boxscore/security
Saturday, August 15, 2026 · all times UTC← 2026-08-14 · archive · 2026-08-16 →

Edition of August 15, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–926 of 926
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-74265await10.9LinuxLinuxnet: mana: initialize gdma queue id to INVALID_QUEUE_ID
CVE-2026-74271await10.9LinuxLinuxpower: supply: core: fix supplied_from allocations
CVE-2026-745548.810.7LinuxLinuxwifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup()
CVE-2026-160077.110.6AppFlowy-IOAppFlowy-CloudCWE-89Authenticated SQL Injection in AppFlowy
CVE-2026-72180await10.3LinuxLinuxmm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade
CVE-2026-199172.110.2code-projectsOnline Food Order SystemCWE-89code-projects Online Food Order System delete_food_items1.php sql injection
CVE-2026-199202.110.2code-projectsOnline Shopping SystemCWE-74code-projects Online Shopping System action.php sql injection
CVE-2026-72007await10.2LinuxLinuxpmdomain: imx: Fix i.MX8MP VC8000E power up sequence
CVE-2026-72015await10.2LinuxLinuxfs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
CVE-2026-72017await10.1LinuxLinuxnet: macb: drop in-flight Tx SKBs on close
CVE-2026-72023await10.2LinuxLinuxocteontx2-pf: fix SQB pointer leak on init failure
CVE-2026-72026await10.2LinuxLinuxirqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
CVE-2026-72028await10.2LinuxLinuxriscv: probes: save original sp in rethook trampoline
CVE-2026-72030await10.2LinuxLinuxata: libata-core: Reject an invalid concurrent positioning ranges count
CVE-2026-72032await10.2LinuxLinuxnet/mlx5: HWS, fix matcher leak on resize target setup failure
CVE-2026-72040await10.2LinuxLinuxipmi: fix refcount leak in i_ipmi_request()
CVE-2026-72050await10.2LinuxLinuxocteontx2-af: Free BPID bitmap on setup failure
CVE-2026-72096await10.2LinuxLinuxdm-verity: make error counter atomic
CVE-2026-72101await10.1LinuxLinuxdm-integrity: fix leaking uninitialized kernel memory
CVE-2026-72117await10.2LinuxLinuxcan: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
CVE-2026-72118await10.2LinuxLinuxcan: bcm: fix CAN frame rx/tx statistics
CVE-2026-72127await10.1LinuxLinuxnetdev-genl: report NAPI thread PID in the caller's pid namespace
CVE-2026-72132await10.2LinuxLinuxNFS: Charge unstable writes by request size, not folio size
CVE-2026-72142await10.2LinuxLinuxi2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
CVE-2026-72147await10.2LinuxLinuxdmaengine: dw-edma-pcie: Reject devices without driver data
CVE-2026-72158await10.1LinuxLinuxfpga: dfl: add bounds check in dfh_get_param_size()
CVE-2026-72168await10.2LinuxLinuxmtd: maps: vmu-flash: fix fault in unaligned fixup
CVE-2026-72174await10.1LinuxLinuxfs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
CVE-2026-72176await10.1LinuxLinuxmm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
CVE-2026-72178await10.1LinuxLinuxmm/damon/core: always put unsuccessfully committed target pids
CVE-2026-72212await10.2LinuxLinuxmm/memory_hotplug: fix incorrect altmap passing in error path
CVE-2026-72216await10.2LinuxLinuxremoteproc: qcom: Fix leak when custom dump_segments addition fails
CVE-2026-72237await10.2LinuxLinuxperf/x86/amd/brs: Fix kernel address leakage
CVE-2026-72258await10.2LinuxLinuxASoC: mediatek: mt8183: Release reserved memory on cleanup
CVE-2026-72259await10.2LinuxLinuxASoC: mediatek: mt8192: Release reserved memory on cleanup
CVE-2026-72266await10.1LinuxLinuxfbdev: vesafb: fix memory leak in vesafb_probe()
CVE-2026-72273await10.1LinuxLinuxfbdev: efifb: fix memory leak in efifb_probe()
CVE-2026-72300await10.1LinuxLinuxASoC: SOF: topology: validate vendor array size before parsing
CVE-2026-72305await10.2LinuxLinuxVDUSE: avoid leaking information to userspace
CVE-2026-72336await10.2LinuxLinuxBluetooth: 6lowpan: hold L2CAP conn across debugfs control
CVE-2026-72362await10.2LinuxLinuxdrm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
CVE-2026-72386await10.1LinuxLinuxdrm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced
CVE-2026-72387await10.2LinuxLinuxdrm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()
CVE-2026-72394await10.2LinuxLinuxhwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
CVE-2026-72430await10.1LinuxLinuxnet/sched: act_ct: fix nf_connlabels leak on two error paths
CVE-2026-72468await10.2LinuxLinuxxprtrdma: Initialize re_id before removal registration
CVE-2026-72475await10.2LinuxLinuxdmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
CVE-2026-199162.010.0code-projectsOnline Food Order SystemCWE-79code-projects Online Food Order System edit_food_items.php cross site scripting
CVE-2026-72006await9.9LinuxLinuxnet/mlx5: free mlx5_st_idx_data on final dealloc
CVE-2026-72016await9.9LinuxLinuxcpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
CVE-2026-72091await9.9LinuxLinuxaccel/amdxdna: reject user command submission without a command BO
CVE-2026-72094await9.9LinuxLinuxdma-buf: dma-fence: Fix potential NULL pointer dereference
CVE-2026-72104await9.9LinuxLinuxdm-pcache: reject option groups without values
CVE-2026-72128await9.9LinuxLinuxnvmet: fix refcount leak in nvmet_sq_create()
CVE-2026-72131await9.9LinuxLinuxnvme-apple: Prevent shared tags across queues on Apple A11
CVE-2026-72150await9.9LinuxLinuxsunrpc: fix uninitialized xprt_create_args structure
CVE-2026-72169await9.9LinuxLinuxkho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
CVE-2026-72205await9.9LinuxLinuxntfs: free volume-wide resources on fill_super failure
CVE-2026-72281await9.9LinuxLinuxKVM: arm64: account pKVM reclaim against the VM mm
CVE-2026-72292await9.9LinuxLinuxKVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory
CVE-2026-72309await9.9LinuxLinuxtracing/remotes: Fix leak in trace_remote_alloc_buffer() error path
CVE-2026-72311await9.9LinuxLinuxdrm/xe: free madvise VMA array on L2 flush failure
