By vendor
Linux vulnerabilities
Known CVEs affecting Linux products, prioritized by severity, with SEC.co remediation and detection guidance.
1178 published vulnerabilities · page 9 of 12
- CVE-2026-46193MEDIUM 5.5
A flaw in the Linux kernel's AH (Authentication Header) implementation causes incorrect packet authentication when Extended Sequence Numbers (ESN) are enabled and async cryptographic operations are used. The kernel miscalculates where authentication data is stored during async callbacks, leading to the comparison of wrong bytes and packet validation failures. This breaks IPsec AH protection on affected systems.
- CVE-2026-46196MEDIUM 5.5
A flaw in the Linux kernel's tracepoint subsystem can leave internal state in an inconsistent condition when probe registration fails. Specifically, when the kernel tries to activate a tracepoint for the first time and the activation succeeds but the probe installation fails (e.g., due to out-of-memory conditions), the cleanup routine is never called. This leaves persistent overhead on every task in the system—most notably for syscall tracing—until the system is rebooted. The issue is a resource leak of kernel state rather than a direct security bypass, but it degrades performance and system stability under memory pressure or specific tracepoint registration sequences.
- CVE-2026-46200MEDIUM 5.5
A flaw in the Linux kernel's MPC52xx SPI controller driver can cause a system crash or denial of service when the driver is unloaded. The issue stems from improper resource cleanup during driver removal—specifically, the controller is disabled and its resources (interrupts, GPIOs) are released before the controller is properly deregistered from the kernel, leaving dangling references that can trigger a crash.
- CVE-2026-46202MEDIUM 5.5
A locking bug in the Linux kernel's Apple Touch Bar keyboard driver (hid-appletb-kbd) causes the system to attempt sleeping operations from atomic (interrupt) contexts where sleeping is forbidden. The bug occurs in two code paths that adjust keyboard backlight brightness: a periodic inactivity timer and a user-activity reset handler. Both trigger calls to the backlight subsystem's brightness function, which tries to acquire a mutex while running in softirq or IRQ context, causing kernel warnings and potential system instability. The fix moves these blocking operations to a workqueue, allowing them to run safely in process context.
- CVE-2026-46207MEDIUM 5.5
A flaw in the Linux kernel's vsock/virtio module causes monitoring tools to receive incomplete data when handling certain network packets. Specifically, when the kernel processes non-linear network buffers for the virtual socket monitoring interface (vsockmon), it fails to properly initialize a data structure that controls how much information gets copied. This leaves monitoring tools unable to see the full payload of these packets, potentially obscuring network activity. The issue affects local processes with standard privileges and could be exploited to hide data from network inspection.
- CVE-2026-46211MEDIUM 5.5
A flaw in the Linux kernel's graphics driver (msm/gem) causes an ioctl function to report success even when it fails. When userspace attempts to retrieve metadata about graphics objects, the function incorrectly returns 0 (success) even if the underlying operations—such as copying data to userspace or allocating memory—actually fail. Additionally, if memory allocation fails, the code does not check for a NULL pointer, leading to a crash. This allows applications to think they've successfully retrieved metadata when they haven't, or to trigger a denial of service.
- CVE-2026-46214MEDIUM 5.5
A flaw in the Linux kernel's virtual socket (vsock) implementation can cause connection listeners to stop accepting new connections after a small number of transport negotiation failures. The bug occurs in the virtio transport layer when the code increments an internal counter to track pending connections but fails to decrement it if the transport negotiation fails. After enough failed attempts, the listener incorrectly believes its connection queue is full and rejects all new incoming connections, effectively causing a denial of service for applications relying on vsock communication.
- CVE-2026-46216MEDIUM 5.5
A flaw in the Linux kernel's GPU driver for Intel Arc graphics allows a local attacker with basic user privileges to crash the system. The vulnerability occurs when certain GPU components (specifically the media GT) are disabled through system configuration. Under these conditions, the driver attempts to access memory that hasn't been allocated, causing a kernel panic. An attacker with local access can trigger this crash, resulting in a denial of service. This is a localized memory safety issue that requires local access to exploit.
- CVE-2026-46220MEDIUM 5.5
A vulnerability in the Linux kernel's AMD GPU driver allows an unprivileged user to crash the system by submitting specially crafted graphics commands. The driver was using an overly aggressive error check (BUG_ON) that would panic the entire kernel when it detected a misaligned memory address—even though the real fix should have happened earlier in the validation pipeline. By replacing these fatal assertions with warnings, the system can log the problem without crashing, while proper validation is moved to the correct layer of the code.
- CVE-2026-46221MEDIUM 5.5
A memory leak exists in the Linux kernel's EDAC (Error Detection and Correction) versalnet driver. When the driver initializes memory controller devices, it allocates memory for a device name string but fails to properly free it during normal driver removal. The kernel's device registration process copies the name internally and then loses track of the original allocation, leaving orphaned memory that cannot be reclaimed. This gradually consumes system memory over repeated device initialization and removal cycles.
- CVE-2026-46222MEDIUM 5.5
A flaw exists in the Linux kernel's Rockchip RKCam Interface (rkcif) media driver where certain data connection points (pads) lack proper validation checks. When a video stream is started on a device where these pads are not correctly connected, the kernel attempts to access memory that doesn't exist, causing the system to crash. This is a local issue—only users with login access to the affected system can trigger it, typically through video application commands.
- CVE-2026-46223MEDIUM 5.5
This Linux kernel vulnerability centers on a deadlock condition in cgroup resource management during container shutdown. When a system administrator removes a cgroup (via rmdir), the kernel's cleanup logic can become stuck waiting for tasks to exit under certain conditions—specifically when the process performing the removal is also responsible for reaping zombie processes. This creates a circular dependency where the cleanup cannot proceed because the reaper is blocked, and the zombies cannot be cleaned because the reaper is stuck. The fix defers the actual cleanup work to run asynchronously after tasks have already left the cgroup, allowing the rmdir operation to return promptly while kernel-side cleanup continues in the background.
