Security Box Score — September 11, 2026 — page 2
Edition of September 11, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-89471 | await | — | Linux | Linux | — | power: supply: cros_usbpd-charger: bound the EC-reported port count |
| CVE-2026-89472 | await | — | Linux | Linux | — | power: supply: charger-manager: register regulators before exposing sysfs |
| CVE-2026-89473 | await | — | Linux | Linux | — | power: supply: bq25890: Fix power_supply reference leak |
| CVE-2026-89474 | await | — | Linux | Linux | — | power: supply: bq256xx: drain usb_work before freeing the charger |
| CVE-2026-89475 | await | — | Linux | Linux | — | power: supply: bq24257: fix use-after-free on remove |
| CVE-2026-89476 | await | — | Linux | Linux | — | sctp: fix stream->outcnt underflow on duplicate RECONF responses |
| CVE-2026-89477 | await | — | Linux | Linux | — | sctp: fix NULL deref on untransmitted RECONF completion |
| CVE-2026-89478 | await | — | Linux | Linux | — | sctp: drop a chunk if its transport was removed |
| CVE-2026-89479 | await | — | Linux | Linux | — | sctp: stop processing a packet once its association is deleted |
| CVE-2026-89480 | await | — | Linux | Linux | — | nvme-tcp: reject a read that transferred too few bytes |
| CVE-2026-89481 | await | — | Linux | Linux | — | nvme-tcp: fix host memory disclosure on R2T for a read command |
| CVE-2026-89482 | await | — | Linux | Linux | — | nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone |
| CVE-2026-89483 | await | — | Linux | Linux | — | nvme: zero the discard fallback page |
| CVE-2026-89484 | await | — | Linux | Linux | — | lockd: fix NULL dereference on lockowner allocation failure |
| CVE-2026-89485 | await | — | Linux | Linux | — | lockd: pin next file across nlm_inspect_file lock-drop |
| CVE-2026-89486 | await | — | Linux | Linux | — | ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() |
| CVE-2026-89487 | await | — | Linux | Linux | — | openvswitch: only skb_tx_error() a packet we are about to drop |
| CVE-2026-89488 | await | — | Linux | Linux | — | openvswitch: Fix CT limit teardown use-after-free |
| CVE-2026-89489 | await | — | Linux | Linux | — | openrisc: fix arbitrary kernel memory access via or1k_atomic syscall |
| CVE-2026-89490 | await | — | Linux | Linux | — | ocfs2: fix readdir position truncation on 32-bit kernels |
| CVE-2026-89491 | await | — | Linux | Linux | — | ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() |
| CVE-2026-89492 | await | — | Linux | Linux | — | ocfs2: validate directory-index entry counts when reading metadata |
| CVE-2026-89493 | await | — | Linux | Linux | — | ocfs2: validate rl_used against rl_count in refcount block validator |
| CVE-2026-89494 | await | — | Linux | Linux | — | ocfs2: validate lengths in dlm_mig_lockres_handler |
| CVE-2026-89495 | await | — | Linux | Linux | — | ocfs2: bound namelen in dlm_migrate_request_handler |
| CVE-2026-89496 | await | — | Linux | Linux | — | ocfs2: always run deallocs on copy-on-write completion |
| CVE-2026-89497 | await | — | Linux | Linux | — | orangefs: skip leading spaces before parsing client debug masks |
| CVE-2026-89498 | await | — | Linux | Linux | — | orangefs: fix double-free of trailer_buf on readdir copy failure |
| CVE-2026-89499 | await | — | Linux | Linux | — | ring-buffer: Stop remote reader update when page swap fails |
| CVE-2026-89500 | await | — | Linux | Linux | — | ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page |
| CVE-2026-89501 | await | — | Linux | Linux | — | ring-buffer: Hold cpu_buffer::lock when resizing a subbuf |
| CVE-2026-89502 | await | — | Linux | Linux | — | ring-buffer: Free cpu_buffer::free_page with subbuf_order |
| CVE-2026-89503 | await | — | Linux | Linux | — | ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() |
| CVE-2026-89504 | await | — | Linux | Linux | — | regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving da… |
| CVE-2026-89505 | await | — | Linux | Linux | — | RDMA/uverbs: Guard legacy bundles without method_elm |
| CVE-2026-89506 | await | — | Linux | Linux | — | RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR |
| CVE-2026-89507 | await | — | Linux | Linux | — | RDMA/ucma: Lock the handler in ucma_write_cm_event() |
