These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in the Linux kernel's s390 Channel I/O (CIO) subsystem has been resolved. The issue was in `css_alloc_subchannel()`, where improper device lifecycle handling in an error path could lead to use-after-free or double-free conditions. Specifically, after `device_initialize()` was called, subsequent DMA mask setup failures triggered a direct `kfree()` of the subchannel structure instead of usin [truncated]
A use-after-free vulnerability in the Linux kernel's AMD XDNA AI accelerator driver (accel/amdxdna) could allow local attackers to cause system crashes. The flaw occurs when job scheduling continues during hardware context resource release, leading to memory corruption. The fix stops job scheduling before resource release and adds active context validation in the job run path.
A vulnerability in the Linux kernel's AMDGPU DRM driver has been resolved. The issue involved improper cleanup in `amdgpu_cs_parser_bos()` when `kmalloc()` fails under low memory conditions. The fix ensures the mutex is properly unlocked for a clean exit path. The `amdgpu_bo_list_put()` call was not needed in the error path as it is already handled by `amdgpu_cs_parser_fini()`. This is a memory exhaustion [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's Greybus staging driver, specifically in the lights subsystem. The flaw occurs in gb_lights_light_config() where channel_count is stored before the channels array is allocated via kcalloc(). If the allocation fails, gb_lights_release() iterates using the non-zero channel_count and dereferences the NULL light->channels pointer. The fix re [truncated]
A use-after-free vulnerability exists in the Linux kernel's fbnic (Facebook/Meta network interface controller) driver. The flaw involves a race condition between firmware log (fw_log) teardown and concurrent write operations. The fw_log structure can be accessed by the mailbox interrupt handler (fbnic_fw_msix_intr → fbnic_fw_log_write) after it has been freed during driver removal, leading to dereference [truncated]
A memory leak vulnerability exists in the Linux kernel's AMDGPU driver, specifically within the `amdgpu_ras_init()` function. When `amdgpu_nbio_ras_sw_init()` fails during initialization, the function returns directly without freeing a previously allocated `con` structure, resulting in a memory leak. The fix redirects error handling to a `release_con` label to ensure proper cleanup. This vulnerability was [truncated]
A race condition vulnerability in the Linux kernel's ublk (userspace block device) subsystem could allow local attackers to manipulate control command data through concurrent userspace writes. The flaw exists because `struct ublksrv_ctrl_cmd`, embedded within io_uring submission queue entries (SQEs) mapped to userspace memory, was accessed with normal loads rather than atomic reads. This creates a TOCTOU [truncated]
A vulnerability in the Linux kernel's Btrfs filesystem could allow invalid memory access during quota enablement operations. The flaw occurs in btrfs_quota_enable() when btrfs_search_slot_for_read() returns 1, indicating no matching key was found and the end of the tree has been reached. In this case, the code path fails to properly break from the loop, leading to subsequent access of an invalid path stru [truncated]
A race condition in the Linux kernel's RDMA/mlx5 driver can cause indefinite hangs during device unload when firmware reset occurs in LAG (Link Aggregation Group) mode. The vulnerability stems from improper error event propagation: in LAG mode, the bond device is only registered on the master, so slave devices never receive sys_error events. During firmware reset, this causes UMR (User Memory Region) comp [truncated]
A use-after-free (UAF) and double-free vulnerability exists in the Linux kernel's SMB client implementation, specifically within the smb2_open_file() function. The flaw occurs when retrying SMB2_open() operations: if the @data pointer is non-NULL, uninitialized @err_iov and @err_buftype variables can lead to memory corruption. The fix zeroes out these variables before retry to prevent both UAF and double- [truncated]
A vulnerability in the Linux kernel's BPF subsystem allowed excessive BPF program signature sizes to trigger expensive allocation paths. The fix limits signature sizes to prevent abuse via kmalloc_large or vmalloc.
