By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
8541 published vulnerabilities · page 62 of 86
- CVE-2026-46151MEDIUM 5.5
A flaw in the Linux kernel's USB printer driver (usblp) allows a malicious or malfunctioning printer to leak uninitialized kernel memory to local users. When a printer responds to a device ID request with fewer bytes than claimed in its length header, the driver fails to zero out the remaining buffer before exposing it via sysfs or an ioctl. An attacker with local access could craft a printer (or intercept USB traffic) to trigger this and read sensitive kernel memory.
- CVE-2026-46153MEDIUM 5.5
A memory leak exists in the Linux kernel's VLAN (802.1Q) network driver. When network administrators repeatedly configure and then clear egress QoS priority mappings on VLAN interfaces, the kernel fails to properly delete the cleared mappings. Instead, it retains them as empty placeholders (tombstones) in memory. Over time, this causes memory to accumulate and leak, eventually exhausting system resources when the VLAN device is torn down. The fix involves properly deleting these cleared mappings after a safe grace period rather than leaving them in place.
- CVE-2026-46156MEDIUM 5.5
A flaw in the Linux kernel's Loongson GPU driver can cause a system crash when the code attempts to read from an invalid memory address during hardware initialization. The vulnerability occurs in the `loongson_gpu_fixup_dma_hang()` function, which uses incorrect logic to identify and configure GPU devices on certain Loongarch-based systems. When a discrete GPU is present in a non-standard PCI slot configuration, the driver may try to access memory at a random address, triggering a kernel panic. This is a local issue that requires prior system access and affects the stability and availability of affected systems.
- CVE-2026-46158MEDIUM 5.5
CVE-2026-46158 is a resource leak in the Linux kernel's MPTCP (Multipath TCP) protocol implementation. When the kernel retransmits an ADD_ADDR control message, it fails to properly release a reference to a socket object in certain error paths, allowing the socket's memory to remain allocated longer than necessary. This leak occurs only when specific unlikely conditions are met during ADD_ADDR retransmission, making it a localized but real availability concern on systems handling MPTCP traffic.
- CVE-2026-46160MEDIUM 5.5
A flaw in the Linux kernel's Btrfs filesystem can corrupt the transaction log during recovery if a directory is removed while a process still holds an open file descriptor to it and performs an fsync operation. When the system crashes after this sequence, the filesystem becomes inconsistent and fails to mount, resulting in data loss or extended downtime. This is a local issue requiring user-level access and specific conditions to trigger.
- CVE-2026-46161MEDIUM 5.5
A divide-by-zero vulnerability exists in the Linux kernel's RAID10 disk management code. When a user configures RAID10 with a "far_copies" value of zero, the kernel crashes instead of rejecting the invalid configuration. This requires local access and root-level privileges to trigger, making it a local denial-of-service risk rather than a remote compromise threat.
- CVE-2026-46165MEDIUM 5.5
A self-deadlock vulnerability exists in the Linux kernel's Open vSwitch module when tunnel ports are released. The issue occurs because the code attempts to clean up network device references while holding locks that prevent the cleanup from completing, causing the system to hang during tunnel port deletion. This is a local denial-of-service condition that affects systems running vulnerable kernel versions with Open vSwitch configured.
- CVE-2026-46167MEDIUM 5.5
A flaw in the Linux kernel's USB printer driver (usblp) allows uninitialized kernel memory to leak to user-space applications through the LPGETSTATUS ioctl command. When a USB printer responds with fewer bytes than expected, the driver fails to initialize the response buffer properly, potentially exposing stale heap memory to callers. This can occur even with standard-behaving printers; the vulnerability is particularly concerning in multi-user environments where one user's application could inadvertently receive residual kernel memory from prior operations.
- CVE-2026-46168MEDIUM 5.5
A vulnerability in the Linux kernel's multipath TCP (MPTCP) implementation allows a local attacker with standard user privileges to trigger a denial-of-service condition. The issue stems from improper locking during socket option handling for timestamps. When the kernel attempts to set timestamp options, it uses a fast atomic lock that cannot safely call functions designed to sleep, resulting in a kernel panic. An unprivileged user can exploit this by making specific socket option calls, causing the system to crash or become unresponsive.
- CVE-2026-46169MEDIUM 5.5
CVE-2026-46169 is a memory initialization bug in the Linux kernel's HFS+ filesystem driver. When mounting a corrupted HFS+ filesystem, the kernel may read incomplete catalog records and fail to detect that the data is truncated. This leaves portions of a kernel data structure uninitialized. Later, when the filesystem code attempts to process the incomplete record—such as performing case-insensitive string comparison—it uses the uninitialized memory as array indices, triggering a kernel warning. An unprivileged local attacker with the ability to mount a crafted filesystem image could trigger this condition, potentially causing a denial of service or information disclosure.
- CVE-2026-46170MEDIUM 5.5
A flaw in the Linux kernel's MPTCP (Multipath TCP) path manager can cause a denial of service when certain network protocol messages are retransmitted. Specifically, when an ADD_ADDR message is resent, the kernel may mismanage internal reference counting for a socket object, potentially leading to a deadlock or crash. An unprivileged local user can trigger this condition, causing the affected system to become unresponsive.
- CVE-2026-46171MEDIUM 5.5
A memory leak exists in the Linux kernel's RISC-V KVM (virtualization) subsystem. When the kernel attempts to allocate memory for virtual CPU vector context during guest setup, it allocates two separate memory blocks. If the second allocation fails, the first block is not freed, causing a memory leak. This leak occurs in unprivileged code paths and can gradually exhaust kernel memory, leading to system denial of service.
