Edition of August 15, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-74265 | await | 10.9 | Linux | Linux | — | net: mana: initialize gdma queue id to INVALID_QUEUE_ID |
| CVE-2026-74271 | await | 10.9 | Linux | Linux | — | power: supply: core: fix supplied_from allocations |
| CVE-2026-74554 | 8.8 | 10.7 | Linux | Linux | — | wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup() |
| CVE-2026-16007 | 7.1 | 10.6 | AppFlowy-IO | AppFlowy-Cloud | CWE-89 | Authenticated SQL Injection in AppFlowy |
| CVE-2026-72180 | await | 10.3 | Linux | Linux | — | mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade |
| CVE-2026-19917 | 2.1 | 10.2 | code-projects | Online Food Order System | CWE-89 | code-projects Online Food Order System delete_food_items1.php sql injection |
| CVE-2026-19920 | 2.1 | 10.2 | code-projects | Online Shopping System | CWE-74 | code-projects Online Shopping System action.php sql injection |
| CVE-2026-72007 | await | 10.2 | Linux | Linux | — | pmdomain: imx: Fix i.MX8MP VC8000E power up sequence |
| CVE-2026-72015 | await | 10.2 | Linux | Linux | — | fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list |
| CVE-2026-72017 | await | 10.1 | Linux | Linux | — | net: macb: drop in-flight Tx SKBs on close |
| CVE-2026-72023 | await | 10.2 | Linux | Linux | — | octeontx2-pf: fix SQB pointer leak on init failure |
| CVE-2026-72026 | await | 10.2 | Linux | Linux | — | irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure |
| CVE-2026-72028 | await | 10.2 | Linux | Linux | — | riscv: probes: save original sp in rethook trampoline |
| CVE-2026-72030 | await | 10.2 | Linux | Linux | — | ata: libata-core: Reject an invalid concurrent positioning ranges count |
| CVE-2026-72032 | await | 10.2 | Linux | Linux | — | net/mlx5: HWS, fix matcher leak on resize target setup failure |
| CVE-2026-72040 | await | 10.2 | Linux | Linux | — | ipmi: fix refcount leak in i_ipmi_request() |
| CVE-2026-72050 | await | 10.2 | Linux | Linux | — | octeontx2-af: Free BPID bitmap on setup failure |
| CVE-2026-72096 | await | 10.2 | Linux | Linux | — | dm-verity: make error counter atomic |
| CVE-2026-72101 | await | 10.1 | Linux | Linux | — | dm-integrity: fix leaking uninitialized kernel memory |
| CVE-2026-72117 | await | 10.2 | Linux | Linux | — | can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() |
| CVE-2026-72118 | await | 10.2 | Linux | Linux | — | can: bcm: fix CAN frame rx/tx statistics |
| CVE-2026-72127 | await | 10.1 | Linux | Linux | — | netdev-genl: report NAPI thread PID in the caller's pid namespace |
| CVE-2026-72132 | await | 10.2 | Linux | Linux | — | NFS: Charge unstable writes by request size, not folio size |
| CVE-2026-72142 | await | 10.2 | Linux | Linux | — | i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) |
| CVE-2026-72147 | await | 10.2 | Linux | Linux | — | dmaengine: dw-edma-pcie: Reject devices without driver data |
| CVE-2026-72158 | await | 10.1 | Linux | Linux | — | fpga: dfl: add bounds check in dfh_get_param_size() |
| CVE-2026-72168 | await | 10.2 | Linux | Linux | — | mtd: maps: vmu-flash: fix fault in unaligned fixup |
| CVE-2026-72174 | await | 10.1 | Linux | Linux | — | fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() |
| CVE-2026-72176 | await | 10.1 | Linux | Linux | — | mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error |
| CVE-2026-72178 | await | 10.1 | Linux | Linux | — | mm/damon/core: always put unsuccessfully committed target pids |
| CVE-2026-72212 | await | 10.2 | Linux | Linux | — | mm/memory_hotplug: fix incorrect altmap passing in error path |
| CVE-2026-72216 | await | 10.2 | Linux | Linux | — | remoteproc: qcom: Fix leak when custom dump_segments addition fails |
| CVE-2026-72237 | await | 10.2 | Linux | Linux | — | perf/x86/amd/brs: Fix kernel address leakage |
| CVE-2026-72258 | await | 10.2 | Linux | Linux | — | ASoC: mediatek: mt8183: Release reserved memory on cleanup |
| CVE-2026-72259 | await | 10.2 | Linux | Linux | — | ASoC: mediatek: mt8192: Release reserved memory on cleanup |
| CVE-2026-72266 | await | 10.1 | Linux | Linux | — | fbdev: vesafb: fix memory leak in vesafb_probe() |
| CVE-2026-72273 | await | 10.1 | Linux | Linux | — | fbdev: efifb: fix memory leak in efifb_probe() |
| CVE-2026-72300 | await | 10.1 | Linux | Linux | — | ASoC: SOF: topology: validate vendor array size before parsing |
| CVE-2026-72305 | await | 10.2 | Linux | Linux | — | VDUSE: avoid leaking information to userspace |
| CVE-2026-72336 | await | 10.2 | Linux | Linux | — | Bluetooth: 6lowpan: hold L2CAP conn across debugfs control |
| CVE-2026-72362 | await | 10.2 | Linux | Linux | — | drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() |
| CVE-2026-72386 | await | 10.1 | Linux | Linux | — | drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced |
| CVE-2026-72387 | await | 10.2 | Linux | Linux | — | drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() |
| CVE-2026-72394 | await | 10.2 | Linux | Linux | — | hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero |
| CVE-2026-72430 | await | 10.1 | Linux | Linux | — | net/sched: act_ct: fix nf_connlabels leak on two error paths |
| CVE-2026-72468 | await | 10.2 | Linux | Linux | — | xprtrdma: Initialize re_id before removal registration |
| CVE-2026-72475 | await | 10.2 | Linux | Linux | — | dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc |
| CVE-2026-19916 | 2.0 | 10.0 | code-projects | Online Food Order System | CWE-79 | code-projects Online Food Order System edit_food_items.php cross site scripting |
| CVE-2026-72006 | await | 9.9 | Linux | Linux | — | net/mlx5: free mlx5_st_idx_data on final dealloc |
| CVE-2026-72016 | await | 9.9 | Linux | Linux | — | cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable() |
| CVE-2026-72091 | await | 9.9 | Linux | Linux | — | accel/amdxdna: reject user command submission without a command BO |
| CVE-2026-72094 | await | 9.9 | Linux | Linux | — | dma-buf: dma-fence: Fix potential NULL pointer dereference |
| CVE-2026-72104 | await | 9.9 | Linux | Linux | — | dm-pcache: reject option groups without values |
| CVE-2026-72128 | await | 9.9 | Linux | Linux | — | nvmet: fix refcount leak in nvmet_sq_create() |
| CVE-2026-72131 | await | 9.9 | Linux | Linux | — | nvme-apple: Prevent shared tags across queues on Apple A11 |
| CVE-2026-72150 | await | 9.9 | Linux | Linux | — | sunrpc: fix uninitialized xprt_create_args structure |
| CVE-2026-72169 | await | 9.9 | Linux | Linux | — | kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES |
| CVE-2026-72205 | await | 9.9 | Linux | Linux | — | ntfs: free volume-wide resources on fill_super failure |
| CVE-2026-72281 | await | 9.9 | Linux | Linux | — | KVM: arm64: account pKVM reclaim against the VM mm |
| CVE-2026-72292 | await | 9.9 | Linux | Linux | — | KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory |
| CVE-2026-72309 | await | 9.9 | Linux | Linux | — | tracing/remotes: Fix leak in trace_remote_alloc_buffer() error path |
| CVE-2026-72311 | await | 9.9 | Linux | Linux | — | drm/xe: free madvise VMA array on L2 flush failure |
| CVE-2026-72332 | await | 9.9 | Linux | Linux | — | accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo() |
| CVE-2026-72337 | await | 9.9 | Linux | Linux | — | Bluetooth: 6lowpan: avoid untracked enable work |
