boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, August 15, 2026 · all times UTC← 2026-08-14 · archive · 2026-08-16 →

Security Box Score — August 15, 2026 — page 2

Edition of August 15, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–925 of 925
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-72193await10.5LinuxLinux—ntfs3: cap RESTART_TABLE free-chain walker at rt->used
CVE-2026-72214await10.5LinuxLinux—power: supply: cpcap-battery: Fix missing nvmem_device_put() causing referenc…
CVE-2026-72216await10.5LinuxLinux—remoteproc: qcom: Fix leak when custom dump_segments addition fails
CVE-2026-72237await10.5LinuxLinux—perf/x86/amd/brs: Fix kernel address leakage
CVE-2026-72257await10.5LinuxLinux—ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
CVE-2026-72274await10.5LinuxLinux—fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
CVE-2026-72275await10.5LinuxLinux—fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
CVE-2026-72290await10.5LinuxLinux—KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
CVE-2026-72305await10.5LinuxLinux—VDUSE: avoid leaking information to userspace
CVE-2026-72384await10.5LinuxLinux—irqchip/ts4800: Fix missing chained handler cleanup on remove
CVE-2026-72467await10.5LinuxLinux—xprtrdma: Check frwr_wp_create() during connect
CVE-2026-74265await10.5LinuxLinux—net: mana: initialize gdma queue id to INVALID_QUEUE_ID
CVE-2026-74271await10.5LinuxLinux—power: supply: core: fix supplied_from allocations
CVE-2026-72097await10.5LinuxLinux—dm-verity: fix a possible NULL pointer dereference
CVE-2026-72391await10.5LinuxLinux—net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
CVE-2026-745548.810.3LinuxLinux—wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup()
CVE-2026-160077.110.2AppFlowy-IOAppFlowy-CloudCWE-89Authenticated SQL Injection in AppFlowy
CVE-2026-72180await9.9LinuxLinux—mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade
CVE-2026-199172.19.8code-projectsOnline Food Order SystemCWE-74code-projects Online Food Order System delete_food_items1.php sql injection
CVE-2026-199202.19.8code-projectsOnline Shopping SystemCWE-74code-projects Online Shopping System action.php sql injection
CVE-2026-72007await9.8LinuxLinux—pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
CVE-2026-72026await9.8LinuxLinux—irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
CVE-2026-72028await9.8LinuxLinux—riscv: probes: save original sp in rethook trampoline
CVE-2026-72032await9.8LinuxLinux—net/mlx5: HWS, fix matcher leak on resize target setup failure
CVE-2026-72050await9.8LinuxLinux—octeontx2-af: Free BPID bitmap on setup failure
CVE-2026-72101await9.8LinuxLinux—dm-integrity: fix leaking uninitialized kernel memory
CVE-2026-72127await9.8LinuxLinux—netdev-genl: report NAPI thread PID in the caller's pid namespace
CVE-2026-72132await9.8LinuxLinux—NFS: Charge unstable writes by request size, not folio size
CVE-2026-72147await9.8LinuxLinux—dmaengine: dw-edma-pcie: Reject devices without driver data
CVE-2026-72158await9.8LinuxLinux—fpga: dfl: add bounds check in dfh_get_param_size()
CVE-2026-72174await9.8LinuxLinux—fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
CVE-2026-72176await9.8LinuxLinux—mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
CVE-2026-72178await9.8LinuxLinux—mm/damon/core: always put unsuccessfully committed target pids
CVE-2026-72212await9.8LinuxLinux—mm/memory_hotplug: fix incorrect altmap passing in error path
CVE-2026-72258await9.8LinuxLinux—ASoC: mediatek: mt8183: Release reserved memory on cleanup
CVE-2026-72259await9.8LinuxLinux—ASoC: mediatek: mt8192: Release reserved memory on cleanup
CVE-2026-72266await9.8LinuxLinux—fbdev: vesafb: fix memory leak in vesafb_probe()
CVE-2026-72273await9.8LinuxLinux—fbdev: efifb: fix memory leak in efifb_probe()
CVE-2026-72300await9.8LinuxLinux—ASoC: SOF: topology: validate vendor array size before parsing
CVE-2026-72336await9.8LinuxLinux—Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
CVE-2026-72362await9.8LinuxLinux—drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
CVE-2026-72386await9.8LinuxLinux—drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced
CVE-2026-72387await9.8LinuxLinux—drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()
CVE-2026-72394await9.8LinuxLinux—hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
CVE-2026-72430await9.8LinuxLinux—net/sched: act_ct: fix nf_connlabels leak on two error paths
CVE-2026-72468await9.8LinuxLinux—xprtrdma: Initialize re_id before removal registration
CVE-2026-72475await9.8LinuxLinux—dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
CVE-2026-199162.09.6code-projectsOnline Food Order SystemCWE-79code-projects Online Food Order System edit_food_items.php cross site scripting
CVE-2026-72006await9.6LinuxLinux—net/mlx5: free mlx5_st_idx_data on final dealloc
CVE-2026-72016await9.5LinuxLinux—cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
CVE-2026-72091await9.5LinuxLinux—accel/amdxdna: reject user command submission without a command BO
CVE-2026-72094await9.5LinuxLinux—dma-buf: dma-fence: Fix potential NULL pointer dereference
CVE-2026-72104await9.5LinuxLinux—dm-pcache: reject option groups without values
CVE-2026-72128await9.5LinuxLinux—nvmet: fix refcount leak in nvmet_sq_create()
CVE-2026-72131await9.5LinuxLinux—nvme-apple: Prevent shared tags across queues on Apple A11
CVE-2026-72150await9.6LinuxLinux—sunrpc: fix uninitialized xprt_create_args structure
CVE-2026-72169await9.5LinuxLinux—kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
CVE-2026-72205await9.5LinuxLinux—ntfs: free volume-wide resources on fill_super failure
CVE-2026-72281await9.5LinuxLinux—KVM: arm64: account pKVM reclaim against the VM mm
CVE-2026-72292await9.5LinuxLinux—KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory
CVE-2026-72309await9.5LinuxLinux—tracing/remotes: Fix leak in trace_remote_alloc_buffer() error path