CVE-2026-72332await9.9LinuxLinuxaccel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()
CVE-2026-72337await9.9LinuxLinuxBluetooth: 6lowpan: avoid untracked enable work
CVE-2026-72346await9.9LinuxLinuxplatform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/r…
CVE-2026-72359await9.9LinuxLinuxdrm/xe: fix NPD in bo_meminfo()
CVE-2026-72370await9.9LinuxLinuxiomap: release pages on atomic dio size mismatch
CVE-2026-72377await9.9LinuxLinuxafs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints
CVE-2026-72385await9.9LinuxLinuxtracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
CVE-2026-72403await9.9LinuxLinuxALSA: FCP: Fix NULL pointer dereference in interface lookup
CVE-2026-72431await9.9LinuxLinuxalloc_tag: fix use-after-free in /proc/allocinfo after module unload
CVE-2026-72432await9.9LinuxLinuxtpm_crb: Check ACPI_COMPANION() against NULL during probe
CVE-2026-72453await9.9LinuxLinuxregcache: Do not overwrite error code when finalizing cache after error
CVE-2026-72458await9.9LinuxLinuxapparmor: fix NULL pointer dereference in unpack_pdb
CVE-2026-74261await9.9LinuxLinuxALSA: seq: avoid stale FIFO cells during resize
CVE-2026-74266await9.9LinuxLinuxnet/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek bef…
CVE-2026-723438.49.6LinuxLinuxnet/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
CVE-2026-74382await9.5LinuxLinuxnet/sched: cls_bpf: prevent unbounded recursion in offload rollback
CVE-2026-722779.39.4LinuxLinuxKVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
CVE-2026-722789.39.4LinuxLinuxKVM: arm64: nv: Re-translate VNCR before injecting abort
CVE-2026-723428.49.3LinuxLinuxnet/mlx5e: Fix HV VHCA stats agent registration race
CVE-2026-74331await9.0LinuxLinuxfirmware_loader: Fix recursive lock in device_cache_fw_images()
CVE-2026-722799.08.8LinuxLinuxKVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
CVE-2026-72008await8.9LinuxLinuxpmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check
CVE-2026-72031await8.9LinuxLinuxata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD
CVE-2026-72145await8.9LinuxLinuxplatform/x86/intel/tpmi: use cleanup helpers in mem_write()
CVE-2026-72173await8.9LinuxLinuxfs/proc/task_mmu: do not warn on seeing non-migration pmd entry
CVE-2026-72184await8.9LinuxLinuxntfs: fix hole runlist memory leak in insert range error path
CVE-2026-72187await8.9LinuxLinuxntfs: avoid self-deadlock during inode eviction
CVE-2026-72189await8.9LinuxLinuxntfs: fail attrlist updates when the superblock is inactive
CVE-2026-72190await8.9LinuxLinuxntfs: fix mrec_lock ABBA deadlock in rename
CVE-2026-72263await8.9LinuxLinuxASoC: SOF: topology: fix memory leak in snd_sof_load_topology
CVE-2026-72293await8.9LinuxLinuxKVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault()
CVE-2026-72313await8.9LinuxLinuxdrm/fb-helper: Only consider active CRTCs for vblank sync
CVE-2026-72388await8.9LinuxLinuxdrm/panthor: Always use the IRQ-safe variant when acquiring the fence lock
CVE-2026-72402await8.9LinuxLinuxbpf: Mask pseudo pointer values in verifier logs
CVE-2026-72413await8.9LinuxLinuxsctp: fix err_chunk memory leaks in INIT handling
CVE-2026-72456await8.9LinuxLinuxapparmor: release exe file resources on path failure
CVE-2026-722847.18.6LinuxLinuxKVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
CVE-2026-722807.18.5LinuxLinuxKVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
CVE-2026-724257.18.5LinuxLinuxice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
CVE-2026-72448await8.3LinuxLinuxocteontx2-pf: Fix leak of SQ timestamp buffer on teardown
CVE-2026-722899.38.1LinuxLinuxKVM: arm64: vgic: Check the interrupt is still ours before migrating it
CVE-2026-721338.48.1LinuxLinuxspi: uniphier: Fix completion initialization order before devm_request_irq()
CVE-2026-721518.48.1LinuxLinuxtpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
CVE-2026-721968.48.1LinuxLinuxfs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
CVE-2026-721978.48.1LinuxLinuxfs/ntfs3: bound DeleteIndexEntryAllocation memmove length
CVE-2026-722988.48.1LinuxLinuxnet: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
CVE-2026-742568.48.1LinuxLinuxbpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
CVE-2026-742598.48.1LinuxLinuxcifs: remove all cifs files before kill super
CVE-2026-724837.88.0LinuxLinuxusb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
CVE-2026-723299.37.8LinuxLinuxnet/liquidio: drop cached VF pci_dev LUT
CVE-2026-724129.37.8LinuxLinuxs390/mm: Fix handling of _PAGE_UNUSED pte bit
CVE-2026-721468.47.9LinuxLinuxdmaengine: sh: rz-dmac: Move interrupt request after everything is set up
CVE-2026-724268.47.8LinuxLinuxbpf: Preserve pointer spill metadata during half-slot cleanup
CVE-2026-724877.77.9LinuxLinuxPCI: Check ROM header and data structure addr before accessing
CVE-2026-721167.17.8LinuxLinuxcan: bcm: fix stale rx/tx ops after device removal
CVE-2026-72424await7.9LinuxLinuxrtc: msc313: fix NULL deref in shared IRQ handler at probe
CVE-2026-72486await7.9LinuxLinuxmailbox: mtk-adsp: fix UAF during device teardown
CVE-2026-722838.87.7LinuxLinuxKVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
CVE-2026-722889.37.6LinuxLinuxKVM: arm64: vgic: Handle race between interrupt affinity change and LPI disab…
CVE-2026-724959.37.6LinuxLinuxRDMA/bnxt_re: Avoid repeated requests to allocate WC pages
CVE-2026-720859.37.6LinuxLinuxscsi: xen: scsiback: Free unsubmitted command instead of double-putting it
CVE-2026-722627.87.5LinuxLinuxASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
CVE-2026-723027.87.6LinuxLinuxASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
CVE-2026-74402await7.5LinuxLinuxcrypto: atmel-sha204a - fix blocking and non-blocking rng logic
CVE-2026-74416await7.5LinuxLinuxdrm/radeon: fix memory leak in radeon_ring_restore() on lock failure