- CVE-2026-46224MEDIUM 5.5
A memory leak vulnerability exists in the Linux kernel's DRM (Direct Rendering Manager) Xe driver. When the driver attempts to initialize a DMA buffer object and encounters an allocation failure, it fails to properly clean up a pre-allocated buffer object, causing it to leak into memory. The vulnerability requires local system access and affects the kernel's ability to manage GPU memory correctly. While this is not a critical security issue, it can lead to denial of service through memory exhaustion over time.
- CVE-2026-46225MEDIUM 5.5
A flaw has been found in how the Linux kernel's SPI (Serial Peripheral Interface) RSPI driver shuts down. When a system stops using the driver, it wasn't properly cleaning up in the right order—specifically, it was releasing DMA (direct memory access) resources before telling the SPI controller to stop. This ordering problem can cause the system to become unstable or crash.
- CVE-2026-46226MEDIUM 5.5
A flaw in the Linux kernel's Freescale SPI controller driver can cause a system crash when the driver is unloaded. The issue occurs because the driver releases hardware resources (like DMA) before properly shutting down the SPI controller, leaving it in an inconsistent state. An attacker with local system access could trigger this crash by unloading the driver, resulting in a denial of service.
- CVE-2026-46228MEDIUM 5.5
A memory management flaw in the Linux kernel's SPI CH341 USB driver can cause memory to persist after the driver is unloaded, potentially leading to denial of service. The issue arises because device resources tied to a USB driver are incorrectly managed at the parent device level rather than at the individual interface level, preventing proper cleanup when drivers unbind without physical device disconnection.
- CVE-2026-46229MEDIUM 5.5
A vulnerability in the Linux kernel's AMD KFD (Kernel Fusion Driver) GPU memory management allows stale data from previous GPU memory allocations to remain accessible to new compute tasks. When GPU VRAM is allocated for new workloads, the kernel does not properly clear it, leaving behind fragments of prior page tables and data. Compute kernels can observe this leftover information, which can corrupt GPU-to-GPU communication protocols and cause application crashes, particularly in high-performance computing scenarios involving NVIDIA RCCL P2P transport operations.
- CVE-2026-46231MEDIUM 5.5
A flaw in the Linux kernel's batman-adv (B.A.T.M.A.N. Advanced) networking module leaks memory when certain network claim operations fail. Specifically, when the system attempts to record a new claim in an internal hash table but the insertion fails, it forgets to release a reference to a network backbone object, causing that object to remain in memory indefinitely. This gradual accumulation of unreleased objects can eventually degrade system performance or trigger a denial of service.
- CVE-2026-46233MEDIUM 5.5
A flaw in the Linux kernel's Batman-adv bridge loop avoidance (BLA) subsystem can cause a crash when the system attempts to clean up stale network bridge claims. The issue occurs because the cleanup routine doesn't properly check whether a claim is still valid before trying to access it, potentially leading to a null pointer dereference. An attacker with local access could trigger this condition to cause a denial of service.
- CVE-2026-46235MEDIUM 5.5
The Linux kernel's saa7164 media driver failed to properly validate whether memory mapping operations succeeded before using the results. When the kernel tries to map I/O memory regions for certain hardware (specifically PCI base address registers 0 and 2), it could receive a null pointer if the operation failed. The driver would then attempt to use these null pointers, causing a system crash. This patch adds defensive checks: if memory mapping fails, the driver now properly cleans up any partially allocated resources and safely reports an error instead of proceeding with unusable pointers.
- CVE-2026-46236MEDIUM 5.5
A flaw has been identified in the Linux kernel's Xbox remote control driver that mishandles memory buffers used for direct hardware communication (DMA). The driver incorrectly stores DMA buffers as part of the device structure, violating fundamental DMA coherency rules. This misconfiguration can cause the system to become unstable or unresponsive, though it requires local access to trigger. The issue affects systems running vulnerable versions of the Linux kernel with the Xbox remote driver enabled.
- CVE-2026-46239MEDIUM 5.5
A memory management bug in the Linux kernel's OV5647 camera driver causes system resources to not be properly released when certain camera control operations are performed. Specifically, three control settings—autogain, automatic exposure, and analog gain—skip the cleanup step that tells the system a resource is no longer needed, leaving the system in a degraded state. Repeated use of these controls can exhaust system resources and cause the kernel to become unstable or unresponsive.
- CVE-2026-46245MEDIUM 5.5
A flaw in the Linux kernel's AMD display driver (amdgpu) can cause a system crash when the driver attempts to initialize Hot Plug Detect (HPD) interrupts for video connectors. The problem occurs because the code checks whether a connector's data structure (dc_link) is valid in one place, but then later uses it without checking again, leading to a null pointer dereference. This vulnerability affects systems with AMD GPUs running vulnerable kernel versions and can be triggered by a local user, resulting in a denial of service.
- CVE-2026-46247MEDIUM 5.5
This vulnerability affects the Linux kernel's clock management subsystem, specifically the graphics processor (GFX3D) clock driver. A bug in how parent clock information is passed during rate calculations causes the system to crash when the GPU attempts to change its operating frequency. The issue emerged after a code refactoring that changed how clock dividers calculate rates. When the GPU's power management system tries to adjust clock speed—a routine operation during dynamic frequency scaling—the missing parent clock information causes a kernel panic. The vulnerability requires local access and affects systems running vulnerable kernel versions on Qualcomm-based devices.
- CVE-2026-46248MEDIUM 5.5
This vulnerability affects the Linux kernel's WiFi driver for Qualcomm Atheros ath12k chipsets. When a WiFi interface fails during setup for multi-link operation (MLO), the driver can retain stale data about link mappings. If a new connection attempt reuses the same link ID, the driver triggers a warning and may experience instability. The issue stems from incomplete cleanup during failed initialization—specifically, link deletion code only runs if the interface was fully created, leaving orphaned references behind.