CVE-2026-72311await9.5LinuxLinux—drm/xe: free madvise VMA array on L2 flush failure
CVE-2026-72332await9.5LinuxLinux—accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()
CVE-2026-72337await9.5LinuxLinux—Bluetooth: 6lowpan: avoid untracked enable work
CVE-2026-72346await9.5LinuxLinux—platform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/r…
CVE-2026-72359await9.5LinuxLinux—drm/xe: fix NPD in bo_meminfo()
CVE-2026-72370await9.5LinuxLinux—iomap: release pages on atomic dio size mismatch
CVE-2026-72377await9.5LinuxLinux—afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints
CVE-2026-72385await9.5LinuxLinux—tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
CVE-2026-72403await9.5LinuxLinux—ALSA: FCP: Fix NULL pointer dereference in interface lookup
CVE-2026-72431await9.5LinuxLinux—alloc_tag: fix use-after-free in /proc/allocinfo after module unload
CVE-2026-72432await9.5LinuxLinux—tpm_crb: Check ACPI_COMPANION() against NULL during probe
CVE-2026-72458await9.5LinuxLinux—apparmor: fix NULL pointer dereference in unpack_pdb
CVE-2026-74261await9.6LinuxLinux—ALSA: seq: avoid stale FIFO cells during resize
CVE-2026-74266await9.6LinuxLinux—net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek bef…
CVE-2026-74382await9.2LinuxLinux—net/sched: cls_bpf: prevent unbounded recursion in offload rollback
CVE-2026-723428.49.0LinuxLinux—net/mlx5e: Fix HV VHCA stats agent registration race
CVE-2026-723438.49.0LinuxLinux—net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
CVE-2026-722779.38.8LinuxLinux—KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
CVE-2026-722789.38.8LinuxLinux—KVM: arm64: nv: Re-translate VNCR before injecting abort
CVE-2026-74331await8.7LinuxLinux—firmware_loader: Fix recursive lock in device_cache_fw_images()
CVE-2026-722799.08.5LinuxLinux—KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
CVE-2026-72008await8.6LinuxLinux—pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check
CVE-2026-72031await8.6LinuxLinux—ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD
CVE-2026-72145await8.6LinuxLinux—platform/x86/intel/tpmi: use cleanup helpers in mem_write()
CVE-2026-72173await8.6LinuxLinux—fs/proc/task_mmu: do not warn on seeing non-migration pmd entry
CVE-2026-72184await8.6LinuxLinux—ntfs: fix hole runlist memory leak in insert range error path
CVE-2026-72187await8.6LinuxLinux—ntfs: avoid self-deadlock during inode eviction
CVE-2026-72189await8.5LinuxLinux—ntfs: fail attrlist updates when the superblock is inactive
CVE-2026-72190await8.6LinuxLinux—ntfs: fix mrec_lock ABBA deadlock in rename
CVE-2026-72263await8.5LinuxLinux—ASoC: SOF: topology: fix memory leak in snd_sof_load_topology
CVE-2026-72293await8.6LinuxLinux—KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault()
CVE-2026-72313await8.6LinuxLinux—drm/fb-helper: Only consider active CRTCs for vblank sync
CVE-2026-72388await8.6LinuxLinux—drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock
CVE-2026-72402await8.6LinuxLinux—bpf: Mask pseudo pointer values in verifier logs
CVE-2026-72413await8.6LinuxLinux—sctp: fix err_chunk memory leaks in INIT handling
CVE-2026-72453await8.6LinuxLinux—regcache: Do not overwrite error code when finalizing cache after error
CVE-2026-72456await8.6LinuxLinux—apparmor: release exe file resources on path failure
CVE-2026-722847.18.3LinuxLinux—KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
CVE-2026-722807.17.9LinuxLinux—KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
CVE-2026-724257.17.9LinuxLinux—ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
CVE-2026-721338.47.8LinuxLinux—spi: uniphier: Fix completion initialization order before devm_request_irq()
CVE-2026-721518.47.8LinuxLinux—tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
CVE-2026-721978.47.8LinuxLinux—fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
CVE-2026-724837.87.7LinuxLinux—usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
CVE-2026-721167.17.6LinuxLinux—can: bcm: fix stale rx/tx ops after device removal
CVE-2026-722899.37.6LinuxLinux—KVM: arm64: vgic: Check the interrupt is still ours before migrating it
CVE-2026-723299.37.5LinuxLinux—net/liquidio: drop cached VF pci_dev LUT
CVE-2026-724129.37.5LinuxLinux—s390/mm: Fix handling of _PAGE_UNUSED pte bit
CVE-2026-721468.47.6LinuxLinux—dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
CVE-2026-721968.47.6LinuxLinux—fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
CVE-2026-722988.47.6LinuxLinux—net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
CVE-2026-724268.47.5LinuxLinux—bpf: Preserve pointer spill metadata during half-slot cleanup
CVE-2026-742568.47.6LinuxLinux—bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
CVE-2026-742598.47.6LinuxLinux—cifs: remove all cifs files before kill super
CVE-2026-724877.77.6LinuxLinux—PCI: Check ROM header and data structure addr before accessing
CVE-2026-74468await7.6LinuxLinux—gpio: pch: use raw_spinlock_t for the register lock
CVE-2026-722838.87.4LinuxLinux—KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
CVE-2026-722889.37.4LinuxLinux—KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disab…
CVE-2026-724959.37.4LinuxLinux—RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
CVE-2026-722627.87.3LinuxLinux—ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
CVE-2026-723027.87.3LinuxLinux—ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
CVE-2026-68460await7.2LinuxLinux—f2fs: fix potential deadlock in f2fs_balance_fs()
CVE-2026-74276await7.2LinuxLinux—spi: xilinx: use FIFO occupancy register to determine buffer size
CVE-2026-74320await7.2LinuxLinux—fbdev: sm501fb: Fix buffer errors in OF binding code
CVE-2026-74348await7.2LinuxLinux—ocfs2/dlm: require a ref for locking_state debugfs open
CVE-2026-74351await7.2LinuxLinux—ocfs2: rebase copied fsdlm LVB pointers in locking_state
