Security Box Score — September 25, 2026 — page 2
Edition of September 25, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-97553 | await | — | Linux | Linux | — | xfs: lock the healthmon when inserting unmount event |
| CVE-2026-97554 | await | — | Linux | Linux | — | smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr() |
| CVE-2026-97556 | await | — | Linux | Linux | — | smb: client: avoid leaking refcount when cifs_sb_tlink() fails |
| CVE-2026-97558 | await | — | Linux | Linux | — | smb: client: fix cifsFileInfo reference leak in deferred close |
| CVE-2026-97559 | await | — | Linux | Linux | — | smb: client: fail DACL rewrite when the new DACL exceeds 64K |
| CVE-2026-97560 | await | — | Linux | Linux | — | smb: client: fix one-byte OOB read in smb2_parse_native_symlink() |
| CVE-2026-97561 | await | — | Linux | Linux | — | smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid |
| CVE-2026-97563 | await | — | Linux | Linux | — | smb: client: reject out-of-bounds DataOffset in CIFSSMBRead() |
| CVE-2026-97564 | await | — | Linux | Linux | — | smb: client: reject userspace cifs.idmap descriptions |
| CVE-2026-97565 | await | — | Linux | Linux | — | smb: client: reject short READ responses in CIFSSMBRead() |
| CVE-2026-97566 | await | — | Linux | Linux | — | mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0 |
| CVE-2026-97567 | await | — | Linux | Linux | — | mptcp: prevent race between disconnect() and rtx |
| CVE-2026-97568 | await | — | Linux | Linux | — | mptcp: syncookies: remember the request backup flag |
| CVE-2026-97569 | await | — | Linux | Linux | — | bnxt_en: Prevent queue stop with deferred completions |
| CVE-2026-97571 | await | — | Linux | Linux | — | bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc() |
| CVE-2026-97572 | await | — | Linux | Linux | — | bnxt_en: Propagate RX ring init failures in bnxt_init_nic() |
| CVE-2026-97574 | await | — | Linux | Linux | — | bnxt_en: Don't free the live ring's TPA state on queue restart failure |
| CVE-2026-97581 | await | — | Linux | Linux | — | media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity |
| CVE-2026-97582 | await | — | Linux | Linux | — | hwmon: (gpio-fan) Fix use-after-free in alarm work |
| CVE-2026-97585 | await | — | Linux | Linux | — | afs: Fix double-unmap of directory block |
| CVE-2026-97586 | await | — | Linux | Linux | — | afs: Fix missing kunmap in afs_dir_search_bucket() |
| CVE-2026-97587 | await | — | Linux | Linux | — | perf: RISC-V: store available counter mask as bitmap |
| CVE-2026-97588 | await | — | Linux | Linux | — | s390/crypto: Map EBUSY to EIO when key conversion fails repeatedly |
| CVE-2026-97590 | await | — | Linux | Linux | — | s390/crypto: Fix missing scrub of temp buffers with PAES algorithm |
| CVE-2026-97591 | await | — | Linux | Linux | — | s390/crypto: Fix handling of EBUSY in PHMAC when req is pushed to crypto engine |
| CVE-2026-97592 | await | — | Linux | Linux | — | s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm |
| CVE-2026-97593 | await | — | Linux | Linux | — | iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX |
| CVE-2026-97596 | await | — | Linux | Linux | — | ipvs: reject invalid states in connection template sync records |
| CVE-2026-97597 | await | — | Linux | Linux | — | ipv6: flowlabel: cap duplicate leases per socket |
| CVE-2026-97598 | await | — | Linux | Linux | — | ipv4: fib: bound automatic table ID allocation |
| CVE-2026-97599 | await | — | Linux | Linux | — | ieee802154: hwsim: serialize pib updates to fix double-free |
| CVE-2026-97600 | await | — | Linux | Linux | — | ieee802154: cc2520: fix FIFOP work use-after-free |
| CVE-2026-97601 | await | — | Linux | Linux | — | ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink |
| CVE-2026-97603 | await | — | Linux | Linux | — | idpf: disable DIM work before freeing q_vectors |