| CVE-2026-72346 | await | 9.9 | Linux | Linux | — | platform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/r… |
| CVE-2026-72359 | await | 9.9 | Linux | Linux | — | drm/xe: fix NPD in bo_meminfo() |
| CVE-2026-72370 | await | 9.9 | Linux | Linux | — | iomap: release pages on atomic dio size mismatch |
| CVE-2026-72377 | await | 9.9 | Linux | Linux | — | afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints |
| CVE-2026-72385 | await | 9.9 | Linux | Linux | — | tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry() |
| CVE-2026-72403 | await | 9.9 | Linux | Linux | — | ALSA: FCP: Fix NULL pointer dereference in interface lookup |
| CVE-2026-72431 | await | 9.9 | Linux | Linux | — | alloc_tag: fix use-after-free in /proc/allocinfo after module unload |
| CVE-2026-72432 | await | 9.9 | Linux | Linux | — | tpm_crb: Check ACPI_COMPANION() against NULL during probe |
| CVE-2026-72453 | await | 9.9 | Linux | Linux | — | regcache: Do not overwrite error code when finalizing cache after error |
| CVE-2026-72458 | await | 9.9 | Linux | Linux | — | apparmor: fix NULL pointer dereference in unpack_pdb |
| CVE-2026-74261 | await | 9.9 | Linux | Linux | — | ALSA: seq: avoid stale FIFO cells during resize |
| CVE-2026-74266 | await | 9.9 | Linux | Linux | — | net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek bef… |
| CVE-2026-72343 | 8.4 | 9.6 | Linux | Linux | — | net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation |
| CVE-2026-74382 | await | 9.5 | Linux | Linux | — | net/sched: cls_bpf: prevent unbounded recursion in offload rollback |
| CVE-2026-72277 | 9.3 | 9.4 | Linux | Linux | — | KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory |
| CVE-2026-72278 | 9.3 | 9.4 | Linux | Linux | — | KVM: arm64: nv: Re-translate VNCR before injecting abort |
| CVE-2026-72342 | 8.4 | 9.3 | Linux | Linux | — | net/mlx5e: Fix HV VHCA stats agent registration race |
| CVE-2026-74331 | await | 9.0 | Linux | Linux | — | firmware_loader: Fix recursive lock in device_cache_fw_images() |
| CVE-2026-72279 | 9.0 | 8.8 | Linux | Linux | — | KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR |
| CVE-2026-72008 | await | 8.9 | Linux | Linux | — | pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check |
| CVE-2026-72031 | await | 8.9 | Linux | Linux | — | ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD |
| CVE-2026-72145 | await | 8.9 | Linux | Linux | — | platform/x86/intel/tpmi: use cleanup helpers in mem_write() |
| CVE-2026-72173 | await | 8.9 | Linux | Linux | — | fs/proc/task_mmu: do not warn on seeing non-migration pmd entry |
| CVE-2026-72184 | await | 8.9 | Linux | Linux | — | ntfs: fix hole runlist memory leak in insert range error path |
| CVE-2026-72187 | await | 8.9 | Linux | Linux | — | ntfs: avoid self-deadlock during inode eviction |
| CVE-2026-72189 | await | 8.9 | Linux | Linux | — | ntfs: fail attrlist updates when the superblock is inactive |
| CVE-2026-72190 | await | 8.9 | Linux | Linux | — | ntfs: fix mrec_lock ABBA deadlock in rename |
| CVE-2026-72263 | await | 8.9 | Linux | Linux | — | ASoC: SOF: topology: fix memory leak in snd_sof_load_topology |
| CVE-2026-72293 | await | 8.9 | Linux | Linux | — | KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault() |
| CVE-2026-72313 | await | 8.9 | Linux | Linux | — | drm/fb-helper: Only consider active CRTCs for vblank sync |
| CVE-2026-72388 | await | 8.9 | Linux | Linux | — | drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock |
| CVE-2026-72402 | await | 8.9 | Linux | Linux | — | bpf: Mask pseudo pointer values in verifier logs |
| CVE-2026-72413 | await | 8.9 | Linux | Linux | — | sctp: fix err_chunk memory leaks in INIT handling |
| CVE-2026-72456 | await | 8.9 | Linux | Linux | — | apparmor: release exe file resources on path failure |
| CVE-2026-72284 | 7.1 | 8.6 | Linux | Linux | — | KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs |
| CVE-2026-72280 | 7.1 | 8.5 | Linux | Linux | — | KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 |
| CVE-2026-72425 | 7.1 | 8.5 | Linux | Linux | — | ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() |
| CVE-2026-72448 | await | 8.3 | Linux | Linux | — | octeontx2-pf: Fix leak of SQ timestamp buffer on teardown |
| CVE-2026-72289 | 9.3 | 8.1 | Linux | Linux | — | KVM: arm64: vgic: Check the interrupt is still ours before migrating it |
| CVE-2026-72133 | 8.4 | 8.1 | Linux | Linux | — | spi: uniphier: Fix completion initialization order before devm_request_irq() |
| CVE-2026-72151 | 8.4 | 8.1 | Linux | Linux | — | tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt |
| CVE-2026-72196 | 8.4 | 8.1 | Linux | Linux | — | fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass |
| CVE-2026-72197 | 8.4 | 8.1 | Linux | Linux | — | fs/ntfs3: bound DeleteIndexEntryAllocation memmove length |
| CVE-2026-72298 | 8.4 | 8.1 | Linux | Linux | — | net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() |
| CVE-2026-74256 | 8.4 | 8.1 | Linux | Linux | — | bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check |
| CVE-2026-74259 | 8.4 | 8.1 | Linux | Linux | — | cifs: remove all cifs files before kill super |
| CVE-2026-72483 | 7.8 | 8.0 | Linux | Linux | — | usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() |
| CVE-2026-72329 | 9.3 | 7.8 | Linux | Linux | — | net/liquidio: drop cached VF pci_dev LUT |
| CVE-2026-72412 | 9.3 | 7.8 | Linux | Linux | — | s390/mm: Fix handling of _PAGE_UNUSED pte bit |
| CVE-2026-72146 | 8.4 | 7.9 | Linux | Linux | — | dmaengine: sh: rz-dmac: Move interrupt request after everything is set up |
| CVE-2026-72426 | 8.4 | 7.8 | Linux | Linux | — | bpf: Preserve pointer spill metadata during half-slot cleanup |
| CVE-2026-72487 | 7.7 | 7.9 | Linux | Linux | — | PCI: Check ROM header and data structure addr before accessing |
| CVE-2026-72116 | 7.1 | 7.8 | Linux | Linux | — | can: bcm: fix stale rx/tx ops after device removal |
| CVE-2026-72424 | await | 7.9 | Linux | Linux | — | rtc: msc313: fix NULL deref in shared IRQ handler at probe |
| CVE-2026-72486 | await | 7.9 | Linux | Linux | — | mailbox: mtk-adsp: fix UAF during device teardown |
| CVE-2026-72283 | 8.8 | 7.7 | Linux | Linux | — | KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails |
| CVE-2026-72288 | 9.3 | 7.6 | Linux | Linux | — | KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disab… |
| CVE-2026-72495 | 9.3 | 7.6 | Linux | Linux | — | RDMA/bnxt_re: Avoid repeated requests to allocate WC pages |
| CVE-2026-72085 | 9.3 | 7.6 | Linux | Linux | — | scsi: xen: scsiback: Free unsubmitted command instead of double-putting it |
| CVE-2026-72262 | 7.8 | 7.5 | Linux | Linux | — | ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get |
| CVE-2026-72302 | 7.8 | 7.6 | Linux | Linux | — | ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc |
| CVE-2026-74402 | await | 7.5 | Linux | Linux | — | crypto: atmel-sha204a - fix blocking and non-blocking rng logic |
| CVE-2026-74416 | await | 7.5 | Linux | Linux | — | drm/radeon: fix memory leak in radeon_ring_restore() on lock failure |
| CVE-2026-72061 | 8.8 | 7.4 | Linux | Linux | — | net: sit: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-72066 | 7.8 | 7.4 | Linux | Linux | — | cpu: hotplug: Bound hotplug states sysfs output |
| CVE-2026-72067 | 7.8 | 7.4 | Linux | Linux | — | cpu: hotplug: Preserve per instance callback errors |