- CVE-2026-46172MEDIUM 5.5
A memory leak vulnerability exists in the Linux kernel's IPv6 IPsec handling code. When the kernel processes certain incoming IPv6 packets with IPsec encapsulation, it performs a route lookup but fails to properly clean up a reference to the routing information in error conditions. An attacker with local access could trigger this flaw repeatedly, exhausting kernel memory and causing a denial of service.
- CVE-2026-46179MEDIUM 5.5
A vulnerability in the Linux kernel's ASoC (ALSA System on Chip) audio subsystem allows local users to trigger a divide-by-zero condition when working with compressed audio streams. The kernel fails to validate that critical stream configuration parameters are properly initialized before performing calculations with them, creating a denial-of-service vector for any local process with audio subsystem access.
- CVE-2026-46182MEDIUM 5.5
A vulnerability in the Linux kernel's IBM POWER Systems (pseries) PAPR hypervisor pipe driver allows uninitialized kernel memory to be exposed to unprivileged users. When the driver copies a header structure to userspace, it fails to zero out reserved padding fields within that structure, inadvertently leaking sensitive kernel data. An attacker with local access could read this leaked memory to potentially gather information about the running kernel state.
- CVE-2026-46184MEDIUM 5.5
A USB audio device driver in the Linux kernel can crash if a malformed device provides zero audio channels. The driver fails to validate a critical USB descriptor field before using it in calculations, leading to a division-by-zero error when the device is connected. An attacker with physical access to plug in a crafted USB device could trigger a kernel panic on vulnerable systems.
- CVE-2026-46186MEDIUM 5.5
A flaw in the Linux kernel's Bluetooth virtio driver fails to validate that incoming packets contain enough data before processing them. When a malformed or truncated packet arrives, the driver can read beyond the packet's actual boundaries, potentially accessing uninitialized memory. This could cause the system to crash or misbehave, particularly on systems with active Bluetooth connections.
- CVE-2026-46188MEDIUM 5.5
A flaw exists in the Linux kernel's Cavium Octeon EP VF driver where a memory allocation function can fail but the code doesn't check for failure. When this happens, the driver tries to use the failed allocation as if it were valid, causing the system to crash. This is a local issue requiring user-level access to trigger.
- CVE-2026-46192MEDIUM 5.5
A flaw exists in the Linux kernel's Microchip QSPI (Quad SPI) driver that causes read operations to fail when using dual or quad-mode communication. The driver incorrectly attempts to transmit garbage data to generate clock cycles during read-only operations, but QSPI lacks a dedicated output line for this purpose in these modes. This causes the transfer to stall, effectively making data reads unreliable or impossible on affected systems using this driver.
- CVE-2026-46193MEDIUM 5.5
A flaw in the Linux kernel's AH (Authentication Header) implementation causes incorrect packet authentication when Extended Sequence Numbers (ESN) are enabled and async cryptographic operations are used. The kernel miscalculates where authentication data is stored during async callbacks, leading to the comparison of wrong bytes and packet validation failures. This breaks IPsec AH protection on affected systems.
- CVE-2026-46196MEDIUM 5.5
A flaw in the Linux kernel's tracepoint subsystem can leave internal state in an inconsistent condition when probe registration fails. Specifically, when the kernel tries to activate a tracepoint for the first time and the activation succeeds but the probe installation fails (e.g., due to out-of-memory conditions), the cleanup routine is never called. This leaves persistent overhead on every task in the system—most notably for syscall tracing—until the system is rebooted. The issue is a resource leak of kernel state rather than a direct security bypass, but it degrades performance and system stability under memory pressure or specific tracepoint registration sequences.
- CVE-2026-46200MEDIUM 5.5
A flaw in the Linux kernel's MPC52xx SPI controller driver can cause a system crash or denial of service when the driver is unloaded. The issue stems from improper resource cleanup during driver removal—specifically, the controller is disabled and its resources (interrupts, GPIOs) are released before the controller is properly deregistered from the kernel, leaving dangling references that can trigger a crash.
- CVE-2026-46202MEDIUM 5.5
A locking bug in the Linux kernel's Apple Touch Bar keyboard driver (hid-appletb-kbd) causes the system to attempt sleeping operations from atomic (interrupt) contexts where sleeping is forbidden. The bug occurs in two code paths that adjust keyboard backlight brightness: a periodic inactivity timer and a user-activity reset handler. Both trigger calls to the backlight subsystem's brightness function, which tries to acquire a mutex while running in softirq or IRQ context, causing kernel warnings and potential system instability. The fix moves these blocking operations to a workqueue, allowing them to run safely in process context.
- CVE-2026-46207MEDIUM 5.5
A flaw in the Linux kernel's vsock/virtio module causes monitoring tools to receive incomplete data when handling certain network packets. Specifically, when the kernel processes non-linear network buffers for the virtual socket monitoring interface (vsockmon), it fails to properly initialize a data structure that controls how much information gets copied. This leaves monitoring tools unable to see the full payload of these packets, potentially obscuring network activity. The issue affects local processes with standard privileges and could be exploited to hide data from network inspection.
- CVE-2026-46211MEDIUM 5.5
A flaw in the Linux kernel's graphics driver (msm/gem) causes an ioctl function to report success even when it fails. When userspace attempts to retrieve metadata about graphics objects, the function incorrectly returns 0 (success) even if the underlying operations—such as copying data to userspace or allocating memory—actually fail. Additionally, if memory allocation fails, the code does not check for a NULL pointer, leading to a crash. This allows applications to think they've successfully retrieved metadata when they haven't, or to trigger a denial of service.
- CVE-2026-46214MEDIUM 5.5
A flaw in the Linux kernel's virtual socket (vsock) implementation can cause connection listeners to stop accepting new connections after a small number of transport negotiation failures. The bug occurs in the virtio transport layer when the code increments an internal counter to track pending connections but fails to decrement it if the transport negotiation fails. After enough failed attempts, the listener incorrectly believes its connection queue is full and rejects all new incoming connections, effectively causing a denial of service for applications relying on vsock communication.
