PatchSiren

Linux CVE debriefs · Page 96

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-05-27

CVE-2026-46012

A memory leak vulnerability in the Linux kernel's RxRPC (Remote Procedure Call over Rx) subsystem has been resolved. The flaw existed in the `rxkad_verify_response()` function within the rxkad security module, which failed to properly free allocated memory for Kerberos tickets and server keys under certain error conditions. The fix ensures consistent cleanup by initializing the ticket pointer to NULL and [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-46011

A use-after-free vulnerability exists in the Linux kernel's MediaTek JPEG driver (mtk-jpeg). The `mtk_jpeg_release()` function frees the context structure (`ctx`) without first cancelling pending or running work in `ctx->jpeg_work`. This creates a race condition where the workqueue callback (`mtk_jpegenc_worker`) may access freed memory if the device is closed while JPEG encode/decode operations are pendi [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-46010

A missing error-handling path in the Linux kernel's RxRPC (Remote Procedure Call over RX) subsystem could allow memory-allocation failures to go unhandled, potentially leading to undefined behavior or service disruption. The flaw resides in rxgk_extract_token(), which failed to propagate -ENOMEM errors from rxgk_decrypt_skb() correctly. When memory allocation fails during token decryption, the function sh [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-46009

A use-after-free vulnerability exists in the Linux kernel's PCI Endpoint NTB (Non-Transparent Bridge) function driver. The `epf_ntb_epc_destroy()` helper function performs duplicate resource teardown operations that the caller is expected to handle later. When `.allow_link` fails or `.drop_link` is executed, this double teardown triggers a kernel oops due to accessing already-freed resources. The fix remo [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-46008

A race condition in the Linux kernel's DAMON (Data Access MONitor) subsystem can cause deadlocks when the `damos_walk()` function races with `kdamond_fn()` thread termination. The vulnerability exists because `damos_walk()` request registration and `damon_ctx->kdamond` unset operations are protected by different mutexes. An attacker with local access could trigger this condition, causing the `damos_walk() [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-46007

This CVE addresses a cache coherency vulnerability in the Linux kernel's hwmon (hardware monitoring) subsystem, specifically within the powerz driver. The issue stems from a DMA buffer potentially sharing a cacheline with an adjacent mutex, which can lead to data corruption or undefined behavior on architectures where cache coherency between CPU and DMA operations is not automatically maintained. The reso [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-46006

An integer overflow vulnerability exists in the Linux kernel's Nouveau DRM driver, specifically within the `nouveau_gem_pushbuf_reloc_apply()` function. The flaw arises from a 32-bit unsigned integer overflow during bounds checking of GPU pushbuffer relocations. The `reloc_bo_offset` field is defined as `__u32` in the UAPI header, and when added to the integer literal `4`, the operation is performed in 32 [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-46005

A resource leak vulnerability in the Linux kernel's XFS filesystem could allow reference count imbalance on DAX-capable block devices. The flaw exists in xfs_alloc_buftarg() where error paths fail to release a held DAX device reference via fs_put_dax(). Successful exploitation could lead to resource exhaustion or use-after-free conditions in DAX-enabled XFS deployments. The vulnerability was resolved by a [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-46004

A use-after-free (UAF) vulnerability exists in the Linux kernel's ALSA caiaq audio driver. The `setup_card()` probe function failed to properly handle errors from `snd_card_register()`, calling `snd_card_free()` but continuing execution instead of returning an error. This leads to subsequent calls like `snd_usb_caiaq_control_init()` operating on freed memory. The fix converts `setup_card()` to return erro [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-46002

A vulnerability in the Linux kernel's ext2 filesystem implementation allows corrupted inodes with zero link count but valid mode bits to reach VFS operations, triggering kernel warnings. The flaw exists in ext2_iget(), which failed to reject inodes where i_nlink == 0 with non-zero i_mode and zero i_dtime—a combination that can only result from filesystem corruption. When such inodes are processed through [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-46001