CVE-2026-74395await7.2LinuxLinux—RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
CVE-2026-74402await7.3LinuxLinux—crypto: atmel-sha204a - fix blocking and non-blocking rng logic
CVE-2026-74416await7.3LinuxLinux—drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
CVE-2026-74455await7.2LinuxLinux—can: peak_usb: validate uCAN receive record lengths
CVE-2026-74457await7.2LinuxLinux—can: peak_usb: add bounds check for USB channel index
CVE-2026-74458await7.2LinuxLinux—can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command e…
CVE-2026-74463await7.2LinuxLinux—i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
CVE-2026-74464await7.2LinuxLinux—net: openvswitch: fix skb leak on flow key update failure during ct
CVE-2026-74486await7.2LinuxLinux—binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
CVE-2026-74487await7.2LinuxLinux—binfmt_misc: restore write access when removing an entry
CVE-2026-74498await7.2LinuxLinux—ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
CVE-2026-74499await7.2LinuxLinux—ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
CVE-2026-74505await7.2LinuxLinux—ALSA: 6fire: Fix UAF at error handling during probe
CVE-2026-74525await7.2LinuxLinux—net: sxgbe: free TX rings on RX allocation failure
CVE-2026-74547await7.3LinuxLinux—hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
CVE-2026-720618.87.1LinuxLinux—net: sit: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-720667.87.1LinuxLinux—cpu: hotplug: Bound hotplug states sysfs output
CVE-2026-720677.87.1LinuxLinux—cpu: hotplug: Preserve per instance callback errors
CVE-2026-722827.87.1LinuxLinux—KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
CVE-2026-723147.87.1LinuxLinux—regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK
CVE-2026-723507.87.1LinuxLinux—netfilter: xt_u32: reject invalid shift counts
CVE-2026-723717.87.1LinuxLinux—afs: Fix the volume AFS_VOLUME_RM_TREE is set on
CVE-2026-68456await7.2LinuxLinux—usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
CVE-2026-72448await7.2LinuxLinux—octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
CVE-2026-720859.37.0LinuxLinux—scsi: xen: scsiback: Free unsubmitted command instead of double-putting it
CVE-2026-722868.87.0LinuxLinux—KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
CVE-2026-720277.87.0LinuxLinux—mm/compaction: handle free_pages_prepare() properly in compaction_free()
CVE-2026-723407.87.0LinuxLinux—net: microchip: vcap: fix races on the shared Super VCAP block
CVE-2026-723527.87.0LinuxLinux—HID: bpf: Fix hid_bpf_get_data() range check
CVE-2026-723697.87.0LinuxLinux—minix: avoid overflow in bitmap block count calculation
CVE-2026-723727.87.0LinuxLinux—afs: Fix lack of locking around modifications of net->cells_dyn_ino
CVE-2026-723477.36.9LinuxLinux—netfilter: xt_connmark: reject invalid shift parameters
CVE-2026-721547.86.8LinuxLinux—openrisc: Fix jump_label smp syncing
CVE-2026-723577.86.8LinuxLinux—uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
CVE-2026-723757.86.8LinuxLinux—afs: Fix reinitialisation of the inode, in particular ->lock_work
CVE-2026-724167.36.8LinuxLinux—netfilter: nft_compat: ebtables emulation must reject non-bridge targets
CVE-2026-68459await6.7LinuxLinux—f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
CVE-2026-72424await6.7LinuxLinux—rtc: msc313: fix NULL deref in shared IRQ handler at probe
CVE-2026-72486await6.7LinuxLinux—mailbox: mtk-adsp: fix UAF during device teardown
CVE-2026-74274await6.7LinuxLinux—cxl/region: Fill first free targets[] slot during auto-discovery
CVE-2026-74290await6.7LinuxLinux—net/sched: cls_flow: Dont expose folded kernel pointers
CVE-2026-74327await6.7LinuxLinux—vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
CVE-2026-74339await6.7LinuxLinux—ALSA: seq: Clear variable event pointer on read
CVE-2026-74346await6.7LinuxLinux—RDMA/irdma: Fix OOB read during CQ MR registration
CVE-2026-74373await6.7LinuxLinux—md/raid1,raid10: fix bio accounting for split md cloned bios
CVE-2026-74379await6.7LinuxLinux—dax/kmem: account for partial discontiguous resource upon removal
CVE-2026-74381await6.7LinuxLinux—gpu: host1x: Allow entries in BO caches to be freed
CVE-2026-74399await6.7LinuxLinux—evm: terminate and bound the evm_xattrs read buffer
CVE-2026-74441await6.7LinuxLinux—usb: typec: ucsi: Fix race condition and ordering in port unregistration
CVE-2026-74459await6.7LinuxLinux—can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubm…
CVE-2026-74460await6.7LinuxLinux—can: ems_usb: validate CPC message lengths
CVE-2026-74472await6.7LinuxLinux—ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
CVE-2026-74494await6.7LinuxLinux—ksmbd: reject repeated SMB2 NEGOTIATE requests
CVE-2026-74514await6.7LinuxLinux—KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
CVE-2026-74546await6.7LinuxLinux—hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
CVE-2026-74552await6.7LinuxLinux—hwmon: (lm90) Only report alarms if driver is ready
CVE-2026-721118.86.6LinuxLinux—bpf: Reset register bounds before narrowing retval range in check_mem_access()
CVE-2026-722257.86.7LinuxLinux—jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
CVE-2026-721757.16.6LinuxLinux—fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
CVE-2026-74329await6.7LinuxLinux—watchdog: unregister PM notifier on watchdog unregister
CVE-2026-723608.46.6LinuxLinux—drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
CVE-2026-720727.86.5LinuxLinux—net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
CVE-2026-723357.86.6LinuxLinux—Bluetooth: MGMT: Fix adv monitor add failure cleanup
CVE-2026-724497.86.5LinuxLinux—drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
CVE-2026-724767.86.6LinuxLinux—dmaengine: Fix possible use after free
CVE-2026-723647.16.6LinuxLinux—netfs: Fix writeback error handling
