PatchSiren

Linux CVE debriefs · Page 90

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46193

A vulnerability in the Linux kernel's XFRM AH (Authentication Header) implementation causes incorrect offset calculations during asynchronous hash completion callbacks when Extended Sequence Number (ESN) is enabled. The async setup path allocates a 4-byte seqhi slot before the ICV/auth_data area, but the completion callbacks reconstruct the temporary layout without accounting for this slot, causing AH to [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46192

A vulnerability in the Linux kernel's Microchip Core QSPI driver could cause SPI transfer failures during emulated read-only dual/quad operations. The driver incorrectly attempted to transmit garbage data to generate clock cycles, which conflicts with how the QSPI core handles read operations internally. Since QSPI lacks a dedicated master-out line like standard SPI's MOSI, this transmission behavior corr [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46191

A vulnerability in the Linux kernel's framebuffer console (fbcon) subsystem could allow out-of-bounds (OOB) memory access when console rotation fails. The issue occurs in fbcon_rotate_font(), which previously retained an old, undersized font buffer when reallocation for rotated console output failed. Subsequent character output with sufficiently high character codes could then overflow this buffer. The fi [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46190

A vulnerability in the Linux kernel's SPI NOR flash driver debugfs interface could allow out-of-bounds memory reads. The issue stems from an incorrect size calculation when passing an array of flag names to a helper function.

HIGH Linux CVE published 2026-05-28

CVE-2026-46189

A double-free vulnerability was found in the Linux kernel's RDMA/vmw_pvrdma module. This issue occurs on the error path of pvrdma_alloc_ucontext() when pvrdma_uar_free() is called prematurely, leading to a double-free condition. The vulnerability affects Linux kernel versions and could lead to potential exploitation if not addressed. Linux kernel developers and maintainers should verify affected versions [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46188

A NULL pointer dereference vulnerability exists in the Linux kernel's octeon_ep_vf driver. The function `napi_build_skb()` can return NULL on memory allocation failure, but `__octep_vf_oq_process_rx()` uses this return value without validation in both single-buffer and multi-fragment receive paths. This flaw could lead to kernel crashes when the system is under memory pressure. The vulnerability was resol [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46187

A use-after-free (UAF) vulnerability exists in the Linux kernel's RSI (Redpine Signals) Wi-Fi driver due to a race condition in kthread lifetime management. The driver uses both self-exit (kthread_complete_and_exit) and external-stop (kthread_stop) mechanisms when terminating kernel threads. While kthread_stop() is typically called first without issue, a rare race where kthread_complete_and_exit() execute [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46186

A vulnerability in the Linux kernel's Bluetooth virtio transport driver (virtio_bt) allowed a malicious or compromised backend to trigger out-of-bounds memory reads. The virtbt_rx_handle() function processed received packets without validating that the remaining payload length met the minimum header size requirements for the declared packet type (event, ACL, SCO, or ISO). A one-byte packet could reach hci [truncated]

CRITICAL Linux CVE published 2026-05-28

CVE-2026-46185

A vulnerability in the Linux kernel's SMB client implementation could allow an out-of-bounds read when processing malformed symbolic link error responses. The issue stems from insufficient length validation in the `smb2_check_message()` function, which returns success without verifying the response length for symlink error responses. Subsequently, in `symlink_data()`, the code accesses fields at offsets 6 [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46184

A division-by-zero vulnerability in the Linux kernel's UA-101 USB audio driver could allow a malicious USB device to crash the kernel. The flaw exists in the Edirol UA-101 driver (sound/usb/ua101.c), where a missing validation of the bNrChannels field in USB audio class descriptors leads to a zero divisor in URB completion handlers. An attacker with physical access could connect a crafted USB device repor [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46183

A use-after-free vulnerability exists in the Linux kernel's DAMON (Data Access MONitor) sysfs interface. The `damon_sysfs_quot_goal->path` field can be read and written by users via the DAMON sysfs 'path' file. While reads for parameter committing to DAMON are protected by `damon_sysfs_lock`, user-driven direct reads and writes were not protected. A writer could deallocate the path-pointing buffer while a [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46182

A kernel stack memory leak vulnerability in the Linux kernel's pseries/papr-hvpipe subsystem has been resolved. The issue stemmed from incomplete initialization of a stack-allocated `struct papr_hvpipe_hdr` structure, where reserved padding bytes (`reserved[3]` and `reserved2[40]`) could leak uninitialized kernel stack memory to userspace via `copy_to_user()`. The fix ensures complete zero-initialization [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46181

A race condition vulnerability in the Linux kernel's RDMA/mlx4 driver could allow system crashes due to improper synchronization during Shared Receive Queue (SRQ) event handling. The flaw stems from incorrect use of RCU (Read-Copy-Update) synchronization in mlx4_srq_event(), where the SRQ structure was accessed without adequate protection against partially initialized objects. The vulnerability could be t [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46180

A use-after-free vulnerability exists in the Linux kernel's brcmfmac Wi-Fi driver, specifically in the watchdog task teardown path. The race condition occurs when the watchdog task terminates between send_sig() and kthread_stop() calls, potentially leading to memory corruption. The fix increases the watchdog task's reference count before signal delivery and uses kthread_stop_put() to properly release the [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46179

A divide-by-zero vulnerability exists in the Linux kernel's ALSA System-on-Chip (ASoC) Sound Open Firmware (SOF) subsystem. When reporting the pointer position for a compressed audio stream, the driver divides the current I/O frame position by the product of channel count and container byte size. These configuration values default to zero and are only populated when stream parameters are explicitly set. I [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46178

