Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54499
Total
4309
Critical
16193
High
15930
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97920 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tracing: Keep the entry count when the histogram stats allocation fails print_entries() uses n_entries both … | Sep 25, 2026 |
| CVE-2026-97919 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tracing: Take the reference before publishing the named histogram trigger event_hist_trigger_named_init() puts the trigger on … | Sep 25, 2026 |
| CVE-2026-97918 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tracing: Undo the registration when enabling the histogram trigger fails Commit 6f86bdeab633 ("tracing: Fix bad … | Sep 25, 2026 |
| CVE-2026-97917 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr Add a size parameter to ivpu_to_cpu_addr() and validate … | Sep 25, 2026 |
| CVE-2026-97916 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Validate firmware log buffer metadata The tracing log headers parsed by fw_log_print_buffer() reside in … | Sep 25, 2026 |
| CVE-2026-97915 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Limit firmware log name prints to field size The name in struct vpu_tracing_buffer_header is … | Sep 25, 2026 |
| CVE-2026-97914 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Fix ethosu_job_open() return value A WARN_ON() returns a 0 or 1, not the … | Sep 25, 2026 |
| CVE-2026-97913 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure cmd stream ends with a stop op While the QSIZE register setting … | Sep 25, 2026 |
| CVE-2026-97912 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure SRAM size is 0 on mapping failure On a mapping failure of … | Sep 25, 2026 |
| CVE-2026-97911 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure SRAM region size matches job It is possible for userspace to set … | Sep 25, 2026 |
| CVE-2026-97910 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: ASoC: sprd: validate compress buffer sizes against fixed allocations sprd_platform_compr_open() allocates the stage 0 IRAM … | Sep 25, 2026 |
| CVE-2026-97909 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: sti: initialize IRQ lock before requesting IRQ uni_reader_init() registers the shared IRQ before initializing … | Sep 25, 2026 |
| CVE-2026-97908 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev The command and ACL RPMsg endpoints store … | Sep 25, 2026 |
| CVE-2026-97907 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 When key_id from chip … | Sep 25, 2026 |
| CVE-2026-97906 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bootconfig: Fix integer overflow in initrd size check Sashiko reported that in get_boot_config_from_initrd(), a crafted … | Sep 25, 2026 |
| CVE-2026-97905 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: cpufreq: zero-initialize policy cpumask before sysfs publication cpufreq_policy_alloc() allocates policy->cpus with alloc_cpumask_var(), i.e. without __GFP_ZERO, … | Sep 25, 2026 |
| CVE-2026-97904 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: cpufreq: initialize policy rwsem before sysfs publication cpufreq_policy_alloc() initializes policy->rwsem after kobject_init_and_add() has created the … | Sep 25, 2026 |
| CVE-2026-97903 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: exit: hold a reference to thread_pid across proc_flush_pid Commit 0a36bad01731 ("release_task: kill the no longer … | Sep 25, 2026 |
| CVE-2026-97902 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fs: don't return -EINVAL for successful nested thaw Commit 7366f8b6fc6a ("fs: handle freezing from multiple … | Sep 25, 2026 |
| CVE-2026-97901 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: genetlink: pin family module during policy dump The generic netlink controller's policy dump keeps pointers … | Sep 25, 2026 |
| CVE-2026-97900 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/drm_exec: fix up contended obj when num_objects is 0 drm_exec_prepare_array() silently returns success without calling … | Sep 25, 2026 |
| CVE-2026-97899 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix memory leak in query_perf_config_list() When krealloc() fails, free the original oa_config_ids before returning … | Sep 25, 2026 |
| CVE-2026-97875 | HIGH | 8.1 | Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all … | Sep 25, 2026 |
| CVE-2026-97621 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: analogix_dp: fix unchecked bound endpoint name length rockchip_dp_drm_encoder_enable() uses sprintf() to format a device … | Sep 25, 2026 |
| CVE-2026-97620 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches emit_render_cache_flush() sets PIPE_CONTROL0_HDC_PIPELINE_FLUSH to flush … | Sep 25, 2026 |