Security Box Score — September 17, 2026 — page 2
Edition of September 17, 2026, continued — page 2 of 3. Back to page 1 · page 3
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-54649 | 2.1 | — | PunchIn-App | punchin-email | CWE-200 | punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on rep… |
| CVE-2026-92962 | 2.1 | — | patriksimek | vm2 | CWE-693 | vm2 before 3.11.4 Defense Invariant Violation via setup-sandbox.js |
| CVE-2026-92992 | 2.1 | — | Dromara | mayfly-go | CWE-862 | Dromara mayfly-go AI Assistant ai.go authorization |
| CVE-2026-92993 | 2.1 | — | Dromara | mayfly-go | CWE-77 | Dromara mayfly-go Machine Script Feature machine_script.go RunMachineScript o… |
| CVE-2026-93307 | 2.1 | — | O-RAN-SC | SMO OAM | CWE-400 | O-RAN-SC SMO OAM VES Collector memory allocation |
| CVE-2026-54577 | 2.0 | — | MidnightBSD | mport | CWE-20 | mport audit can inspect the wrong package when options are present |
| CVE-2026-54578 | 2.0 | — | MidnightBSD | mport | CWE-354 | mport verify can compare stale checksum data after hashing failures |
| CVE-2026-82723 | 1.8 | — | team-alembic | ash_authentication | CWE-532 | Actor record with password digest stored in AshAuthentication audit log entries |
| CVE-2026-82759 | 1.8 | — | team-alembic | ash_authentication | CWE-760 | Reversible IP address pseudonymisation in AshAuthentication audit log hash mode |
| CVE-2026-55061 | 1.0 | — | uniget-org | cli | CWE-88 | uniget: EDITOR Command Injection in uniget CLI |
| CVE-2026-49292 | 0.0 | — | kiwitcms | Kiwi | CWE-862 | Kiwi TCMS: The /init-db/ page renders and responds to requests after first use |
| CVE-2021-3030 | await | — | n/a | n/a | — | Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting c… |
| CVE-2025-55787 | await | — | n/a | n/a | — | In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerab… |
| CVE-2026-52483 | await | — | n/a | n/a | — | The ping diagnostics and other similar functions of the MitraStar GPT-2741GNA… |
| CVE-2026-73638 | await | — | — | Imager | CWE-125 | Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF bloc… |
| CVE-2026-73639 | await | — | — | Imager-File-PNG | CWE-787 | Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the en… |
| CVE-2026-90050 | await | — | Linux | Linux | — | net/sched: fq: clamp quantum and initial_quantum in change path |
| CVE-2026-90051 | await | — | Linux | Linux | — | tcp: reject non zerocopy devmem tx |
| CVE-2026-90052 | await | — | Linux | Linux | — | dm-integrity: fix buffer overflow with keyed discard |
| CVE-2026-90053 | await | — | Linux | Linux | — | net/sched: sch_htb: limit htb_classify inner-class filter hops |
| CVE-2026-90054 | await | — | Linux | Linux | — | tcp: fix corruption of urgent data on multi-segment retransmit |
| CVE-2026-90055 | await | — | Linux | Linux | — | usb: atm: usbatm: fix invalid ci_range initialization |
| CVE-2026-90056 | await | — | Linux | Linux | — | net: fec: only stop PTP if it was initialized |
| CVE-2026-90057 | await | — | Linux | Linux | — | slip: remove slip_hangup() to fix use-after-free in slip_receive_buf() |
| CVE-2026-90058 | await | — | Linux | Linux | — | net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup |
| CVE-2026-90059 | await | — | Linux | Linux | — | net: stmmac: restore NET_IP_ALIGN in the RX DMA offset |
| CVE-2026-90060 | await | — | Linux | Linux | — | ALSA: control: Don't add invalid kcontrols to LED layer |
| CVE-2026-90061 | await | — | Linux | Linux | — | netfilter: nf_tables: skip double clone set expressions on element insert |
| CVE-2026-90062 | await | — | Linux | Linux | — | netfilter: nf_tables: move hardware offload step after building the chain blob |
| CVE-2026-90063 | await | — | Linux | Linux | — | virtio-net: Ensure that TCP packets don't overflow gso_segs |
| CVE-2026-90064 | await | — | Linux | Linux | — | drm/xe: Reject page faults from non-fault-mode scratch VMs |
| CVE-2026-90065 | await | — | Linux | Linux | — | net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure |
| CVE-2026-90066 | await | — | Linux | Linux | — | samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify |
| CVE-2026-90067 | await | — | Linux | Linux | — | libceph: validate banner payload length |
| CVE-2026-90068 | await | — | Linux | Linux | — | ASoC: dapm: Fix off-by-one check on the second enum channel |
| CVE-2026-90069 | await | — | Linux | Linux | — | crypto: acomp - allocate async request context when cloning |
| CVE-2026-90070 | await | — | Linux | Linux | — | tpm: st33zp24: Return zero on status read failure |
| CVE-2026-90071 | await | — | Linux | Linux | — | net/sched: sch_teql: restore skb->dev on the slave failure path |
| CVE-2026-90072 | await | — | Linux | Linux | — | net/sched: sfq: clamp quantum to avoid signed overflow soft lockup |
| CVE-2026-90073 | await | — | Linux | Linux | — | net/sched: hhf: clamp quantum before hhf_change() to avoid overflow |
| CVE-2026-90074 | await | — | Linux | Linux | — | net/sched: fq_pie: clamp default quantum to avoid signed overflow |
| CVE-2026-90075 | await | — | Linux | Linux | — | net/sched: fq_codel: clamp default quantum and mtu |
| CVE-2026-90076 | await | — | Linux | Linux | — | net/sched: fq: add overflow bounds to quantum and initial quantum |
| CVE-2026-90077 | await | — | Linux | Linux | — | net: fix a resource leak in copy_net_ns() error handling path |
| CVE-2026-90078 | await | — | Linux | Linux | — | net/sched: act_skbmod: fix length calculations and avoid invalid header warnings |
| CVE-2026-90079 | await | — | Linux | Linux | — | octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init() |
| CVE-2026-90080 | await | — | Linux | Linux | — | octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup |
| CVE-2026-90081 | await | — | Linux | Linux | — | net/rds: use wq_has_sleeper() in rds_cong_map_updated() |
| CVE-2026-90082 | await | — | Linux | Linux | — | net: mana: Cap MSI-X vectors to the device MSI-X table size |
| CVE-2026-90083 | await | — | Linux | Linux | — | net/sched: act_ife: Only operate on Ethernet frames |
| CVE-2026-90084 | await | — | Linux | Linux | — | octeontx2-vf: fix workqueue and netdev race in probe/remove |
| CVE-2026-90085 | await | — | Linux | Linux | — | octeontx2-af: fix NULL deref in NIX TM tree debugfs read path |
| CVE-2026-90086 | await | — | Linux | Linux | — | xsk: honor XDP_TX_METADATA in zero-copy path |
| CVE-2026-90087 | await | — | Linux | Linux | — | Bluetooth: do not leak an hci_conn when a second LE connect is rejected |
| CVE-2026-90088 | await | — | Linux | Linux | — | Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop |
| CVE-2026-90089 | await | — | Linux | Linux | — | Bluetooth: btnxpuart: Validate the FW dump header length |
| CVE-2026-90090 | await | — | Linux | Linux | — | Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path |
| CVE-2026-90091 | await | — | Linux | Linux | — | Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan |
| CVE-2026-90092 | await | — | Linux | Linux | — | Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN |
| CVE-2026-90093 | await | — | Linux | Linux | — | Bluetooth: L2CAP: access chan->conn safely in get/setsockopt |
| CVE-2026-90094 | await | — | Linux | Linux | — | arm64: process: Fix context switching MTE store-only tag check |
| CVE-2026-90095 | await | — | Linux | Linux | — | fuse: Fix the condition to enable over-io-uring |
| CVE-2026-90096 | await | — | Linux | Linux | — | fuse: invalidate the correct range after O_APPEND direct write |
| CVE-2026-90097 | await | — | Linux | Linux | — | Drivers: hv: vmbus: Skip VMBus module cleanup for non-nested root partition |
| CVE-2026-90098 | await | — | Linux | Linux | — | net: sparx5: fix sleep in atomic context in MAC table access |
| CVE-2026-90099 | await | — | Linux | Linux | — | net/sched: account classifier filter allocations to memcg |
| CVE-2026-90100 | await | — | Linux | Linux | — | ptp: netc: fix period truncation and potential divide-by-zero in PEROUT |
| CVE-2026-90101 | await | — | Linux | Linux | — | bnxt_en: Fix call to hardware monitoring event handler |
| CVE-2026-90102 | await | — | Linux | Linux | — | NFSv4/pnfs: key the data server cache on the NFS version |
| CVE-2026-90103 | await | — | Linux | Linux | — | NFSv4.2: fix LAYOUTSTATS send buffer exhaustion |
| CVE-2026-90104 | await | — | Linux | Linux | — | NFSv4.1: zero referring call lists before decoding |
