These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in the Linux kernel's mpt3sas SCSI driver could allow oversized NVMe I/O requests to trigger a kernel oops. The driver allocates a fixed 4K buffer for PRP (Physical Region Page) lists, supporting at most 512 entries and thus a maximum 2 MiB transfer size. However, the HBA firmware reports NVMe MDTS (Maximum Data Transfer Size) values based on underlying drive capabilities, which may exceed [truncated]
A vulnerability in the Linux kernel's SELinux implementation could cause incorrect security decisions in stacked LSM configurations. The `sock_has_perm()` and `nlmsg_sock_has_extended_perms()` functions directly dereferenced `sk->sk_security`, assuming SELinux's socket blob resides at offset zero. When another LSM allocates socket blob storage first, these helpers read the wrong blob, potentially feeding [truncated]
A memory management vulnerability in the Linux kernel's USB CAN driver (ucan) could lead to resource leaks when drivers are unbound without physical disconnection. The issue stems from improper device resource (devres) lifetime management where control message buffers were tied to the parent USB device rather than the USB interface. This affects scenarios such as probe deferral or configuration changes wh [truncated]
A memory leak vulnerability exists in the Linux kernel's stream parser (strparser) subsystem. When the stream parser is aborted—such as after a message assembly timeout—it may retain a reference to a partially assembled message in `strp->skb_head`. This socket buffer (skb) is not released in `strp_abort_strp()`, causing the partially assembled message to leak. Repeated triggering of this condition can exh [truncated]
A vulnerability in the Linux kernel's netfilter subsystem could allow undefined behavior when processing malformed nftables rules. The nft_bitwise expression, used for bitwise operations in packet filtering rules, failed to validate zero-value shift operands during initialization. When a zero shift is specified, the carry propagation logic computes `BITS_PER_TYPE(u32) - shift`, resulting in a 32-bit shift [truncated]
A memory leak vulnerability exists in the Linux kernel's AFS (Andrew File System) implementation due to improper use of the .mmap_prepare() callback. The vulnerability stems from a partial revert of commit 9d5403b1036c, which had converted generic_file_*mmap() users to .mmap_prepare(). The core issue is that .mmap_prepare() is invoked at a point where subsequent memory merge operations or allocation failu [truncated]
A use-after-free vulnerability was found in the Linux kernel's IPv6 seg6 and rpl lwtunnels. The vulnerability occurs when a concurrent task releases a pcpu_rt while ksoftirqd is preemptible, leading to a use-after-free error when trying to cache the dst. This issue affects Linux kernel versions 4.12 to 5.15.209, 5.16 to 6.1.175, 6.2 to 6.6.140, 6.7 to 6.12.86, 6.13 to 6.18.27, 6.19 to 7.0.4, and 7.1 rc1.
A use-after-free vulnerability in the Linux kernel's EDT FT5x06 touchscreen driver (edt-ft5x06) was resolved. The issue stemmed from a race condition between debugfs teardown and buffer access. Commit 68743c500c6e removed manual debugfs teardown in favor of I2C core handling, but this created a window where debugfs files remained accessible after edt_ft5x06_ts_teardown_debugfs() freed tsdata->raw_buffer. [truncated]
A memory leak vulnerability exists in the Linux kernel's TPM2 (Trusted Platform Module 2.0) session handling code. The function `tpm2_read_public()` in the `tpm2-sessions` subsystem allocates a buffer via `tpm_buf_init()` but fails to release it on two specific code paths: (1) when `name_size()` returns an error due to an unrecognized hash algorithm, and (2) on the success path. This results in a page all [truncated]
A race condition vulnerability in the Linux kernel's MD (Multiple Device) driver bitmap subsystem has been resolved. The issue existed in the md-llbitmap module, where barrier operations were incorrectly ordered relative to state machine transitions in the `llbitmap_start_write()` and `llbitmap_start_discard()` functions. The vulnerability could allow the state machine to complete before the barrier was p [truncated]
A bounds check flaw in the Linux kernel's ext4 filesystem xattr validation code allows out-of-bounds memory reads. The vulnerability exists in check_xattrs() where the loop condition (void *)next >= end permits the xattr entry pointer to advance within sizeof(u32) bytes of the buffer end. On the subsequent iteration, IS_LAST_ENTRY() performs a 4-byte read that can exceed the allocated xattr region, potent [truncated]
A race condition in the Linux kernel's vmalloc subsystem could lead to memory leaks when the shrinker path and purge path execute concurrently. The vulnerability exists because decay_va_pool_node() lacks proper serialization when invoked from vmap_node_shrink_scan() via the shrinker, while __purge_vmap_area_lazy() already holds vmap_purge_lock. The fix adds vmap_purge_lock acquisition in the shrinker path [truncated]
A null-pointer dereference vulnerability in the Linux kernel's Realtek rtw88 Wi-Fi driver could cause system crashes during device probe when the 8821CE chipset is installed in systems with a root bus PCI topology. The issue occurs because pci_upstream_bridge() returns NULL when no PCI-to-PCI bridge exists upstream, and the driver previously did not validate this return value before applying a workaround. [truncated]
A DMA coherency vulnerability in the Linux kernel's igorplugusb remote control driver has been resolved. The USB request structure used in control requests could be subject to DMA on some host controllers without obeying DMA coherency rules, potentially leading to memory corruption or unstable behavior. The fix allocates the USB request structure separately to ensure proper DMA coherency compliance.