CVE-2026-721838.46.4LinuxLinux—landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
CVE-2026-720717.86.5LinuxLinux—tracing/user_events: Fix use-after-free in user_event_mm_dup()
CVE-2026-74466await6.4LinuxLinux—s390/zcrypt: Close speculative mem read possibility
CVE-2026-723287.86.3LinuxLinux—accel/amdxdna: Fix potential amdxdna_umap lifetime race
CVE-2026-723957.16.4LinuxLinux—hwmon: (pmbus) Fix passing events to regulator core
CVE-2026-722399.36.2LinuxLinux—x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"
CVE-2026-722919.36.2LinuxLinux—KVM: s390: Fix unlikely race in try_get_locked_pte()
CVE-2026-722048.46.2LinuxLinux—ntfs: centalize $INDEX_ROOT header validation
CVE-2026-720807.86.3LinuxLinux—fs/resctrl: Fix use-after-free during unmount
CVE-2026-720937.86.3LinuxLinux—accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
CVE-2026-720197.36.2LinuxLinux—macsec: don't read an unset MAC header in macsec_encrypt()
CVE-2026-72443await6.2LinuxLinux—ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
CVE-2026-74263await6.2LinuxLinux—net: wwan: t7xx: check skb_clone in control TX
CVE-2026-74278await6.2LinuxLinux—ALSA: seq: Fix kernel heap address leak in bounce_error_event()
CVE-2026-74286await6.2LinuxLinux—net: pfcp: allocate per-cpu tstats for PFCP netdevs
CVE-2026-74301await6.2LinuxLinux—Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path
CVE-2026-74303await6.2LinuxLinux—Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-ser…
CVE-2026-74308await6.2LinuxLinux—ext4: fix kernel BUG in ext4_write_inline_data_end
CVE-2026-74318await6.2LinuxLinux—btrfs: fix deadlock cloning inline extent when using flushoncommit
CVE-2026-74352await6.2LinuxLinux—of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails
CVE-2026-74353await6.2LinuxLinux—drm/amdkfd: always resume_all after suspend_all
CVE-2026-74362await6.2LinuxLinux—ext2: fix ignored return value of generic_write_sync()
CVE-2026-74386await6.3LinuxLinux—nvmet-tcp: fix page fragment cache leak in error path
CVE-2026-74389await6.2LinuxLinux—RDMA/hns: Fix log flood after cmd_mbox failure
CVE-2026-74391await6.3LinuxLinux—tracing: Bound synthetic-field strings with seq_buf
CVE-2026-74393await6.2LinuxLinux—drm/syncobj: Fix memory leak in drm_syncobj_find_fence()
CVE-2026-74442await6.2LinuxLinux—drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
CVE-2026-74445await6.2LinuxLinux—drm/vmwgfx: reject DX_BIND_QUERY without a DX context
CVE-2026-74448await6.2LinuxLinux—drm/amdkfd: fix QID bit leak in pqm_create_queue()
CVE-2026-74483await6.2LinuxLinux—binfmt_misc: don't leak the user namespace when the mount fails
CVE-2026-74484await6.2LinuxLinux—binfmt_misc: don't let an 'F' entry pin its own instance
CVE-2026-74500await6.2LinuxLinux—ALSA: usb-audio: fix stack info leak in RME Digiface status
CVE-2026-74501await6.2LinuxLinux—ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
CVE-2026-74502await6.2LinuxLinux—ALSA: ump: fix double free of out_cvts on rawmidi error
CVE-2026-74504await6.2LinuxLinux—ALSA: seq: Fix division by zero in initialize_timer()
CVE-2026-74524await6.2LinuxLinux—riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
CVE-2026-74532await6.2LinuxLinux—Bluetooth: btintel: Validate length before parsing diagnostics TLV
CVE-2026-74536await6.2LinuxLinux—Bluetooth: ISO: fix leaking sk after socket release
CVE-2026-74543await6.3LinuxLinux—net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
CVE-2026-723387.86.0LinuxLinux—net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
CVE-2026-720897.16.0LinuxLinux—accel/ivpu: Reject firmware log with size smaller than header
CVE-2026-68463await6.0LinuxLinux—mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
CVE-2026-68464await6.0LinuxLinux—mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
CVE-2026-68465await6.0LinuxLinux—mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore
CVE-2026-72498await6.0LinuxLinux—RDMA/bnxt_re: Avoid displaying the kernel pointer
CVE-2026-72501await6.0LinuxLinux—RDMA/bnxt_re: Initialize dpi variable to zero
CVE-2026-74307await6.0LinuxLinux—ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT
CVE-2026-74322await6.0LinuxLinux—wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write…
CVE-2026-74324await6.0LinuxLinux—wifi: mt76: mt7925: validate skb length in testmode query
CVE-2026-74335await6.0LinuxLinux—bpf: Fix NULL pointer dereference in bpf_task_from_vpid()
CVE-2026-74337await6.0LinuxLinux—bpf: Fix NMI/tracepoint re-entry deadlock on lru locks
CVE-2026-74358await6.0LinuxLinux—ext4: fix fast commit wait/wake bit mapping on 64-bit
CVE-2026-74360await6.0LinuxLinux—bpf: Reject exclusive maps for bpf_map_elem iterators
CVE-2026-74366await6.0LinuxLinux—wifi: ath12k: fix NULL deref in change_sta_links for unready link
CVE-2026-74372await6.0LinuxLinux—raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
CVE-2026-74400await6.0LinuxLinux—bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries
CVE-2026-74462await6.0LinuxLinux—i2c: imx: mark I2C adapter when hardware is powered down
CVE-2026-74477await6.0LinuxLinux—uprobes: Fix NULL pointer dereference in hprobe_expire()
CVE-2026-74491await6.0LinuxLinux—of/address: Fix NULL bus dereference in of_pci_range_parser_one()
CVE-2026-74559await6.0LinuxLinux—xsk: drain continuation descs after overflow in xsk_build_skb()
CVE-2026-723157.85.9LinuxLinux—smb: client: fix busy dentry warning on unmount after DIO
CVE-2026-723317.85.9LinuxLinux—accel/amdxdna: Fix VMA access race
CVE-2026-723447.85.9LinuxLinux—net/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable
CVE-2026-723457.85.9LinuxLinux—net/mlx5: LAG, Fix off-by-one in single-FDB error rollback
CVE-2026-723587.85.9LinuxLinux—drm/xe/pt: prevent invalid cursor access for purged BOs
CVE-2026-723687.85.9LinuxLinux—cachefiles: Fix double unlock in nomem_d_alloc error path
CVE-2026-74426await5.9LinuxLinux—afs: fix NULL pointer dereference in afs_get_tree()
