These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A use-after-free vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem has been resolved. The issue affected the `check_pseudo_btf_id()` function, where incorrect reference counting could lead to a use-after-free condition on BTF (BPF Type Format) objects. Specifically, the `__check_pseudo_btf_id()` function could be invoked with a BTF object having a zero refcount, creating a potenti [truncated]
A memory leak vulnerability exists in the StarFive cryptographic driver within the Linux kernel. The `starfive_aes_aead_do_one_req()` function in the crypto subsystem allocates memory for `rctx->adata` using `kzalloc()` but fails to free this allocation when either `sg_copy_to_buffer()` or `starfive_aes_hw_init()` encounters an error. This leads to a memory leak condition that could potentially degrade sy [truncated]
A use-after-free vulnerability in the Linux kernel's hardware random number generator (hwrng) core could allow local attackers to trigger memory corruption. The flaw stems from a race condition where hwrng_unregister() could call kthread_stop() multiple times on the same task_struct due to unsynchronized access to the global hwrng_fill pointer. Additionally, rapid register/unregister sequences could leave [truncated]
A memory leak vulnerability exists in the Linux kernel's ext4 filesystem implementation, specifically within the `ext4_ext_shift_extents()` function. The issue occurs when the function obtains an extent path via `ext4_find_extent()` but returns immediately upon encountering a NULL extent in the while loop without releasing the allocated path, resulting in a memory leak. The fix ensures proper cleanup by j [truncated]
A memory leak vulnerability exists in the Linux kernel's AMDGPU driver, specifically within the `amdgpu_acpi_enumerate_xcc()` function. When `amdgpu_acpi_dev_init()` returns `-ENOMEM` (indicating memory allocation failure), the function exits directly without freeing the previously allocated `xcc_info` structure, resulting in a resource leak. This issue was identified through prototype static analysis too [truncated]
A use-after-free vulnerability in the Linux kernel's AB8500 power supply driver could allow system crashes or memory corruption during driver removal or probe operations. The issue stems from incorrect devm_ resource allocation ordering where the IRQ handler could execute with a freed or uninitialized power_supply handle.
A race condition in the Linux kernel's Intel VT-d IOMMU driver could allow torn reads of PASID table entries, potentially causing unpredictable IOMMU behavior or spurious faults. The vulnerability exists because the kernel performed atomic 512-bit structure assignments to active PASID entries without ensuring hardware-consistent updates. The fix implements a clear-then-update flow with proper invalidation handshakes.
A race condition vulnerability exists in the Linux kernel's Intel VT-d (Virtualization Technology for Directed I/O) IOMMU driver. When tearing down context entries, the driver previously zeroed the entire 128-bit entry using multiple 64-bit writes without first clearing the Present bit. This created a window where the hardware could fetch a partially-zeroed (torn) entry while the Present bit remained set, [truncated]
A NULL pointer dereference vulnerability exists in the Linux kernel's EROFS (Enhanced Read-Only File System) implementation, specifically affecting ztailpacking pclusters. The flaw occurs when compressed folios for ztailpacking pclusters are not validated before being added to I/O chains, causing z_erofs_decompress_pcluster() to dereference a NULL pointer. The vulnerability can be triggered when a fatal s [truncated]
A race condition in the Linux kernel's ext4 filesystem between page migration and bitmap modification can cause bitmap inconsistency reports and potential data corruption. The vulnerability exists in the ext4_mb_load_buddy() fast path, which only increments folio reference counts without acquiring the folio lock, allowing concurrent folio migration to interfere with bitmap operations. The fix modifies loa [truncated]
A locality leak vulnerability in the Linux kernel's Infineon I2C TPM driver (tpm_i2c_infineon) allows the TPM locality to remain held when get_burstcount() times out, potentially causing resource exhaustion or denial of service conditions. The issue occurs in tpm_tis_i2c_send() where a direct return on -EBUSY bypasses the cleanup path. The fix ensures proper locality release via goto out_err on all failure paths.