| CVE-2026-90105 | await | — | Linux | Linux | — | vxlan: fix reading neigh ha |
| CVE-2026-90106 | await | — | Linux | Linux | — | net: bridge: arp/nd proxy: fix reading neigh ha |
| CVE-2026-90107 | await | — | Linux | Linux | — | net/smc: free pending qentry in smc_llc_flow_stop() before memset |
| CVE-2026-90108 | await | — | Linux | Linux | — | net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK tra… |
| CVE-2026-90109 | await | — | Linux | Linux | — | net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue |
| CVE-2026-90110 | await | — | Linux | Linux | — | inetpeer: randomize RB-tree node comparison using SipHash |
| CVE-2026-90111 | await | — | Linux | Linux | — | ip6mr: do not clone dst in ip6mr_cache_report() |
| CVE-2026-90112 | await | — | Linux | Linux | — | net: qlcnic: validate unified ROM sections before loading |
| CVE-2026-90113 | await | — | Linux | Linux | — | netdevsim: update queue NAPI association on queue reset |
| CVE-2026-90114 | await | — | Linux | Linux | — | net: bridge: Reject descending VLAN tunnel ranges |
| CVE-2026-90115 | await | — | Linux | Linux | — | xsk: fix NULL pointer dereference in __xsk_rcv() |
| CVE-2026-90116 | await | — | Linux | Linux | — | ALSA: mtpav: shut down output timer before card teardown |
| CVE-2026-90117 | await | — | Linux | Linux | — | ntfs: validate usa_ofs before preserving the update sequence number |
| CVE-2026-90118 | await | — | Linux | Linux | — | ntfs: fix off-by-one page overflow in ntfs_decompress() |
| CVE-2026-90119 | await | — | Linux | Linux | — | ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup |
| CVE-2026-90120 | await | — | Linux | Linux | — | irqchip/gic-v5: Check get_logical_index() return value in MADT IAFFID parsing |
| CVE-2026-90121 | await | — | Linux | Linux | — | irqchip/gic-v5: Clear per-CPU IRS data on teardown |
| CVE-2026-90122 | await | — | Linux | Linux | — | clk: visconti: Make sure clk_init_data is fully initialized |
| CVE-2026-90123 | await | — | Linux | Linux | — | irqchip/ast2700-intc: Avoid allocating in the irq_domain activate() callback |
| CVE-2026-90124 | await | — | Linux | Linux | — | irqchip/renesas-rzg2l: Fix loss of interrupt |
| CVE-2026-90125 | await | — | Linux | Linux | — | smb: client: fix request buffer leak in smb2_new_read_req() |
| CVE-2026-90126 | await | — | Linux | Linux | — | rtc: pcf8563: fix clock provider leak on unbind |
| CVE-2026-90127 | await | — | Linux | Linux | — | virtio: rtc: time out alarm requests |
| CVE-2026-90128 | await | — | Linux | Linux | — | vdpa/mlx5: fix wrong list iterated in add_direct_chain error path |
| CVE-2026-90129 | await | — | Linux | Linux | — | virtio_balloon: quiesce balloon work before device shutdown |
| CVE-2026-90130 | await | — | Linux | Linux | — | vdpa_sim: fix cleanup after worker creation failure |
| CVE-2026-90131 | await | — | Linux | Linux | — | ntfs: serialize resident iomap reads with mrec_lock |
| CVE-2026-90132 | await | — | Linux | Linux | — | ntfs: reject unprivileged writes to reserved $LX* xattrs |
| CVE-2026-90133 | await | — | Linux | Linux | — | ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib() |
| CVE-2026-90134 | await | — | Linux | Linux | — | ntfs: fix kmap_local_page() usage in compress |
| CVE-2026-90135 | await | — | Linux | Linux | — | net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs() |
| CVE-2026-90136 | await | — | Linux | Linux | — | platform/x86/amd/hsmp: Reject negative power cap writes in hwmon |
| CVE-2026-90137 | await | — | Linux | Linux | — | platform/x86: hp-bioscfg: fix password encoding bounds check |
| CVE-2026-90138 | await | — | Linux | Linux | — | vsock: don't check the listener's sk_err in vsock_accept() |
| CVE-2026-90139 | await | — | Linux | Linux | — | fuse: check for NULL root inode in fuse_fill_super_submount |
| CVE-2026-90140 | await | — | Linux | Linux | — | cuse: wait for pending RCU callbacks on module exit |
| CVE-2026-90141 | await | — | Linux | Linux | — | ipvs: fix integer overflow in ftp helper port/address parsing |
| CVE-2026-90142 | await | — | Linux | Linux | — | virtio_net: Fix resize of the RX ring |
| CVE-2026-90143 | await | — | Linux | Linux | — | net: kcm: Hold RCU read lock while running BPF parser |
| CVE-2026-90144 | await | — | Linux | Linux | — | dpll: fix NULL deref in dpll_device_ops() during teardown race |
| CVE-2026-90145 | await | — | Linux | Linux | — | hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() … |
| CVE-2026-90146 | await | — | Linux | Linux | — | bpf, xdp: move offload check into dev_xdp_install() |
| CVE-2026-90147 | await | — | Linux | Linux | — | clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() |
| CVE-2026-90148 | await | — | Linux | Linux | — | NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease() |
| CVE-2026-90149 | await | — | Linux | Linux | — | NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers |
| CVE-2026-90150 | await | — | Linux | Linux | — | pnfs/blocklayout: Fix device leaks on parse failure |
| CVE-2026-90151 | await | — | Linux | Linux | — | NFSv4: remove callback IDR entry on client allocation failure |
| CVE-2026-90152 | await | — | Linux | Linux | — | smb/server: fix session leak in ksmbd_session_register() |
| CVE-2026-90153 | await | — | Linux | Linux | — | ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size |
| CVE-2026-90154 | await | — | Linux | Linux | — | ksmbd: scope session state changes to bound connections |
| CVE-2026-90155 | await | — | Linux | Linux | — | ksmbd: detach blocked lock requests before freeing |
| CVE-2026-90156 | await | — | Linux | Linux | — | ksmbd: safely discard unregistered deferred locks |
| CVE-2026-90157 | await | — | Linux | Linux | — | bpf: Reject negative optlen in cgroup getsockopt hook |
| CVE-2026-90158 | await | — | Linux | Linux | — | m68k: nfcon: Do not call console_is_registered() in nfcon_device() |
| CVE-2026-90159 | await | — | Linux | Linux | — | bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks |
| CVE-2026-90160 | await | — | Linux | Linux | — | lwt_bpf: Restore reserved headroom after xmit program |
| CVE-2026-90161 | await | — | Linux | Linux | — | erofs: fix interlaced ztailpacking pclusters |
| CVE-2026-90162 | await | — | Linux | Linux | — | ksmbd: defer publishing granted locks to prevent UAF/double-free race |
| CVE-2026-90163 | await | — | Linux | Linux | — | smb/server: call ksmbd_proc_cleanup() on module init failure |
| CVE-2026-90164 | await | — | Linux | Linux | — | smb/server: abort initialization when proc setup fails |
| CVE-2026-90165 | await | — | Linux | Linux | — | smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger() |
| CVE-2026-90166 | await | — | Linux | Linux | — | smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request() |
| CVE-2026-90167 | await | — | Linux | Linux | — | ksmbd: serialize oplock close with pending break ownership |
| CVE-2026-90168 | await | — | Linux | Linux | — | ksmbd: retain connection for pending notify work |
| CVE-2026-90169 | await | — | Linux | Linux | — | ksmbd: free preauth sessions on connection teardown |
| CVE-2026-90170 | await | — | Linux | Linux | — | ksmbd: validate ipc response length before dereferencing its fields |
| CVE-2026-90171 | await | — | Linux | Linux | — | smb: smbdirect: release pending child sockets outside the handler lock |
| CVE-2026-90172 | await | — | Linux | Linux | — | smb: smbdirect: destroy QP before mem pools on accept failure |
| CVE-2026-90173 | await | — | Linux | Linux | — | smb: smbdirect: free completion queues with ib_free_cq() |
| CVE-2026-90174 | await | — | Linux | Linux | — | ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user() |
| CVE-2026-90175 | await | — | Linux | Linux | — | smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer |
| CVE-2026-90176 | await | — | Linux | Linux | — | ksmbd: Do not skip lock checks for single-byte ranges |
| CVE-2026-90177 | await | — | Linux | Linux | — | bpf: Check pointer type for all atomic RMW paths |
| CVE-2026-90178 | await | — | Linux | Linux | — | hwmon: (coretemp) Fix core_data leak on CPUs without PTS |
| CVE-2026-90179 | await | — | Linux | Linux | — | apparmor: fix deadlock in complain-mode change_hat |
| CVE-2026-90180 | await | — | Linux | Linux | — | block: mtip32xx: synchronize ioctls with device removal |
