Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56890
Total
4508
Critical
16896
High
16708
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-89899 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: cec: disable delayed work before freeing an interrupted transmit cec_transmit_msg_fh() drops adap->lock to wait … | Sep 16, 2026 |
| CVE-2026-89898 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: media: cec: extron-da-hd-4k-plus: add sanity check Add check to prevent overflowing msg.msg[] in case the … | Sep 16, 2026 |
| CVE-2026-89897 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: media: cec: Serialize exclusive follower delivery cec_receive_notify() reads the exclusive follower pointer without the adapter … | Sep 16, 2026 |
| CVE-2026-89896 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: cedrus: fix memory leak in cedrus_init_ctrls() In cedrus_init_ctrls(), the V4L2 control handler is initialized … | Sep 16, 2026 |
| CVE-2026-89895 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: cobalt: Avoid freeing ALSA private data twice snd_cobalt_card_create() stores cobsc in sc->private_data and installs … | Sep 16, 2026 |
| CVE-2026-89894 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: reject geometry changes while the VBI queue is busy vidioc_s_fmt_vid_cap() and vidioc_s_std() change … | Sep 16, 2026 |
| CVE-2026-89893 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: cx23885: cancel NetUP CI work before teardown netup_ci_exit() frees a netup_ci_state while its work … | Sep 16, 2026 |
| CVE-2026-89892 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: em28xx: defer audio-only extension registration The audio-only path registers extensions while probing the primary … | Sep 16, 2026 |
| CVE-2026-89891 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: em28xx: fix use-after-free of dev_next->devlist on disconnect When a device with has_dual_ts=1 is probed … | Sep 16, 2026 |
| CVE-2026-89890 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: go7007: defer the ALSA v4l2 put until card release go7007_snd_init() already takes a v4l2_device … | Sep 16, 2026 |
| CVE-2026-89889 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: i2c: imx415: Release runtime PM reference on VBLANK error The VBLANK path returned immediately … | Sep 16, 2026 |
| CVE-2026-89888 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov02a10: fix endpoint parsing use-after-free The ov02a10_check_hwcfg() function calls fwnode_handle_put(ep) immediately after allocating … | Sep 16, 2026 |
| CVE-2026-89887 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov7740: fix use-after-destroy in remove The ov7740_remove() function had a severe teardown order … | Sep 16, 2026 |
| CVE-2026-89886 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: intel/ipu6: fix async notifier cleanup leak on parse error isys_notifier_init() calls v4l2_async_nf_init() and then … | Sep 16, 2026 |
| CVE-2026-89885 | HIGH | 8.4 | In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: Fix SCP device refcounting mdp_probe() first tries to get the SCP handle … | Sep 16, 2026 |
| CVE-2026-89884 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup Add the missing sanity check … | Sep 16, 2026 |
| CVE-2026-89883 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: rc: sunxi-cir: Unregister rc device on probe failure After rc_register_device() succeeds, later probe failures … | Sep 16, 2026 |
| CVE-2026-89882 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow st_ref_pic_set_prediction() computes the reference RPS index as st_rps_idx … | Sep 16, 2026 |
| CVE-2026-89881 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak rtl2832_sdr_remove() runs on USB disconnect … | Sep 16, 2026 |
| CVE-2026-89880 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure rtl2832_sdr_start_streaming() calls rtl2832_sdr_alloc_stream_bufs(), rtl2832_sdr_alloc_urbs() and … | Sep 16, 2026 |
| CVE-2026-89879 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: s2255: bound JPEG frame size before copying into the buffer s2255_fillbuff() memcpy()s vc->jpg_size bytes … | Sep 16, 2026 |
| CVE-2026-89878 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: s2255: check firmware size before reading trailing marker s2255_probe() reads a 4-byte marker and … | Sep 16, 2026 |
| CVE-2026-89877 | HIGH | 8.4 | In the Linux kernel, the following vulnerability has been resolved: media: saa7164: fix cleanup on resource allocation failure saa7164_dev_setup() adds the device to the global … | Sep 16, 2026 |
| CVE-2026-89876 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: tda18250: fix possible integer overflow Integer overflow may occur, when variable exp equals to … | Sep 16, 2026 |
| CVE-2026-89875 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: ti: vpe: quiesce overflow recovery before freeing streams The VIP overflow recovery worker is … | Sep 16, 2026 |