A kernel memory corruption vulnerability in the Linux stmmac Ethernet driver can trigger an oops (kernel crash) when the split header feature is enabled on GMAC4 hardware. The root cause is an incorrect assumption in buffer length calculation: the driver assumed buf2 of the first descriptor is always fully filled when it is not the last descriptor, but hardware behavior in rare cases violates this assumpt [truncated]
A memory leak vulnerability in the Linux kernel's GPIB (General Purpose Interface Bus) subsystem has been resolved. The issue occurred in the `ni_usb_init()` function within the National Instruments USB-GPIB driver. If `ni_usb_setup_init()` failed during initialization, the function returned `-EFAULT` without freeing the previously allocated `writes` buffer, resulting in a memory leak. Additionally, `ni_u [truncated]
A use-after-free vulnerability exists in the Linux kernel's PM8916 LBC (Low Battery Charger) power supply driver. The issue stems from incorrect ordering of devm-managed resource allocation: the IRQ is requested via devm_request_irq() before the power_supply handle is registered via devm_power_supply_register(). Since devm resources are deallocated in reverse order, during driver removal the power_supply [truncated]
A logic error in the Inside Secure EIP-93 cryptographic driver for the Linux kernel causes a kernel panic during driver detach operations. The vulnerability stems from an incorrect iterator in the driver's cleanup routine that attempts to unregister the same hash algorithm multiple times. This double-unregistration triggers a kernel panic, resulting in a denial-of-service condition when the driver is remo [truncated]
A use-after-free vulnerability exists in the Linux kernel's Goldfish power supply driver. The issue stems from incorrect ordering of devm_ resource allocations: the IRQ was requested before the power_supply handle was registered, causing the power_supply to be freed before the IRQ handler is unregistered during driver removal. This creates a race condition where an interrupt can fire after the power_suppl [truncated]
A slab-out-of-bounds read vulnerability exists in the Linux kernel's NTFS3 filesystem driver, specifically within the `DeleteIndexEntryRoot` case of the `do_action` function. The flaw stems from insufficient bounds validation when retrieving the entry size (`esize`) from a log record. When calculating the end of an entry pointer (`e2`) by adding `esize` to the entry start (`e1`), a maliciously large `esiz [truncated]
A logic flaw in the Linux kernel's Btrfs filesystem can cause chunk allocation to produce overlapping physical extents, leading to transaction aborts with EEXIST (-17) errors. The vulnerability manifests when non-consecutive gaps exist in chunk allocation, particularly affecting DUP (duplicate) chunk types and forced chunk allocation (CONFIG_BTRFS_EXPERIMENTAL). When triggered, the filesystem aborts the t [truncated]
A logic flaw in the Linux kernel's BPF verifier allows incorrect register ID propagation during bounds synchronization, potentially enabling unsafe code paths including division by zero. The vulnerability exists in sync_linked_regs() which incorrectly copies BPF_ADD_CONST state when propagating bounds between linked registers, causing subsequent register links to break and preventing proper bounds propaga [truncated]
A permission bypass vulnerability in the Linux kernel's BPF subsystem allowed unprivileged users to detach BPF programs from tcx and netkit network devices when no program file descriptor was provided to BPF_PROG_DETACH. The vulnerability stemmed from missing capability checks in this specific code path. The fix adds verification that the calling process holds CAP_NET_ADMIN or CAP_SYS_ADMIN before allowin [truncated]
A use-after-free vulnerability in the Linux kernel's AMD XDNA AI accelerator driver (accel/amdxdna) could allow local attackers to trigger system crashes. The flaw occurs when the IOMMU Shared Virtual Address (SVA) unbind operation accesses a memory management (mm) structure that has already been freed. The fix ensures the mm structure reference is held for the entire SVA bind/unbind lifetime by explicitl [truncated]
A vulnerability in the Linux kernel's MCTP (Management Component Transport Protocol) netlink implementation could allow unprivileged users to read uninitialized kernel memory. The issue affects RTM_GETNEIGH responses where padding bytes in ndmsg structures were not zero-initialized, potentially leaking sensitive kernel data to user space. The vulnerability was reported by Syed Faraz Abrar of Zellic and Pu [truncated]
A use-after-free vulnerability exists in the Linux kernel's OpenVPN (ovpn) driver within the `ovpn_net_xmit` function. The flaw occurs during packet transmission when building a socket buffer (skb) list: `skb_share_check` may free the original skb if it is shared, but subsequent operations—including peer lookup, `skb_dst_drop`, and `ovpn_peer_stats_increment_tx`—continue to use the now-stale pointer. The [truncated]
A memory leak vulnerability exists in the Linux kernel's Chips&Media Wave5 VPU driver. When opening encoder or decoder instances, if allocation of codec_info fails after the VPU instance is allocated, the instance is not freed before returning -ENOMEM. This results in a memory leak that could be triggered by resource exhaustion scenarios. The vulnerability affects kernel versions prior to the fix commits. [truncated]
A Time-of-Check-Time-of-Use (TOCTOU) vulnerability in the Linux kernel's BPF subsystem allowed userspace to cache a map hash before modifying map contents, potentially tricking trusted loaders into verifying stale hashes against modified data. The fix enforces that map hashes are only calculated when maps are frozen (immutable), preventing the race condition.
A memory leak vulnerability exists in the Linux kernel's Rust PWM (Pulse Width Modulation) subsystem. When initializing a PWM chip using `pwmchip_alloc()`, the allocated device holds an initial reference that must be released on all error paths. If `__pinned_init()` fails during initialization, the error path returns without calling `pwmchip_put()`, resulting in a memory leak of the allocated `pwm_chip` s [truncated]
A reference-count leak in the Linux kernel's thermal subsystem could allow gradual memory exhaustion on affected systems. The vulnerability exists in thermal_of_cm_lookup(), where a device tree node obtained via of_parse_phandle() was not properly released. The fix applies the __free(device_node) cleanup attribute to ensure automatic deallocation. This is a local issue requiring no authentication; while n [truncated]
A resource leak vulnerability in the Linux kernel's ksmbd SMB server implementation can lead to deadlocks and system instability. The flaw occurs when error paths fail to properly release inode locks and references acquired during path lookup operations, resulting in unbalanced locking that triggers kernel warnings and potential denial of service.
CVE-2026-45923 documents a vulnerability in the Linux kernel's CATC USB Ethernet driver (net/usb/catc.c). The driver failed to validate USB endpoint descriptors before use, assuming hardcoded endpoint numbers (1 for bulk TX/RX, 2 for interrupt status) without verifying their transfer types. A malicious USB device could present endpoints with mismatched transfer types, potentially causing undefined behavio [truncated]
A memory leak vulnerability exists in the Linux kernel's RDMA/mlx5 driver within the UVERBS_HANDLER(MLX5_IB_METHOD_GET_DATA_DIRECT_SYSFS_PATH) function. The function allocates memory via kobject_get_path() to store a device path string. When the device path length exceeds the output buffer length, the handler returns -ENOSPC but fails to free the previously allocated memory, resulting in a kernel memory l [truncated]