| CVE-2026-90181 | await | — | Linux | Linux | — | ublk: avoid teardown retry loop on xarray allocation failure |
| CVE-2026-90182 | await | — | Linux | Linux | — | blk-iocost: clear delay state when freeing policy data |
| CVE-2026-90183 | await | — | Linux | Linux | — | blk-iolatency: clear delay state when freeing policy data |
| CVE-2026-90184 | await | — | Linux | Linux | — | null_blk: serialize configfs attribute updates with device setup |
| CVE-2026-90185 | await | — | Linux | Linux | — | null_blk: serialize configfs attribute stores with the lock |
| CVE-2026-90186 | await | — | Linux | Linux | — | null_blk: reject per-device queue resize for shared tag set |
| CVE-2026-90187 | await | — | Linux | Linux | — | null_blk: free zones array on device power-off |
| CVE-2026-90188 | await | — | Linux | Linux | — | null_blk: free global tag_set on init error path |
| CVE-2026-90189 | await | — | Linux | Linux | — | null_blk: register configfs subsystem after creating default devices |
| CVE-2026-90190 | await | — | Linux | Linux | — | null_blk: use DEFINE_MUTEX for the file-scope mutex |
| CVE-2026-90191 | await | — | Linux | Linux | — | mailbox: riscv-sbi-mpxy: validate RPMI notification lengths |
| CVE-2026-90192 | await | — | Linux | Linux | — | mailbox: qcom-cpucp: handle NULL data in send_data callback |
| CVE-2026-90193 | await | — | Linux | Linux | — | mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler |
| CVE-2026-90194 | await | — | Linux | Linux | — | ACPI: scan: fix bus ID cleanup on device_add() failures |
| CVE-2026-90195 | await | — | Linux | Linux | — | riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args |
| CVE-2026-90196 | await | — | Linux | Linux | — | ASoC: SOF: validate topology volume range before allocation |
| CVE-2026-90197 | await | — | Linux | Linux | — | HID: haptic: don't write an uninitialized value to unhandled usages |
| CVE-2026-90198 | await | — | Linux | Linux | — | ALSA: core: Fix use-after-free in snd_card_do_free() |
| CVE-2026-90199 | await | — | Linux | Linux | — | fs/ntfs3: reject out-of-range evcn in mi_enum_attr() |
| CVE-2026-90200 | await | — | Linux | Linux | — | fs/ntfs3: fix integer overflow in MFT cluster validation |
| CVE-2026-90201 | await | — | Linux | Linux | — | net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race |
| CVE-2026-90202 | await | — | Linux | Linux | — | scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers |
| CVE-2026-90203 | await | — | Linux | Linux | — | Squashfs: check block offset is not negative |
| CVE-2026-90204 | await | — | Linux | Linux | — | ocfs2: validate DIO orphan slot during inode read |
| CVE-2026-90205 | await | — | Linux | Linux | — | ocfs2: validate orphan slot during inode read |
| CVE-2026-90206 | await | — | Linux | Linux | — | nvmet: fix max_qid race between configfs and controller allocation |
| CVE-2026-90207 | await | — | Linux | Linux | — | ALSA: seq: midi: Serialize input teardown with event_input |
| CVE-2026-90208 | await | — | Linux | Linux | — | clocksource/drivers/samsung_pwm: Switch to raw_spinlock_t type |
| CVE-2026-90209 | await | — | Linux | Linux | — | s390/debug: Fix deadlock during unregister |
| CVE-2026-90210 | await | — | Linux | Linux | — | bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure |
| CVE-2026-90211 | await | — | Linux | Linux | — | bpf, s390: Clear fetch destination on faulting arena atomic |
| CVE-2026-90212 | await | — | Linux | Linux | — | arm64/efi: Avoid voluntary preemption with efi_mm installed |
| CVE-2026-90213 | await | — | Linux | Linux | — | firewire: core: fix memory leak in error path of build_tree() |
| CVE-2026-90214 | await | — | Linux | Linux | — | ASoC: xilinx: formatter_pcm: fix stream_data leak on open error |
| CVE-2026-90215 | await | — | Linux | Linux | — | mtd: ubi: Release device reference on busy detach |
| CVE-2026-90216 | await | — | Linux | Linux | — | ubi: Fix rollback for explicit UBI device numbers |
| CVE-2026-90217 | await | — | Linux | Linux | — | bpf: Compare iterator types during state pruning |
| CVE-2026-90218 | await | — | Linux | Linux | — | RDMA/cma: Fix WARNING in res_to_rt |
| CVE-2026-90219 | await | — | Linux | Linux | — | RDMA/cxgb4: Free debugfs on registration failure |
| CVE-2026-90220 | await | — | Linux | Linux | — | ALSA: seq: Don't leak the extension cell pointer in the bounce payload |
| CVE-2026-90221 | await | — | Linux | Linux | — | nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing |
| CVE-2026-90222 | await | — | Linux | Linux | — | nfc: pn533: hold a reference to the request skb during send_frame |
| CVE-2026-90223 | await | — | Linux | Linux | — | nfc: llcp: bound SNL TLV parsing to the skb and add length checks |
| CVE-2026-90224 | await | — | Linux | Linux | — | nfc: nci: fix double completion race in nci_data_exchange_complete |
| CVE-2026-90225 | await | — | Linux | Linux | — | nfc: llcp: read llcp_sock->local under the socket lock in getsockopt |
| CVE-2026-90226 | await | — | Linux | Linux | — | nfc: llcp: avoid userspace overflow on invalid optlen |
| CVE-2026-90227 | await | — | Linux | Linux | — | nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() |
| CVE-2026-90228 | await | — | Linux | Linux | — | nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns() |
| CVE-2026-90229 | await | — | Linux | Linux | — | nvme-apple: Destroy the admin queue on removal |
| CVE-2026-90230 | await | — | Linux | Linux | — | nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() |
| CVE-2026-90231 | await | — | Linux | Linux | — | apparmor: fix unconfined user namespace restriction forced stack |
| CVE-2026-90232 | await | — | Linux | Linux | — | amt: Don't support cross-netns setup. |
| CVE-2026-90233 | await | — | Linux | Linux | — | nvme-pci: release descriptor pools on probe failure |
| CVE-2026-90234 | await | — | Linux | Linux | — | NFS: Return a delegation the client fails to record |
| CVE-2026-90235 | await | — | Linux | Linux | — | sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE |
| CVE-2026-90236 | await | — | Linux | Linux | — | NFSD: Release the export reference when reaping open stateids |
| CVE-2026-90237 | await | — | Linux | Linux | — | netfilter: nft_ct: move custom expectation support to helper |
| CVE-2026-90238 | await | — | Linux | Linux | — | media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path |
| CVE-2026-90239 | await | — | Linux | Linux | — | media: amd: isp4: release partial allocations in isp4if_alloc_fw_gpumem() |
| CVE-2026-90240 | await | — | Linux | Linux | — | iommu/vt-d: Flush context cache with correct SID when tearing down aliases |
| CVE-2026-90241 | await | — | Linux | Linux | — | iommu/vt-d: Tear down scalable-mode context on probe failure |
| CVE-2026-90242 | await | — | Linux | Linux | — | iommu/vt-d: Fix iopf_refcount leak on RID domain replacement |
| CVE-2026-90243 | await | — | Linux | Linux | — | iommu/vt-d: Clear Present bit before tearing down copied context entry |
| CVE-2026-90244 | await | — | Linux | Linux | — | iommu/dma: Restore locking around msi_page_list |
| CVE-2026-90245 | await | — | Linux | Linux | — | fbdev: kyro: Validate overlay viewport coordinates |
| CVE-2026-90246 | await | — | Linux | Linux | — | apparmor: fix integer overflow in verify_tags() bounds check |
| CVE-2026-90247 | await | — | Linux | Linux | — | bpf: Fix mmap_lock leak in irq_work path |
| CVE-2026-90248 | await | — | Linux | Linux | — | net/sched: cls_api: fix teardown of an adopted proto on insert-race loss |
| CVE-2026-90249 | await | — | Linux | Linux | — | iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes |
| CVE-2026-90250 | await | — | Linux | Linux | — | bpf, cgroup: Fix storage null-ptr-deref after replacing prog |
| CVE-2026-90251 | await | — | Linux | Linux | — | Bluetooth: MSFT: validate evt_prefix_len against the response length |
| CVE-2026-90252 | await | — | Linux | Linux | — | Bluetooth: MGMT: free the HCI command when it is cancelled |
| CVE-2026-90253 | await | — | Linux | Linux | — | Bluetooth: MGMT: free the mesh send cancel command when it is cancelled |
| CVE-2026-90254 | await | — | Linux | Linux | — | Bluetooth: hci_sync: free the advertising instance on the failure and cancel … |
| CVE-2026-90255 | await | — | Linux | Linux | — | Bluetooth: hci_conn: fix the SCO setup context lifetime |