- CVE-2026-46249MEDIUM 5.5
This Linux kernel vulnerability affects the OcteonTX2 ARM-based System-on-Chip (SoC) driver stack, specifically the Application Firmware (AF) and Physical Function (PF) drivers used in Marvell networking hardware. During a kexec reboot—a fast reboot mechanism that skips the firmware/BIOS phase—hardware state from the previous kernel persists. The bug occurs when AF fails to properly clear its initialization marker before shutdown. When the PF driver loads in the new kernel, it checks this marker to determine if AF is ready. Finding a stale marker, the PF driver incorrectly assumes AF has already initialized and attempts to access hardware that was never properly reset, causing a kernel crash. This is primarily a denial-of-service condition affecting systems performing kexec reboots with modular driver configurations.
- CVE-2026-46252MEDIUM 5.5
A locking bug exists in the Linux kernel's regulator power management subsystem. When the system attempts to enable a power supply regulator and that operation fails, the error-handling code releases a reference to the regulator object without holding the required lock. This creates a race condition where another part of the system could be accessing the regulator data simultaneously, potentially causing a crash or memory corruption. The fix involves using the correct function call that ensures proper locking during cleanup, and adding additional safeguards to prevent concurrent access while clearing internal pointers.
- CVE-2026-46254MEDIUM 5.5
A vulnerability in the Linux kernel's AppArmor security module can cause system crashes or hangs when AppArmor processes policy rules containing improperly aligned data structures. The kernel's DFA (Deterministic Finite Automaton) tables used by AppArmor to enforce security policies may originate from either kernel memory or user-supplied configuration, and when these tables aren't properly aligned to 8-byte boundaries, certain CPU architectures trigger unaligned memory access errors. This is a denial-of-service issue—an unprivileged user with the ability to load or modify AppArmor policies could crash the kernel without data loss or privilege escalation.
- CVE-2026-46255MEDIUM 5.5
The Linux kernel's fsl-edma driver contains a resource management bug where clock handles are being manually disabled during driver removal, even though they were allocated using automatic cleanup functions. This causes the system to attempt disabling clocks that have already been cleaned up by the kernel, generating warnings and potentially destabilizing the driver removal process. The fix is straightforward: remove the redundant manual disable calls and let the automatic cleanup mechanism handle it.
- CVE-2026-46256MEDIUM 5.5
A recursion deadlock vulnerability exists in the Linux kernel's NFS LOCALIO feature, which optimizes loopback NFS mounts by bypassing the network when client and server run on the same system. Under memory pressure, the kernel's direct reclaim mechanism can trigger a circular chain: NFS writes → XFS filesystem → back into NFS page cache operations, causing the system to hang. The vulnerability requires local access and affects systems using LOCALIO-enabled NFS mounts. A fix ensures memory allocations in the LOCALIO code path use GFP_NOFS context to prevent this recursion.
- CVE-2026-46257MEDIUM 5.5
A flaw in the Linux kernel's SP804 timer driver can cause the system to crash when certain timing functions are called on ARM32 platforms. The issue arises when the SP804 timer is configured in a way that leaves a shared clock object uninitialized, but the kernel still tries to read from it. This vulnerability has been fixed by separating the delay timer functionality into its own dedicated clock instance, preventing the kernel from attempting to access uninitialized memory.
- CVE-2026-46258MEDIUM 5.5
A flaw in the Linux kernel's GPIO character device (cdev) interface causes the system to crash when creating a line handle. The issue occurs because code attempts to use a pointer after it has been intentionally cleared to NULL, leading to a crash when the kernel tries to access memory through that invalid pointer. This is a local issue—an authenticated user on the system would need to trigger it, typically through ioctl calls to the GPIO device.
- CVE-2026-46261MEDIUM 5.5
A vulnerability in the Linux kernel's SPI WPC flash interface unit driver can cause the system to crash due to a missing safety check. When the driver initializes, it attempts to access memory resources without first verifying they exist, potentially leading to a NULL pointer dereference that brings down the affected process or system. This is a localized denial-of-service issue requiring local system access to trigger.
- CVE-2026-46262MEDIUM 5.5
A deadlock vulnerability exists in the Linux kernel's audio subsystem (ASoC fsl_xcvr driver) where a recent locking fix introduced the opposite problem: the code attempts to re-acquire a lock that is already held by the calling function, causing the system to hang. When a user adjusts audio control settings through ALSA, the kernel deadlocks instead of safely updating the configuration.
- CVE-2026-46268MEDIUM 5.5
A logic error in the Linux kernel's PCI peer-to-peer DMA memory allocation code causes a spurious warning to be logged when kernel debug features are enabled. The vulnerability stems from a mismatch between a code assertion and a prior change to how memory pages are initialized—the assertion expects a non-zero reference count, but the pages are now created with a zero count by design. While the actual functionality remains intact, the warning floods kernel logs and can trigger monitoring alerts, degrading system observability and potentially masking other issues.
- CVE-2026-46269MEDIUM 5.5
A NULL pointer dereference vulnerability exists in the Linux kernel's Canaan K230 pinctrl driver. During device initialization, the driver attempts to access a device structure through an uninitialized pointer, causing the kernel to crash. The issue occurs because the code tries to retrieve the device reference via a control structure that hasn't been set up yet. An attacker with local access could trigger this crash by loading the affected driver or probing the device, leading to a denial of service.
- CVE-2026-46276MEDIUM 5.5
A Linux kernel bug in AMD's GPU driver causes the system to crash during startup when loading newer AMD Radeon RX 9070 XT graphics cards on RDNA4 hardware. The issue stems from the driver trying to initialize memory regions that don't physically exist on this newer GPU architecture. When the kernel attempts to set up these non-existent resources with zero size, it triggers a safety check that crashes the boot process. This only affects systems where kernel debugging is enabled; most deployments have avoided the crash by accident rather than design.