| CVE-2026-72282 | 7.8 | 7.4 | Linux | Linux | — | KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers |
| CVE-2026-72314 | 7.8 | 7.4 | Linux | Linux | — | regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK |
| CVE-2026-72350 | 7.8 | 7.4 | Linux | Linux | — | netfilter: xt_u32: reject invalid shift counts |
| CVE-2026-72371 | 7.8 | 7.4 | Linux | Linux | — | afs: Fix the volume AFS_VOLUME_RM_TREE is set on |
| CVE-2026-72450 | 7.8 | 7.4 | Linux | Linux | — | xfrm: validate selector family and prefixlen during match |
| CVE-2026-68456 | await | 7.5 | Linux | Linux | — | usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() |
| CVE-2026-68460 | await | 7.5 | Linux | Linux | — | f2fs: fix potential deadlock in f2fs_balance_fs() |
| CVE-2026-74276 | await | 7.5 | Linux | Linux | — | spi: xilinx: use FIFO occupancy register to determine buffer size |
| CVE-2026-74320 | await | 7.5 | Linux | Linux | — | fbdev: sm501fb: Fix buffer errors in OF binding code |
| CVE-2026-74348 | await | 7.5 | Linux | Linux | — | ocfs2/dlm: require a ref for locking_state debugfs open |
| CVE-2026-74351 | await | 7.5 | Linux | Linux | — | ocfs2: rebase copied fsdlm LVB pointers in locking_state |
| CVE-2026-74395 | await | 7.5 | Linux | Linux | — | RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference |
| CVE-2026-72286 | 8.8 | 7.3 | Linux | Linux | — | KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs |
| CVE-2026-72027 | 7.8 | 7.3 | Linux | Linux | — | mm/compaction: handle free_pages_prepare() properly in compaction_free() |
| CVE-2026-72340 | 7.8 | 7.3 | Linux | Linux | — | net: microchip: vcap: fix races on the shared Super VCAP block |
| CVE-2026-72352 | 7.8 | 7.3 | Linux | Linux | — | HID: bpf: Fix hid_bpf_get_data() range check |
| CVE-2026-72369 | 7.8 | 7.3 | Linux | Linux | — | minix: avoid overflow in bitmap block count calculation |
| CVE-2026-72372 | 7.8 | 7.3 | Linux | Linux | — | afs: Fix lack of locking around modifications of net->cells_dyn_ino |
| CVE-2026-72452 | 7.8 | 7.3 | Linux | Linux | — | drm/i915: clear CRTC color blob pointers after dropping refs |
| CVE-2026-72443 | await | 7.3 | Linux | Linux | — | ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints |
| CVE-2026-72347 | 7.3 | 7.1 | Linux | Linux | — | netfilter: xt_connmark: reject invalid shift parameters |
| CVE-2026-72154 | 7.8 | 7.1 | Linux | Linux | — | openrisc: Fix jump_label smp syncing |
| CVE-2026-72357 | 7.8 | 7.1 | Linux | Linux | — | uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline |
| CVE-2026-72375 | 7.8 | 7.1 | Linux | Linux | — | afs: Fix reinitialisation of the inode, in particular ->lock_work |
| CVE-2026-72416 | 7.3 | 7.0 | Linux | Linux | — | netfilter: nft_compat: ebtables emulation must reject non-bridge targets |
| CVE-2026-72111 | 8.8 | 6.9 | Linux | Linux | — | bpf: Reset register bounds before narrowing retval range in check_mem_access() |
| CVE-2026-72225 | 7.8 | 7.0 | Linux | Linux | — | jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() |
| CVE-2026-68459 | await | 7.0 | Linux | Linux | — | f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() |
| CVE-2026-74274 | await | 7.0 | Linux | Linux | — | cxl/region: Fill first free targets[] slot during auto-discovery |
| CVE-2026-74290 | await | 7.0 | Linux | Linux | — | net/sched: cls_flow: Dont expose folded kernel pointers |
| CVE-2026-74327 | await | 7.0 | Linux | Linux | — | vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() |
| CVE-2026-74329 | await | 7.0 | Linux | Linux | — | watchdog: unregister PM notifier on watchdog unregister |
| CVE-2026-74339 | await | 7.0 | Linux | Linux | — | ALSA: seq: Clear variable event pointer on read |
| CVE-2026-74346 | await | 7.0 | Linux | Linux | — | RDMA/irdma: Fix OOB read during CQ MR registration |
| CVE-2026-74373 | await | 7.0 | Linux | Linux | — | md/raid1,raid10: fix bio accounting for split md cloned bios |
| CVE-2026-74379 | await | 7.0 | Linux | Linux | — | dax/kmem: account for partial discontiguous resource upon removal |
| CVE-2026-74381 | await | 7.0 | Linux | Linux | — | gpu: host1x: Allow entries in BO caches to be freed |
| CVE-2026-74399 | await | 7.0 | Linux | Linux | — | evm: terminate and bound the evm_xattrs read buffer |
| CVE-2026-72360 | 8.4 | 6.8 | Linux | Linux | — | drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays |
| CVE-2026-72072 | 7.8 | 6.8 | Linux | Linux | — | net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete |
| CVE-2026-72335 | 7.8 | 6.8 | Linux | Linux | — | Bluetooth: MGMT: Fix adv monitor add failure cleanup |
| CVE-2026-72449 | 7.8 | 6.8 | Linux | Linux | — | drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm |
| CVE-2026-72476 | 7.8 | 6.8 | Linux | Linux | — | dmaengine: Fix possible use after free |
| CVE-2026-72175 | 7.1 | 6.9 | Linux | Linux | — | fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race |
| CVE-2026-72364 | 7.1 | 6.8 | Linux | Linux | — | netfs: Fix writeback error handling |
| CVE-2026-72071 | 7.8 | 6.8 | Linux | Linux | — | tracing/user_events: Fix use-after-free in user_event_mm_dup() |
| CVE-2026-74466 | await | 6.7 | Linux | Linux | — | s390/zcrypt: Close speculative mem read possibility |
| CVE-2026-72183 | 8.4 | 6.7 | Linux | Linux | — | landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path |
| CVE-2026-72395 | 7.1 | 6.7 | Linux | Linux | — | hwmon: (pmbus) Fix passing events to regulator core |
| CVE-2026-72239 | 9.3 | 6.5 | Linux | Linux | — | x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN" |
| CVE-2026-72291 | 9.3 | 6.5 | Linux | Linux | — | KVM: s390: Fix unlikely race in try_get_locked_pte() |
| CVE-2026-72204 | 8.4 | 6.5 | Linux | Linux | — | ntfs: centalize $INDEX_ROOT header validation |
| CVE-2026-72080 | 7.8 | 6.6 | Linux | Linux | — | fs/resctrl: Fix use-after-free during unmount |
| CVE-2026-72093 | 7.8 | 6.6 | Linux | Linux | — | accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap() |
| CVE-2026-72328 | 7.8 | 6.6 | Linux | Linux | — | accel/amdxdna: Fix potential amdxdna_umap lifetime race |
| CVE-2026-74263 | await | 6.5 | Linux | Linux | — | net: wwan: t7xx: check skb_clone in control TX |
| CVE-2026-74278 | await | 6.5 | Linux | Linux | — | ALSA: seq: Fix kernel heap address leak in bounce_error_event() |
| CVE-2026-74286 | await | 6.5 | Linux | Linux | — | net: pfcp: allocate per-cpu tstats for PFCP netdevs |
| CVE-2026-74301 | await | 6.5 | Linux | Linux | — | Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path |
| CVE-2026-74303 | await | 6.5 | Linux | Linux | — | Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-ser… |
| CVE-2026-74308 | await | 6.5 | Linux | Linux | — | ext4: fix kernel BUG in ext4_write_inline_data_end |
| CVE-2026-74318 | await | 6.5 | Linux | Linux | — | btrfs: fix deadlock cloning inline extent when using flushoncommit |
| CVE-2026-74352 | await | 6.5 | Linux | Linux | — | of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails |
| CVE-2026-74353 | await | 6.5 | Linux | Linux | — | drm/amdkfd: always resume_all after suspend_all |
| CVE-2026-74362 | await | 6.5 | Linux | Linux | — | ext2: fix ignored return value of generic_write_sync() |
| CVE-2026-74386 | await | 6.6 | Linux | Linux | — | nvmet-tcp: fix page fragment cache leak in error path |
