falls through to strcmp(), dereferencing a garbage pointer. This issue has been resolved by replacing manual read/strcmp with device_property_match_property_string().

HIGH Linux CVE published 2026-06-08

CVE-2026-46281

A buffer overflow vulnerability exists in the Linux kernel's vmalloc function, specifically in the vrealloc_node_align function. This function is used to reallocate memory and can lead to an out-of-bounds write if the requested size is smaller than the original size. The vulnerability was introduced by a commit that allowed forcing a new allocation if the current pointer is on the wrong NUMA node or if an [truncated]

HIGH Linux CVE published 2026-06-08

CVE-2026-46280

A use-after-free vulnerability was discovered in the Linux kernel's test_hmm module. The vulnerability occurs when the dmirror_fops_release() function is called, which frees the dmirror struct without migrating device private pages back to system memory. This leaves the pages with a dangling zone_device_data pointer to the freed dmirror. If a subsequent fault occurs on those pages, the dmirror_devmem_faul [truncated]

HIGH Linux CVE published 2026-06-08

CVE-2026-46279

A vulnerability was found in the Linux kernel, specifically in the mm/alloc_tag component. The issue arises due to the initialization ordering of page_ext, which is allocated and initialized relatively late during boot. Some pages have already been allocated and freed before page_ext becomes available, leaving their codetag uninitialized. This can cause a warning to trigger when these pages are later recl [truncated]

MEDIUM Linux CVE published 2026-06-08

CVE-2026-46278

A vulnerability was discovered in the Linux kernel, specifically in the drm/imagination component. The issue occurs when updating the ftrace mask, leading to a segmentation fault due to invalid data access. The problem arises from passing incorrect data to a debugfs entry. This vulnerability can be triggered by writing to a debugfs attribute, which causes the kernel to attempt to access a null pointer, re [truncated]

HIGH Linux CVE published 2026-06-08

CVE-2026-46277

A HIGH severity vulnerability was found in the Linux kernel, with a CVSS score of 7.8. The vulnerability is related to the handling of device folios in the mm/zone_device module. Specifically, the issue arises when trying to access a device folio after it has been freed, which can lead to unexpected behavior. The vulnerability has been resolved by using a local stack variable instead of touching the folio [truncated]

MEDIUM Linux CVE published 2026-06-08

CVE-2026-46276

A vulnerability was discovered in the Linux kernel related to the initialization of zero-size GDS range on RDNA4 hardware. The RDNA4 (GFX 12) hardware removes the GDS, GWS, and OA on-chip memory resources. However, the gfx_v12_0 initialization code correctly sets the sizes of these resources to zero to reflect this. The issue arises when amdgpu_ttm_init() unconditionally calls amdgpu_ttm_init_on_chip() fo [truncated]

HIGH Linux CVE published 2026-06-08

CVE-2026-46275

CVE-2026-46275 is a HIGH severity vulnerability in the Linux kernel Bluetooth HCI UART implementation. The vulnerability allows for Use-After-Free (UAF) and Null Pointer Dereference (NPD) conditions due to improper lifecycle management of hci_uart. The primary issue arises from the workqueues (init_ready and write_work) only being flushed/cancelled if the HCI_UART_PROTO_READY flag is set during TTY close. [truncated]

HIGH Linux CVE published 2026-06-08

CVE-2026-46274

A use-after-free vulnerability was discovered in the Linux kernel's io-wq subsystem. The io_wq_remove_pending function did not properly check if the predecessor work was hashed before updating the hash_tail array. This could lead to a dangling pointer being stored in the hash_tail array, allowing for remote code execution.

MEDIUM Linux CVE published 2026-06-08

CVE-2025-71315

A vulnerability in the Linux kernel has been resolved. The vulnerability was related to the drm/vkms module, which has been converted to use DRM's vblank timer. This change replaces vkms' vblank timer with the DRM implementation, which is identical in concept but differs in implementation. The vblank timer calls vkms' custom timeout code via handle_vblank_timeout in struct drm_crtc_helper_funcs.

HIGH Linux CVE published 2026-06-01

CVE-2026-46243

A local privilege escalation vulnerability in the Linux kernel's SMB client (CIFS) subsystem allows unprivileged users to forge cifs.spnego key descriptions, potentially leading to authentication bypass or elevated privileges. The flaw exists because userspace processes could create cifs.spnego keys via request_key(2) or add_key(2) with attacker-controlled authority-bearing fields (pid, uid, creduid, upca [truncated]

HIGH Linux CVE published 2026-05-30

CVE-2026-46242

A use-after-free (UAF) vulnerability in the Linux kernel's eventpoll (epoll) subsystem allows concurrent operations to trigger memory corruption. The flaw exists in ep_remove() where a struct file pointer is used after its reference count may have dropped to zero, enabling writes to freed kmalloc-192 memory and potential attacker-controllable kmem_cache_free() against incorrect slab caches. The vulnerabil [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46241

A use-after-free vulnerability exists in the Linux kernel's MPC52xx SPI controller driver. When SPI controller registration fails, the driver previously failed to properly disable and free allocated interrupts, leading to potential use-after-free conditions and resource leaks. The vulnerability was identified during review of a related controller deregistration fix. The fix ensures proper cleanup of inter [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46240

A use-after-free vulnerability in the Linux kernel's Qualcomm IRIS video driver (media: iris) was introduced by a regression in commit 1dabf00ee206. The flaw occurs in iris_release_internal_buffers() where session_release_buf() may free a buffer, but the caller continues to access the buffer pointer afterward. The fix sets BUF_ATTR_PENDING_RELEASE before calling session_release_buf() and reverts the flag [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46239

