Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56890
Total
4508
Critical
16896
High
16708
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-90048 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() ni_create_attr_list() allocates a fixed buffer of al_aligned(record_size) (== record_size) … | Sep 16, 2026 |
| CVE-2026-90047 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't hand out the flat CCS storage as usable VRAM get_flat_ccs_offset() reads the base … | Sep 16, 2026 |
| CVE-2026-90046 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP". … | Sep 16, 2026 |
| CVE-2026-90045 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifetime handling io_data stores a pointer to the submitting task's … | Sep 16, 2026 |
| CVE-2026-90044 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix Use-After-Free in AIO error path In ffs_epfile_write_iter() and ffs_epfile_read_iter(), when ffs_epfile_io() … | Sep 16, 2026 |
| CVE-2026-90043 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: zram: fix slot lock bit position on big-endian 64-bit The slot lock is a bit … | Sep 16, 2026 |
| CVE-2026-90042 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ceph: properly decrypt filenames in vmalloc() buffers The fscrypt subsystem uses the scatterlist crypto API, … | Sep 16, 2026 |
| CVE-2026-90041 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: HID: sony: clean up device list on probe failure sony_input_configured() adds some controllers to sony_device_list … | Sep 16, 2026 |
| CVE-2026-90040 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped Wire up … | Sep 16, 2026 |
| CVE-2026-90039 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: NFSD: Guard admin state-revocation walks with NFSD_NET_UP Writing to /proc/fs/nfsd/unlock_filesystem, or sending the NFSD_CMD_UNLOCK_FILESYSTEM or … | Sep 16, 2026 |
| CVE-2026-90038 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during export state revocation nfsd4_revoke_export_states() has the same use-after-free as nfsd4_revoke_states(): … | Sep 16, 2026 |
| CVE-2026-90037 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during close_lru reaping An nfs4_openowner left on nn->close_lru after its final … | Sep 16, 2026 |
| CVE-2026-90036 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during blocked-lock reaping A bare lock owner -- its only remaining … | Sep 16, 2026 |
| CVE-2026-90035 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix division by zero in get_estimated_bw() get_estimated_bw() divides by link->dpia_bw_alloc_config.bw_granularity, which is zeroed by … | Sep 16, 2026 |
| CVE-2026-90034 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: image: mdc800: change kmalloc() to kzalloc() Change the kmalloc() calls in usb_mdc800_init() for irq_urb_buffer … | Sep 16, 2026 |
| CVE-2026-90033 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() The snd_usbmidi_us122l_output() picks a count of 2 on … | Sep 16, 2026 |
| CVE-2026-90032 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: usbtv: keep device alive while ALSA card exists The ALSA PCM callbacks store the … | Sep 16, 2026 |
| CVE-2026-90031 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb-storage: ene_ub6250: fix race between scan work and probe ene_ub6250_probe() calls usb_stor_probe2(), which starts the … | Sep 16, 2026 |
| CVE-2026-90030 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: clear forceRM when issuing EndTransfer The forceRM bit of the DEPCMD register controls … | Sep 16, 2026 |
| CVE-2026-90029 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: storage: realtek_cr: fix use-after-free on disconnect realtek_cr_destructor() calls timer_delete() before the chip containing the … | Sep 16, 2026 |
| CVE-2026-90028 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: typec: hd3ss3220: track VBUS enable state per consumer regulator_is_enabled() reports the aggregate regulator state, … | Sep 16, 2026 |
| CVE-2026-90027 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop cc_debounce_dwork is queued from the set_cc() and start_toggling() … | Sep 16, 2026 |
| CVE-2026-90026 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic: cancel reset_work on stop pdphy_stop() disables IRQs but leaves reset_work pending. If … | Sep 16, 2026 |
| CVE-2026-90025 | HIGH | 7.7 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix OOB altmode array index The UCSI displayport driver indexes the … | Sep 16, 2026 |
| CVE-2026-90024 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs A null-pointer dereference occurs in f_midi2_free_ep_reqs() when … | Sep 16, 2026 |