| CVE-2026-89508 | await | — | Linux | Linux | — | RDMA/ucma: Lock the handler in ucma_set_ib_path() |
| CVE-2026-89509 | await | — | Linux | Linux | — | RDMA/ionic: Embed counter driver data in rdma_counter allocation |
| CVE-2026-89510 | await | — | Linux | Linux | — | RDMA/cxgb4: Cancel reg_work before freeing device on remove |
| CVE-2026-89511 | await | — | Linux | Linux | — | qede: Fix NULL pointer dereference in TPA fragment processing |
| CVE-2026-89512 | await | — | Linux | Linux | — | remoteproc: scp: Fix device reference leak on failed lookup |
| CVE-2026-89513 | await | — | Linux | Linux | — | RISC-V: KVM: Fix PMU event info array size overflow |
| CVE-2026-89514 | await | — | Linux | Linux | — | scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock |
| CVE-2026-89515 | await | — | Linux | Linux | — | scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() |
| CVE-2026-89516 | await | — | Linux | Linux | — | sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users |
| CVE-2026-89517 | await | — | Linux | Linux | — | sched_ext: Fix rq->core_pick corruption under core scheduling |
| CVE-2026-89518 | await | — | Linux | Linux | — | sched_ext: Fix this_rq() assumptions in dispatch kfuncs |
| CVE-2026-89519 | await | — | Linux | Linux | — | sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return |
| CVE-2026-89520 | await | — | Linux | Linux | — | sched/core: Make core-sched flips wait for in-flight selections |
| CVE-2026-89521 | await | — | Linux | Linux | — | sched/core: Handle pick_task() releasing the rq lock |
| CVE-2026-89522 | await | — | Linux | Linux | — | media: staging/ipu7: fix async notifier UAF on probe error path |
| CVE-2026-89523 | await | — | Linux | Linux | — | wifi: mt76: mt7925: cancel pending mlo_pm_work |
| CVE-2026-89524 | await | — | Linux | Linux | — | wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets |
| CVE-2026-89525 | await | — | Linux | Linux | — | udf: reject VAT indexes equal to the entry count |
| CVE-2026-89526 | await | — | Linux | Linux | — | svcrdma: Validate Read chunk positions before reconstruction |
| CVE-2026-89527 | await | — | Linux | Linux | — | svcrdma: Use svc_xprt_put to free listener on create failure |
| CVE-2026-89528 | await | — | Linux | Linux | — | svcrdma: Reject Read lists that exceed the page budget |
| CVE-2026-89529 | await | — | Linux | Linux | — | svcrdma: Reject oversized Read segments at decode time |
| CVE-2026-89530 | await | — | Linux | Linux | — | svcrdma: Reject inline replies that overflow the pull-up buffer |
| CVE-2026-89531 | await | — | Linux | Linux | — | svcrdma: Reject connection when transport allocation fails |
| CVE-2026-89532 | await | — | Linux | Linux | — | svcrdma: Fix pcl_for_each_segment for empty chunks |
| CVE-2026-89533 | await | — | Linux | Linux | — | svcrdma: Fix offset arithmetic in read_chunk_range |
| CVE-2026-89534 | await | — | Linux | Linux | — | svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails |
| CVE-2026-89535 | await | — | Linux | Linux | — | svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id |
| CVE-2026-89536 | await | — | Linux | Linux | — | SUNRPC: wait for in-flight client TLS handshake callback |
| CVE-2026-89537 | await | — | Linux | Linux | — | SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 |
| CVE-2026-89538 | await | — | Linux | Linux | — | SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field |
| CVE-2026-89539 | await | — | Linux | Linux | — | SUNRPC: reject duplicate CREDS_VALUE options |
| CVE-2026-89540 | await | — | Linux | Linux | — | sunrpc: init gssp_lock before publishing proc entry |
| CVE-2026-89541 | await | — | Linux | Linux | — | SUNRPC: harden gss_unwrap_resp_priv length checks |
| CVE-2026-89542 | await | — | Linux | Linux | — | SUNRPC: harden gss_krb5_unwrap_v2 against short tokens |
| CVE-2026-89543 | await | — | Linux | Linux | — | sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_p… |
| CVE-2026-89544 | await | — | Linux | Linux | — | SUNRPC: fix gssx_dec_option_array error path bugs |
| CVE-2026-89545 | await | — | Linux | Linux | — | sunrpc: defer rq_argp and rq_resp free until after RCU grace period |