- CVE-2026-46216MEDIUM 5.5
A flaw in the Linux kernel's GPU driver for Intel Arc graphics allows a local attacker with basic user privileges to crash the system. The vulnerability occurs when certain GPU components (specifically the media GT) are disabled through system configuration. Under these conditions, the driver attempts to access memory that hasn't been allocated, causing a kernel panic. An attacker with local access can trigger this crash, resulting in a denial of service. This is a localized memory safety issue that requires local access to exploit.
- CVE-2026-46220MEDIUM 5.5
A vulnerability in the Linux kernel's AMD GPU driver allows an unprivileged user to crash the system by submitting specially crafted graphics commands. The driver was using an overly aggressive error check (BUG_ON) that would panic the entire kernel when it detected a misaligned memory address—even though the real fix should have happened earlier in the validation pipeline. By replacing these fatal assertions with warnings, the system can log the problem without crashing, while proper validation is moved to the correct layer of the code.
- CVE-2026-46221MEDIUM 5.5
A memory leak exists in the Linux kernel's EDAC (Error Detection and Correction) versalnet driver. When the driver initializes memory controller devices, it allocates memory for a device name string but fails to properly free it during normal driver removal. The kernel's device registration process copies the name internally and then loses track of the original allocation, leaving orphaned memory that cannot be reclaimed. This gradually consumes system memory over repeated device initialization and removal cycles.
- CVE-2026-46222MEDIUM 5.5
A flaw exists in the Linux kernel's Rockchip RKCam Interface (rkcif) media driver where certain data connection points (pads) lack proper validation checks. When a video stream is started on a device where these pads are not correctly connected, the kernel attempts to access memory that doesn't exist, causing the system to crash. This is a local issue—only users with login access to the affected system can trigger it, typically through video application commands.
- CVE-2026-46223MEDIUM 5.5
This Linux kernel vulnerability centers on a deadlock condition in cgroup resource management during container shutdown. When a system administrator removes a cgroup (via rmdir), the kernel's cleanup logic can become stuck waiting for tasks to exit under certain conditions—specifically when the process performing the removal is also responsible for reaping zombie processes. This creates a circular dependency where the cleanup cannot proceed because the reaper is blocked, and the zombies cannot be cleaned because the reaper is stuck. The fix defers the actual cleanup work to run asynchronously after tasks have already left the cgroup, allowing the rmdir operation to return promptly while kernel-side cleanup continues in the background.
- CVE-2026-46224MEDIUM 5.5
A memory leak vulnerability exists in the Linux kernel's DRM (Direct Rendering Manager) Xe driver. When the driver attempts to initialize a DMA buffer object and encounters an allocation failure, it fails to properly clean up a pre-allocated buffer object, causing it to leak into memory. The vulnerability requires local system access and affects the kernel's ability to manage GPU memory correctly. While this is not a critical security issue, it can lead to denial of service through memory exhaustion over time.
- CVE-2026-46225MEDIUM 5.5
A flaw has been found in how the Linux kernel's SPI (Serial Peripheral Interface) RSPI driver shuts down. When a system stops using the driver, it wasn't properly cleaning up in the right order—specifically, it was releasing DMA (direct memory access) resources before telling the SPI controller to stop. This ordering problem can cause the system to become unstable or crash.
- CVE-2026-46226MEDIUM 5.5
A flaw in the Linux kernel's Freescale SPI controller driver can cause a system crash when the driver is unloaded. The issue occurs because the driver releases hardware resources (like DMA) before properly shutting down the SPI controller, leaving it in an inconsistent state. An attacker with local system access could trigger this crash by unloading the driver, resulting in a denial of service.
- CVE-2026-46228MEDIUM 5.5
A memory management flaw in the Linux kernel's SPI CH341 USB driver can cause memory to persist after the driver is unloaded, potentially leading to denial of service. The issue arises because device resources tied to a USB driver are incorrectly managed at the parent device level rather than at the individual interface level, preventing proper cleanup when drivers unbind without physical device disconnection.
- CVE-2026-46229MEDIUM 5.5
A vulnerability in the Linux kernel's AMD KFD (Kernel Fusion Driver) GPU memory management allows stale data from previous GPU memory allocations to remain accessible to new compute tasks. When GPU VRAM is allocated for new workloads, the kernel does not properly clear it, leaving behind fragments of prior page tables and data. Compute kernels can observe this leftover information, which can corrupt GPU-to-GPU communication protocols and cause application crashes, particularly in high-performance computing scenarios involving NVIDIA RCCL P2P transport operations.
- CVE-2026-46231MEDIUM 5.5
A flaw in the Linux kernel's batman-adv (B.A.T.M.A.N. Advanced) networking module leaks memory when certain network claim operations fail. Specifically, when the system attempts to record a new claim in an internal hash table but the insertion fails, it forgets to release a reference to a network backbone object, causing that object to remain in memory indefinitely. This gradual accumulation of unreleased objects can eventually degrade system performance or trigger a denial of service.
- CVE-2026-46233MEDIUM 5.5
A flaw in the Linux kernel's Batman-adv bridge loop avoidance (BLA) subsystem can cause a crash when the system attempts to clean up stale network bridge claims. The issue occurs because the cleanup routine doesn't properly check whether a claim is still valid before trying to access it, potentially leading to a null pointer dereference. An attacker with local access could trigger this condition to cause a denial of service.
