Security Box Score — September 24, 2026 — page 2
Edition of September 24, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-93233 | await | — | Linux | Linux | — | drm/nouveau/dmem: fix callocated underflow on large folio split |
| CVE-2026-93234 | await | — | Linux | Linux | — | drm/gud: validate TV mode names before creating enum property |
| CVE-2026-93235 | await | — | Linux | Linux | — | f2fs: fix to zero post-EOF data when extending file size |
| CVE-2026-93236 | await | — | Linux | Linux | — | media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common |
| CVE-2026-93238 | await | — | Linux | Linux | — | s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap |
| CVE-2026-93239 | await | — | Linux | Linux | — | arm64: mm: Fix the lockless page-table walk in show_pte() |
| CVE-2026-93240 | await | — | Linux | Linux | — | memcg: make the v1 soft limit knob inert |
| CVE-2026-93241 | await | — | Linux | Linux | — | memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done |
| CVE-2026-93242 | await | — | Linux | Linux | — | scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb() |
| CVE-2026-93243 | await | — | Linux | Linux | — | mm/secretmem: properly account locked pages |
| CVE-2026-93244 | await | — | Linux | Linux | — | drm/sysfb: simpledrm: Improve stride validation |
| CVE-2026-93245 | await | — | Linux | Linux | — | apparmor: policy_int make sure list heads are initialized before fail path |
| CVE-2026-93246 | await | — | Linux | Linux | — | octeontx2-af: fix out-of-bounds read setting MSI-X irq affinity |
| CVE-2026-93247 | await | — | Linux | Linux | — | Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference |
| CVE-2026-93248 | await | — | Linux | Linux | — | drm/xe: don't WARN on kernel job timeout when device already wedged |
| CVE-2026-93249 | await | — | Linux | Linux | — | spi: amlogic-spisg: Make sure clk_init_data is fully initialized |
| CVE-2026-93251 | await | — | Linux | Linux | — | ACPI: bus: Introduce acpi_bus_get_primary_device() |
| CVE-2026-93252 | await | — | Linux | Linux | — | ocfs2: fix circular locking dependency in ocfs2_init_acl() |
| CVE-2026-93253 | await | — | Linux | Linux | — | sched/isolation: Defer freeing of cpumask memblock memory to initcall |
| CVE-2026-93254 | await | — | Linux | Linux | — | arm64: entry: Avoid unnecessary local_irq_disable() on kernel exit |
| CVE-2026-93255 | await | — | Linux | Linux | — | btrfs: make sure EXTENT_BUFFER_READING is cleared under refs_lock |
| CVE-2026-93256 | await | — | Linux | Linux | — | arm64: hibernate: mask DAIF before restoring hibernated kernel |
| CVE-2026-93257 | await | — | Linux | Linux | — | block: handle nogenerate/noverify properly in fs-integrity |
| CVE-2026-93258 | await | — | Linux | Linux | — | ocfs2: do not use make_bad_inode() in ocfs2_read_inode_block_full() |
| CVE-2026-93259 | await | — | Linux | Linux | — | powerpc/irq: Fix missing r2 clobber in PCREL inline assembly |
| CVE-2026-93261 | await | — | Linux | Linux | — | locking/lockdep: Fix NULL pointer dereference in __lock_set_class() |
| CVE-2026-93263 | await | — | Linux | Linux | — | clk: eswin: Zero-initialize stack-allocated clk_init_data |
| CVE-2026-93264 | await | — | Linux | Linux | — | RDMA/efa: Fix PBL chunk length computation |
| CVE-2026-93266 | await | — | Linux | Linux | — | arm64: RSI: fix field-spanning write warning in attestation token init |
| CVE-2026-93267 | await | — | Linux | Linux | — | RDMA/core: Fix potential use after free in uverbs_free_dmah() |
| CVE-2026-93268 | await | — | Linux | Linux | — | ext4: skip extra isize expansion during mount to prevent deadlock |
| CVE-2026-93269 | await | — | Linux | Linux | — | ext4: fix circular lock dependency in ext4_ext_migrate |
| CVE-2026-93270 | await | — | Linux | Linux | — | bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn |
| CVE-2026-93271 | await | — | Linux | Linux | — | wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate |
| CVE-2026-93272 | await | — | Linux | Linux | — | remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3 |
| CVE-2026-93273 | await | — | Linux | Linux | — | regulator: tps6594: Fix device node reference leaks in multiphase loop |
| CVE-2026-93274 | await | — | Linux | Linux | — | pinctrl: bcm2835: Don't remove an unregistered GPIO chip |