CVE-2026-74566await5.8LinuxLinux—keys: make keyring key-chunk byte order agree with keyring_diff_objects()
CVE-2026-74577await5.9LinuxLinux—net: mpls: initialize rtm_tos in mpls_getroute()
CVE-2026-720458.85.8LinuxLinux—octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
CVE-2026-720518.85.8LinuxLinux—net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-720528.85.8LinuxLinux—net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-720538.85.8LinuxLinux—net: ipip: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-720548.85.8LinuxLinux—net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-720558.85.8LinuxLinux—net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-721368.85.8LinuxLinux—xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-684747.85.8LinuxLinux—powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
CVE-2026-684797.85.8LinuxLinux—Bluetooth: btrtl: validate firmware patch bounds
CVE-2026-720057.85.8LinuxLinux—wifi: rt2x00: avoid full teardown before work setup in probe
CVE-2026-720127.85.8LinuxLinux—tracing/osnoise: Call synchronize_rcu() when unregistering
CVE-2026-720247.85.8LinuxLinux—mac802154: remove interfaces with RCU list deletion
CVE-2026-720367.85.8LinuxLinux—net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeu…
CVE-2026-721027.85.8LinuxLinux—dm_early_create: fix freeing used table on dm_resume failure
CVE-2026-721057.85.8LinuxLinux—dm-log: fix a bitset_size overflow on 32bit machines
CVE-2026-721087.85.8LinuxLinux—dm thin metadata: fix metadata snapshot consistency on commit failure
CVE-2026-721097.85.8LinuxLinux—net: sparx5: unregister blocking notifier on init failure
CVE-2026-721107.85.8LinuxLinux—bpf,fork: wipe ->bpf_storage before bailouts that access it
CVE-2026-721137.85.8LinuxLinux—can: bcm: add missing device refcount for CAN filter removal
CVE-2026-721147.85.8LinuxLinux—can: bcm: validate frame length in bcm_rx_setup() for RTR replies
CVE-2026-721197.85.8LinuxLinux—can: bcm: extend bcm_tx_lock usage for data and timer updates
CVE-2026-721207.85.8LinuxLinux—can: bcm: add missing rcu list annotations and operations
CVE-2026-721237.85.8LinuxLinux—can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
CVE-2026-721357.85.8LinuxLinux—tpm: Make the TPM character devices non-seekable
CVE-2026-721647.85.8LinuxLinux—ocfs2: avoid moving extents to occupied clusters
CVE-2026-721657.85.8LinuxLinux—mtd: rawnand: fix condition in 'nand_select_target()'
CVE-2026-721707.85.8LinuxLinux—9p: skip nlink update in cacheless mode to fix WARN_ON
CVE-2026-721717.85.8LinuxLinux—mtd: slram: remove failed entries from the device list
CVE-2026-721727.85.8LinuxLinux—mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
CVE-2026-721817.85.8LinuxLinux—mips: sched: Fix CPUMASK_OFFSTACK memory corruption
CVE-2026-721957.85.8LinuxLinux—fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
CVE-2026-722507.85.8LinuxLinux—netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag
CVE-2026-722527.85.8LinuxLinux—netfilter: nft_set_pipapo: don't leak bad clone into future transaction
CVE-2026-722557.85.8LinuxLinux—netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
CVE-2026-722617.85.8LinuxLinux—ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
CVE-2026-723017.85.8LinuxLinux—ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
CVE-2026-724007.85.8LinuxLinux—seg6: validate SRH length before reading fixed fields
CVE-2026-724067.85.8LinuxLinux—net: sungem: fix probe error cleanup
CVE-2026-724197.85.8LinuxLinux—netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
CVE-2026-724357.85.8LinuxLinux—netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
CVE-2026-724507.85.8LinuxLinux—xfrm: validate selector family and prefixlen during match
CVE-2026-742837.85.8LinuxLinux—tipc: require net admin for TIPCv2 netlink mutators
CVE-2026-722948.85.7LinuxLinux—LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
CVE-2026-720187.85.7LinuxLinux—dibs: loopback: validate offset and size in move_data()
CVE-2026-720347.85.7LinuxLinux—fhandle: reject detached mounts in capable_wrt_mount()
CVE-2026-721447.85.7LinuxLinux—platform/x86: dell-laptop: fix missing cleanups in init error path
CVE-2026-722447.85.7LinuxLinux—gpu/buddy: bail out of try_harder when alignment cannot be honoured
CVE-2026-723047.85.7LinuxLinux—ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
CVE-2026-724107.85.7LinuxLinux—octeontx2-af: Validate NIX maximum LFs correctly
CVE-2026-724347.85.7LinuxLinux—netfilter: ipset: make sure gc is properly stopped
CVE-2026-724527.85.7LinuxLinux—drm/i915: clear CRTC color blob pointers after dropping refs
CVE-2026-722958.85.5LinuxLinux—LoongArch: KVM: Validate irqchip index in irqfd routing
CVE-2026-725008.85.5LinuxLinux—RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
CVE-2026-720097.85.5LinuxLinux—pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
CVE-2026-720427.85.5LinuxLinux—ipmi: Fix user refcount underflow in event delivery
CVE-2026-721627.85.5LinuxLinux—ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
CVE-2026-721987.85.5LinuxLinux—ntfs: reject non-resident records for resident-only attributes
CVE-2026-723907.85.6LinuxLinux—net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF
CVE-2026-724887.85.5LinuxLinux—soundwire: fix bug in sdw_add_element_group_count found by syzkaller
CVE-2026-742647.85.5LinuxLinux—net: watchdog: fix refcount tracking races
CVE-2026-72439await5.6LinuxLinux—md/raid10: fix writes_pending leak on write request failures
CVE-2026-722438.45.4LinuxLinux—selinux: check connect-related permissions on TCP Fast Open
CVE-2026-720957.85.5LinuxLinux—dma-fence: Make dma_fence_dedup_array() robust against 0-count input
CVE-2026-74424await5.5LinuxLinux—fbcon: fix NULL pointer dereference for a console without vc_data
CVE-2026-74553await5.5LinuxLinux—hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