| CVE-2026-89546 | await | — | Linux | Linux | — | SUNRPC: close backchannel before destroying callback service |
| CVE-2026-89547 | await | — | Linux | Linux | — | SUNRPC: Check svc pool percpu counter allocation |
| CVE-2026-89548 | await | — | Linux | Linux | — | SUNRPC: always drain cache_cleaner before destroying a cache_detail |
| CVE-2026-89549 | await | — | Linux | Linux | — | sunrpc: route to a populated pool in svc_pool_for_cpu() |
| CVE-2026-89550 | await | — | Linux | Linux | — | SUNRPC: svcauth_gss: enforce krb5 token minimum length |
| CVE-2026-89551 | await | — | Linux | Linux | — | SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow |
| CVE-2026-89552 | await | — | Linux | Linux | — | params: fix charp corruption on allocation failure |
| CVE-2026-89553 | await | — | Linux | Linux | — | nouveau/gem: reserve the bo in the info ioctl around the vma lookup |
| CVE-2026-89554 | await | — | Linux | Linux | — | mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction |
| CVE-2026-89555 | await | — | Linux | Linux | — | mpls: reload header after pskb_may_pull() |
| CVE-2026-89556 | await | — | Linux | Linux | — | module: validate string table section types |
| CVE-2026-89557 | await | — | Linux | Linux | — | md: do overflow check for sb->bblog_shift in super_1_load() |
| CVE-2026-89558 | await | — | Linux | Linux | — | md/raid10: fix still_degraded being inverted in raid10_sync_request() |
| CVE-2026-89559 | await | — | Linux | Linux | — | libnvdimm/labels: Prevent integer overflow in __nd_label_validate() |
| CVE-2026-89560 | await | — | Linux | Linux | — | landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation |
| CVE-2026-89561 | await | — | Linux | Linux | — | ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() |
| CVE-2026-89562 | await | — | Linux | Linux | — | ip6_gre: fix hardware header length for NBMA tunnels |
| CVE-2026-89563 | await | — | Linux | Linux | — | ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() |
| CVE-2026-89564 | await | — | Linux | Linux | — | ip: orphan prefetched skbs before multicast forwarding |
| CVE-2026-89565 | await | — | Linux | Linux | — | ipip: fix skb leak in collect_md mode when metadata_dst allocation fails |
| CVE-2026-89566 | await | — | Linux | Linux | — | jbd2: check need_resched() when skipping busy checkpoint buffers |
| CVE-2026-89567 | await | — | Linux | Linux | — | jbd2: bound shrinker scans by examined checkpoint buffers |
| CVE-2026-89568 | await | — | Linux | Linux | — | kho: fix size calculation in kho_preserved_memory_reserve() |
| CVE-2026-89569 | await | — | Linux | Linux | — | Bluetooth: RFCOMM: serialize security confirmation handling |
| CVE-2026-89570 | await | — | Linux | Linux | — | cxl/mce: Make the MCE notifier per-region |
| CVE-2026-89571 | await | — | Linux | Linux | — | cxl/features: bound fwctl command payload to the input buffer |
| CVE-2026-89572 | await | — | Linux | Linux | — | cpufreq: apple-soc: Fix OPP table cleanup |
| CVE-2026-89573 | await | — | Linux | Linux | — | dm array: reject an array block whose value size is not the caller's |
| CVE-2026-89574 | await | — | Linux | Linux | — | dm array: validate array block headers on read |
| CVE-2026-89575 | await | — | Linux | Linux | — | dm raid1: reserve space for NUL-terminator in build_constructor_string() |
| CVE-2026-89576 | await | — | Linux | Linux | — | dm-era: fix shadowed superblock leak on take-snap failure |
| CVE-2026-89577 | await | — | Linux | Linux | — | dm-io: report non-retryable errors separatedly |
| CVE-2026-89578 | await | — | Linux | Linux | — | dm-io: clone the source bio instead of copying its biovec |
| CVE-2026-89579 | await | — | Linux | Linux | — | bpf: Harden bloom filter sizing and indexing on 32-bit kernels |
| CVE-2026-89580 | await | — | Linux | Linux | — | bpf: Disable preemption in __bpf_get_stack |
| CVE-2026-89581 | await | — | Linux | Linux | — | bpf, x86: Fix per-CPU address resolution into an extended register |
| CVE-2026-89582 | await | — | Linux | Linux | — | bnx2x: fix double free in bnx2x_init_firmware() error path |
| CVE-2026-89583 | await | — | Linux | Linux | — | Bluetooth: eir: Fix OOB read in eir_get_service_data() |
