Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56890
Total
4508
Critical
16896
High
16708
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-89974 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails nvmf_create_ctrl() owns the fabrics options … | Sep 16, 2026 |
| CVE-2026-89973 | HIGH | 8.2 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: check the data direction of a C2HData PDU nvme_tcp_handle_c2h_data() finds the request by command … | Sep 16, 2026 |
| CVE-2026-89972 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path nvme_alloc_ns() error path at out_unlink_ns removes … | Sep 16, 2026 |
| CVE-2026-89971 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nvme: skip the zoned limits update if the zone info query failed nvme_query_zone_info() returns either … | Sep 16, 2026 |
| CVE-2026-89970 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ teardown nvmet_auth_sq_free() cancels auth_expired_work with cancel_delayed_work(). If the work … | Sep 16, 2026 |
| CVE-2026-89969 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU nvmet_tcp_try_recv_pdu() reads a PDU header into … | Sep 16, 2026 |
| CVE-2026-89968 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: reject unsolicited H2CData PDUs nvmet_tcp_handle_h2c_data_pdu() accepts an H2CData PDU after only checking that its … | Sep 16, 2026 |
| CVE-2026-89967 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: avoid out-of-bounds writes for compound folios migrate_device_range() and migrate_device_pfns() clear the entries following a … | Sep 16, 2026 |
| CVE-2026-89966 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio alloc_buddy_hugetlb_folio_with_mpol() can pass a NULL nodemask to alloc_fresh_hugetlb_folio() … | Sep 16, 2026 |
| CVE-2026-89965 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: reject an arena whose nfree is below the lane count The BTT info block's … | Sep 16, 2026 |
| CVE-2026-89964 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: parisc: eisa: Fix infinite loop when parsing invalid IRQ value When an invalid value is … | Sep 16, 2026 |
| CVE-2026-89963 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec_file: Fix null-ptr-def in extra size calculation A static Sashiko AI review identified a potential … | Sep 16, 2026 |
| CVE-2026-89962 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec_file: Prevent kexec range truncation Sashiko AI review pointed out the following issue. The __merge_memory_ranges() … | Sep 16, 2026 |
| CVE-2026-89961 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population vmemmap_populate_compound_pages() uses addr_pfn to determine the … | Sep 16, 2026 |
| CVE-2026-89960 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm() In vfio_ap_mdev_set_kvm(), kvm->arch.crypto.pqap_hook is set to … | Sep 16, 2026 |
| CVE-2026-89959 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove The vfio_ap_config_remove function uses the bitmap_andnot function to … | Sep 16, 2026 |
| CVE-2026-89958 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL The ap_driver structure has two fields which … | Sep 16, 2026 |
| CVE-2026-89957 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed The vfio_ap_mdev_hot_unplug_cfg() function uses … | Sep 16, 2026 |
| CVE-2026-89956 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects In order to traverse … | Sep 16, 2026 |
| CVE-2026-89955 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix NULL deref in status_show() during queue probe When vfio_ap_mdev_probe_queue() creates the sysfs attribute … | Sep 16, 2026 |
| CVE-2026-89954 | HIGH | 8.0 | In the Linux kernel, the following vulnerability has been resolved: mtd: afs: validate v2 image info bounds The AFS v2 parser uses footer[8] to locate … | Sep 16, 2026 |
| CVE-2026-89953 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mtd: mtdoops: free page bitmap when the backing MTD is removed mtdoops_notify_add() allocates oops_page_used when … | Sep 16, 2026 |
| CVE-2026-89952 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: validate ONFI extended parameter page sections nand_flash_detect_ext_param_page() allocates the length declared by the … | Sep 16, 2026 |
| CVE-2026-89951 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix stale receive device on merged fragments Fragment reassembly reuses the skb from the … | Sep 16, 2026 |
| CVE-2026-89950 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: linearize skbuff for packet generation batadv_mcast_forw_packet() and batadv_mcast_forw_scrape() is not only called (indirectly) … | Sep 16, 2026 |