- CVE-2026-46235MEDIUM 5.5
The Linux kernel's saa7164 media driver failed to properly validate whether memory mapping operations succeeded before using the results. When the kernel tries to map I/O memory regions for certain hardware (specifically PCI base address registers 0 and 2), it could receive a null pointer if the operation failed. The driver would then attempt to use these null pointers, causing a system crash. This patch adds defensive checks: if memory mapping fails, the driver now properly cleans up any partially allocated resources and safely reports an error instead of proceeding with unusable pointers.
- CVE-2026-46236MEDIUM 5.5
A flaw has been identified in the Linux kernel's Xbox remote control driver that mishandles memory buffers used for direct hardware communication (DMA). The driver incorrectly stores DMA buffers as part of the device structure, violating fundamental DMA coherency rules. This misconfiguration can cause the system to become unstable or unresponsive, though it requires local access to trigger. The issue affects systems running vulnerable versions of the Linux kernel with the Xbox remote driver enabled.
- CVE-2026-46239MEDIUM 5.5
A memory management bug in the Linux kernel's OV5647 camera driver causes system resources to not be properly released when certain camera control operations are performed. Specifically, three control settings—autogain, automatic exposure, and analog gain—skip the cleanup step that tells the system a resource is no longer needed, leaving the system in a degraded state. Repeated use of these controls can exhaust system resources and cause the kernel to become unstable or unresponsive.
- CVE-2026-46245MEDIUM 5.5
A flaw in the Linux kernel's AMD display driver (amdgpu) can cause a system crash when the driver attempts to initialize Hot Plug Detect (HPD) interrupts for video connectors. The problem occurs because the code checks whether a connector's data structure (dc_link) is valid in one place, but then later uses it without checking again, leading to a null pointer dereference. This vulnerability affects systems with AMD GPUs running vulnerable kernel versions and can be triggered by a local user, resulting in a denial of service.
- CVE-2026-46247MEDIUM 5.5
This vulnerability affects the Linux kernel's clock management subsystem, specifically the graphics processor (GFX3D) clock driver. A bug in how parent clock information is passed during rate calculations causes the system to crash when the GPU attempts to change its operating frequency. The issue emerged after a code refactoring that changed how clock dividers calculate rates. When the GPU's power management system tries to adjust clock speed—a routine operation during dynamic frequency scaling—the missing parent clock information causes a kernel panic. The vulnerability requires local access and affects systems running vulnerable kernel versions on Qualcomm-based devices.
- CVE-2026-46248MEDIUM 5.5
This vulnerability affects the Linux kernel's WiFi driver for Qualcomm Atheros ath12k chipsets. When a WiFi interface fails during setup for multi-link operation (MLO), the driver can retain stale data about link mappings. If a new connection attempt reuses the same link ID, the driver triggers a warning and may experience instability. The issue stems from incomplete cleanup during failed initialization—specifically, link deletion code only runs if the interface was fully created, leaving orphaned references behind.
- CVE-2026-46249MEDIUM 5.5
This Linux kernel vulnerability affects the OcteonTX2 ARM-based System-on-Chip (SoC) driver stack, specifically the Application Firmware (AF) and Physical Function (PF) drivers used in Marvell networking hardware. During a kexec reboot—a fast reboot mechanism that skips the firmware/BIOS phase—hardware state from the previous kernel persists. The bug occurs when AF fails to properly clear its initialization marker before shutdown. When the PF driver loads in the new kernel, it checks this marker to determine if AF is ready. Finding a stale marker, the PF driver incorrectly assumes AF has already initialized and attempts to access hardware that was never properly reset, causing a kernel crash. This is primarily a denial-of-service condition affecting systems performing kexec reboots with modular driver configurations.
- CVE-2026-46252MEDIUM 5.5
A locking bug exists in the Linux kernel's regulator power management subsystem. When the system attempts to enable a power supply regulator and that operation fails, the error-handling code releases a reference to the regulator object without holding the required lock. This creates a race condition where another part of the system could be accessing the regulator data simultaneously, potentially causing a crash or memory corruption. The fix involves using the correct function call that ensures proper locking during cleanup, and adding additional safeguards to prevent concurrent access while clearing internal pointers.
- CVE-2026-46254MEDIUM 5.5
A vulnerability in the Linux kernel's AppArmor security module can cause system crashes or hangs when AppArmor processes policy rules containing improperly aligned data structures. The kernel's DFA (Deterministic Finite Automaton) tables used by AppArmor to enforce security policies may originate from either kernel memory or user-supplied configuration, and when these tables aren't properly aligned to 8-byte boundaries, certain CPU architectures trigger unaligned memory access errors. This is a denial-of-service issue—an unprivileged user with the ability to load or modify AppArmor policies could crash the kernel without data loss or privilege escalation.
- CVE-2026-46255MEDIUM 5.5
The Linux kernel's fsl-edma driver contains a resource management bug where clock handles are being manually disabled during driver removal, even though they were allocated using automatic cleanup functions. This causes the system to attempt disabling clocks that have already been cleaned up by the kernel, generating warnings and potentially destabilizing the driver removal process. The fix is straightforward: remove the redundant manual disable calls and let the automatic cleanup mechanism handle it.
- CVE-2026-46256MEDIUM 5.5
A recursion deadlock vulnerability exists in the Linux kernel's NFS LOCALIO feature, which optimizes loopback NFS mounts by bypassing the network when client and server run on the same system. Under memory pressure, the kernel's direct reclaim mechanism can trigger a circular chain: NFS writes → XFS filesystem → back into NFS page cache operations, causing the system to hang. The vulnerability requires local access and affects systems using LOCALIO-enabled NFS mounts. A fix ensures memory allocations in the LOCALIO code path use GFP_NOFS context to prevent this recursion.