| CVE-2026-74389 | await | 6.5 | Linux | Linux | — | RDMA/hns: Fix log flood after cmd_mbox failure |
| CVE-2026-74391 | await | 6.6 | Linux | Linux | — | tracing: Bound synthetic-field strings with seq_buf |
| CVE-2026-74393 | await | 6.5 | Linux | Linux | — | drm/syncobj: Fix memory leak in drm_syncobj_find_fence() |
| CVE-2026-74441 | await | 6.5 | Linux | Linux | — | usb: typec: ucsi: Fix race condition and ordering in port unregistration |
| CVE-2026-74442 | await | 6.5 | Linux | Linux | — | drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure |
| CVE-2026-74445 | await | 6.5 | Linux | Linux | — | drm/vmwgfx: reject DX_BIND_QUERY without a DX context |
| CVE-2026-74448 | await | 6.5 | Linux | Linux | — | drm/amdkfd: fix QID bit leak in pqm_create_queue() |
| CVE-2026-74455 | await | 6.5 | Linux | Linux | — | can: peak_usb: validate uCAN receive record lengths |
| CVE-2026-74457 | await | 6.5 | Linux | Linux | — | can: peak_usb: add bounds check for USB channel index |
| CVE-2026-74458 | await | 6.5 | Linux | Linux | — | can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command e… |
| CVE-2026-74459 | await | 6.5 | Linux | Linux | — | can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubm… |
| CVE-2026-74460 | await | 6.5 | Linux | Linux | — | can: ems_usb: validate CPC message lengths |
| CVE-2026-74463 | await | 6.5 | Linux | Linux | — | i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock |
| CVE-2026-74464 | await | 6.5 | Linux | Linux | — | net: openvswitch: fix skb leak on flow key update failure during ct |
| CVE-2026-74468 | await | 6.5 | Linux | Linux | — | gpio: pch: use raw_spinlock_t for the register lock |
| CVE-2026-74472 | await | 6.5 | Linux | Linux | — | ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() |
| CVE-2026-74484 | await | 6.5 | Linux | Linux | — | binfmt_misc: don't let an 'F' entry pin its own instance |
| CVE-2026-74498 | await | 6.5 | Linux | Linux | — | ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set |
| CVE-2026-74499 | await | 6.5 | Linux | Linux | — | ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() |
| CVE-2026-74500 | await | 6.5 | Linux | Linux | — | ALSA: usb-audio: fix stack info leak in RME Digiface status |
| CVE-2026-74501 | await | 6.5 | Linux | Linux | — | ALSA: usb-audio: fix use-after-free in ump_to_endpoint() |
| CVE-2026-74502 | await | 6.5 | Linux | Linux | — | ALSA: ump: fix double free of out_cvts on rawmidi error |
| CVE-2026-74504 | await | 6.5 | Linux | Linux | — | ALSA: seq: Fix division by zero in initialize_timer() |
| CVE-2026-74505 | await | 6.5 | Linux | Linux | — | ALSA: 6fire: Fix UAF at error handling during probe |
| CVE-2026-74524 | await | 6.5 | Linux | Linux | — | riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove |
| CVE-2026-74525 | await | 6.5 | Linux | Linux | — | net: sxgbe: free TX rings on RX allocation failure |
| CVE-2026-74532 | await | 6.5 | Linux | Linux | — | Bluetooth: btintel: Validate length before parsing diagnostics TLV |
| CVE-2026-74536 | await | 6.5 | Linux | Linux | — | Bluetooth: ISO: fix leaking sk after socket release |
| CVE-2026-74543 | await | 6.6 | Linux | Linux | — | net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() |
| CVE-2026-74546 | await | 6.5 | Linux | Linux | — | hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read |
| CVE-2026-74547 | await | 6.6 | Linux | Linux | — | hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread |
| CVE-2026-74552 | await | 6.5 | Linux | Linux | — | hwmon: (lm90) Only report alarms if driver is ready |
| CVE-2026-72019 | 7.3 | 6.4 | Linux | Linux | — | macsec: don't read an unset MAC header in macsec_encrypt() |
| CVE-2026-72338 | 7.8 | 6.3 | Linux | Linux | — | net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload |
| CVE-2026-72089 | 7.1 | 6.3 | Linux | Linux | — | accel/ivpu: Reject firmware log with size smaller than header |
| CVE-2026-68463 | await | 6.3 | Linux | Linux | — | mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend |
| CVE-2026-68464 | await | 6.3 | Linux | Linux | — | mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt |
| CVE-2026-68465 | await | 6.3 | Linux | Linux | — | mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore |
| CVE-2026-72498 | await | 6.3 | Linux | Linux | — | RDMA/bnxt_re: Avoid displaying the kernel pointer |
| CVE-2026-72501 | await | 6.3 | Linux | Linux | — | RDMA/bnxt_re: Initialize dpi variable to zero |
| CVE-2026-74307 | await | 6.3 | Linux | Linux | — | ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT |
| CVE-2026-74322 | await | 6.3 | Linux | Linux | — | wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write… |
| CVE-2026-74324 | await | 6.3 | Linux | Linux | — | wifi: mt76: mt7925: validate skb length in testmode query |
| CVE-2026-74335 | await | 6.3 | Linux | Linux | — | bpf: Fix NULL pointer dereference in bpf_task_from_vpid() |
| CVE-2026-74337 | await | 6.3 | Linux | Linux | — | bpf: Fix NMI/tracepoint re-entry deadlock on lru locks |
| CVE-2026-74358 | await | 6.3 | Linux | Linux | — | ext4: fix fast commit wait/wake bit mapping on 64-bit |
| CVE-2026-74360 | await | 6.3 | Linux | Linux | — | bpf: Reject exclusive maps for bpf_map_elem iterators |
| CVE-2026-74366 | await | 6.3 | Linux | Linux | — | wifi: ath12k: fix NULL deref in change_sta_links for unready link |
| CVE-2026-74372 | await | 6.3 | Linux | Linux | — | raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path |
| CVE-2026-74400 | await | 6.3 | Linux | Linux | — | bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries |
| CVE-2026-74462 | await | 6.3 | Linux | Linux | — | i2c: imx: mark I2C adapter when hardware is powered down |
| CVE-2026-74477 | await | 6.3 | Linux | Linux | — | uprobes: Fix NULL pointer dereference in hprobe_expire() |
| CVE-2026-74486 | await | 6.3 | Linux | Linux | — | binfmt_misc: use exe_file_deny_write_access() for the interpreter clone |
| CVE-2026-74487 | await | 6.3 | Linux | Linux | — | binfmt_misc: restore write access when removing an entry |
| CVE-2026-74491 | await | 6.3 | Linux | Linux | — | of/address: Fix NULL bus dereference in of_pci_range_parser_one() |
| CVE-2026-74494 | await | 6.3 | Linux | Linux | — | ksmbd: reject repeated SMB2 NEGOTIATE requests |
| CVE-2026-74514 | await | 6.3 | Linux | Linux | — | KVM: s390: pci: Fix memory accounting for pinned/unpinned pages |
| CVE-2026-74559 | await | 6.3 | Linux | Linux | — | xsk: drain continuation descs after overflow in xsk_build_skb() |
| CVE-2026-72134 | 7.8 | 6.2 | Linux | Linux | — | spi: imx: reconfigure for PIO when DMA cannot be started |
| CVE-2026-72315 | 7.8 | 6.2 | Linux | Linux | — | smb: client: fix busy dentry warning on unmount after DIO |
| CVE-2026-72331 | 7.8 | 6.2 | Linux | Linux | — | accel/amdxdna: Fix VMA access race |
| CVE-2026-72344 | 7.8 | 6.2 | Linux | Linux | — | net/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable |
| CVE-2026-72345 | 7.8 | 6.2 | Linux | Linux | — | net/mlx5: LAG, Fix off-by-one in single-FDB error rollback |
| CVE-2026-72358 | 7.8 | 6.2 | Linux | Linux | — | drm/xe/pt: prevent invalid cursor access for purged BOs |
| CVE-2026-72368 | 7.8 | 6.2 | Linux | Linux | — | cachefiles: Fix double unlock in nomem_d_alloc error path |
| CVE-2026-74426 | await | 6.2 | Linux | Linux | — | afs: fix NULL pointer dereference in afs_get_tree() |
