PatchSiren

Linux CVE debriefs · Page 99

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45921

A memory leak vulnerability exists in the Linux kernel's MTD (Memory Technology Device) parser subsystem, specifically within the TP-Link Safeloader parser. The function `mtd_parser_tplink_safeloader_parse()` allocates a buffer via `mtd_parser_tplink_safeloader_read_table()`. If a subsequent allocation for `parts[idx].name` fails during loop iteration, the error handling path jumps to the `err_free` label [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45920

This CVE addresses a double-decrement bug in the Linux kernel's ext4 filesystem that could cause s_dirtyclusters_counter to underflow to -1 during filesystem shutdown scenarios. The vulnerability manifests as a WARNING in ext4_put_super() when the dirty clusters counter becomes negative. The root cause involves error handling in the block allocation path: when ext4_mb_mark_diskspace_used() encounters an e [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45919

A logic flaw in the Linux kernel's real-time (RT) scheduler load balancing code can cause an overloaded CPU to enter an infinite self-IPI loop, resulting in a CPU hardlockup. The vulnerability exists in the `rto_next_cpu()` function used during RT task push operations when `HAVE_RT_PUSH_IPI` is enabled. When multiple CPUs trigger RT load balancing simultaneously, a race condition between `rd->rto_loop` an [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45918

A race condition in the Linux kernel's OpenVPN (ovpn) TCP socket handling can cause a NULL pointer dereference crash. When a peer is removed due to keepalive expiration, it enters a release list for socket cleanup. If userspace closes the TCP socket while the peer is in this list, tcp_close() sets sk->sk_socket to NULL. When the release routine later calls ovpn_tcp_socket_detach(), it dereferences this NU [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45917

A race condition in the Linux kernel's IP Virtual Server (IPVS) subsystem can lead to leaked device references when network interfaces are brought down. The vulnerability exists in the interaction between the `ip_vs_dst_event()` netdev notifier and code that caches destination routes (`dest_dst`) with devices that are shutting down. Because the Forwarding Information Base (FIB) may be notified about a clo [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45916

A use-after-free vulnerability in the Linux kernel's SBS battery driver (power: supply: sbs-battery) could allow system crashes or memory corruption during driver removal or probe operations. The issue stems from incorrect ordering of devm_ resource allocations: the IRQ was requested before the power_supply handle registration, causing the power_supply to be freed before IRQ unregistration during removal. [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45915

A vulnerability in the Linux kernel's FAT filesystem implementation could allow corrupted FAT images to trigger a kernel warning or potentially cause undefined behavior. The issue occurs when a directory inode has an incorrect link count (i_nlink) due to filesystem corruption. When rmdir is called on such a directory, the kernel unconditionally decrements the link count, which can drive i_nlink to zero an [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45913

A logic error in the Linux kernel's bridge multicast (mcast) implementation allows an unpaired decrement of the mdb_n_entries counter, triggering a kernel warning and potential instability. The vulnerability exists because mdb_n_entries was increased conditionally based on runtime state, but decreased unconditionally during cleanup operations. A specific trigger sequence involves: creating a bridge with V [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45912

A vulnerability in the Linux kernel's ext4 filesystem could lead to stale extent entries in the extent status tree during extent splitting operations. When ext4_split_extent_at() splits an unwritten extent, the caching of extents during this process may insert truncated ranges as holes into the extent status tree. These holes are not replaced with correct status after the split completes. If a delayed buf [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45911

A NULL pointer dereference vulnerability exists in the Linux kernel's Cadence USB3 (cdns3) driver during system resume operations. The issue occurs when a USB role change happens while the system is suspended. Upon resume, the driver attempts to switch to host mode, but the xhci-hcd device registration is deferred during the resume path. The host role's resume() operation assumes the xhci-hcd device has a [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45910

A race condition in the Linux kernel's RDMA/rxe (Soft-RoCE) driver can cause use-after-free warnings and reference count underflow during Queue Pair (QP) destruction. The vulnerability exists in the interaction between retransmit_timer() and rxe_destroy_qp(), where the QP's reference count may drop to zero while a timer handler is still executing. The issue manifests as kernel warnings including refcount_ [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45909

A vulnerability in the Linux kernel's Mediatek clock driver has been resolved. The issue stemmed from incorrect use of the `__initconst` annotation on `mtk_gate` structures. Following a refactoring in commit 8ceff24a754a, these structures are accessed at runtime, not just during initialization. The `__initconst` annotation causes the kernel to discard this data after boot, leading to use-after-free or inv [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45908

A memory leak vulnerability exists in the Linux kernel's AMD XDNA accelerator driver. The `amdxdna_ubuf_map()` function in `accel/amdxdna` allocates memory for scatter-gather (sg) and internal sg table structures, but fails to free these allocations if subsequent operations—specifically `sg_alloc_table_from_pages()` or `dma_map_sgtable()`—fail. This results in a resource leak that could lead to memory exh [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45907

A lock ordering vulnerability in the Linux kernel's Mellanox mlx5 Ethernet driver (mlx5e) can cause deadlocks during health reporter recovery operations. The issue stems from incorrect lock acquisition order when recovery work handlers attempt to acquire the netdev lock before the devlink lock, violating the established initialization hierarchy of devlink lock → rtnl lock → netdev lock. This affects recov [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45906

A use-after-free vulnerability exists in the Linux kernel's PF1550 power supply driver. The issue stems from incorrect ordering of devm-managed resource allocations: the IRQ is requested via devm_request_irq() before the power_supply handle is registered via devm_power_supply_register(). Because devm resources are deallocated in reverse order of allocation, during driver removal the power_supply handle is [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45905