A resource leak vulnerability exists in the Linux kernel's RDMA/mlx4 driver. The mlx4_ib_create_srq() function fails to call mlx4_srq_free() during error unwind paths after mlx4_srq_alloc() has been called, leading to a resource leak. This affects systems using Mellanox ConnectX-3 InfiniBand/Ethernet adapters with the mlx4 driver. The vulnerability was resolved by adding the missing mlx4_srq_free() call i [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46177

A vulnerability in the Linux kernel's IPMI driver could allow a misbehaving Baseboard Management Controller (BMC) to cause denial of service through unbounded event/message fetching loops. The driver previously lacked limits on how many events or messages it would fetch from the BMC in a single operation, and could become stuck if the BMC's attention bit remained asserted. The fix introduces a hard limit [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46176

A logic error in the Linux kernel's RDMA/mlx5 driver allows use-after-free and NULL/ERR_PTR dereference when SRQ initialization fails. The vulnerability exists in mlx5_ib_dev_res_srq_init(), which allocates two shared receive queues (s0 and s1). When ib_create_srq() fails for s1, the error path destroys s0 but falls through to unconditionally assign both the freed s0 and the error-valued s1 to device reso [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46175

A vulnerability in the Linux kernel's F2FS (Flash-Friendly File System) could cause filesystem consistency check (fsck) failures following a sudden power loss. The issue occurs during Foreground Garbage Collection (FGGC) of node blocks, where the garbage collector fails to clear dentry and fsync marks during node block migration. This causes fsck to incorrectly interpret migrated node blocks as user-issue [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46173

A race condition in the Linux kernel's task exit path allows a preempted TASK_DEAD task to cause use-after-free or double-free of task stacks, potentially leading to memory corruption and two tasks executing on the same stack. The vulnerability occurs when an oopsing task calls do_task_dead() with preemption enabled, violating the scheduler's precondition that __schedule() must be called with preemption d [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46172

A memory leak vulnerability exists in the Linux kernel's IPv6 IPsec implementation. The function `xfrm6_rcv_encap()` in the IPv6 transform subsystem fails to release a destination cache (dst) entry reference when an error route is encountered during packet processing. Specifically, when `ip6_route_input_lookup()` returns an error route (indicated by `dst->error` being set), the code path jumps to a drop h [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46171

A memory leak vulnerability exists in the Linux kernel's RISC-V KVM (Kernel-based Virtual Machine) subsystem, specifically within the vector context allocation routine. When `kvm_riscv_vcpu_alloc_vector_context` fails to allocate memory for `host_context.vector.datap` via the second `kzalloc` call, the previously allocated `guest_context.vector.datap` is not freed, resulting in a resource leak. This flaw [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46170

A use-after-free vulnerability was found in the Linux kernel's MPTCP implementation. When an ADD_ADDR is retransmitted, the associated socket is not properly released, leading to a potential denial-of-service condition. This vulnerability requires local access and specific configuration to exploit. Patches are available to mitigate the vulnerability. The affected product is the Linux kernel, and the vulne [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46169

A use of uninitialized value vulnerability exists in the Linux kernel's HFS+ filesystem driver. When mounting a corrupted HFS+ filesystem, the hfs_brec_read() function fails to validate that the on-disk catalog record size matches the expected size for the record type being read. This allows a partial read where fewer bytes are read than expected, leaving portions of a 520-byte structure uninitialized. Th [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46168

A vulnerability in the Linux kernel's Multipath TCP (MPTCP) implementation could cause system instability through a scheduling-while-atomic condition. The issue occurs when setting socket timestamp options, where an atomic locking primitive was incorrectly used around functions that may sleep.

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46167

A vulnerability in the Linux kernel's USB printer driver (usblp) allows information disclosure via an uninitialized heap memory leak. The statusbuf buffer, allocated via kmalloc(8) at probe time, is never initialized before the first LPGETSTATUS ioctl. When usblp_read_status() requests 1 byte and a malicious or misbehaving USB printer responds with zero bytes, the driver returns one byte of stale heap mem [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46166

A slab-use-after-free vulnerability in the Linux kernel's mac80211 wireless subsystem has been resolved. The issue occurred in the radar detection work handler where unsafe list iteration could lead to accessing freed memory when `ieee80211_dfs_cac_cancel` is called. The fix implements safe list iteration to prevent the use-after-free condition when channel contexts are freed and removed from the list dur [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46165

A self-deadlock vulnerability exists in the Linux kernel's Open vSwitch (OVS) vport implementation during the release of tunnel ports. The issue stems from improper ordering of RCU callback scheduling relative to RTNL lock release when deleting tunnel vports. In the vulnerable code path, netdev_put() was scheduled via call_rcu() after rtnl_unlock(), but rtnl_unlock() invokes netdev_run_todo() which blocks [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46164

A double-free vulnerability exists in the Linux kernel's Btrfs filesystem driver, specifically within the `create_space_info_sub_group()` function. When `kobject_init_and_add()` fails during sysfs registration, the error handling path incorrectly frees memory that has already been released by the kobject's release callback. This occurs because `kobject_put()` triggers `space_info_release()`, which calls ` [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46163

A bounds-checking vulnerability in the Linux kernel's b43legacy wireless driver could allow out-of-bounds memory access during frame reception. The b43legacy_rx() function accepts a firmware-controlled key index without enforcing validation against dev->max_nr_keys. While a B43legacy_WARN_ON macro exists, it is non-enforcing in production builds, permitting invalid indices to trigger out-of-bounds reads o [truncated]