PatchSiren

Linux CVE debriefs · Page 89

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46223

A vulnerability in the Linux kernel's cgroup subsystem could cause system-wide A-A deadlocks during cgroup rmdir operations. The issue stems from a chain of commits (v7.0+) that reworked rmdir to satisfy controller invariants, specifically the requirement that a subsystem's ->css_offline() must not run while tasks are still doing kernel-side work in the cgroup. The problematic commit sequence moved task c [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46222

A null pointer dereference vulnerability exists in the Linux kernel's Rockchip Camera Interface (rkcif) driver. The issue stems from missing MUST_CONNECT flag validation on media pads, allowing stream enablement without verifying that connected devices are present. When streaming is initiated on an unconfigured interface, the driver dereferences a null pointer at offset 0x20 in rkcif_interface_enable_stre [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46221

A memory leak vulnerability in the Linux kernel's EDAC (Error Detection and Correction) driver for AMD/Xilinx Versal NET platforms has been resolved. The issue occurred in the `init_one_mc()` function where a device name was allocated via `kzalloc()` and assigned to `dev->init_name`. After `device_register()` executes, it copies the `init_name` value and sets `dev->init_name` to NULL, leaving the original [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46220

A local denial-of-service vulnerability exists in the Linux kernel's AMDGPU SDMA4 driver. The `sdma_v4_0_ring_emit_fence()` function contained `BUG_ON()` assertions verifying dword alignment of fence writeback addresses. These assertions were reachable from unprivileged userspace through crafted `DRM_IOCTL_AMDGPU_CS` submissions, causing fatal kernel panics in scheduler worker threads. The fix replaces bo [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46219

A use-after-free vulnerability exists in the Freescale MPC52xx SPI driver within the Linux kernel. The issue occurs during driver unbind operations when the state machine work, scheduled by the interrupt handler, is not properly cancelled after interrupts are disabled. This timing window allows the work to execute after the driver data structures have been freed, leading to memory corruption. The vulnerab [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46218

A bounds-checking vulnerability in the Linux kernel's AMDGPU DRM driver affects the indirect buffer (IB) access routines used by UVD, VCE, and VCN video acceleration engines. The `ib_get_value` and `ib_set_value` functions previously accessed IB memory at predefined offsets without verifying that the buffer was sufficiently large, potentially leading to out-of-bounds memory access. The fix adds explicit b [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46217

A vulnerability in the Linux kernel's AMDGPU VCN4 driver has been resolved. The issue involved an integer overflow vulnerability in a message boundary check condition, as identified by SDL (Software Development Lifecycle) analysis. The fix prevents potential overflow during bound checking operations in the VCN4 (Video Core Next 4) driver component. The vulnerability was addressed by cherry-picking commit [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46216

## Summary CVE-2026-46216 is a NULL pointer dereference vulnerability in the Linux kernel's Intel Xe graphics driver (drm/xe/hdcp). When the media GT (Graphics Technology) is disabled via configfs, `media_gt` remains NULL. The function `intel_hdcp_gsc_check_status()` dereferences this pointer to access `gt->uc.gsc`, causing a kernel page fault. The fix adds a NULL check on `media_gt` and returns early if [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46215

A use-after-free vulnerability in the Linux kernel's Direct Rendering Manager (DRM) subsystem has been resolved. The flaw existed in the `change_handle` function, where a race condition could occur during prime handle swapping. The ioctl temporarily created a single GEM object with two IDR entries; a concurrent `gem_close` operation could delete the object and remove one handle while leaving the other dan [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46214

A logic error in the Linux kernel's virtio vsock transport causes the accept queue backlog counter to leak when transport assignment fails or selects a non-virtio transport. The vulnerability exists in virtio_transport_recv_listen(), which increments sk_ack_backlog via sk_acceptq_added() before validating the transport assignment. When vsock_assign_transport() fails or returns a different transport, the e [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46213

A use-after-free (UAF) vulnerability exists in the Linux kernel's HID appletb-kbd driver, specifically in the inactivity-timer cleanup path during driver teardown. The flaw stems from two distinct race windows where the inactivity timer remains reachable after resources are freed. Window A occurs when put_device() is called before timer_delete_sync(), allowing the timer softirq to access a freed backlight [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46212

A use-after-free vulnerability exists in the Linux kernel's batman-adv (Better Approach To Mobile Ad-hoc Networking) subsystem, specifically within the Bridge Loop Avoidance (BLA) component. The flaw occurs in batadv_bla_del_backbone_claims() when removing claims for a backbone gateway. The function incorrectly drops the reference count via batadv_claim_put() before completing all accesses to the claim ob [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46211

A vulnerability in the Linux kernel's DRM/MSM GEM subsystem allows `msm_ioctl_gem_info_get_metadata()` to unconditionally return success (0) even when errors occur. The function fails to propagate error codes from `copy_to_user()` failures or undersized user buffers, misleading userspace into believing the ioctl succeeded. Additionally, a missing NULL check on `kmemdup()` return values permits NULL pointe [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46210

A use-after-free vulnerability exists in the Linux kernel's Qualcomm IRIS video driver (drivers/media/platform/qcom/iris). The flaw occurs due to a race condition between the Macro Blocks Per Frame (MBPF) checker and instance teardown. The MBPF checker iterates through active instances under core->lock to validate format dimensions, while iris_close() frees fmt_src and fmt_dst under inst->lock without fir [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46209

A vulnerability in the Linux kernel's Direct Rendering Manager (DRM) subsystem allows an attacker to bypass GEM object size validation, potentially leading to out-of-bounds memory access on the GPU. The root cause is an inconsistency between how plane dimensions are calculated in drm_gem_fb_init_with_funcs() (using plain integer division) versus framebuffer_check() (using DIV_ROUND_UP rounding). For certa [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46208