| CVE-2026-97604 | await | — | Linux | Linux | — | fbdev: vfb: defer cleanup until the last reference |
| CVE-2026-97605 | await | — | Linux | Linux | — | erofs: preserve LZMA decoders on resize failure |
| CVE-2026-97606 | await | — | Linux | Linux | — | fs: autofs: fix memory leak in autofs_fill_super() |
| CVE-2026-97607 | await | — | Linux | Linux | — | vdpa: ifcvf: Put device on unsupported feature error |
| CVE-2026-97610 | await | — | Linux | Linux | — | netfs: Fix uninitialized return value in netfs_unbuffered_write() |
| CVE-2026-97613 | await | — | Linux | Linux | — | net: mana: Reserve extra CQ slot for the fence completion CQE |
| CVE-2026-97614 | await | — | Linux | Linux | — | net: dsa: tag_brcm: legacy FCS: request needed tailroom |
| CVE-2026-97615 | await | — | Linux | Linux | — | net: bridge: use option bits for CFM/MRP frame handlers |
| CVE-2026-97616 | await | — | Linux | Linux | — | net/sched: act_api: release all action references on NEWACTION failure |
| CVE-2026-97617 | await | — | Linux | Linux | — | ring-buffer: Check resize_disabled before publishing the new subbuf order |
| CVE-2026-97618 | await | — | Linux | Linux | — | io_uring/net: don't overconsume buffers when using MSG_TRUNC |
| CVE-2026-97619 | await | — | Linux | Linux | — | io_uring/rw: end write accounting from ->ki_complete |
| CVE-2026-97620 | await | — | Linux | Linux | — | drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches |
| CVE-2026-97621 | await | — | Linux | Linux | — | drm/rockchip: analogix_dp: fix unchecked bound endpoint name length |
| CVE-2026-97899 | await | — | Linux | Linux | — | drm/i915: Fix memory leak in query_perf_config_list() |
| CVE-2026-97900 | await | — | Linux | Linux | — | drm/drm_exec: fix up contended obj when num_objects is 0 |
| CVE-2026-97901 | await | — | Linux | Linux | — | genetlink: pin family module during policy dump |
| CVE-2026-97902 | await | — | Linux | Linux | — | fs: don't return -EINVAL for successful nested thaw |
| CVE-2026-97904 | await | — | Linux | Linux | — | cpufreq: initialize policy rwsem before sysfs publication |
| CVE-2026-97905 | await | — | Linux | Linux | — | cpufreq: zero-initialize policy cpumask before sysfs publication |
| CVE-2026-97906 | await | — | Linux | Linux | — | bootconfig: Fix integer overflow in initrd size check |
| CVE-2026-97907 | await | — | Linux | Linux | — | Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 |
| CVE-2026-97908 | await | — | Linux | Linux | — | Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev |
| CVE-2026-97909 | await | — | Linux | Linux | — | ASoC: sti: initialize IRQ lock before requesting IRQ |
| CVE-2026-97912 | await | — | Linux | Linux | — | accel: ethosu: Ensure SRAM size is 0 on mapping failure |
| CVE-2026-97913 | await | — | Linux | Linux | — | accel: ethosu: Ensure cmd stream ends with a stop op |
| CVE-2026-97914 | await | — | Linux | Linux | — | accel: ethosu: Fix ethosu_job_open() return value |
| CVE-2026-97915 | await | — | Linux | Linux | — | accel/ivpu: Limit firmware log name prints to field size |
| CVE-2026-97916 | await | — | Linux | Linux | — | accel/ivpu: Validate firmware log buffer metadata |
| CVE-2026-97917 | await | — | Linux | Linux | — | accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr |
| CVE-2026-97918 | await | — | Linux | Linux | — | tracing: Undo the registration when enabling the histogram trigger fails |
| CVE-2026-97919 | await | — | Linux | Linux | — | tracing: Take the reference before publishing the named histogram trigger |
| CVE-2026-97920 | await | — | Linux | Linux | — | tracing: Keep the entry count when the histogram stats allocation fails |
| CVE-2026-97921 | await | — | Linux | Linux | — | tracing: Free histogram the field rejected for a bad modifier |
| CVE-2026-97922 | await | — | Linux | Linux | — | tracing: Free histogram var refs regardless of how often they are referenced |