- CVE-2026-46257MEDIUM 5.5
A flaw in the Linux kernel's SP804 timer driver can cause the system to crash when certain timing functions are called on ARM32 platforms. The issue arises when the SP804 timer is configured in a way that leaves a shared clock object uninitialized, but the kernel still tries to read from it. This vulnerability has been fixed by separating the delay timer functionality into its own dedicated clock instance, preventing the kernel from attempting to access uninitialized memory.
- CVE-2026-46258MEDIUM 5.5
A flaw in the Linux kernel's GPIO character device (cdev) interface causes the system to crash when creating a line handle. The issue occurs because code attempts to use a pointer after it has been intentionally cleared to NULL, leading to a crash when the kernel tries to access memory through that invalid pointer. This is a local issue—an authenticated user on the system would need to trigger it, typically through ioctl calls to the GPIO device.
- CVE-2026-46261MEDIUM 5.5
A vulnerability in the Linux kernel's SPI WPC flash interface unit driver can cause the system to crash due to a missing safety check. When the driver initializes, it attempts to access memory resources without first verifying they exist, potentially leading to a NULL pointer dereference that brings down the affected process or system. This is a localized denial-of-service issue requiring local system access to trigger.
- CVE-2026-46262MEDIUM 5.5
A deadlock vulnerability exists in the Linux kernel's audio subsystem (ASoC fsl_xcvr driver) where a recent locking fix introduced the opposite problem: the code attempts to re-acquire a lock that is already held by the calling function, causing the system to hang. When a user adjusts audio control settings through ALSA, the kernel deadlocks instead of safely updating the configuration.
- CVE-2026-46268MEDIUM 5.5
A logic error in the Linux kernel's PCI peer-to-peer DMA memory allocation code causes a spurious warning to be logged when kernel debug features are enabled. The vulnerability stems from a mismatch between a code assertion and a prior change to how memory pages are initialized—the assertion expects a non-zero reference count, but the pages are now created with a zero count by design. While the actual functionality remains intact, the warning floods kernel logs and can trigger monitoring alerts, degrading system observability and potentially masking other issues.
- CVE-2026-46269MEDIUM 5.5
A NULL pointer dereference vulnerability exists in the Linux kernel's Canaan K230 pinctrl driver. During device initialization, the driver attempts to access a device structure through an uninitialized pointer, causing the kernel to crash. The issue occurs because the code tries to retrieve the device reference via a control structure that hasn't been set up yet. An attacker with local access could trigger this crash by loading the affected driver or probing the device, leading to a denial of service.
- CVE-2026-46276MEDIUM 5.5
A Linux kernel bug in AMD's GPU driver causes the system to crash during startup when loading newer AMD Radeon RX 9070 XT graphics cards on RDNA4 hardware. The issue stems from the driver trying to initialize memory regions that don't physically exist on this newer GPU architecture. When the kernel attempts to set up these non-existent resources with zero size, it triggers a safety check that crashes the boot process. This only affects systems where kernel debugging is enabled; most deployments have avoided the crash by accident rather than design.
- CVE-2026-46278MEDIUM 5.5
A null pointer dereference vulnerability exists in the Linux kernel's Imagination PowerVR graphics driver. When a local user attempts to update ftrace debug settings through a debugfs interface, the driver passes incorrect data to the operation, causing the kernel to crash. This is a stability issue rather than a data breach or privilege escalation risk—an authenticated local user can trigger a denial of service condition.
- CVE-2026-46282MEDIUM 5.5
A flaw in the Linux kernel's admv1013 frequency driver can cause the system to crash or become unresponsive. The vulnerability occurs when the driver fails to properly read a configuration setting from the device, but then tries to use that uninitialized data anyway, leading to a null pointer dereference. An unprivileged local user with access to the affected system could trigger this condition to cause a denial of service.
- CVE-2026-46283MEDIUM 5.5
A vulnerability in the Linux kernel's TPM (Trusted Platform Module) driver leaves sensitive cryptographic session keys in freed memory when a TPM device is closed. The driver should zero out this memory before releasing it—a standard security practice it already uses in other code paths—but this particular cleanup path was missed. An attacker with local access could potentially recover these keys from freed memory before it's overwritten by other processes.
- CVE-2026-46284MEDIUM 5.5
A defect in the Linux kernel's hugepages parameter parsing can cause the system to crash during early boot if certain kernel command-line parameters are malformed. Specifically, if hugepages, hugepagesz, or default_hugepagesz parameters are supplied without an equals sign (e.g., 'hugepages 1G' instead of 'hugepages=1G'), the kernel's early parameter handler passes a NULL pointer to the hugetlb_add_param() function, which then crashes when attempting to measure the string length. The fix validates input before processing and rejects malformed parameters gracefully.
- CVE-2026-46286MEDIUM 5.5
A vulnerability exists in the Linux kernel's Qualcomm LED driver (qcom-lpg) where a register value intended to select from a predefined array is not properly validated before use. The register can hold values 0–7 (from a 3-bit field), but the array contains only 5 entries. Without bounds checking, out-of-range values cause the code to read uninitialized or incorrect memory, which then gets used to configure LED brightness timing parameters. While actual hardware typically produces valid register values, the lack of defensive checks creates a potential denial-of-service condition if invalid data is encountered.
- CVE-2026-46287MEDIUM 5.5
The Linux kernel's txgbe network driver has a defect in how it disconnects from external PHY (Physical Layer transceiver) devices when the driver module is unloaded. When users remove the txgbe module, the driver attempts to disconnect the PHY without first acquiring the RTNL (Real-Time Netlink) lock, which is required by the kernel's phylink subsystem. This causes a kernel assertion failure and warning message, though it does not directly compromise system security or data. The fix involves wrapping the disconnect call with proper locking.
