PatchSiren

Linux CVE debriefs · Page 92

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46132

CVE-2026-46132 is an information disclosure vulnerability in the Linux kernel's rtnetlink subsystem. The flaw exists in `rtnl_fill_vfinfo()` where a stack-allocated `struct ifla_vf_broadcast` is not initialized before a partial `memcpy()` copies only 6 bytes of device broadcast address data, leaving 26 bytes of uninitialized kernel stack memory that is subsequently leaked to userspace via `nla_put()`. The [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46131

A logic error in KVM x86 nested virtualization flush hypercalls could lead to invalid memory translations when nested EPT/NPT is disabled. The vulnerability stems from an incorrect condition check: `is_guest_mode(vcpu)` was used to determine whether to call `translate_nested_gpa()`, but this function is only valid when an L2 guest is running with nested EPT/NPT enabled. The fix aligns the condition with ` [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46130

A vulnerability in the Linux kernel's dm-verity-fec (device-mapper verity forward error correction) subsystem could cause out-of-bounds reads from parity block buffers during Reed-Solomon decoding. The issue occurs in `fec_decode_bufs()` when parity bytes for the first RS codeword span across block boundaries—a condition triggered by specific non-default `fec_roots` values combined with low-memory conditi [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46129

A double-free vulnerability exists in the Linux kernel's Btrfs filesystem, specifically within the `create_space_info()` error handling path. The flaw occurs when `kobject_init_and_add()` fails during sysfs registration: the kobject's release callback (`space_info_release()`) already frees the `space_info` structure via `kfree()`, but control returns to `create_space_info()` which then executes another `k [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46128

A vulnerability in the Linux kernel's IPMI subsystem has been resolved. The issue involved insufficient validation of event message buffer response data sizes. Some Baseboard Management Controllers (BMCs) were returning empty messages instead of proper error codes when fetching events, which could lead to processing of malformed data. The fix adds immediate size checking upon response receipt, rather than [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46127

A NULL pointer dereference vulnerability exists in the Linux kernel's RDMA/ocrdma driver. The function `ocrdma_copy_pd_uresp()` in the OCRDMA (Oracle Cloud RDMA) driver references `pd->uctx` in error handling paths before it has been initialized, leading to a kernel crash when error conditions occur. The fix ensures that the valid `uctx` pointer available earlier in the function is used instead of the uni [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46126

A vulnerability in the Linux kernel's RDMA/mana driver affects error handling during queue pair creation with RSS (Receive Side Scaling). The bug involves incorrect cleanup logic in `mana_ib_create_qp_rss()` that can lead to resource leaks or double-decrement issues when unwinding the Work Queue (WQ) table on failure paths. Specifically, a double `i--` decrement occurs on the first failure path due to the [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46125

A use-after-free/double-free vulnerability exists in the Linux kernel's mac80211 Wi-Fi subsystem when Multi-Link Operation (MLO) connection preparation fails. The issue occurs because the interface is reset to non-MLD state without properly removing the associated station, which is tied to the virtual interface link being removed. When debugfs is enabled, this leads to memory corruption as the virtual int [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46124

## Summary CVE-2026-46124 is a hardening fix for the Linux kernel's ISO 9660 filesystem (isofs) NFS export handler. The vulnerability allows an authenticated NFS peer to supply a crafted file handle with an attacker-controlled block number that, while in-range for the backing device, exceeds the ISO filesystem's declared size. This can cause the server to read and interpret unrelated data (e.g., from adja [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46123

A buffer validation flaw in the Linux kernel's Bluetooth virtio transport driver (virtio_bt) allows a malicious or buggy hypervisor/backend to cause information disclosure via uninitialized kernel heap memory. The virtbt_rx_work() function accepts length values from virtqueue_get_buf() without proper bounds checking against the actual buffer size exposed to the device. While the RX buffer is allocated as [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46122

