boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, September 11, 2026 · all times UTC← 2026-09-10 · archive

Security Box Score — September 11, 2026 — page 2

Edition of September 11, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–703 of 703
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-89471await—LinuxLinux—power: supply: cros_usbpd-charger: bound the EC-reported port count
CVE-2026-89472await—LinuxLinux—power: supply: charger-manager: register regulators before exposing sysfs
CVE-2026-89473await—LinuxLinux—power: supply: bq25890: Fix power_supply reference leak
CVE-2026-89474await—LinuxLinux—power: supply: bq256xx: drain usb_work before freeing the charger
CVE-2026-89475await—LinuxLinux—power: supply: bq24257: fix use-after-free on remove
CVE-2026-89476await—LinuxLinux—sctp: fix stream->outcnt underflow on duplicate RECONF responses
CVE-2026-89477await—LinuxLinux—sctp: fix NULL deref on untransmitted RECONF completion
CVE-2026-89478await—LinuxLinux—sctp: drop a chunk if its transport was removed
CVE-2026-89479await—LinuxLinux—sctp: stop processing a packet once its association is deleted
CVE-2026-89480await—LinuxLinux—nvme-tcp: reject a read that transferred too few bytes
CVE-2026-89481await—LinuxLinux—nvme-tcp: fix host memory disclosure on R2T for a read command
CVE-2026-89482await—LinuxLinux—nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
CVE-2026-89483await—LinuxLinux—nvme: zero the discard fallback page
CVE-2026-89484await—LinuxLinux—lockd: fix NULL dereference on lockowner allocation failure
CVE-2026-89485await—LinuxLinux—lockd: pin next file across nlm_inspect_file lock-drop
CVE-2026-89486await—LinuxLinux—ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
CVE-2026-89487await—LinuxLinux—openvswitch: only skb_tx_error() a packet we are about to drop
CVE-2026-89488await—LinuxLinux—openvswitch: Fix CT limit teardown use-after-free
CVE-2026-89489await—LinuxLinux—openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
CVE-2026-89490await—LinuxLinux—ocfs2: fix readdir position truncation on 32-bit kernels
CVE-2026-89491await—LinuxLinux—ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
CVE-2026-89492await—LinuxLinux—ocfs2: validate directory-index entry counts when reading metadata
CVE-2026-89493await—LinuxLinux—ocfs2: validate rl_used against rl_count in refcount block validator
CVE-2026-89494await—LinuxLinux—ocfs2: validate lengths in dlm_mig_lockres_handler
CVE-2026-89495await—LinuxLinux—ocfs2: bound namelen in dlm_migrate_request_handler
CVE-2026-89496await—LinuxLinux—ocfs2: always run deallocs on copy-on-write completion
CVE-2026-89497await—LinuxLinux—orangefs: skip leading spaces before parsing client debug masks
CVE-2026-89498await—LinuxLinux—orangefs: fix double-free of trailer_buf on readdir copy failure
CVE-2026-89499await—LinuxLinux—ring-buffer: Stop remote reader update when page swap fails
CVE-2026-89500await—LinuxLinux—ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page
CVE-2026-89501await—LinuxLinux—ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
CVE-2026-89502await—LinuxLinux—ring-buffer: Free cpu_buffer::free_page with subbuf_order
CVE-2026-89503await—LinuxLinux—ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
CVE-2026-89504await—LinuxLinux—regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving da…
CVE-2026-89505await—LinuxLinux—RDMA/uverbs: Guard legacy bundles without method_elm
CVE-2026-89506await—LinuxLinux—RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
CVE-2026-89507await—LinuxLinux—RDMA/ucma: Lock the handler in ucma_write_cm_event()
CVE-2026-89508await—LinuxLinux—RDMA/ucma: Lock the handler in ucma_set_ib_path()
CVE-2026-89509await—LinuxLinux—RDMA/ionic: Embed counter driver data in rdma_counter allocation
CVE-2026-89510await—LinuxLinux—RDMA/cxgb4: Cancel reg_work before freeing device on remove