- CVE-2026-46290MEDIUM 5.5
A Linux kernel bug affects how the system handles page faults during firmware calls on x86/EFI systems. Recent changes to improve cryptographic performance modified how the kernel manages floating-point unit access, inadvertently causing the page fault handler to always bail out when firmware triggers a fault. On systems with buggy firmware that generates page faults during runtime calls, this escalates to a system panic and hard freeze instead of gracefully recovering. The fix changes the fault detection logic to properly distinguish between real interrupt contexts and the FPU management code path.
- CVE-2026-46291MEDIUM 5.5
A flaw in the Linux kernel's cryptographic subsystem can expose sensitive HMAC key material through debug output when certain debugging configurations are enabled. The vulnerability exists in the hash_digest_key function of the CAAM (Cryptographic Acceleration and Assurance Module) driver, which was inadvertently dumping key bytes in plaintext during kernel logging. An attacker with local access could potentially read these keys from kernel logs or memory if dynamic debugging is active, compromising cryptographic operations that depend on key secrecy.
- CVE-2026-46292MEDIUM 5.5
A Linux kernel vulnerability in the power domain management (genpd) subsystem leaves virtual devices with runtime PM incorrectly enabled after detachment. When drivers use genpd_dev_pm_attach_by_id() to register virtual devices, the kernel enables runtime PM for them but fails to disable it when those devices detach. This leaves the system in an inconsistent state that can trigger NULL pointer dereferences or cause the kernel to unnecessarily vote for higher performance states. The fix adds a missing pm_runtime_disable() call during device detachment to restore proper state management.
- CVE-2026-46295MEDIUM 5.5
A race condition in the Linux kernel's KVM hypervisor can cause the system to incorrectly report whether virtual CPUs have pending interrupts. When one virtual CPU sends an interrupt to another while the receiving CPU is simultaneously checking for pending interrupts, a timing gap allows the system to think an interrupt has arrived when it hasn't actually been delivered yet. While the interrupt itself isn't lost—it remains queued internally—the false reporting triggers a warning message and wastes CPU cycles with unnecessary virtual machine context switches. This affects systems running KVM hypervisor on x86 processors, particularly in nested virtualization scenarios under heavy load.
- CVE-2026-46296MEDIUM 5.5
A bug in the Linux kernel's SPI driver for Samsung S3C64xx controllers can crash the system when the driver is unloaded. The issue stems from incomplete refactoring: code that allocates DMA channels was moved from initialization to a later setup phase, but the corresponding cleanup code was not removed from the driver shutdown process. When the driver unloads, it tries to release DMA resources that were never allocated, triggering a NULL-pointer crash.
- CVE-2026-46297MEDIUM 5.5
A vulnerability in the Linux kernel's libwx networking driver incorrectly uses a threaded interrupt handler setup with missing threaded handler logic, triggering kernel warnings and potential system instability. The issue affects virtual function (VF) miscellaneous interrupt handling. The fix involves switching to the standard non-threaded interrupt request function and removing an unnecessary flag that doesn't apply to non-threaded handlers.
- CVE-2026-46302MEDIUM 5.5
A Linux kernel vulnerability allows a single process to monopolize read access to the SELinux security policy file, preventing other processes from retrieving critical security configuration. This denial-of-service condition stems from an overly restrictive locking mechanism that was originally intended to prevent memory exhaustion and inconsistent policy views, but achieves neither goal effectively. The issue is resolved by allowing concurrent reads of the policy file while maintaining data integrity through refined locking.
- CVE-2026-46305MEDIUM 5.5
A flaw in the Linux kernel's rtl8723bs WiFi driver can cause the system to crash if memory allocation fails during buffer initialization. When the driver attempts to create a buffer, it doesn't properly check whether the memory allocation succeeded before trying to use it. If the allocation fails—a condition that may occur under memory pressure—the code will attempt to access a NULL pointer, causing a denial of service. This is a localized driver issue affecting WiFi functionality rather than a system-wide kernel compromise.
- CVE-2026-46310MEDIUM 5.5
A flaw in the Linux kernel's Renesas VSP1 media driver causes a system crash when the module is unloaded on certain hardware generations. The bug stems from cleanup code calling the wrong function variant, leaving a dangling pointer that triggers a crash. This affects local users with module unload privileges and requires a kernel patch to resolve.
- CVE-2026-46312MEDIUM 5.5
A flaw in the Linux kernel's video buffer management can trigger a kernel warning when memory-mapped video buffers from certain capture drivers are accessed through the graphics subsystem. While the warning itself doesn't cause data loss or direct compromise, it indicates improperly configured memory protections that should have been set. This affects primarily developers and systems running specialized camera capture software on affected kernels.
- CVE-2026-46313MEDIUM 5.5
A flaw exists in the Linux kernel's Intel IPU6 media driver where an error-handling code path incorrectly dereferences a pointer that has been marked as invalid (an error pointer). When the driver encounters certain initialization failures during PCI device probing, it attempts to clean up resources but doesn't properly null-check a pointer before using it, leading to a kernel crash. This is a local denial-of-service issue affecting systems running vulnerable kernel versions with the Intel IPU6 driver enabled.
- CVE-2026-46314MEDIUM 5.5
A flaw in the Linux kernel's DRM v3d driver allows a local user to trigger an infinite loop by submitting a maliciously crafted system call with a self-referential extension structure containing zero synchronization counts. This causes the kernel to hang indefinitely, consuming CPU resources and freezing the affected process. An attacker with local access can exploit this to perform a denial-of-service attack on systems running vulnerable kernel versions.
- CVE-2026-46315MEDIUM 5.5
A vulnerability in the Linux kernel's io_uring subsystem can leak uninitialized kernel memory to userspace when using the IOURING_OP_WAITID operation. When a wait operation completes without reporting child process events, the kernel fails to zero-initialize its result buffer before copying it to user applications, exposing stale data that was previously stored in the same kernel memory. This is a local information disclosure issue affecting users who can invoke io_uring operations on systems where they have access.