A bounds-checking vulnerability in the Linux kernel's b43 wireless driver allows out-of-bounds memory access when processing received frames. The b43_rx() function accepts a firmware-controlled key index without enforcing array bounds against the 58-entry dev->key[] array. The existing B43_WARN_ON() macro is non-enforcing in production builds, permitting out-of-bounds reads. The fix converts this warning [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46121

A use-after-free vulnerability in the Linux kernel's DAMON (Data Access MONitor) sysfs interface could allow local attackers to trigger memory corruption. The flaw exists in mm/damon/sysfs-schemes where concurrent reads and writes to the 'memcg_path' file could race, causing readers to access freed memory. The vulnerability stems from insufficient locking around user-driven direct reads and writes of damo [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46120

A use-after-free vulnerability exists in the Linux kernel's IPv6 ERSPAN tunnel implementation (ip6_gre). The ip6erspan_changelink() function incorrectly uses dev_net(dev) instead of the cached t->net when re-inserting tunnel entries into per-netns hash tables. This causes a namespace mismatch after IFLA_NET_NS_FD migration: the tunnel is inserted into the wrong namespace's hash while leaving a stale entry [truncated]

CRITICAL Linux CVE published 2026-05-28

CVE-2026-46119

A slab-out-of-bounds access vulnerability exists in the Linux kernel's libceph component during Ceph authentication message processing. The flaw occurs when a corrupted CEPH_MSG_AUTH_REPLY message contains a positive value in its result field, which is incorrectly treated as an error code. This value is subsequently interpreted as a size parameter for the front segment of a CEPH_MSG_AUTH message, potentia [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46118

A null pointer dereference vulnerability in the Linux kernel's pseries/papr-hvpipe driver could allow local attackers to trigger a kernel panic. The flaw was introduced during a refactoring that converted `papr_hvpipe_dev_create_handle()` to use the `FD_PREPARE()` macro, which inadvertently caused `src_info` to be nullified before being reused for list operations. The vulnerability manifests as a kernel N [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46117

A vulnerability in the Linux kernel's RDMA/mana component can be triggered by a user to potentially corrupt the kernel. The issue arises from the user being able to specify Work Queues (WQs) that share the same Completion Queue (CQ) as part of the uAPI, which can trigger a WARN_ON() and subsequently corrupt the kernel. To address this, the QP creation is now outright rejected and fails when such a configu [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46116

A use-after-free vulnerability was found in the Linux kernel's xfrm state management. The vulnerability occurs when the `__xfrm_state_delete` function is called, which can lead to a slab-use-after-free error. This vulnerability can be triggered by a specially crafted sequence of system calls, potentially allowing an attacker to escalate privileges or cause a denial-of-service.

CRITICAL Linux CVE published 2026-05-28

CVE-2026-46115

CVE-2026-46115 is a Linux kernel vulnerability in the block layer's segment merging logic. The biovec_phys_mergeable() function, used by request merging, DMA mapping, and integrity merge paths, lacked a check for whether physically contiguous bvec segments belong to different dev_pagemaps. When zone device memory is registered in multiple chunks, each chunk receives its own dev_pagemap. A single bio can c [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46114

A remote information disclosure vulnerability exists in the Linux kernel's RDMA/rxe (Soft-RoCE) driver. The `atomic_write_reply()` function in `drivers/infiniband/sw/rxe/rxe_resp.c` unconditionally dereferences 8 bytes from the packet payload without validating that the payload contains exactly 8 bytes as required by the InfiniBand Architecture specification (IBA oA19-28). The `check_rkey()` function prev [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46113

A use-after-free vulnerability in the Linux kernel's KVM x86 shadow MMU implementation allows privilege escalation and denial of service. The flaw occurs when guest page tables are modified between VM entries, causing KVM to create stale reverse map (rmap) entries that reference freed kvm_mmu_page structures. When a memslot is deleted, the rmap walk fails to locate entries outside the expected GFN range, [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46112

A race condition vulnerability exists in the Linux kernel's RDMA/hns driver where hns_roce_qp_remove() is called without holding required locks during error handling in hns_roce_create_qp_common(). This unlocked access risks memory corruption during queue pair creation failure paths. The fix ensures proper lock acquisition matching other callers' patterns.