CVE-2026-89511await—LinuxLinux—qede: Fix NULL pointer dereference in TPA fragment processing
CVE-2026-89512await—LinuxLinux—remoteproc: scp: Fix device reference leak on failed lookup
CVE-2026-89513await—LinuxLinux—RISC-V: KVM: Fix PMU event info array size overflow
CVE-2026-89514await—LinuxLinux—scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock
CVE-2026-89515await—LinuxLinux—scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
CVE-2026-89516await—LinuxLinux—sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users
CVE-2026-89517await—LinuxLinux—sched_ext: Fix rq->core_pick corruption under core scheduling
CVE-2026-89518await—LinuxLinux—sched_ext: Fix this_rq() assumptions in dispatch kfuncs
CVE-2026-89519await—LinuxLinux—sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return
CVE-2026-89520await—LinuxLinux—sched/core: Make core-sched flips wait for in-flight selections
CVE-2026-89521await—LinuxLinux—sched/core: Handle pick_task() releasing the rq lock
CVE-2026-89522await—LinuxLinux—media: staging/ipu7: fix async notifier UAF on probe error path
CVE-2026-89523await—LinuxLinux—wifi: mt76: mt7925: cancel pending mlo_pm_work
CVE-2026-89524await—LinuxLinux—wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
CVE-2026-89525await—LinuxLinux—udf: reject VAT indexes equal to the entry count
CVE-2026-89526await—LinuxLinux—svcrdma: Validate Read chunk positions before reconstruction
CVE-2026-89527await—LinuxLinux—svcrdma: Use svc_xprt_put to free listener on create failure
CVE-2026-89528await—LinuxLinux—svcrdma: Reject Read lists that exceed the page budget
CVE-2026-89529await—LinuxLinux—svcrdma: Reject oversized Read segments at decode time
CVE-2026-89530await—LinuxLinux—svcrdma: Reject inline replies that overflow the pull-up buffer
CVE-2026-89531await—LinuxLinux—svcrdma: Reject connection when transport allocation fails
CVE-2026-89532await—LinuxLinux—svcrdma: Fix pcl_for_each_segment for empty chunks
CVE-2026-89533await—LinuxLinux—svcrdma: Fix offset arithmetic in read_chunk_range
CVE-2026-89534await—LinuxLinux—svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails
CVE-2026-89535await—LinuxLinux—svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id
CVE-2026-89536await—LinuxLinux—SUNRPC: wait for in-flight client TLS handshake callback
CVE-2026-89537await—LinuxLinux—SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2
CVE-2026-89538await—LinuxLinux—SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
CVE-2026-89539await—LinuxLinux—SUNRPC: reject duplicate CREDS_VALUE options
CVE-2026-89540await—LinuxLinux—sunrpc: init gssp_lock before publishing proc entry
CVE-2026-89541await—LinuxLinux—SUNRPC: harden gss_unwrap_resp_priv length checks
CVE-2026-89542await—LinuxLinux—SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
CVE-2026-89543await—LinuxLinux—sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_p…
CVE-2026-89544await—LinuxLinux—SUNRPC: fix gssx_dec_option_array error path bugs
CVE-2026-89545await—LinuxLinux—sunrpc: defer rq_argp and rq_resp free until after RCU grace period
CVE-2026-89546await—LinuxLinux—SUNRPC: close backchannel before destroying callback service
CVE-2026-89547await—LinuxLinux—SUNRPC: Check svc pool percpu counter allocation
CVE-2026-89548await—LinuxLinux—SUNRPC: always drain cache_cleaner before destroying a cache_detail
CVE-2026-89549await—LinuxLinux—sunrpc: route to a populated pool in svc_pool_for_cpu()
CVE-2026-89550await—LinuxLinux—SUNRPC: svcauth_gss: enforce krb5 token minimum length
CVE-2026-89551await—LinuxLinux—SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
CVE-2026-89552await—LinuxLinux—params: fix charp corruption on allocation failure
CVE-2026-89553await—LinuxLinux—nouveau/gem: reserve the bo in the info ioctl around the vma lookup
CVE-2026-89554await—LinuxLinux—mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
