boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, September 25, 2026 · all times UTC← 2026-09-24 · archive

Security Box Score — September 25, 2026 — page 2

Edition of September 25, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–681 of 681
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-97553await—LinuxLinux—xfs: lock the healthmon when inserting unmount event
CVE-2026-97554await—LinuxLinux—smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()
CVE-2026-97556await—LinuxLinux—smb: client: avoid leaking refcount when cifs_sb_tlink() fails
CVE-2026-97558await—LinuxLinux—smb: client: fix cifsFileInfo reference leak in deferred close
CVE-2026-97559await—LinuxLinux—smb: client: fail DACL rewrite when the new DACL exceeds 64K
CVE-2026-97560await—LinuxLinux—smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
CVE-2026-97561await—LinuxLinux—smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid
CVE-2026-97563await—LinuxLinux—smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()
CVE-2026-97564await—LinuxLinux—smb: client: reject userspace cifs.idmap descriptions
CVE-2026-97565await—LinuxLinux—smb: client: reject short READ responses in CIFSSMBRead()
CVE-2026-97566await—LinuxLinux—mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0
CVE-2026-97567await—LinuxLinux—mptcp: prevent race between disconnect() and rtx
CVE-2026-97568await—LinuxLinux—mptcp: syncookies: remember the request backup flag
CVE-2026-97569await—LinuxLinux—bnxt_en: Prevent queue stop with deferred completions
CVE-2026-97571await—LinuxLinux—bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc()
CVE-2026-97572await—LinuxLinux—bnxt_en: Propagate RX ring init failures in bnxt_init_nic()
CVE-2026-97574await—LinuxLinux—bnxt_en: Don't free the live ring's TPA state on queue restart failure
CVE-2026-97581await—LinuxLinux—media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity
CVE-2026-97582await—LinuxLinux—hwmon: (gpio-fan) Fix use-after-free in alarm work
CVE-2026-97585await—LinuxLinux—afs: Fix double-unmap of directory block
CVE-2026-97586await—LinuxLinux—afs: Fix missing kunmap in afs_dir_search_bucket()
CVE-2026-97587await—LinuxLinux—perf: RISC-V: store available counter mask as bitmap
CVE-2026-97588await—LinuxLinux—s390/crypto: Map EBUSY to EIO when key conversion fails repeatedly
CVE-2026-97590await—LinuxLinux—s390/crypto: Fix missing scrub of temp buffers with PAES algorithm
CVE-2026-97591await—LinuxLinux—s390/crypto: Fix handling of EBUSY in PHMAC when req is pushed to crypto engine
CVE-2026-97592await—LinuxLinux—s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm
CVE-2026-97593await—LinuxLinux—iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX
CVE-2026-97596await—LinuxLinux—ipvs: reject invalid states in connection template sync records
CVE-2026-97597await—LinuxLinux—ipv6: flowlabel: cap duplicate leases per socket
CVE-2026-97598await—LinuxLinux—ipv4: fib: bound automatic table ID allocation
CVE-2026-97599await—LinuxLinux—ieee802154: hwsim: serialize pib updates to fix double-free
CVE-2026-97600await—LinuxLinux—ieee802154: cc2520: fix FIFOP work use-after-free
CVE-2026-97601await—LinuxLinux—ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink
CVE-2026-97603await—LinuxLinux—idpf: disable DIM work before freeing q_vectors
CVE-2026-97604await—LinuxLinux—fbdev: vfb: defer cleanup until the last reference
CVE-2026-97605await—LinuxLinux—erofs: preserve LZMA decoders on resize failure
CVE-2026-97606await—LinuxLinux—fs: autofs: fix memory leak in autofs_fill_super()
CVE-2026-97607await—LinuxLinux—vdpa: ifcvf: Put device on unsupported feature error
CVE-2026-97610await—LinuxLinux—netfs: Fix uninitialized return value in netfs_unbuffered_write()
CVE-2026-97613await—LinuxLinux—net: mana: Reserve extra CQ slot for the fence completion CQE