A use-after-free vulnerability exists in the Linux kernel's batman-adv (Better Approach To Mobile Ad-hoc Networking) subsystem. The tp_meter (throughput meter) sessions remain linked on bat_priv->tp_list after netlink requests complete. When a mesh interface is removed, batadv_mesh_free() tears down the mesh without first draining these active sessions. A running sender thread or late incoming tp_meter pa [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46207

A vulnerability in the Linux kernel's virtio-vsock transport layer could cause uninitialized data to be delivered to the vsockmon monitoring interface when handling non-linear socket buffers (skbs). The issue stems from virtio_transport_build_skb() failing to properly initialize iov_iter.count when copying payload data for non-linear buffers, resulting in zero bytes copied and leaving monitor tap data uni [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46206

A race condition in the Linux kernel's B.A.T.M.A.N. advanced (batman-adv) mesh networking subsystem could allow improper tp_meter session initialization during mesh teardown. The vulnerability exists because tp_meter sender and receiver sessions could be started after the mesh state had already transitioned away from BATADV_MESH_ACTIVE, potentially leading to use-after-free conditions or undefined behavio [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46205

A vulnerability in the Linux kernel's staging media atomisp driver has been resolved by disabling all private IOCTL handlers. The fix prevents potential security issues arising from unsafe IOCTL implementations by returning early when any non-zero command is received, rather than removing the code entirely to maintain static analysis compatibility.

HIGH Linux CVE published 2026-05-28

CVE-2026-46204

A vulnerability in the Linux kernel's AMDGPU driver for VCN4 (Video Core Next 4) hardware could allow out-of-bounds (OOB) memory reads during command buffer parsing. The issue stems from insufficient bounds checking when parsing Indirect Buffers (IBs) in the VCN4 video decode/encode engine driver. The fix rewrites the IB parsing logic to use `amdgpu_ib_get_value()`, a helper function that performs proper [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46203

A vulnerability in the Linux kernel's Cadence Quad SPI (QSPI) driver could allow unclocked register access during driver unbind operations. The issue occurs when the controller is not runtime resumed before being disabled, potentially leading to undefined behavior or system instability. The fix ensures proper runtime power management state before controller disablement.

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46202

## Summary CVE-2026-46202 is a Linux kernel bug in the `hid-appletb-kbd` driver (Apple Touch Bar keyboard HID support). The driver’s backlight autodim logic called `backlight_device_set_brightness()`—which takes a mutex—from two atomic contexts: a timer-list softirq callback and input-event handlers running in IRQ/softirq context. This triggered “sleeping function called from invalid context” warnings and [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46201

A resource leak vulnerability in the Linux kernel's Xe graphics driver (drm/xe) could allow memory exhaustion or system instability. The flaw occurs in xe_gem_prime_import() where a DMA-BUF attachment is not properly detached when xe_dma_buf_init_obj() fails, leading to a reference count leak. The vulnerability affects kernel versions receiving stable backports. Patches are available from the Linux kernel [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46200

A use-after-free vulnerability in the Linux kernel's Freescale MPC52xx SPI driver could allow local attackers to cause denial of service or potentially escalate privileges. The flaw occurs because the SPI controller is deregistered after underlying resources (interrupts, GPIOs) have already been disabled and released during driver unbind, creating a race condition where the controller may attempt to acces [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46199

A bounds-checking vulnerability in the Linux kernel's AMDGPU VCN4 (Video Core Next 4) driver could allow out-of-bounds (OOB) memory reads when parsing decoder messages. The flaw exists because the driver previously failed to validate buffer object (BO) bounds before accessing message data. An attacker with local access could potentially exploit this to read kernel memory, leading to information disclosure [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46198

An integer overflow vulnerability exists in the Linux kernel's batman-adv (Better Approach To Mobile Ad-hoc Networking) subsystem. The flaw occurs in `batadv_iv_ogm_send_to_if` where `buff_pos` is declared as `s16` (signed 16-bit), but size validation in `batadv_iv_ogm_aggr_packet` uses `int` type. This type mismatch can cause integer overflow, leading to out-of-bounds read conditions when processing aggr [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46197

A vulnerability in the Linux kernel's AMD GPU kernel driver (amdkfd) allowed out-of-bounds buffer access through the SVM (Shared Virtual Memory) ioctl interface. The flaw stemmed from insufficient validation of the `nattr` field, which specifies the number of attributes in a user-supplied buffer. Without proper bounds checking against the actual buffer size, a user-controlled attribute count could trigger [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46196

A logic error in the Linux kernel's tracepoint subsystem can leave syscall tracing permanently enabled across all tasks when memory allocation fails during probe installation. The vulnerability occurs in tracepoint_add_func() when a 0→1 transition invokes ext->regfunc() before func_add(), but func_add() fails (e.g., -ENOMEM from allocate_probes()) without triggering the matching ext->unregfunc(). For sysc [truncated]

CRITICAL Linux CVE published 2026-05-28

CVE-2026-46195

This CVE addresses an integer overflow vulnerability in the Linux kernel's SMB client implementation. The flaw exists in how the kernel parses security descriptors from SMB servers, specifically in the handling of the DACL (Discretionary Access Control List) offset field. On 32-bit systems, a malicious SMB server can supply a dacloffset value near U32_MAX that causes pointer arithmetic to wrap below the v [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46194

A race condition in the Linux kernel's F2FS (Flash-Friendly File System) extent tree management can trigger a kernel bug check (f2fs_bug_on) during inode destruction. The vulnerability occurs when f2fs_destroy_extent_node() clears extent nodes without first setting the FI_NO_EXTENT flag, allowing concurrent writeback operations to insert new extent nodes into the same tree. This race leaves the node count [truncated]