| CVE-2026-89584 | await | — | Linux | Linux | — | block: validate user space vectors during extraction |
| CVE-2026-89585 | await | — | Linux | Linux | — | auxdisplay: charlcd: cancel backlight work on registration failure |
| CVE-2026-89586 | await | — | Linux | Linux | — | ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes |
| CVE-2026-89587 | await | — | Linux | Linux | — | ACPI: pfr_update: fix stack buffer overflow in query_capability() |
| CVE-2026-89588 | await | — | Linux | Linux | — | ACPI: APEI: GHES: fix ARM section length accounting after header |
| CVE-2026-89589 | await | — | Linux | Linux | — | acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks |
| CVE-2026-89590 | await | — | Linux | Linux | — | accel/rocket: Fix error path handling in rocket_job_run() |
| CVE-2026-89591 | await | — | Linux | Linux | — | accel/rocket: initialize job domain before cleanup paths |
| CVE-2026-89592 | await | — | Linux | Linux | — | accel/rocket: fix NULL dereference and integer overflow in rocket_job_push() |
| CVE-2026-89593 | await | — | Linux | Linux | — | hugetlb: only adjust reservation during unmapping if mapcount is 0 |
| CVE-2026-89594 | await | — | Linux | Linux | — | hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device |
| CVE-2026-89595 | await | — | Linux | Linux | — | fsnotify: Fix stale object mask after concurrent mark updates |
| CVE-2026-89596 | await | — | Linux | Linux | — | forcedeth: fix off-by-one when saving/restoring non-PCI config space |
| CVE-2026-89597 | await | — | Linux | Linux | — | fbdev: uvesafb: unregister connector callback on init failure |
| CVE-2026-89598 | await | — | Linux | Linux | — | fbdev: ssd1307fb: defer I2C transfers from damage callbacks |
| CVE-2026-89599 | await | — | Linux | Linux | — | fbdev: omapfb: panel-dsi-cm: initialize lock before registering display |
| CVE-2026-89600 | await | — | Linux | Linux | — | fanotify: fix use-after-free of file range info |
| CVE-2026-89601 | await | — | Linux | Linux | — | ext2: Fix lost inode updates for IS_SYNC inodes |
| CVE-2026-89602 | await | — | Linux | Linux | — | erofs: skip sufficiently large global buffers when resizing |
| CVE-2026-89603 | await | — | Linux | Linux | — | entry: Fix seccomp bypass after ptrace with TSYNC |
| CVE-2026-89604 | await | — | Linux | Linux | — | efivarfs: Rate limit statfs() handler |
| CVE-2026-89605 | await | — | Linux | Linux | — | ecryptfs: release message context on send failure |
| CVE-2026-89606 | await | — | Linux | Linux | — | ecryptfs: reject too-small tag 70 packets |
| CVE-2026-89607 | await | — | Linux | Linux | — | ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet |
| CVE-2026-89608 | await | — | Linux | Linux | — | ecryptfs: pass packet set buffer size to parser |
| CVE-2026-89609 | await | — | Linux | Linux | — | ecryptfs: hold msg ctx list lock when cleaning daemon queue |
| CVE-2026-89610 | await | — | Linux | Linux | — | ntfs: verify run length exceeding volume boundary |
| CVE-2026-89611 | await | — | Linux | Linux | — | ntfs: validate non-resident attribute offsets |
| CVE-2026-89612 | await | — | Linux | Linux | — | ntfs: reject invalid MFT LCNs from boot sector |
| CVE-2026-89613 | await | — | Linux | Linux | — | ntfs: reject invalid empty mapping pairs |
| CVE-2026-89614 | await | — | Linux | Linux | — | ntfs: bound the free-cluster bitmap scan to the volume |
| CVE-2026-89615 | await | — | Linux | Linux | — | fs/ntfs3: bound page_lcns[] index by the log record |
| CVE-2026-89616 | await | — | Linux | Linux | — | fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() |
| CVE-2026-89617 | await | — | Linux | Linux | — | fs/ntfs3: validate dirty page table on log replay |
| CVE-2026-89618 | await | — | Linux | Linux | — | eventfs: Initialize ei->children and ei->list in init_ei() |
| CVE-2026-89619 | await | — | Linux | Linux | — | HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller b… |
| CVE-2026-89620 | await | — | Linux | Linux | — | HID: intel-thc-hid: intel-quickspi: validate report size before copy |
| CVE-2026-89621 | await | — | Linux | Linux | — | HID: mcp2221: validate report size in mcp2221_raw_event() |
| CVE-2026-89622 | await | — | Linux | Linux | — | HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes |
| CVE-2026-89623 | await | — | Linux | Linux | — | HID: mcp2221: stop device IO before hid_hw_stop |
| CVE-2026-89624 | await | — | Linux | Linux | — | HID: universal-pidff: stop the device when force-feedback init fails |
| CVE-2026-89625 | await | — | Linux | Linux | — | HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind |
| CVE-2026-89626 | await | — | Linux | Linux | — | HID: sensor: custom: Fix field sysfs group cleanup on failure |
| CVE-2026-89627 | await | — | Linux | Linux | — | HID: roccat: free buffered reports when destroying device |
| CVE-2026-89628 | await | — | Linux | Linux | — | HID: picolcd: clamp eeprom debugfs read to bytes actually received |
| CVE-2026-89629 | await | — | Linux | Linux | — | HID: corsair-void: Check size of status and firmware events before reading them |
| CVE-2026-89630 | await | — | Linux | Linux | — | smb: client: restore the data_offset bound in is_valid_oplock_break() |
| CVE-2026-89631 | await | — | Linux | Linux | — | smb: client: reject a tree connect response whose byte count is too small |
| CVE-2026-89632 | await | — | Linux | Linux | — | smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr() |
| CVE-2026-89633 | await | — | Linux | Linux | — | smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() |
| CVE-2026-89634 | await | — | Linux | Linux | — | smb: client: fix ALIGN() overflow in symlink_data() error context loop |
| CVE-2026-89635 | await | — | Linux | Linux | — | ksmbd: only rebind the reopened file's own oplock on durable reconnect |
| CVE-2026-89636 | await | — | Linux | Linux | — | smb: client: clear ce->tgthint in free_tgts() |
| CVE-2026-89637 | await | — | Linux | Linux | — | smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed sec… |
| CVE-2026-89638 | await | — | Linux | Linux | — | smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix … |
| CVE-2026-89639 | await | — | Linux | Linux | — | cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC |
| CVE-2026-89640 | await | — | Linux | Linux | — | cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 |
| CVE-2026-89641 | await | — | Linux | Linux | — | cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size() |
| CVE-2026-89642 | await | — | Linux | Linux | — | cifs: call pagecache_isize_extended() in cifs_setsize() when extending |
| CVE-2026-89643 | await | — | Linux | Linux | — | audit: avoid dropping live tree ref on fsnotify rule autoremove |
| CVE-2026-89644 | await | — | Linux | Linux | — | btrfs: fix extent map leak in NOCOW direct I/O write |
| CVE-2026-89645 | await | — | Linux | Linux | — | btrfs: drop recovered reloc root refs on recovery failure |
| CVE-2026-89646 | await | — | Linux | Linux | — | ceph: fix leaked inode reference on writeback abort at umount |
| CVE-2026-89647 | await | — | Linux | Linux | — | ceph: do not repeat ceph_trim_dentries() if no progress possible |
| CVE-2026-89648 | await | — | Linux | Linux | — | ceph: cap delegated inode count in ceph_parse_deleg_inos() |
| CVE-2026-89649 | await | — | Linux | Linux | — | ceph: bound xattr value length in __build_xattrs() |
| CVE-2026-89650 | await | — | Linux | Linux | — | ceph: bound num_export_targets array for mds info v2/v3 |
| CVE-2026-89651 | await | — | Linux | Linux | — | ceph: bound MDSCapAuth path and fs_name decode in handle_session() |
| CVE-2026-89652 | await | — | Linux | Linux | — | ceph: bound copied dentry name length in NFS export get_name |
| CVE-2026-89653 | await | — | Linux | Linux | — | ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode |
| CVE-2026-89654 | await | — | Linux | Linux | — | ceph: fix UAF in check_new_map() on session freed during unlock |
| CVE-2026-89655 | await | — | Linux | Linux | — | ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock |
| CVE-2026-89656 | await | — | Linux | Linux | — | libceph: reject buckets with mismatched CRUSH ids |
| CVE-2026-89657 | await | — | Linux | Linux | — | libceph: validate OSD extent maps before cursor advance |
| CVE-2026-89658 | await | — | Linux | Linux | — | NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup |
| CVE-2026-89659 | await | — | Linux | Linux | — | NFSD: Prevent client use-after-free during delegation revoke |