CVE-2026-46001 describes two bugs in the Linux kernel hwmon driver for the PT5161L temperature sensor. The first bug is a stack buffer overflow: the local buffer `rbuf` is sized at 24 bytes, but `i2c_smbus_read_block_data()` can return up to `I2C_SMBUS_BLOCK_MAX` (32) bytes. Because the I2C core copies data into the caller's buffer before the return value is validated, a malicious or misbehaving device re [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-46000

A vulnerability in the Linux kernel's rxrpc (Remote Procedure Call over Rx) subsystem could allow packet sniffers to observe partially decrypted RESPONSE packets. The issue occurs because security operations that verify RESPONSE packets perform in-place decryption on sk_buff structures that may be shared with packet sniffers. When the sk_buff is cloned (shared), the sniffer would see corrupted packet data [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45999

A vulnerability in the Linux kernel's EROFS (Enhanced Read-Only File System) implementation could allow an attacker with a crafted filesystem image to trigger an out-of-bounds read during LZ4 decompression. The issue stems from an unsigned integer underflow in `z_erofs_lz4_handle_overlap()` when processing malformed extents that specify `m_llen < m_plen` without the `partial_decoding` flag. This causes th [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45998

A use-after-free vulnerability in the Linux kernel's rxrpc subsystem has been addressed. The issue arises when `skb_unshare()` fails to unshare a packet due to allocation failure in `rxrpc_input_packet()`, potentially causing a crash when `trace_rxrpc_rx_done()` is called. The fix involves moving the unsharing down to where `rxrpc_input_call_event()` calls `rxrpc_input_call_packet()`.

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45997

A vulnerability in the Linux kernel's SCSI disk (sd) driver could lead to a resource leak when device registration fails. The issue occurs in the error handling path of the SCSI disk probe function: if `device_add()` fails for the disk device, the cleanup code calls `put_device()` which triggers `scsi_disk_release()` to free the `scsi_disk` structure, but the associated `gendisk` structure remains referen [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45996

A use-after-free vulnerability exists in the Linux kernel's SPI i.MX driver that triggers during device unbind operations. The SPI subsystem automatically frees the controller and driver data upon deregistration unless device-managed allocation is used. The fix takes an additional reference before deregistering the controller to ensure driver data remains valid until the driver completes its cleanup. This [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45995

A use-after-free (UAF) vulnerability in the Linux kernel's io_uring subsystem, specifically within the zero-copy receive (zcrx) ring buffer handling. The flaw occurs in `io_free_rbuf_ring()` which accesses a `struct user_struct` that `io_zcrx_ifq_free()` has already put (decremented reference count), leading to potential memory corruption or privilege escalation. The vulnerability was resolved by ensuring [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45994

CVE-2026-45994 is a vulnerability in the Linux kernel's ibmasm driver that could allow out-of-bounds memory reads and information disclosure. The command_file_write() handler failed to validate user-supplied buffer sizes against the dot command protocol header before processing. An attacker with local access could craft malicious input causing get_dot_command_size() to return values exceeding the allocate [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45993

A Spectre v1 speculative execution vulnerability exists in the LoongArch Linux kernel syscall dispatch path. The syscall number supplied by userspace is used to index into the syscall function pointer table without proper bounds clamping via array_index_nospec(). This allows an attacker to train the branch predictor and speculatively execute code beyond the valid syscall table bounds, potentially leaking [truncated]

Review Linux CVE published 2026-05-27

CVE-2026-45992

A vulnerability in the Linux kernel's ALSA caiaq audio driver could allow a resource leak when device initialization fails. The issue occurs because an internal USB Request Block (URB) named `ep1_in_urb` may be submitted before `setup_card()` encounters an error, but was not properly cleaned up in that error path. While the URB is normally killed during device disconnection, the error path lacked this cle [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45991