| CVE-2026-97923 | await | — | Linux | Linux | — | tracing: Free histogram the var ref when its initialization fails |
| CVE-2026-97924 | await | — | Linux | Linux | — | tracing/user_events: Don't destroy fields when event removal fails |
| CVE-2026-97925 | await | — | Linux | Linux | — | tick/broadcast: Plug clockevents replacement race |
| CVE-2026-97927 | await | — | Linux | Linux | — | ufs: create the root dentry after loading cylinder metadata |
| CVE-2026-97928 | await | — | Linux | Linux | — | drm/amdgpu: skip the VMID 0 flush for VRAM |
| CVE-2026-97929 | await | — | Linux | Linux | — | ALSA: usbusx2y: validate URB actual_length in interrupt callback |
| CVE-2026-97930 | await | — | Linux | Linux | — | ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf |
| CVE-2026-97932 | await | — | Linux | Linux | — | tracing: Don't dereference trace_event_file in deferred trigger free |
| CVE-2026-97933 | await | — | Linux | Linux | — | tracing: Take trace_array reference when opening a tracer options file |
| CVE-2026-97934 | await | — | Linux | Linux | — | tracing: Fix memory corruption from a "STACKTRACE" histogram key |
| CVE-2026-97935 | await | — | Linux | Linux | — | tracing: Set the trace clock before registering the histogram trigger |
| CVE-2026-97936 | await | — | Linux | Linux | — | tracing: Fix memory corruption from the histogram stacktrace modifier |
| CVE-2026-97938 | await | — | Linux | Linux | — | reboot: fix cad_pid use-after-free race |
| CVE-2026-97939 | await | — | Linux | Linux | — | ipmr: account multicast table and route memory |
| CVE-2026-97942 | await | — | Linux | Linux | — | x86/alternatives: Exclude text poking against change_page_attr() |
| CVE-2026-97943 | await | — | Linux | Linux | — | x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF |
| CVE-2026-97944 | await | — | Linux | Linux | — | x86/cfi: Fix FineIBT hash offset in cfi_get_func_hash() |
| CVE-2026-97945 | await | — | Linux | Linux | — | x86/mm: Fix user-space data loss with MADV_FREE and THP |
| CVE-2026-97946 | await | — | Linux | Linux | — | x86/amd_node: Fix PCI device reference counting in amd_smn_init() |
| CVE-2026-97947 | await | — | Linux | Linux | — | x86/amd_node: Fix potential NULL pointer dereference |
| CVE-2026-97948 | await | — | Linux | Linux | — | powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver |
| CVE-2026-97949 | await | — | Linux | Linux | — | configfs: unhash the dentry before dropping the item in rmdir |
| CVE-2026-97950 | await | — | Linux | Linux | — | configfs: pin the symlink target's dirent instead of chasing ->ci_dentry |
| CVE-2026-97951 | await | — | Linux | Linux | — | scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands |
| CVE-2026-97952 | await | — | Linux | Linux | — | sunvdc: unmap LDC cookies when the descriptor send fails |
| CVE-2026-97954 | await | — | Linux | Linux | — | net/rds: fix tcp stream corruption with large pages |
| CVE-2026-97955 | await | — | Linux | Linux | — | net: mana: restore the XDP program pointer when pre-allocation fails |
| CVE-2026-97956 | await | — | Linux | Linux | — | net: net_failover: Fix the deadlock in net_failover_slave_name_change() |
| CVE-2026-97958 | await | — | Linux | Linux | — | net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain(). |
| CVE-2026-97959 | await | — | Linux | Linux | — | net/sched: cls_route: free emptied bucket on filter move |
| CVE-2026-97960 | await | — | Linux | Linux | — | perf/x86/intel: Prevent drain_pebs() reentry |
| CVE-2026-97961 | await | — | Linux | Linux | — | perf/core: Allow list_del during perf_event_overflow() |
| CVE-2026-97962 | await | — | Linux | Linux | — | net/mlx5e: Move representor vnic reporter to eswitch devlink port |
| CVE-2026-97963 | await | — | Linux | Linux | — | net: stmmac: initialize ptp_lock at probe time |