CVE-2026-97614await—LinuxLinux—net: dsa: tag_brcm: legacy FCS: request needed tailroom
CVE-2026-97615await—LinuxLinux—net: bridge: use option bits for CFM/MRP frame handlers
CVE-2026-97616await—LinuxLinux—net/sched: act_api: release all action references on NEWACTION failure
CVE-2026-97617await—LinuxLinux—ring-buffer: Check resize_disabled before publishing the new subbuf order
CVE-2026-97618await—LinuxLinux—io_uring/net: don't overconsume buffers when using MSG_TRUNC
CVE-2026-97619await—LinuxLinux—io_uring/rw: end write accounting from ->ki_complete
CVE-2026-97620await—LinuxLinux—drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches
CVE-2026-97621await—LinuxLinux—drm/rockchip: analogix_dp: fix unchecked bound endpoint name length
CVE-2026-97899await—LinuxLinux—drm/i915: Fix memory leak in query_perf_config_list()
CVE-2026-97900await—LinuxLinux—drm/drm_exec: fix up contended obj when num_objects is 0
CVE-2026-97901await—LinuxLinux—genetlink: pin family module during policy dump
CVE-2026-97902await—LinuxLinux—fs: don't return -EINVAL for successful nested thaw
CVE-2026-97904await—LinuxLinux—cpufreq: initialize policy rwsem before sysfs publication
CVE-2026-97905await—LinuxLinux—cpufreq: zero-initialize policy cpumask before sysfs publication
CVE-2026-97906await—LinuxLinux—bootconfig: Fix integer overflow in initrd size check
CVE-2026-97907await—LinuxLinux—Bluetooth: btrtl: Don't leak return code when parsing firmware format v2
CVE-2026-97908await—LinuxLinux—Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev
CVE-2026-97909await—LinuxLinux—ASoC: sti: initialize IRQ lock before requesting IRQ
CVE-2026-97912await—LinuxLinux—accel: ethosu: Ensure SRAM size is 0 on mapping failure
CVE-2026-97913await—LinuxLinux—accel: ethosu: Ensure cmd stream ends with a stop op
CVE-2026-97914await—LinuxLinux—accel: ethosu: Fix ethosu_job_open() return value
CVE-2026-97915await—LinuxLinux—accel/ivpu: Limit firmware log name prints to field size
CVE-2026-97916await—LinuxLinux—accel/ivpu: Validate firmware log buffer metadata
CVE-2026-97917await—LinuxLinux—accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr
CVE-2026-97918await—LinuxLinux—tracing: Undo the registration when enabling the histogram trigger fails
CVE-2026-97919await—LinuxLinux—tracing: Take the reference before publishing the named histogram trigger
CVE-2026-97920await—LinuxLinux—tracing: Keep the entry count when the histogram stats allocation fails
CVE-2026-97921await—LinuxLinux—tracing: Free histogram the field rejected for a bad modifier
CVE-2026-97922await—LinuxLinux—tracing: Free histogram var refs regardless of how often they are referenced
CVE-2026-97923await—LinuxLinux—tracing: Free histogram the var ref when its initialization fails
CVE-2026-97924await—LinuxLinux—tracing/user_events: Don't destroy fields when event removal fails
CVE-2026-97925await—LinuxLinux—tick/broadcast: Plug clockevents replacement race
CVE-2026-97927await—LinuxLinux—ufs: create the root dentry after loading cylinder metadata
CVE-2026-97928await—LinuxLinux—drm/amdgpu: skip the VMID 0 flush for VRAM
CVE-2026-97929await—LinuxLinux—ALSA: usbusx2y: validate URB actual_length in interrupt callback
CVE-2026-97930await—LinuxLinux—ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf
CVE-2026-97932await—LinuxLinux—tracing: Don't dereference trace_event_file in deferred trigger free
CVE-2026-97933await—LinuxLinux—tracing: Take trace_array reference when opening a tracer options file
CVE-2026-97934await—LinuxLinux—tracing: Fix memory corruption from a "STACKTRACE" histogram key
CVE-2026-97935await—LinuxLinux—tracing: Set the trace clock before registering the histogram trigger
CVE-2026-97936await—LinuxLinux—tracing: Fix memory corruption from the histogram stacktrace modifier