CVE-2026-89555await—LinuxLinux—mpls: reload header after pskb_may_pull()
CVE-2026-89556await—LinuxLinux—module: validate string table section types
CVE-2026-89557await—LinuxLinux—md: do overflow check for sb->bblog_shift in super_1_load()
CVE-2026-89558await—LinuxLinux—md/raid10: fix still_degraded being inverted in raid10_sync_request()
CVE-2026-89559await—LinuxLinux—libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
CVE-2026-89560await—LinuxLinux—landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
CVE-2026-89561await—LinuxLinux—ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
CVE-2026-89562await—LinuxLinux—ip6_gre: fix hardware header length for NBMA tunnels
CVE-2026-89563await—LinuxLinux—ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
CVE-2026-89564await—LinuxLinux—ip: orphan prefetched skbs before multicast forwarding
CVE-2026-89565await—LinuxLinux—ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
CVE-2026-89566await—LinuxLinux—jbd2: check need_resched() when skipping busy checkpoint buffers
CVE-2026-89567await—LinuxLinux—jbd2: bound shrinker scans by examined checkpoint buffers
CVE-2026-89568await—LinuxLinux—kho: fix size calculation in kho_preserved_memory_reserve()
CVE-2026-89569await—LinuxLinux—Bluetooth: RFCOMM: serialize security confirmation handling
CVE-2026-89570await—LinuxLinux—cxl/mce: Make the MCE notifier per-region
CVE-2026-89571await—LinuxLinux—cxl/features: bound fwctl command payload to the input buffer
CVE-2026-89572await—LinuxLinux—cpufreq: apple-soc: Fix OPP table cleanup
CVE-2026-89573await—LinuxLinux—dm array: reject an array block whose value size is not the caller's
CVE-2026-89574await—LinuxLinux—dm array: validate array block headers on read
CVE-2026-89575await—LinuxLinux—dm raid1: reserve space for NUL-terminator in build_constructor_string()
CVE-2026-89576await—LinuxLinux—dm-era: fix shadowed superblock leak on take-snap failure
CVE-2026-89577await—LinuxLinux—dm-io: report non-retryable errors separatedly
CVE-2026-89578await—LinuxLinux—dm-io: clone the source bio instead of copying its biovec
CVE-2026-89579await—LinuxLinux—bpf: Harden bloom filter sizing and indexing on 32-bit kernels
CVE-2026-89580await—LinuxLinux—bpf: Disable preemption in __bpf_get_stack
CVE-2026-89581await—LinuxLinux—bpf, x86: Fix per-CPU address resolution into an extended register
CVE-2026-89582await—LinuxLinux—bnx2x: fix double free in bnx2x_init_firmware() error path
CVE-2026-89583await—LinuxLinux—Bluetooth: eir: Fix OOB read in eir_get_service_data()
CVE-2026-89584await—LinuxLinux—block: validate user space vectors during extraction
CVE-2026-89585await—LinuxLinux—auxdisplay: charlcd: cancel backlight work on registration failure
CVE-2026-89586await—LinuxLinux—ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
CVE-2026-89587await—LinuxLinux—ACPI: pfr_update: fix stack buffer overflow in query_capability()
CVE-2026-89588await—LinuxLinux—ACPI: APEI: GHES: fix ARM section length accounting after header
CVE-2026-89589await—LinuxLinux—acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks
CVE-2026-89590await—LinuxLinux—accel/rocket: Fix error path handling in rocket_job_run()
CVE-2026-89591await—LinuxLinux—accel/rocket: initialize job domain before cleanup paths
CVE-2026-89592await—LinuxLinux—accel/rocket: fix NULL dereference and integer overflow in rocket_job_push()
CVE-2026-89593await—LinuxLinux—hugetlb: only adjust reservation during unmapping if mapcount is 0
CVE-2026-89594await—LinuxLinux—hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
CVE-2026-89595await—LinuxLinux—fsnotify: Fix stale object mask after concurrent mark updates
CVE-2026-89596await—LinuxLinux—forcedeth: fix off-by-one when saving/restoring non-PCI config space
CVE-2026-89597await—LinuxLinux—fbdev: uvesafb: unregister connector callback on init failure
