These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A use-after-free vulnerability was found in the Linux kernel's kmod dups code. The kmod_dup_request_delete function removes the kmod_dup_req from the dup_kmod_reqs list, waits via synchronize_rcu, and finally frees it. However, parallel users referencing the instance in kmod_dup_request_exists_wait don't enter an RCU read-side critical section, which can result in a use-after-free. The issue is fixed by c [truncated]
A vulnerability in the Linux kernel's phy: renesas: rcar-gen2 has been resolved. The issue involves a double of_node_put on phy creation failure. for_each_child_of_node_scoped() releases the node reference on scope exit, so the explicit of_node_put(np) in the devm_phy_create() error path drops it twice. This vulnerability affects Linux kernel maintainers, system administrators, and security teams responsi [truncated]
A vulnerability in the Linux kernel has been resolved, affecting the drm/amdgpu/gfx6 component. The issue involves the use of PFP on compute queues. This change ensures that PFP is used for register writes on both graphics and compute queues, and that the PFP waits for the previous fence to prevent concurrent execution. This update addresses a potential vulnerability in the Linux kernel.
A vulnerability in the Linux kernel's SCSI subsystem has been addressed. The issue arises in the sd_probe() function after a large pool creation failure. If sd_large_pool_create() fails after device_add(&sdkp->disk_dev) succeeds, the disk_dev must be unregistered to prevent resource leaks. The fix ensures proper cleanup by calling scsi_disk_release() to free sdkp, avoiding potential issues with already re [truncated]
A vulnerability in the Linux kernel's btrfs module has been resolved. The issue arises when a freed-but-still-dirty tree block is written out as zeros on a zoned filesystem, potentially destroying the in-memory buffer and causing data corruption. This can lead to data loss or corruption and potentially allow local attackers to escalate privileges or cause a denial of service. Linux system administrators, [truncated]
A use-after-free vulnerability exists in the Linux kernel's Bluetooth L2CAP protocol. The `hci_conn::l2cap_data` is accessed without proper locking in `l2cap_disconn_ind` via `hci_conn_timeout`, leading to potential use-after-free if `l2cap_conn` is deleted concurrently. This vulnerability affects Linux kernel deployments with Bluetooth L2CAP protocol in use, requiring prompt assessment and patching. The [truncated]
A vulnerability in the Linux kernel's Bluetooth HCI connection handling has been addressed. The issue involves the setup context lifetime for SCO (Synchronous Connection-Oriented) connections. When `hci_setup_sync()` queues a connection handle with a NULL destroy callback, the context is not freed if `hci_enhanced_setup_sync()` does not run. This leads to a memory leak when an entry is cancelled. Addition [truncated]
A Linux kernel vulnerability was resolved, affecting the AppArmor component. The vulnerability, CVE-2026-90246, is an integer overflow in the verify_tags() bounds check. An attacker-supplied count close to U32_MAX can cause an out-of-bounds read on the policy load path. This vulnerability can be triggered by an unprivileged task in a matched-level nested namespace, not only by a globally privileged one. T [truncated]
A vulnerability in the Linux kernel's iommu_dma_get_msi_page() function has been resolved. The function did not properly lock around the msi_page_list, allowing for concurrent access and potential corruption of the list. This vulnerability affects systems using VFIO type1 and an IOMMU that publishes IOMMU_RESV_SW_MSI, such as ARM SMMU. The issue arises from the improper locking mechanism, which can lead t [truncated]
A vulnerability in the Linux kernel's iommu/vt-d has been resolved. The issue involves the improper teardown of copied context entries, which could lead to unpredictable behavior or spurious faults. The fix involves clearing the Present bit before tearing down the entry and performing invalidations. This change ensures that hardware cannot fetch torn entries, preventing potential issues. Linux kernel deve [truncated]
A vulnerability in the Linux kernel's iommu/vt-d has been resolved. The issue arises from intel_pasid_setup_sm_context() not properly tearing down scalable-mode context entries on probe failure, potentially leading to the IOMMU walking present context entries that reference freed memory. This can cause system instability or crashes if not addressed. The vulnerability has a CVSS score of 8.2 and is conside [truncated]
A vulnerability in the Linux kernel's iommu/vt-d has been resolved. The issue arises from the incorrect flushing of the context cache when tearing down aliases, leading to the potential use of stale cached entries and allowing the IOMMU to walk freed memory. This vulnerability requires attention from system administrators and security teams to assess exposure and verify kernel versions. The affected produ [truncated]
A vulnerability in the Linux kernel's netfilter component has been addressed. The issue involves custom expectation support in nft_ct, which has been moved to a helper function. This change aims to resolve problems with stale entries in the expectations list when the conntrack is unconfirmed. The fix includes introducing an internal ct helper and a new function, nf_conntrack_helper_release(), to manage th [truncated]
A critical vulnerability has been resolved in the Linux kernel, specifically in the sunrpc module. The vulnerability was caused by a plain store and load of shared socket callbacks, which could lead to a stale callback snapshot being invoked after the live callback fields have been restored to the lower-socket handlers. This could potentially allow an attacker to execute arbitrary code or cause a denial of service.