CVE-2026-74555await5.5LinuxLinux—scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
CVE-2026-721257.85.3LinuxLinux—can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
CVE-2026-723897.85.3LinuxLinux—bridge: stp: Fix a potential use-after-free when deleting a bridge
CVE-2026-721227.35.3LinuxLinux—can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
CVE-2026-720437.15.4LinuxLinux—LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
CVE-2026-720497.15.4LinuxLinux—ieee802154: admin-gate legacy LLSEC dump operations
CVE-2026-721267.85.3LinuxLinux—can: isotp: use unconditional synchronize_rcu() in isotp_release()
CVE-2026-721037.35.2LinuxLinux—dm: avoid leaking the caller's thread keyring via the table device file
CVE-2026-722137.15.3LinuxLinux—mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
CVE-2026-722977.15.3LinuxLinux—net: atm: reject out-of-range traffic classes in QoS validation
CVE-2026-723837.85.1LinuxLinux—sctp: fix addr_wq_timer race in sctp_free_addr_wq()
CVE-2026-721437.15.1LinuxLinux—platform/x86: ISST: Restore SST-PP control to all domains
CVE-2026-722327.84.9LinuxLinux—batman-adv: ensure minimal ethernet header on TX
CVE-2026-74392await5.0LinuxLinux—dm: limit target bio polling to one shot
CVE-2026-74432await5.0LinuxLinux—rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
CVE-2026-185008.14.9@fastify/jwt@fastify/jwtCWE-347@fastify/jwt vulnerable to authorization bypass via global secret overriding …
CVE-2026-68455await4.9LinuxLinux—liveupdate: validate session type before performing operation
CVE-2026-68468await4.9LinuxLinux—mtd: virt-concat: free duplicate generated name
CVE-2026-72490await4.9LinuxLinux—staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt
CVE-2026-74272await4.9LinuxLinux—cxl/region: Resolve region deletion races
CVE-2026-74273await4.9LinuxLinux—cxl/region: Block region delete during region creation
CVE-2026-74291await4.9LinuxLinux—ASoC: topology: Check PCM and DAI name strings before use
CVE-2026-74298await4.9LinuxLinux—RDMA/core: Fix FRMR set pinned push error path
CVE-2026-74299await4.9LinuxLinux—RDMA/core: Fix FRMR aging push to queue error flow
CVE-2026-74304await4.9LinuxLinux—Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serde…
CVE-2026-74319await4.9LinuxLinux—btrfs: zoned: fix deadlock waiting for ticket during data relocation
CVE-2026-74326await4.9LinuxLinux—wifi: mt76: mt7921: fix resource leak in probe error path
CVE-2026-74336await4.9LinuxLinux—wifi: mac80211: bound S1G TIM PVB walk to the TIM element
CVE-2026-74342await4.9LinuxLinux—kernfs: link kn to its parent before the LSM init hook
CVE-2026-74368await4.9LinuxLinux—wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic()
CVE-2026-74369await4.9LinuxLinux—liveupdate: fix u-a-f in luo_file_unpreserve_files() and luo_file_finish()
CVE-2026-74370await4.9LinuxLinux—liveupdate: fix TOCTOU race in luo_session_retrieve()
CVE-2026-74375await4.9LinuxLinux—md/raid1,raid10: fix deadlock in read error recovery path
CVE-2026-74414await4.9LinuxLinux—hfsplus: Remove the duplicate attr inode dirty marking action
CVE-2026-74415await4.9LinuxLinux—spi: atcspi200: fix use-after-free when driver unbind
CVE-2026-74420await4.9LinuxLinux—drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges
CVE-2026-74421await4.9LinuxLinux—drm/rockchip: dw_dp: Switch to drmm_kzalloc()
CVE-2026-74423await4.8LinuxLinux—accel/amdxdna: Fix leak when pinning ubuf pages
CVE-2026-74437await4.8LinuxLinux—media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work
CVE-2026-74526await4.9LinuxLinux—scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit
CVE-2026-74542await4.9LinuxLinux—netfs: Fix folio_queue ENOMEM in writeback by adding a mempool
CVE-2026-74560await4.8LinuxLinux—xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
CVE-2026-724238.84.8LinuxLinux—bpf: Guard conntrack opts error writes
CVE-2026-742778.84.8LinuxLinux—iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path
CVE-2026-723127.94.8LinuxLinux—octeontx2-af: fix VF bringup affecting PF promiscuous state
CVE-2026-684737.84.8LinuxLinux—powerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address()
CVE-2026-720907.84.8LinuxLinux—accel/amdxdna: Use caller client for debug BO sync
CVE-2026-721127.84.8LinuxLinux—io_uring/bpf-ops: reject re-registration of an already-bound ops
CVE-2026-721347.84.7LinuxLinux—spi: imx: reconfigure for PIO when DMA cannot be started
CVE-2026-722857.84.8LinuxLinux—KVM: TDX: Reject concurrent change to CPUID entry count
CVE-2026-723037.84.8LinuxLinux—ASoC: SOF: ipc4-control: Validate notification payload size
CVE-2026-724047.84.8LinuxLinux—tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()
CVE-2026-724117.84.7LinuxLinux—net: dsa: mxl862xx: fix use-after-free of DSA ports in crc_err_work
CVE-2026-724857.84.8LinuxLinux—coresight: platform: defer connection counter increment until alloc succeeds
CVE-2026-742587.84.8LinuxLinux—bpf: Guard __get_user acesss with access_ok for uprobe_multi data
CVE-2026-742607.84.8LinuxLinux—netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them
CVE-2026-74418await4.7LinuxLinux—dma-fence: Fix potential tracepoint null pointer dereferences
CVE-2026-724467.84.7LinuxLinux—ALSA: usb-audio: qcom: reject stream disable with no active interface
CVE-2026-724788.44.6LinuxLinux—fs/ntfs3: add bounds check to run_get_highest_vcn()
CVE-2026-188074.34.6UnknownECSCWE-862ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modificat…
CVE-2026-723977.14.5LinuxLinux—hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()
CVE-2026-724157.14.4LinuxLinux—ASoC: SDCA: Validate written enum value in ge_put_enum_double()
CVE-2026-724898.44.2LinuxLinux—staging: nvec: fix use-after-free in nvec_rx_completed()
CVE-2026-745197.84.1LinuxLinux—pinctrl: devicetree: don't free uninitialized dev_name on error path