| CVE-2026-89660 | await | — | Linux | Linux | — | NFSD: Prevent client use-after-free during admin state revocation |
| CVE-2026-89661 | await | — | Linux | Linux | — | NFSD: Prevent post-shutdown use-after-free in unlock_filesystem |
| CVE-2026-89662 | await | — | Linux | Linux | — | NFSD: Prevent lock owner use-after-free during client teardown |
| CVE-2026-89663 | await | — | Linux | Linux | — | nfsd: revoke copy-notify stateids before dropping their reference |
| CVE-2026-89664 | await | — | Linux | Linux | — | nfsd: release OPEN-decoded posix ACLs via op_release |
| CVE-2026-89665 | await | — | Linux | Linux | — | nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE |
| CVE-2026-89666 | await | — | Linux | Linux | — | nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops |
| CVE-2026-89667 | await | — | Linux | Linux | — | nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache |
| CVE-2026-89668 | await | — | Linux | Linux | — | nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd() |
| CVE-2026-89669 | await | — | Linux | Linux | — | nfsd: initialize copy-notify stateid before publishing it |
| CVE-2026-89670 | await | — | Linux | Linux | — | nfsd: hold rcu across localio cmpxchg retry |
| CVE-2026-89671 | await | — | Linux | Linux | — | nfsd: gate nfs3 setacl by argp->mask |
| CVE-2026-89672 | await | — | Linux | Linux | — | nfsd: gate nfs2 setacl by argp->mask |
| CVE-2026-89673 | await | — | Linux | Linux | — | nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo |
| CVE-2026-89674 | await | — | Linux | Linux | — | nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget |
| CVE-2026-89675 | await | — | Linux | Linux | — | nfsd: fix UAF in async copy cancel and shutdown |
| CVE-2026-89676 | await | — | Linux | Linux | — | nfsd: fix stale s2s_cp_stateids IDR entry for async COPY |
| CVE-2026-89677 | await | — | Linux | Linux | — | nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() |
| CVE-2026-89678 | await | — | Linux | Linux | — | nfsd: fix partial-write detection in nfsd_direct_write |
| CVE-2026-89679 | await | — | Linux | Linux | — | nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs |
| CVE-2026-89680 | await | — | Linux | Linux | — | nfsd: fix nfsd_file leak on inter-server COPY setup failure |
| CVE-2026-89681 | await | — | Linux | Linux | — | nfsd: fix layout fence worker double-reference race |
| CVE-2026-89682 | await | — | Linux | Linux | — | nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net |
| CVE-2026-89683 | await | — | Linux | Linux | — | nfsd: fix dentry ref leak on V4ROOT export filehandle lookup |
| CVE-2026-89684 | await | — | Linux | Linux | — | nfsd: fix cpntf publish race in nfs4_init_cp_state |
| CVE-2026-89685 | await | — | Linux | Linux | — | nfsd: fix clock domain mismatch in clients_still_reclaiming() |
| CVE-2026-89686 | await | — | Linux | Linux | — | nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke |
| CVE-2026-89687 | await | — | Linux | Linux | — | nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file |
| CVE-2026-89688 | await | — | Linux | Linux | — | nfsd: drop the stateid, not the stateowner, on seqid_op replay retry |
| CVE-2026-89689 | await | — | Linux | Linux | — | nfsd: don't free session slots that are still in use |
| CVE-2026-89690 | await | — | Linux | Linux | — | nfsd: defer vfree of compound ops to fix rpc_status UAF |
| CVE-2026-89691 | await | — | Linux | Linux | — | nfsd: clear opcnt on compound arg release to prevent OOB read |
| CVE-2026-89692 | await | — | Linux | Linux | — | nfsd: clear CALLBACK_RUNNING on failed delegation recall queue |
| CVE-2026-89693 | await | — | Linux | Linux | — | nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() |
| CVE-2026-89694 | await | — | Linux | Linux | — | nfsd: check client ownership when cancelling a copy-notify stateid |
| CVE-2026-89695 | await | — | Linux | Linux | — | nfsd: cap decoded POSIX ACL count to bound sort cost |
| CVE-2026-89696 | await | — | Linux | Linux | — | nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref |
| CVE-2026-89697 | await | — | Linux | Linux | — | nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() |
