These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A double-free vulnerability exists in the Linux kernel's Intel Ethernet Connection (ice) driver, specifically within the `ice_sf_eth_activate()` function. The flaw occurs in the error handling path when `auxiliary_device_add()` fails. The function calls `auxiliary_device_uninit()`, which triggers `ice_sf_dev_release()` to free the `sf_dev` structure. However, the error path continues to `sf_dev_free` and [truncated]
A divide-by-zero vulnerability exists in the Linux kernel's md/raid10 driver within the setup_geo() function. The function extracts near_copies (nc) and far_copies (fc) values from a user-provided layout parameter without validating that these values are non-zero. When fc equals zero and the 'improved' far set layout is selected, the calculation 'geo->far_set_size = disks / fc' triggers a divide-by-zero c [truncated]
A logic error in the Linux kernel's Btrfs filesystem implementation allows directory removal operations to leave stale metadata that corrupts the journal replay process. When a directory is removed via rmdir(2) while a file descriptor remains open, the kernel fails to update the directory's last_unlink_trans field. If a subsequent fsync is issued on that file descriptor before a power failure, the resulti [truncated]
A Time-of-Check to Time-of-Use (TOCTOU) race condition in the Linux kernel's Btrfs filesystem driver can lead to information disclosure. The vulnerability exists in `btrfs_ioctl_space_info()`, which performs two passes over block group RAID type lists: first to count entries and allocate a buffer, then to fill that buffer. The `groups_sem` rwlock is released between these passes, allowing concurrent block [truncated]
A potential memory leak vulnerability was found in the Linux kernel's MPTCP (Multipath TCP) implementation. When an ADD_ADDR is retransmitted, the socket reference count is not properly decremented in all cases, leading to a potential resource leak. This issue can impact Linux kernel maintainers and users who rely on MPTCP, as it may result in resource exhaustion if exploited. The vulnerability has been r [truncated]
A data race vulnerability in the Linux kernel's ALSA PCM OSS (Open Sound System) compatibility layer could allow concurrent, unprotected access to the `runtime.oss.trigger` bit field. Because this field is a bit field, unsynchronized writes risk corrupting adjacent bit fields, leading to undefined behavior and potential operational confusion. The issue was discovered through fuzzing. The fix adds `params_ [truncated]
A vulnerability in the Linux kernel's LoongArch architecture support could cause an Address Display Error (ADE) panic during PCI device enumeration when a discrete GPU is present on the platform. The issue occurs in `loongson_gpu_fixup_dma_hang()` where an incorrect device address calculation leads to reading from a random memory address when the switch case does not match expected DC2 or DC3 values. The [truncated]
A vulnerability in the Linux kernel's SMB client implementation allows an out-of-bounds read that can leak adjacent kernel heap memory. The flaw exists in smb2_compound_op() where a malicious SMB server can send a truncated response with a large OutputBufferLength value. The check_wsl_eas() function returns success without validating that OutputBufferLength fits within the actual iov_len of the response b [truncated]
A use-after-free (UAF) vulnerability exists in the Linux kernel's sched_ext (SCX) subsystem. The flaw occurs in cgroup setter functions `scx_group_set_{weight,idle,bandwidth}()` where `scx_root` is cached before acquiring the `scx_cgroup_ops_rwsem` lock. This creates a race window: if a scheduler is disabled and freed via RCU work, and a new scheduler is enabled between the naked load and the rwsem acquir [truncated]
CVE-2026-46153 is a memory leak vulnerability in the Linux kernel's 802.1Q VLAN subsystem. The flaw exists in `vlan_dev_set_egress_priority()`, which manages egress QoS priority mappings for VLAN devices. When a priority mapping is cleared (by setting `vlan_prio` to 0), the function previously retained the mapping node as a tombstone in the hash table rather than removing it. Repeated set/clear cycles wit [truncated]
A race condition vulnerability in the Linux kernel's mac80211 Wi-Fi subsystem could cause packet misrouting or state corruption under concurrent receive conditions. The ieee80211_invoke_fast_rx() function was documented as safe for parallel RX, but used a static variable for its rx_result, causing concurrent callers to share and overwrite each other's results. This could lead to packets being incorrectly [truncated]
A heap information disclosure vulnerability exists in the Linux kernel's USB printer driver (usblp). The driver fails to zero-initialize a 1024-byte kmalloc buffer before requesting IEEE 1284 device ID data from USB printers. A malicious or malfunctioning device can complete the control transfer with only 2 bytes (the length prefix), causing the driver to trust a fabricated length value and subsequently e [truncated]
A logic error in the Linux kernel's fanotify subsystem could allow permission checks to be bypassed. The function `fsnotify_get_mark_safe()` may incorrectly return false for a mark belonging to an unrelated group, causing the permission event handler to skip validation. The fix ensures that detached marks not associated with the current fanotify group are properly skipped rather than triggering a false po [truncated]
A buffer over-read vulnerability exists in the Linux kernel's SCSI target subsystem. The function `tg_pt_gp_members_show()` in `drivers/target/target_core_configfs.c` uses `snprintf()` to format LUN paths into a 256-byte stack buffer, then copies the result using `memcpy()` based on `snprintf()`'s return value. Because `snprintf()` returns the length the output *would* have had (not the truncated length), [truncated]
A vulnerability in the Linux kernel's Microchip CoreQSPI driver could cause incorrect chip select signaling when multiple SPI devices are attached to the controller. The hardware-automated chip select would activate during transfers to GPIO-controlled devices, potentially causing data corruption or unintended device operations. The fix implements manual software control of the built-in chip select and rem [truncated]
This CVE addresses two bugs in the KVM arm64 vCPU initialization path within the Linux kernel's protected KVM (pKVM) subsystem. The first bug involves a resource leak where pin references on host vCPU and SVE state pages are not released if a check fails after `hyp_pin_shared_mem()` succeeds, leading to permanent pin leaks. The second bug is a publication ordering issue where `register_hyp_vcpu()` publish [truncated]
A vulnerability in the Linux kernel's ALSA USB audio driver could allow a malformed USB audio descriptor to trigger an endless loop. The convert_chmap_v3() function iterates through channel map descriptors using a size field (cs_desc->wLength) that was not validated, permitting a zero or malformed value to stall the kernel. The fix adds proper bounds checking to abort iteration on invalid descriptor sizes.