CVE-2026-97938await—LinuxLinux—reboot: fix cad_pid use-after-free race
CVE-2026-97939await—LinuxLinux—ipmr: account multicast table and route memory
CVE-2026-97942await—LinuxLinux—x86/alternatives: Exclude text poking against change_page_attr()
CVE-2026-97943await—LinuxLinux—x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF
CVE-2026-97944await—LinuxLinux—x86/cfi: Fix FineIBT hash offset in cfi_get_func_hash()
CVE-2026-97945await—LinuxLinux—x86/mm: Fix user-space data loss with MADV_FREE and THP
CVE-2026-97946await—LinuxLinux—x86/amd_node: Fix PCI device reference counting in amd_smn_init()
CVE-2026-97947await—LinuxLinux—x86/amd_node: Fix potential NULL pointer dereference
CVE-2026-97948await—LinuxLinux—powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver
CVE-2026-97949await—LinuxLinux—configfs: unhash the dentry before dropping the item in rmdir
CVE-2026-97950await—LinuxLinux—configfs: pin the symlink target's dirent instead of chasing ->ci_dentry
CVE-2026-97951await—LinuxLinux—scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands
CVE-2026-97952await—LinuxLinux—sunvdc: unmap LDC cookies when the descriptor send fails
CVE-2026-97954await—LinuxLinux—net/rds: fix tcp stream corruption with large pages
CVE-2026-97955await—LinuxLinux—net: mana: restore the XDP program pointer when pre-allocation fails
CVE-2026-97956await—LinuxLinux—net: net_failover: Fix the deadlock in net_failover_slave_name_change()
CVE-2026-97958await—LinuxLinux—net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain().
CVE-2026-97959await—LinuxLinux—net/sched: cls_route: free emptied bucket on filter move
CVE-2026-97960await—LinuxLinux—perf/x86/intel: Prevent drain_pebs() reentry
CVE-2026-97961await—LinuxLinux—perf/core: Allow list_del during perf_event_overflow()
CVE-2026-97962await—LinuxLinux—net/mlx5e: Move representor vnic reporter to eswitch devlink port
CVE-2026-97963await—LinuxLinux—net: stmmac: initialize ptp_lock at probe time
CVE-2026-97964await—LinuxLinux—ppp_synctty: ensure a writeable skb header
CVE-2026-97965await—LinuxLinux—vxlan: initialize _md in vxlan_xmit_one()
CVE-2026-97966await—LinuxLinux—octeontx2-pf: reset HTB scheduler topology before freeing queues
CVE-2026-97967await—LinuxLinux—hwmon: (corsair-cpro) Remove debugfs entries when probe fails
CVE-2026-97968await—LinuxLinux—hwmon: (corsair-cpro) Create debugfs entries after hwmon registration
CVE-2026-97969await—LinuxLinux—watchdog: msc313e: Fix clock leak and spurious timer in settimeout()
CVE-2026-97970await—LinuxLinux—watchdog: msc313e: Avoid division by zero
CVE-2026-97972await—LinuxLinux—net: macb: put the "mdio" child node reference on success
CVE-2026-97973await—LinuxLinux—net: macb: destroy the phylink instance on the probe error path
CVE-2026-97974await—LinuxLinux—ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings()
CVE-2026-97975await—LinuxLinux—Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del()
CVE-2026-97976await—LinuxLinux—Bluetooth: btintel_pcie: validate packet_len before skb_put_data
CVE-2026-97977await—LinuxLinux—Bluetooth: btusb: Fix UAF of btusb_data by rx_work
CVE-2026-97978await—LinuxLinux—eth: ice: don't dereference pointers from TP_printk()
CVE-2026-97979await—LinuxLinux—ice: add missing xa_destroy for sched_node_ids
CVE-2026-97980await—LinuxLinux—s390/debug: Fix NULL pointer dereference in debug_set_level()
CVE-2026-97981await—LinuxLinux—net: ethernet: cortina: Count dropped frames as NAPI work
CVE-2026-97982await—LinuxLinux—net: ethernet: cortina: Fix budget accounting
CVE-2026-97983await—LinuxLinux—vduse: return compat ioctl results directly
CVE-2026-97984await—LinuxLinux—net: ipv6: Fix UDP length overflow with PMTU discover and big MTU
CVE-2026-97985await—LinuxLinux—af_unix: Update last skb marker in manage_oob().