| CVE-2026-72052 | 8.8 | 6.1 | Linux | Linux | — | net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-72053 | 8.8 | 6.1 | Linux | Linux | — | net: ipip: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-72054 | 8.8 | 6.1 | Linux | Linux | — | net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-72055 | 8.8 | 6.1 | Linux | Linux | — | net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-72136 | 8.8 | 6.1 | Linux | Linux | — | xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-68474 | 7.8 | 6.1 | Linux | Linux | — | powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() |
| CVE-2026-68479 | 7.8 | 6.1 | Linux | Linux | — | Bluetooth: btrtl: validate firmware patch bounds |
| CVE-2026-72005 | 7.8 | 6.1 | Linux | Linux | — | wifi: rt2x00: avoid full teardown before work setup in probe |
| CVE-2026-72024 | 7.8 | 6.1 | Linux | Linux | — | mac802154: remove interfaces with RCU list deletion |
| CVE-2026-72036 | 7.8 | 6.1 | Linux | Linux | — | net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeu… |
| CVE-2026-72102 | 7.8 | 6.1 | Linux | Linux | — | dm_early_create: fix freeing used table on dm_resume failure |
| CVE-2026-72105 | 7.8 | 6.1 | Linux | Linux | — | dm-log: fix a bitset_size overflow on 32bit machines |
| CVE-2026-72108 | 7.8 | 6.1 | Linux | Linux | — | dm thin metadata: fix metadata snapshot consistency on commit failure |
| CVE-2026-72109 | 7.8 | 6.1 | Linux | Linux | — | net: sparx5: unregister blocking notifier on init failure |
| CVE-2026-72120 | 7.8 | 6.1 | Linux | Linux | — | can: bcm: add missing rcu list annotations and operations |
| CVE-2026-72123 | 7.8 | 6.1 | Linux | Linux | — | can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF |
| CVE-2026-72135 | 7.8 | 6.1 | Linux | Linux | — | tpm: Make the TPM character devices non-seekable |
| CVE-2026-72164 | 7.8 | 6.1 | Linux | Linux | — | ocfs2: avoid moving extents to occupied clusters |
| CVE-2026-72165 | 7.8 | 6.1 | Linux | Linux | — | mtd: rawnand: fix condition in 'nand_select_target()' |
| CVE-2026-72171 | 7.8 | 6.1 | Linux | Linux | — | mtd: slram: remove failed entries from the device list |
| CVE-2026-72181 | 7.8 | 6.1 | Linux | Linux | — | mips: sched: Fix CPUMASK_OFFSTACK memory corruption |
| CVE-2026-72195 | 7.8 | 6.1 | Linux | Linux | — | fs/ntfs3: bound attr_off in UpdateResidentValue against data_off |
| CVE-2026-72250 | 7.8 | 6.1 | Linux | Linux | — | netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag |
| CVE-2026-72255 | 7.8 | 6.1 | Linux | Linux | — | netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst |
| CVE-2026-72261 | 7.8 | 6.1 | Linux | Linux | — | ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control |
| CVE-2026-72301 | 7.8 | 6.1 | Linux | Linux | — | ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get |
| CVE-2026-72400 | 7.8 | 6.1 | Linux | Linux | — | seg6: validate SRH length before reading fixed fields |
| CVE-2026-72406 | 7.8 | 6.1 | Linux | Linux | — | net: sungem: fix probe error cleanup |
| CVE-2026-72419 | 7.8 | 6.1 | Linux | Linux | — | netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() |
| CVE-2026-72435 | 7.8 | 6.1 | Linux | Linux | — | netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() |
| CVE-2026-74283 | 7.8 | 6.1 | Linux | Linux | — | tipc: require net admin for TIPCv2 netlink mutators |
| CVE-2026-72045 | 8.8 | 6.0 | Linux | Linux | — | octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF |
| CVE-2026-72051 | 8.8 | 6.0 | Linux | Linux | — | net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-72294 | 8.8 | 6.0 | Linux | Linux | — | LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt() |
| CVE-2026-72012 | 7.8 | 6.0 | Linux | Linux | — | tracing/osnoise: Call synchronize_rcu() when unregistering |
| CVE-2026-72018 | 7.8 | 6.0 | Linux | Linux | — | dibs: loopback: validate offset and size in move_data() |
| CVE-2026-72034 | 7.8 | 6.0 | Linux | Linux | — | fhandle: reject detached mounts in capable_wrt_mount() |
| CVE-2026-72110 | 7.8 | 6.0 | Linux | Linux | — | bpf,fork: wipe ->bpf_storage before bailouts that access it |
| CVE-2026-72113 | 7.8 | 6.0 | Linux | Linux | — | can: bcm: add missing device refcount for CAN filter removal |
| CVE-2026-72114 | 7.8 | 6.0 | Linux | Linux | — | can: bcm: validate frame length in bcm_rx_setup() for RTR replies |
| CVE-2026-72119 | 7.8 | 6.0 | Linux | Linux | — | can: bcm: extend bcm_tx_lock usage for data and timer updates |
| CVE-2026-72144 | 7.8 | 6.0 | Linux | Linux | — | platform/x86: dell-laptop: fix missing cleanups in init error path |
| CVE-2026-72170 | 7.8 | 6.0 | Linux | Linux | — | 9p: skip nlink update in cacheless mode to fix WARN_ON |
| CVE-2026-72172 | 7.8 | 6.0 | Linux | Linux | — | mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE |
| CVE-2026-72244 | 7.8 | 6.0 | Linux | Linux | — | gpu/buddy: bail out of try_harder when alignment cannot be honoured |
| CVE-2026-72252 | 7.8 | 6.0 | Linux | Linux | — | netfilter: nft_set_pipapo: don't leak bad clone into future transaction |
| CVE-2026-72304 | 7.8 | 6.0 | Linux | Linux | — | ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put |
| CVE-2026-72410 | 7.8 | 6.0 | Linux | Linux | — | octeontx2-af: Validate NIX maximum LFs correctly |
| CVE-2026-72434 | 7.8 | 6.0 | Linux | Linux | — | netfilter: ipset: make sure gc is properly stopped |
| CVE-2026-72162 | 7.8 | 5.8 | Linux | Linux | — | ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec |
| CVE-2026-72390 | 7.8 | 5.9 | Linux | Linux | — | net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF |
| CVE-2026-72488 | 7.8 | 5.8 | Linux | Linux | — | soundwire: fix bug in sdw_add_element_group_count found by syzkaller |
| CVE-2026-72439 | await | 5.9 | Linux | Linux | — | md/raid10: fix writes_pending leak on write request failures |
| CVE-2026-72490 | await | 5.9 | Linux | Linux | — | staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt |
| CVE-2026-72295 | 8.8 | 5.8 | Linux | Linux | — | LoongArch: KVM: Validate irqchip index in irqfd routing |
| CVE-2026-72500 | 8.8 | 5.8 | Linux | Linux | — | RDMA/bnxt_re: Free SRQ toggle page after firmware teardown |
| CVE-2026-72243 | 8.4 | 5.7 | Linux | Linux | — | selinux: check connect-related permissions on TCP Fast Open |
| CVE-2026-72009 | 7.8 | 5.8 | Linux | Linux | — | pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI |
| CVE-2026-72042 | 7.8 | 5.8 | Linux | Linux | — | ipmi: Fix user refcount underflow in event delivery |
| CVE-2026-72095 | 7.8 | 5.8 | Linux | Linux | — | dma-fence: Make dma_fence_dedup_array() robust against 0-count input |
| CVE-2026-74264 | 7.8 | 5.8 | Linux | Linux | — | net: watchdog: fix refcount tracking races |
| CVE-2026-74424 | await | 5.8 | Linux | Linux | — | fbcon: fix NULL pointer dereference for a console without vc_data |
| CVE-2026-72389 | 7.8 | 5.6 | Linux | Linux | — | bridge: stp: Fix a potential use-after-free when deleting a bridge |
| CVE-2026-72122 | 7.3 | 5.7 | Linux | Linux | — | can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure |
| CVE-2026-72043 | 7.1 | 5.7 | Linux | Linux | — | LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect() |
| CVE-2026-72049 | 7.1 | 5.7 | Linux | Linux | — | ieee802154: admin-gate legacy LLSEC dump operations |
| CVE-2026-72125 | 7.8 | 5.6 | Linux | Linux | — | can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER |
| CVE-2026-72126 | 7.8 | 5.6 | Linux | Linux | — | can: isotp: use unconditional synchronize_rcu() in isotp_release() |
| CVE-2026-72103 | 7.3 | 5.6 | Linux | Linux | — | dm: avoid leaking the caller's thread keyring via the table device file |
| CVE-2026-72213 | 7.1 | 5.6 | Linux | Linux | — | mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch |
| CVE-2026-72297 | 7.1 | 5.6 | Linux | Linux | — | net: atm: reject out-of-range traffic classes in QoS validation |
| CVE-2026-72383 | 7.8 | 5.4 | Linux | Linux | — | sctp: fix addr_wq_timer race in sctp_free_addr_wq() |
| CVE-2026-72143 | 7.1 | 5.4 | Linux | Linux | — | platform/x86: ISST: Restore SST-PP control to all domains |
| CVE-2026-74553 | await | 5.4 | Linux | Linux | — | hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 |
| CVE-2026-74577 | await | 5.4 | Linux | Linux | — | net: mpls: initialize rtm_tos in mpls_getroute() |
| CVE-2026-72232 | 7.8 | 5.2 | Linux | Linux | — | batman-adv: ensure minimal ethernet header on TX |
| CVE-2026-74392 | await | 5.2 | Linux | Linux | — | dm: limit target bio polling to one shot |
| CVE-2026-74432 | await | 5.3 | Linux | Linux | — | rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) |
| CVE-2026-74555 | await | 5.3 | Linux | Linux | — | scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race |
| CVE-2026-74566 | await | 5.3 | Linux | Linux | — | keys: make keyring key-chunk byte order agree with keyring_diff_objects() |
| CVE-2026-18500 | 8.1 | 5.2 | @fastify/jwt | @fastify/jwt | CWE-347 | @fastify/jwt vulnerable to authorization bypass via global secret overriding … |
| CVE-2026-68455 | await | 5.2 | Linux | Linux | — | liveupdate: validate session type before performing operation |
| CVE-2026-68468 | await | 5.2 | Linux | Linux | — | mtd: virt-concat: free duplicate generated name |
| CVE-2026-74272 | await | 5.2 | Linux | Linux | — | cxl/region: Resolve region deletion races |
| CVE-2026-74273 | await | 5.2 | Linux | Linux | — | cxl/region: Block region delete during region creation |
| CVE-2026-74291 | await | 5.2 | Linux | Linux | — | ASoC: topology: Check PCM and DAI name strings before use |
| CVE-2026-74298 | await | 5.2 | Linux | Linux | — | RDMA/core: Fix FRMR set pinned push error path |
| CVE-2026-74299 | await | 5.2 | Linux | Linux | — | RDMA/core: Fix FRMR aging push to queue error flow |
| CVE-2026-74304 | await | 5.2 | Linux | Linux | — | Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serde… |
| CVE-2026-74319 | await | 5.2 | Linux | Linux | — | btrfs: zoned: fix deadlock waiting for ticket during data relocation |
| CVE-2026-74326 | await | 5.2 | Linux | Linux | — | wifi: mt76: mt7921: fix resource leak in probe error path |
| CVE-2026-74336 | await | 5.2 | Linux | Linux | — | wifi: mac80211: bound S1G TIM PVB walk to the TIM element |
| CVE-2026-74342 | await | 5.2 | Linux | Linux | — | kernfs: link kn to its parent before the LSM init hook |
| CVE-2026-74368 | await | 5.2 | Linux | Linux | — | wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic() |
| CVE-2026-74369 | await | 5.2 | Linux | Linux | — | liveupdate: fix u-a-f in luo_file_unpreserve_files() and luo_file_finish() |
| CVE-2026-74370 | await | 5.2 | Linux | Linux | — | liveupdate: fix TOCTOU race in luo_session_retrieve() |
| CVE-2026-74375 | await | 5.2 | Linux | Linux | — | md/raid1,raid10: fix deadlock in read error recovery path |
| CVE-2026-74414 | await | 5.2 | Linux | Linux | — | hfsplus: Remove the duplicate attr inode dirty marking action |
| CVE-2026-74415 | await | 5.2 | Linux | Linux | — | spi: atcspi200: fix use-after-free when driver unbind |
| CVE-2026-74420 | await | 5.2 | Linux | Linux | — | drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges |
| CVE-2026-74421 | await | 5.2 | Linux | Linux | — | drm/rockchip: dw_dp: Switch to drmm_kzalloc() |
| CVE-2026-74483 | await | 5.2 | Linux | Linux | — | binfmt_misc: don't leak the user namespace when the mount fails |
| CVE-2026-74526 | await | 5.2 | Linux | Linux | — | scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit |
| CVE-2026-74542 | await | 5.2 | Linux | Linux | — | netfs: Fix folio_queue ENOMEM in writeback by adding a mempool |
| CVE-2026-74560 | await | 5.1 | Linux | Linux | — | xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx |
| CVE-2026-72423 | 8.8 | 5.1 | Linux | Linux | — | bpf: Guard conntrack opts error writes |
| CVE-2026-74277 | 8.8 | 5.1 | Linux | Linux | — | iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path |
| CVE-2026-72478 | 8.4 | 5.1 | Linux | Linux | — | fs/ntfs3: add bounds check to run_get_highest_vcn() |
| CVE-2026-72312 | 7.9 | 5.1 | Linux | Linux | — | octeontx2-af: fix VF bringup affecting PF promiscuous state |
| CVE-2026-68473 | 7.8 | 5.1 | Linux | Linux | — | powerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address() |
| CVE-2026-72090 | 7.8 | 5.1 | Linux | Linux | — | accel/amdxdna: Use caller client for debug BO sync |
| CVE-2026-72112 | 7.8 | 5.1 | Linux | Linux | — | io_uring/bpf-ops: reject re-registration of an already-bound ops |
| CVE-2026-72198 | 7.8 | 5.1 | Linux | Linux | — | ntfs: reject non-resident records for resident-only attributes |
| CVE-2026-72285 | 7.8 | 5.1 | Linux | Linux | — | KVM: TDX: Reject concurrent change to CPUID entry count |
| CVE-2026-72303 | 7.8 | 5.1 | Linux | Linux | — | ASoC: SOF: ipc4-control: Validate notification payload size |
| CVE-2026-72404 | 7.8 | 5.1 | Linux | Linux | — | tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy() |
| CVE-2026-72411 | 7.8 | 5.1 | Linux | Linux | — | net: dsa: mxl862xx: fix use-after-free of DSA ports in crc_err_work |
| CVE-2026-72485 | 7.8 | 5.1 | Linux | Linux | — | coresight: platform: defer connection counter increment until alloc succeeds |
| CVE-2026-74258 | 7.8 | 5.1 | Linux | Linux | — | bpf: Guard __get_user acesss with access_ok for uprobe_multi data |
| CVE-2026-74260 | 7.8 | 5.1 | Linux | Linux | — | netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them |
| CVE-2026-74418 | await | 5.0 | Linux | Linux | — | dma-fence: Fix potential tracepoint null pointer dereferences |
| CVE-2026-74423 | await | 5.1 | Linux | Linux | — | accel/amdxdna: Fix leak when pinning ubuf pages |
| CVE-2026-74437 | await | 5.1 | Linux | Linux | — | media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work |
| CVE-2026-72446 | 7.8 | 5.0 | Linux | Linux | — | ALSA: usb-audio: qcom: reject stream disable with no active interface |
| CVE-2026-18807 | 4.3 | 4.9 | Unknown | ECS | CWE-862 | ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modificat… |
| CVE-2026-72397 | 7.1 | 4.8 | Linux | Linux | — | hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid() |
| CVE-2026-72489 | 8.4 | 4.7 | Linux | Linux | — | staging: nvec: fix use-after-free in nvec_rx_completed() |
| CVE-2026-72415 | 7.1 | 4.7 | Linux | Linux | — | ASoC: SDCA: Validate written enum value in ge_put_enum_double() |
| CVE-2026-74519 | 7.8 | 4.3 | Linux | Linux | — | pinctrl: devicetree: don't free uninitialized dev_name on error path |
| CVE-2026-74422 | await | 4.3 | Linux | Linux | — | drm/rockchip: inno-hdmi: Switch to drmm_kzalloc() |
| CVE-2026-74558 | await | 4.3 | Linux | Linux | — | xsk: reclaim invalid Tx descriptors in ZC batch path |