CVE-2026-89598await—LinuxLinux—fbdev: ssd1307fb: defer I2C transfers from damage callbacks
CVE-2026-89599await—LinuxLinux—fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
CVE-2026-89600await—LinuxLinux—fanotify: fix use-after-free of file range info
CVE-2026-89601await—LinuxLinux—ext2: Fix lost inode updates for IS_SYNC inodes
CVE-2026-89602await—LinuxLinux—erofs: skip sufficiently large global buffers when resizing
CVE-2026-89603await—LinuxLinux—entry: Fix seccomp bypass after ptrace with TSYNC
CVE-2026-89604await—LinuxLinux—efivarfs: Rate limit statfs() handler
CVE-2026-89605await—LinuxLinux—ecryptfs: release message context on send failure
CVE-2026-89606await—LinuxLinux—ecryptfs: reject too-small tag 70 packets
CVE-2026-89607await—LinuxLinux—ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
CVE-2026-89608await—LinuxLinux—ecryptfs: pass packet set buffer size to parser
CVE-2026-89609await—LinuxLinux—ecryptfs: hold msg ctx list lock when cleaning daemon queue
CVE-2026-89610await—LinuxLinux—ntfs: verify run length exceeding volume boundary
CVE-2026-89611await—LinuxLinux—ntfs: validate non-resident attribute offsets
CVE-2026-89612await—LinuxLinux—ntfs: reject invalid MFT LCNs from boot sector
CVE-2026-89613await—LinuxLinux—ntfs: reject invalid empty mapping pairs
CVE-2026-89614await—LinuxLinux—ntfs: bound the free-cluster bitmap scan to the volume
CVE-2026-89615await—LinuxLinux—fs/ntfs3: bound page_lcns[] index by the log record
CVE-2026-89616await—LinuxLinux—fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
CVE-2026-89617await—LinuxLinux—fs/ntfs3: validate dirty page table on log replay
CVE-2026-89618await—LinuxLinux—eventfs: Initialize ei->children and ei->list in init_ei()
CVE-2026-89619await—LinuxLinux—HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller b…
CVE-2026-89620await—LinuxLinux—HID: intel-thc-hid: intel-quickspi: validate report size before copy
CVE-2026-89621await—LinuxLinux—HID: mcp2221: validate report size in mcp2221_raw_event()
CVE-2026-89622await—LinuxLinux—HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes
CVE-2026-89623await—LinuxLinux—HID: mcp2221: stop device IO before hid_hw_stop
CVE-2026-89624await—LinuxLinux—HID: universal-pidff: stop the device when force-feedback init fails
CVE-2026-89625await—LinuxLinux—HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind
CVE-2026-89626await—LinuxLinux—HID: sensor: custom: Fix field sysfs group cleanup on failure
CVE-2026-89627await—LinuxLinux—HID: roccat: free buffered reports when destroying device
CVE-2026-89628await—LinuxLinux—HID: picolcd: clamp eeprom debugfs read to bytes actually received
CVE-2026-89629await—LinuxLinux—HID: corsair-void: Check size of status and firmware events before reading them
CVE-2026-89630await—LinuxLinux—smb: client: restore the data_offset bound in is_valid_oplock_break()
CVE-2026-89631await—LinuxLinux—smb: client: reject a tree connect response whose byte count is too small
CVE-2026-89632await—LinuxLinux—smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()
CVE-2026-89633await—LinuxLinux—smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()
CVE-2026-89634await—LinuxLinux—smb: client: fix ALIGN() overflow in symlink_data() error context loop
CVE-2026-89635await—LinuxLinux—ksmbd: only rebind the reopened file's own oplock on durable reconnect
CVE-2026-89636await—LinuxLinux—smb: client: clear ce->tgthint in free_tgts()
CVE-2026-89637await—LinuxLinux—smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed sec…
CVE-2026-89638await—LinuxLinux—smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix …
CVE-2026-89639await—LinuxLinux—cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC
CVE-2026-89640await—LinuxLinux—cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
CVE-2026-89641await—LinuxLinux—cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