| CVE-2026-93275 | await | — | Linux | Linux | — | perf/x86/intel/pt: Fix stop/start with no update |
| CVE-2026-93276 | await | — | Linux | Linux | — | phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled V… |
| CVE-2026-93278 | await | — | Linux | Linux | — | staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown |
| CVE-2026-93279 | await | — | Linux | Linux | — | staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown |
| CVE-2026-93281 | await | — | Linux | Linux | — | wifi: rtw89: fix HE extended capability length check |
| CVE-2026-93283 | await | — | Linux | Linux | — | i3c: master: Fix device_register() error path |
| CVE-2026-93285 | await | — | Linux | Linux | — | f2fs: embed f2fs_gc_kthread in f2fs_sb_info |
| CVE-2026-93286 | await | — | Linux | Linux | — | net: appletalk: fix NULL pointer dereference in aarp_send_ddp() |
| CVE-2026-93781 | await | — | Linux | Linux | — | scsi: core: Do not block on tag allocation in scsi_eh_lock_door() |
| CVE-2026-93783 | await | — | Linux | Linux | — | Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame |
| CVE-2026-93784 | await | — | Linux | Linux | — | wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() |
| CVE-2026-93785 | await | — | Linux | Linux | — | cifs: validate idmap key payload length |
| CVE-2026-93788 | await | — | Linux | Linux | — | wifi: iwlwifi: acpi: validate WGDS table revision index |
| CVE-2026-93789 | await | — | Linux | Linux | — | wifi: iwlwifi: bound aligned TLV advance in FW parser |
| CVE-2026-93791 | await | — | Linux | Linux | — | wifi: iwlwifi: mvm: add a check on the tid coming from the firmware |
| CVE-2026-93792 | await | — | Linux | Linux | — | wifi: iwlwifi: mvm: fix a possible underflow |
| CVE-2026-93794 | await | — | Linux | Linux | — | smb/client: flush dirty data before punching a hole |
| CVE-2026-93795 | await | — | Linux | Linux | — | blk-cgroup: fix leaks and online flag on radix_tree_insert failure |
| CVE-2026-93797 | await | — | Linux | Linux | — | wifi: iwlwifi: mvm: fix an off-by-1 boundary check |
| CVE-2026-93800 | await | — | Linux | Linux | — | btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol() |
| CVE-2026-93802 | await | — | Linux | Linux | — | wifi: rsi: validate beacon length before fixed buffer copy |
| CVE-2026-93803 | await | — | Linux | Linux | — | wifi: libipw: fix key index receive bound checks |
| CVE-2026-93804 | await | — | Linux | Linux | — | wifi: mac80211: ibss: wait for in-flight TX on disconnect |
| CVE-2026-93805 | await | — | Linux | Linux | — | wifi: cfg80211: validate rx/tx MLME callback frame lengths before access |
| CVE-2026-93807 | await | — | Linux | Linux | — | wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers |
| CVE-2026-93808 | await | — | Linux | Linux | — | ALSA: usb-audio: caiaq: validate EP1 reply lengths |
| CVE-2026-93809 | await | — | Linux | Linux | — | drm/amdgpu: flush pending RCU callbacks on module unload |
| CVE-2026-93811 | await | — | Linux | Linux | — | ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling |
| CVE-2026-93812 | await | — | Linux | Linux | — | ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr |
| CVE-2026-93814 | await | — | Linux | Linux | — | spi: core: Abort active target transfer on controller suspend |
| CVE-2026-93815 | await | — | Linux | Linux | — | net: au1000: move free_irq out of the close-time spinlocked section |
| CVE-2026-93818 | await | — | Linux | Linux | — | PCI: plda: Protect root bus removal with rescan lock |
| CVE-2026-93819 | await | — | Linux | Linux | — | PCI: mediatek: Protect root bus removal with rescan lock |
| CVE-2026-93820 | await | — | Linux | Linux | — | PCI: rockchip: Protect root bus removal with rescan lock |
| CVE-2026-93821 | await | — | Linux | Linux | — | PCI: altera: Protect root bus removal with rescan lock |
| CVE-2026-93822 | await | — | Linux | Linux | — | PCI: iproc: Protect root bus removal with rescan lock |
| CVE-2026-93823 | await | — | Linux | Linux | — | drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl |
| CVE-2026-93824 | await | — | Linux | Linux | — | tls: reject the combination of TLS and sockmap |
| CVE-2026-93825 | await | — | Linux | Linux | — | spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data() |