CVE-2026-97986await—LinuxLinux—virtio_input: stop callbacks before unregistering input device
CVE-2026-97987await—LinuxLinux—virtio_input: reset device if input_register_device() fails
CVE-2026-97988await—LinuxLinux—vhost: invalidate vring access on IOTLB transitions
CVE-2026-97989await—LinuxLinux—vduse: validate virtqueue alignment
CVE-2026-97992await—LinuxLinux—vhost-vdpa: protect config_ctx from being freed under the config callback
CVE-2026-97993await—LinuxLinux—vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx
CVE-2026-97994await—LinuxLinux—vhost/vdpa: reject VRING_NUM larger than device max
CVE-2026-97995await—LinuxLinux—virtio_console: do not free control-out buffers on remove
CVE-2026-97996await—LinuxLinux—virtio: fix use-after-free in unregister_virtio_device()
CVE-2026-97997await—LinuxLinux—virtio_ring: fix stale descriptor flags after a failed packed add
CVE-2026-97998await—LinuxLinux—netfilter: nfnetlink_log: cope with concurrent instance destruction
CVE-2026-98000await—LinuxLinux—hwmon: Fix potential UAF in pec_store
CVE-2026-98001await—LinuxLinux—hwmon: (ltc4282) Make sure clk_init_data is fully initialized
CVE-2026-98003await—LinuxLinux—iommu/amd: Do not reallocate GA log buffers on resume
CVE-2026-98004await—LinuxLinux—iommu/riscv: Serialize command queue publishing
CVE-2026-98005await—LinuxLinux—erofs: delimit inode_share cache key components
CVE-2026-98006await—LinuxLinux—ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev
CVE-2026-98007await—LinuxLinux—bpf: Reject non-scalar bpf_loop iteration counts
CVE-2026-98008await—LinuxLinux—net: macb: fix NULL pointer dereference on unbind with fixed-link
CVE-2026-98009await—LinuxLinux—net/sched: ets: clamp quantum in parse and fallback paths
CVE-2026-98010await—LinuxLinux—net/sched: drr: clamp quantum in change class
CVE-2026-98011await—LinuxLinux—net/sched: hhf: clamp quantum in change and init paths
CVE-2026-98012await—LinuxLinux—net/sched: sfq: clamp quantum in change path
CVE-2026-98013await—LinuxLinux—net/sched: fq_pie: clamp quantum in change path
CVE-2026-98014await—LinuxLinux—net/mlx5: E-Switch, prevent mc_list repopulation during vport disable
CVE-2026-98015await—LinuxLinux—net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put
CVE-2026-98016await—LinuxLinux—net/mlx5e: Fix use-after-free race in sample_restore_put()
CVE-2026-98018await—LinuxLinux—net: mctp: i3c: serialize probe with bus removal
CVE-2026-98019await—LinuxLinux—bpf: mark a NULL call argument precise
CVE-2026-98020await—LinuxLinux—pds_core: fix cmd_regs access racing BAR unmap on reset
CVE-2026-98021await—LinuxLinux—net: reject oversized tx_queue_len at netlink parse time
CVE-2026-98022await—LinuxLinux—net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations
CVE-2026-98024await—LinuxLinux—s390/ism: folio_put() after error
CVE-2026-98025await—LinuxLinux—net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent parti…
CVE-2026-98026await—LinuxLinux—net: bridge: mcast: properly convert mglist to rcu
CVE-2026-98028await—LinuxLinux—eth: nfp: drop the replaced rule from the list when reprogramming fails
CVE-2026-98031await—LinuxLinux—nexthop: Initialize extack in remove_nh_grp_entry()
CVE-2026-98032await—LinuxLinux—tracing: Fix subbuf resize races with trace_pipe_raw readers
CVE-2026-98033await—LinuxLinux—bpf: Preserve inner map identity in callback frames
CVE-2026-98034await—LinuxLinux—bpf: Mark NULL kptr stores precise