A runtime Power Management (PM) reference count leak exists in the OV5647 camera sensor driver within the Linux kernel media subsystem. The vulnerability occurs in the s_ctrl function where three specific V4L2 control cases—AUTOGAIN, EXPOSURE_AUTO, and ANALOGUE_GAIN—execute direct returns without invoking pm_runtime_put(). This omission causes the runtime PM reference count to increment without correspond [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46238

A use-after-free vulnerability exists in the Linux kernel's batman-adv (Better Approach To Mobile Ad-hoc Networking) subsystem, specifically within the BAT IV (BATMAN IV) routing protocol implementation. The vulnerability stems from improper pointer management where originator pointers derived from temporary lookups were cached in neighbor node structures without ownership. These cached pointers could ref [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46237

This CVE addresses an integer overflow vulnerability in the Linux kernel's AMDGPU driver, specifically within the Video Core Next 3 (VCN3) component. The vulnerability exists in a message boundary check condition that could be exploited to cause an overflow, potentially leading to memory corruption or other undefined behavior. The fix was identified through Static Driver Verifier (SDL) analysis and has be [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46236

A DMA coherency vulnerability in the Linux kernel's Xbox remote driver (xbox_remote) has been resolved. The issue involved a buffer for I/O operations being incorrectly placed within the device structure, violating DMA coherency rules. This could lead to memory corruption or undefined behavior during remote control operations. The fix ensures proper memory allocation for DMA operations by separating the I [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46234

A logic error in the Linux kernel's vsock (virtual socket) subsystem allows buffer size constraints to be bypassed when a user-configured minimum exceeds the configured maximum. The vulnerability exists in `vsock_update_buffer_size()`, where clamping operations were performed in incorrect order—maximum bound applied first, then minimum bound. When `buffer_min_size > buffer_max_size`, the second check over [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46233

A NULL pointer dereference vulnerability exists in the Linux kernel's batman-adv (Better Approach To Mobile Ad-hoc Networking) subsystem, specifically within the Bridge Loop Avoidance (BLA) component. The issue occurs in batadv_bla_purge_claims() when traversing claim entries with only rcu_read_lock() protection. A race condition with batadv_claim_put() can encounter a claim being concurrently released by [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46232

A vulnerability in the Linux kernel's HID PlayStation driver could allow a malicious or compromised DualShock 4 controller to trigger an out-of-bounds read of up to approximately 2 KiB. The flaw exists in `dualshock4_parse_report()` where the `num_touch_reports` value provided by the device is used without validation to iterate over the `touch_reports` array. A device reporting up to 256 touch reports wou [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46231

A reference counting vulnerability in the Linux kernel's B.A.T.M.A.N. Advanced (batman-adv) mesh networking subsystem could allow memory exhaustion through object leakage. The flaw occurs in the Bridge Loop Avoidance (BLA) component when batadv_bla_add_claim() fails to insert a new claim into the hash table, leaking a reference to the backbone gateway (backbone_gw) object. Without the proper reference rel [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46230

A bounds-checking vulnerability in the Linux kernel's AMDGPU driver for VCN3 (Video Core Next 3) hardware could allow out-of-bounds (OOB) memory reads when parsing decoder messages. The flaw exists in the VCN3 decode message parsing path where buffer object (BO) bounds were not validated before accessing message data. An attacker with local access could potentially trigger OOB reads, leading to informatio [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46229

A vulnerability in the Linux kernel's AMDGPU KFD (Kernel Fusion Driver) subsystem allows stale VRAM data to persist across allocations, potentially exposing sensitive information from prior GPU computations and causing stability issues in ROCm/RCCL workloads. The KFD VRAM allocation path failed to set the AMDGPU_GEM_CREATE_VRAM_CLEARED flag, which is already present in the standard GEM ioctl and dumb buff [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46228

A vulnerability in the Linux kernel's CH341 USB-to-SPI driver has been resolved. The issue involved incorrect device resource (devres) lifetime management, where controller and driver data were tied to the parent USB device rather than the USB interface. This could lead to memory leaks when drivers were unbound without physical disconnection, such as during probe deferral or configuration changes. The fix [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46227

A use-after-free vulnerability exists in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. The SCTP_SENDALL path in sctp_sendmsg() uses list_for_each_entry_safe() to iterate over endpoint associations, caching the next entry before the loop body executes. When sctp_sendmsg_to_asoc() drops the socket lock via sctp_wait_for_sndbuf(), a concurrent thread can peel off the cached a [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46226

A use-after-free vulnerability exists in the Freescale (NXP) SPI controller driver for the Linux kernel. The flaw occurs during driver unbind, where DMA and other underlying resources are released before the SPI controller is deregistered. This ordering error can lead to invalid memory access if the controller or its consumers attempt to use those resources after they have been freed. The vulnerability is [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46225

A vulnerability in the Linux kernel's Renesas Serial Peripheral Interface (RSPI) driver has been resolved. The issue involved improper ordering of operations during driver unbind, where underlying resources such as DMA could be released before the SPI controller was deregistered. This sequence error could lead to use-after-free conditions or resource management failures when the driver is removed. The fix [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46224

A memory leak vulnerability exists in the Linux kernel's Intel Xe graphics driver (drm/xe). When xe_dma_buf_init_obj() fails during GPU VM reservation object allocation, a pre-allocated buffer object (bo) is not freed, leading to resource exhaustion. The fix adds proper cleanup by calling xe_bo_free(storage) on the error path and documents ownership semantics to prevent future mishandling.