A race condition in the Linux kernel's XFRM (IPsec) subsystem can cause a kernel warning when generating ICMP error messages. The vulnerability exists in `icmp_route_lookup()` during reverse path processing for ICMP replies. When an address becomes local between route checks and `ip_route_input()` execution (e.g., via concurrent `ip addr add`), the function may obtain a LOCAL route with `dst.output` set t [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45904

A recursive locking vulnerability in the Linux kernel's PowerPC EEH (Enhanced Error Handling) driver can cause deadlock conditions and disrupt PCI error reporting on IBM Power systems. The issue stems from commit 1010b4c012b0, which restructured EEH driver synchronization with PCI hotplug but inadvertently moved pci_lock_rescan_remove() outside its intended scope in eeh_handle_normal_event(). This caused [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45903

A memory access flag inconsistency in Linux kernel BPF helper prototypes allows the verifier to incorrectly optimize away memory reads, potentially causing correctness issues in BPF programs. The vulnerability stems from helper functions using ARG_PTR_TO_MEM without proper MEM_RDONLY or MEM_WRITE flags, causing the verifier to assume buffer contents remain unchanged across helper calls. The fix corrects t [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45902

A use-after-free vulnerability in the Linux kernel's BQ256xx power supply driver could allow system crashes or memory corruption during driver removal or probe. The issue stems from incorrect ordering of devm-managed resource allocation: the IRQ was requested before the power_supply handle registration, causing the power_supply to be freed before IRQ unregistration during teardown. This creates a race whe [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45901

A vulnerability in the Linux kernel's netfilter nf_tables subsystem has been resolved. The issue involved a circular lock dependency between commit_mutex, nfnl_subsys_ipset, and nlk_cb_mutex that could occur when nft reset operations, ipset list operations, and iptables-nft rules using '-m set' were executed concurrently. The fix reverts the use of commit_mutex in the reset path, as previous patches had m [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45900

A memory leak vulnerability exists in the Linux kernel's NXP CAAM (Cryptographic Acceleration and Assurance Module) driver for DPAA2 (Data Path Acceleration Architecture Gen 2) platforms. The issue stems from incomplete cleanup of dynamically allocated net_device structures during probe failure paths. When commit 0e1a4d427f58 converted embedded net_device structures to dynamically allocated pointers, clea [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45899

A vulnerability in the Linux kernel's ext4 filesystem could leave stale extent entries in the extent status tree when extent splitting operations fail. The issue occurs because failed split operations may return errors directly without cleaning up partially processed extents, resulting in inconsistent filesystem state. The fix ensures that all potentially stale extents are dropped when splitting fails, ma [truncated]

CRITICAL Linux CVE published 2026-05-27

CVE-2026-45898

A use-after-free vulnerability in the Linux kernel's RDMA iWARP Connection Manager (iw_cm) can cause kernel crashes due to workqueue list corruption. The issue stems from commit e1168f0, which changed work submission logic to unconditionally call queue_work() while using a free list of iwcm_work structures. Each queue_work() call queues unique work items, allowing a work handler to process and release an [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45897

A vulnerability in the Linux kernel's netfilter component has been addressed. The nft_counter vulnerability allowed concurrent dump-and-reset operations to underrun values. A global static spinlock has been added to serialize counter fetch+reset operations. This change prevents potential underruns of counter values during concurrent access, enhancing the stability and security of the Linux kernel's netfil [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45896

A vulnerability in the Linux kernel's Intel Discrete Graphics (DG) MTD driver could allow out-of-bounds memory access during device initialization. The flaw occurs in drivers/mtd/devices/mtd_intel_dg.c where the regions array is accessed using nregions before the variable is properly set, triggering UBSAN array-index-out-of-bounds warnings. The bug also masks memory allocation failures (ENOMEM) by silentl [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45895

A livelock vulnerability exists in the Linux kernel's quota subsystem that can cause system hangs when filesystem freeze operations and quota control operations execute concurrently on non-preemptible kernels. The issue occurs in quotactl_block() when it enters a retry loop waiting for a frozen filesystem to thaw. On kernels with preemption disabled, this loop lacks scheduling points, preventing the CPU f [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45894

A race condition vulnerability in the Linux kernel's Intel VT-d (Virtualization Technology for Directed I/O) driver could allow IOMMU hardware to observe inconsistent PASID (Process Address Space ID) table entry states during teardown operations. The flaw occurs because the current implementation zeros the entire 64-byte PASID entry while the Present bit remains set, creating a window where hardware fetch [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45893

A vulnerability in the Linux kernel's AppArmor security module has been resolved. The issue involved unaligned memory access when creating tables from data blobs that may originate from userspace. The fix optimizes the copying process to avoid unaligned memory accesses, which could lead to undefined behavior or potential crashes on architectures sensitive to alignment. The patch was committed to the stabl [truncated]

MEDIUM Linux CVE published 2026-05-27

CVE-2026-45892

A vulnerability in the Linux kernel's ext4 filesystem could leave stale unwritten extent entries in the extent status tree after a partial zeroout operation. When ext4_split_extent() splits an unwritten extent with EXT4_EXT_MAY_ZEROOUT and EXT4_EXT_DATA_PARTIAL_VALID1 flags set, a failed split attempt at one boundary followed by a successful split at another boundary can result in the extent status tree c [truncated]

HIGH Linux CVE published 2026-05-27

CVE-2026-45891

A double-free vulnerability exists in the Linux kernel's HNS3 (Hisilicon Network Subsystem 3) Ethernet driver. The flaw occurs in `hns3_set_ringparam()` when modifying ring parameters. During this operation, a temporary copy of the ring structure (`tmp_rings`) is created for rollback purposes, but the `tx_spare` pointer in the original ring structure is not cleared after being saved. If subsequent memory [truncated]