Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56534
Total
4478
Critical
16763
High
16605
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-90168 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: retain connection for pending notify work Deferred CHANGE_NOTIFY work keeps an async message ID … | Sep 17, 2026 |
| CVE-2026-90167 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize oplock close with pending break ownership close may abort an in-flight oplock break … | Sep 17, 2026 |
| CVE-2026-90166 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request() See the procedure below: ksmbd_tree_conn_connect ksmbd_share_config_get share->name = kstrdup() // … | Sep 17, 2026 |
| CVE-2026-90165 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger() See the procedure below: ksmbd_launch_ksmbd_durable_scavenger durable_scavenger_running = true … | Sep 17, 2026 |
| CVE-2026-90164 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb/server: abort initialization when proc setup fails ksmbd_server_init() calls ksmbd_proc_init() before creating the remaining proc … | Sep 17, 2026 |
| CVE-2026-90163 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_proc_cleanup() on module init failure When a later initializer fails, the unwind chain … | Sep 17, 2026 |
| CVE-2026-90162 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: defer publishing granted locks to prevent UAF/double-free race In smb2_lock(), mid-batch granted locks are … | Sep 17, 2026 |
| CVE-2026-90161 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: erofs: fix interlaced ztailpacking pclusters On-disk sizes of interlaced pclusters should be block-aligned, and ztailpacking … | Sep 17, 2026 |
| CVE-2026-90160 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: lwt_bpf: Restore reserved headroom after xmit program ip_finish_output2() expands an skb to LL_RESERVED_SPACE(dev) before LWT … | Sep 17, 2026 |
| CVE-2026-90159 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks _bpf_setsockopt() and _bpf_getsockopt() call sock_owned_by_me() for full … | Sep 17, 2026 |
| CVE-2026-90158 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in nfcon_device() Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for … | Sep 17, 2026 |
| CVE-2026-90157 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative optlen in cgroup getsockopt hook A cgroup getsockopt BPF program can shrink … | Sep 17, 2026 |
| CVE-2026-90156 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely discard unregistered deferred locks When vfs_lock_file() defers a lock, smb2_lock() puts its ksmbd_lock … | Sep 17, 2026 |
| CVE-2026-90155 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: detach blocked lock requests before freeing A file_lock retained by ksmbd for byte-range lock … | Sep 17, 2026 |
| CVE-2026-90154 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope session state changes to bound connections ksmbd_all_conn_set_status() treats every connection whose transient binding … | Sep 17, 2026 |
| CVE-2026-90153 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size smb_check_perm_dacl() validates that the DACL fits inside … | Sep 17, 2026 |
| CVE-2026-90152 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_register() See the procedure below: smb2_sess_setup ksmbd_smb2_session_create __session_create atomic_set(&sess->refcnt, 2) … | Sep 17, 2026 |
| CVE-2026-90151 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocation failure nfs4_alloc_client() allocates an NFSv4.0 callback identifier … | Sep 17, 2026 |
| CVE-2026-90150 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: pnfs/blocklayout: Fix device leaks on parse failure bl_parse_concat() and bl_parse_stripe() allocate a child device array … | Sep 17, 2026 |
| CVE-2026-90149 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers flexfiles accepts NFSv4.0 data servers, but two … | Sep 17, 2026 |
| CVE-2026-90148 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease() When nfs4_add_lease() races with a delegation … | Sep 17, 2026 |
| CVE-2026-90147 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() devm_clk_get_optional_enabled_with_rate() registers its cleanup action before setting the clock … | Sep 17, 2026 |
| CVE-2026-90146 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf, xdp: move offload check into dev_xdp_install() bpf_xdp_link_update() calls dev_xdp_install() directly and skips dev_xdp_attach(), so … | Sep 17, 2026 |
| CVE-2026-90145 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed Previously, hinic3_send_one_skb() cached the … | Sep 17, 2026 |
| CVE-2026-90144 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: dpll: fix NULL deref in dpll_device_ops() during teardown race When the last owner of a … | Sep 17, 2026 |