Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56534
Total
4478
Critical
16763
High
16605
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-90193 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler qcom_cpucp_mbox_irq_fn() calls mbox_chan_received_data() while holding chan->lock. Under … | Sep 17, 2026 |
| CVE-2026-90192 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mailbox: qcom-cpucp: handle NULL data in send_data callback mailbox_clear_channel() calls mbox_send_message() with NULL data to … | Sep 17, 2026 |
| CVE-2026-90191 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mailbox: riscv-sbi-mpxy: validate RPMI notification lengths The SBI return value controls how many bytes are … | Sep 17, 2026 |
| CVE-2026-90190 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: null_blk: use DEFINE_MUTEX for the file-scope mutex In null_init(), mutex_init(&lock) currently happens after configfs_register_subsystem(), which … | Sep 17, 2026 |
| CVE-2026-90189 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: null_blk: register configfs subsystem after creating default devices In null_init(), configfs_register_subsystem() currently runs before register_blkdev(), … | Sep 17, 2026 |
| CVE-2026-90188 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: null_blk: free global tag_set on init error path If shared_tags is enabled, null_setup_tagset() allocates the … | Sep 17, 2026 |
| CVE-2026-90187 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: null_blk: free zones array on device power-off null_init_zoned_dev() allocates dev->zones when a zoned device is … | Sep 17, 2026 |
| CVE-2026-90186 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: null_blk: reject per-device queue resize for shared tag set When shared_tags is enabled, null_setup_tagset() makes … | Sep 17, 2026 |
| CVE-2026-90185 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: null_blk: serialize configfs attribute stores with the lock The NULLB_DEVICE_ATTR _store takes no lock: apply_fn … | Sep 17, 2026 |
| CVE-2026-90184 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: null_blk: serialize configfs attribute updates with device setup The attribute store methods generated with NULLB_DEVICE_ATTR() … | Sep 17, 2026 |
| CVE-2026-90183 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: blk-iolatency: clear delay state when freeing policy data io.latency can throttle a group which has … | Sep 17, 2026 |
| CVE-2026-90182 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: blk-iocost: clear delay state when freeing policy data iocg_kick_delay() turns sufficiently large debt into an … | Sep 17, 2026 |
| CVE-2026-90181 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ublk: avoid teardown retry loop on xarray allocation failure __ublk_shmem_remove_ranges() removes matching maple tree ranges … | Sep 17, 2026 |
| CVE-2026-90180 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: block: mtip32xx: synchronize ioctls with device removal The ioctl handlers only test REMOVE_PENDING before entering … | Sep 17, 2026 |
| CVE-2026-90179 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix deadlock in complain-mode change_hat The use of change_hat when in complain mode can … | Sep 17, 2026 |
| CVE-2026-90178 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix core_data leak on CPUs without PTS pdata->core_data is allocated in init_temp_data() when … | Sep 17, 2026 |
| CVE-2026-90177 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Check pointer type for all atomic RMW paths Atomic RMW verification records an instruction … | Sep 17, 2026 |
| CVE-2026-90176 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: Do not skip lock checks for single-byte ranges check_lock_range() uses inclusive ranges. Its callers … | Sep 17, 2026 |
| CVE-2026-90175 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer Free it unconditionally after ksmbd_alloc_user() calls. kmemleak … | Sep 17, 2026 |
| CVE-2026-90174 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user() ksmbd_alloc_user() copies resp->hash_sz bytes out of the mountd IPC … | Sep 17, 2026 |
| CVE-2026-90173 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: free completion queues with ib_free_cq() smbdirect_connection_destroy_qp() creates the send and receive completion queues … | Sep 17, 2026 |
| CVE-2026-90172 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: destroy QP before mem pools on accept failure On the rdma_accept_failed error path … | Sep 17, 2026 |
| CVE-2026-90171 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: release pending child sockets outside the handler lock smbdirect_socket_destroy() releases the listener's pending/ready … | Sep 17, 2026 |
| CVE-2026-90170 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ipc response length before dereferencing its fields ipc_validate_msg() computes the expected message size … | Sep 17, 2026 |
| CVE-2026-90169 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: free preauth sessions on connection teardown SMB3.1.1 multichannel binding preserves the preauthentication hash in … | Sep 17, 2026 |