CVE-2026-720618.87.4LinuxLinuxnet: sit: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-720667.87.4LinuxLinuxcpu: hotplug: Bound hotplug states sysfs output
CVE-2026-720677.87.4LinuxLinuxcpu: hotplug: Preserve per instance callback errors
CVE-2026-722827.87.4LinuxLinuxKVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
CVE-2026-723147.87.4LinuxLinuxregulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK
CVE-2026-723507.87.4LinuxLinuxnetfilter: xt_u32: reject invalid shift counts
CVE-2026-723717.87.4LinuxLinuxafs: Fix the volume AFS_VOLUME_RM_TREE is set on
CVE-2026-724507.87.4LinuxLinuxxfrm: validate selector family and prefixlen during match
CVE-2026-68456await7.5LinuxLinuxusb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
CVE-2026-68460await7.5LinuxLinuxf2fs: fix potential deadlock in f2fs_balance_fs()
CVE-2026-74276await7.5LinuxLinuxspi: xilinx: use FIFO occupancy register to determine buffer size
CVE-2026-74320await7.5LinuxLinuxfbdev: sm501fb: Fix buffer errors in OF binding code
CVE-2026-74348await7.5LinuxLinuxocfs2/dlm: require a ref for locking_state debugfs open
CVE-2026-74351await7.5LinuxLinuxocfs2: rebase copied fsdlm LVB pointers in locking_state
CVE-2026-74395await7.5LinuxLinuxRDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
CVE-2026-722868.87.3LinuxLinuxKVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
CVE-2026-720277.87.3LinuxLinuxmm/compaction: handle free_pages_prepare() properly in compaction_free()
CVE-2026-723407.87.3LinuxLinuxnet: microchip: vcap: fix races on the shared Super VCAP block
CVE-2026-723527.87.3LinuxLinuxHID: bpf: Fix hid_bpf_get_data() range check
CVE-2026-723697.87.3LinuxLinuxminix: avoid overflow in bitmap block count calculation
CVE-2026-723727.87.3LinuxLinuxafs: Fix lack of locking around modifications of net->cells_dyn_ino
CVE-2026-724527.87.3LinuxLinuxdrm/i915: clear CRTC color blob pointers after dropping refs
CVE-2026-72443await7.3LinuxLinuxALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
CVE-2026-723477.37.1LinuxLinuxnetfilter: xt_connmark: reject invalid shift parameters
CVE-2026-721547.87.1LinuxLinuxopenrisc: Fix jump_label smp syncing
CVE-2026-723577.87.1LinuxLinuxuprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
CVE-2026-723757.87.1LinuxLinuxafs: Fix reinitialisation of the inode, in particular ->lock_work
CVE-2026-724167.37.0LinuxLinuxnetfilter: nft_compat: ebtables emulation must reject non-bridge targets
CVE-2026-721118.86.9LinuxLinuxbpf: Reset register bounds before narrowing retval range in check_mem_access()
CVE-2026-722257.87.0LinuxLinuxjbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
CVE-2026-68459await7.0LinuxLinuxf2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
CVE-2026-74274await7.0LinuxLinuxcxl/region: Fill first free targets[] slot during auto-discovery
CVE-2026-74290await7.0LinuxLinuxnet/sched: cls_flow: Dont expose folded kernel pointers
CVE-2026-74327await7.0LinuxLinuxvmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
CVE-2026-74329await7.0LinuxLinuxwatchdog: unregister PM notifier on watchdog unregister
CVE-2026-74339await7.0LinuxLinuxALSA: seq: Clear variable event pointer on read
CVE-2026-74346await7.0LinuxLinuxRDMA/irdma: Fix OOB read during CQ MR registration
CVE-2026-74373await7.0LinuxLinuxmd/raid1,raid10: fix bio accounting for split md cloned bios
CVE-2026-74379await7.0LinuxLinuxdax/kmem: account for partial discontiguous resource upon removal
CVE-2026-74381await7.0LinuxLinuxgpu: host1x: Allow entries in BO caches to be freed
CVE-2026-74399await7.0LinuxLinuxevm: terminate and bound the evm_xattrs read buffer
CVE-2026-723608.46.8LinuxLinuxdrm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
CVE-2026-720727.86.8LinuxLinuxnet/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
CVE-2026-723357.86.8LinuxLinuxBluetooth: MGMT: Fix adv monitor add failure cleanup
CVE-2026-724497.86.8LinuxLinuxdrm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
CVE-2026-724767.86.8LinuxLinuxdmaengine: Fix possible use after free
CVE-2026-721757.16.9LinuxLinuxfs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
CVE-2026-723647.16.8LinuxLinuxnetfs: Fix writeback error handling
CVE-2026-720717.86.8LinuxLinuxtracing/user_events: Fix use-after-free in user_event_mm_dup()
CVE-2026-74466await6.7LinuxLinuxs390/zcrypt: Close speculative mem read possibility
CVE-2026-721838.46.7LinuxLinuxlandlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
CVE-2026-723957.16.7LinuxLinuxhwmon: (pmbus) Fix passing events to regulator core
CVE-2026-722399.36.5LinuxLinuxx86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"
CVE-2026-722919.36.5LinuxLinuxKVM: s390: Fix unlikely race in try_get_locked_pte()
CVE-2026-722048.46.5LinuxLinuxntfs: centalize $INDEX_ROOT header validation
CVE-2026-720807.86.6LinuxLinuxfs/resctrl: Fix use-after-free during unmount
CVE-2026-720937.86.6LinuxLinuxaccel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
CVE-2026-723287.86.6LinuxLinuxaccel/amdxdna: Fix potential amdxdna_umap lifetime race
CVE-2026-74263await6.5LinuxLinuxnet: wwan: t7xx: check skb_clone in control TX
CVE-2026-74278await6.5LinuxLinuxALSA: seq: Fix kernel heap address leak in bounce_error_event()
CVE-2026-74286await6.5LinuxLinuxnet: pfcp: allocate per-cpu tstats for PFCP netdevs
CVE-2026-74301await6.5LinuxLinuxBluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path
CVE-2026-74303await6.5LinuxLinuxBluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-ser…
CVE-2026-74308await6.5LinuxLinuxext4: fix kernel BUG in ext4_write_inline_data_end
CVE-2026-74318await6.5LinuxLinuxbtrfs: fix deadlock cloning inline extent when using flushoncommit
CVE-2026-74352await6.5LinuxLinuxof: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails
CVE-2026-74353await6.5LinuxLinuxdrm/amdkfd: always resume_all after suspend_all
CVE-2026-74362await6.5LinuxLinuxext2: fix ignored return value of generic_write_sync()