- CVE-2026-46278MEDIUM 5.5
A null pointer dereference vulnerability exists in the Linux kernel's Imagination PowerVR graphics driver. When a local user attempts to update ftrace debug settings through a debugfs interface, the driver passes incorrect data to the operation, causing the kernel to crash. This is a stability issue rather than a data breach or privilege escalation risk—an authenticated local user can trigger a denial of service condition.
- CVE-2026-46282MEDIUM 5.5
A flaw in the Linux kernel's admv1013 frequency driver can cause the system to crash or become unresponsive. The vulnerability occurs when the driver fails to properly read a configuration setting from the device, but then tries to use that uninitialized data anyway, leading to a null pointer dereference. An unprivileged local user with access to the affected system could trigger this condition to cause a denial of service.
- CVE-2026-46283MEDIUM 5.5
A vulnerability in the Linux kernel's TPM (Trusted Platform Module) driver leaves sensitive cryptographic session keys in freed memory when a TPM device is closed. The driver should zero out this memory before releasing it—a standard security practice it already uses in other code paths—but this particular cleanup path was missed. An attacker with local access could potentially recover these keys from freed memory before it's overwritten by other processes.
- CVE-2026-46284MEDIUM 5.5
A defect in the Linux kernel's hugepages parameter parsing can cause the system to crash during early boot if certain kernel command-line parameters are malformed. Specifically, if hugepages, hugepagesz, or default_hugepagesz parameters are supplied without an equals sign (e.g., 'hugepages 1G' instead of 'hugepages=1G'), the kernel's early parameter handler passes a NULL pointer to the hugetlb_add_param() function, which then crashes when attempting to measure the string length. The fix validates input before processing and rejects malformed parameters gracefully.
- CVE-2026-46286MEDIUM 5.5
A vulnerability exists in the Linux kernel's Qualcomm LED driver (qcom-lpg) where a register value intended to select from a predefined array is not properly validated before use. The register can hold values 0–7 (from a 3-bit field), but the array contains only 5 entries. Without bounds checking, out-of-range values cause the code to read uninitialized or incorrect memory, which then gets used to configure LED brightness timing parameters. While actual hardware typically produces valid register values, the lack of defensive checks creates a potential denial-of-service condition if invalid data is encountered.
- CVE-2026-46287MEDIUM 5.5
The Linux kernel's txgbe network driver has a defect in how it disconnects from external PHY (Physical Layer transceiver) devices when the driver module is unloaded. When users remove the txgbe module, the driver attempts to disconnect the PHY without first acquiring the RTNL (Real-Time Netlink) lock, which is required by the kernel's phylink subsystem. This causes a kernel assertion failure and warning message, though it does not directly compromise system security or data. The fix involves wrapping the disconnect call with proper locking.
- CVE-2026-46290MEDIUM 5.5
A Linux kernel bug affects how the system handles page faults during firmware calls on x86/EFI systems. Recent changes to improve cryptographic performance modified how the kernel manages floating-point unit access, inadvertently causing the page fault handler to always bail out when firmware triggers a fault. On systems with buggy firmware that generates page faults during runtime calls, this escalates to a system panic and hard freeze instead of gracefully recovering. The fix changes the fault detection logic to properly distinguish between real interrupt contexts and the FPU management code path.
- CVE-2026-46291MEDIUM 5.5
A flaw in the Linux kernel's cryptographic subsystem can expose sensitive HMAC key material through debug output when certain debugging configurations are enabled. The vulnerability exists in the hash_digest_key function of the CAAM (Cryptographic Acceleration and Assurance Module) driver, which was inadvertently dumping key bytes in plaintext during kernel logging. An attacker with local access could potentially read these keys from kernel logs or memory if dynamic debugging is active, compromising cryptographic operations that depend on key secrecy.
- CVE-2026-46292MEDIUM 5.5
A Linux kernel vulnerability in the power domain management (genpd) subsystem leaves virtual devices with runtime PM incorrectly enabled after detachment. When drivers use genpd_dev_pm_attach_by_id() to register virtual devices, the kernel enables runtime PM for them but fails to disable it when those devices detach. This leaves the system in an inconsistent state that can trigger NULL pointer dereferences or cause the kernel to unnecessarily vote for higher performance states. The fix adds a missing pm_runtime_disable() call during device detachment to restore proper state management.
- CVE-2026-46295MEDIUM 5.5
A race condition in the Linux kernel's KVM hypervisor can cause the system to incorrectly report whether virtual CPUs have pending interrupts. When one virtual CPU sends an interrupt to another while the receiving CPU is simultaneously checking for pending interrupts, a timing gap allows the system to think an interrupt has arrived when it hasn't actually been delivered yet. While the interrupt itself isn't lost—it remains queued internally—the false reporting triggers a warning message and wastes CPU cycles with unnecessary virtual machine context switches. This affects systems running KVM hypervisor on x86 processors, particularly in nested virtualization scenarios under heavy load.
- CVE-2026-46296MEDIUM 5.5
A bug in the Linux kernel's SPI driver for Samsung S3C64xx controllers can crash the system when the driver is unloaded. The issue stems from incomplete refactoring: code that allocates DMA channels was moved from initialization to a later setup phase, but the corresponding cleanup code was not removed from the driver shutdown process. When the driver unloads, it tries to release DMA resources that were never allocated, triggering a NULL-pointer crash.
- CVE-2026-46297MEDIUM 5.5
A vulnerability in the Linux kernel's libwx networking driver incorrectly uses a threaded interrupt handler setup with missing threaded handler logic, triggering kernel warnings and potential system instability. The issue affects virtual function (VF) miscellaneous interrupt handling. The fix involves switching to the standard non-threaded interrupt request function and removing an unnecessary flag that doesn't apply to non-threaded handlers.
