These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A memory leak vulnerability exists in the Linux kernel's CH341 SPI driver that occurs during probe failure conditions. The flaw stems from improper cleanup paths when device initialization fails, leading to resource leaks including the SPI controller, pin configurations, and USB request block (URB) memory. The vulnerability also encompasses a related use-after-free risk due to incomplete teardown sequence [truncated]
A logic error in the Linux kernel hwmon powerz driver fails to abort USB transfers when interrupted by a signal, potentially leading to use of uninitialized data.
A vulnerability in the Linux kernel's NTFS3 filesystem driver allows out-of-bounds heap reads when mounting crafted NTFS images. The `run_unpack()` function in the NTFS3 driver performs insufficient buffer boundary validation before reading run data from MFT attributes. Specifically, while the function checks `run_buf < run_last` at the loop start, it subsequently calls `run_unpack_s64()` to read `size_si [truncated]
A vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) nested SVM (Secure Virtual Machine) implementation has been resolved. The issue involved improper handling of VMCB (Virtual Machine Control Block) clean bits during nested VM exits. Specifically, the `svm_copy_lbrs()` function always marked the VMCB_LBR (Last Branch Record) field as dirty in the destination VMCB. When `nested_svm_vme [truncated]
A vulnerability in the Linux kernel's RAID5/RAID6 cache (r5c) and log (r5l) journal recovery code could allow out-of-bounds reads when processing corrupted journal metadata. The functions `r5c_recovery_analyze_meta_block()` and `r5l_recovery_verify_data_checksum_for_mb()` failed to validate on-disk payload size fields against the remaining space in metadata blocks before iterating over payloads. A corrupt [truncated]
A use-after-free vulnerability exists in the Linux kernel's Marvell WiFi driver (mwifiex). The mwifiex_adapter_cleanup() function uses timer_delete() (non-synchronous) to cancel the wakeup_timer before the adapter structure is freed. Because timer_delete() does not wait for running timer callbacks to complete, the wakeup_timer_fn callback may continue executing and access adapter fields (adapter->hw_statu [truncated]
A memory management bug in the Linux kernel's NX842 crypto driver causes bounce buffer leaks due to mismatched allocation and deallocation functions. The buffers are allocated with `__get_free_pages()` using order 2 (4 pages) but freed with `free_page()` instead of `free_pages()` with the correct order. This affects both the allocation error path and the `nx842_crypto_free_ctx()` cleanup function. The vul [truncated]
A vulnerability in the Linux kernel's DAMON (Data Access MONitor) subsystem allowed out-of-bounds memory access due to insufficient validation of the `damos_quota_goal->nid` (node ID) field. The DAMON core used this user-supplied value directly in `NODE-DATA()` macro calls for `node_memcg_used_bp` and `node_memcg_free_bp` quota goal types without bounds checking. An attacker with local access and privileg [truncated]
A kernel panic vulnerability exists in the Linux kernel's CephFS client when handling encrypted file writeback. The issue stems from an off-by-one error in `ceph_wbc->num_ops` accounting when bounce buffer allocation fails during multi-folio encrypted writeback operations. Specifically, when `move_dirty_folio_in_page_array()` fails due to memory pressure on a non-first folio in a batch, `ceph_process_foli [truncated]
A use-after-free vulnerability in the Linux kernel's framebuffer deferred I/O (fbdev/defio) subsystem has been resolved. The issue occurred when a graphics device was hot-unplugged while user space maintained an active memory mapping of the framebuffer. The hot-unplug operation freed the struct fb_info instance, but subsequent accesses through the still-active mapping operated on undefined memory state, l [truncated]
A heap over-read vulnerability in the Linux kernel's ibmasm driver allows root users to trigger out-of-bounds reads of up to ~65 KB by supplying crafted dot_command_header values. The ibmasm_send_i2o_message() function uses get_dot_command_size() to compute memcpy_toio() byte counts from user-controlled command_size (u8) and data_size (u16) fields without validation against actual allocation size. This ca [truncated]
A deadlock vulnerability exists in the Linux kernel's x86 shadow stack (shstk) signal return handling. When processing sigreturn, the kernel reads the shadow stack signal frame while holding the mmap read lock to verify the memory is actually shadow stack memory. If this read triggers a page fault, the fault handler attempts to acquire another mmap read lock. Under contention with a writer waiting on anot [truncated]
A vulnerability in the Linux kernel's ntfs3 filesystem driver has been resolved. The issue was an integer overflow in the `run_unpack()` function's volume boundary check. The original check `lcn + len > sbi->used.bitmap.nbits` used raw addition that could wrap around for large `lcn` and `len` values, allowing validation to be bypassed. The fix applies `check_add_overflow()`, consistent with adjacent overf [truncated]
A deadlock vulnerability exists in the Linux kernel's JBD2 (journaling block device 2) subsystem, specifically within the jbd2_journal_cancel_revoke() function. The issue stems from a lock ordering violation introduced by commit f76d4c28a46a, which changed the function to use __find_get_block_nonatomic(). This function acquires the folio lock instead of i_private_lock, breaking the established lock orderi [truncated]
A resource cleanup vulnerability in the Linux kernel's Intel QuickAssist Technology (QAT) driver for 6xxx series devices could cause kernel warnings and potential resource leaks during device probe failure. When adf_dev_up() partially completes then fails, IRQ handlers registered during adf_isr_resource_alloc() remain attached while MSI-X vectors are released by devres cleanup, triggering remove_proc_entr [truncated]
A logic error in KVM's nested SVM (nSVM) implementation could cause incorrect NextRIP handling in vmcb02 after L2 guest state save/restore. The vulnerability affects nested virtualization scenarios where L1 disables NRIPS (NextRIP Save) and injects soft interrupts into L2. After the first L2 VMRUN, the CPU and/or KVM updates NextRIP, making the current RIP stale for subsequent vmcb02 usage. The fix ensure [truncated]
A use-after-free vulnerability in the Linux kernel's Amphion VPU driver could allow local attackers to trigger kernel panics. The race condition occurs between v4l2_m2m_ctx_release() freeing memory and v4l2_m2m_try_run() attempting to use that freed context. The fix prevents the m2m framework from scheduling jobs by implementing a job_ready callback that returns 0 and removing the job_abort callback entirely.