CVE-2026-74386await6.6LinuxLinuxnvmet-tcp: fix page fragment cache leak in error path
CVE-2026-74389await6.5LinuxLinuxRDMA/hns: Fix log flood after cmd_mbox failure
CVE-2026-74391await6.6LinuxLinuxtracing: Bound synthetic-field strings with seq_buf
CVE-2026-74393await6.5LinuxLinuxdrm/syncobj: Fix memory leak in drm_syncobj_find_fence()
CVE-2026-74441await6.5LinuxLinuxusb: typec: ucsi: Fix race condition and ordering in port unregistration
CVE-2026-74442await6.5LinuxLinuxdrm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
CVE-2026-74445await6.5LinuxLinuxdrm/vmwgfx: reject DX_BIND_QUERY without a DX context
CVE-2026-74448await6.5LinuxLinuxdrm/amdkfd: fix QID bit leak in pqm_create_queue()
CVE-2026-74455await6.5LinuxLinuxcan: peak_usb: validate uCAN receive record lengths
CVE-2026-74457await6.5LinuxLinuxcan: peak_usb: add bounds check for USB channel index
CVE-2026-74458await6.5LinuxLinuxcan: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command e…
CVE-2026-74459await6.5LinuxLinuxcan: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubm…
CVE-2026-74460await6.5LinuxLinuxcan: ems_usb: validate CPC message lengths
CVE-2026-74463await6.5LinuxLinuxi2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
CVE-2026-74464await6.5LinuxLinuxnet: openvswitch: fix skb leak on flow key update failure during ct
CVE-2026-74468await6.5LinuxLinuxgpio: pch: use raw_spinlock_t for the register lock
CVE-2026-74472await6.5LinuxLinuxublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
CVE-2026-74484await6.5LinuxLinuxbinfmt_misc: don't let an 'F' entry pin its own instance
CVE-2026-74498await6.5LinuxLinuxALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
CVE-2026-74499await6.5LinuxLinuxALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
CVE-2026-74500await6.5LinuxLinuxALSA: usb-audio: fix stack info leak in RME Digiface status
CVE-2026-74501await6.5LinuxLinuxALSA: usb-audio: fix use-after-free in ump_to_endpoint()
CVE-2026-74502await6.5LinuxLinuxALSA: ump: fix double free of out_cvts on rawmidi error
CVE-2026-74504await6.5LinuxLinuxALSA: seq: Fix division by zero in initialize_timer()
CVE-2026-74505await6.5LinuxLinuxALSA: 6fire: Fix UAF at error handling during probe
CVE-2026-74524await6.5LinuxLinuxriscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
CVE-2026-74525await6.5LinuxLinuxnet: sxgbe: free TX rings on RX allocation failure
CVE-2026-74532await6.5LinuxLinuxBluetooth: btintel: Validate length before parsing diagnostics TLV
CVE-2026-74536await6.5LinuxLinuxBluetooth: ISO: fix leaking sk after socket release
CVE-2026-74543await6.6LinuxLinuxnet: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
CVE-2026-74546await6.5LinuxLinuxhwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
CVE-2026-74547await6.6LinuxLinuxhwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
CVE-2026-74552await6.5LinuxLinuxhwmon: (lm90) Only report alarms if driver is ready
CVE-2026-720197.36.4LinuxLinuxmacsec: don't read an unset MAC header in macsec_encrypt()
CVE-2026-723387.86.3LinuxLinuxnet/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
CVE-2026-720897.16.3LinuxLinuxaccel/ivpu: Reject firmware log with size smaller than header
CVE-2026-68463await6.3LinuxLinuxmmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
CVE-2026-68464await6.3LinuxLinuxmmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
CVE-2026-68465await6.3LinuxLinuxmmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore
CVE-2026-72498await6.3LinuxLinuxRDMA/bnxt_re: Avoid displaying the kernel pointer
CVE-2026-72501await6.3LinuxLinuxRDMA/bnxt_re: Initialize dpi variable to zero
CVE-2026-74307await6.3LinuxLinuxext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT
CVE-2026-74322await6.3LinuxLinuxwifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write…
CVE-2026-74324await6.3LinuxLinuxwifi: mt76: mt7925: validate skb length in testmode query
CVE-2026-74335await6.3LinuxLinuxbpf: Fix NULL pointer dereference in bpf_task_from_vpid()
CVE-2026-74337await6.3LinuxLinuxbpf: Fix NMI/tracepoint re-entry deadlock on lru locks
CVE-2026-74358await6.3LinuxLinuxext4: fix fast commit wait/wake bit mapping on 64-bit
CVE-2026-74360await6.3LinuxLinuxbpf: Reject exclusive maps for bpf_map_elem iterators
CVE-2026-74366await6.3LinuxLinuxwifi: ath12k: fix NULL deref in change_sta_links for unready link
CVE-2026-74372await6.3LinuxLinuxraid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
CVE-2026-74400await6.3LinuxLinuxbpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries
CVE-2026-74462await6.3LinuxLinuxi2c: imx: mark I2C adapter when hardware is powered down
CVE-2026-74477await6.3LinuxLinuxuprobes: Fix NULL pointer dereference in hprobe_expire()
CVE-2026-74486await6.3LinuxLinuxbinfmt_misc: use exe_file_deny_write_access() for the interpreter clone
CVE-2026-74487await6.3LinuxLinuxbinfmt_misc: restore write access when removing an entry
CVE-2026-74491await6.3LinuxLinuxof/address: Fix NULL bus dereference in of_pci_range_parser_one()
CVE-2026-74494await6.3LinuxLinuxksmbd: reject repeated SMB2 NEGOTIATE requests
CVE-2026-74514await6.3LinuxLinuxKVM: s390: pci: Fix memory accounting for pinned/unpinned pages
CVE-2026-74559await6.3LinuxLinuxxsk: drain continuation descs after overflow in xsk_build_skb()
CVE-2026-721347.86.2LinuxLinuxspi: imx: reconfigure for PIO when DMA cannot be started
CVE-2026-723157.86.2LinuxLinuxsmb: client: fix busy dentry warning on unmount after DIO
CVE-2026-723317.86.2LinuxLinuxaccel/amdxdna: Fix VMA access race
CVE-2026-723447.86.2LinuxLinuxnet/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable
CVE-2026-723457.86.2LinuxLinuxnet/mlx5: LAG, Fix off-by-one in single-FDB error rollback
CVE-2026-723587.86.2LinuxLinuxdrm/xe/pt: prevent invalid cursor access for purged BOs
CVE-2026-723687.86.2LinuxLinuxcachefiles: Fix double unlock in nomem_d_alloc error path