| CVE-2026-90256 | await | — | Linux | Linux | — | Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind |
| CVE-2026-90257 | await | — | Linux | Linux | — | Bluetooth: virtio_bt: avoid OOB read of build info string |
| CVE-2026-90258 | await | — | Linux | Linux | — | pinctrl: airoha: add missed IRQ resource helpers |
| CVE-2026-90259 | await | — | Linux | Linux | — | btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data() |
| CVE-2026-90260 | await | — | Linux | Linux | — | btrfs: zoned: don't clobber the extent buffer when zeroing it out |
| CVE-2026-90261 | await | — | Linux | Linux | — | btrfs: zoned: flush active metadata block group at btree_writepages() start |
| CVE-2026-90262 | await | — | Linux | Linux | — | btrfs: retry verity reads for not-uptodate Merkle folios |
| CVE-2026-90263 | await | — | Linux | Linux | — | btrfs: check if root is readonly when setting posix acl |
| CVE-2026-90264 | await | — | Linux | Linux | — | btrfs: always wait for ordered extents to avoid OE races |
| CVE-2026-90265 | await | — | Linux | Linux | — | btrfs: defrag: fix deadlock between defrag and delalloc space reservation |
| CVE-2026-90266 | await | — | Linux | Linux | — | btrfs: zoned: don't force read-only on transient -EAGAIN from reloc merge |
| CVE-2026-90267 | await | — | Linux | Linux | — | scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails |
| CVE-2026-90268 | await | — | Linux | Linux | — | scsi: sd: Fix error handling in sd_probe() after large pool creation failure |
| CVE-2026-90269 | await | — | Linux | Linux | — | bpf: Reject load-acquire from pointers requiring fault protection |
| CVE-2026-90270 | await | — | Linux | Linux | — | arm_mpam: Disable driver unbind to avoid UAF |
| CVE-2026-90271 | await | — | Linux | Linux | — | arm_mpam: Fix a NULL pointer dereference on unbinding after an error interrupt |
| CVE-2026-90272 | await | — | Linux | Linux | — | perf: arm_pmuv3: Zero initialize hw_id branch stack field |
| CVE-2026-90273 | await | — | Linux | Linux | — | coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable |
| CVE-2026-90274 | await | — | Linux | Linux | — | coresight: etm4x: fix underflow for usage of (nrseqstate - 1) |
| CVE-2026-90275 | await | — | Linux | Linux | — | md/raid1: don't set array_frozen in raid1_takeover() |
| CVE-2026-90276 | await | — | Linux | Linux | — | md/md-llbitmap: stop daemon timer rearm on destroy |
| CVE-2026-90277 | await | — | Linux | Linux | — | md/md-llbitmap: prevent create failure bitmap UAF |
| CVE-2026-90278 | await | — | Linux | Linux | — | md: wait for behind writes before destroying bitmap |
| CVE-2026-90279 | await | — | Linux | Linux | — | md/raid5: round bitmap stripes with sector division |
| CVE-2026-90280 | await | — | Linux | Linux | — | phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend |
| CVE-2026-90281 | await | — | Linux | Linux | — | phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend |
| CVE-2026-90282 | await | — | Linux | Linux | — | phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend |
| CVE-2026-90283 | await | — | Linux | Linux | — | hugetlbfs: release subpool on fill_super failure |
| CVE-2026-90284 | await | — | Linux | Linux | — | firmware_loader: do not queue completed sysfs fallback requests |
| CVE-2026-90285 | await | — | Linux | Linux | — | scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path |
| CVE-2026-90286 | await | — | Linux | Linux | — | drm/amdgpu/gfx6: Use PFP on the compute queues too |
| CVE-2026-90287 | await | — | Linux | Linux | — | phy: sunplus: fix error handling in sp_uphy_init() |
| CVE-2026-90288 | await | — | Linux | Linux | — | phy: renesas: rcar-gen2: Fix double of_node_put on phy creation failure |
| CVE-2026-90289 | await | — | Linux | Linux | — | drm/amd/display: Resize MST HDCP per-connector arrays to 32 |
| CVE-2026-90290 | await | — | Linux | Linux | — | arm64: hibernate: Restore DAIF state on error |
| CVE-2026-90291 | await | — | Linux | Linux | — | module/dups: Fix use-after-free in kmod_dup_req lifetime handling |
| CVE-2026-90292 | await | — | Linux | Linux | — | RDMA/siw: Fix use-after-free in siw_accept() |
| CVE-2026-90293 | await | — | Linux | Linux | — | IB/isert: post the full-feature receive buffers after session registration |
| CVE-2026-90294 | await | — | Linux | Linux | — | IB/isert: delay the final Login Response until the session is registered |
| CVE-2026-90295 | await | — | Linux | Linux | — | cpufreq: imx6q: fix out-of-bounds write when probed more than once |
| CVE-2026-90296 | await | — | Linux | Linux | — | cpufreq: imx6q: fix devres accumulation across driver rebind |
| CVE-2026-90297 | await | — | Linux | Linux | — | drm/sun4i: crtc: Propagate layer initialization error |
| CVE-2026-90298 | await | — | Linux | Linux | — | drm/sun4i: tcon: Drop TCON TOP device reference |
| CVE-2026-90299 | await | — | Linux | Linux | — | bpf: Fix sleepable check for tracing/lsm prog |
| CVE-2026-90300 | await | — | Linux | Linux | — | bpf: Clear buf on error in __bpf_get_task_stack |
| CVE-2026-90301 | await | — | Linux | Linux | — | ocfs2: o2hb: quiesce negotiate handlers and timeout work |
| CVE-2026-90302 | await | — | Linux | Linux | — | ocfs2: synchronize heartbeat callbacks with o2net teardown |
| CVE-2026-90303 | await | — | Linux | Linux | — | ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults |
| CVE-2026-90304 | await | — | Linux | Linux | — | ARM: 9484/1: enable interrupts when unhandled user faults are triggered |
| CVE-2026-90305 | await | — | Linux | Linux | — | ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK |
| CVE-2026-90306 | await | — | Linux | Linux | — | ARM: 9481/2: breakpoint: CFI breakpoints only on demand |
| CVE-2026-90307 | await | — | Linux | Linux | — | RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ |
| CVE-2026-90308 | await | — | Linux | Linux | — | RDMA/erdma: Hold QP references for AE and CM processing |
| CVE-2026-90309 | await | — | Linux | Linux | — | RDMA/erdma: Hold CQ references when processing EQ events |
| CVE-2026-90310 | await | — | Linux | Linux | — | xen/xenbus: check otherend_id only after it has been initialized |
| CVE-2026-90311 | await | — | Linux | Linux | — | thermal: hwmon: Remove hwmon class device along with its parent |
| CVE-2026-90312 | await | — | Linux | Linux | — | bpf: Check load-acquire src ptr type before the load |
| CVE-2026-90313 | await | — | Linux | Linux | — | bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed |
| CVE-2026-90314 | await | — | Linux | Linux | — | remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() |
| CVE-2026-90315 | await | — | Linux | Linux | — | PCI/sysfs: Add lockdown checks to legacy I/O and memory handlers |
| CVE-2026-90316 | await | — | Linux | Linux | — | drm/omap: dsi: Do not copy isr table |
| CVE-2026-90317 | await | — | Linux | Linux | — | bpf: Invalidate RCU pointers after final spin unlock |
| CVE-2026-90318 | await | — | Linux | Linux | — | fat: release buffer head after rebuilding parent |
| CVE-2026-90319 | await | — | Linux | Linux | — | rapidio: clear mport->net when rio_add_net() fails |
| CVE-2026-90320 | await | — | Linux | Linux | — | ocfs2: validate external xattr entries when reading metadata |
| CVE-2026-90321 | await | — | Linux | Linux | — | ocfs2: validate inline xattrs during inode block validation |
| CVE-2026-90322 | await | — | Linux | Linux | — | ocfs2/cluster: keep heartbeat local node stable |
| CVE-2026-90323 | await | — | Linux | Linux | — | ublk: validate auto buf reg before taking uring_cmd |
| CVE-2026-90324 | await | — | Linux | Linux | — | ublk: check import_ubuf() return value |
| CVE-2026-90325 | await | — | Linux | Linux | — | blk-cgroup: skip dying blkg in blkcg_activate_policy() |
| CVE-2026-90326 | await | — | Linux | Linux | — | blk-cgroup: fix race between policy activation and blkg destruction |
| CVE-2026-90327 | await | — | Linux | Linux | — | phonet: pep: do not write beyond optlen in getsockopt |
| CVE-2026-90328 | await | — | Linux | Linux | — | HID: steam: Reject short reads |
| CVE-2026-90329 | await | — | Linux | Linux | — | HID: synchronize input before cleaning up a failed probe |
| CVE-2026-90330 | await | — | Linux | Linux | — | HID: logitech-hidpp: Fix FF device cleanup on init failure |
| CVE-2026-90331 | await | — | Linux | Linux | — | HID: asus: refactor the two workqueues and init sequence |