- CVE-2026-46302MEDIUM 5.5
A Linux kernel vulnerability allows a single process to monopolize read access to the SELinux security policy file, preventing other processes from retrieving critical security configuration. This denial-of-service condition stems from an overly restrictive locking mechanism that was originally intended to prevent memory exhaustion and inconsistent policy views, but achieves neither goal effectively. The issue is resolved by allowing concurrent reads of the policy file while maintaining data integrity through refined locking.
- CVE-2026-46305MEDIUM 5.5
A flaw in the Linux kernel's rtl8723bs WiFi driver can cause the system to crash if memory allocation fails during buffer initialization. When the driver attempts to create a buffer, it doesn't properly check whether the memory allocation succeeded before trying to use it. If the allocation fails—a condition that may occur under memory pressure—the code will attempt to access a NULL pointer, causing a denial of service. This is a localized driver issue affecting WiFi functionality rather than a system-wide kernel compromise.
- CVE-2026-46310MEDIUM 5.5
A flaw in the Linux kernel's Renesas VSP1 media driver causes a system crash when the module is unloaded on certain hardware generations. The bug stems from cleanup code calling the wrong function variant, leaving a dangling pointer that triggers a crash. This affects local users with module unload privileges and requires a kernel patch to resolve.
- CVE-2026-46312MEDIUM 5.5
A flaw in the Linux kernel's video buffer management can trigger a kernel warning when memory-mapped video buffers from certain capture drivers are accessed through the graphics subsystem. While the warning itself doesn't cause data loss or direct compromise, it indicates improperly configured memory protections that should have been set. This affects primarily developers and systems running specialized camera capture software on affected kernels.
- CVE-2026-46313MEDIUM 5.5
A flaw exists in the Linux kernel's Intel IPU6 media driver where an error-handling code path incorrectly dereferences a pointer that has been marked as invalid (an error pointer). When the driver encounters certain initialization failures during PCI device probing, it attempts to clean up resources but doesn't properly null-check a pointer before using it, leading to a kernel crash. This is a local denial-of-service issue affecting systems running vulnerable kernel versions with the Intel IPU6 driver enabled.
- CVE-2026-46314MEDIUM 5.5
A flaw in the Linux kernel's DRM v3d driver allows a local user to trigger an infinite loop by submitting a maliciously crafted system call with a self-referential extension structure containing zero synchronization counts. This causes the kernel to hang indefinitely, consuming CPU resources and freezing the affected process. An attacker with local access can exploit this to perform a denial-of-service attack on systems running vulnerable kernel versions.
- CVE-2026-46315MEDIUM 5.5
A vulnerability in the Linux kernel's io_uring subsystem can leak uninitialized kernel memory to userspace when using the IOURING_OP_WAITID operation. When a wait operation completes without reporting child process events, the kernel fails to zero-initialize its result buffer before copying it to user applications, exposing stale data that was previously stored in the same kernel memory. This is a local information disclosure issue affecting users who can invoke io_uring operations on systems where they have access.
- CVE-2026-46318MEDIUM 5.5
A vulnerability in the Linux kernel's hugetlbfs memory management subsystem can cause a memory leak when virtual memory area (VMA) lock allocation fails during the memory mapping preparation stage. The issue stems from an earlier patch that attempted to optimize how hugetlb mappings are set up, but inadvertently created a window where a failed lock allocation could leave resources unreleased. A local user with standard privileges can trigger this condition, leading to denial of service through memory exhaustion.
- CVE-2026-46329MEDIUM 5.5
A flaw in the Linux kernel's EROFS (Enhanced Read-Only File System) implementation fails to properly handle I/O requests that extend beyond the filesystem boundary when the filesystem is mounted from a file. Instead of safely zeroing out the requested data (as loopback devices and the kernel's expected behavior dictate), the kernel may access invalid memory or return uninitialized data. This can lead to a denial of service or potential information disclosure on systems using file-backed EROFS mounts.
- CVE-2026-52904MEDIUM 5.5
A memory leak exists in the Linux kernel's Nouveau graphics driver. During the device initialization process, if a specific system configuration check fails, the driver fails to properly clean up an allocated device object, leaving resources dangling in kernel memory. This is a kernel-level resource exhaustion issue that can be triggered by unprivileged users on affected systems.
- CVE-2026-52905MEDIUM 5.5
A bug in the Linux kernel's DAMON (Data Access Monitoring) subsystem allows administrators or local users to configure memory monitoring settings with invalid parameters, potentially causing system instability or denial of service. The vulnerability stems from incomplete validation of the minimum region size parameter—it must be a power of two, but the DAMON sysfs interface can accept non-power-of-two values, leading to unaligned memory address ranges that violate kernel assumptions. This creates conditions for crashes or hangs during memory access monitoring operations.
- CVE-2026-52913MEDIUM 5.5
A vulnerability in the Linux kernel's batman-adv networking module can cause a system crash when network interfaces are disabled. The issue stems from code that continues sending mesh network announcements (OGMs) through interfaces that have been taken offline, leading to attempts to access memory that no longer contains valid data. An unprivileged local user with access to the affected system could trigger this crash, resulting in a denial of service.
- CVE-2026-52916MEDIUM 5.5
A flaw in the Linux kernel's batman-adv networking module allows a local attacker to crash the system by sending specially crafted fragmented network packets that nest themselves within each other. When the kernel attempts to reassemble these packets, it becomes trapped in recursive processing that consumes kernel stack memory until it runs out, causing a denial of service. The vulnerability requires local network access and appropriate user privileges to exploit.
- CVE-2026-52921MEDIUM 5.5
A bug in the Linux kernel's netfilter ipset module causes certain hash-based set variants to iterate past their intended range boundaries when processing IPv4 addresses. When a user requests a range of IP addresses to be processed—for example, in firewall or traffic filtering rules—the iterator should stop after handling the last address in that range. Instead, it advances one more step, potentially moving the traversal state outside the original request boundary. This can cause problems on retry operations, where the system might resume from an incorrect position rather than the intended starting point. The issue affects four specific ipset hash variants used in network filtering configurations.