A use-after-free vulnerability exists in the Linux kernel's ALSA aloop component. When a concurrent close occurs during a format-change stop, it can lead to a use-after-free condition. This issue has been resolved with multiple patches available. The vulnerability is caused by a race condition between the loopback_check_format() function and the snd_pcm_stop() function. An attacker could potentially explo [truncated]
A vulnerability in the Linux kernel's zram driver causes partial discard requests to hang indefinitely. The issue occurs because zram does not support partial discards and returns early without completing the I/O operation, leaving processes waiting in submit_bio_wait(). The fix ensures bio_endio() is called via the end_bio label before exiting.
A vulnerability in the Linux kernel's ALSA control subsystem could cause kernel panics when processing malformed enum control names. The issue exists in snd_ctl_elem_init_enum_names(), which iterates through a names buffer while decrementing buf_len. If buf_len reaches zero while items remain to process, the code calls strnlen(p, 0). Under CONFIG_FORTIFY_SOURCE with Clang, the fortified strnlen() implemen [truncated]
A memory leak vulnerability exists in the Linux kernel's DAMON (Data Access MONitor) statistics subsystem. When damon_start() fails during damon_stat_start() execution, the DAMON context allocated by damon_stat_build_ctx() is not properly destroyed, resulting in a memory leak. Additionally, the stale damon_stat_context pointer persists and will be overwritten on subsequent enable attempts, rendering the o [truncated]
A race condition in the Linux kernel's network bridge forwarding database (FDB) implementation can lead to a NULL pointer dereference. The vulnerability exists because RCU readers in the bridge subsystem load the `f->dst` field multiple times without proper synchronization, allowing a concurrent update via `fdb_delete_local()` to change the value between a NULL check and subsequent dereference. Specifical [truncated]
A vulnerability in the Linux kernel's rxrpc subsystem has been resolved. The issue involved improper handling of packets with misaligned crypto lengths in the rxkad authentication mechanism. The fix addresses three specific problems: (1) correct handling of packets where the crypto length is not properly aligned, (2) proper abort handling for non-ENOMEM errors from decryption operations rather than contin [truncated]
A vulnerability in the Linux kernel's RDMA/mana_ib driver allows stale RX steering configuration to persist after RSS QP destruction, potentially causing RX completions to be delivered to incorrect TX CQs when the VF interface is subsequently brought up. The fix disables vPort RX steering before destroying RX WQ objects and refactors the disable logic into a shared function.
A resource leak vulnerability in the Linux kernel's SPI subsystem could allow resource exhaustion when device registration fails. The flaw occurs in spi_setup() during device registration, where controller cleanup() was not invoked on setup failure, leading to leaked resources allocated by setup(). The fix ensures proper cleanup path execution when registration fails.
## Summary CVE-2026-46082 is a vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) SVM (Secure Virtual Machine) module. The issue involves the INVLPGA instruction not properly injecting an undefined opcode (#UD) exception when the EFER.SVME (Secure Virtual Machine Enable) bit is not set. According to AMD architecture specifications, INVLPGA should cause a #UD when SVM is not enabled. Th [truncated]
A memory corruption vulnerability exists in the Linux kernel's asynchronous compression (acomp) subsystem. The flaw resides in `acomp_save_req()`, which incorrectly stores a pointer to `&req->chain` in `req->base.data` instead of the request structure itself. When `acomp_reqchain_done()` is invoked upon asynchronous completion, it receives this pointer but casts it directly to `struct acomp_req`, causing [truncated]
A null-pointer dereference vulnerability exists in the Linux kernel's RBD (RADOS Block Device) driver. The flaw occurs in the error handling path of `do_rbd_add()` when `device_add_disk()` fails after `device_add()` has already succeeded. In this scenario, `rbd_free_disk()` is called twice—once directly in the error path and again through `rbd_dev_device_release()`—leading to a double teardown that corrup [truncated]
A vulnerability in the Linux kernel's EROFS (Enhanced Read-Only File System) implementation allows out-of-bounds memory reads when processing crafted filesystem images. The issue affects trailing directory entries (dirents) where name offset (nameoff) values are not properly validated before use in strnlen() calculations. When a malicious EROFS image contains a trailing dirent with nameoff exceeding the m [truncated]
A DMA cache coherency bug in the Linux kernel's Atmel TDES crypto driver could cause stale data to be returned on non-coherent platforms. The fix corrects the DMA sync direction from `dma_sync_single_for_device()` to `dma_sync_single_for_cpu()` when the CPU consumes DMA output.
A logic error in KVM's nested SVM (nSVM) implementation could allow a nested guest (L2) to execute hypercalls with L1 privileges when L1 has not configured interception of VMMCALL instructions. The vulnerability occurs when nested_svm_l2_tlb_flush_enabled() is true and the hypercall is not a supported Hyper-V hypercall. In this scenario, KVM would intercept the VMMCALL but fail to forward it to L1, effect [truncated]
A use-after-free (UAF) and memory leak vulnerability exists in the Linux kernel's Atmel SHA204A cryptographic driver. The issue occurs during device removal when the hardware random number generator (hwrng) is not properly unregistered before teardown, allowing queued I2C workqueue callbacks to execute after the device structure has been freed. Additionally, an early return path prevents proper cleanup of [truncated]
A memory leak vulnerability exists in the Linux kernel's CH341 SPI driver that occurs during probe failure conditions. The flaw stems from improper cleanup paths when device initialization fails, leading to resource leaks including the SPI controller, pin configurations, and USB request block (URB) memory. The vulnerability also encompasses a related use-after-free risk due to incomplete teardown sequence [truncated]