A use-after-free (UAF) vulnerability exists in the Linux kernel's bonding driver, specifically within the Adaptive Load Balancing (ALB) receive path. The flaw occurs when `rlb_arp_recv()` can still be accessed after `recv_probe` is set to NULL during rapid bond interface up/down cycles, leading to concurrent access with `rlb_deinitialize()` which frees `rx_hashtbl`. This race condition results in a null p [truncated]
A missing return value check in the Linux kernel's HID PlayStation driver could lead to incorrect behavior or potential crashes when force feedback (FF) effects are triggered. The `ps_gamepad_create()` function in the PlayStation HID driver calls `input_ff_create_memless()` without verifying whether the call succeeded. If `input_ff_create_memless()` fails (e.g., due to memory allocation failure), subseque [truncated]
A vulnerability in the Linux kernel's cpuidle subsystem could cause system crashes on PowerNV platforms with only a single idle state available. The ladder governor incorrectly treated state 1 as the first usable state when only state 0 (polling) was registered, leading to an out-of-bounds index and NULL pointer dereference. The fix adds a bail-out in cpuidle_select() to return state 0 directly when state [truncated]
A double-offset bug in the Linux kernel's BPF instruction array map handling could lead to incorrect address calculations. The `map_direct_value_addr()` function incorrectly adds an offset to the resulting address, but `resolve_pseudo_ldimm64()` later adds the same offset again. This duplicate offset application could cause BPF programs to reference wrong memory locations, potentially leading to informati [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's AppArmor security module, specifically within the `__unix_needs_revalidation()` function. The flaw was introduced in AppArmor 5.0.0 (kernel 6.17+) when this function was added without proper NULL pointer validation. When file descriptors are received via SCM_RIGHTS (socket control message rights), both the socket pointer and the socket' [truncated]
A NULL pointer dereference vulnerability in the Linux kernel's AppArmor security module can cause a kernel oops when resolving symbolic links to profile rawdata. The issue occurs when the export_binary parameter is disabled at runtime after profiles have been loaded. When such profiles are subsequently replaced, their rawdata is set to NULL, but symbolic link resolution attempts to dereference profile->ra [truncated]
A reference counting bug in the Linux kernel's SUNRPC GSS authentication subsystem can cause a kernel memory leak. When gss_alloc_msg() fails to duplicate a service name string, the error path omits releasing a reference taken on the gss_auth structure, preventing its eventual deallocation. This flaw was introduced when balancing reference counts in commit 5940d1cf9f42. The fix adds the missing kref_put() [truncated]
A use-after-free vulnerability in the Linux kernel's Nuvoton NAU8821 audio codec driver (ASoC) can cause kernel crashes during driver unload. The issue occurs when the nau8821_jdet_work delayed work item remains pending while the driver component is removed. When the work item eventually executes, it attempts to access freed memory, triggering a page fault. The fix cancels unscheduled jack detection work [truncated]
A vulnerability in the Linux kernel's ublk (userspace block device) subsystem could allow out-of-bounds memory access. The issue exists in ublk_ctrl_cmd_dump(), which accesses sqe->cmd as a header pointer before verifying that the IO_URING_F_SQE128 flag is set. Without this flag check, the function may read beyond allocated memory boundaries. The fix moves the SQE128 flag validation earlier in ublk_ctrl_u [truncated]
CVE-2026-45961 describes two memory leaks in the Linux kernel's GFS2 (Global File System 2) filesystem driver, specifically within the `gfs2_fill_super()` error handling path during filesystem initialization. The vulnerability occurs when transitioning a filesystem to read-write mode fails after certain initialization steps have succeeded, leaving allocated resources unreleased. The first leak involves ke [truncated]
A reference count inconsistency in the Linux kernel's HFS+ filesystem implementation can lead to kernel panic. The vulnerability exists in hfs_bnode_create() which, when encountering an already-hashed node (an abnormal condition), returns the existing node without incrementing its reference count. This causes a BUG_ON assertion failure in hfs_bnode_put() when the node is later freed. The issue can be trig [truncated]
A memory management defect in the Linux kernel's AMD Cryptographic Coprocessor (CCP) driver could cause system crashes due to improper cleanup attribute usage. The vulnerability stems from incorrect application of the `__cleanup(kfree)` attribute on a local pointer variable, which causes the address of the stack variable itself—rather than the heap-allocated memory returned by kmalloc—to be passed to kfre [truncated]
A vulnerability in the Linux kernel's DRM/Exynos VIDI driver allowed direct dereferencing of a user-supplied pointer in `vidi_connection_ioctl()`, enabling potential arbitrary kernel memory access from user space. The issue was resolved by replacing direct pointer access with proper `copy_from_user()` usage to safely copy EDID data into kernel memory.
A vulnerability in the Linux kernel's RCU (Read-Copy-Update) subsystem could cause a deadloop in rcu_read_unlock() when softirq is raised. The issue stems from commit 5f5fa7ea89dc, which removed recursion-protection code from __rcu_read_unlock(). When ftrace is enabled, this can trigger an infinite loop in raise_softirq_irqoff() during RCU read-side critical section exit processing. The fix applies the sa [truncated]
A vulnerability in the Linux kernel's DRM/Exynos VIDI driver could allow local attackers to trigger memory safety errors including null pointer dereferences, use-after-free, and out-of-bounds access. The flaw exists in vidi_connection_ioctl() which incorrectly retrieves driver_data from the exynos-drm master device rather than the VIDI component device, leading to type confusion and potential memory corru [truncated]
A vulnerability in the Linux kernel's md/md-llbitmap subsystem could leave a percpu_ref in a permanently killed state when llbitmap_suspend_timeout() times out. The function returns -ETIMEDOUT without resurrecting the reference, causing subsequent page operations to fail as the page control structure becomes unusable. The fix ensures percpu_ref is resurrected before returning the timeout error, maintainin [truncated]
A memory leak vulnerability exists in the Linux kernel's au1200fb framebuffer driver. The flaw occurs in the `au1200fb_drv_probe()` function, where a direct return on `platform_get_irq()` failure bypasses necessary cleanup, causing allocated memory to leak. The fix replaces the direct return with a goto label to ensure proper resource cleanup on error paths. This vulnerability affects the fbdev au1200fb d [truncated]
A logic error in the Linux kernel's RAID5 implementation can cause I/O operations to hang indefinitely when using a degraded array with the lazy-latency bitmap (llbitmap) feature. The vulnerability stems from a missing consistency check in the `need_this_block()` function that creates a deadlock condition during stripe handling. When the llbitmap bit state remains unwritten and new write operations force [truncated]
A vulnerability in the Linux kernel's fbnic (Facebook/Meta network interface controller) driver allowed MTU increases after XDP attachment, causing multi-fragment packet drops. The driver previously blocked XDP attachment when MTU was too high but failed to prevent post-attachment MTU changes. When MTU exceeds the HDS (Header/Data Split) threshold, hardware fragments packets across multiple buffers; singl [truncated]