- CVE-2026-52925MEDIUM 5.5
A Linux kernel vulnerability exists in Virtual Routing and Forwarding (VRF) port removal that can cause a system crash. When a network port is removed from a VRF configuration, the kernel may incorrectly assume it can access Layer 3 device operations on a newly assigned master device (like a bridge) that doesn't support those operations. This leads to a null pointer dereference—essentially the kernel trying to read data from a memory address that doesn't exist. The issue stems from insufficient synchronization during the port removal process, allowing RCU readers (kernel code paths that read without locks) to encounter inconsistent state.
- CVE-2026-52926MEDIUM 5.5
A memory state management bug exists in the Linux kernel's batman-adv (B.A.T.M.A.N. Advanced) mesh networking module. When the mesh network is torn down, the code removes gateway nodes from the list but fails to clear the reference to the currently selected gateway. This leaves stale gateway state in memory that persists across cleanup operations. If the mesh is recreated later, this orphaned state can interfere with proper initialization and cause the mesh to malfunction. The fix is straightforward: clear the current gateway pointer before iterating through the gateway list during teardown.
- CVE-2026-52928MEDIUM 5.5
A flaw in the Linux kernel's AF_UNIX socket implementation allows improper handling of the SIOCATMARK socket operation on datagram and sequenced packet sockets. SIOCATMARK is designed to check whether incoming data has reached an urgent marker—a feature that should only apply to stream-based sockets. The kernel currently does not reject this operation on other socket types, potentially leading to unexpected behavior or denial of service. The fix ensures SIOCATMARK returns an unsupported error for non-stream sockets, aligning the kernel's behavior with its own rules for out-of-band messaging.
- CVE-2026-52930MEDIUM 5.5
A synchronization flaw in the Linux kernel's shared memory (shm) subsystem allows a local privileged attacker to cause a denial of service. The vulnerability exists in how the kernel decides when to clean up abandoned shared memory segments. The cleanup routine checks whether a segment is safe to destroy, but performs this safety check without holding the necessary lock, creating a race condition. Between the time the check passes and the segment is actually removed, another process can attach to it, leaving the kernel in an inconsistent state and potentially triggering a crash or hang.
- CVE-2026-52936MEDIUM 5.5
This vulnerability describes a performance and availability issue in the Linux kernel's jitterentropy random number generator. The problem occurs because a critical lock (spinlock) is held for too long while the system performs expensive entropy collection and cryptographic operations. When multiple processes try to generate random numbers simultaneously, they waste CPU cycles spinning and waiting for the lock instead of sleeping, causing system slowdowns and potential denial of service. The fix replaces the spinlock with a mutex, allowing contending processes to sleep efficiently rather than spin, improving overall system responsiveness under load.
- CVE-2026-52937MEDIUM 5.5
A vulnerability in the Linux kernel's tap network interface driver leaks sensitive kernel memory to unprivileged local users. When a user queries the hardware address of a tap or macvtap device using standard network tools, the kernel copies an incompletely initialized data structure to userspace, inadvertently disclosing 8 bytes of kernel stack contents. On systems running macvtap, this leak can expose kernel code pointers and direct-map memory addresses, undermining KASLR (kernel address space layout randomization) protections and providing attackers with information useful for exploiting other vulnerabilities.
- CVE-2026-52938MEDIUM 5.5
A flaw in the Linux kernel's BPF (Berkeley Packet Filter) socket storage mechanism can cause a system crash when the kernel tries to access memory that no longer exists. The vulnerability occurs during a race condition where one part of the kernel clears a reference to storage data while another part is simultaneously trying to read it, resulting in a NULL pointer dereference. This affects scenarios where socket cloning happens during TCP connection establishment and when diagnostic tools query BPF socket storage. The issue is local to the system and requires user-level privilege to trigger.
- CVE-2026-52939MEDIUM 5.5
A flaw in the Linux kernel's RDS (Reliable Datagram Sockets) over InfiniBand implementation causes a null pointer crash when handling masked atomic operations. When an unprivileged user sends certain atomic messages over an active RDS/IB connection, the kernel fails to properly track the request state, leading to a NULL dereference in interrupt context. This can crash the system or trigger a kernel panic. The issue only manifests on InfiniBand hardware that natively supports masked atomic operations, such as Mellanox MLX4 and MLX5 adapters.
- CVE-2026-52940MEDIUM 5.5
A bug in the Linux kernel's TUN network interface code fails to properly clear memory before sending it to unprivileged users. When a user reads from a TUN device, the kernel copies a 24-byte header structure to userspace, but only initializes the first 10 bytes. The remaining 14 bytes contain leftover kernel memory from the stack—sensitive data that should never leave kernel space. An attacker with local user privileges can repeatedly read packets and collect fragments of kernel memory, potentially revealing sensitive information used internally by the kernel.
- CVE-2026-52941MEDIUM 5.5
A vulnerability exists in the Linux kernel's SMC (Shared Memory Communications) networking implementation that can crash a system when tracing is enabled. Specifically, when a tracepoint used to monitor socket messaging is turned on, sending or receiving data over an SMC-D (Shared Memory Communications over DAPL) connection triggers a null pointer dereference. The kernel tries to access link information that doesn't exist for SMC-D sockets, causing a kernel panic. While enabling the tracepoint requires root access, unprivileged users can create SMC-D sockets and trigger the crash.
- CVE-2026-52944MEDIUM 5.5
CVE-2026-52944 is a permission-bypass flaw in the Linux kernel's ksmbd (SMB server) implementation. The FSCTL_SET_SPARSE operation, which controls whether a file is marked as sparse (a storage optimization technique), fails to verify user permissions before allowing the change. This means an unprivileged user could modify file attributes they shouldn't be able to touch—either because they're on a read-only share or because they lack the necessary write permissions on a writable share. The vulnerability requires local access to trigger but could lead to unauthorized file attribute modifications.