A heap out-of-bounds write vulnerability exists in the Linux kernel's UDF filesystem driver. The flaw occurs in `handle_partition_descriptor()` when mounting crafted UDF images containing repeated partition descriptors. The function deduplicates entries by partition number, but appended slots fail to record the partition number (`partnum`). This causes duplicate partition descriptors to be appended repeat [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45990

A vulnerability in the Linux kernel's SLUB allocator affects krealloc() and kvrealloc() operations. The issue stems from commit 2cd8231796b5, which introduced forced reallocation capabilities for alignment and NUMA node changes. Two distinct bugs were introduced in the fallback reallocation path: data loss during NUMA migration due to uninitialized size variables causing zero-byte copies, and buffer overf [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45989

A use-after-free vulnerability exists in the Linux kernel's Open Firmware (OF) unit test driver. The `testdrv_probe()` function in the OF unittest code incorrectly releases a reference to the device tree node (`device_node`) that is owned by the device model, rather than the driver. Specifically, after retrieving `pdev->dev.of_node` and applying a device tree overlay, the code calls `of_node_put(dn)` whic [truncated]

CRITICAL Linux CVE published 2026-05-27

CVE-2026-45988

A logic error in the Linux kernel's RxRPC (Remote Procedure Call over RX) subsystem could allow partially decrypted RESPONSE packets to be requeued for retry, potentially leading to cryptographic state corruption. The vulnerability occurs when temporary processing failures leave packets in an inconsistent decryption state. The fix discards affected packets rather than requeuing them, relying on protocol r [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45987

A state synchronization flaw in the Linux kernel's KVM nested virtualization (nSVM) implementation can cause L2 guest vCPUs to hang when restoring nested state. The vulnerability exists because the interrupt shadow state (int_state bit 0, SVM_INTERRUPT_SHADOW_MASK) written by the CPU during VMRUN was not synchronized to the cached vmcb12 structure. When KVM_SET_VCPU_EVENTS precedes KVM_SET_NESTED_STATE du [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45986

A memory leak vulnerability in the Linux kernel's ARM TrustZone CryptoCell (ccree) driver has been resolved. The flaw exists in the cc_mac_digest() function, where a failure path in cc_map_hash_request_final() could leave mapped memory unreleased. The fix adds a cc_unmap_result() call to ensure proper cleanup when mapping operations fail. This affects systems utilizing the CryptoCell hardware cryptographi [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45985

A stale data exposure vulnerability exists in the Linux kernel's ext4 filesystem when handling direct I/O (DIO) writes with dioread_nolock enabled. The issue occurs during block allocation when splitting an existing large unwritten extent before submitting I/O. The EXT4_GET_BLOCKS_CONVERT flag was incorrectly passed to ext4_split_convert_extents() during this pre-I/O splitting phase. Under specific failur [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45984

A use-after-free vulnerability exists in the Linux kernel's GFS2 (Global File System 2) filesystem driver, specifically within the iomap inline data write path. The flaw occurs when gfs2_iomap_begin() prematurely releases a buffer head (dibh) via release_metapath() while iomap->inline_data still holds a pointer to dibh->b_data. This creates a race condition where kswapd can reclaim the freed page before i [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45983

A vulnerability in the Linux kernel's NFSv4 server (nfsd) could cause persistent session slot exhaustion, leading to denial of service for NFSv4 clients. The issue occurs when idmap lookup upcalls during compound request decoding exceed time limits, triggering improper request deferral that leaves session slots permanently marked as in-use.

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45982

A NULL pointer dereference vulnerability in the Linux kernel's ACPICA (ACPI Component Architecture) subsystem has been resolved. The flaw existed in the acpi_ev_address_space_dispatch() function, where a missed execution path could lead to dereferencing a NULL pointer. The fix adds a new check to cover this previously unhandled code path. This vulnerability affects the kernel's ACPI event handling infrast [truncated]