| CVE-2026-89698 | await | — | Linux | Linux | — | nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage |
| CVE-2026-89699 | await | — | Linux | Linux | — | nfsd: validate symlink target length in NFSv4 CREATE |
| CVE-2026-89700 | await | — | Linux | Linux | — | nfsd: validate sockaddr length per family in listener_set |
| CVE-2026-89701 | await | — | Linux | Linux | — | nfsd: validate nseconds in TIME_DELEG decode paths |
| CVE-2026-89702 | await | — | Linux | Linux | — | nfsd: size fh_verify server sockaddr slot by xpt_locallen |
| CVE-2026-89703 | await | — | Linux | Linux | — | nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations |
| CVE-2026-89704 | await | — | Linux | Linux | — | nfsd: sample writeback error cursor before async COPY loop |
| CVE-2026-89705 | await | — | Linux | Linux | — | nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths |
| CVE-2026-89706 | await | — | Linux | Linux | — | nfsd: Reset write verifier when async COPY writeback fails |
| CVE-2026-89707 | await | — | Linux | Linux | — | nfsd: release path refs on follow_down() error |
| CVE-2026-89708 | await | — | Linux | Linux | — | nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown |
| CVE-2026-89709 | await | — | Linux | Linux | — | lockd, nfsd: RCU-protect nlmsvc_ops dispatch |
| CVE-2026-89710 | await | — | Linux | Linux | — | NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path |
| CVE-2026-89711 | await | — | Linux | Linux | — | NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check |
| CVE-2026-89712 | await | — | Linux | Linux | — | NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock |
| CVE-2026-89713 | await | — | Linux | Linux | — | NFSD: check truncate permission under inode lock |
| CVE-2026-89714 | await | — | Linux | Linux | — | NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails |
| CVE-2026-89715 | await | — | Linux | Linux | — | NFS/localio: fix ref leak on nfs_uuid_add_file failure |
| CVE-2026-89716 | await | — | Linux | Linux | — | zram: validate deflate params |
| CVE-2026-89717 | await | — | Linux | Linux | — | zram: set default primary compressor in zram_destroy_comps() |
| CVE-2026-89718 | await | — | Linux | Linux | — | zram: fix out-of-bounds access in writeback_store() |
| CVE-2026-89719 | await | — | Linux | Linux | — | zram: fix out-of-bounds access in read_block_state() |
| CVE-2026-89720 | await | — | Linux | Linux | — | ubifs: fix out-of-bounds read in signature length check |
| CVE-2026-89721 | await | — | Linux | Linux | — | phy: rockchip-samsung-dcphy: fix out-of-range max_register |
| CVE-2026-89722 | await | — | Linux | Linux | — | PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() |
| CVE-2026-89723 | await | — | Linux | Linux | — | nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation |
| CVE-2026-89724 | await | — | Linux | Linux | — | media: vicodec: fix out-of-bounds write in FWHT encoder |
| CVE-2026-89725 | await | — | Linux | Linux | — | media: cec: stm32: prevent out-of-bounds write on RX overflow |
| CVE-2026-89726 | await | — | Linux | Linux | — | lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() |
| CVE-2026-89727 | await | — | Linux | Linux | — | KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID |
| CVE-2026-89728 | await | — | Linux | Linux | — | i3c: renesas: Fix out-of-bounds access for newdevs mask |
| CVE-2026-89729 | await | — | Linux | Linux | — | HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature |
| CVE-2026-89730 | await | — | Linux | Linux | — | fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write |
| CVE-2026-89731 | await | — | Linux | Linux | — | cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read |
| CVE-2026-89732 | await | — | Linux | Linux | — | usb: gadget: f_fs: Prevent deadlock during ep0 read loop |
| CVE-2026-89733 | await | — | Linux | Linux | — | usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_functi… |
| CVE-2026-89734 | await | — | Linux | Linux | — | usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init() |
| CVE-2026-89735 | await | — | Linux | Linux | — | usb: gadget: midi2: remove default configfs groups on teardown |