| CVE-2026-93828 | await | — | Linux | Linux | — | exfat: fix handling of damaged volume in exfat_create_upcase_table() |
| CVE-2026-93829 | await | — | Linux | Linux | — | smb: client: fix races in cifsd thread creation |
| CVE-2026-97230 | await | — | — | IO-Socket-SSL-SelfCertificate | CWE-506 | IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware whic… |
| CVE-2026-97407 | await | — | Linux | Linux | — | ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt |
| CVE-2026-97408 | await | — | Linux | Linux | — | Bluetooth: L2CAP: validate connectionless PSM length |
| CVE-2026-97410 | await | — | Linux | Linux | — | netconsole: take target_cleanup_list_lock in drop_netconsole_target() |
| CVE-2026-97411 | await | — | Linux | Linux | — | net: ibm: emac: mal: fix potential system hang in mal_remove() |
| CVE-2026-97412 | await | — | Linux | Linux | — | pds_core: quiesce DMA before freeing resources |
| CVE-2026-97414 | await | — | Linux | Linux | — | ASoC: mediatek: mt8365-afe-pcm: fix possible NULL-pointer dereferences in mt8… |
| CVE-2026-97416 | await | — | Linux | Linux | — | btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk() |
| CVE-2026-97418 | await | — | Linux | Linux | — | ALSA: es18xx: check control allocation before private data setup |
| CVE-2026-97419 | await | — | Linux | Linux | — | hsr: broadcast netlink notifications in the device's net namespace |
| CVE-2026-97420 | await | — | Linux | Linux | — | bpf: NUL-terminate replaced sysctl value |
| CVE-2026-97422 | await | — | Linux | Linux | — | drm/amdkfd: fix SMI event cross-process information leak |
| CVE-2026-97423 | await | — | Linux | Linux | — | cxl/region: Validate partition index before array access |
| CVE-2026-97424 | await | — | Linux | Linux | — | drm/amdgpu/ras: add ras_suspend callback and use it for cp_ecc_error_irq |
| CVE-2026-97425 | await | — | Linux | Linux | — | drm/amdgpu: fix buffer overflow during vBIOS update |
| CVE-2026-97426 | await | — | Linux | Linux | — | drm/amdgpu/pm: fix SmartShift bias sysfs store PM refcount on parse error |
| CVE-2026-97427 | await | — | Linux | Linux | — | drm/amd/pm: bound pp_dpm_set_pp_table() memcpy |
| CVE-2026-97430 | await | — | Linux | Linux | — | xhci: Prevent queuing new commands if xhci is inaccessible |
| CVE-2026-97431 | await | — | Linux | Linux | — | drm/amd/display: Avoid DPMS-on for phantom stream |
| CVE-2026-97432 | await | — | Linux | Linux | — | wifi: iwlwifi: mvm: fix P2P-Device binding handling |
| CVE-2026-97434 | await | — | Linux | Linux | — | dpaa2-switch: fix handling of NAPI on the remove path |
| CVE-2026-97435 | await | — | Linux | Linux | — | net: dsa: sja1105: flower: reject cross-chip redirect |
| CVE-2026-97436 | await | — | Linux | Linux | — | dpaa2-switch: rework FDB management on the bridge leave path |
| CVE-2026-97439 | await | — | Linux | Linux | — | fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib |
| CVE-2026-97440 | await | — | Linux | Linux | — | net: qrtr: fix node refcount leak on ctrl packet alloc failure |
| CVE-2026-97441 | await | — | Linux | Linux | — | ata: ahci: fail probe if BAR too small for claimed ports |
| CVE-2026-97443 | await | — | Linux | Linux | — | perf/ftrace: Fix WARNING in __unregister_ftrace_function |
| CVE-2026-97446 | await | — | Linux | Linux | — | ACPICA: Fix NULL pointer dereference in acpi_ns_custom_package() |
| CVE-2026-97447 | await | — | Linux | Linux | — | ACPICA: Enhance OEM ID and Table ID validation in acpi_ex_load_table_op() |
| CVE-2026-97449 | await | — | Linux | Linux | — | ACPICA: Add package limit checks in parser functions |
| CVE-2026-97453 | await | — | Linux | Linux | — | ACPICA: validate byte_count in acpi_ps_get_next_package_length() |
| CVE-2026-97456 | await | — | Linux | Linux | — | ACPICA: Fix condition check in acpi_ps_parse_loop() |
| CVE-2026-97472 | await | — | Linux | Linux | — | ipv6: addrconf: fix temp address generation after prefix deprecation |
| CVE-2026-97473 | await | — | Linux | Linux | — | powercap: intel_rapl: Fix memory leak in rapl_add_package_cpuslocked() |
| CVE-2026-97475 | await | — | Linux | Linux | — | thermal/drivers/tegra/soctherma: Switch to devm cooling device registration |
| CVE-2026-97476 | await | — | Linux | Linux | — | rds: filter RDS_INFO_* getsockopt by caller's netns |