CVE-2026-74422await4.0LinuxLinux—drm/rockchip: inno-hdmi: Switch to drmm_kzalloc()
CVE-2026-74558await4.0LinuxLinux—xsk: reclaim invalid Tx descriptors in ZC batch path
CVE-2026-74571await4.0LinuxLinux—btrfs: skip global block reserve accounting for rescue mounts
CVE-2026-743787.83.8LinuxLinux—RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
CVE-2026-743328.43.7LinuxLinux—ASoC: amd: acp-sdw-sof: Bound DAI link iteration
CVE-2026-743338.43.7LinuxLinux—ASoC: amd: acp-sdw-legacy: Bound DAI link iteration
CVE-2026-743838.43.8LinuxLinux—nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools
CVE-2026-744928.43.7LinuxLinux—netfilter: ipset: do not update comments from kernel-side hash adds
CVE-2026-744978.43.7LinuxLinux—ALSA: usb-audio: Clamp frame size in implicit-feedback mode
CVE-2026-744047.83.8LinuxLinux—crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one
CVE-2026-744527.83.7LinuxLinux—drm/panthor: reject firmware sections with oversized data
CVE-2026-722877.83.7LinuxLinux—KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks
CVE-2026-724597.83.5LinuxLinux—apparmor: aa_label_alloc use aa_label_free on alloc failure
CVE-2026-745107.83.5LinuxLinux—Bluetooth: mgmt: fix UAF in pair command cancellation
CVE-2026-743109.33.4LinuxLinux—vhost/net: complete zerocopy ubufs only once
CVE-2026-745179.33.4LinuxLinux—KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
CVE-2026-744618.43.4LinuxLinux—i2c: imx: Cancel hrtimer before clearing slave pointer
CVE-2026-724707.83.4LinuxLinux—fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
CVE-2026-742627.83.3LinuxLinux—kcm: use WRITE_ONCE() when changing lower socket callbacks
CVE-2026-745168.23.2LinuxLinux—KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
CVE-2026-744399.33.1LinuxLinux—iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry
CVE-2026-724057.83.1LinuxLinux—net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
CVE-2026-724277.83.1LinuxLinux—bpf: Fix effective prog array index with BPF_F_PREORDER
CVE-2026-730478.63.0siyuan-notesiyuanCWE-200siyuan before v3.7.4 Server-Side Template Injection via attribute-view
CVE-2026-744387.83.0LinuxLinux—crypto: sun4i-ss - Remove insecure and unused rng_alg
CVE-2026-743558.23.0LinuxLinux—iommu/vt-d: Fix RB-tree corruption in probe error path
CVE-2026-744817.83.0LinuxLinux—mm/page_reporting: use system_freezable_wq to fix UAF during suspend
CVE-2026-743657.33.0LinuxLinux—nvdimm/btt: Handle preemption in BTT lane acquisition
CVE-2026-743647.13.0LinuxLinux—bpf: Reject exclusive maps as inner maps in map-in-map
CVE-2026-745739.32.9LinuxLinux—iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
CVE-2026-742758.42.9LinuxLinux—cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach()
CVE-2026-724827.82.9LinuxLinux—gpib: fix double decrement of descriptor_busy in command_ioctl()
CVE-2026-743907.82.8LinuxLinux—RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs
CVE-2026-745497.82.8LinuxLinux—hwmon: (nct6775-core) Prevent access to unsupported weight registers
CVE-2026-684668.82.8LinuxLinux—mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
CVE-2026-743808.82.8LinuxLinux—gpu: host1x: Fix iommu_map_sgtable() return value check
CVE-2026-744438.82.8LinuxLinux—drm/vmwgfx: bound DMA command body size against suffix pointer
CVE-2026-745158.82.8LinuxLinux—KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
CVE-2026-684617.82.8LinuxLinux—device property: initialize the remaining fields of fwnode_handle in fwnode_i…
CVE-2026-684677.82.8LinuxLinux—mtd: mchp23k256: use SPI match data for chip caps
CVE-2026-724447.82.8LinuxLinux—flow_dissector: check device type before reading ETH_ADDRS
CVE-2026-724807.82.8LinuxLinux—iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
CVE-2026-742887.82.8LinuxLinux—net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
CVE-2026-742937.82.8LinuxLinux—ASoC: fsl: fsl_audmix: Validate written enum values
CVE-2026-742967.82.8LinuxLinux—RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
CVE-2026-742977.82.8LinuxLinux—RDMA/mlx5: Fix undefined shift of user RQ WQE size
CVE-2026-743057.82.8LinuxLinux—bpf: Tighten cgroup storage cookie checks for prog arrays
CVE-2026-743067.82.7LinuxLinux—vfio/qat: fix f_pos race in qat_vf_resume_write()
CVE-2026-743127.82.8LinuxLinux—vhost/vdpa: validate virtqueue index in mmap and fault paths
CVE-2026-743147.82.8LinuxLinux—bpf: Cancel special fields on map value recycle
CVE-2026-743307.82.8LinuxLinux—configfs: fix lockless traversals of ->s_children
CVE-2026-743777.82.8LinuxLinux—RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
CVE-2026-743977.82.8LinuxLinux—IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
CVE-2026-744407.82.7LinuxLinux—drm/xe: Wait on external BO kernel fences in exec IOCTL
CVE-2026-744447.82.8LinuxLinux—drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
CVE-2026-744467.82.8LinuxLinux—drm/amdkfd: hold event_mutex while checkpointing CRIU events
CVE-2026-744477.82.7LinuxLinux—drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
CVE-2026-744517.82.7LinuxLinux—drm/panthor: validate firmware interface structure sizes
CVE-2026-744537.82.8LinuxLinux—drm/vc4: Zero the tile state data array before each BIN job
CVE-2026-744547.82.8LinuxLinux—drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
CVE-2026-744567.82.8LinuxLinux—can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB su…
CVE-2026-744677.82.8LinuxLinux—s390/qeth: Check CAP_NET_ADMIN for private ioctls
CVE-2026-744707.82.8LinuxLinux—scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
CVE-2026-745037.82.7LinuxLinux—ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
CVE-2026-745517.82.8LinuxLinux—hwmon: (nzxt-smart2) DMA-align output buffer
CVE-2026-142305.42.8UnknownECSCWE-79ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings
CVE-2026-742707.82.7LinuxLinux—handshake: Require admin permission for DONE command
