Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54499
Total
4309
Critical
16193
High
15930
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97995 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: virtio_console: do not free control-out buffers on remove __send_control_msg() publishes &portdev->cpkt as the control-out virtqueue … | Sep 25, 2026 |
| CVE-2026-97994 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: vhost/vdpa: reject VRING_NUM larger than device max vhost_vring_set_num() accepts any non-zero power-of-two queue size that … | Sep 25, 2026 |
| CVE-2026-97993 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value into … | Sep 25, 2026 |
| CVE-2026-97992 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: protect config_ctx from being freed under the config callback vhost_vdpa_config_cb() loads v->config_ctx and signals … | Sep 25, 2026 |
| CVE-2026-97991 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: vdpa_sim_blk: reject out-of-range sector starts vdpasim_blk_check_range() logs an invalid start sector but continues validating the … | Sep 25, 2026 |
| CVE-2026-97990 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: vdpa_sim_net: check TX pull result before RX copy vringh_iov_pull_iotlb() returns a signed byte count. A … | Sep 25, 2026 |
| CVE-2026-97989 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: vduse: validate virtqueue alignment vduse_validate_config() only checks the upper bound of vq_align. Invalid values can … | Sep 25, 2026 |
| CVE-2026-97988 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: vhost: invalidate vring access on IOTLB transitions When VIRTIO_F_ACCESS_PLATFORM changes, cached vring pointers and IOTLB … | Sep 25, 2026 |
| CVE-2026-97987 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: virtio_input: reset device if input_register_device() fails Probe marks the device DRIVER_OK with virtio_device_ready() before calling … | Sep 25, 2026 |
| CVE-2026-97986 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: virtio_input: stop callbacks before unregistering input device virtinput_remove() unregisters the input device before resetting the … | Sep 25, 2026 |
| CVE-2026-97985 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: af_unix: Update last skb marker in manage_oob(). Fahad Alharbi reported that blocking recv(MSG_PEEK) could hog … | Sep 25, 2026 |
| CVE-2026-97984 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: ipv6: Fix UDP length overflow with PMTU discover and big MTU This commit bounds … | Sep 25, 2026 |
| CVE-2026-97983 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: vduse: return compat ioctl results directly The compat handler handles VDUSE_IOTLB_GET_FD and VDUSE_VQ_GET_INFO, but then … | Sep 25, 2026 |
| CVE-2026-97982 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Fix budget accounting The gmac_rx() function returns the remaining NAPI budget, but … | Sep 25, 2026 |
| CVE-2026-97981 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Count dropped frames as NAPI work The RX loop only consumes budget … | Sep 25, 2026 |
| CVE-2026-97980 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: s390/debug: Fix NULL pointer dereference in debug_set_level() Commit a2cec6863709 ("s390/debug: Add s390dbf kernel parameter") incorrectly … | Sep 25, 2026 |
| CVE-2026-97979 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ice: add missing xa_destroy for sched_node_ids Commit 16dfa49406bc ("ice: Introduce new parameters in ice_sched_node") added … | Sep 25, 2026 |
| CVE-2026-97978 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: eth: ice: don't dereference pointers from TP_printk() After forwarding net-next during the v7.3 merge window … | Sep 25, 2026 |
| CVE-2026-97977 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: Fix UAF of btusb_data by rx_work btusb_close() and btusb_flush() cancel data->rx_work with the … | Sep 25, 2026 |
| CVE-2026-97976 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: validate packet_len before skb_put_data btintel_pcie_submit_rx_work() reads packet_len from rfh_hdr without checking if it … | Sep 25, 2026 |
| CVE-2026-97975 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() A NULL pointer dereference in klist_put() occurs … | Sep 25, 2026 |
| CVE-2026-97974 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings() syzbot reported a null-ptr-deref in __ip6_del_rt_siblings() [0]. The … | Sep 25, 2026 |
| CVE-2026-97973 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: macb: destroy the phylink instance on the probe error path macb_mii_init() creates a phylink … | Sep 25, 2026 |
| CVE-2026-97972 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: macb: put the "mdio" child node reference on success macb_mii_init() holds the reference returned … | Sep 25, 2026 |
| CVE-2026-97971 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: nstree: check listing permission before taking a namespace reference legitimize_ns() takes a reference on the … | Sep 25, 2026 |