- CVE-2026-52948MEDIUM 5.5
A flaw in the Linux kernel's I2C device driver allows a local user to crash the system or leave I2C/SMBus hardware in a broken state. The vulnerability stems from an integer overflow when the driver processes timeout values submitted through a system call. An attacker with local access can supply a specially crafted timeout value that bypasses validation checks, causing the driver to set an invalid timeout internally. This leads to premature timeouts and corrupts the SMBus state machine, effectively denying service to legitimate I2C operations.
- CVE-2026-52949MEDIUM 5.5
A flaw exists in the Linux kernel's memory management subsystem (DRM TTM) where the buffer object shrinking function can enter an infinite loop when a backup operation fails. This happens because the code attempts to remove a buffer from a tracking list before confirming the backup succeeded, leaving the list in an inconsistent state if the operation fails. The fix ensures the removal from the tracking list only occurs after a successful backup, preventing the infinite loop condition.
- CVE-2026-52961MEDIUM 5.5
A bug in the Linux kernel's Ceph filesystem implementation can cause the system to crash when handling extended attributes (metadata tags attached to files). The problem stems from a timing issue where one part of the code calculates the size of attribute data while another part may simultaneously update that data, leading to an inconsistency. When the code later tries to verify the size matches expectations, the mismatch triggers a kernel panic. This affects systems using Ceph as a networked storage backend, particularly under specific file operation patterns.
- CVE-2026-52963MEDIUM 5.5
A flaw exists in the Linux kernel's USB audio MIDI handling code. When processing USB MIDI endpoint descriptors, the kernel validates the size of internal descriptor structures but fails to properly bound subsequent reads against the actual available data. An attacker with local access could craft a malicious USB device that provides specially formatted MIDI endpoint descriptors, causing the kernel to read beyond allocated memory regions during descriptor parsing. This results in a kernel crash or denial of service.
- CVE-2026-52964MEDIUM 5.5
A flaw in how the Linux kernel processes USB MIDI 2.0 device descriptors allows a malformed USB device to trigger an out-of-bounds memory read. When the kernel parses endpoint descriptors from a specially crafted MIDI 2.0 device, it fails to properly validate descriptor boundaries, potentially causing the parser to read memory beyond the intended descriptor region. This could lead to system crashes or information disclosure, but only affects systems where an untrusted USB device is connected and a user with non-root privileges interacts with MIDI functionality.
- CVE-2026-52965MEDIUM 5.5
This is a memory management bug in the Linux kernel's graphics driver subsystem (DRM/TTM). When the kernel tries to move graphics memory to disk storage and that operation fails, it attempts to restore the memory's position in its tracking list. However, the restoration logic places the memory in the wrong position—ahead of where the system was searching—which causes the kernel to repeatedly examine the same memory block in an infinite loop. This infinite loop can freeze or crash the system. The fix involves changing when certain cleanup operations happen and how they handle memory marked as non-evictable.
- CVE-2026-52966MEDIUM 5.5
A logic error in the Linux kernel's DRM (Direct Rendering Manager) subsystem can cause a denial of service when handling graphics device file descriptors. The bug stems from a recent change that failed to correctly update an internal pointer during memory management operations, leaving stale references that trigger a warning and potential crash when files are closed. This affects local users who can open DRM device files.
- CVE-2026-52970MEDIUM 5.5
A memory management flaw exists in the Linux kernel's netfilter module, specifically in how it handles network connection expectations. When the system creates a temporary expectation object for tracking network connections, it fails to properly release the memory reference it holds. This creates a resource leak that can accumulate over time, eventually exhausting available memory and causing the system to become unresponsive or crash. The vulnerability requires local access to trigger, making it a lower-risk issue for most internet-facing systems but a concern for multi-user environments or systems where untrusted local users have access.
- CVE-2026-52972MEDIUM 5.5
A vulnerability in the Linux kernel's cryptographic socket implementation allows a local attacker to trigger an arithmetic overflow when processing AEAD (Authenticated Encryption with Associated Data) operations. By crafting requests with excessively large associated data lengths, an attacker can cause a denial-of-service condition affecting system stability. The vulnerability requires local access and standard user privileges to exploit.
- CVE-2026-52977MEDIUM 5.5
A race condition in the Linux kernel's futex (fast userspace mutex) implementation can cause a system lockup when one task times out or receives a signal while waiting to be requeued to another futex. The issue arises because a departing task cannot remove itself from the queue quickly enough when a higher-priority task is holding the necessary locks, leading to deadlock or busy-loop scenarios that freeze the system. The fix involves properly removing waiters from the queue when requeue operations fail, allowing other tasks to progress and preventing the lockup condition.
- CVE-2026-52978MEDIUM 5.5
A Linux kernel networking subsystem (PSP) fails to enforce proper permission checks on two critical operations: changing device settings (dev-set) and rotating cryptographic keys (key-rotate). Currently, any user on the system who has access to the network namespace can perform these operations, even though they modify shared device state that should be restricted to administrators. This allows unprivileged local users to tamper with PSP configuration and key material without needing root-level capabilities.
- CVE-2026-52979MEDIUM 5.5
A flaw in the Linux kernel's PSP (Platform Security Processor) networking subsystem can lead to a denial-of-service condition. When creating a network association, the code obtains a reference to a PSP device but fails to verify the device is still active after acquiring a lock. This allows a device unregistration to proceed undetected, leaving the association code operating on stale or invalid device state, ultimately causing the system to crash or become unresponsive.
- CVE-2026-52980MEDIUM 5.5
CVE-2026-52980 is a memory corruption and denial-of-service vulnerability in the Linux kernel scheduler that can be triggered by a combination of process forking and yield operations. When a new process is created, the kernel's fair scheduling class fails to properly initialize certain deadline tracking state, causing subsequent scheduler operations to compute abnormally large deadline values. If the affected process later yields, these inflated values cascade into corrupted internal accounting structures, potentially rendering the entire scheduler unable to pick runnable processes and causing a system crash. The vulnerability requires local access and unprivileged execution, making it a practical risk in multi-user and containerized Linux environments.