- CVE-2026-46318MEDIUM 5.5
A vulnerability in the Linux kernel's hugetlbfs memory management subsystem can cause a memory leak when virtual memory area (VMA) lock allocation fails during the memory mapping preparation stage. The issue stems from an earlier patch that attempted to optimize how hugetlb mappings are set up, but inadvertently created a window where a failed lock allocation could leave resources unreleased. A local user with standard privileges can trigger this condition, leading to denial of service through memory exhaustion.
- CVE-2026-46329MEDIUM 5.5
A flaw in the Linux kernel's EROFS (Enhanced Read-Only File System) implementation fails to properly handle I/O requests that extend beyond the filesystem boundary when the filesystem is mounted from a file. Instead of safely zeroing out the requested data (as loopback devices and the kernel's expected behavior dictate), the kernel may access invalid memory or return uninitialized data. This can lead to a denial of service or potential information disclosure on systems using file-backed EROFS mounts.
- CVE-2026-46465MEDIUM 5.5
Dell PowerProtect Data Domain contains a format string vulnerability that allows a high-privileged attacker with network access to trigger information disclosure or crash the system. While the vulnerability requires elevated privileges to exploit, its presence in backup and archival infrastructure—often a critical dependency—warrants careful monitoring and timely patching.
- CVE-2026-46521MEDIUM 5.5
ImageMagick, a widely-used open-source image manipulation library, contains a flaw in its LZMA compression handling within the MIFF encoder. When processing specially crafted image files, the software can write data beyond allocated memory boundaries, potentially crashing the application or corrupting system memory. This vulnerability affects versions prior to 6.9.13-48 (legacy branch) and 7.1.2-23 (current branch).
- CVE-2026-47262MEDIUM 5.5
containerd, the widely-used container runtime that powers Docker and Kubernetes, has a memory exhaustion vulnerability that can crash the entire runtime. A specially crafted container image can trigger the vulnerability when the container is created, causing memory to be consumed until the containerd process runs out of memory and is killed by the operating system. This knocks the container runtime offline, breaking both container orchestration and any applications depending on it. The flaw affects containerd versions before 1.7.33, 2.0.10, 2.1.9, 2.2.5, and 2.3.2.
- CVE-2026-47326MEDIUM 5.5
Ubuntu Linux versions 6.8, 6.17, and 7.0 contain a memory leak flaw in how the kernel handles large responses from AppArmor (the mandatory access control framework). An unprivileged local user can trigger this leak repeatedly, causing the system to exhaust available memory and potentially become unstable or unresponsive. The vulnerability requires local access and does not compromise data confidentiality or integrity, but can degrade or deny service to legitimate users.
- CVE-2026-47332MEDIUM 5.5
Ubuntu Linux versions 6.8, 6.17, and 7.0 contain a flaw in their AppArmor security module patches that allows unprivileged local users to read sensitive data from kernel memory. The vulnerability stems from incorrect validation of an internal data structure size during notification processing. An attacker with local user privileges can exploit this to leak information from adjacent memory regions (kernel slab objects), potentially exposing cryptographic keys, session tokens, or other sensitive kernel data.
- CVE-2026-47334MEDIUM 5.5
Ubuntu Linux kernels 6.8, 6.17, and 7.0 contain a bug in AppArmor notification handling code that can be triggered by any unprivileged local user to crash the kernel or cause it to hang. The issue stems from code that incorrectly sleeps while holding a spinlock—a low-level synchronization primitive—creating a condition where the system becomes unresponsive or fails entirely. An attacker with basic local access can reliably exploit this without special privileges or user interaction.
- CVE-2026-47335MEDIUM 5.5
Ubuntu Linux kernel version 6.8 contains a defect in how it handles AppArmor security notifications. An unprivileged local user can trigger a NULL pointer dereference—a programming error where the kernel tries to access memory that doesn't exist—causing the entire system to crash. This is a local denial-of-service vulnerability; it does not allow data theft or privilege escalation, but it can disrupt service availability.
- CVE-2026-47748MEDIUM 5.5
A flaw in stable-diffusion.cpp allows attackers to crash applications or potentially read sensitive memory by providing a malformed or intentionally truncated model checkpoint (.ckpt) file. The vulnerability exists in how the library parses PyTorch checkpoint files—it fails to validate that sufficient data remains before reading, so a crafted file can cause the parser to read past the end of its buffer. An attacker would need to trick a user or application into loading a malicious .ckpt file, typically from an untrusted model repository. The practical risk is limited to environments that load external model files, but the impact on those systems can be significant.
- CVE-2026-47770MEDIUM 5.5
jq, a widely-used command-line tool for processing and querying JSON data, contains a denial-of-service vulnerability in versions before 1.8.2. When comparing two deeply nested JSON arrays using the == operator, jq crashes due to stack exhaustion. An attacker can trigger this crash by supplying specially crafted nested JSON structures, either directly via command-line input or through embedded jq usage in applications. The crash leaves no data corruption or security breach—just service unavailability. This is a local or user-interaction vulnerability, not remotely exploitable on its own, but it can disrupt any workflow or service relying on jq to process untrusted JSON.
- CVE-2026-47923MEDIUM 5.5
Adobe Acrobat Reader contains a flaw that allows an attacker to read sensitive data from a user's computer memory by tricking them into opening a specially crafted file. The vulnerability doesn't damage files or prevent the application from running, but it could expose confidential information like passwords, encryption keys, or personal data that happens to be in memory at the time of exploitation. Versions 24.001.30365, 26.001.21651 and earlier on Windows and macOS are affected.