CVE-2026-74426await6.2LinuxLinuxafs: fix NULL pointer dereference in afs_get_tree()
CVE-2026-720528.86.1LinuxLinuxnet: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-720538.86.1LinuxLinuxnet: ipip: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-720548.86.1LinuxLinuxnet: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-720558.86.1LinuxLinuxnet: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-721368.86.1LinuxLinuxxfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-684747.86.1LinuxLinuxpowerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
CVE-2026-684797.86.1LinuxLinuxBluetooth: btrtl: validate firmware patch bounds
CVE-2026-720057.86.1LinuxLinuxwifi: rt2x00: avoid full teardown before work setup in probe
CVE-2026-720247.86.1LinuxLinuxmac802154: remove interfaces with RCU list deletion
CVE-2026-720367.86.1LinuxLinuxnet/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeu…
CVE-2026-721027.86.1LinuxLinuxdm_early_create: fix freeing used table on dm_resume failure
CVE-2026-721057.86.1LinuxLinuxdm-log: fix a bitset_size overflow on 32bit machines
CVE-2026-721087.86.1LinuxLinuxdm thin metadata: fix metadata snapshot consistency on commit failure
CVE-2026-721097.86.1LinuxLinuxnet: sparx5: unregister blocking notifier on init failure
CVE-2026-721207.86.1LinuxLinuxcan: bcm: add missing rcu list annotations and operations
CVE-2026-721237.86.1LinuxLinuxcan: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
CVE-2026-721357.86.1LinuxLinuxtpm: Make the TPM character devices non-seekable
CVE-2026-721647.86.1LinuxLinuxocfs2: avoid moving extents to occupied clusters
CVE-2026-721657.86.1LinuxLinuxmtd: rawnand: fix condition in 'nand_select_target()'
CVE-2026-721717.86.1LinuxLinuxmtd: slram: remove failed entries from the device list
CVE-2026-721817.86.1LinuxLinuxmips: sched: Fix CPUMASK_OFFSTACK memory corruption
CVE-2026-721957.86.1LinuxLinuxfs/ntfs3: bound attr_off in UpdateResidentValue against data_off
CVE-2026-722507.86.1LinuxLinuxnetfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag
CVE-2026-722557.86.1LinuxLinuxnetfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
CVE-2026-722617.86.1LinuxLinuxASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
CVE-2026-723017.86.1LinuxLinuxASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
CVE-2026-724007.86.1LinuxLinuxseg6: validate SRH length before reading fixed fields
CVE-2026-724067.86.1LinuxLinuxnet: sungem: fix probe error cleanup
CVE-2026-724197.86.1LinuxLinuxnetfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
CVE-2026-724357.86.1LinuxLinuxnetfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
CVE-2026-742837.86.1LinuxLinuxtipc: require net admin for TIPCv2 netlink mutators
CVE-2026-720458.86.0LinuxLinuxocteontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
CVE-2026-720518.86.0LinuxLinuxnet: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-722948.86.0LinuxLinuxLoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
CVE-2026-720127.86.0LinuxLinuxtracing/osnoise: Call synchronize_rcu() when unregistering
CVE-2026-720187.86.0LinuxLinuxdibs: loopback: validate offset and size in move_data()
CVE-2026-720347.86.0LinuxLinuxfhandle: reject detached mounts in capable_wrt_mount()
CVE-2026-721107.86.0LinuxLinuxbpf,fork: wipe ->bpf_storage before bailouts that access it
CVE-2026-721137.86.0LinuxLinuxcan: bcm: add missing device refcount for CAN filter removal
CVE-2026-721147.86.0LinuxLinuxcan: bcm: validate frame length in bcm_rx_setup() for RTR replies
CVE-2026-721197.86.0LinuxLinuxcan: bcm: extend bcm_tx_lock usage for data and timer updates
CVE-2026-721447.86.0LinuxLinuxplatform/x86: dell-laptop: fix missing cleanups in init error path
CVE-2026-721707.86.0LinuxLinux9p: skip nlink update in cacheless mode to fix WARN_ON
CVE-2026-721727.86.0LinuxLinuxmm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
CVE-2026-722447.86.0LinuxLinuxgpu/buddy: bail out of try_harder when alignment cannot be honoured
CVE-2026-722527.86.0LinuxLinuxnetfilter: nft_set_pipapo: don't leak bad clone into future transaction
CVE-2026-723047.86.0LinuxLinuxASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
CVE-2026-724107.86.0LinuxLinuxocteontx2-af: Validate NIX maximum LFs correctly
CVE-2026-724347.86.0LinuxLinuxnetfilter: ipset: make sure gc is properly stopped
CVE-2026-721627.85.8LinuxLinuxocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
CVE-2026-723907.85.9LinuxLinuxnet/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF
CVE-2026-724887.85.8LinuxLinuxsoundwire: fix bug in sdw_add_element_group_count found by syzkaller
CVE-2026-72439await5.9LinuxLinuxmd/raid10: fix writes_pending leak on write request failures
CVE-2026-72490await5.9LinuxLinuxstaging: rtl8723bs: fix stainfo check in rtw_aes_decrypt
CVE-2026-722958.85.8LinuxLinuxLoongArch: KVM: Validate irqchip index in irqfd routing
CVE-2026-725008.85.8LinuxLinuxRDMA/bnxt_re: Free SRQ toggle page after firmware teardown
CVE-2026-722438.45.7LinuxLinuxselinux: check connect-related permissions on TCP Fast Open
CVE-2026-720097.85.8LinuxLinuxpmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
CVE-2026-720427.85.8LinuxLinuxipmi: Fix user refcount underflow in event delivery
CVE-2026-720957.85.8LinuxLinuxdma-fence: Make dma_fence_dedup_array() robust against 0-count input
CVE-2026-742647.85.8LinuxLinuxnet: watchdog: fix refcount tracking races
CVE-2026-74424await5.8LinuxLinuxfbcon: fix NULL pointer dereference for a console without vc_data
CVE-2026-723897.85.6LinuxLinuxbridge: stp: Fix a potential use-after-free when deleting a bridge
CVE-2026-721227.35.7LinuxLinuxcan: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
CVE-2026-720437.15.7LinuxLinuxLoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
CVE-2026-720497.15.7LinuxLinuxieee802154: admin-gate legacy LLSEC dump operations