CVE-2026-743387.82.7LinuxLinux—bpf: Reject sleepable BPF_LSM_CGROUP programs at load time
CVE-2026-744057.82.6LinuxLinux—OPP: Fix race between OPP addition and lookup
CVE-2026-724628.82.6LinuxLinux—apparmor: fix race in unix socket mediation when peer_path is used
CVE-2026-745208.82.6LinuxLinux—iommu/iommufd: Fix IOPF group ownership UAF
CVE-2026-684587.82.6LinuxLinux—binder: cache secctx size before release zeroes it
CVE-2026-724617.82.6LinuxLinux—apparmor: fix refcount leak when updating the sk_ctx
CVE-2026-743117.82.6LinuxLinux—virtio: rtc: tear down old virtqueues before restore
CVE-2026-743257.82.6LinuxLinux—wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
CVE-2026-743447.82.6LinuxLinux—bpf: Clear rb node linkage when freeing bpf_rb_root
CVE-2026-743717.82.6LinuxLinux—bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
CVE-2026-743138.82.5LinuxLinux—vduse: hold vduse_lock across IDR lookup in open path
CVE-2026-743597.82.5LinuxLinux—configfs_lookup(): don't leave ->s_dentry dangling on failure
CVE-2026-743877.82.5LinuxLinux—ALSA: seq: midi: Serialize output teardown with event_input
CVE-2026-744507.82.5LinuxLinux—drm/amd/pm: fix pptable use-after-free
CVE-2026-744657.82.5LinuxLinux—net: openvswitch: fix potential UAF on meter attach failure
CVE-2026-744717.82.5LinuxLinux—tracing: Check return value of __register_event() in trace_module_add_events()
CVE-2026-744797.82.5LinuxLinux—net: pktgen: fix proc entry use-after-free
CVE-2026-744827.82.5LinuxLinux—mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
CVE-2026-745127.82.5LinuxLinux—audit: fix potential use-after-free in audit_del_rule()
CVE-2026-745187.82.5LinuxLinux—mm/hugetlb: fix list corruption in allocate_file_region_entries()
CVE-2026-745487.82.5LinuxLinux—forcedeth: fix UAF of txrx_stats in nv_remove
CVE-2026-724607.12.5LinuxLinux—apparmor: check label build before no_new_privs test
CVE-2026-742927.12.5LinuxLinux—ASoC: tegra: tegra210_ahub: Validate written enum value
CVE-2026-742957.12.5LinuxLinux—ASoC: codecs: hdac_hdmi: Validate written enum value
CVE-2026-743497.12.5LinuxLinux—ocfs2: reject FITRIM ranges shorter than a cluster
CVE-2026-744857.12.5LinuxLinux—binfmt_misc: reject a flag character as the field delimiter
CVE-2026-743027.82.4LinuxLinux—Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
CVE-2026-743637.82.5LinuxLinux—bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
CVE-2026-724969.22.4LinuxLinux—RDMA/bnxt_re: Proper rollback if the ioremap fails
CVE-2026-742577.82.3LinuxLinux—sockmap: Fix use-after-free in udp_bpf_recvmsg()
CVE-2026-743887.82.3LinuxLinux—ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data
CVE-2026-745067.82.3LinuxLinux—afs: Fix UAF when sending a message
CVE-2026-745137.82.3LinuxLinux—dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
CVE-2026-724557.12.4LinuxLinux—apparmor: fix uninitialised pointer passed to audit_log_untrustedstring()
CVE-2026-198916.32.4TRENDnetTEW-WLC100CWE-310TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption
CVE-2026-745689.32.2LinuxLinux—KVM: arm64: vgic: Fix race between LPI release and re-registration
CVE-2026-745747.82.2LinuxLinux—dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
CVE-2026-744037.82.1LinuxLinux—crypto: ccp - Check for page allocation failure correctly in TIO
CVE-2026-745447.82.1LinuxLinux—net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
CVE-2026-724978.82.1LinuxLinux—RDMA/bnxt_re: Add a max slot check for SQ
CVE-2026-724998.82.1LinuxLinux—RDMA/bnxt_re: Free CQ toggle page after firmware teardown
CVE-2026-742858.82.0LinuxLinux—net: Stop leased rxq before uninstalling its memory provider
CVE-2026-743288.82.1LinuxLinux—iommufd: Destroy the pages content after detaching from dmabuf
CVE-2026-745278.82.1LinuxLinux—octeontx2-af: Block VFs from clobbering special CGX PKIND state
CVE-2026-684627.82.0LinuxLinux—bpf: Reject negative const offsets for buffer pointers
CVE-2026-724547.82.1LinuxLinux—i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()
CVE-2026-742897.82.1LinuxLinux—ipv4: fib: Don't dump dying fib_info in fib_leaf_notify().
CVE-2026-743177.82.1LinuxLinux—ixgbe: do not configure xps for XDP queues
CVE-2026-743347.82.1LinuxLinux—RDMA/nldev: Fix locking when accessing mr->pd
CVE-2026-743437.82.1LinuxLinux—kernfs: fix xattr race condition with multiple superblocks
CVE-2026-743477.82.1LinuxLinux—netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount
CVE-2026-743547.82.1LinuxLinux—bpf: Take mmap_lock in zap_pages()
CVE-2026-743577.82.0LinuxLinux—drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump
CVE-2026-743677.82.1LinuxLinux—wifi: ath12k: fix inconsistent arvif state in vdev_create error paths
CVE-2026-744177.82.0LinuxLinux—drm/radeon: fix integer overflow in radeon_align_pitch()
CVE-2026-744497.82.1LinuxLinux—drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport
CVE-2026-744967.82.1LinuxLinux—fou: Fix use-after-free in fou_create()
CVE-2026-745297.82.1LinuxLinux—Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
CVE-2026-745647.11.9LinuxLinux—netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
CVE-2026-745637.81.9LinuxLinux—rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
CVE-2026-745677.11.8LinuxLinux—keys: fix out-of-bounds read in keyring_get_key_chunk()
CVE-2026-745657.81.8LinuxLinux—netfilter: nf_tables: make nft_object rhltable per table
CVE-2026-742947.31.7LinuxLinux—ASoC: meson: aiu: Validate written enum values
CVE-2026-745628.81.5LinuxLinux—nexthop: take nh->lock for f6i_list walks in replace check and notify
CVE-2026-745618.81.5LinuxLinux—nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush
CVE-2026-744197.31.4LinuxLinux—accel/amdxdna: Adjust size for copy_to_user()
CVE-2026-181654.20.9@fastify/oauth2@fastify/oauth2CWE-352@fastify/oauth2 vulnerable to Login CSRF via plantable OAuth state cookies