A logic error in the Linux kernel's Landlock security module causes the LOG_SUBDOMAINS_OFF flag to be lost when a process forks. The hook_cred_transfer() function only copies the Landlock credential blob when a domain is present, but landlock_restrict_self() can set LOG_SUBDOMAINS_OFF without creating a domain (via ruleset_fd=-1). This inconsistency breaks the documented workflow where a parent process mu [truncated]
A use-after-free (UAF) vulnerability exists in the Linux kernel's Bluetooth subsystem, specifically within the Simple Secure Pairing (SSP) passkey event handlers. The flaw affects `hci_user_passkey_notify_evt()` and `hci_keypress_notify_evt()` functions in `net/bluetooth/hci_event.c`. Without proper synchronization, the `hci_conn` connection object can be freed by a concurrent thread while these handlers [truncated]
A slab-out-of-bounds read vulnerability exists in the Linux kernel's AppArmor security module, specifically within the DFA (Deterministic Finite Automaton) matching logic used for mount path validation. The issue stems from a missing string termination check in `aa_dfa_match()` at `security/apparmor/match.c:535`, triggered when processing mount operations via `aa_bind_mount()`. The KASAN report indicates [truncated]
A Linux kernel vulnerability allows unauthorized access to overlayfs filesystems, impacting mmap() and mprotect() operations. This issue, resolved through a series of patches, affects systems utilizing Linux kernel versions between 4.19 and 7.0.4. Attackers with local access could potentially exploit this flaw to escalate privileges or access sensitive data.
A use-after-free vulnerability exists in the Linux kernel's Reliable Datagram Sockets (RDS) subsystem. The flaw occurs in `__rds_rdma_map()` when memory region (MR) mapping succeeds but subsequent copying of the generated cookie to user space fails. In this error path, the code incorrectly attempts to free scatter-gather (sg) pages that have already been transferred to transport ownership, leading to pote [truncated]
A vulnerability in the Linux kernel's Ceph filesystem client (fs/ceph/dir.c) allows re-insertion of already-hashed negative dentries into the dcache hash bucket, causing kernel list corruption and potential RCU stalls. The issue occurs when ceph_finish_lookup() or ceph_lookup() calls d_add(dentry, NULL) on negative dentries that are already present in the primary dcache hash. This re-insertion creates sel [truncated]
A soft lockup vulnerability exists in the Linux kernel's md/raid5 driver, specifically within the retry_aligned_read() function. The issue arises when an overlapped stripe is encountered during read operations. The function releases the stripe via raid5_release_stripe(), placing it on a lockless released_stripes linked list. In subsequent raid5d loop iterations, release_stripe_list() moves the stripe to h [truncated]
A vulnerability in the Linux kernel's RAID10 (md/raid10) implementation can cause a deadlock condition when array consistency checks run concurrently with NOWAIT I/O requests. The issue stems from an accounting imbalance in the barrier synchronization mechanism introduced by a prior memory-leak fix.
A logic error in the Linux kernel's ALSA ctxfi (Creative Sound Blaster X-Fi) driver can cause an infinite loop during S/PDIF passthrough playback setup. The vulnerability exists because `spdif_passthru_playback_get_resources()` uses `atc->pll_rate` for MSR calculation, but this field remains zero after card initialization when `hw_pll_init()` is used instead of `atc_pll_init()`. When 32000 Hz playback tri [truncated]
A reference-counting defect in the Linux kernel's ALSA caiaq USB audio driver can cause memory leaks when device probe fails. The driver takes a reference on the USB device during initialization but only installs the matching release callback near the end of a multi-step setup sequence. If any intermediate step fails—such as interface selection, endpoint validation, URB submission, or device info exchange [truncated]
A use-after-free vulnerability exists in the Linux kernel's Qualcomm IPC Router (QRTR) namespace driver. The flaw occurs in the driver's remove callback, where a race condition between packet arrival and workqueue destruction can lead to memory corruption. Specifically, if a packet arrives after `destroy_workqueue()` is called but before `sock_release()` completes, the `qrtr_ns_data_ready()` callback atte [truncated]
A buffer reference leak vulnerability exists in the Linux kernel's ext4 filesystem implementation. The flaw occurs in `ext4_xattr_inode_dec_ref_all()` where `ext4_get_inode_loc()` acquires `iloc.bh` (a buffer head), but this buffer is never released via `brelse()` when `block_csum` is false. This was introduced by commit c8e008b60492 (ext4: ignore xattrs past end). The missing buffer release leads to a re [truncated]
A resource leak vulnerability exists in the Linux kernel's IPMI SSIF (System Management Interface - SMBus System Interface) driver. If an error occurs after the SSIF kernel thread is created but before the main IPMI code starts the SSIF interface, the kernel thread is not properly stopped, leading to a dangling kthread. This can result in resource exhaustion or system instability over repeated error condi [truncated]