| CVE-2026-97964 | await | — | Linux | Linux | — | ppp_synctty: ensure a writeable skb header |
| CVE-2026-97965 | await | — | Linux | Linux | — | vxlan: initialize _md in vxlan_xmit_one() |
| CVE-2026-97966 | await | — | Linux | Linux | — | octeontx2-pf: reset HTB scheduler topology before freeing queues |
| CVE-2026-97967 | await | — | Linux | Linux | — | hwmon: (corsair-cpro) Remove debugfs entries when probe fails |
| CVE-2026-97968 | await | — | Linux | Linux | — | hwmon: (corsair-cpro) Create debugfs entries after hwmon registration |
| CVE-2026-97969 | await | — | Linux | Linux | — | watchdog: msc313e: Fix clock leak and spurious timer in settimeout() |
| CVE-2026-97970 | await | — | Linux | Linux | — | watchdog: msc313e: Avoid division by zero |
| CVE-2026-97972 | await | — | Linux | Linux | — | net: macb: put the "mdio" child node reference on success |
| CVE-2026-97973 | await | — | Linux | Linux | — | net: macb: destroy the phylink instance on the probe error path |
| CVE-2026-97974 | await | — | Linux | Linux | — | ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings() |
| CVE-2026-97975 | await | — | Linux | Linux | — | Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() |
| CVE-2026-97976 | await | — | Linux | Linux | — | Bluetooth: btintel_pcie: validate packet_len before skb_put_data |
| CVE-2026-97977 | await | — | Linux | Linux | — | Bluetooth: btusb: Fix UAF of btusb_data by rx_work |
| CVE-2026-97978 | await | — | Linux | Linux | — | eth: ice: don't dereference pointers from TP_printk() |
| CVE-2026-97979 | await | — | Linux | Linux | — | ice: add missing xa_destroy for sched_node_ids |
| CVE-2026-97980 | await | — | Linux | Linux | — | s390/debug: Fix NULL pointer dereference in debug_set_level() |
| CVE-2026-97981 | await | — | Linux | Linux | — | net: ethernet: cortina: Count dropped frames as NAPI work |
| CVE-2026-97982 | await | — | Linux | Linux | — | net: ethernet: cortina: Fix budget accounting |
| CVE-2026-97983 | await | — | Linux | Linux | — | vduse: return compat ioctl results directly |
| CVE-2026-97984 | await | — | Linux | Linux | — | net: ipv6: Fix UDP length overflow with PMTU discover and big MTU |
| CVE-2026-97985 | await | — | Linux | Linux | — | af_unix: Update last skb marker in manage_oob(). |
| CVE-2026-97986 | await | — | Linux | Linux | — | virtio_input: stop callbacks before unregistering input device |
| CVE-2026-97987 | await | — | Linux | Linux | — | virtio_input: reset device if input_register_device() fails |
| CVE-2026-97988 | await | — | Linux | Linux | — | vhost: invalidate vring access on IOTLB transitions |
| CVE-2026-97989 | await | — | Linux | Linux | — | vduse: validate virtqueue alignment |
| CVE-2026-97992 | await | — | Linux | Linux | — | vhost-vdpa: protect config_ctx from being freed under the config callback |
| CVE-2026-97993 | await | — | Linux | Linux | — | vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx |
| CVE-2026-97994 | await | — | Linux | Linux | — | vhost/vdpa: reject VRING_NUM larger than device max |
| CVE-2026-97995 | await | — | Linux | Linux | — | virtio_console: do not free control-out buffers on remove |
| CVE-2026-97996 | await | — | Linux | Linux | — | virtio: fix use-after-free in unregister_virtio_device() |
| CVE-2026-97997 | await | — | Linux | Linux | — | virtio_ring: fix stale descriptor flags after a failed packed add |
| CVE-2026-97998 | await | — | Linux | Linux | — | netfilter: nfnetlink_log: cope with concurrent instance destruction |
| CVE-2026-98000 | await | — | Linux | Linux | — | hwmon: Fix potential UAF in pec_store |
| CVE-2026-98001 | await | — | Linux | Linux | — | hwmon: (ltc4282) Make sure clk_init_data is fully initialized |
| CVE-2026-98003 | await | — | Linux | Linux | — | iommu/amd: Do not reallocate GA log buffers on resume |
| CVE-2026-98004 | await | — | Linux | Linux | — | iommu/riscv: Serialize command queue publishing |