| CVE-2026-89736 | await | — | Linux | Linux | — | usb: gadget: u_audio: Fix use-after-free on sound card disconnect |
| CVE-2026-89737 | await | — | Linux | Linux | — | usb: typec: thunderbolt: Disable work before freeing tbt on remove |
| CVE-2026-89738 | await | — | Linux | Linux | — | usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed |
| CVE-2026-89739 | await | — | Linux | Linux | — | usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to ra… |
| CVE-2026-89740 | await | — | Linux | Linux | — | serial: imx: serialize imx_uart_ports[] lifetime |
| CVE-2026-89741 | await | — | Linux | Linux | — | Revert "media: v4l2-dev: fix error handling in __video_register_device()" |
| CVE-2026-89742 | await | — | Linux | Linux | — | rapidio: mport_cdev: fix use-after-free in dma_req_free() |
| CVE-2026-89743 | await | — | Linux | Linux | — | misc: nsm: bound the device-reported response length |
| CVE-2026-89744 | await | — | Linux | Linux | — | device property: fix infinite loop in fwnode_for_each_child_node() |
| CVE-2026-89745 | await | — | Linux | Linux | — | debugfs: Fix lockdown check for mmap_prepare |
| CVE-2026-89746 | await | — | Linux | Linux | — | tracing: Fix use-after-free with same-name named triggers |
| CVE-2026-89747 | await | — | Linux | Linux | — | tracing: Fix use-after-free in trace_pipe read on sub-buffer order change |
| CVE-2026-89748 | await | — | Linux | Linux | — | tracing: Fix retry exhaustion in simple ring buffer reader swap |
| CVE-2026-89749 | await | — | Linux | Linux | — | tracing: Fix crash passing ERR_PTR to kthread_stop() |
| CVE-2026-89750 | await | — | Linux | Linux | — | tracing/user_events: Clear copied tracing state before fork duplication |
| CVE-2026-89751 | await | — | Linux | Linux | — | x86/tdx: Fix off-by-one in port I/O handling |
| CVE-2026-89752 | await | — | Linux | Linux | — | mm: memcg: stop reclaim when a limit update is superseded |
| CVE-2026-89753 | await | — | Linux | Linux | — | mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() |
| CVE-2026-89754 | await | — | Linux | Linux | — | mm/pagewalk: fix stale walk->action escaping walk_pmd_range() |
| CVE-2026-89755 | await | — | Linux | Linux | — | mm/migrate_device: clear stale mapping after freeing swapcache |
| CVE-2026-89756 | await | — | Linux | Linux | — | mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() |
| CVE-2026-89757 | await | — | Linux | Linux | — | mm/mglru: fix and remove redundant unevictable folio handling |
| CVE-2026-89758 | await | — | Linux | Linux | — | mm/mempolicy: skip non-present PMDs when queueing folios |
| CVE-2026-89759 | await | — | Linux | Linux | — | mm/kmemleak: avoid soft lockup when scanning task stacks |
| CVE-2026-89760 | await | — | Linux | Linux | — | mm, swap: don't free a hibernation slot that is in the swap cache |
| CVE-2026-89761 | await | — | Linux | Linux | — | apparmor: fix out-of-bounds write when null terminating a label vec |
| CVE-2026-89762 | await | — | Linux | Linux | — | apparmor: fix cred UAF caused by begin_current_label_crit_section() |
| CVE-2026-89763 | await | — | Linux | Linux | — | KEYS: trusted: Fix TPM teardown ordering |
| CVE-2026-89764 | await | — | Linux | Linux | — | rust: devres: fix race between concurrent revokers |
| CVE-2026-89765 | await | — | Linux | Linux | — | timers/itimer: Zero-init old itimerval before copy to userspace |
| CVE-2026-89766 | await | — | Linux | Linux | — | pidfd: hold exec_update_lock around namespace ioctl |
| CVE-2026-89767 | await | — | Linux | Linux | — | ovl: fix double end_creating() on the casefold-mismatch path |
| CVE-2026-89768 | await | — | Linux | Linux | — | fs: fix user path of nested backing files |
| CVE-2026-89769 | await | — | Linux | Linux | — | clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path |
| CVE-2026-89770 | await | — | Linux | Linux | — | iomap: don't free integrity payload that doesn't exist |
| CVE-2026-89771 | await | — | Linux | Linux | — | ring-buffer: Fix subbuf resize race with ring buffer readers |
| CVE-2026-89772 | await | — | Linux | Linux | — | btrfs: write-protect folios during data writeback |
| CVE-2026-89773 | await | — | Linux | Linux | — | drm/amd/display: Skip Update HDCP Config In Transition State |