These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-46043 is an integer underflow vulnerability in the Linux kernel's RDMA/rxe (Soft-RoCE) driver. The flaw exists in the `rxe_rcv()` function, which validates incoming packet length against only `header_size(pkt)` before calling `payload_size()`. However, `payload_size()` subtracts both the attacker-controlled BTH pad field and `RXE_ICRC_SIZE` from `pkt->paylen`. A malicious packet with a forged non [truncated]
A memory leak vulnerability exists in the Linux kernel's memory policy subsystem, specifically within the weighted_interleave_auto_store() function in mm/mempolicy.c. The flaw stems from improper placement of a pointer fetch operation that leaves allocated memory unreleased under specific input conditions. When a user writes 'false' to the weighted interleave auto control while the current mode is already [truncated]
A sleep-in-atomic-context vulnerability in the Linux kernel's Greybus BeaglePlay driver could cause system instability. The hdlc_append() function called usleep_range() while holding tx_producer_lock, a spinlock, which violates kernel locking rules and can trigger 'BUG: scheduling while atomic' errors. The fix restructures the code to wait for buffer space before acquiring the spinlock, ensuring all sleep [truncated]
A resource leak vulnerability in the Linux kernel's inotify subsystem allows watch count exhaustion through repeated failed watch creation attempts. The flaw exists in inotify_new_watch() where fsnotify_add_inode_mark_locked() failure triggers an error path that removes the watch from the IDR but fails to decrement the per-user watch counter. This regression was introduced when commit 1cce1eea0aff moved i [truncated]
A vulnerability in the Linux kernel's rxgk (RXGK - RX GSSAPI Kerberos) component has been resolved. The issue was a potential integer overflow in the `rxgk_extract_token()` function during a length check for ticket validation. The fix changes the comparison logic: instead of rounding up the value being tested (which could overflow), the patch rounds down the size of available data for comparison. This is [truncated]
A memory leak vulnerability exists in the Linux kernel's Qualcomm IPC Router (QRTR) nameserver implementation. When a node sends a BYE packet to indicate it is shutting down, the nameserver properly advertises the node's removal to observers but fails to free the associated node memory. This leak occurs in the `ctrl_cmd_bye()` function, which handles node departure notifications. The vulnerability affects [truncated]
This CVE addresses an out-of-bounds array access vulnerability in the Linux kernel's IPv4 ICMP handling code. The issue occurs when processing extended echo replies (ICMP_EXT_ECHOREPLY), which use a reply type value outside the range covered by the icmp_pointers[] array. The fix validates the reply type before consulting icmp_pointers[] and uses array_index_nospec() for in-range lookups to prevent specula [truncated]
A use-after-free vulnerability exists in the Linux kernel's VFIO CDX (Compute Express Link) driver. The flaw occurs in vfio_cdx_set_msi_trigger() where concurrent VFIO_DEVICE_SET_IRQS ioctls can race: one thread observes vdev->config_msi as set while another clears it and frees vdev->cdx_irqs via vfio_cdx_msi_disable(), leading to use-after-free of the cdx_irqs array. The fix introduces a per-device cdx_i [truncated]
A vulnerability in the Linux kernel's memory management subsystem could allow memory corruption on uniprocessor (UP) systems when Non-Maskable Interrupt (NMI) handlers allocate memory. The issue exists because `spin_trylock()` is a no-op that unconditionally succeeds on UP kernels (`!CONFIG_SMP`), even when the lock is already held. This permits `alloc_frozen_pages_nolock()` called from NMI context to re- [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's VFIO CDX driver. The flaw occurs in vfio_cdx_set_msi_trigger() when userspace invokes VFIO_DEVICE_SET_IRQS with VFIO_IRQ_SET_DATA_BOOL or VFIO_IRQ_SET_DATA_NONE flags before configuring MSI interrupts via VFIO_IRQ_SET_DATA_EVENTFD. The cdx_irqs array is only allocated and config_msi set to 1 when vfio_cdx_msi_enable() is called through [truncated]
A vulnerability in the Linux kernel's authencesn crypto driver allowed creation of AEAD transforms with invalid default authentication sizes when paired with hash algorithms having digest sizes of 1-3 bytes. The ESN (Extended Sequence Number) code paths require at least 4 bytes of authentication tag space to handle high-order sequence number data. While explicit setauthsize() calls rejected invalid sizes, [truncated]
A vulnerability in the Linux kernel's KVM nested virtualization (nSVM) subsystem could allow a malicious L2 guest to cause the host to continue execution with corrupted state. When loading L1's CR3 fails during a nested #VMEXIT, the nested_svm_vmexit() function previously returned an error code that was ignored by most callers, causing the hypervisor to continue running L1 with invalid state rather than t [truncated]
A deadlock vulnerability exists in the Linux kernel's KS8851 Ethernet driver. The issue arises when the driver's IRQ handler executes concurrently with softirq processing under specific conditions. When CONFIG_PREEMPT_RT is enabled and packets are both transmitted and received, the netdev_alloc_skb_ip_align() function can trigger pending softirq processing via local_bh_enable(), which may invoke the drive [truncated]
A memory leak vulnerability in the Linux kernel's EDAC (Error Detection and Correction) driver for AMD/Xilinx Versal NET platforms has been resolved. The issue was in the `mc_probe()` function within the `versalnet` EDAC driver, where `of_parse_phandle()` returns a device_node reference that was never released with `of_node_put()`, causing a reference count leak on all exit paths. The fix implements the a [truncated]
A slab allocator re-entrancy vulnerability exists in the Linux kernel's memory management subsystem on uniprocessor (UP) builds. On UP kernels (!CONFIG_SMP), spin_trylock() unconditionally succeeds even when the target lock is already held. When kmalloc_nolock() is invoked from non-maskable interrupt (NMI) context, it can re-enter the slab allocator and acquire n->list_lock that the interrupted context al [truncated]