CVE-2026-89642await—LinuxLinux—cifs: call pagecache_isize_extended() in cifs_setsize() when extending
CVE-2026-89643await—LinuxLinux—audit: avoid dropping live tree ref on fsnotify rule autoremove
CVE-2026-89644await—LinuxLinux—btrfs: fix extent map leak in NOCOW direct I/O write
CVE-2026-89645await—LinuxLinux—btrfs: drop recovered reloc root refs on recovery failure
CVE-2026-89646await—LinuxLinux—ceph: fix leaked inode reference on writeback abort at umount
CVE-2026-89647await—LinuxLinux—ceph: do not repeat ceph_trim_dentries() if no progress possible
CVE-2026-89648await—LinuxLinux—ceph: cap delegated inode count in ceph_parse_deleg_inos()
CVE-2026-89649await—LinuxLinux—ceph: bound xattr value length in __build_xattrs()
CVE-2026-89650await—LinuxLinux—ceph: bound num_export_targets array for mds info v2/v3
CVE-2026-89651await—LinuxLinux—ceph: bound MDSCapAuth path and fs_name decode in handle_session()
CVE-2026-89652await—LinuxLinux—ceph: bound copied dentry name length in NFS export get_name
CVE-2026-89653await—LinuxLinux—ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
CVE-2026-89654await—LinuxLinux—ceph: fix UAF in check_new_map() on session freed during unlock
CVE-2026-89655await—LinuxLinux—ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
CVE-2026-89656await—LinuxLinux—libceph: reject buckets with mismatched CRUSH ids
CVE-2026-89657await—LinuxLinux—libceph: validate OSD extent maps before cursor advance
CVE-2026-89658await—LinuxLinux—NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
CVE-2026-89659await—LinuxLinux—NFSD: Prevent client use-after-free during delegation revoke
CVE-2026-89660await—LinuxLinux—NFSD: Prevent client use-after-free during admin state revocation
CVE-2026-89661await—LinuxLinux—NFSD: Prevent post-shutdown use-after-free in unlock_filesystem
CVE-2026-89662await—LinuxLinux—NFSD: Prevent lock owner use-after-free during client teardown
CVE-2026-89663await—LinuxLinux—nfsd: revoke copy-notify stateids before dropping their reference
CVE-2026-89664await—LinuxLinux—nfsd: release OPEN-decoded posix ACLs via op_release
CVE-2026-89665await—LinuxLinux—nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
CVE-2026-89666await—LinuxLinux—nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops
CVE-2026-89667await—LinuxLinux—nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache
CVE-2026-89668await—LinuxLinux—nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()
CVE-2026-89669await—LinuxLinux—nfsd: initialize copy-notify stateid before publishing it
CVE-2026-89670await—LinuxLinux—nfsd: hold rcu across localio cmpxchg retry
CVE-2026-89671await—LinuxLinux—nfsd: gate nfs3 setacl by argp->mask
CVE-2026-89672await—LinuxLinux—nfsd: gate nfs2 setacl by argp->mask
CVE-2026-89673await—LinuxLinux—nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
CVE-2026-89674await—LinuxLinux—nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
CVE-2026-89675await—LinuxLinux—nfsd: fix UAF in async copy cancel and shutdown
CVE-2026-89676await—LinuxLinux—nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
CVE-2026-89677await—LinuxLinux—nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file()
CVE-2026-89678await—LinuxLinux—nfsd: fix partial-write detection in nfsd_direct_write
CVE-2026-89679await—LinuxLinux—nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs
CVE-2026-89680await—LinuxLinux—nfsd: fix nfsd_file leak on inter-server COPY setup failure
CVE-2026-89681await—LinuxLinux—nfsd: fix layout fence worker double-reference race
CVE-2026-89682await—LinuxLinux—nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net
CVE-2026-89683await—LinuxLinux—nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
CVE-2026-89684await—LinuxLinux—nfsd: fix cpntf publish race in nfs4_init_cp_state
CVE-2026-89685await—LinuxLinux—nfsd: fix clock domain mismatch in clients_still_reclaiming()