- CVE-2026-47924MEDIUM 5.5
Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain a use-after-free memory flaw that could allow an attacker to read sensitive data from the application's memory. The vulnerability requires a user to open a crafted malicious PDF or document file, making this a low-friction attack that relies on social engineering rather than complex exploitation techniques. While memory disclosure alone does not enable direct system compromise, the leaked information could include credentials, encryption keys, or other confidential content.
- CVE-2026-47925MEDIUM 5.5
Adobe Acrobat Reader contains an integer overflow flaw that crashes the application when a user opens a specially crafted file. While this is a denial-of-service issue rather than a data breach or code execution vulnerability, it can disrupt business workflows. The flaw affects Acrobat Reader DC versions 24.001.30365, 26.001.21651 and earlier across Windows and macOS. An attacker must trick a user into opening a malicious PDF or document to trigger the crash.
- CVE-2026-47926MEDIUM 5.5
Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain a memory reading flaw that allows attackers to extract sensitive information from your system. The vulnerability requires a user to open a specially crafted malicious file, making social engineering a necessary component of any attack. While the flaw cannot be used to modify files or crash the application, the potential for exposing confidential data—such as encryption keys, credentials, or personal information resident in memory—presents a meaningful risk to organizations handling sensitive documents.
- CVE-2026-47927MEDIUM 5.5
Adobe's DNG SDK, a toolkit for processing Digital Negative image files, contains a flaw that allows an attacker to read sensitive data from a victim's computer memory. When a user opens a specially crafted malicious DNG image file, the SDK attempts to read data from memory regions it shouldn't access, potentially exposing passwords, encryption keys, or other confidential information. An attacker must trick a user into opening the malicious file—the vulnerability cannot be exploited remotely or automatically.
- CVE-2026-47934MEDIUM 5.5
Adobe's DNG SDK, a widely-used library for processing Digital Negative image files, contains a memory reading flaw that could expose sensitive data. When a user opens a specially crafted DNG image file, the SDK reads memory it shouldn't access, potentially leaking information like encryption keys, passwords, or other confidential data stored in application memory. The vulnerability requires user interaction—an attacker must trick someone into opening a malicious file—which limits its reach but doesn't eliminate the risk for targeted scenarios.
- CVE-2026-47961MEDIUM 5.5
Adobe Acrobat Reader contains an out-of-bounds read flaw that allows attackers to extract sensitive data from system memory. The vulnerability requires user interaction—specifically, opening a malicious PDF or document file. When triggered, the flaw exposes unintended memory contents that could include confidential information resident in the application's process space.
- CVE-2026-47963MEDIUM 5.5
Adobe's DNG SDK—a tool developers use to handle DNG (Digital Negative) image files—contains a flaw that lets attackers read private information from a computer's memory. The vulnerability exists in DNG SDK version 1.7.1 build 2536 and earlier. An attacker would need to trick a user into opening a specially crafted malicious file to trigger the leak. While the memory exposure is significant, the attack requires user action, which limits its immediate reach.
- CVE-2026-48155MEDIUM 5.5
pypdf, a popular open-source PDF processing library, contains a denial-of-service vulnerability affecting versions prior to 6.12.0. An attacker can craft a malicious PDF file that, when processed by pypdf's text extraction feature in layout mode, triggers excessive memory consumption. This occurs specifically when the PDF contains large character offsets. The flaw does not compromise data confidentiality or integrity, but can render systems unresponsive or crash applications that depend on pypdf for PDF handling.
- CVE-2026-48267MEDIUM 5.5
Adobe DNG SDK versions 1.7.1 (build 2536) and earlier contain a flaw that can crash applications using the library when a user opens a specially crafted file. An attacker would need to trick a user into opening a malicious file—there's no remote exploitation vector. The result is a denial-of-service condition; the attacker cannot steal data or gain code execution.
- CVE-2026-48493MEDIUM 5.5
Snipe-IT is an asset management platform used by IT teams to track hardware, software licenses, and inventory. A flaw in versions before 8.6.0 allows a basic user who can only edit their own profile to escalate their own privileges. By sending a specially crafted request to their account settings, they can grant themselves broader permissions—such as the ability to view or create assets, access reports, or perform imports—without needing administrator approval. While admin and superuser roles remain protected, this self-service privilege escalation undermines access controls and could let a low-privilege insider gain visibility into sensitive IT operations data or make unauthorized asset changes.
- CVE-2026-48566MEDIUM 5.5
CVE-2026-48566 is a memory-reading flaw in Windows Desktop Window Manager (DWM) Core Library that allows a logged-in user to read sensitive information from memory that they should not have access to. An attacker with a local user account can exploit this to leak confidential data—such as encryption keys, authentication tokens, or other protected information—without crashing the system or modifying files. The vulnerability requires the attacker to already have an account on the machine; it cannot be exploited remotely.
- CVE-2026-48724MEDIUM 5.5
ImageMagick versions before 7.1.2-24 contain a memory corruption flaw triggered when processing images that use a mask combined with the Floyd-Steinberg dithering algorithm. The vulnerability allows an attacker to overwrite heap memory in negative offsets, potentially causing the application to crash. An attacker would need to trick a user into opening a specially crafted image file, making this a local attack that depends on user interaction.
- CVE-2026-48734MEDIUM 5.5
ImageMagick, a widely-used open-source image manipulation tool, contains a stack overflow vulnerability when processing specially crafted MVG (Magick Vector Graphics) files. An attacker can create a malicious MVG file that, when opened by a user in ImageMagick, causes the application to crash or become unresponsive. This occurs because the software fails to properly limit recursion depth or track which parts of the file it has already processed, allowing unbounded stack consumption. The vulnerability requires user interaction—someone must explicitly open the malicious file—but no special privileges are needed.