- CVE-2026-52984MEDIUM 5.5
A flaw in the Linux kernel's network traffic scheduling (netem) module allows queue size limits to be bypassed when packets are reordered. The vulnerability occurs because the queue limit check only counts packets in one internal queue structure but ignores packets placed elsewhere during reordering, enabling total queue size to grow beyond configured limits. This can degrade system performance or cause denial of service conditions on systems relying on network queue limits for stability.
- CVE-2026-52985MEDIUM 5.5
CVE-2026-52985 is a memory initialization bug in the Linux kernel's netdevsim module. When the kernel builds dummy network packets for trap simulation, it fails to properly zero-initialize the IP header structure, leaving uninitialized memory that can be read by subsequent code. This is a kernel memory safety issue rather than a direct network-exploitable vulnerability. The fix is straightforward: replace a memory allocation function with one that guarantees zeroed memory.
- CVE-2026-52990MEDIUM 5.5
A vulnerability in the Linux kernel's file notification system causes an inode reference leak when monitoring marks are added and removed concurrently. When a file system mark transitions from being actively tracked to not, the kernel fails to properly release the inode reference, eventually causing processes (like umount) to hang indefinitely. This is a timing-sensitive race condition that requires specific concurrent activity to trigger.
- CVE-2026-52994MEDIUM 5.5
A flaw in the Linux kernel's virtual socket (vsock) implementation over virtio transport allows unprivileged users to bypass memory resource limits (RLIMIT_MEMLOCK) when using zero-copy message operations. The bug occurs because the kernel fails to properly account for pinned memory pages on the final network packet, allowing an attacker with local access to pin more memory than their account should be permitted, potentially causing denial of service.
- CVE-2026-52995MEDIUM 5.5
A vulnerability in the Linux kernel's RDS (Reliable Datagram Sockets) networking subsystem leaks uninitialized kernel memory to unprivileged local users. When certain RDS connection state queries are made, the kernel copies stack memory that was never properly initialized to user space, potentially exposing sensitive kernel addresses and data. The vulnerability affects code paths where the connection info visitor functions fail to populate all output fields before the buffer is returned to the caller.
- CVE-2026-52996MEDIUM 5.5
A resource leak vulnerability exists in the Linux kernel's SMB server implementation (ksmbd). When a client attempts to reconnect to a file using durable handle version 2, the server may fail to properly release a reference to a file descriptor if the client's identifier doesn't match what's stored on the server. This causes server memory and file table entries to accumulate over time, potentially degrading performance or causing denial of service as the system exhausts resources.
- CVE-2026-52997MEDIUM 5.5
A flaw in the Linux kernel's dualpi2 network queue management system can cause the system to crash when configuration changes are applied. The issue occurs when packets are routed to one queue while another queue is empty—the kernel tries to access data from the wrong location and encounters a NULL pointer, causing a denial of service. This vulnerability requires local access to trigger and affects systems using the dualpi2 qdisc for traffic shaping.
- CVE-2026-53001MEDIUM 5.5
A vulnerability in the Linux kernel's netfilter xtables subsystem allows a local user with limited privileges to cause a denial-of-service condition. The issue stems from improper protocol family restrictions in certain packet filtering modules (xt_mac, xt_owner, xt_physdev, and xt_realm). By crafting specific netfilter rules, an attacker could trigger excessive resource consumption or system crashes. This is a low-privilege local attack with no remote exploitation path.
- CVE-2026-53007MEDIUM 5.5
A NULL pointer dereference vulnerability exists in the Linux kernel's Intel ice driver that can crash the system. The flaw occurs when the driver attempts to configure transmit ring parameters but fails partway through the operation. Specifically, the code fails to properly clean up a flag indicating that timestamp functionality is enabled, even though the underlying data structure has been nullified. During error recovery, the code then tries to access that nullified structure, causing a kernel panic. This requires local system access to trigger.
- CVE-2026-53012MEDIUM 5.5
CVE-2026-53012 is a kernel bug affecting IPv6 routing in Linux. The issue occurs when an IPv6 nexthop (a routing destination point) is replaced with an IPv4 one, and the system fails to update its internal tracking flags. This mismatch causes the kernel to attempt operations on IPv4 routing data while treating it as IPv6, resulting in a crash when traffic tries to use the affected route. An unprivileged local user with network namespace privileges can trigger this by crafting specific routing configuration changes and then sending IPv6 traffic.
- CVE-2026-53013MEDIUM 5.5
A flaw in the Linux kernel's macvlan networking driver causes a space-reservation mismatch in network interface information reporting. When a macvlan interface is configured with a broadcast cutoff setting other than the default, the kernel fails to allocate enough buffer space for the configuration data when querying interface details. This triggers a warning and prevents the interface from being reported, potentially causing network management tools to fail silently.
- CVE-2026-53014MEDIUM 5.5
CVE-2026-53014 is a logic error in the Linux kernel's traffic control (tc) packet mirroring feature that causes the system to misidentify device types when redirecting network traffic to multiple destinations simultaneously. When a tc rule redirects packets to several devices at once—particularly when those devices have different underlying transmission modes (like an Ethernet interface versus a tunnel)—the kernel checks the wrong device's configuration, leading it to corrupt packet headers. In severe cases, this can cause the kernel to run out of memory and crash. The vulnerability requires local access to configure tc rules.
- CVE-2026-53015MEDIUM 5.5
A bug in the Linux kernel's EROFS (Enhanced Read-Only File System) implementation causes incorrect handling of logical cluster numbers on 32-bit systems. The vulnerability stems from using a 32-bit data type (`unsigned long` or `unsigned int`) for a value that can exceed 4 GiB when shifted by the cluster size multiplier. By unifying this value to a 64-bit type, the kernel prevents truncation and data corruption that could occur when the filesystem attempts to access or manipulate file locations beyond the 4 GiB boundary on 32-bit platforms.