CVE-2026-89686await—LinuxLinux—nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
CVE-2026-89687await—LinuxLinux—nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file
CVE-2026-89688await—LinuxLinux—nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
CVE-2026-89689await—LinuxLinux—nfsd: don't free session slots that are still in use
CVE-2026-89690await—LinuxLinux—nfsd: defer vfree of compound ops to fix rpc_status UAF
CVE-2026-89691await—LinuxLinux—nfsd: clear opcnt on compound arg release to prevent OOB read
CVE-2026-89692await—LinuxLinux—nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
CVE-2026-89693await—LinuxLinux—nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()
CVE-2026-89694await—LinuxLinux—nfsd: check client ownership when cancelling a copy-notify stateid
CVE-2026-89695await—LinuxLinux—nfsd: cap decoded POSIX ACL count to bound sort cost
CVE-2026-89696await—LinuxLinux—nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
CVE-2026-89697await—LinuxLinux—nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
CVE-2026-89698await—LinuxLinux—nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage
CVE-2026-89699await—LinuxLinux—nfsd: validate symlink target length in NFSv4 CREATE
CVE-2026-89700await—LinuxLinux—nfsd: validate sockaddr length per family in listener_set
CVE-2026-89701await—LinuxLinux—nfsd: validate nseconds in TIME_DELEG decode paths
CVE-2026-89702await—LinuxLinux—nfsd: size fh_verify server sockaddr slot by xpt_locallen
CVE-2026-89703await—LinuxLinux—nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
CVE-2026-89704await—LinuxLinux—nfsd: sample writeback error cursor before async COPY loop
CVE-2026-89705await—LinuxLinux—nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths
CVE-2026-89706await—LinuxLinux—nfsd: Reset write verifier when async COPY writeback fails
CVE-2026-89707await—LinuxLinux—nfsd: release path refs on follow_down() error
CVE-2026-89708await—LinuxLinux—nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown
CVE-2026-89709await—LinuxLinux—lockd, nfsd: RCU-protect nlmsvc_ops dispatch
CVE-2026-89710await—LinuxLinux—NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
CVE-2026-89711await—LinuxLinux—NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
CVE-2026-89712await—LinuxLinux—NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
CVE-2026-89713await—LinuxLinux—NFSD: check truncate permission under inode lock
CVE-2026-89714await—LinuxLinux—NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails
CVE-2026-89715await—LinuxLinux—NFS/localio: fix ref leak on nfs_uuid_add_file failure
CVE-2026-89716await—LinuxLinux—zram: validate deflate params
CVE-2026-89717await—LinuxLinux—zram: set default primary compressor in zram_destroy_comps()
CVE-2026-89718await—LinuxLinux—zram: fix out-of-bounds access in writeback_store()
CVE-2026-89719await—LinuxLinux—zram: fix out-of-bounds access in read_block_state()
CVE-2026-89720await—LinuxLinux—ubifs: fix out-of-bounds read in signature length check
CVE-2026-89721await—LinuxLinux—phy: rockchip-samsung-dcphy: fix out-of-range max_register
CVE-2026-89722await—LinuxLinux—PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()
CVE-2026-89723await—LinuxLinux—nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
CVE-2026-89724await—LinuxLinux—media: vicodec: fix out-of-bounds write in FWHT encoder
CVE-2026-89725await—LinuxLinux—media: cec: stm32: prevent out-of-bounds write on RX overflow
CVE-2026-89726await—LinuxLinux—lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
CVE-2026-89727await—LinuxLinux—KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID
CVE-2026-89728await—LinuxLinux—i3c: renesas: Fix out-of-bounds access for newdevs mask
CVE-2026-89729await—LinuxLinux—HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
CVE-2026-89730await—LinuxLinux—fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