CVE-2026-98035await—LinuxLinux—bpf: Cancel special fields when recycling rhtab elements
CVE-2026-98036await—LinuxLinux—bpf: Preserve special fields in recycled rhtab elements
CVE-2026-98037await—LinuxLinux—bpf: Reject untrusted allocated-object pointers
CVE-2026-98038await—LinuxLinux—bpf: Keep refcount_acquire nullable for borrowed RCU kptrs
CVE-2026-98039await—LinuxLinux—bpf: Require MEM_PERCPU for percpu kptr stores
CVE-2026-98040await—LinuxLinux—bpf: Mark the zero register precise for a register-form NULL check
CVE-2026-98042await—LinuxLinux—bpf: Don't resurrect a scalar id dropped by collect_linked_regs()
CVE-2026-98043await—LinuxLinux—bpf: Don't infer non-NULL from a pointer with an unbounded offset
CVE-2026-98044await—LinuxLinux—bpf: Reject legacy packet loads from callbacks
CVE-2026-98045await—LinuxLinux—bpf: Mark faultable stack helpers as sleepable
CVE-2026-98046await—LinuxLinux—bpf: Mark bpf_btf_find_by_name_kind() as sleepable
CVE-2026-98047await—LinuxLinux—bpf: Check ancestor frames for rbtree callbacks
CVE-2026-98048await—LinuxLinux—bpf: don't rewrite bpf_fastcall patterns entered by a jump
CVE-2026-98049await—LinuxLinux—bpf: zero extend the result of an arena 32-bit cmpxchg
CVE-2026-98051await—LinuxLinux—net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times
CVE-2026-98053await—LinuxLinux—ASoC: Intel: avs: Refactor and fix init_config access
CVE-2026-98054await—LinuxLinux—ASoC: Intel: avs: Fix unbalanced module reference count
CVE-2026-98055await—LinuxLinux—ASoC: Intel: avs: Clean up the bus when fetching ML caps fails
CVE-2026-98057await—LinuxLinux—ring-buffer: Add checking nr_subbufs to persistent ring buffer validation
CVE-2026-98058await—LinuxLinux—bpf: Mark syscall helpers as sleepable
CVE-2026-98059await—LinuxLinux—bpf: Mark sched_process_wait argument as nullable
CVE-2026-98060await—LinuxLinux—bpf: Reject resilient lock operations in rbtree callbacks
CVE-2026-98061await—LinuxLinux—bpf: Reject tail calls directly from callback frames
CVE-2026-98062await—LinuxLinux—bpf: Mark signal tracepoint siginfo arguments as scalar
CVE-2026-98063await—LinuxLinux—bpf: Fix NULL-ptr-deref in btf_var_show()
CVE-2026-98064await—LinuxLinux—bpf: Fix NULL-ptr-deref when showing a void BTF type
CVE-2026-98065await—LinuxLinux—bpf: Reject key-less BTF for hash maps
CVE-2026-98066await—LinuxLinux—ALSA: caiaq: Fix potential double-free at error path
CVE-2026-98067await—LinuxLinux—erofs: disable LZ4 rolling decompression for now
CVE-2026-98068await—LinuxLinux—net/rds: don't let rds_conn_shutdown() consume a concurrent drop
CVE-2026-98071await—LinuxLinux—net/rds: clear cp_flags bits individually in rds_conn_path_reset()
CVE-2026-98072await—LinuxLinux—net/rds: use wq_has_sleeper() in release_in_xmit()
CVE-2026-98074await—LinuxLinux—bonding: do not clear curr_active_slave prematurely when releasing all slaves
CVE-2026-98075await—LinuxLinux—bpf: reject BPF_PSEUDO_FUNC reference to the main program
CVE-2026-98076await—LinuxLinux—tracing/probes: Fix use-after-free on field name/type of events with multiple…
CVE-2026-98077await—LinuxLinux—netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace()
CVE-2026-98078await—LinuxLinux—ipvs: fix reversed sequence option serialization
CVE-2026-98079await—LinuxLinux—btrfs: zstd: fix lost wakeup when waiting for a workspace
CVE-2026-98080await—LinuxLinux—btrfs: do not force reloc root creation during qgroup_account_snapshot()