| CVE-2026-74571 | await | 4.3 | Linux | Linux | — | btrfs: skip global block reserve accounting for rescue mounts |
| CVE-2026-74332 | 8.4 | 4.2 | Linux | Linux | — | ASoC: amd: acp-sdw-sof: Bound DAI link iteration |
| CVE-2026-74333 | 8.4 | 4.0 | Linux | Linux | — | ASoC: amd: acp-sdw-legacy: Bound DAI link iteration |
| CVE-2026-74383 | 8.4 | 4.1 | Linux | Linux | — | nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools |
| CVE-2026-74492 | 8.4 | 4.0 | Linux | Linux | — | netfilter: ipset: do not update comments from kernel-side hash adds |
| CVE-2026-74497 | 8.4 | 4.0 | Linux | Linux | — | ALSA: usb-audio: Clamp frame size in implicit-feedback mode |
| CVE-2026-74378 | 7.8 | 4.0 | Linux | Linux | — | RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe |
| CVE-2026-74404 | 7.8 | 4.0 | Linux | Linux | — | crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one |
| CVE-2026-74452 | 7.8 | 4.0 | Linux | Linux | — | drm/panthor: reject firmware sections with oversized data |
| CVE-2026-72287 | 7.8 | 4.0 | Linux | Linux | — | KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks |
| CVE-2026-74310 | 9.3 | 3.8 | Linux | Linux | — | vhost/net: complete zerocopy ubufs only once |
| CVE-2026-72482 | 7.8 | 3.8 | Linux | Linux | — | gpib: fix double decrement of descriptor_busy in command_ioctl() |
| CVE-2026-74510 | 7.8 | 3.8 | Linux | Linux | — | Bluetooth: mgmt: fix UAF in pair command cancellation |
| CVE-2026-74461 | 8.4 | 3.6 | Linux | Linux | — | i2c: imx: Cancel hrtimer before clearing slave pointer |
| CVE-2026-72444 | 7.8 | 3.7 | Linux | Linux | — | flow_dissector: check device type before reading ETH_ADDRS |
| CVE-2026-72459 | 7.8 | 3.7 | Linux | Linux | — | apparmor: aa_label_alloc use aa_label_free on alloc failure |
| CVE-2026-72470 | 7.8 | 3.7 | Linux | Linux | — | fs/ntfs3: resize log->one_page_buf when adopting on-disk page size |
| CVE-2026-72480 | 7.8 | 3.7 | Linux | Linux | — | iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling |
| CVE-2026-72462 | 8.8 | 3.5 | Linux | Linux | — | apparmor: fix race in unix socket mediation when peer_path is used |
| CVE-2026-72461 | 7.8 | 3.5 | Linux | Linux | — | apparmor: fix refcount leak when updating the sk_ctx |
| CVE-2026-74262 | 7.8 | 3.5 | Linux | Linux | — | kcm: use WRITE_ONCE() when changing lower socket callbacks |
| CVE-2026-74439 | 9.3 | 3.3 | Linux | Linux | — | iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry |
| CVE-2026-74516 | 8.2 | 3.4 | Linux | Linux | — | KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active |
| CVE-2026-72405 | 7.8 | 3.4 | Linux | Linux | — | net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync |
| CVE-2026-72427 | 7.8 | 3.4 | Linux | Linux | — | bpf: Fix effective prog array index with BPF_F_PREORDER |
| CVE-2026-73047 | 8.6 | 3.3 | siyuan-note | siyuan | CWE-200 | siyuan before v3.7.4 Server-Side Template Injection via attribute-view |
| CVE-2026-74438 | 7.8 | 3.3 | Linux | Linux | — | crypto: sun4i-ss - Remove insecure and unused rng_alg |
| CVE-2026-14230 | 5.4 | 3.3 | Unknown | ECS | CWE-79 | ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings |
| CVE-2026-74355 | 8.2 | 3.2 | Linux | Linux | — | iommu/vt-d: Fix RB-tree corruption in probe error path |
| CVE-2026-74481 | 7.8 | 3.2 | Linux | Linux | — | mm/page_reporting: use system_freezable_wq to fix UAF during suspend |
| CVE-2026-74365 | 7.3 | 3.2 | Linux | Linux | — | nvdimm/btt: Handle preemption in BTT lane acquisition |
| CVE-2026-74364 | 7.1 | 3.2 | Linux | Linux | — | bpf: Reject exclusive maps as inner maps in map-in-map |
| CVE-2026-74517 | 9.3 | 3.2 | Linux | Linux | — | KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs |
| CVE-2026-74573 | 9.3 | 3.1 | Linux | Linux | — | iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE |
| CVE-2026-74275 | 8.4 | 3.1 | Linux | Linux | — | cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach() |
| CVE-2026-72460 | 7.1 | 3.1 | Linux | Linux | — | apparmor: check label build before no_new_privs test |
| CVE-2026-68466 | 8.8 | 3.0 | Linux | Linux | — | mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout |
| CVE-2026-74380 | 8.8 | 3.0 | Linux | Linux | — | gpu: host1x: Fix iommu_map_sgtable() return value check |
| CVE-2026-74443 | 8.8 | 2.9 | Linux | Linux | — | drm/vmwgfx: bound DMA command body size against suffix pointer |
| CVE-2026-74515 | 8.8 | 2.9 | Linux | Linux | — | KVM: s390: pci: Reject adapter interrupt forwarding if already enabled |
| CVE-2026-68461 | 7.8 | 3.0 | Linux | Linux | — | device property: initialize the remaining fields of fwnode_handle in fwnode_i… |
| CVE-2026-68467 | 7.8 | 3.0 | Linux | Linux | — | mtd: mchp23k256: use SPI match data for chip caps |
| CVE-2026-72454 | 7.8 | 3.0 | Linux | Linux | — | i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev() |
| CVE-2026-74288 | 7.8 | 3.0 | Linux | Linux | — | net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). |
| CVE-2026-74293 | 7.8 | 3.0 | Linux | Linux | — | ASoC: fsl: fsl_audmix: Validate written enum values |
| CVE-2026-74296 | 7.8 | 3.0 | Linux | Linux | — | RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one |
| CVE-2026-74297 | 7.8 | 3.0 | Linux | Linux | — | RDMA/mlx5: Fix undefined shift of user RQ WQE size |
| CVE-2026-74305 | 7.8 | 3.0 | Linux | Linux | — | bpf: Tighten cgroup storage cookie checks for prog arrays |
| CVE-2026-74312 | 7.8 | 3.0 | Linux | Linux | — | vhost/vdpa: validate virtqueue index in mmap and fault paths |
| CVE-2026-74314 | 7.8 | 3.0 | Linux | Linux | — | bpf: Cancel special fields on map value recycle |
| CVE-2026-74330 | 7.8 | 3.0 | Linux | Linux | — | configfs: fix lockless traversals of ->s_children |
| CVE-2026-74377 | 7.8 | 3.0 | Linux | Linux | — | RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path |
| CVE-2026-74390 | 7.8 | 3.0 | Linux | Linux | — | RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs |
| CVE-2026-74397 | 7.8 | 3.0 | Linux | Linux | — | IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier |
| CVE-2026-74440 | 7.8 | 2.9 | Linux | Linux | — | drm/xe: Wait on external BO kernel fences in exec IOCTL |
| CVE-2026-74444 | 7.8 | 2.9 | Linux | Linux | — | drm/vmwgfx: validate DRAW_PRIMITIVES header size before division |
| CVE-2026-74446 | 7.8 | 2.9 | Linux | Linux | — | drm/amdkfd: hold event_mutex while checkpointing CRIU events |
| CVE-2026-74447 | 7.8 | 2.9 | Linux | Linux | — | drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment |
| CVE-2026-74451 | 7.8 | 2.9 | Linux | Linux | — | drm/panthor: validate firmware interface structure sizes |
| CVE-2026-74453 | 7.8 | 2.9 | Linux | Linux | — | drm/vc4: Zero the tile state data array before each BIN job |
| CVE-2026-74454 | 7.8 | 2.9 | Linux | Linux | — | drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size |
| CVE-2026-74456 | 7.8 | 2.9 | Linux | Linux | — | can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB su… |
| CVE-2026-74467 | 7.8 | 2.9 | Linux | Linux | — | s390/qeth: Check CAP_NET_ADMIN for private ioctls |
| CVE-2026-74470 | 7.8 | 2.9 | Linux | Linux | — | scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write |
| CVE-2026-74503 | 7.8 | 2.9 | Linux | Linux | — | ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes |
| CVE-2026-74549 | 7.8 | 3.0 | Linux | Linux | — | hwmon: (nct6775-core) Prevent access to unsupported weight registers |