CVE-2026-89731await—LinuxLinux—cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
CVE-2026-89732await—LinuxLinux—usb: gadget: f_fs: Prevent deadlock during ep0 read loop
CVE-2026-89733await—LinuxLinux—usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_functi…
CVE-2026-89734await—LinuxLinux—usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()
CVE-2026-89735await—LinuxLinux—usb: gadget: midi2: remove default configfs groups on teardown
CVE-2026-89736await—LinuxLinux—usb: gadget: u_audio: Fix use-after-free on sound card disconnect
CVE-2026-89737await—LinuxLinux—usb: typec: thunderbolt: Disable work before freeing tbt on remove
CVE-2026-89738await—LinuxLinux—usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
CVE-2026-89739await—LinuxLinux—usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to ra…
CVE-2026-89740await—LinuxLinux—serial: imx: serialize imx_uart_ports[] lifetime
CVE-2026-89741await—LinuxLinux—Revert "media: v4l2-dev: fix error handling in __video_register_device()"
CVE-2026-89742await—LinuxLinux—rapidio: mport_cdev: fix use-after-free in dma_req_free()
CVE-2026-89743await—LinuxLinux—misc: nsm: bound the device-reported response length
CVE-2026-89744await—LinuxLinux—device property: fix infinite loop in fwnode_for_each_child_node()
CVE-2026-89745await—LinuxLinux—debugfs: Fix lockdown check for mmap_prepare
CVE-2026-89746await—LinuxLinux—tracing: Fix use-after-free with same-name named triggers
CVE-2026-89747await—LinuxLinux—tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
CVE-2026-89748await—LinuxLinux—tracing: Fix retry exhaustion in simple ring buffer reader swap
CVE-2026-89749await—LinuxLinux—tracing: Fix crash passing ERR_PTR to kthread_stop()
CVE-2026-89750await—LinuxLinux—tracing/user_events: Clear copied tracing state before fork duplication
CVE-2026-89751await—LinuxLinux—x86/tdx: Fix off-by-one in port I/O handling
CVE-2026-89752await—LinuxLinux—mm: memcg: stop reclaim when a limit update is superseded
CVE-2026-89753await—LinuxLinux—mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
CVE-2026-89754await—LinuxLinux—mm/pagewalk: fix stale walk->action escaping walk_pmd_range()
CVE-2026-89755await—LinuxLinux—mm/migrate_device: clear stale mapping after freeing swapcache
CVE-2026-89756await—LinuxLinux—mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
CVE-2026-89757await—LinuxLinux—mm/mglru: fix and remove redundant unevictable folio handling
CVE-2026-89758await—LinuxLinux—mm/mempolicy: skip non-present PMDs when queueing folios
CVE-2026-89759await—LinuxLinux—mm/kmemleak: avoid soft lockup when scanning task stacks
CVE-2026-89760await—LinuxLinux—mm, swap: don't free a hibernation slot that is in the swap cache
CVE-2026-89761await—LinuxLinux—apparmor: fix out-of-bounds write when null terminating a label vec
CVE-2026-89762await—LinuxLinux—apparmor: fix cred UAF caused by begin_current_label_crit_section()
CVE-2026-89763await—LinuxLinux—KEYS: trusted: Fix TPM teardown ordering
CVE-2026-89764await—LinuxLinux—rust: devres: fix race between concurrent revokers
CVE-2026-89765await—LinuxLinux—timers/itimer: Zero-init old itimerval before copy to userspace
CVE-2026-89766await—LinuxLinux—pidfd: hold exec_update_lock around namespace ioctl
CVE-2026-89767await—LinuxLinux—ovl: fix double end_creating() on the casefold-mismatch path
CVE-2026-89768await—LinuxLinux—fs: fix user path of nested backing files
CVE-2026-89769await—LinuxLinux—clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path
CVE-2026-89770await—LinuxLinux—iomap: don't free integrity payload that doesn't exist
CVE-2026-89771await—LinuxLinux—ring-buffer: Fix subbuf resize race with ring buffer readers
CVE-2026-89772await—LinuxLinux—btrfs: write-protect folios during data writeback
CVE-2026-89773await—LinuxLinux—drm/amd/display: Skip Update HDCP Config In Transition State