| CVE-2026-98005 | await | — | Linux | Linux | — | erofs: delimit inode_share cache key components |
| CVE-2026-98006 | await | — | Linux | Linux | — | ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev |
| CVE-2026-98007 | await | — | Linux | Linux | — | bpf: Reject non-scalar bpf_loop iteration counts |
| CVE-2026-98008 | await | — | Linux | Linux | — | net: macb: fix NULL pointer dereference on unbind with fixed-link |
| CVE-2026-98009 | await | — | Linux | Linux | — | net/sched: ets: clamp quantum in parse and fallback paths |
| CVE-2026-98010 | await | — | Linux | Linux | — | net/sched: drr: clamp quantum in change class |
| CVE-2026-98011 | await | — | Linux | Linux | — | net/sched: hhf: clamp quantum in change and init paths |
| CVE-2026-98012 | await | — | Linux | Linux | — | net/sched: sfq: clamp quantum in change path |
| CVE-2026-98013 | await | — | Linux | Linux | — | net/sched: fq_pie: clamp quantum in change path |
| CVE-2026-98014 | await | — | Linux | Linux | — | net/mlx5: E-Switch, prevent mc_list repopulation during vport disable |
| CVE-2026-98015 | await | — | Linux | Linux | — | net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put |
| CVE-2026-98016 | await | — | Linux | Linux | — | net/mlx5e: Fix use-after-free race in sample_restore_put() |
| CVE-2026-98018 | await | — | Linux | Linux | — | net: mctp: i3c: serialize probe with bus removal |
| CVE-2026-98019 | await | — | Linux | Linux | — | bpf: mark a NULL call argument precise |
| CVE-2026-98020 | await | — | Linux | Linux | — | pds_core: fix cmd_regs access racing BAR unmap on reset |
| CVE-2026-98021 | await | — | Linux | Linux | — | net: reject oversized tx_queue_len at netlink parse time |
| CVE-2026-98022 | await | — | Linux | Linux | — | net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations |
| CVE-2026-98024 | await | — | Linux | Linux | — | s390/ism: folio_put() after error |
| CVE-2026-98025 | await | — | Linux | Linux | — | net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent parti… |
| CVE-2026-98026 | await | — | Linux | Linux | — | net: bridge: mcast: properly convert mglist to rcu |
| CVE-2026-98028 | await | — | Linux | Linux | — | eth: nfp: drop the replaced rule from the list when reprogramming fails |
| CVE-2026-98031 | await | — | Linux | Linux | — | nexthop: Initialize extack in remove_nh_grp_entry() |
| CVE-2026-98032 | await | — | Linux | Linux | — | tracing: Fix subbuf resize races with trace_pipe_raw readers |
| CVE-2026-98033 | await | — | Linux | Linux | — | bpf: Preserve inner map identity in callback frames |
| CVE-2026-98034 | await | — | Linux | Linux | — | bpf: Mark NULL kptr stores precise |
| CVE-2026-98035 | await | — | Linux | Linux | — | bpf: Cancel special fields when recycling rhtab elements |
| CVE-2026-98036 | await | — | Linux | Linux | — | bpf: Preserve special fields in recycled rhtab elements |
| CVE-2026-98037 | await | — | Linux | Linux | — | bpf: Reject untrusted allocated-object pointers |
| CVE-2026-98038 | await | — | Linux | Linux | — | bpf: Keep refcount_acquire nullable for borrowed RCU kptrs |
| CVE-2026-98039 | await | — | Linux | Linux | — | bpf: Require MEM_PERCPU for percpu kptr stores |
| CVE-2026-98040 | await | — | Linux | Linux | — | bpf: Mark the zero register precise for a register-form NULL check |
| CVE-2026-98042 | await | — | Linux | Linux | — | bpf: Don't resurrect a scalar id dropped by collect_linked_regs() |
| CVE-2026-98043 | await | — | Linux | Linux | — | bpf: Don't infer non-NULL from a pointer with an unbounded offset |
| CVE-2026-98044 | await | — | Linux | Linux | — | bpf: Reject legacy packet loads from callbacks |
| CVE-2026-98045 | await | — | Linux | Linux | — | bpf: Mark faultable stack helpers as sleepable |
| CVE-2026-98046 | await | — | Linux | Linux | — | bpf: Mark bpf_btf_find_by_name_kind() as sleepable |