A race condition in the Linux kernel's AF_ALG AEAD (Authenticated Encryption with Associated Data) AIO implementation allows later socket activity to corrupt the initialization vector (IV) of in-flight asynchronous cryptographic requests. The vulnerability exists because the socket-wide IV buffer is shared across concurrent operations; when an async request is pending, subsequent socket operations can mod [truncated]
A race condition in the Linux kernel's Shared Memory Communications (SMC) subsystem could lead to invalid memory access during connection handshake. The vulnerability exists in smc_clc_wait_msg() where CLC decline messages received before link group setup completion could trigger link-group state updates on uninitialized structures. The fix adds proper guards to prevent early link-group access while prese [truncated]
A vulnerability in the Linux kernel's Qualcomm IPC Router (QRTR) nameserver allows a malicious local client to exhaust system resources by sending an unbounded number of NEW_LOOKUP messages. The QRTR protocol facilitates communication between Qualcomm subsystem components, and its nameserver component previously performed no bound checking on lookup operations. While the code restricts lookups to local cl [truncated]
A race condition in the Linux kernel's DAMON (Data Access MONitor) subsystem can cause memory leaks or deadlocks when `damon_call()` or `damos_walk()` operations race with kdamond thread termination. The vulnerability exists because request registration and the `damon_ctx->kdamond` unset operation were protected by different mutexes, allowing a window where a new request could be registered after cancella [truncated]
A null pointer dereference vulnerability exists in the Linux kernel's libceph component within the ceph_handle_auth_reply() function. The flaw occurs when a CEPH_MSG_AUTH_REPLY message contains zero values for both protocol and result fields. Under specific conditions—when ac->negotiating is true and ac->protocol is greater than zero—the code sets ac->protocol to 0 and ac->ops to NULL. The existing check [truncated]
An integer overflow vulnerability in the Linux kernel's device mapper (dm) mirror subsystem could allow an attacker with privileges to configure device mapper tables to trigger out-of-bounds memory reads. The flaw exists in create_dirty_log() where param_count is added to 2 before validation against argc; when param_count is near UINT_MAX, the unsigned addition wraps to a small value, bypassing bounds che [truncated]
This CVE addresses two related vulnerabilities in the Linux kernel thermal management subsystem. The first issue involves a memory leak that occurs when thermal_zone_device_register_with_trips() fails after adding a thermal governor to a thermal zone—the governor is not properly removed during error cleanup. The second issue is a race condition in thermal_zone_device_unregister(), which calls thermal_set_ [truncated]
A validation flaw in the Linux kernel's DAMON (Data Access MONitor) subsystem allows privileged users to trigger out-of-bounds memory access through the DAMON_SYSFS interface. The vulnerability exists in the handling of `damos_quota_goal->nid` (node ID) parameters for `node_mem_{used,free}_bp` quota goals, which are passed to `si_meminfo_node()` and `NODE_DATA()` without proper bounds checking. An attacke [truncated]
A memory leak vulnerability exists in the Linux kernel's Atmel AES crypto driver. The `atmel_aes_buff_init()` function allocates 4 pages of memory using `__get_free_pages()` with `ATMEL_AES_BUFFER_ORDER`, but the corresponding cleanup function `atmel_aes_buff_cleanup()` incorrectly frees only a single page using `free_page()`. This mismatch causes 3 pages (12KB on typical systems) to be leaked on each cle [truncated]
A logic error in the Linux kernel's USB Audio Class 2 (UAC2) sample rate parsing allows malformed device descriptors to trigger excessive kernel logging while holding a mutex, potentially causing denial-of-service conditions through log flooding and extended lock contention.
A race condition in the Linux kernel's memory management (mm) subsystem could allow a concurrent rmap-removal path to mark a destination folio as partially mapped, triggering a WARN in deferred_split_folio(). The vulnerability occurs in migrate_folio_move() where the deferred split queue state is replayed on the destination folio after remove_migration_ptes() makes it visible. A concurrent operation could [truncated]
A NULL pointer dereference vulnerability in the Linux kernel's Xilinx remoteproc driver could allow a local attacker to cause a system crash. The flaw exists in the receive callback where buffer information is accessed without first verifying that the Inter-Processor Interrupt (IPI) message is buffered. The vulnerability has been resolved by adding a NULL check on the message pointer before accessing buff [truncated]
A race condition in the Linux kernel's TCP stack can cause poll()/epoll_wait() waiters and blocking accept() callers to remain asleep indefinitely when a child socket is migrated from a closing listener to another socket in the same SO_REUSEPORT group. The root cause is that inet_csk_listen_stop() adds the migrated socket to the target listener's accept queue via inet_csk_reqsk_queue_add() without notifyi [truncated]
A vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) subsystem for AMD SVM (Secure Virtual Machine) was resolved on 2026-05-27. The issue involved missing save/restore handling of Last Branch Record (LBR) Model-Specific Registers (MSRs), specifically MSR_IA32_DEBUGCTLMSR and LBR MSRs. These MSRs were not enumerated by KVM_GET_MSR_INDEX_LIST, and LBR MSRs could not be set with KVM_SET_M [truncated]
A vulnerability in the Linux kernel's memfd_luo subsystem has been resolved. The issue involved incorrect physical address conversion in the put_folios cleanup path of memfd_luo_retrieve_folios(). Specifically, kho_restore_folio() received a raw PFN instead of a proper phys_addr_t, causing kho_restore_page() to check the wrong physical address. Additionally, the cleanup loop lacked a !pfolio->pfn check pr [truncated]