CVE-2026-721257.85.6LinuxLinuxcan: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
CVE-2026-721267.85.6LinuxLinuxcan: isotp: use unconditional synchronize_rcu() in isotp_release()
CVE-2026-721037.35.6LinuxLinuxdm: avoid leaking the caller's thread keyring via the table device file
CVE-2026-722137.15.6LinuxLinuxmm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
CVE-2026-722977.15.6LinuxLinuxnet: atm: reject out-of-range traffic classes in QoS validation
CVE-2026-723837.85.4LinuxLinuxsctp: fix addr_wq_timer race in sctp_free_addr_wq()
CVE-2026-721437.15.4LinuxLinuxplatform/x86: ISST: Restore SST-PP control to all domains
CVE-2026-74553await5.4LinuxLinuxhwmon: (nct6775-core) Fix number of temperature registers for NCT6116
CVE-2026-74577await5.4LinuxLinuxnet: mpls: initialize rtm_tos in mpls_getroute()
CVE-2026-722327.85.2LinuxLinuxbatman-adv: ensure minimal ethernet header on TX
CVE-2026-74392await5.2LinuxLinuxdm: limit target bio polling to one shot
CVE-2026-74432await5.3LinuxLinuxrxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
CVE-2026-74555await5.3LinuxLinuxscsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
CVE-2026-74566await5.3LinuxLinuxkeys: make keyring key-chunk byte order agree with keyring_diff_objects()
CVE-2026-185008.15.2@fastify/jwt@fastify/jwtCWE-347@fastify/jwt vulnerable to authorization bypass via global secret overriding …
CVE-2026-68455await5.2LinuxLinuxliveupdate: validate session type before performing operation
CVE-2026-68468await5.2LinuxLinuxmtd: virt-concat: free duplicate generated name
CVE-2026-74272await5.2LinuxLinuxcxl/region: Resolve region deletion races
CVE-2026-74273await5.2LinuxLinuxcxl/region: Block region delete during region creation
CVE-2026-74291await5.2LinuxLinuxASoC: topology: Check PCM and DAI name strings before use
CVE-2026-74298await5.2LinuxLinuxRDMA/core: Fix FRMR set pinned push error path
CVE-2026-74299await5.2LinuxLinuxRDMA/core: Fix FRMR aging push to queue error flow
CVE-2026-74304await5.2LinuxLinuxBluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serde…
CVE-2026-74319await5.2LinuxLinuxbtrfs: zoned: fix deadlock waiting for ticket during data relocation
CVE-2026-74326await5.2LinuxLinuxwifi: mt76: mt7921: fix resource leak in probe error path
CVE-2026-74336await5.2LinuxLinuxwifi: mac80211: bound S1G TIM PVB walk to the TIM element
CVE-2026-74342await5.2LinuxLinuxkernfs: link kn to its parent before the LSM init hook
CVE-2026-74368await5.2LinuxLinuxwifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic()
CVE-2026-74369await5.2LinuxLinuxliveupdate: fix u-a-f in luo_file_unpreserve_files() and luo_file_finish()
CVE-2026-74370await5.2LinuxLinuxliveupdate: fix TOCTOU race in luo_session_retrieve()
CVE-2026-74375await5.2LinuxLinuxmd/raid1,raid10: fix deadlock in read error recovery path
CVE-2026-74414await5.2LinuxLinuxhfsplus: Remove the duplicate attr inode dirty marking action
CVE-2026-74415await5.2LinuxLinuxspi: atcspi200: fix use-after-free when driver unbind
CVE-2026-74420await5.2LinuxLinuxdrm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges
CVE-2026-74421await5.2LinuxLinuxdrm/rockchip: dw_dp: Switch to drmm_kzalloc()
CVE-2026-74483await5.2LinuxLinuxbinfmt_misc: don't leak the user namespace when the mount fails
CVE-2026-74526await5.2LinuxLinuxscsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit
CVE-2026-74542await5.2LinuxLinuxnetfs: Fix folio_queue ENOMEM in writeback by adding a mempool
CVE-2026-74560await5.1LinuxLinuxxsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
CVE-2026-724238.85.1LinuxLinuxbpf: Guard conntrack opts error writes
CVE-2026-742778.85.1LinuxLinuxiommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path
CVE-2026-724788.45.1LinuxLinuxfs/ntfs3: add bounds check to run_get_highest_vcn()
CVE-2026-723127.95.1LinuxLinuxocteontx2-af: fix VF bringup affecting PF promiscuous state
CVE-2026-684737.85.1LinuxLinuxpowerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address()
CVE-2026-720907.85.1LinuxLinuxaccel/amdxdna: Use caller client for debug BO sync
CVE-2026-721127.85.1LinuxLinuxio_uring/bpf-ops: reject re-registration of an already-bound ops
CVE-2026-721987.85.1LinuxLinuxntfs: reject non-resident records for resident-only attributes
CVE-2026-722857.85.1LinuxLinuxKVM: TDX: Reject concurrent change to CPUID entry count
CVE-2026-723037.85.1LinuxLinuxASoC: SOF: ipc4-control: Validate notification payload size
CVE-2026-724047.85.1LinuxLinuxtipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()
CVE-2026-724117.85.1LinuxLinuxnet: dsa: mxl862xx: fix use-after-free of DSA ports in crc_err_work
CVE-2026-724857.85.1LinuxLinuxcoresight: platform: defer connection counter increment until alloc succeeds
CVE-2026-742587.85.1LinuxLinuxbpf: Guard __get_user acesss with access_ok for uprobe_multi data
CVE-2026-742607.85.1LinuxLinuxnetfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them
CVE-2026-74418await5.0LinuxLinuxdma-fence: Fix potential tracepoint null pointer dereferences
CVE-2026-74423await5.1LinuxLinuxaccel/amdxdna: Fix leak when pinning ubuf pages
CVE-2026-74437await5.1LinuxLinuxmedia: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work
CVE-2026-724467.85.0LinuxLinuxALSA: usb-audio: qcom: reject stream disable with no active interface
CVE-2026-188074.34.9UnknownECSCWE-862ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modificat…
CVE-2026-723977.14.8LinuxLinuxhwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()
CVE-2026-724898.44.7LinuxLinuxstaging: nvec: fix use-after-free in nvec_rx_completed()
CVE-2026-724157.14.7LinuxLinuxASoC: SDCA: Validate written enum value in ge_put_enum_double()
CVE-2026-745197.84.3LinuxLinuxpinctrl: devicetree: don't free uninitialized dev_name on error path
CVE-2026-74422await4.3LinuxLinuxdrm/rockchip: inno-hdmi: Switch to drmm_kzalloc()
CVE-2026-74558await4.3LinuxLinuxxsk: reclaim invalid Tx descriptors in ZC batch path
