Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56890
Total
4508
Critical
16896
High
16708
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-89874 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: v4l2-async: avoid deleting unlinked ASC entry on link error v4l2_async_match_notify() creates ancillary media links … | Sep 16, 2026 |
| CVE-2026-89873 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC EXT SPS RPS counts The HEVC SPS control carries the short-term … | Sep 16, 2026 |
| CVE-2026-89872 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link In v4l2_fwnode_parse_link(), the remote endpoint fwnode reference is … | Sep 16, 2026 |
| CVE-2026-89871 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure kthread_run() returns an ERR_PTR … | Sep 16, 2026 |
| CVE-2026-89870 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: zoran: Avoid freeing a registered video_device twice zoran_init_video_device() installs zoran_vdev_release() as the video_device release … | Sep 16, 2026 |
| CVE-2026-89869 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: qcom: iris: use disable_irq() during power-off The IRQ is registered as a threaded IRQ. … | Sep 16, 2026 |
| CVE-2026-89868 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Add timeout while stop_streaming When stop_streaming is called, an infinite loop may … | Sep 16, 2026 |
| CVE-2026-89867 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued Decoder instances sharing a … | Sep 16, 2026 |
| CVE-2026-89866 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Resume device before setting EOS flag Setting the EOS flag talks to … | Sep 16, 2026 |
| CVE-2026-89865 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers The FRU and I2C bsg … | Sep 16, 2026 |
| CVE-2026-89864 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound i2c->length in I2C bsg handlers struct qla_i2c_access carries a 16-bit length field … | Sep 16, 2026 |
| CVE-2026-89863 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check qla_chk_edif_rx_sa_delete_pending() obtains the … | Sep 16, 2026 |
| CVE-2026-89862 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix BSG job leak on validate flash image error path qla28xx_validate_flash_image() returns QLA_SUCCESS … | Sep 16, 2026 |
| CVE-2026-89861 | HIGH | 8.1 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() In the format 1 path, the virtual port … | Sep 16, 2026 |
| CVE-2026-89860 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Initialize NVMe abort_work once at submission qla_nvme_fcp_abort() and qla_nvme_ls_abort() ran INIT_WORK() on priv->abort_work … | Sep 16, 2026 |
| CVE-2026-89859 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak qla2x00_do_dport_diagnostics() allocates the qla_dport_diag response … | Sep 16, 2026 |
| CVE-2026-89858 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() qla2x00_update_fru_versions() copies the user-supplied BSG request into a … | Sep 16, 2026 |
| CVE-2026-89857 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject qla_nvme_ls_reject_iocb() allocates from and advances … | Sep 16, 2026 |
| CVE-2026-89856 | HIGH | 8.4 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation ha->msix_count is u16, but ha->max_req_queues, … | Sep 16, 2026 |
| CVE-2026-89855 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize flash version read in reset handler The "update cache versions without reset" … | Sep 16, 2026 |
| CVE-2026-89854 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix cs84xx use-after-free on host teardown qla84xx_put_chip() drops the last reference to ha->cs84xx … | Sep 16, 2026 |
| CVE-2026-89853 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump qla2x00_free_fce_trace() freed and cleared ha->fce while … | Sep 16, 2026 |
| CVE-2026-89852 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() The mbx_cmd_t is allocated on the stack but … | Sep 16, 2026 |
| CVE-2026-89851 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace enable parsing in debugfs qla2x00_dfs_fce_write() called kstrtoul() with a NULL … | Sep 16, 2026 |
| CVE-2026-89850 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Don't query firmware state while chip is down qla2x00_fw_state_show() initializes rval to QLA_FUNCTION_FAILED … | Sep 16, 2026 |