| CVE-2026-90332 | await | — | Linux | Linux | — | PCI: dwc: ep: Flush cached MSI write before unmapping the iATU |
| CVE-2026-90333 | await | — | Linux | Linux | — | dm-integrity: replace forgeable discard filler with a keyed sector marker |
| CVE-2026-90334 | await | — | Linux | Linux | — | tty: clear cdev pointer after cdev_add() failure |
| CVE-2026-90335 | await | — | Linux | Linux | — | tty: skip cdev_del() when no cdev is registered |
| CVE-2026-90336 | await | — | Linux | Linux | — | serial: core: clear freed pointers on uart_register_driver() failure |
| CVE-2026-90337 | await | — | Linux | Linux | — | serial: core: do fallible allocations before the console can be registered |
| CVE-2026-90338 | await | — | Linux | Linux | — | serial: amba-pl011: keep console clock enabled for atomic writes |
| CVE-2026-90339 | await | — | Linux | Linux | — | powerpc/syscall: Fix syscall skip handling for seccomp and ptrace |
| CVE-2026-90340 | await | — | Linux | Linux | — | pinctrl: generic: free maps on pinctrl_generic_to_map() failure |
| CVE-2026-90341 | await | — | Linux | Linux | — | firmware: coreboot: Validate table bounds |
| CVE-2026-90342 | await | — | Linux | Linux | — | bpf: Fix mmap_lock deadlock on arena lock failure |
| CVE-2026-90343 | await | — | Linux | Linux | — | wifi: cfg80211: stop PMSR before P2P and NAN teardown |
| CVE-2026-90344 | await | — | Linux | Linux | — | wifi: mac80211: disconnect on CSA to channel 0 |
| CVE-2026-90345 | await | — | Linux | Linux | — | wifi: brcmfmac: fix P2P action frame handling without device vif |
| CVE-2026-90346 | await | — | Linux | Linux | — | wifi: nl80211: clean up color-change beacon data on errors |
| CVE-2026-90347 | await | — | Linux | Linux | — | arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry |
| CVE-2026-90348 | await | — | Linux | Linux | — | wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump |
| CVE-2026-90349 | await | — | Linux | Linux | — | wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx() |
| CVE-2026-90350 | await | — | Linux | Linux | — | wifi: mt76: reject out-of-range link ids in mt76_vif_link() |
| CVE-2026-90351 | await | — | Linux | Linux | — | wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed |
| CVE-2026-90352 | await | — | Linux | Linux | — | wifi: mt76: mt7915: release hif2 reference on probe IRQ failure |
| CVE-2026-90353 | await | — | Linux | Linux | — | wifi: mt76: mt7915: fix ext PHY use-after-free on register error path |
| CVE-2026-90354 | await | — | Linux | Linux | — | wifi: mt76: mt7915: fix double hif2 init on the non-WED path |
| CVE-2026-90355 | await | — | Linux | Linux | — | wifi: mt76: mt7996: clear stale link state on full reset |
| CVE-2026-90356 | await | — | Linux | Linux | — | wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset |
| CVE-2026-90357 | await | — | Linux | Linux | — | wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement |
| CVE-2026-90358 | await | — | Linux | Linux | — | bpf, x86: Fix trampoline stack size for 128-bit arguments |
| CVE-2026-90359 | await | — | Linux | Linux | — | bpf: Reject >8 byte return values on return-reading trampoline paths |
| CVE-2026-90360 | await | — | Linux | Linux | — | regulator: core: use system_freezable_wq for init complete work |
| CVE-2026-90361 | await | — | Linux | Linux | — | wifi: ath11k: fix leak in ath11k_service_ready_ext_event() |
| CVE-2026-90362 | await | — | Linux | Linux | — | drm/msm/dsi: Drop dev_pm_opp_set_rate(0) |
| CVE-2026-90363 | await | — | Linux | Linux | — | drm/msm: don't tear down KMS twice when KMS init fails |
| CVE-2026-90364 | await | — | Linux | Linux | — | ACPI: processor: Unregister cpufreq notifier on init failure |
| CVE-2026-90365 | await | — | Linux | Linux | — | wifi: mt76: cancel reset and rc work on device unregister |
| CVE-2026-90366 | await | — | Linux | Linux | — | wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV |
| CVE-2026-90367 | await | — | Linux | Linux | — | wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER |
| CVE-2026-90368 | await | — | Linux | Linux | — | wifi: mt76: mt7915: unwind state on add_interface failure |
| CVE-2026-90369 | await | — | Linux | Linux | — | wifi: mt76: fix out-of-bounds access in mmio copy helpers |
| CVE-2026-90370 | await | — | Linux | Linux | — | wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config |
| CVE-2026-90371 | await | — | Linux | Linux | — | wifi: mt76: fix RXDMAD_C buffer recycling race |
| CVE-2026-90372 | await | — | Linux | Linux | — | wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss |
| CVE-2026-90373 | await | — | Linux | Linux | — | wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear |
| CVE-2026-90374 | await | — | Linux | Linux | — | wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] |
| CVE-2026-90375 | await | — | Linux | Linux | — | wifi: mt76: fix non-AQL packet accounting for MLO stations |
| CVE-2026-90376 | await | — | Linux | Linux | — | wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP |
| CVE-2026-90377 | await | — | Linux | Linux | — | wifi: mt76: fix RX data queuing of RRO 3.0 |
| CVE-2026-90378 | await | — | Linux | Linux | — | wifi: mt76: mt792x: Fix memory leak in SDIO TX path |
| CVE-2026-90379 | await | — | Linux | Linux | — | wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash |
| CVE-2026-90380 | await | — | Linux | Linux | — | wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete |
| CVE-2026-90381 | await | — | Linux | Linux | — | wifi: mt76: fix handling channel context with different bands in mt76_switch_… |
| CVE-2026-90382 | await | — | Linux | Linux | — | wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length |
| CVE-2026-90383 | await | — | Linux | Linux | — | misc: sgi-gru: remove interrupt-context page-table walks |
| CVE-2026-90384 | await | — | Linux | Linux | — | iomap: release the folio batch on iomap callback failures |
| CVE-2026-90385 | await | — | Linux | Linux | — | md/raid1: create serial pool adding rdev to array with serialize_policy=1 |
| CVE-2026-90386 | await | — | Linux | Linux | — | i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices |
| CVE-2026-90387 | await | — | Linux | Linux | — | swiotlb: Preserve allocation virtual address for dynamic pools |
| CVE-2026-90388 | await | — | Linux | Linux | — | iommu/dma: Check atomic pool allocation result directly |
| CVE-2026-90389 | await | — | Linux | Linux | — | md: scope memalloc_noio to allocation critical sections |
| CVE-2026-90390 | await | — | Linux | Linux | — | md/bitmap: resume array on backlog_store() error path |
| CVE-2026-90391 | await | — | Linux | Linux | — | lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone |
| CVE-2026-90392 | await | — | Linux | Linux | — | bpf: Fix potential UAF when reading bpf link info |
| CVE-2026-90393 | await | — | Linux | Linux | — | bpf: Fix potential UAF in bpf_netns_link_update_prog |
| CVE-2026-90394 | await | — | Linux | Linux | — | power: supply: sc2731_charger: cancel work on remove |
| CVE-2026-90395 | await | — | Linux | Linux | — | power: supply: isp1704_charger: cancel work on remove |
| CVE-2026-90396 | await | — | Linux | Linux | — | block: fix dio leak on metadata mapping error |
| CVE-2026-90397 | await | — | Linux | Linux | — | firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is publ… |
| CVE-2026-90398 | await | — | Linux | Linux | — | wifi: ath11k: fix stride mismatch in mac_phy_caps_parse() |
| CVE-2026-90399 | await | — | Linux | Linux | — | wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() |
| CVE-2026-90400 | await | — | Linux | Linux | — | md: recheck spare changes before starting sync |
| CVE-2026-90401 | await | — | Linux | Linux | — | md: remove REQ_NOWAIT support from raid1/10/456 |
| CVE-2026-90402 | await | — | Linux | Linux | — | bus: mhi: host: Fix controller cleanup on EDL sysfs failure |
| CVE-2026-90403 | await | — | Linux | Linux | — | wifi: rtlwifi: pci: fix error path in rtl_pci_probe() |
| CVE-2026-90404 | await | — | Linux | Linux | — | platform/chrome: cros_ec_debugfs: Unregister panic notifier |
| CVE-2026-90405 | await | — | Linux | Linux | — | media: stm32: dcmi: fix some error handling bugs in probe() |
| CVE-2026-90406 | await | — | Linux | Linux | — | media: qcom: iris: handle runtime PM resume failure in core deinit |