| CVE-2026-98047 | await | — | Linux | Linux | — | bpf: Check ancestor frames for rbtree callbacks |
| CVE-2026-98048 | await | — | Linux | Linux | — | bpf: don't rewrite bpf_fastcall patterns entered by a jump |
| CVE-2026-98049 | await | — | Linux | Linux | — | bpf: zero extend the result of an arena 32-bit cmpxchg |
| CVE-2026-98051 | await | — | Linux | Linux | — | net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times |
| CVE-2026-98053 | await | — | Linux | Linux | — | ASoC: Intel: avs: Refactor and fix init_config access |
| CVE-2026-98054 | await | — | Linux | Linux | — | ASoC: Intel: avs: Fix unbalanced module reference count |
| CVE-2026-98055 | await | — | Linux | Linux | — | ASoC: Intel: avs: Clean up the bus when fetching ML caps fails |
| CVE-2026-98057 | await | — | Linux | Linux | — | ring-buffer: Add checking nr_subbufs to persistent ring buffer validation |
| CVE-2026-98058 | await | — | Linux | Linux | — | bpf: Mark syscall helpers as sleepable |
| CVE-2026-98059 | await | — | Linux | Linux | — | bpf: Mark sched_process_wait argument as nullable |
| CVE-2026-98060 | await | — | Linux | Linux | — | bpf: Reject resilient lock operations in rbtree callbacks |
| CVE-2026-98061 | await | — | Linux | Linux | — | bpf: Reject tail calls directly from callback frames |
| CVE-2026-98062 | await | — | Linux | Linux | — | bpf: Mark signal tracepoint siginfo arguments as scalar |
| CVE-2026-98063 | await | — | Linux | Linux | — | bpf: Fix NULL-ptr-deref in btf_var_show() |
| CVE-2026-98064 | await | — | Linux | Linux | — | bpf: Fix NULL-ptr-deref when showing a void BTF type |
| CVE-2026-98065 | await | — | Linux | Linux | — | bpf: Reject key-less BTF for hash maps |
| CVE-2026-98066 | await | — | Linux | Linux | — | ALSA: caiaq: Fix potential double-free at error path |
| CVE-2026-98067 | await | — | Linux | Linux | — | erofs: disable LZ4 rolling decompression for now |
| CVE-2026-98068 | await | — | Linux | Linux | — | net/rds: don't let rds_conn_shutdown() consume a concurrent drop |
| CVE-2026-98071 | await | — | Linux | Linux | — | net/rds: clear cp_flags bits individually in rds_conn_path_reset() |
| CVE-2026-98072 | await | — | Linux | Linux | — | net/rds: use wq_has_sleeper() in release_in_xmit() |
| CVE-2026-98074 | await | — | Linux | Linux | — | bonding: do not clear curr_active_slave prematurely when releasing all slaves |
| CVE-2026-98075 | await | — | Linux | Linux | — | bpf: reject BPF_PSEUDO_FUNC reference to the main program |
| CVE-2026-98076 | await | — | Linux | Linux | — | tracing/probes: Fix use-after-free on field name/type of events with multiple… |
| CVE-2026-98077 | await | — | Linux | Linux | — | netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() |
| CVE-2026-98078 | await | — | Linux | Linux | — | ipvs: fix reversed sequence option serialization |
| CVE-2026-98079 | await | — | Linux | Linux | — | btrfs: zstd: fix lost wakeup when waiting for a workspace |
| CVE-2026-98080 | await | — | Linux | Linux | — | btrfs: do not force reloc root creation during qgroup_account_snapshot() |
| CVE-2026-98081 | await | — | Linux | Linux | — | btrfs: zoned: finish active block group cleanup if call_zone_finish() fails |
| CVE-2026-98082 | await | — | Linux | Linux | — | btrfs: fix the possible bioc_list memory leak during error |
| CVE-2026-98084 | await | — | Linux | Linux | — | bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks |
| CVE-2026-98085 | await | — | Linux | Linux | — | bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge |
| CVE-2026-98086 | await | — | Linux | Linux | — | ALSA: ump: do not touch legacy_rmidi before it exists |
| CVE-2026-98087 | await | — | Linux | Linux | — | sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate |
| CVE-2026-98088 | await | — | Linux | Linux | — | scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_rep… |