| CVE-2026-74551 | 7.8 | 2.9 | Linux | Linux | — | hwmon: (nzxt-smart2) DMA-align output buffer |
| CVE-2026-72455 | 7.1 | 3.0 | Linux | Linux | — | apparmor: fix uninitialised pointer passed to audit_log_untrustedstring() |
| CVE-2026-74270 | 7.8 | 2.9 | Linux | Linux | — | handshake: Require admin permission for DONE command |
| CVE-2026-74306 | 7.8 | 2.9 | Linux | Linux | — | vfio/qat: fix f_pos race in qat_vf_resume_write() |
| CVE-2026-74338 | 7.8 | 2.8 | Linux | Linux | — | bpf: Reject sleepable BPF_LSM_CGROUP programs at load time |
| CVE-2026-74405 | 7.8 | 2.8 | Linux | Linux | — | OPP: Fix race between OPP addition and lookup |
| CVE-2026-74520 | 8.8 | 2.8 | Linux | Linux | — | iommu/iommufd: Fix IOPF group ownership UAF |
| CVE-2026-68458 | 7.8 | 2.8 | Linux | Linux | — | binder: cache secctx size before release zeroes it |
| CVE-2026-74311 | 7.8 | 2.8 | Linux | Linux | — | virtio: rtc: tear down old virtqueues before restore |
| CVE-2026-74325 | 7.8 | 2.8 | Linux | Linux | — | wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link |
| CVE-2026-74344 | 7.8 | 2.8 | Linux | Linux | — | bpf: Clear rb node linkage when freeing bpf_rb_root |
| CVE-2026-74371 | 7.8 | 2.8 | Linux | Linux | — | bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat |
| CVE-2026-74292 | 7.1 | 2.7 | Linux | Linux | — | ASoC: tegra: tegra210_ahub: Validate written enum value |
| CVE-2026-74295 | 7.1 | 2.7 | Linux | Linux | — | ASoC: codecs: hdac_hdmi: Validate written enum value |
| CVE-2026-74349 | 7.1 | 2.7 | Linux | Linux | — | ocfs2: reject FITRIM ranges shorter than a cluster |
| CVE-2026-74313 | 8.8 | 2.6 | Linux | Linux | — | vduse: hold vduse_lock across IDR lookup in open path |
| CVE-2026-74302 | 7.8 | 2.6 | Linux | Linux | — | Bluetooth: hci_core: Fix UAF in hci_unregister_dev() |
| CVE-2026-74359 | 7.8 | 2.6 | Linux | Linux | — | configfs_lookup(): don't leave ->s_dentry dangling on failure |
| CVE-2026-74363 | 7.8 | 2.6 | Linux | Linux | — | bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs |
| CVE-2026-74387 | 7.8 | 2.6 | Linux | Linux | — | ALSA: seq: midi: Serialize output teardown with event_input |
| CVE-2026-74465 | 7.8 | 2.6 | Linux | Linux | — | net: openvswitch: fix potential UAF on meter attach failure |
| CVE-2026-74471 | 7.8 | 2.6 | Linux | Linux | — | tracing: Check return value of __register_event() in trace_module_add_events() |
| CVE-2026-74482 | 7.8 | 2.6 | Linux | Linux | — | mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios |
| CVE-2026-74511 | 7.8 | 2.6 | Linux | Linux | — | Bluetooth: mgmt: fix pending command UAF in EIR updates |
| CVE-2026-74512 | 7.8 | 2.6 | Linux | Linux | — | audit: fix potential use-after-free in audit_del_rule() |
| CVE-2026-74518 | 7.8 | 2.6 | Linux | Linux | — | mm/hugetlb: fix list corruption in allocate_file_region_entries() |
| CVE-2026-74548 | 7.8 | 2.6 | Linux | Linux | — | forcedeth: fix UAF of txrx_stats in nv_remove |
| CVE-2026-74485 | 7.1 | 2.6 | Linux | Linux | — | binfmt_misc: reject a flag character as the field delimiter |
| CVE-2026-72496 | 9.2 | 2.6 | Linux | Linux | — | RDMA/bnxt_re: Proper rollback if the ioremap fails |
| CVE-2026-74257 | 7.8 | 2.5 | Linux | Linux | — | sockmap: Fix use-after-free in udp_bpf_recvmsg() |
| CVE-2026-74388 | 7.8 | 2.5 | Linux | Linux | — | ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data |
| CVE-2026-74479 | 7.8 | 2.5 | Linux | Linux | — | net: pktgen: fix proc entry use-after-free |
| CVE-2026-74506 | 7.8 | 2.5 | Linux | Linux | — | afs: Fix UAF when sending a message |
| CVE-2026-74513 | 7.8 | 2.5 | Linux | Linux | — | dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister |
| CVE-2026-19891 | 6.3 | 2.5 | TRENDnet | TEW-WLC100 | CWE-311 | TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption |
| CVE-2026-74568 | 9.3 | 2.4 | Linux | Linux | — | KVM: arm64: vgic: Fix race between LPI release and re-registration |
| CVE-2026-74574 | 7.8 | 2.4 | Linux | Linux | — | dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() |
| CVE-2026-74403 | 7.8 | 2.3 | Linux | Linux | — | crypto: ccp - Check for page allocation failure correctly in TIO |
| CVE-2026-74544 | 7.8 | 2.3 | Linux | Linux | — | net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds |
| CVE-2026-72497 | 8.8 | 2.2 | Linux | Linux | — | RDMA/bnxt_re: Add a max slot check for SQ |
| CVE-2026-72499 | 8.8 | 2.2 | Linux | Linux | — | RDMA/bnxt_re: Free CQ toggle page after firmware teardown |
| CVE-2026-74285 | 8.8 | 2.2 | Linux | Linux | — | net: Stop leased rxq before uninstalling its memory provider |
| CVE-2026-74328 | 8.8 | 2.2 | Linux | Linux | — | iommufd: Destroy the pages content after detaching from dmabuf |
| CVE-2026-74527 | 8.8 | 2.2 | Linux | Linux | — | octeontx2-af: Block VFs from clobbering special CGX PKIND state |
| CVE-2026-68462 | 7.8 | 2.2 | Linux | Linux | — | bpf: Reject negative const offsets for buffer pointers |
| CVE-2026-74289 | 7.8 | 2.2 | Linux | Linux | — | ipv4: fib: Don't dump dying fib_info in fib_leaf_notify(). |
| CVE-2026-74317 | 7.8 | 2.2 | Linux | Linux | — | ixgbe: do not configure xps for XDP queues |
| CVE-2026-74334 | 7.8 | 2.2 | Linux | Linux | — | RDMA/nldev: Fix locking when accessing mr->pd |
| CVE-2026-74343 | 7.8 | 2.2 | Linux | Linux | — | kernfs: fix xattr race condition with multiple superblocks |
| CVE-2026-74347 | 7.8 | 2.2 | Linux | Linux | — | netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount |
| CVE-2026-74354 | 7.8 | 2.2 | Linux | Linux | — | bpf: Take mmap_lock in zap_pages() |
| CVE-2026-74357 | 7.8 | 2.2 | Linux | Linux | — | drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump |
| CVE-2026-74367 | 7.8 | 2.2 | Linux | Linux | — | wifi: ath12k: fix inconsistent arvif state in vdev_create error paths |
| CVE-2026-74417 | 7.8 | 2.1 | Linux | Linux | — | drm/radeon: fix integer overflow in radeon_align_pitch() |
| CVE-2026-74449 | 7.8 | 2.2 | Linux | Linux | — | drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport |
| CVE-2026-74450 | 7.8 | 2.2 | Linux | Linux | — | drm/amd/pm: fix pptable use-after-free |
| CVE-2026-74496 | 7.8 | 2.2 | Linux | Linux | — | fou: Fix use-after-free in fou_create() |
| CVE-2026-74529 | 7.8 | 2.2 | Linux | Linux | — | Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback |
| CVE-2026-74563 | 7.8 | 1.9 | Linux | Linux | — | rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() |
| CVE-2026-74564 | 7.1 | 2.0 | Linux | Linux | — | netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH |
| CVE-2026-74567 | 7.1 | 1.9 | Linux | Linux | — | keys: fix out-of-bounds read in keyring_get_key_chunk() |
| CVE-2026-74565 | 7.8 | 1.9 | Linux | Linux | — | netfilter: nf_tables: make nft_object rhltable per table |
| CVE-2026-74294 | 7.3 | 1.8 | Linux | Linux | — | ASoC: meson: aiu: Validate written enum values |
| CVE-2026-74562 | 8.8 | 1.6 | Linux | Linux | — | nexthop: take nh->lock for f6i_list walks in replace check and notify |
| CVE-2026-74561 | 8.8 | 1.6 | Linux | Linux | — | nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush |
| CVE-2026-74419 | 7.3 | 1.5 | Linux | Linux | — | accel/amdxdna: Adjust size for copy_to_user() |
| CVE-2026-18165 | 4.2 | 0.9 | @fastify/oauth2 | @fastify/oauth2 | CWE-352 | @fastify/oauth2 vulnerable to Login CSRF via plantable OAuth state cookies |