| CVE-2026-90407 | await | — | Linux | Linux | — | wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() |
| CVE-2026-90408 | await | — | Linux | Linux | — | wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event() |
| CVE-2026-90409 | await | — | Linux | Linux | — | drm/panthor: Add vm_bind region with kbo range overlap check |
| CVE-2026-90410 | await | — | Linux | Linux | — | spi: davinci: switch to managed controller allocation |
| CVE-2026-90411 | await | — | Linux | Linux | — | nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request |
| CVE-2026-90412 | await | — | Linux | Linux | — | nvmet: fix return status of RMI log page on allocation failure |
| CVE-2026-90413 | await | — | Linux | Linux | — | IB/isert: reject login PDUs declaring more data than was received |
| CVE-2026-90414 | await | — | Linux | Linux | — | IB/isert: reject PDUs declaring more data than was received |
| CVE-2026-90415 | await | — | Linux | Linux | — | RDMA/cxgb4: free STAG index when TPT entry write fails |
| CVE-2026-90416 | await | — | Linux | Linux | — | RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs |
| CVE-2026-90417 | await | — | Linux | Linux | — | RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry() |
| CVE-2026-90418 | await | — | Linux | Linux | — | nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch |
| CVE-2026-90419 | await | — | Linux | Linux | — | nilfs2: prevent out-of-bounds read in super root block parsing |
| CVE-2026-90420 | await | — | Linux | Linux | — | nilfs2: fix infinite loop in nilfs_clean_segments() |
| CVE-2026-90421 | await | — | Linux | Linux | — | PCI: Fix UAF when probe runs concurrent to dyn ID removal |
| CVE-2026-90422 | await | — | Linux | Linux | — | clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path |
| CVE-2026-90423 | await | — | Linux | Linux | — | RDMA/rxe: Fix UAF in ODP init error-handling path |
| CVE-2026-90424 | await | — | Linux | Linux | — | iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path |
| CVE-2026-90425 | await | — | Linux | Linux | — | iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID |
| CVE-2026-90426 | await | — | Linux | Linux | — | iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs |
| CVE-2026-90427 | await | — | Linux | Linux | — | iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() |
| CVE-2026-90428 | await | — | Linux | Linux | — | iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs |
| CVE-2026-90429 | await | — | Linux | Linux | — | iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init |
| CVE-2026-90430 | await | — | Linux | Linux | — | iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized |
| CVE-2026-90431 | await | — | Linux | Linux | — | remoteproc: Prevent crash handling to race with rproc_del() |
| CVE-2026-90432 | await | — | Linux | Linux | — | sched_ext: Abort directly from the hardlockup handler |
| CVE-2026-90433 | await | — | Linux | Linux | — | spi: oc-tiny: switch to managed controller allocation |
| CVE-2026-90434 | await | — | Linux | Linux | — | isofs: release zisofs block pointer buffer head |
| CVE-2026-90435 | await | — | Linux | Linux | — | RDMA/mlx5: Fix integer overflow of user QP buffer size |
| CVE-2026-92230 | await | — | Apache Software Foundation | Apache Karaf | CWE-401 | Apache Karaf: Improper release of ClassLoader references via static ThreadLoc… |
| CVE-2026-92476 | await | — | Linux | Linux | — | crypto: keembay - Initialize completion before requesting IRQ |
| CVE-2026-92477 | await | — | Linux | Linux | — | scsi: ufs: debugfs: Reserve space for a string terminator |
| CVE-2026-92478 | await | — | Linux | Linux | — | scsi: ufs: core: Validate connected lane counts |
| CVE-2026-92479 | await | — | Linux | Linux | — | scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags |
| CVE-2026-92480 | await | — | Linux | Linux | — | scsi: ufs: core: Validate string descriptors |
| CVE-2026-92481 | await | — | Linux | Linux | — | pinctrl: mediatek: free EINT resources on unbind |
| CVE-2026-92482 | await | — | Linux | Linux | — | pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip |
| CVE-2026-92483 | await | — | Linux | Linux | — | liveupdate: Remember FLB retrieve() status |
| CVE-2026-92484 | await | — | Linux | Linux | — | cxl/region: Fix use-after-free in find_pos_and_ways() error path |
| CVE-2026-92485 | await | — | Linux | Linux | — | bpf: Fix WARNING in bpf_tracing_link_release |
| CVE-2026-92486 | await | — | Linux | Linux | — | bpf: Fix CFI mismatch in task work callback |
| CVE-2026-92487 | await | — | Linux | Linux | — | exfat: fix valid_size extension over a shared writable mapping |
| CVE-2026-92488 | await | — | Linux | Linux | — | RDMA/erdma: complete object teardown when the destroy command fails |
| CVE-2026-92489 | await | — | Linux | Linux | — | xfrm: Fix skb double-free in xfrm_dev_direct_output() |
| CVE-2026-92490 | await | — | Linux | Linux | — | firmware: arm_scmi: Unrequest devices if driver registration fails |
| CVE-2026-92491 | await | — | Linux | Linux | — | firmware: arm_scmi: Roll back partial protocol table registration |
| CVE-2026-92492 | await | — | Linux | Linux | — | cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks |
| CVE-2026-92493 | await | — | Linux | Linux | — | cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active |
| CVE-2026-92494 | await | — | Linux | Linux | — | ext4: fix buffer_head leak in ext4_init_orphan_info |
| CVE-2026-92495 | await | — | Linux | Linux | — | RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap |
| CVE-2026-92496 | await | — | Linux | Linux | — | wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() |
| CVE-2026-92497 | await | — | Linux | Linux | — | wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() |
| CVE-2026-92498 | await | — | Linux | Linux | — | wifi: ath6kl: avoid buffer overreads in WMI event handlers |
| CVE-2026-92499 | await | — | Linux | Linux | — | ext4: validate readdir offset before accessing dirent |
| CVE-2026-92500 | await | — | Linux | Linux | — | ext4: use fsdata to track inline data write state and fix race |
| CVE-2026-92501 | await | — | Linux | Linux | — | ext4: drain in-flight DIO before buffered write fallback |
| CVE-2026-92502 | await | — | Linux | Linux | — | ext4: clear stale xarray tags on folios skipped during writeback |
| CVE-2026-92503 | await | — | Linux | Linux | — | ext4: fix ABBA deadlock in ext4_xattr_inode_cache_find() |
| CVE-2026-92504 | await | — | Linux | Linux | — | thermal: intel: int3400: clean up ODVP on probe failures |
| CVE-2026-92505 | await | — | Linux | Linux | — | iommu/amd: Fix undefined behavior in devid_write debugfs function |
| CVE-2026-92506 | await | — | Linux | Linux | — | firmware: arm_scmi: Fix requested device removal race |
| CVE-2026-92507 | await | — | Linux | Linux | — | RDMA/core: Fix potential use after free in ib_dealloc_pd_user() |
| CVE-2026-92508 | await | — | Linux | Linux | — | RDMA/core: Fix potential use after free in ib_free_cq() |
| CVE-2026-92509 | await | — | Linux | Linux | — | RDMA/core: Fix potential use after free in counter_release() |
| CVE-2026-92510 | await | — | Linux | Linux | — | RDMA/core: Fix potential use after free in ib_destroy_srq_user() |
| CVE-2026-92511 | await | — | Linux | Linux | — | RDMA/core: Fix potential use after free in ib_destroy_cq_user() |
| CVE-2026-92512 | await | — | Linux | Linux | — | RDMA/core: Fix use after free in ib_query_qp() |
| CVE-2026-92513 | await | — | Linux | Linux | — | RDMA/mana_ib: drain QP references after partial table insertion |
| CVE-2026-92514 | await | — | Linux | Linux | — | RDMA/erdma: Fix CEQ tasklet use-after-free on removal |
| CVE-2026-92515 | await | — | Linux | Linux | — | bpf: Preserve unique-field state across nested structs |
| CVE-2026-92516 | await | — | Linux | Linux | — | bpf: Fix offset warn check for bpf_res_spin_lock |
| CVE-2026-92517 | await | — | Linux | Linux | — | bpf, riscv: Fix extable handling for arena load_acquire |
| CVE-2026-92518 | await | — | Linux | Linux | — | riscv, bpf: Fix kernel stack corruption in tailcall with CFI |
| CVE-2026-92519 | await | — | Linux | Linux | — | riscv, bpf: Fix memory leak in bpf_jit_free |
| CVE-2026-92520 | await | — | Linux | Linux | — | bpf: Zero queue and stack outputs on lock failure |