CVE-2026-74571await4.3LinuxLinuxbtrfs: skip global block reserve accounting for rescue mounts
CVE-2026-743328.44.2LinuxLinuxASoC: amd: acp-sdw-sof: Bound DAI link iteration
CVE-2026-743338.44.0LinuxLinuxASoC: amd: acp-sdw-legacy: Bound DAI link iteration
CVE-2026-743838.44.1LinuxLinuxnvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools
CVE-2026-744928.44.0LinuxLinuxnetfilter: ipset: do not update comments from kernel-side hash adds
CVE-2026-744978.44.0LinuxLinuxALSA: usb-audio: Clamp frame size in implicit-feedback mode
CVE-2026-743787.84.0LinuxLinuxRDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
CVE-2026-744047.84.0LinuxLinuxcrypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one
CVE-2026-744527.84.0LinuxLinuxdrm/panthor: reject firmware sections with oversized data
CVE-2026-722877.84.0LinuxLinuxKVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks
CVE-2026-743109.33.8LinuxLinuxvhost/net: complete zerocopy ubufs only once
CVE-2026-724827.83.8LinuxLinuxgpib: fix double decrement of descriptor_busy in command_ioctl()
CVE-2026-745107.83.8LinuxLinuxBluetooth: mgmt: fix UAF in pair command cancellation
CVE-2026-744618.43.6LinuxLinuxi2c: imx: Cancel hrtimer before clearing slave pointer
CVE-2026-724447.83.7LinuxLinuxflow_dissector: check device type before reading ETH_ADDRS
CVE-2026-724597.83.7LinuxLinuxapparmor: aa_label_alloc use aa_label_free on alloc failure
CVE-2026-724707.83.7LinuxLinuxfs/ntfs3: resize log->one_page_buf when adopting on-disk page size
CVE-2026-724807.83.7LinuxLinuxiio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
CVE-2026-724628.83.5LinuxLinuxapparmor: fix race in unix socket mediation when peer_path is used
CVE-2026-724617.83.5LinuxLinuxapparmor: fix refcount leak when updating the sk_ctx
CVE-2026-742627.83.5LinuxLinuxkcm: use WRITE_ONCE() when changing lower socket callbacks
CVE-2026-744399.33.3LinuxLinuxiommu/vt-d: Clear Present bit before tearing down scalable-mode context entry
CVE-2026-745168.23.4LinuxLinuxKVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
CVE-2026-724057.83.4LinuxLinuxnet: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
CVE-2026-724277.83.4LinuxLinuxbpf: Fix effective prog array index with BPF_F_PREORDER
CVE-2026-730478.63.3siyuan-notesiyuanCWE-200siyuan before v3.7.4 Server-Side Template Injection via attribute-view
CVE-2026-744387.83.3LinuxLinuxcrypto: sun4i-ss - Remove insecure and unused rng_alg
CVE-2026-142305.43.3UnknownECSCWE-79ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings
CVE-2026-743558.23.2LinuxLinuxiommu/vt-d: Fix RB-tree corruption in probe error path
CVE-2026-744817.83.2LinuxLinuxmm/page_reporting: use system_freezable_wq to fix UAF during suspend
CVE-2026-743657.33.2LinuxLinuxnvdimm/btt: Handle preemption in BTT lane acquisition
CVE-2026-743647.13.2LinuxLinuxbpf: Reject exclusive maps as inner maps in map-in-map
CVE-2026-745179.33.2LinuxLinuxKVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
CVE-2026-745739.33.1LinuxLinuxiommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
CVE-2026-742758.43.1LinuxLinuxcxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach()
CVE-2026-724607.13.1LinuxLinuxapparmor: check label build before no_new_privs test
CVE-2026-684668.83.0LinuxLinuxmtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
CVE-2026-743808.83.0LinuxLinuxgpu: host1x: Fix iommu_map_sgtable() return value check
CVE-2026-744438.82.9LinuxLinuxdrm/vmwgfx: bound DMA command body size against suffix pointer
CVE-2026-745158.82.9LinuxLinuxKVM: s390: pci: Reject adapter interrupt forwarding if already enabled
CVE-2026-684617.83.0LinuxLinuxdevice property: initialize the remaining fields of fwnode_handle in fwnode_i…
CVE-2026-684677.83.0LinuxLinuxmtd: mchp23k256: use SPI match data for chip caps
CVE-2026-724547.83.0LinuxLinuxi3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()
CVE-2026-742887.83.0LinuxLinuxnet: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
CVE-2026-742937.83.0LinuxLinuxASoC: fsl: fsl_audmix: Validate written enum values
CVE-2026-742967.83.0LinuxLinuxRDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
CVE-2026-742977.83.0LinuxLinuxRDMA/mlx5: Fix undefined shift of user RQ WQE size
CVE-2026-743057.83.0LinuxLinuxbpf: Tighten cgroup storage cookie checks for prog arrays
CVE-2026-743127.83.0LinuxLinuxvhost/vdpa: validate virtqueue index in mmap and fault paths
CVE-2026-743147.83.0LinuxLinuxbpf: Cancel special fields on map value recycle
CVE-2026-743307.83.0LinuxLinuxconfigfs: fix lockless traversals of ->s_children
CVE-2026-743777.83.0LinuxLinuxRDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
CVE-2026-743907.83.0LinuxLinuxRDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs
CVE-2026-743977.83.0LinuxLinuxIB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
CVE-2026-744407.82.9LinuxLinuxdrm/xe: Wait on external BO kernel fences in exec IOCTL
CVE-2026-744447.82.9LinuxLinuxdrm/vmwgfx: validate DRAW_PRIMITIVES header size before division
CVE-2026-744467.82.9LinuxLinuxdrm/amdkfd: hold event_mutex while checkpointing CRIU events
CVE-2026-744477.82.9LinuxLinuxdrm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
CVE-2026-744517.82.9LinuxLinuxdrm/panthor: validate firmware interface structure sizes
CVE-2026-744537.82.9LinuxLinuxdrm/vc4: Zero the tile state data array before each BIN job
CVE-2026-744547.82.9LinuxLinuxdrm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
CVE-2026-744567.82.9LinuxLinuxcan: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB su…
CVE-2026-744677.82.9LinuxLinuxs390/qeth: Check CAP_NET_ADMIN for private ioctls
CVE-2026-744707.82.9LinuxLinuxscsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
CVE-2026-745037.82.9LinuxLinuxALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
