Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56576
Total
4483
Critical
16766
High
16609
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-90160 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: lwt_bpf: Restore reserved headroom after xmit program ip_finish_output2() expands an skb to LL_RESERVED_SPACE(dev) before LWT … | Sep 17, 2026 |
| CVE-2026-90159 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks _bpf_setsockopt() and _bpf_getsockopt() call sock_owned_by_me() for full … | Sep 17, 2026 |
| CVE-2026-90158 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in nfcon_device() Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for … | Sep 17, 2026 |
| CVE-2026-90157 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative optlen in cgroup getsockopt hook A cgroup getsockopt BPF program can shrink … | Sep 17, 2026 |
| CVE-2026-90156 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely discard unregistered deferred locks When vfs_lock_file() defers a lock, smb2_lock() puts its ksmbd_lock … | Sep 17, 2026 |
| CVE-2026-90155 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: detach blocked lock requests before freeing A file_lock retained by ksmbd for byte-range lock … | Sep 17, 2026 |
| CVE-2026-90154 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope session state changes to bound connections ksmbd_all_conn_set_status() treats every connection whose transient binding … | Sep 17, 2026 |
| CVE-2026-90153 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size smb_check_perm_dacl() validates that the DACL fits inside … | Sep 17, 2026 |
| CVE-2026-90152 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_register() See the procedure below: smb2_sess_setup ksmbd_smb2_session_create __session_create atomic_set(&sess->refcnt, 2) … | Sep 17, 2026 |
| CVE-2026-90151 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocation failure nfs4_alloc_client() allocates an NFSv4.0 callback identifier … | Sep 17, 2026 |
| CVE-2026-90150 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: pnfs/blocklayout: Fix device leaks on parse failure bl_parse_concat() and bl_parse_stripe() allocate a child device array … | Sep 17, 2026 |
| CVE-2026-90149 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers flexfiles accepts NFSv4.0 data servers, but two … | Sep 17, 2026 |
| CVE-2026-90148 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease() When nfs4_add_lease() races with a delegation … | Sep 17, 2026 |
| CVE-2026-90147 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() devm_clk_get_optional_enabled_with_rate() registers its cleanup action before setting the clock … | Sep 17, 2026 |
| CVE-2026-90146 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf, xdp: move offload check into dev_xdp_install() bpf_xdp_link_update() calls dev_xdp_install() directly and skips dev_xdp_attach(), so … | Sep 17, 2026 |
| CVE-2026-90145 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed Previously, hinic3_send_one_skb() cached the … | Sep 17, 2026 |
| CVE-2026-90144 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: dpll: fix NULL deref in dpll_device_ops() during teardown race When the last owner of a … | Sep 17, 2026 |
| CVE-2026-90143 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF parser kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which prevents … | Sep 17, 2026 |
| CVE-2026-90142 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix resize of the RX ring When a AF_XDP socket is attached, the virtnet_rx_resize … | Sep 17, 2026 |
| CVE-2026-90141 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ipvs: fix integer overflow in ftp helper port/address parsing ip_vs_ftp_get_addrport() accumulates decimal digits into a … | Sep 17, 2026 |
| CVE-2026-90140 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: cuse: wait for pending RCU callbacks on module exit Since commit 053fc4f755ad ("fuse: fix UAF … | Sep 17, 2026 |
| CVE-2026-90139 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fuse: check for NULL root inode in fuse_fill_super_submount fuse_iget() can return NULL when its inode … | Sep 17, 2026 |
| CVE-2026-90138 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: vsock: don't check the listener's sk_err in vsock_accept() Syzbot reported an issue which can be … | Sep 17, 2026 |
| CVE-2026-90137 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix password encoding bounds check The password PSWD_ENCODINGS parser reads password_obj[elem + pos_values] … | Sep 17, 2026 |
| CVE-2026-90136 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/hsmp: Reject negative power cap writes in hwmon hsmp_hwmon_write() takes the user-supplied hwmon value as … | Sep 17, 2026 |