| CVE-2026-92521 | await | — | Linux | Linux | — | ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root |
| CVE-2026-92522 | await | — | Linux | Linux | — | ACPI: processor: validate MADT IOAPIC entry bounds |
| CVE-2026-92523 | await | — | Linux | Linux | — | RDMA/nldev: validate dynamic counter attribute length |
| CVE-2026-92524 | await | — | Linux | Linux | — | irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() |
| CVE-2026-92525 | await | — | Linux | Linux | — | RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] |
| CVE-2026-93037 | await | — | Linux | Linux | — | RDMA/hfi1: Propagate sdma_txinit_ahg() errors |
| CVE-2026-93038 | await | — | Linux | Linux | — | iio: dac: ad5686: missing NULL check on match data |
| CVE-2026-93039 | await | — | Linux | Linux | — | ASoC: meson: Keep link pointers valid on realloc failure |
| CVE-2026-93040 | await | — | Linux | Linux | — | dmaengine: dw-edma: Serialize channel state checks |
| CVE-2026-93041 | await | — | Linux | Linux | — | dmaengine: dw-edma: Serialize abort state updates |
| CVE-2026-93042 | await | — | Linux | Linux | — | dmaengine: dw-edma: Terminate all descriptors without callbacks |
| CVE-2026-93043 | await | — | Linux | Linux | — | bpf: Disallow interpreter fallback for gotox insn |
| CVE-2026-93044 | await | — | Linux | Linux | — | bpf: Disallow interpreter fallback for arena-related insns |
| CVE-2026-93045 | await | — | Linux | Linux | — | bpf: Reject arena frees below the arena base |
| CVE-2026-93046 | await | — | Linux | Linux | — | software node: Fix software_node_get_reference_args() with index -1 |
| CVE-2026-93047 | await | — | Linux | Linux | — | drm/v3d: Associate BOs with every job that accesses them |
| CVE-2026-93048 | await | — | Linux | Linux | — | mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() |
| CVE-2026-93049 | await | — | Linux | Linux | — | mtd: mtdswap: Avoid freeing registered blktrans device twice |
| CVE-2026-93050 | await | — | Linux | Linux | — | ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove |
| CVE-2026-93051 | await | — | Linux | Linux | — | misc: ad525x_dpot: use driver core groups for sysfs files |
| CVE-2026-93052 | await | — | Linux | Linux | — | misc: bcm-vk: Use acquire/release for msgq_inited |
| CVE-2026-93053 | await | — | Linux | Linux | — | speakup: keyhelp: guard letter_offsets possible out-of-range indexing |
| CVE-2026-93054 | await | — | Linux | Linux | — | uio: Fix stale info pointer in failed registration path |
| CVE-2026-93055 | await | — | Linux | Linux | — | UDF symlink pathComponent header OOB read |
| CVE-2026-93056 | await | — | Linux | Linux | — | usb: gadget: f_uac1_legacy: remove broken string configfs attributes |
| CVE-2026-93057 | await | — | Linux | Linux | — | scsi: ufs: core: Avoid possible memory reclaim deadlock in TX EQTR context |
| CVE-2026-93058 | await | — | Linux | Linux | — | drm/msm: Only fini scheduler after successful init |
| CVE-2026-93059 | await | — | Linux | Linux | — | drm/msm: Fix task_struct reference leak in recover_worker |
| CVE-2026-93060 | await | — | Linux | Linux | — | drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() |
| CVE-2026-93061 | await | — | Linux | Linux | — | gpu: host1x: Avoid stack over-read in debug output helpers |
| CVE-2026-93062 | await | — | Linux | Linux | — | wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments |
| CVE-2026-93063 | await | — | Linux | Linux | — | wifi: iwlwifi: mei: check SAP message length before reading it |
| CVE-2026-93064 | await | — | Linux | Linux | — | wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser |
| CVE-2026-93065 | await | — | Linux | Linux | — | wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs |
| CVE-2026-93066 | await | — | Linux | Linux | — | x86/mm/pat: Take cpa_lock around large-page collapse |
| CVE-2026-93067 | await | — | Linux | Linux | — | drm/bridge: tc358767: clamp the reported AUX read size to the request |
| CVE-2026-93068 | await | — | Linux | Linux | — | drm/amd/display: Fix DM I2C teardown race |
| CVE-2026-93069 | await | — | Linux | Linux | — | OPP: Fix cleanup ordering |
| CVE-2026-93070 | await | — | Linux | Linux | — | media: ipu6: Do not free aux device pdata after init |
| CVE-2026-93071 | await | — | Linux | Linux | — | media: bcm2835-unicam: Fix asc leaked in error/remove path |
| CVE-2026-93072 | await | — | Linux | Linux | — | irqchip/renesas-irqc: Fix generic interrupt chip leak on remove |
| CVE-2026-93073 | await | — | Linux | Linux | — | dax: read holder_ops once in dax_holder_notify_failure() |
| CVE-2026-93074 | await | — | Linux | Linux | — | dax/fsdev: use __va(phys) for kaddr in direct_access |
| CVE-2026-93075 | await | — | Linux | Linux | — | dax/fsdev: clear pgmap ops and owner on unbind |
| CVE-2026-93076 | await | — | Linux | Linux | — | dax/fsdev: clear vmemmap_shift when binding static pgmap |
| CVE-2026-93077 | await | — | Linux | Linux | — | cxl/features: Clamp Get Feature output size to the remaining buffer |
| CVE-2026-93078 | await | — | Linux | Linux | — | cxl/features: Reject Set Features output buffer smaller than the header |
| CVE-2026-93079 | await | — | Linux | Linux | — | cxl/features: Reject Get Feature count larger than the output buffer |
| CVE-2026-93080 | await | — | Linux | Linux | — | firmware: arm_scmi: Fix transport device teardown lookup |
| CVE-2026-93081 | await | — | Linux | Linux | — | firmware: arm_scmi: Fix SCMI device destroy lifetimes |
| CVE-2026-93082 | await | — | Linux | Linux | — | firmware: arm_scmi: Unwind P2A receiver mailbox setup failure |
| CVE-2026-93083 | await | — | Linux | Linux | — | firmware: arm_scmi: Unwind TX receiver mailbox setup failure |
| CVE-2026-93084 | await | — | Linux | Linux | — | firmware: arm_scmi: Drop handle on protocol bind failures |
| CVE-2026-93085 | await | — | Linux | Linux | — | firmware: arm_scmi: Reject out of range DT protocol IDs |
| CVE-2026-93086 | await | — | Linux | Linux | — | firmware: arm_scmi: Avoid IDR updates while cleaning channels |
| CVE-2026-93089 | await | — | Linux | Linux | — | firmware: arm_scmi: Free transport channel on IDR failure |
| CVE-2026-93090 | await | — | Linux | Linux | — | firmware: arm_scmi: Clean up channels on setup failure |
| CVE-2026-93091 | await | — | Linux | Linux | — | firmware: arm_scmi: Quiesce notifications before teardown |
| CVE-2026-93092 | await | — | Linux | Linux | — | firmware: arm_scmi: Unregister device notifier before IDR teardown |
| CVE-2026-93093 | await | — | Linux | Linux | — | firmware: arm_scmi: Publish channel state before callbacks |
| CVE-2026-93094 | await | — | Linux | Linux | — | wifi: ath12k: fix dp_link_peer dangling references on AP vdev rollback |
| CVE-2026-93095 | await | — | Linux | Linux | — | hfsplus: validate thread record before delete key rebuild |
| CVE-2026-93096 | await | — | Linux | Linux | — | cxl/features: Serialize multi-part Get/Set Feature transfers |
| CVE-2026-93097 | await | — | Linux | Linux | — | cxl/mbox: Break poison list loop on an empty payload |
| CVE-2026-93098 | await | — | Linux | Linux | — | rpmsg: glink: fix deadlock in endpoint destroy during driver detach |
| CVE-2026-93099 | await | — | Linux | Linux | — | fs/resctrl: Fix UAF from worker threads when domains are removed |
| CVE-2026-93100 | await | — | Linux | Linux | — | fs/resctrl: Prevent use-after-free in rdtgroup_kn_put() |
| CVE-2026-93101 | await | — | Linux | Linux | — | media: v4l2-async: Unregister sub-device if asc_list is empty |
| CVE-2026-93102 | await | — | Linux | Linux | — | RDMA/hfi1: Free RX data on late probe failure |
| CVE-2026-93103 | await | — | Linux | Linux | — | RDMA/hfi1: Preserve unit 0 on allocation failure |
| CVE-2026-93104 | await | — | Linux | Linux | — | RDMA/rvt: Return NULL after port allocation failure |
| CVE-2026-93105 | await | — | Linux | Linux | — | esp: do not unref managed frag pages in esp_ssg_unref() |
| CVE-2026-93106 | await | — | Linux | Linux | — | crash_dump: release keyring reference at the correct time |
| CVE-2026-93107 | await | — | Linux | Linux | — | RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error… |
| CVE-2026-93108 | await | — | Linux | Linux | — | RDMA/ipoib: Drain RCU callbacks during module teardown |
| CVE-2026-93109 | await | — | Linux | Linux | — | RDMA/mlx5: Drain RCU callbacks during module teardown |