| CVE-2026-98089 | await | — | Linux | Linux | — | bonding: alb: fix uninitialized transport header access in alb_determine_nd() |
| CVE-2026-98090 | await | — | Linux | Linux | — | btrfs: restore active device pointers after failed sprout |
| CVE-2026-98091 | await | — | Linux | Linux | — | btrfs: detach failed sprout device from transaction update list |
| CVE-2026-98092 | await | — | Linux | Linux | — | ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() |
| CVE-2026-98093 | await | — | Linux | Linux | — | ASoC: fsl_micfil: balance mclk enable/disable |
| CVE-2026-98094 | await | — | Linux | Linux | — | staging: fbtft: make dirty_lock IRQ-safe |
| CVE-2026-98095 | await | — | Linux | Linux | — | af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header(). |
| CVE-2026-98097 | await | — | Linux | Linux | — | tipc: Dont send random pad bytes in RESET/ACTIVATE messages |
| CVE-2026-98098 | await | — | Linux | Linux | — | tipc: fix NULL deref in tipc_named_node_up() on empty publication list |
| CVE-2026-98099 | await | — | Linux | Linux | — | ipv6: mcast: use rcu_assign_pointer() for __rcu list updates |
| CVE-2026-98101 | await | — | Linux | Linux | — | ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source() |
| CVE-2026-98102 | await | — | Linux | Linux | — | ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src() |
| CVE-2026-98103 | await | — | Linux | Linux | — | igmp: convert struct ip_sf_list to RCU |
| CVE-2026-98104 | await | — | Linux | Linux | — | net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted |
| CVE-2026-98105 | await | — | Linux | Linux | — | net: ethernet: oa_tc6: Improve the error recovery |
| CVE-2026-98106 | await | — | Linux | Linux | — | drm/pagemap: Prevent double migration of device pages |
| CVE-2026-98107 | await | — | Linux | Linux | — | Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect |
| CVE-2026-98109 | await | — | Linux | Linux | — | Bluetooth: hci_core: Fix race condition during device registration |
| CVE-2026-98110 | await | — | Linux | Linux | — | Bluetooth: btintel: bound firmware ID by TLV length |
| CVE-2026-98111 | await | — | Linux | Linux | — | Bluetooth: btintel: validate version TLV value lengths |
| CVE-2026-98113 | await | — | Linux | Linux | — | ksmbd: rate limit unmapped SID errors |
| CVE-2026-98114 | await | — | Linux | Linux | — | ksmbd: propagate DACL parsing errors |
| CVE-2026-98117 | await | — | Linux | Linux | — | cachefiles: Fix potential UAF/KASAN warning |
| CVE-2026-98118 | await | — | Linux | Linux | — | netfs: Fix readahead synchronisation issues by loading all folios upfront |
| CVE-2026-98119 | await | — | Linux | Linux | — | netfs: break unbuffered write when netfs_alloc_subrequest() fails |
| CVE-2026-98120 | await | — | Linux | Linux | — | netfs: Fix subreq ref leak |
| CVE-2026-98121 | await | — | Linux | Linux | — | watchdog: msc313e: Fix NULL pointer dereference in PM callbacks |
| CVE-2026-98123 | await | — | Linux | Linux | — | sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration |
| CVE-2026-98124 | await | — | Linux | Linux | — | smb/client: invalidate fscache for fallocate range operations |
| CVE-2026-98125 | await | — | Linux | Linux | — | smb/client: fix stale page cache in insert/collapse range |
| CVE-2026-98126 | await | — | Linux | Linux | — | smb/client: validate new EOF for zero range |
| CVE-2026-98127 | await | — | Linux | Linux | — | smb/client: validate new EOF for insert range |
| CVE-2026-98128 | await | — | Linux | Linux | — | scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add() |
| CVE-2026-98129 | await | — | Linux | Linux | — | scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() |
| CVE-2026-98131 | await | — | Linux | Linux | — | net: stmmac: fix dma mapping leak in stmmac_tso_xmit() |
| CVE-2026-98132 | await | — | Linux | Linux | — | bpf: don't downgrade half-dead scalar zero spills to STACK_ZERO |