CVE-2026-98081await—LinuxLinux—btrfs: zoned: finish active block group cleanup if call_zone_finish() fails
CVE-2026-98082await—LinuxLinux—btrfs: fix the possible bioc_list memory leak during error
CVE-2026-98084await—LinuxLinux—bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks
CVE-2026-98085await—LinuxLinux—bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge
CVE-2026-98086await—LinuxLinux—ALSA: ump: do not touch legacy_rmidi before it exists
CVE-2026-98087await—LinuxLinux—sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate
CVE-2026-98088await—LinuxLinux—scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_rep…
CVE-2026-98089await—LinuxLinux—bonding: alb: fix uninitialized transport header access in alb_determine_nd()
CVE-2026-98090await—LinuxLinux—btrfs: restore active device pointers after failed sprout
CVE-2026-98091await—LinuxLinux—btrfs: detach failed sprout device from transaction update list
CVE-2026-98092await—LinuxLinux—ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close()
CVE-2026-98093await—LinuxLinux—ASoC: fsl_micfil: balance mclk enable/disable
CVE-2026-98094await—LinuxLinux—staging: fbtft: make dirty_lock IRQ-safe
CVE-2026-98095await—LinuxLinux—af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header().
CVE-2026-98097await—LinuxLinux—tipc: Dont send random pad bytes in RESET/ACTIVATE messages
CVE-2026-98098await—LinuxLinux—tipc: fix NULL deref in tipc_named_node_up() on empty publication list
CVE-2026-98099await—LinuxLinux—ipv6: mcast: use rcu_assign_pointer() for __rcu list updates
CVE-2026-98101await—LinuxLinux—ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source()
CVE-2026-98102await—LinuxLinux—ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src()
CVE-2026-98103await—LinuxLinux—igmp: convert struct ip_sf_list to RCU
CVE-2026-98104await—LinuxLinux—net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted
CVE-2026-98105await—LinuxLinux—net: ethernet: oa_tc6: Improve the error recovery
CVE-2026-98106await—LinuxLinux—drm/pagemap: Prevent double migration of device pages
CVE-2026-98107await—LinuxLinux—Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect
CVE-2026-98109await—LinuxLinux—Bluetooth: hci_core: Fix race condition during device registration
CVE-2026-98110await—LinuxLinux—Bluetooth: btintel: bound firmware ID by TLV length
CVE-2026-98111await—LinuxLinux—Bluetooth: btintel: validate version TLV value lengths
CVE-2026-98113await—LinuxLinux—ksmbd: rate limit unmapped SID errors
CVE-2026-98114await—LinuxLinux—ksmbd: propagate DACL parsing errors
CVE-2026-98117await—LinuxLinux—cachefiles: Fix potential UAF/KASAN warning
CVE-2026-98118await—LinuxLinux—netfs: Fix readahead synchronisation issues by loading all folios upfront
CVE-2026-98119await—LinuxLinux—netfs: break unbuffered write when netfs_alloc_subrequest() fails
CVE-2026-98120await—LinuxLinux—netfs: Fix subreq ref leak
CVE-2026-98121await—LinuxLinux—watchdog: msc313e: Fix NULL pointer dereference in PM callbacks
CVE-2026-98123await—LinuxLinux—sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration
CVE-2026-98124await—LinuxLinux—smb/client: invalidate fscache for fallocate range operations
CVE-2026-98125await—LinuxLinux—smb/client: fix stale page cache in insert/collapse range
CVE-2026-98126await—LinuxLinux—smb/client: validate new EOF for zero range
CVE-2026-98127await—LinuxLinux—smb/client: validate new EOF for insert range