A vulnerability in the Linux kernel's RDMA/mana component allows userspace to pass an unchecked rx_hash_key_len value, which can lead to a kernel memory overflow. This issue has been resolved with bounds checking to prevent the memcpy overflow. The vulnerability affects Linux kernel versions 6.2 through 7.0.7, and 7.1 rc1 and rc2. Linux kernel maintainers, Linux distribution maintainers, and users of affe [truncated]
A resource leak vulnerability exists in the Linux kernel's RDMA MANA driver. When `mana_ib_create_qp_rss()` encounters an error condition, the `mana_ib_cfg_vport_steering()` configuration is not properly released during the error unwind path. While the normal destroy path cleans up this resource, the failure path omits this cleanup, leading to a resource leak. This affects systems using Microsoft's MANA ( [truncated]
A memory leak vulnerability exists in the Qualcomm ASoC (ALSA System on Chip) q6apm-lpass-dai driver within the Linux kernel. The issue occurs because the driver's prepare callback can be invoked multiple times during playback operations, resulting in repeated graph opens without proper state tracking. Each redundant graph open allocates resources that are never released, leading to cumulative memory exha [truncated]
A vulnerability in the Linux kernel's libwx network driver allowed Virtual Functions (VFs) to trigger illegal register access, causing system hangs. The issue occurred because the WX_CFG_PORT_ST register is restricted to Physical Functions (PFs), but VFs attempted to read it during initialization. The fix obtains the bus function ID directly from PCI_FUNC(pdev->devfn) when the device is a VF, preventing u [truncated]
A memory leak vulnerability exists in the Linux kernel's XIVE (eXternal Interrupt Virtualization Engine) interrupt controller code on PowerPC architectures. The issue was introduced by commit cc0cc23babc9, which refactored XIVE to untangle it from child interrupt controller drivers. Following this change, the `xive_irq_free_data()` function incorrectly retrieves `chip_data` using `irq_get_chip_data()`, wh [truncated]
A vulnerability in the Linux kernel's Bluetooth MediaTek (btmtk) driver allowed out-of-bounds reads from socket buffer (SKB) tailroom. The btmtk_usb_hci_wmt_sync() function cast WMT event response data to fixed-size structures (7-byte btmtk_hci_wmt_evt and 9-byte btmtk_hci_wmt_evt_funcc) without first validating that the SKB contained sufficient data. A malicious or malfunctioning firmware could send a sh [truncated]
A vulnerability in the Linux kernel's SMB client implementation could cause chmod operations to fail against Samba servers when setting security descriptors. The issue stems from uninitialized heap memory in the reserved field of struct smb_acl, introduced when a prior commit split the num_aces field from 32-bit to 16-bit with a 16-bit reserved field. The build_sec_desc() function used kmalloc() without z [truncated]
A vulnerability in the Linux kernel's Bluetooth subsystem could allow an out-of-bounds read and trigger an infinite loop when processing LE Create BIG Complete events. The hci_le_create_big_complete_evt() function iterates over BT_BOUND connections for a Broadcast Isochronous Group (BIG) handle using a while loop, accessing ev->bis_handle[i++] on each iteration without verifying that the index i remains w [truncated]
A race condition vulnerability in the Linux kernel's Multipath TCP (MPTCP) path manager could allow data corruption or undefined behavior. The mptcp_pm_add_timer() helper function, executed as a timer callback in softirq context, lacked proper socket locking with bh_lock_sock(), creating a potential data race when the socket is concurrently in use. The fix implements retry logic similar to the keepalive t [truncated]
A vulnerability in the Linux kernel's MediaTek MT7921 Wi-Fi driver (mt76) could cause driver initialization failure or near-infinite loop conditions. The issue stems from an integer underflow in buffer length handling when processing Country Location Configuration (CLC) power table data. When buf_len underflows during country power setting retrieval, the driver may either loop excessively or load invalid [truncated]
A race condition in the Linux kernel's NVMe/TCP target implementation (nvmet-tcp) can lead to use-after-free conditions during queue teardown. The vulnerability occurs when nvmet_tcp_handle_icreq() updates queue state after sending an Initialization Connection Response (ICResp) without proper serialization against target-side queue teardown. If a host sends an ICReq and immediately closes the connection, [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's Chrome OS Embedded Controller (cros_ec) Type-C driver. The `cros_typec_register_thunderbolt()` function fails to initialize the `adata->lock` mutex, leading to a NULL dereference when the mutex is subsequently acquired in `cros_typec_altmode_work()`. This is a local vulnerability affecting kernel integrity and availability. The issue ha [truncated]
A vulnerability in the Linux kernel's Soft RoCE (RXE) driver allows unauthenticated remote attackers to trigger kernel panics via a single crafted UDP packet. The flaw exists because packets with unknown/undefined IB opcodes bypass proper validation before ICRC processing, leading to an out-of-bounds read when the rxe_opcode[] array is accessed with a zero-initialized entry. An attacker can exploit this b [truncated]