| CVE-2026-97477 | await | — | Linux | Linux | — | RDMA/counter: Fix num_counters leak on bind_qp failure in alloc_and_bind() |
| CVE-2026-97479 | await | — | Linux | Linux | — | driver core: Avoid warning when removing a device while its supplier is unbin… |
| CVE-2026-97480 | await | — | Linux | Linux | — | tty: serial: 8250: protect against NULL uart->port.dev in register |
| CVE-2026-97481 | await | — | Linux | Linux | — | serial: 8250: fix possible ISR soft lockup |
| CVE-2026-97482 | await | — | Linux | Linux | — | usb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log |
| CVE-2026-97483 | await | — | Linux | Linux | — | usb: core: hcd: fix possible deadlock in rh control transfers |
| CVE-2026-97484 | await | — | Linux | Linux | — | usbip: vhci_hcd: fix NULL deref in status_show_vhci |
| CVE-2026-97485 | await | — | Linux | Linux | — | omfs: handle set_blocksize failures |
| CVE-2026-97486 | await | — | Linux | Linux | — | hpfs: handle set_blocksize failures |
| CVE-2026-97487 | await | — | Linux | Linux | — | jfs: handle set_blocksize failures |
| CVE-2026-97488 | await | — | Linux | Linux | — | qnx4: handle set_blocksize failures |
| CVE-2026-97489 | await | — | Linux | Linux | — | bfs: handle set_blocksize failures |
| CVE-2026-97490 | await | — | Linux | Linux | — | affs: handle set_blocksize failures |
| CVE-2026-97491 | await | — | Linux | Linux | — | net/rds: Don't sleep inside rds_ib_conn_path_shutdown |
| CVE-2026-97492 | await | — | Linux | Linux | — | wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed |
| CVE-2026-97493 | await | — | Linux | Linux | — | drm/amdgpu: Bound GPIO I2C table entry count from VBIOS |
| CVE-2026-97494 | await | — | Linux | Linux | — | drm/amdgpu: validate and share PSP fw_pri_buf copies via psp_copy_fw |
| CVE-2026-97495 | await | — | Linux | Linux | — | drm/amdkfd: Check bounds on allocate_doorbell |
| CVE-2026-97498 | await | — | Linux | Linux | — | drm/amdgpu/userq: pin mqd and fw object bo to avoid eviction |
| CVE-2026-97499 | await | — | Linux | Linux | — | coresight: perf: Retrieve path and source from event data |
| CVE-2026-97500 | await | — | Linux | Linux | — | wifi: rtw89: phy: check length before parsing PHY status IE |
| CVE-2026-97501 | await | — | Linux | Linux | — | pinctrl: mediatek: paris: bypass pinctrl GPIO layer in set GPIO direction |
| CVE-2026-97502 | await | — | Linux | Linux | — | mmc: davinci: avoid NULL deref of host->data in IRQ handler |
| CVE-2026-97503 | await | — | Linux | Linux | — | genirq/proc: Size interrupt directory names for 10-digit interrupt numbers |
| CVE-2026-97504 | await | — | Linux | Linux | — | watchdog: lenovo_se10_wdt: Fix use-after-free and resource leak risk |
| CVE-2026-97505 | await | — | Linux | Linux | — | PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store() |
| CVE-2026-97506 | await | — | Linux | Linux | — | crypto: ixp4xx - fix buffer chain unwind on allocation failure |
| CVE-2026-97507 | await | — | Linux | Linux | — | media: dm1105: fix missing error check for dma_alloc_coherent |
| CVE-2026-97510 | await | — | Linux | Linux | — | thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_respon… |
| CVE-2026-97511 | await | — | Linux | Linux | — | wifi: mac80211: avoid out-of-bounds access in monitor |
| CVE-2026-97512 | await | — | Linux | Linux | — | spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM |
| CVE-2026-97514 | await | — | Linux | Linux | — | media: chips-media: wave5: Fix Reports from Kernel Lock Validator |
| CVE-2026-97515 | await | — | Linux | Linux | — | i3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845 |
| CVE-2026-97516 | await | — | Linux | Linux | — | wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result() |
| CVE-2026-97517 | await | — | Linux | Linux | — | wifi: nl80211: reject beacons with bad HE operation |
| CVE-2026-97518 | await | — | Linux | Linux | — | wifi: cfg80211: reject duplicate wiphy cipher suite entries |
| CVE-2026-97519 | await | — | Linux | Linux | — | drm/xe: Fix null pointer dereference in devcoredump cleanup |
| CVE-2026-97521 | await | — | Linux | Linux | — | gfs2: fix quota init duplicate scan |
| CVE-2026-97636 | await | — | Apache Software Foundation | Apache Airflow HashiCorp provider | CWE-639 | Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scop… |