Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56334
Total
4455
Critical
16700
High
16518
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92483 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: liveupdate: Remember FLB retrieve() status LUO keeps track of successful retrieve attempts on an FLB. … | Sep 17, 2026 |
| CVE-2026-92482 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip The gpio_chip is allocated with device-managed memory but … | Sep 17, 2026 |
| CVE-2026-92481 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: free EINT resources on unbind mtk_eint_do_init() creates an IRQ domain, populates it with … | Sep 17, 2026 |
| CVE-2026-92480 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate string descriptors The string descriptor length includes a two-byte header while … | Sep 17, 2026 |
| CVE-2026-92479 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags The single-doorbell completion path can … | Sep 17, 2026 |
| CVE-2026-92478 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate connected lane counts The connected lane count is used by TX … | Sep 17, 2026 |
| CVE-2026-92477 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: debugfs: Reserve space for a string terminator ufs_saved_err_write() copies user input into a … | Sep 17, 2026 |
| CVE-2026-92476 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Initialize completion before requesting IRQ kmb_ocs_aes_probe() requests the device IRQ before initializing … | Sep 17, 2026 |
| CVE-2026-90435 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix integer overflow of user QP buffer size set_user_buf_size() computes the QP buffer size … | Sep 17, 2026 |
| CVE-2026-90434 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: isofs: release zisofs block pointer buffer head zisofs_fill_pages() reads the compressed block pointer table. The … | Sep 17, 2026 |
| CVE-2026-90433 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: spi: oc-tiny: switch to managed controller allocation The controller is allocated with the non-managed spi_alloc_host() … | Sep 17, 2026 |
| CVE-2026-90432 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Abort directly from the hardlockup handler scx_hardlockup() defers the abort to an irq_work because … | Sep 17, 2026 |
| CVE-2026-90431 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: remoteproc: Prevent crash handling to race with rproc_del() There's no synchronization between rproc_crash_handler_work() and rproc_del(), … | Sep 17, 2026 |
| CVE-2026-90430 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized tegra241_vintf_init_lvcmdq() stores the freshly allocated … | Sep 17, 2026 |
| CVE-2026-90429 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init A user VINTF is torn down by … | Sep 17, 2026 |
| CVE-2026-90428 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs __tegra241_cmdqv_probe() requests the error … | Sep 17, 2026 |
| CVE-2026-90427 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() __tegra241_cmdqv_probe() uses devm_krealloc() to grow … | Sep 17, 2026 |
| CVE-2026-90426 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs tegra241_cmdqv_remove() tears each VINTF down first, … | Sep 17, 2026 |
| CVE-2026-90425 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID tegra241_vintf_init_vsid() maps a guest vSID to … | Sep 17, 2026 |
| CVE-2026-90424 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path tegra241_cmdqv_init_structures() allocates VINTF0 with kzalloc_obj(), inits it, … | Sep 17, 2026 |
| CVE-2026-90423 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix UAF in ODP init error-handling path rxe_odp_mr_init_user() stores &umem_odp->umem in mr->umem before calling … | Sep 17, 2026 |
| CVE-2026-90422 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path When mtk_clk_register_pllfhs function fails … | Sep 17, 2026 |
| CVE-2026-90421 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: PCI: Fix UAF when probe runs concurrent to dyn ID removal Dynamic IDs are only … | Sep 17, 2026 |
| CVE-2026-90420 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix infinite loop in nilfs_clean_segments() syzbot reported a hung task in nilfs_transaction_begin(). This occurs … | Sep 17, 2026 |
| CVE-2026-90419 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent out-of-bounds read in super root block parsing super-root inode metadata size is trusted … | Sep 17, 2026 |