| CVE-2026-93110 | await | — | Linux | Linux | — | RDMA/core: Wait for RCU callbacks before unloading ib_core |
| CVE-2026-93111 | await | — | Linux | Linux | — | bpf: Mark tracing_multi trampolines as ftrace managed |
| CVE-2026-93112 | await | — | Linux | Linux | — | bpf: Require a BPF cpumask for bpf_cpumask_populate() |
| CVE-2026-93113 | await | — | Linux | Linux | — | clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK |
| CVE-2026-93114 | await | — | Linux | Linux | — | platform/surface: acpi-notify: Check ACPI companion before use |
| CVE-2026-93115 | await | — | Linux | Linux | — | platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL |
| CVE-2026-93116 | await | — | Linux | Linux | — | platform/x86: asus-wmi: fix resource leaks on probe failure |
| CVE-2026-93117 | await | — | Linux | Linux | — | usb: fix UAF when probe runs concurrent to dyn ID removal |
| CVE-2026-93118 | await | — | Linux | Linux | — | usb: gadget: aspeed_udc: check endpoint DMA allocation |
| CVE-2026-93119 | await | — | Linux | Linux | — | usb: ljca: bound bank_num in ljca_enumerate_gpio() |
| CVE-2026-93120 | await | — | Linux | Linux | — | usb: gadget: configfs: fix out-of-bounds read of qw_sign |
| CVE-2026-93121 | await | — | Linux | Linux | — | usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths |
| CVE-2026-93122 | await | — | Linux | Linux | — | usb: gadget: uac: validate rate list length before storing |
| CVE-2026-93123 | await | — | Linux | Linux | — | serial: qcom-geni: do not advance stale DMA completions |
| CVE-2026-93124 | await | — | Linux | Linux | — | platform/x86: asus-wireless: Fail probe when there is no ACPI match |
| CVE-2026-93125 | await | — | Linux | Linux | — | bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max |
| CVE-2026-93126 | await | — | Linux | Linux | — | remoteproc: qcom_q6v5_adsp: Fix reference leak for device node |
| CVE-2026-93127 | await | — | Linux | Linux | — | bpf: Drop scalar id on sign-extending narrowing stack fills |
| CVE-2026-93128 | await | — | Linux | Linux | — | platform/x86: lg-laptop: Fix LED resource handling |
| CVE-2026-93129 | await | — | Linux | Linux | — | platform/x86: dell-wmi-base: Fix handling of ultra performance key |
| CVE-2026-93130 | await | — | Linux | Linux | — | platform/x86: dell-wmi-base: Fix resource leak on module load failure |
| CVE-2026-93131 | await | — | Linux | Linux | — | platform/x86: dell-privacy: Fix race condition |
| CVE-2026-93132 | await | — | Linux | Linux | — | ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling |
| CVE-2026-93133 | await | — | Linux | Linux | — | ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() |
| CVE-2026-93134 | await | — | Linux | Linux | — | printk: Fix possible console use-after-free |
| CVE-2026-93135 | await | — | Linux | Linux | — | bpf: Reject programs with inlined helpers if JIT is not available |
| CVE-2026-93136 | await | — | Linux | Linux | — | bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation |
| CVE-2026-93137 | await | — | Linux | Linux | — | bpf: Fix use-after-free on mm_struct in bpf_find_vma() |
| CVE-2026-93138 | await | — | Linux | Linux | — | bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux |
| CVE-2026-93139 | await | — | Linux | Linux | — | drm/amdgpu/mes: Fix hung_queue_db_array loop limit for multi-XCC |
| CVE-2026-93140 | await | — | Linux | Linux | — | udf: Mark LVID buffer as uptodate before marking it dirty |
| CVE-2026-93141 | await | — | Linux | Linux | — | usb: gadget: r8a66597: avoid double free of ep0_req in probe error path |
| CVE-2026-93142 | await | — | Linux | Linux | — | thermal/drivers/rcar: Fix error checking in probe() |
| CVE-2026-93143 | await | — | Linux | Linux | — | staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume() |
| CVE-2026-93144 | await | — | Linux | Linux | — | bpf: Reject writes through untrusted BTF pointers |
| CVE-2026-93145 | await | — | Linux | Linux | — | clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister() |
| CVE-2026-93146 | await | — | Linux | Linux | — | time/namespace: Validate nanosecond field in proc_timens_set_offset() |
| CVE-2026-93147 | await | — | Linux | Linux | — | s390/bpf: Replace ly instruction with llgf |
| CVE-2026-93148 | await | — | Linux | Linux | — | bpf: Reject MEM_ALLOC BTF accesses past object bounds |
| CVE-2026-93149 | await | — | Linux | Linux | — | wifi: mac80211_hwsim: avoid NULL skb in stop queue drain |
| CVE-2026-93150 | await | — | Linux | Linux | — | cgroup/cpuset: Make nr_deadline_tasks an atomic_t |
| CVE-2026-93151 | await | — | Linux | Linux | — | nvmet-rdma: fix response resource leak on queue teardown |
| CVE-2026-93152 | await | — | Linux | Linux | — | nvme-apple: Use acquire/release for queue enabled state |
| CVE-2026-93153 | await | — | Linux | Linux | — | RDMA/bng_re: return a timeout when firmware responses stall |
| CVE-2026-93154 | await | — | Linux | Linux | — | RDMA/irdma: Add refcounting to user ring MRs |
| CVE-2026-93155 | await | — | Linux | Linux | — | crypto: keembay - Fix AEAD unregister count in error path |
| CVE-2026-93156 | await | — | Linux | Linux | — | crypto: rk3288 - fail ahash requests on HASH idle timeout |
| CVE-2026-93157 | await | — | Linux | Linux | — | hwrng: xilinx-trng - propagate timeout before any data is read |
| CVE-2026-93158 | await | — | Linux | Linux | — | crypto: sa2ul - stop probe if context pool creation fails |
| CVE-2026-93159 | await | — | Linux | Linux | — | crypto: atmel-sha204a - fix heap info leak on I2C transfer failure |
| CVE-2026-93160 | await | — | Linux | Linux | — | crypto: atmel-ecc - reject hardware ECDH without a public key |
| CVE-2026-93161 | await | — | Linux | Linux | — | crypto: qat - clear AES key schedule from stack |
| CVE-2026-93162 | await | — | Linux | Linux | — | crypto: qat - cancel work on re-enable SR-IOV timeout |
| CVE-2026-93163 | await | — | Linux | Linux | — | hwrng: core - fix rng list on registration error |
| CVE-2026-93164 | await | — | Linux | Linux | — | uprobes/x86: Move optimized uprobe from nop5 to nop10 |
| CVE-2026-93165 | await | — | Linux | Linux | — | platform/chrome: sensorhub: Fix memory overread in ring handler |
| CVE-2026-93166 | await | — | Linux | Linux | — | wifi: rtw89: debug: fix off by on in rtw89_ppdu_str() |
| CVE-2026-93167 | await | — | Linux | Linux | — | csky: Fix a4/a5 restoration in syscall trace path |
| CVE-2026-93168 | await | — | Linux | Linux | — | dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout |
| CVE-2026-93169 | await | — | Linux | Linux | — | dmaengine: zynqmp_dma: fix race between runtime PM and device removal |
| CVE-2026-93170 | await | — | Linux | Linux | — | dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA … |
| CVE-2026-93171 | await | — | Linux | Linux | — | leds: lp5860: Fix a potential double-unlock |
| CVE-2026-93172 | await | — | Linux | Linux | — | mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug |
| CVE-2026-93173 | await | — | Linux | Linux | — | bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks |
| CVE-2026-93174 | await | — | Linux | Linux | — | bpf: Copy per-CPU map value padding in copy_map_value_long() |
| CVE-2026-93175 | await | — | Linux | Linux | — | drm/amd/display: Fix dangling pointer in CRTC reset function |
| CVE-2026-93176 | await | — | Linux | Linux | — | drm/amd/display: Fix dangling pointer in plane reset function |
| CVE-2026-93177 | await | — | Linux | Linux | — | drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup |
| CVE-2026-93178 | await | — | Linux | Linux | — | drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup |
| CVE-2026-93179 | await | — | Linux | Linux | — | drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read |
| CVE-2026-93180 | await | — | Linux | Linux | — | drm/panthor: Fix NPD issue on partial unmap of an evicted BO |
| CVE-2026-93181 | await | — | Linux | Linux | — | perf/x86/intel/uncore: Fix uncore_box ref/unref ordering |
| CVE-2026-93182 | await | — | Linux | Linux | — | sched/fair: Fix overflow in update_tg_cfs_runnable() |
| CVE-2026-93183 | await | — | Linux | Linux | — | drm/lima: call drm_mm_init() with a valid allocation range |
| CVE-2026-93184 | await | — | Linux | Linux | — | ASoC: fsl_audmix: rework runtime PM handling in probe |
| CVE-2026-93185 | await | — | Linux | Linux | — | ASoC: rt700-sdw: always drain jack work on remove |