HIGH Linux CVE published 2026-05-28

CVE-2026-46111

A use-after-free (UAF) vulnerability in the Linux kernel's Bluetooth subsystem could allow local attackers to trigger memory corruption during BIG (Broadcast Isochronous Group) creation. The flaw exists in create_big_sync() and create_big_complete() where stale hci_conn connection objects may be dereferenced after being freed. The fix adds hci_conn_valid() validation checks, reference counting via hci_con [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46110

A NULL pointer dereference vulnerability exists in the Linux kernel's stmmac network driver when receive buffer memory is exhausted. The driver's receive loop can confuse 'dirty' descriptors (buffer NULL, OWN=0) with 'full' descriptors (buffer valid, OWN=0), leading to a NULL dereference when processing a descriptor whose buffer was already consumed. This occurs when stmmac_rx_refill() fails to allocate n [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46109

A memory leak vulnerability exists in the Linux kernel's USB ULPI (UTMI+ Low Pin Interface) subsystem. The issue occurs in the `ulpi_register()` function when error paths are taken before `device_register()` is called. Specifically, if `ulpi_of_register()` or `ulpi_read_id()` fail, the allocated `ulpi` structure is not freed, resulting in a memory leak. This vulnerability was introduced when a previous fi [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46108

A state management vulnerability in the Linux kernel's IPMI System Interface (SI) driver could cause the driver to become unresponsive when message allocation fails. The flaw occurs because the driver fails to return to a normal operational state after certain message allocation failures, leaving the IPMI interface stalled. The fix ensures proper state recovery to maintain driver availability.

HIGH Linux CVE published 2026-05-28

CVE-2026-46107

A reference count underflow vulnerability exists in the Linux kernel's device-mapper thin provisioning target (dm-thin). The flaw occurs in the `rebalance_children` function during B-tree rebalancing operations. When an internal B-tree node contains exactly one entry, the code attempts to migrate all entries from the child node to the parent node and then decrements the child's reference count. If the chi [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46106

A race condition in the Linux kernel's eventfs subsystem allows use-after-free and memory corruption during concurrent remount operations and event descriptor modifications. The vulnerability exists because tracefs_apply_options() held only rcu_read_lock() while walking eventfs_inode children during remount, but this protection is insufficient against list_del_rcu() operations in eventfs_remove_rec() and [truncated]

HIGH Linux CVE published 2026-05-28

CVE-2026-46105

A vulnerability in the Linux kernel's mpt3sas SCSI driver could allow oversized NVMe I/O requests to trigger a kernel oops. The driver allocates a fixed 4K buffer for PRP (Physical Region Page) lists, supporting at most 512 entries and thus a maximum 2 MiB transfer size. However, the HBA firmware reports NVMe MDTS (Maximum Data Transfer Size) values based on underlying drive capabilities, which may exceed [truncated]

MEDIUM Linux CVE published 2026-05-28

CVE-2026-46104

A vulnerability in the Linux kernel's SELinux implementation could cause incorrect security decisions in stacked LSM configurations. The `sock_has_perm()` and `nlmsg_sock_has_extended_perms()` functions directly dereferenced `sk->sk_security`, assuming SELinux's socket blob resides at offset zero. When another LSM allocates socket blob storage first, these helpers read the wrong blob, potentially feeding [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-46103

A memory management vulnerability in the Linux kernel's USB CAN driver (ucan) could lead to resource leaks when drivers are unbound without physical disconnection. The issue stems from improper device resource (devres) lifetime management where control message buffers were tied to the parent USB device rather than the USB interface. This affects scenarios such as probe deferral or configuration changes wh [truncated]