CVE-2026-98128await—LinuxLinux—scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add()
CVE-2026-98129await—LinuxLinux—scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add()
CVE-2026-98131await—LinuxLinux—net: stmmac: fix dma mapping leak in stmmac_tso_xmit()
CVE-2026-98132await—LinuxLinux—bpf: don't downgrade half-dead scalar zero spills to STACK_ZERO
CVE-2026-98133await—LinuxLinux—ntfs: leave HasEA flag untouched on setxattr failure
CVE-2026-98134await—LinuxLinux—bpf: check_cond_jmp_op(): properly infer if register is null
CVE-2026-98135await—LinuxLinux—ntfs: reject invalid sectors_per_cluster in the boot sector
CVE-2026-98136await—LinuxLinux—ntfs: bound $AttrDef table walk to the loaded table size
CVE-2026-98137await—LinuxLinux—ntfs: treat any nonzero dio zero-range return as an error
CVE-2026-98138await—LinuxLinux—ntfs: do not mark the volume clean in sync_fs when errors were recorded
CVE-2026-98139await—LinuxLinux—ntfs: only count successfully cleared runs when freeing clusters
CVE-2026-98140await—LinuxLinux—ntfs: fix kmap_local leak in write_mft_record_nolock() error paths
CVE-2026-98141await—LinuxLinux—ntfs: propagate reparse index insertion failure
CVE-2026-98142await—LinuxLinux—drm/cirrus-qemu: Validate BAR0 size during probe
CVE-2026-98144await—LinuxLinux—accel/amdxdna: put the chained BO when its mapping fails
CVE-2026-98145await—LinuxLinux—accel/amdxdna: reject a command chain that carries no commands
CVE-2026-98146await—LinuxLinux—accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain
CVE-2026-98147await—LinuxLinux—printk: Don't WARN on kthread_run failure.
CVE-2026-98148await—LinuxLinux—drm/gud: validate GUD_ROTATION_0 is present in supported rotations
CVE-2026-98149await—LinuxLinux—bpf: Fix percpu map update indexing with sparse CPU IDs
CVE-2026-98151await—LinuxLinux—bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic
CVE-2026-98152await—LinuxLinux—nvmet-rdma: fix queue leak when connect backlog is exceeded
CVE-2026-98153await—LinuxLinux—nvme: fix racy access to FDP placement id array
CVE-2026-98155await—LinuxLinux—accel/qaic: Address potential out-of-bounds read in resp_worker()
CVE-2026-98157await—LinuxLinux—EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation
CVE-2026-98158await—LinuxLinux—ppp_async: drop the errored frame instead of resetting its headroom
CVE-2026-98159await—LinuxLinux—wifi: mt76: mt7921: validate CLC firmware records
CVE-2026-98160await—LinuxLinux—staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()
CVE-2026-98161await—LinuxLinux—nvdimm: pmem: keep PREFLUSH before data writes
CVE-2026-98162await—LinuxLinux—smb/server: fix tree connection leak in smb2_tree_connect()
CVE-2026-100070await—LinuxLinux—netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet
CVE-2026-100071await—LinuxLinux—net: hsr: free learned nodes on device setup failure
CVE-2026-100072await—LinuxLinux—ACPI: platform: Use acpi_bus_get_primary_device()
CVE-2026-100073await—LinuxLinux—ext4: fix transaction overflow during writeback
CVE-2026-100074await—LinuxLinux—bpf: Mark bpf_refcount field as unique
CVE-2026-100076await—LinuxLinux—staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths
CVE-2026-100077await—LinuxLinux—drm/msm: Recover HW before retire hung submit
CVE-2026-100078await—LinuxLinux—wifi: iwlwifi: mei: pass correct argument to function
CVE-2026-100079await—LinuxLinux—usb: typec: ucsi: unregister debugfs entries on teardown