CVE-2026-745497.83.0LinuxLinuxhwmon: (nct6775-core) Prevent access to unsupported weight registers
CVE-2026-745517.82.9LinuxLinuxhwmon: (nzxt-smart2) DMA-align output buffer
CVE-2026-724557.13.0LinuxLinuxapparmor: fix uninitialised pointer passed to audit_log_untrustedstring()
CVE-2026-742707.82.9LinuxLinuxhandshake: Require admin permission for DONE command
CVE-2026-743067.82.9LinuxLinuxvfio/qat: fix f_pos race in qat_vf_resume_write()
CVE-2026-743387.82.8LinuxLinuxbpf: Reject sleepable BPF_LSM_CGROUP programs at load time
CVE-2026-744057.82.8LinuxLinuxOPP: Fix race between OPP addition and lookup
CVE-2026-745208.82.8LinuxLinuxiommu/iommufd: Fix IOPF group ownership UAF
CVE-2026-684587.82.8LinuxLinuxbinder: cache secctx size before release zeroes it
CVE-2026-743117.82.8LinuxLinuxvirtio: rtc: tear down old virtqueues before restore
CVE-2026-743257.82.8LinuxLinuxwifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
CVE-2026-743447.82.8LinuxLinuxbpf: Clear rb node linkage when freeing bpf_rb_root
CVE-2026-743717.82.8LinuxLinuxbpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
CVE-2026-742927.12.7LinuxLinuxASoC: tegra: tegra210_ahub: Validate written enum value
CVE-2026-742957.12.7LinuxLinuxASoC: codecs: hdac_hdmi: Validate written enum value
CVE-2026-743497.12.7LinuxLinuxocfs2: reject FITRIM ranges shorter than a cluster
CVE-2026-743138.82.6LinuxLinuxvduse: hold vduse_lock across IDR lookup in open path
CVE-2026-743027.82.6LinuxLinuxBluetooth: hci_core: Fix UAF in hci_unregister_dev()
CVE-2026-743597.82.6LinuxLinuxconfigfs_lookup(): don't leave ->s_dentry dangling on failure
CVE-2026-743637.82.6LinuxLinuxbpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
CVE-2026-743877.82.6LinuxLinuxALSA: seq: midi: Serialize output teardown with event_input
CVE-2026-744657.82.6LinuxLinuxnet: openvswitch: fix potential UAF on meter attach failure
CVE-2026-744717.82.6LinuxLinuxtracing: Check return value of __register_event() in trace_module_add_events()
CVE-2026-744827.82.6LinuxLinuxmm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
CVE-2026-745117.82.6LinuxLinuxBluetooth: mgmt: fix pending command UAF in EIR updates
CVE-2026-745127.82.6LinuxLinuxaudit: fix potential use-after-free in audit_del_rule()
CVE-2026-745187.82.6LinuxLinuxmm/hugetlb: fix list corruption in allocate_file_region_entries()
CVE-2026-745487.82.6LinuxLinuxforcedeth: fix UAF of txrx_stats in nv_remove
CVE-2026-744857.12.6LinuxLinuxbinfmt_misc: reject a flag character as the field delimiter
CVE-2026-724969.22.6LinuxLinuxRDMA/bnxt_re: Proper rollback if the ioremap fails
CVE-2026-742577.82.5LinuxLinuxsockmap: Fix use-after-free in udp_bpf_recvmsg()
CVE-2026-743887.82.5LinuxLinuxALSA: seq: oss: Fix UAF at handling events with embedded SysEx data
CVE-2026-744797.82.5LinuxLinuxnet: pktgen: fix proc entry use-after-free
CVE-2026-745067.82.5LinuxLinuxafs: Fix UAF when sending a message
CVE-2026-745137.82.5LinuxLinuxdibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
CVE-2026-198916.32.5TRENDnetTEW-WLC100CWE-311TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption
CVE-2026-745689.32.4LinuxLinuxKVM: arm64: vgic: Fix race between LPI release and re-registration
CVE-2026-745747.82.4LinuxLinuxdmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
CVE-2026-744037.82.3LinuxLinuxcrypto: ccp - Check for page allocation failure correctly in TIO
CVE-2026-745447.82.3LinuxLinuxnet/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
CVE-2026-724978.82.2LinuxLinuxRDMA/bnxt_re: Add a max slot check for SQ
CVE-2026-724998.82.2LinuxLinuxRDMA/bnxt_re: Free CQ toggle page after firmware teardown
CVE-2026-742858.82.2LinuxLinuxnet: Stop leased rxq before uninstalling its memory provider
CVE-2026-743288.82.2LinuxLinuxiommufd: Destroy the pages content after detaching from dmabuf
CVE-2026-745278.82.2LinuxLinuxocteontx2-af: Block VFs from clobbering special CGX PKIND state
CVE-2026-684627.82.2LinuxLinuxbpf: Reject negative const offsets for buffer pointers
CVE-2026-742897.82.2LinuxLinuxipv4: fib: Don't dump dying fib_info in fib_leaf_notify().
CVE-2026-743177.82.2LinuxLinuxixgbe: do not configure xps for XDP queues
CVE-2026-743347.82.2LinuxLinuxRDMA/nldev: Fix locking when accessing mr->pd
CVE-2026-743437.82.2LinuxLinuxkernfs: fix xattr race condition with multiple superblocks
CVE-2026-743477.82.2LinuxLinuxnetfilter: cttimeout: detach dataplane timeout policy and repurpose refcount
CVE-2026-743547.82.2LinuxLinuxbpf: Take mmap_lock in zap_pages()
CVE-2026-743577.82.2LinuxLinuxdrm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump
CVE-2026-743677.82.2LinuxLinuxwifi: ath12k: fix inconsistent arvif state in vdev_create error paths
CVE-2026-744177.82.1LinuxLinuxdrm/radeon: fix integer overflow in radeon_align_pitch()
CVE-2026-744497.82.2LinuxLinuxdrm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport
CVE-2026-744507.82.2LinuxLinuxdrm/amd/pm: fix pptable use-after-free
CVE-2026-744967.82.2LinuxLinuxfou: Fix use-after-free in fou_create()
CVE-2026-745297.82.2LinuxLinuxBluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
CVE-2026-745637.81.9LinuxLinuxrds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
CVE-2026-745647.12.0LinuxLinuxnetfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
CVE-2026-745677.11.9LinuxLinuxkeys: fix out-of-bounds read in keyring_get_key_chunk()
CVE-2026-745657.81.9LinuxLinuxnetfilter: nf_tables: make nft_object rhltable per table
CVE-2026-742947.31.8LinuxLinuxASoC: meson: aiu: Validate written enum values
CVE-2026-745628.81.6LinuxLinuxnexthop: take nh->lock for f6i_list walks in replace check and notify
CVE-2026-745618.81.6LinuxLinuxnexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush
CVE-2026-744197.31.5LinuxLinuxaccel/amdxdna: Adjust size for copy_to_user()
CVE-2026-181654.20.9@fastify/oauth2@fastify/oauth2CWE-352@fastify/oauth2 vulnerable to Login CSRF via plantable OAuth state cookies