| CVE-2026-98133 | await | — | Linux | Linux | — | ntfs: leave HasEA flag untouched on setxattr failure |
| CVE-2026-98134 | await | — | Linux | Linux | — | bpf: check_cond_jmp_op(): properly infer if register is null |
| CVE-2026-98135 | await | — | Linux | Linux | — | ntfs: reject invalid sectors_per_cluster in the boot sector |
| CVE-2026-98136 | await | — | Linux | Linux | — | ntfs: bound $AttrDef table walk to the loaded table size |
| CVE-2026-98137 | await | — | Linux | Linux | — | ntfs: treat any nonzero dio zero-range return as an error |
| CVE-2026-98138 | await | — | Linux | Linux | — | ntfs: do not mark the volume clean in sync_fs when errors were recorded |
| CVE-2026-98139 | await | — | Linux | Linux | — | ntfs: only count successfully cleared runs when freeing clusters |
| CVE-2026-98140 | await | — | Linux | Linux | — | ntfs: fix kmap_local leak in write_mft_record_nolock() error paths |
| CVE-2026-98141 | await | — | Linux | Linux | — | ntfs: propagate reparse index insertion failure |
| CVE-2026-98142 | await | — | Linux | Linux | — | drm/cirrus-qemu: Validate BAR0 size during probe |
| CVE-2026-98144 | await | — | Linux | Linux | — | accel/amdxdna: put the chained BO when its mapping fails |
| CVE-2026-98145 | await | — | Linux | Linux | — | accel/amdxdna: reject a command chain that carries no commands |
| CVE-2026-98146 | await | — | Linux | Linux | — | accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain |
| CVE-2026-98147 | await | — | Linux | Linux | — | printk: Don't WARN on kthread_run failure. |
| CVE-2026-98148 | await | — | Linux | Linux | — | drm/gud: validate GUD_ROTATION_0 is present in supported rotations |
| CVE-2026-98149 | await | — | Linux | Linux | — | bpf: Fix percpu map update indexing with sparse CPU IDs |
| CVE-2026-98151 | await | — | Linux | Linux | — | bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic |
| CVE-2026-98152 | await | — | Linux | Linux | — | nvmet-rdma: fix queue leak when connect backlog is exceeded |
| CVE-2026-98153 | await | — | Linux | Linux | — | nvme: fix racy access to FDP placement id array |
| CVE-2026-98155 | await | — | Linux | Linux | — | accel/qaic: Address potential out-of-bounds read in resp_worker() |
| CVE-2026-98157 | await | — | Linux | Linux | — | EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation |
| CVE-2026-98158 | await | — | Linux | Linux | — | ppp_async: drop the errored frame instead of resetting its headroom |
| CVE-2026-98159 | await | — | Linux | Linux | — | wifi: mt76: mt7921: validate CLC firmware records |
| CVE-2026-98160 | await | — | Linux | Linux | — | staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() |
| CVE-2026-98161 | await | — | Linux | Linux | — | nvdimm: pmem: keep PREFLUSH before data writes |
| CVE-2026-98162 | await | — | Linux | Linux | — | smb/server: fix tree connection leak in smb2_tree_connect() |
| CVE-2026-100070 | await | — | Linux | Linux | — | netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet |
| CVE-2026-100071 | await | — | Linux | Linux | — | net: hsr: free learned nodes on device setup failure |
| CVE-2026-100072 | await | — | Linux | Linux | — | ACPI: platform: Use acpi_bus_get_primary_device() |
| CVE-2026-100073 | await | — | Linux | Linux | — | ext4: fix transaction overflow during writeback |
| CVE-2026-100074 | await | — | Linux | Linux | — | bpf: Mark bpf_refcount field as unique |
| CVE-2026-100076 | await | — | Linux | Linux | — | staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths |
| CVE-2026-100077 | await | — | Linux | Linux | — | drm/msm: Recover HW before retire hung submit |
| CVE-2026-100078 | await | — | Linux | Linux | — | wifi: iwlwifi: mei: pass correct argument to function |
| CVE-2026-100079 | await | — | Linux | Linux | — | usb: typec: ucsi: unregister debugfs entries on teardown |