A Linux kernel vulnerability allows a client to silently drop a delegation granted by an NFS server, potentially causing the server to revoke the delegation and move it to a revoked list, leading to a state manager loop. The vulnerability occurs when an NFS server grants a delegation in an OPEN reply, but the client fails to record it. In certain error flows, the client returns without sending a DELEGRETU [truncated]
A vulnerability in the Linux kernel's AppArmor has been addressed. The unconfined user namespace restriction was not correctly applied when a task was already confined by a stack, allowing for a potential escape through two transitions of an unconfined profile. This HIGH-severity vulnerability, with a CVSS score of 8.4, could enable local attackers to bypass security restrictions and potentially escalate [truncated]
A heap out-of-bounds read vulnerability was found in the Linux kernel's nvmet_auth_negotiate() function. This issue occurs when the function reads past the end of an allocated buffer due to insufficient validation of the transfer length and hash/DH group identifiers provided by a host. This vulnerability can be triggered by a malicious or non-conformant host, potentially leading to a denial of service or [truncated]
A vulnerability in the Linux kernel's nvme-apple module has been resolved. The admin queue is allocated but never destroyed, leading to a potential crash when the controller fails to come up and is then torn down. This issue can be triggered on Apple Mac mini (M1, 2020) systems. The vulnerability can cause a crash due to a NULL pointer dereference when the controller fails and is subsequently torn down. L [truncated]
A NULL pointer dereference vulnerability in the Linux kernel's nvmet_execute_identify_ns_zns() function can be triggered when a host issues an Identify command with CNS 05h and CSI 02h targeting a file-backed namespace. This vulnerability has been resolved. The vulnerability arises from a NULL pointer dereference when a file-backed namespace has no block device. Linux kernel administrators and developers [truncated]
A vulnerability in the Linux kernel has been resolved, allowing unprivileged callers to issue I/O on a partition device or write through a read-only file descriptor due to a missing check in the NVME_IOCTL_SUBMIT_IO ioctl. This issue has been addressed by passing flags and open_for_write through and rejecting disallowed commands with -EACCES. The vulnerability was addressed by adding a check in the NVME_I [truncated]
A race condition vulnerability in the Linux kernel's NFC LLCP (Logical Link Control and Adaptation Protocol) implementation could allow a local attacker to potentially access sensitive information or cause a denial of service. The vulnerability exists in the `nfc_llcp_getsockopt()` function, which reads the `llcp_sock->local` pointer before acquiring the socket lock. If a `bind()` operation is racing with [truncated]
A vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem has been identified and resolved. The issue, tracked as CVE-2026-90224, arises from a double completion race condition in the `nci_data_exchange_complete` function. This function is called concurrently by `nci_close_device` and `nci_rx_work`, leading to a potential reference count underflow and premature socket freeing. The vul [truncated]
A vulnerability in the Linux kernel's NFC LLCP implementation could allow an attacker to trigger an out-of-bounds read. The issue arises from improper parsing of SNL TLVs, which can lead to underflow and buffer overrun. A nearby NFC device can exploit this without authentication, as LLCP link activation occurs automatically after NFC-DEP. This vulnerability has a high severity score and requires immediate [truncated]
A vulnerability in the Linux kernel's bpf (Berkeley Packet Filter) verifier has been addressed. The issue involves comparing iterator types during state pruning to prevent the verifier from pruning an unsafe path. This CVE has a CVSS score of 7.8 and is considered HIGH severity. The vulnerability could potentially allow for privilege escalation or denial of service if exploited. Defenders should assess ex [truncated]
A vulnerability in the Linux kernel has been resolved, affecting the bpf, s390 implementation. The issue involves a missing register clear on faulting arena atomic operations, which could potentially lead to the exposure of sensitive information. This vulnerability was addressed by clearing the fetch destination on faulting arena atomic operations. The fix ensures that the register is cleared to prevent p [truncated]
A use-after-free vulnerability was found in the Linux kernel's bpf_trampoline_multi_attach_free function. When bpf_trampoline_update fails before modify_fentry_multi/unregister_fentry_multi is called, cur_image remains unchanged and ftrace continues to call into it. Freeing old_image in this case results in a use-after-free condition. Only free old_image when it differs from cur_image.
A Linux kernel vulnerability was resolved, addressing a race condition in the ALSA sequencer MIDI input handling. The issue could lead to a NULL pointer dereference when a rawmidi substream is closing while snd_midi_input_event() is running. This vulnerability affects Linux kernel versions and could be exploited remotely, potentially leading to a denial-of-service or code execution. The fix ensures that s [truncated]
A vulnerability in the Linux kernel's OCFS2 filesystem has been addressed. The vulnerability occurs when validating orphan slots during inode read operations. A corrupted dinode with OCFS2_ORPHANED_FL can carry an i_orphaned_slot outside the mounted filesystem slot range. This can lead to an out-of-bounds memory access when ocfs2_wipe_inode() uses it to index osb_orphan_wipes before looking up the orphan directory.
A use-after-free vulnerability exists in the Linux kernel's ocfs2 filesystem implementation. The vulnerability occurs when an active i_dio_orphaned_slot value falls outside the slot range during dinode validation, leading to an invalid cache entry pointer being dereferenced as an inode pointer. This can cause system crashes, instability, or potential elevation of privileges. Linux kernel developers, maint [truncated]
A vulnerability in the Linux kernel's Squashfs implementation can lead to an out-of-bounds access when a negative offset is read from a crafted Squashfs filesystem. This requires CAP_SYS_ADMIN to mount the filesystem, but an unprivileged user can trigger the access by reading a crafted file with a negative offset. The vulnerability was resolved by checking if the offset is negative and returning 0 in such [truncated]